Mark a Best Answer
Fortinet Community
Recently active
Hello From few days I'm in company where they build network on fortigate devices, before I work only with mikrotik solution, so i need to understand little bit the "fortios idea" So is good time becouse from saturday we notice strange sitauation. In this company they have two localization from one to second is some 25 kilometers, they have direct fiber connection between. This fiber cable are connected to Fortiswitch on site A port 51, on site B port 52.To both Fortiswitch to port1 is connected ISP also with SD-WAN configurationSite A, Fortiswitch Port1 IPS X1 (vlan_X1 -> Fortilink)Site B, Fortiswitch Port1 IPS X2 (vlan_X2 -> Fortilink) On fortigate devices the DMZ port is used for HB, so from both Fortigates DMZ port is connected to port 20 in both Fortiswitch. HA type is A-P, Also SD-WAN This is small picture how this looks with physical connection, and this issiue we have On saturday fiber between Site and Site was broken, SD-WAN showed on both f
Where can I found EOO, LSED, and EOS of fortigate 201F, fortigate 60F, and fortigate 201E? I just downloaded the list of hardware EOO from fortinet support, but i can't find this three on the list.
DearsI have fortiGate SSL and IPSEC RAVPN, i need to force user to change password.any guide please
hi,would it be possible or does it make sense to have a multi VDOM FG managed in FMG to be in separate ADOM?for example, the "core or critical" VDOM such as the "root" and "internet access" are added in the "root" ADOM, then the rest of the "customer" VDOMs would be provisioned/managed in a separate ADOM. we'll deploy an "internet access" VDOM deployment. refer to sample diagram/scenario.the root VDOM in the diagram will be our "internet access" VDOM, like an internet edge device. the rest of the customer VDOM will connect (vlink) to the root/internet access VDOM.
Please help me, FortiClient installation always tuck on Installing drivers state.I've been trying to installing FortiClient 5.6.0.1075, 6.4.10.1821 and 7.4.0.1658 and it always stuck on Installing drivers state and sometime on rollback I've using FCRemover.exe too and it the installation still stuck on Installing drivers
Hi, I have BGP neighbor that advertise me big network range (51.16.0.0/15) and I would to filter this range and get only smaller range from it (51.17.72.0/22); I want that all the rest of this range continue to go through the default route like as always.How can I do it? I tried with prefixlist but it not working because its not the specific range that advertise to me. This BGP neighbor can't split the bigger range that it advertise me and therefor I should filter it by my self. I have Fortigate 500E v 6.4.15. BR,Sefi
Hi,we have a colleague that wasn't able to connect to our VPN due to a unrequested route added by 7.4.0.1645 version of FortiVPN VPN-ONLY client. default via 192.168.1.254 dev en6 default via 192.168.1.254 dev en0 default dev utun13 scope link #this is wrong Could this be a bug or a misconfiguration? Regards,Dimitri
Hello,I can't connect via the Android or IOS APP to VPN with IPV6. No IPV6 support for mobile devices? How do you have the Dual-Stack option for the operating system?
May I know can i connect Fortinet Client VPN which laptop in Singapore but connect in China?How about remote dekstop?
hi,i received a new FG-1800F and saw there's 2x ha and 2x mgmt ports.my question is, can i just utilize/configure only one of these? i.e. use ha1 and mgmt1 onlyor is there a config guide/design to follow wherein i have to use both? seems it will use a lot of switch ports since we're using A/P HA.what are some common design/scenarios for using two ha and mgmt? # show system interface name Name.fortilink static 0.0.0.0 0.0.0.0 10.255.1.1 255.255.255.0 up disable aggregate disable ha1 static 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 up disable physical disable ha2 static 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 up disable physical disable l2t.root static 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 up
Hi All, I have a FortiSwitch which managed via a Fortigate controller. Does anyone know how to create an automate task to automatically shut a switch interface when a cable is disconnected and then only can be then enable again by an administrator? Thanks regardsJimmy
Hi everyone, Looking if there is any way to get Azure AD joined devices to authenticate with FSSO which we have installed in our on prem infrastructure. As we are education based we have different filtering policies for Staff and Students. We have explored the possibility of 802.1x over WiFi however some InTune joined devices will be using Ethernet so not the easiest to configure. Is there any easy way to authenticate with FSSO and/or directly authenticate from Azure to the Fortigate? We currently have multiple Fortigates but don’t have FortiAuthenticator or Forticlient.
This version of FMG was released last week and now CVE-2024-47575 is released as well.https://www.fortiguard.com/psirt/FG-IR-24-423However, the release notes doesn't have anything in the resolved issue section. Does this actually have the vulnerability fix in it?https://docs.fortinet.com/document/fortimanager/7.2.8/release-notes/972111/resolved-issuesToshi
When clients work remotely and connect VPN via FortiClient it takes too long to get the access to the shared drives after connecting with FortiClient, sometimes it takes more than 20 minutes show up the network drives. Any ideas?Thanks
I've been exploring ZTNA and for the most part I have it working as expected when off site with some test cases, accessing some web sites and RDP to a box or two. This is great but since we still use a VPN (And most likely always will use/have it for a while), I've noticed that when ZTNA routes are active on the client, pushed from EMS, I am unable to get to those resources when connected to the VPN. For example, I can ping the server but the RDP port in the ZTNA rule seems to prevent me from accessing it. I'm not sure if this is normal but since I know ZTNA is kind of a solution that should work both in and out of the network, I wasn't sure if anything is actually wrong and I just need to open firewall policies to allow the communication to work. My thought was to add rules to make the VPN connection treat the device on premise but that felt more like a trick than a solution, unless it is. Seeing what other people think about it and trying to get some thoughts on what would be so
Hello; Im planning to update an HA Active Passive.Does both Fortigate must be in the same OS? Or will it be possible to see if I have both on different OS and test the stability of one Fortigate update and later on give the other one the update? Or both must be executed the same day and they must be in the same FortiOS?
I have had two recent incidents where after installing the FortiClient VPN client, one on Windows and one on Ubuntu, where after entering the necessary IP address, port, username, and password the pop up window to accept the certificate never shows. Is there a way to get the cert from the Fortigate and manually install this or somehow force this pop up window to appear?
Hi All, Wondering if anyone else has had this issue or could advise? There are lots of User 802.1x Authentication Failure's in our event log with the Four Way Handshake Timeout error - Is there any recommendations to try and resolve this? Thank you!
Hey all, I have FortiGate 80E firewall (v7.0.7 build0367) with DHCP range 192.168.9.100-192.168.8.250 I'd like to add 25 slots to that range by increasing the starting range from 192.168.9.100 to 192.168.9.75). My question: Can I make this DHCP change in real time? Or will it affect DHCP users, static IP users, VPN users, and my access to the local FortiGate portal?
Good morning, I have a question about what is the best way to update/register a Fortigate 40F behind another Fortigate? There is a big rollout coming up, we want to replace all of our Fortigate 40C with Fortigate 40F and I would like to send the fortigates up to date and registered. We have a lot of small branches and usually we configure new Fortis at our main location just to get them online after they arrive at one branch. Then we register and update the Fortigate, this obviously causes an internet loss.I’m kinda shure that there is a better way, but I can’t figure out how to do it. First I tried to update the firmware manually. But after one successful update I receive this Error-Message:This is a FortiOS v7.6.0-build3401 firmware image that cannot be installed because the device's FortiGuard license for firmware upgrades could not be verified or may have expired. Verify or renew the license to install upgrades.If I understand that correctly the Fortigate needs internet a
I've recently acquired an old (out of support) 60F to "play around with" at home and learn its interface. One issue I've run into that I cannot seem to figure out is how to host a Factorio server. From their wiki they list the following:All game instances need the installation of exactly the same game-versions and mods.Factorio servers use port 34197. The port can be changed in the config file.Factorio uses UDP only. The game builds its own "reliable delivery" layer built on UDP to deal with packet loss and reordering issues.Make sure you configure your router's port forwarding correctly for port 34197.Make sure your router does not randomize the source port on packets outbound from 34197. Some routers do this and require additional configuration to prevent it.Make sure there is no firewall or anti-virus blocking the UDP-packets.It is the not randomized source port that I cannot seem to figure out. To me what makes s
hello,I have a vmware lab and I would try fortigate in vm.I had download the vm image but I saw is limited to 3 interfaces.all interfaces are physical and I can't create vlan is it normal?do you have a solution to create somes others interfaces
Hi All, We are using FSSO to monitor user web activity. We are using the DC Agent to collect logged in users. However, I am seeing on my Domain Controllers, Event 4776 which seems to show that FSSO is still using NTLM. I have NTLM disabled on my policies as well.Does anyone know why event 4776 is being generated by FSSO?Source workstation is the server FSSO is installed on. This event is on the DC. Thanks. I
Hi everyone, Currently testing the Foticlient EMS ztna in trial,I wanted to integrate it with our fortigate 80F on which the SSL VPN is configured for remote access of users on the herberger applications on our multi-application server which contains several application (x,y,z),my need is to integrate ztna with ssl vpn for more granular access control, i.e. authorize a user to only access application x on the server and nothing else, anyone has an idea about this configuration because what I configured doesn't work
HI, im trying to create samba server in DMZ zone when im transfering files from lan to dmz it transfer in 5 or 6 mbps speed . but when i tried withi lan zone it is happaning in 300 to 400 mbps. can any one please suggest how to optimize speed between LAN and DMZ
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.