Mark a Best Answer
Fortinet Community
Recently active
Is it possible to hide this window? I'm not seeing it in EMS portal.
60e - 6.0.4 This is driving me insane. I'm continuously being logged out of the gui. Sometimes its so quick I can't even select "Login Read-Write" and sometimes its the first menu I click on. Other times its after 5 minutes of continuous activity. Doesn't matter if I use a local account or a remote account. Same randomness. Its logging me out "successfully" each time. Login timeout is set to 60 seconds (need time for duo). Inactivity is set to 10 minutes. I'll happily provided any logs/config if someone could point me in the right direction. Thanks
Hello everyone, I am running a Fortigate with FortiOS v7.4.5, where the default VLAN traffic arrives untagged on the LAN interface. Currently, several networks (e.g., 10.0.1.0/24 and 10.0.2.0/24) are operating over this interface.After assigning a secondary IP address to the interface (10.0.1.3/24), routing between the two subnets works as expected. However, the security policies configured between these networks are not being enforced. I have reviewed some relevant articles, but the suggested solutions do not seem to resolve the issue. According to these Fortinet Technical Tips, the traffic should be blocked by default and then allowed through the appropriate policies:Allow traffic between different subnets with the same VLANHow to allow traffic when using the same logical interfaceI have tested this in a lab environment, and as expected, the traffic between the subnets is routed, but the configured security policies are not being applied. Is this behavior expected? Are
Dear all, I'm new to FortiEMS. I have done the fresh installment as a VM using the trial license. Our current architecture is: FortiGate + FortiAuthenticator. The user are connecting to VPN (SSL-VPN) using FortiGate + FortiClient and FortiAuthenticator as a MFA. We want also to add FortiEMS as a layer to do a posture check for the device prior of giving them permissions to connect remotely to the company resources. We have users with a company joined AD laptop + BYOD devices. I'm trying to understand: 1- Where will the FortiEMS stand in the "big picture" at the architecture level ? Will it replace any of the components ?2- Do i need to connect FortiEMS with FortiGate ? If yes, will i have any impact since i do not have a test env and FortiGate is directly in production.3- Do i need anymore the FortiAuthenticator ? Thank You in advance #FortiEMS
Hi everyone : my wifi with WPA2 Enterprise setting can't connect since last week when I typing account & password,it will show up make me typing account again ( account is correct ) here is setting picture ( wifi typing、ssid setting、radius setting )
Hi!In the past, it was possible to connect from Fortimanager to fortigate via "ssh" session also in backup mode (even when the fortigate was behind a NAT device). That "ssh"-session is tunneled inside FGFM connection.In the latest FMG versions, this feature seems to be only available, when Fortigate is managed by Fortimanager.Is there any way to bring this feature back, when operating ADOM in backup mode.I mean this button in System Information box:
There is a ping package loss in the IPsec tunnel.fortinet FGT40F
Newbie here (sorry)!I have searched through this site and could not find what I'm looking for, and hope you can help. Background:I have a FortiGate 1000D running firmware v5.2.11,build754 (GA) in a K-12 school district with 5,000 students with one-to-one devices. I also have a VM with FortiAuthenticator. Issue:I would like to configure my FortiGate to the following.When a user logs into their device and opens up a web browser they are presented a login screen. Once they login and authenticate to my Active Directory, they are then allowed or denied access for a set time frame. Thank you in advance for all your help! Troy
I want to upgrade FortiGate 600F from v7.4.3 build2573 (Feature) to v7.4.5 (Mature). We have several remote clients with window 8.1 Pro to use SSL VPN Connection. All devices are used Forticlient version 7.4.0.1658 Is there any IE internet explorer TLS version issue on window 8.1 pro side for new firmware?
Hi All, I use v7.4.5 on FortiGate 61E.I operate FortiGate VPN with WAN, so it is confirmed that the Device Detection feature cannot be activated.Is there a way to find out or verify the user's MAC address in this situation? The "Device Manager" menu in the guide was also not found on the operating system. (Guide) Best regards,
Dear Experts, Here is my story for SD-WAN IPsec aggregation. The 2nd line is disconnected and it is kept (disconnected).Temporarily whole SD-WAN line is disconnected. I understand it.However, recovery takes much time (more than 3-5 minutes).Can we shorten this time? Thanks in advance,
Has anyone seen the issue when upgrading their HA fortiADCs where the secondary ADCs rspools will show down, even though they show as healthy in different tabs? The primary rspools show as healthy but the secondary do not. Is there any documentation out there that addresses this issue?
We are getting below error in VPN events .How to solve it??? Please share a quick response and solutions for this??
Hello,I have spent some time searching for a solution for this issue and cannot find it anywhere. We recently purchased a bunch of the FortiswitchRugged 112D-POE to replace older switches at our site. This is going to part of a giant network upgrade project. However short term I am using two 112Ds to connect to an existing network. I can connect via CLI and have already changed the IP/netmask (with hope that it would allow the web gui to work). I am looking to log into the web gui to finish a few updates to a few settings. I type in the IP in internet explorer and type in admin for username, I have already changed the password in CLI so I have a password to enter in that field. The login button seems to be disabled and won't let me login. I was wondering if anyone encountered this and has a possible solution. Many thanks!
I want to see what the current settings are set to, and make the changes in this article "Technical Tip: How to limit SSL VPN login attempts and block duration" via Fortimanager.If I log into the actual box it says it will become out of sync with fortimanager. Is there a way for me to easily resync it? John B.
When I connected to my iPhone's hotspot, the FortiClientVPN stays stuck always at 98% during login.My iPhone is at that moment connected to a 4G network here in the Netherlands.What I noticed is the problem is fixed if I disable IPv6 support on my wireless adapter in Windows.See below the logs of the FortiClient VPN (debug level) I am using version 7.0.6 of the FortiClient VPN on Windows 10 21H2, the firewall is running FortiOS 7.0.6 Do more people have this problem?
solved
Hello everybody! A few days ago, I encountered a problem with my Fortigate F40 hanging. The problem was solved by rebooting, after updating to version 7.2.10, it went into the boot loop. The firmware for an earlier version 7.2.3 helped, then updated to 7.4.5. The Internet disappeared in the evening, then appeared in the morning by itself.Here is the crash log: 1: 2024-10-27 03:36:16 the killed daemon is /bin/sflowd: status=0x02: 2024-10-27 03:36:29 the killed daemon is /bin/sshd: status=0x1003: 2024-10-27 03:48:34 the killed daemon is /bin/getty: status=0x04: 2024-10-27 03:48:46 Interface a is brought down. process_id=1700, process_name="cmdbsvr"5: 2024-10-27 03:48:46 Interface lan1 is brought down. process_id=1700, process_name="cmdbsvr"6: 2024-10-27 03:48:46 Interface lan2 is brought down. process_id=1700, process_name="cmdbsvr"7: 2024-10-27 03:48:46 Interface lan3 is brought down. process_id=1700, process_name="cmdbsvr"8: 2024-10-27 03:48:46 Interface wan is brought down.
Hi, i'm wondering the following... I have 4000 endpoints registered in EMS. I need to free up some licenses. I can exclude some endpoints which actually never use the vpn. The endpoint receives a 30 day grace period where they can still connect to the vpn. What happens after 30days? They can no longer connect, that's clear. But the endpoint still exists in the EMS environment? Or is it cleared up? Secondly, with the Forticlient comes the fsso agent (authenticator). What happens when an endpoint is excluded from management? Does the fsso service stop? Immediately, or after 30 days? Of does this just continue to work (as the license for this is basically on the authenticator server)...
Does anyone know what's going on with the psirt advisories lately? They used to drop once a month but they have posted multiple times in October and it looks like they just posted a bunch of old vulnerabilities today. https://www.fortiguard.com/psirt
Hi How do you ensure that when the user locks the pc ,the fortinac disconnects the user from the network ,until when the user logs in again?The user has a persistent agent installed.
Could someone please advise me. I have setup SSO login for SSL-VPN via AAD, but in AAD I have groups for example finance and tech support, but in fortigate I have it all as one group azure - Remote sso, problem is I need different rules for finance and different for tech support, how to make me use SSO, but have multiple groups in fortigate and the female from finance don't have access everywhere like tech support. Thank you for your help!
Hi Guys, New to the forum. I have recently purchased a FortiWifi 30E for home. I would like some opinions and thoughts on what and how to set it up in the best way. For eg. Guest Wifi and Normal Wifi. Would you make a captive portal for guests ? Just use WPA2 ? Regards,
I'm currently testing out the trial version of FortiClientEMS 7.4, however I've been unable to use it to for one of the key purposes we would need it for - to configure VPN connections on FortiClient devices. The device in question is running Ubuntu 24.10 with a FortiClient installer generated by the EMS. The FortiClient successfully registers and continuously syncs with the EMS, but despite having SSLVPN enabled within the EMS, and a tunnel defined, the "Remote Access" tab just does not show up at all. Interestingly enough, the "Remote Access" tab is there *before* the user connects to the EMS, but once connected it goes away. Within the settings of FortiClient it also has "Enable SSL VPN Feature" unchecked, but there is no way to change this while connected to the EMS. Everything works perfectly fine on Windows clients (which would end up being a small minority if we were to fully deploy FortiClient). I'm kinda at a loss here as none of the logs seems useful. Does
Hello Forti Guys and girls. I have 2 Fortinet devices, 60C and 40F. I want to use 60C as a lab device to test some features, routing policies. But there is a problem. They both have different firmwares. While 60C has 4.0 (can bu updated to 5.2.13) the 40F has 7.2. So there is a question: is there any major differences between two firmwares, mainly differencese in firewall, routing policies? I want to test policies in 60C and then make the same in 40F. Of course I have to make some changes, like interface's names and others.Have a nice weekend!
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.