Mark a Best Answer
Fortinet Community
Recently active
I'm currently testing out the trial version of FortiClientEMS 7.4, however I've been unable to use it to for one of the key purposes we would need it for - to configure VPN connections on FortiClient devices. The device in question is running Ubuntu 24.10 with a FortiClient installer generated by the EMS. The FortiClient successfully registers and continuously syncs with the EMS, but despite having SSLVPN enabled within the EMS, and a tunnel defined, the "Remote Access" tab just does not show up at all. Interestingly enough, the "Remote Access" tab is there *before* the user connects to the EMS, but once connected it goes away. Within the settings of FortiClient it also has "Enable SSL VPN Feature" unchecked, but there is no way to change this while connected to the EMS. Everything works perfectly fine on Windows clients (which would end up being a small minority if we were to fully deploy FortiClient). I'm kinda at a loss here as none of the logs seems useful. Does
Hello Forti Guys and girls. I have 2 Fortinet devices, 60C and 40F. I want to use 60C as a lab device to test some features, routing policies. But there is a problem. They both have different firmwares. While 60C has 4.0 (can bu updated to 5.2.13) the 40F has 7.2. So there is a question: is there any major differences between two firmwares, mainly differencese in firewall, routing policies? I want to test policies in 60C and then make the same in 40F. Of course I have to make some changes, like interface's names and others.Have a nice weekend!
Dear Fortinet Community. We want to start with a WiFi project and we are faced with decisions to made. We want to choose good FortiAPs and after checking together with our Fortinet suppliers they stated that a FortiAP 231g could be a good solution. Have you some experience with FortiAPs? Which ones are good which ones are not so fine? An does anyone know if a FortiAP 233g is much better than a 231g? This is a very general question :) So feel free to give me some input about your experience :) Every comment is very much appreciated. Ah and before I forget it. We use a Fortigate 100F (7.4.5) at the moment and think about a Fortigate 400/401F for the future. So we already know the limit for FortiAPs when it comes to the point that they should be managed centrally by the firewall. Fortigate 100F can manage up to 128 FortiAPs. Fortigate 400F can manage up to 512 FortiAPs. With kindest regardsFortiLover
For the FortiDeceptor is there an official document (matrix compatibility type) as is done for FMG and FAZ ?Also among the Fortinet Fabric I mentioned below, can you confirm that the ISOLATOR interacts only with these: Fortigate - YESFortiAnalyzer - YESFortiManager - NOFortiSandbox - YESFortiIsolator - NO Best regards
Hello,We have a hybrid configuration on our domain. When we receive mail from our M365 mailboxes to our on-prem exchange mailboxes, the mail is classified as fortiguard spam outbreak. We has opened a case. Tac engineer gave the following suggestion;1) Change the level from 'High' to 'Medium'.2) Place the domain or sender IP in the Safe list (it will bypass the entire AntiSpam profile).3) Create a specific Recipient policy with the AntiSpam profile where FortiGuard Spam outbreak protection is disabled.4) Set the spam outbreak protection time to minimum (6 minutes).I wonder if I change the outbreak protection level to low or medium, how will this affect us?
Model: Fortigate 60C (FGT60C) When connect to console it has the following error message. The firewall can boot up and functioning. Is there any way to replace this disk ?And what disk is this ?What is the function of fgtag.c ? Thanks.
Hello everyone,I have a single IP address on which I'm going to publish multiple websites.IP is set on one of Fortigate's interfaces. How can I tell FortiGate to: External DNS:aaa.test.com -> My Public IP1bbb.test.com -> My Public IP1ccc.Hello.com -> My Public IP1 1. DNAT "https://aaa.test.com" To "192.168.1.50"1. DNAT "https://bbb.test.com" To "192.168.1.60"3. DNAT "http://ccc.hello.com" To "192.168.1.70" *192.168.1.50,60,70 are VIPs on FortiWeb. It should send traffic destination-ed to each VIP to desired web server.* All client's requests must point to default HTTPS port. All web servers also must only listen over default HTTPS port.
I am using FortiGate 81E, running OS 6.2.3 with the following setup:- Two WAN ports are connected to the ISP using PPPoE mode. WAN1 has a distance of 5, and WAN2 has a distance of 10. Both are ON with the option "Retrieve default gateway from server" and OFF with "Override internal DNS."- WAN1 and WAN2 are members of SD-Wan at the exact 0 cost.- A static route 0.0.0.0/0.0.0.0 -> SD-wan interface has been added.- There are multiple VLANs configured under Aggregate Link (downstream LAG to my Cisco switch), let's say vlan-10, vlan-20, vlan-30.- Policies to access the Internet have been added for all Vlans above (source is vlan-x interface, and destination is SD-Wan). ** When there is just a default implicit SDWan rule with its Load-Balancing Algorithm, all nodes from above VLANs can access the Internet but are unstable due to sessions being switched between WAN1 and WAN2 continuously (look at the Forti View -> All Sessions and see the destination interface switching b
Hi all, I have a device nas with static ip 192.168.10.10 and I would like if a user mount a disk with ip 192.168.100.10 the fortigate had to redirect 192.168.100.10 ip to 192.168.10.10. it is possible? if yes how can I do it?many thanks in advancebest regards
Using a combination of a Webhook automation stitch, External Connector, and a Linux machine running a simple webapp, it is possible to automatically add malicious IPs (e.g. brute-force SSLVPN login attempts or otherwise) to a threatfeed and prevent the IPs from accessing the resource. This tutorial will walk through the setup for banning IPs that have multiple failed SSLVPN login attempts.Full disclosure, I'm not a programmer and ChatGPT helped with the python code. On the Linux machine, install fail2ban: sudo apt-get update sudo apt-get install fail2ban Create a custom Filter to match the malicious IP in a log file. sudo nano /etc/fail2ban/filter.d/fortigate_remote_ip.conf[Definition] failregex = remip=(?P<ip4>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}) ignoreregex = Configure a Jail (note: creating a jail.local file will override the default fail2ban jail settings):Adjust "maxretry" depending on number of times you want to permit failed a
Dears, I recently configure SSL-VPN on my Fortigate 40F.The connection is successful in my iPhone.Howevver, I found that I can only connect to our internal NAS/server using its private IP, like 192.168.3.x.I have set the A record of our NAS/server with their private IP but it not works. Can you advise what should I do to connect to our internal NAS/server with its FQDN?Thank you.
Hi guys,I have my main FGT which has area 0.0.0.0 and some other areas which are connected to other sites via OSPF.When I am directly connected to a subnet which lies in area 0.0.0.0 I can access everything, also I see that every route is propagated nicely. Now as I use OSPF I do not have any routes to the sites nor do I have policies with IP-ranges - just the regarding OSPF-interface tunnel with destination all.Now my problem is when I connect via IPsec or SSL I cant see anything. I read already that you should do a static route to blackhole/ssl.int with the right ip-range and then redistribute static... I then saw the subnet on my branch-sites, but couldnt access them nonetheless. The policy was sourceintf SSL/IPsec - destintf Site1/2/3/xxx. sourceip the right IPsec or SSL range and destination all... I had the right network in the OSPF-network list, I had them as passive,...What is it I am missing? ThanksRaffa
Hi. I would like to modify something. Nowdays I have a App Control that block some sites like FB or Windows Update Application. I would like to restitct it and create a speed limit to thath Apps. I read something, but I don't know is my idea a good solution for that. I reda about Traffic Shaping. Maybe I write point which I want o do:1. Create Traffic Shaping named "limited" with max bandwidth of 256kbps and guaranteed of 100kbps ond Medium Traffic priority) and apply sharper "per policy"2. Create 2 sharping polucy for that all sources to wan port. One is "high priority" and one is "limited". In limit it by choose "windows update and YouTube in Application section".3. Whats the good order for that policies? First "limited" and then "high prioity" or vice versa? I musct create a "high priority" policy or I can create only "limited" to restict YT i Windows Update transfer? How can I see that this is working? Thanks and have a nice day
Hi Fortinet communityI’m currious to hear if anyone has experience or would share their journey towards SD-WAN / SD-WAN zones from a running production FortiGate. I’m managing serveral firewall, all currently build with “normal” interface added to zones etc.FortiOS v6.4.9FMG v7.0.3The interfaces and zones are all referencer in many different policies.I do manage all FortiGates via FortiManager. I’d like to add the interfaces / VPN-interfaces from zones to SD-WAN zones, to start using some the SD-WAN features i.e performance SLA for best egress port. Many of our FortiGates have Dual ISP connection (WAN1 + WAN2) and redundante IPSec / ADVPN tunnels and using BGP for dynamic prefix announcements. However, as I can see - I can’t just move an interface from a zone to a SD-WAN zone, without removing it from the zone first.Then I have to deal with the change to all the IPv4 policies in regards to source / destination interface, where the SD-WAN needs to replace the old zon
Hi, I was reading the FortiGate antivirus topic from Fortinet website. Also I tested them in my test environment by downloading the file from ecior.org. What I found, until or unless you don't use SSL/SSH decryption profile, this antivirus profile is helpless which means that unless or until we don't do the SSL decryption the encrypted files cant be scanned. Is this correct assumption ? Moreover, can any one please help me to point in right direction that where can I find more information about CPRL ?
Hi, I am looking for an ideas to test the proxy based and flow based mechanisms. Today in my lab environment, I configured FGT-VM and windows machine. FGT is carrying all the traffic from Windows machine to internet. First I configured FGT with flow mode and then tried to open different websites such as cnn.com, bbc.com. I also checked the load timing (loader timer extension is added in chrome) for these websites and then marked that timing.Then I changed the inspection mode in policy to proxy mode and checked again, I didnt find any visible difference in loading time. Its quite possible that this is the lab environment and couldnt able to see the difference because of low traffic but is there any way we can actually test both inspection modes apart from features which are only used for specific inspection mode ?
We recently made some changes to our DNS server which now has a new IP addess. When connecting via Forticlient, all network adapters are reverted back to the old IP address causing network drive mapping issues. Changing the settings on the adapter will work while connected through the VPN, but no matter what, the next time a user logs in, the old settings take precedent again. I have manually configured the adapters to the correct DNS address.I have done all the ipconfig / related commands I have tried other solutions from similar posts on this forum and others, but nothing prevents the VPN from changing the settings. Has anyone run into this before, or know of a solution?
Hi guys, We would like to seek similar encountered issue and how did you guys resolve this. We're currently encountering an issue regarding our Web Filter as wherein all access going through internet policies with Web Filter encountered web rating error occured. Had to create a temporary policy without added WebFilter Profile however this impose risks. What should be the workaround for this one for it to work properly again? Suggestions are highly appreciated. Thank you in advance.
Hi allHere is my situation. At home, I use Fortigate 100D (FW 6.2.16) behind my box which forward all traffic to the Fortigate.In recent weeks, when home working with vpn-ssl to entreprise vpn server, my flow has collapsed, and it is the Forti at home that is causing the problem, I have no problem if I plug into one of the ports available on the box and bypass home Fortigate.I don't see any recent changes on home Forti that could explain the problem. The output rules are without filtering or inspections.Wireshark captures I made show tons of TCP Retransmission mainly in the server -> client direction and Dup ACK in the other direction.All your suggestions will be appreciated
I've got an LACP connection from my HA pair of FortiGate 600f's to the rest of the environment. There are 2 physical ports that are under the "LACP_Trunk" 802.3ad aggregate interface. What's the best way to monitor these interfaces for HA failover? Is it best to monitor Port1 and Port2 (which is the indication that I got from an article about Multicast https://community.fortinet.com/t5/FortiGate/Technical-Tip-Best-practice-HA-monitored-interface-configuration/ta-p/214928 ) or is it better to monitor the "LACP_Trunk" 802.3ad aggregate interface directly?TIA!
hello all, I have a FortiGate 100F, I have a problem accessing my internet from my lan, when I plug in a pc, I have an APIPA address while I have configured the DHCP, I have configured a policy, internal to all, from LAN to WAN1, I opened all accesses at first to check and it does not work.Do I have to create a rule in the rules from WAN1 to Internal?However from my forti, when I ping 8.8.8.8 and www.google.fr, everything is OK, but from my LAN I do not have an IP address from my DHCP, and it tells me "No internet access".In the DHCP DNS, do I have to enter the DNS of my internet provider? in the Forti DNS, do I have to enter the DNS of the Provider.Could you help me please ? Regards,
Question regarding FortiManager.Is there any way to only show interfaces for the devices we have, as opposed to the entire product line? We typically use FGT 200F, 201F, 80F, and 60E/F devices. When I want to configure normalized interfaces, I have to wade through every model of device that Fortinet supports in that version of FMG. If I search just for the device type (e.g. 60F), find the port, then make a change, it goes back to the default view of everything and I have search again. When I'm working on building normalized interfaces for a bunch of devices, that can be difficult to deal with and I end up using port specific configurations instead of normalized ones. It would be great if I had the option to choose what devices I want to see in the normalized interface section of FMG and it was a setting that was saved.
I have a TP Link travel router with a (crappy) VPN client built in. I'm trying to connect to my FGT 80 via IPSec. (all my other VPNs work fine) It looks like Phase 1 completes, but I cannot find any indication or idea why it doesn't complete Phase 2. I am currently using a guest subnet to connect. My log is here: PasteBin
When I used the FortiConverter to convert my ASA config into FortiGate, I really didn't care about the Phase2 VPN names. Now the migration to the FortiGate is done and I find that I would like to rename the Phase2 interfaces. Is this possible after the fact? I know it's not possible in the GUI, but thought it might be via CLI however I wasn't able to figure it out just poking at the CLI.
Hello everyone,I’m currently experiencing some issues with our Site-to-Site VPN (fortiOS 7.0.12) that was previously functioning without any problems. It seems that the NAT IP pool is not properly translating the source address, which is causing issues during the Phase 2 negotiation.As a result, the remote site is unable to establish a proper connection to exit the tunnel. I suspect that this misconfiguration might be affecting the traffic routing and connectivity.If anyone has encountered a similar issue or has suggestions on how to troubleshoot this, I would greatly appreciate your input!_______CONFIG SNIPPET_________edit "H_IPSEC_192.168.110.11"set uuid xxxxxxxxxxset subnet 192.168.110.12 255.255.255.255nextedit "IPSEC-192.168.110.12"set phase1name "VPN-IPSEC"set proposal aes256-md5set dhgrp 5set keylifeseconds 3600set src-subnet 10.0.11.6 255.255.255.255set dst-subnet 192.168.110.12 255.255.255.255nextconfig firewall ippooledit "IP-POOL-NAT"set startip 10.0.11.0set endip 10.0.11.25
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.