Mark a Best Answer
Fortinet Community
Recently active
after Upgrading From 7.4.12 to 7.6.7 on FGT70G all users with Fortitoken Cloud cannot connect IPSEC VPN IKE2 , the only way is to remove the token.
Hi All,We just opgraded a few sites to FortiOS 7.6.7 on the Gates running as Wireless Controllers (VMs), and then a few FortiAP 23JK (Inroom) to FW 7.6.5.That breaks PoE Passthrough on port3.Downgrading the AP to 7.6.4 again, brings back the PoE passthrough on port3.
Hi, I would like to filter out all the IP from network 192.168.11.0. Could you guide what is value should I input? I try type 192.168.11.* , or 192.168.11.0 or 192.168.11.1-192.168.11.100. no correct result. BrgdsLiu Wei
Hello everyone, I encountered issue where after I reload on of my core switches I lose connection to Access Switch even tho its connected redundantly to my other Core switch. This is diagram of the connection:Network diagramI am running 400F in HA cluster in Active-Passive mode. From both Fortigates I have Fortilink towards my Core switches. The switches are in MCLAG stack with Fortilink split interface disabled. We connected multiple access switches to the Core stack and they all link up correctly, they have been discovered by Switch Controller on 400F and they created the trunk interfaces towards the Core switches. (automatically)When we reload CORE1 for example we lose connection to the access switch for the time the CORE is being reloaded. We did some troubleshooting and were checking STP states on CORE2 and state of the trunks during the reload. We noticed weird thing when connected to CORE2 via CLI while CORE1 was reloading → We ran some diag commands for trunks and the trunk inf
Hello Everyone, I see that /api/declarative is desribed in fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/7a380719-1f54-11ed-9eba-fa163e15d75b/fortiadc-v7.1.0-handbook.pdf The example is for posting system configuration (Simmilar to F5 DO declarative onboarding) but what about Virtual Servers to be created declaratively ? Something like F5 AS3 way to deploy Virtual Servers. Also is there such options for the WAF?
Could you help me with a suggestion?We have a FortiGate HA setup with two ISP links. The customer wants the SSL VPN service to remain available regardless of which ISP link goes down, so that user connectivity is not impacted.One option is to configure SSL VPN access on both ISP connections. However, I have a question regarding routing behavior. If I configure two default routes for WAN1 and WAN2, with WAN1 as the preferred route, what happens when a user connects to the SSL VPN using the public IP address associated with WAN2? edit 1set dst 0.0.0.0/0set gateway <ISP1_GW>set device "wan1"set distance 10nextedit 2set dst 0.0.0.0/0set gateway <ISP2_GW>set device "wan2"set distance 20next Will the SSL VPN connection work correctly, or could there be issues due to the return traffic being routed out through the preferred WAN1 interface instead of WAN2, or it will be return via wan2 maintain symmetry.similarly., customer want to have DNAT polices for internal services to remain
I have a FortiWeb that is used for our QA environment that is not exposed to the internet. I need to be able to manage certificates on it automatically to avoid having to manually replace them every month as the lifecycle shortens. DNS-01 is completely manual so that's out. I tried HTTP-01 using an internal private ACME server, but the Fortiweb rejects the certificate when making the https request to the ACME server because it is signed by our internal CA. Does anyone have a method they are happy with for managing certificates in this situation?
Dear forti users,I would like to ask why the hb_packet_version number is different on a primary and secondary member in a ha cluster?We have 4 cluster and this is the exact same situation in every one. The devices ordered in pair for cluster, so it hardware and config is matching.One cluster a little bit different in that term I tried to add a third member (which have different bios and part-number version number, but every other parameter is also the same). Unfortunaty there very problems in syncing so I removed it from cluster. Can be the source of the hb_packet_version differences on those cluster? The support said the the version numbers must match. Really should match?fortios 7.0.17Thank you
Dear All,I had to configure Site 2 site IPsec tunnel with cisco router with using OSPF protocol so I thought, First do the lab then implement. I was doing lab to configure IPsec tunnel with cisco (CISCO CONFIG (VTI + IPsec + OSPF). but unfortunately Fortigate does not support AES encryption in config phase 1 and 2 setting. on the other side cisco router support AES encryption does not support legacy encryption like DES. Fortigate proposal setting - BR1-FW1 (phase2-interface) # edit BR12BR1BR1-FW1 (BR12BR1) # set proposalnull-md5 null-md5null-sha1 null-sha1null-sha256 null-sha256null-sha384 null-sha384null-sha512 null-sha512des-null des-nulldes-md5 des-md5des-sha1 des-sha1des-sha256 des-sha256des-sha384 des-sha384des-sha512 des-sha512BR1-FW1 (BR12BR1) # set proposalexitcisco router phase 2 proposal ( cisco router setting)BR2(config)#crypto ipsec transform-set MY_TRANSFORM_SET ? ah-md5-hmac AH-HMAC-MD5 transform ah-sha-hmac
Can you help me to find the FortiGate logs?
Hello, I have a 200F fortigate and it's working with 7.6.4 firmware. After I upgraded, I can't see some SSID (WPA2 Personal).But WPA2 Enterprise and Open Guest SSID are working. Why might this happen?Thank you.
Hi,I have been following the KB articles and forum comments for months, but I still don’t see a workable solution for us.We are using a FG90G (FortiOS 7.4.7) with SSL VPN, around 100 LDAP users, FortiClient VPN-only, and FortiToken for MFA. This setup worked very well for many years, but due to OS-related requirements, we now need to move to a new solution.First, we configured IPSec IKEv1 with around 10 of our LDAP users. Some of them work fine, but others experience significant issues, mainly frequent disconnections — approximately 1–2 disconnects per hour. With 100 users, this is not a viable long-term solution. We then tested IKEv2 on a FG80F. It works fine with local users + FortiToken, but with LDAP + FortiToken + FortiClient VPN-only, we receive an EAP failure message. I’m not sure whether there is a proper solution via FortiClient XML configuration that could resolve this, or whether there are other limitations we are facing.A more drastic option would be to replace the FG90G wi
Hello everyone, I just encountered issue while connected Access Switches (specifically 148F and 124G) to our core switch 2048F. In our enviroment we have FGT 120G as perimeter firewall which is connected to 400F that serves as segmentation firewall and also as switch controller. 2048F is main core switch from which I have connected few access switches (148F and 124G). For some strange reason out of 9 switches only 6 came online without issue. The other 3 did not show up. Strangely I can see the ports leds blinking and if I go to FortiSwitch Ports and roll out the ports of the 2048F I can see the ports online with the missing switches serial numbers shown. The 3 missing switches would show up for authorzation I have waited approx. 30+mins. I have tried to add the FortiSwitches manually but they are still shown as “Offline”.Attaching screenshot from FortiSwtich Controler → Managed SwitchesThis is how it looks from Fortiswitch Ports menu (I circled the switches which I added manually and
Hello everybody,I hope you all doing well,I have some question for Forti web a-a setup as this is my first time updating I did my research and found that both nodes will be updated at the same time and there will be down time so is there any way like splitting the HA connection and try to update one of them then swap the traffic or am taking to much risk ? the upgrade path will be from 7.4.8->7.6.2->7.6.7what is the best way to prepare for such kind of operations I have previously worked with FortiGate's but only in Active-Passive clusters.Please advise as this is my first time trying to prepare for this Forti Web updates.Also have anyone tried 7.6.7 in production env ? it seems for me the most stable one and has no CVEs or known issues.Thank you in advance.
Hello everyone,I am preparing to deploy a brand-new FortiGate appliance for a customer and I have a couple of questions regarding the initial setup process.When I connected to the management interface for the first time, I was presented with a screen requiring FortiCare registration before proceeding.My questions are:Should the FortiCare registration be performed using the customer's FortiCare account, or is it acceptable to use our company's FortiCare account as the implementation partner? What is considered best practice? Does the FortiGate license/support contract need to be activated before performing any configuration changes, or can the firewall be fully configured first and the license activated later? What is the recommended procedure for license activation on a new appliance? Where can the license be downloaded or claimed? Is there an official Fortinet process or best-practice guide for onboarding a new FortiGate? I would appreciate any recommendations based on real-world dep
Hi all, I saw a strange issue today when i was setting up a new VPN to a site. The site has one fiber connection and one 4G connection. I set the tunnel up as usual and i see both in the list under VPN. If i check the status och the VPN i only see the “primary” (fiber) connection and no 4G. If i the edit the firewall policy the secondary (4G) connection shows green/up.If i the run diagnose vpn tunnel list i getname=******-SEC ver=2 serial=52 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.10 tun_id6=::10.0.0.10 status=down dst_mtu=0 weight=1name=******-SEC ver=2 serial=54 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.11 tun_id6=::10.0.0.11 status=down dst_mtu=0 weight=1The site is not commissioned yet, hence the primary connection down.
I have several entra group and this group imported to the fortinac, then i add some user to group called IT.When some user IT connect to the network, some of them can connect and some of them cant connect.I do debug for user who can’t connect to the network and i found this message, seem fortinac see this user is member of another group so the policy is not working. 2026-06-11 06:19:23.911 7C:B5:66:6B:D7:F3 - [Policy] HostRecordUtil.getAbstractPolicy() HostRecord DBID: 1456217792417818 Policy ID 1464353948106780 Groups not matched: Required:OR[GroupId: 1464105708654608, GroupType: 1] Provided:[GroupId: 1454135121485837, GroupType: 0, GroupId: 1456635326402562, GroupType: 0]Below is my queris:The GroupID is id from fortinac? How i can know the group name from group id? What is 0 and 1 in the group id?
Hi!Supposedly, setting executing “diagnose vpn ike log filter name” with phase1 name as argument will confine “diagnose debug application ike 255” or “diagnose debug application ike -1” debug logs to only that tunnel. However, when I do it, I see debug logs for all tunnels. How to filter out all the tunnels’ debug logs?Thanks!
Hello guys! Users on a regular IP based firewall policy with no UTM profiles applied to it, are having problems when trying to access Faceboo. On IE the page appears as text only and on Google Chrome, the pictures are blank. If there is no UTM feature applied to this rule, what can be the cause of this behaviour? Thanks in advanced guys!
Hi Everyone. today we was encountered the Fortigate Dynamic DNS issue in firmware 7.4.11 and 7.4.12. Restart the firewall few time still unable to access even ping google.com also unable to resolve but when PING 8.8.8.8 from Fortigate is reachable. In the Network → DNS → DNS server show Primary DNS and Secondary DNS server is unreachable. Even the host name unable to resolve
Dear Team, When a FortiEMS virtual machine is deployed using OVA file, it loads with one interface and the default gateway pointing to the same interface. Can we have an additional interface ? Because there is a requiremet for dedicated OOB management and Dataplane interface for Forticlient telemetry connction.https://docs.fortinet.com/document/forticlient/7.4.0/new-features/182605/deploying-ems-as-a-vm-image-7-4-1
We have multiple IPSEC VPN dial up customer sites with SAML.One of our clients sites, requires NAT to be turned OFF in the Forticlient profile to connect, and all the rest require it ON. Mostly it's the same or similar ISP, NAT in the Phase 1 policy on the Firewalls are set to the same on the two examples I tested, so I don't think it's that.FortiOS 7.2.13 on a 60F for both.Any ideas where or how I can figure out why this setting requirement differs between this site and the others?TIA
Introduction AI agents are no longer just writing code — they're installing capabilities. Agent Skills (reusable packages that extend tools like Claude Code, Cursor, and other AI coding assistants) are the new dependency layer, and they come with the same supply chain risks that plagued npm and PyPI a decade ago — except with direct access to credentials, file systems, and shell execution.The https://owasp.org/www-project-agentic-skills-top-10/ project now catalogues the threat landscape formally — from deliberately malicious skills (AST01) and supply chain compromise (AST02) through over-privileged access (AST03) and unsafe deserialization (AST05). The barrier to publishing a skill is a single markdown file and a week-old GitHub account. No code signing. No review process. No sandboxing by default.Today we're releasing Skills Scanning as part of FortiCNAPP Code Security — deterministic detection of malicious and risky patterns in AI agent skill definitions, available in both our SAST
I try to add my tplink to the FNAC and in the inventory the port showing 6 from 12. Where i can see the rest of 6 ports?
I am trying to migrate a switch port from root vdom to inside. When I do that the port it does not appear in the inside VDOM and it does not accept any commands in root vdom and it gives the error:“Invalid switch portobject set operator error, -651 discard the settingCommand fail. Return code -651”I managed to bring the port back if I make the change in the config file and then upload the file to the fortigate. However, when I try to move the port again to inside I have the same issue. Also made the corrections mentione in: Fortigate 400E version 7.4.11 build2878FortiSwitch: S224DF-v7.4.6-build895,250129 (GA)
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.