Mark a Best Answer
Fortinet Community
Recently active
We have multiple IPSEC VPN dial up customer sites with SAML.One of our clients sites, requires NAT to be turned OFF in the Forticlient profile to connect, and all the rest require it ON. Mostly it's the same or similar ISP, NAT in the Phase 1 policy on the Firewalls are set to the same on the two examples I tested, so I don't think it's that.FortiOS 7.2.13 on a 60F for both.Any ideas where or how I can figure out why this setting requirement differs between this site and the others?TIA
Introduction AI agents are no longer just writing code — they're installing capabilities. Agent Skills (reusable packages that extend tools like Claude Code, Cursor, and other AI coding assistants) are the new dependency layer, and they come with the same supply chain risks that plagued npm and PyPI a decade ago — except with direct access to credentials, file systems, and shell execution.The https://owasp.org/www-project-agentic-skills-top-10/ project now catalogues the threat landscape formally — from deliberately malicious skills (AST01) and supply chain compromise (AST02) through over-privileged access (AST03) and unsafe deserialization (AST05). The barrier to publishing a skill is a single markdown file and a week-old GitHub account. No code signing. No review process. No sandboxing by default.Today we're releasing Skills Scanning as part of FortiCNAPP Code Security — deterministic detection of malicious and risky patterns in AI agent skill definitions, available in both our SAST
I try to add my tplink to the FNAC and in the inventory the port showing 6 from 12. Where i can see the rest of 6 ports?
I am trying to migrate a switch port from root vdom to inside. When I do that the port it does not appear in the inside VDOM and it does not accept any commands in root vdom and it gives the error:“Invalid switch portobject set operator error, -651 discard the settingCommand fail. Return code -651”I managed to bring the port back if I make the change in the config file and then upload the file to the fortigate. However, when I try to move the port again to inside I have the same issue. Also made the corrections mentione in: Fortigate 400E version 7.4.11 build2878FortiSwitch: S224DF-v7.4.6-build895,250129 (GA)
Microsoft Hyper-VAfter successfully logging in to FortiCloud, the session is automatically logged out after a short period. The logout occurs repeatedly, preventing stable access and management through FortiCloud.Troubleshooting Performed:* Verified internet connectivity* Cleared browser cache and cookies* Tried different web browsers* Confirmed correct system date and time settingsanyone manage to resolve this problem?
HelloWe are using a FortiWeb cluster as a VM for our customer. The backend servers of our customer's customers are gradually being migrated to this FortiWeb cluster from a Sophos UTM 9. We also operate the Sophos UTM 9. The first backend servers are already running on the FortiWeb VM and access is successful. The challenge now is to migrate the backend servers that use SSO login via KeyCloak with Azure to the FortiWeb cluster. We have configured a test backend server for this purpose. Our customer has configured KeyCloak (plain vanilla without any special configuartions) on his environment. We have configured the Azure parameters on our side in Azure. When accessing the test backend server via Sophos UTM 9, everything works without any problems. When accessing via FortiWeb, I can authenticate and then it's pending. After round about 20 seconds comes '404 Not Found'. What did we overlook or configure incorrectly in the FortiWeb cluster configuration?Thank you in advance for
I have an email notification set up to alert when one of our ISP’s goes down. The problem I’m having is the Minimum interval setting is not working. I have it currently set for 2 minutes and it immediately alerts me when this happens when no delay. I’m getting way more notifications than i need to for this. The model is a 60e and the firmware is 7.2.8. Does anyone have any suggestions in order for this to work properly?
HiDue to the reduction in the maximum certificate lifetime, we need to frequently upload local certificates to FortiWeb in the future.My environment uses a true transparent proxy mode, can I change it to use Let's Encrypt? If I do so, the certificates used on FortiWeb and the real server will be different. Will this cause any connection issues?Or is there a way to upload a local certificate and have it automatically applied to all server pool members?Thanks.
Do you use any AI tools for troubleshooting problems with FG's? If so, which ones work best for you and in what situations?I mean, for example, the approach in which you write: "hey, here are the logs, give me the next steps of troubleshooting to determine what is the cause and how to fix it."
One of our clients has a user he's suspicious of browsing social media consistently during work-hours. He's wanting to catch this user-out with logs/reports of the the internet traffic. How would we go about doing this? Did a quick look around, is the FortiAnalyzer the best tool for the job?
Hello,has anyone experienced issues with RADIUS authentication for IPv6 clients on a captive portal interface?Setup: FortiGate 200F, FortiOS 7.4.8, interface with security-mode captive-portal + security-mac-auth-bypass enable.IPv4 MAB works flawlessly — FortiGate sends an Access-Request with the client MAC as username, RADIUS responds with Access-Accept, and the auth entry appears in diagnose firewall auth list. No issues. config authentication rule edit "TEST Radius" set srcintf "50 Lan" set srcaddr "all" set srcaddr6 "all" nextend For IPv6, FortiGate sends no RADIUS request at all (confirmed via tcpdump). The diagnose firewall auth ipv6 list remains empty regardless of configuration.What was tested without success:1. config authentication rule with srcaddr6 "all" — CLI accepts and saves it, but the daemon never processes IPv6 sources.2. Framed-IPv6-Address (RFC 3162) in Access-Accept reply — FortiGate receives the attribute (confirmed via tcpdump, packet le
I'm trying to setup a POC to demo ZTP.....Using the Fortigate Cloud service, I was able to provision a Fortigate to it's proper On-Prem FMG. However I was unable to get the gate provisioned to the proper CLOUD FMG. (Even though it says it's supported). I then tried using FortiZTP service and was able to provision to the CLOUG FMG successfully. Has anyone else run into this ? Should we be using the FortiZTP since it's still in beta ? Tom
Anyone using FortiManager cloud with multiple FortiGates? I’m new to FortiManager Cloud and I’m having trouble streamlining FortiGate onboarding. I have about 30 firewalls to deploy.What methods are you using? We’re trying to go down the CSV upload method with several configuration variables defined in the CSV file
Hello FTNTI see in known issues of FortiOS 7.4.11 the following bug id. 1256278 Packet loss occurs when asic-offloading is enabled on FortiGate. Can anyone explain in which models and/or circumstances this can happen?
Hello,Would really appreciate it if someone can point me to the right direction or help me with the following. Using DoS policy would like to know if its possible to create 2 polices with source like soPolicy#1 IPs from specific country. The limits are set higher or set to disable.Policy#2 All other IPs . The limits are set very low The questions are Does Fortigate support anything similar to the above? If both policies are enabled Will this lead to an increase in the resource usage of the Fortigate firewall? Thank you in advance.
Is it possible to configure link aggregation on wan1 of the FG-80F? It was possible on the FG-80E.
Anyone experiencing this issue with FortiClient 7.4.7 and the latest macOS? I had to prep a new MacBook for one of my people and upon installing FortiClient from my EMS (Cloud) installer, it just will not register from the still good invite code bundled in the installer nor will it accept the invite code trying to manually enter and connect. It does not give me an error or anything, it just does nothing. Invite code is still good as I used it with a Windows PC afterwards and no issues. I have went through the release notes for 7.4.7 in regards to macOS and ensure disk permission access and system extension activations were good, etc… and all are on/allowed based on the release notes requirements.
Hello community. I will have to work on a deployment of a FortiADC to publish internal applications to our users. The existing (non-Fortinet) solution is publishing the internal app with the following values: App PATH: C:\red\blue\app.exeStart in folder: C:\myfolderParameters: -an entry -b entryb -c entryc.... On FortiADC I do have the fields for App Path and parameters, however im not seeing where to place the "start in folder" info on FortiADC. Any ideas here, what to do?
Hi there, due to crazy pricing in subscription models and such we're considering FortiADC as a possible replacement for our F5 BIG-IP 2-node-cluster. I have FortiADC v7.4.4 running in an eve-ng lab and some questions arose. We have BIG-IP LTM & APM but we do nothing with App Portals, we just use 1:1 mappings (almost) with a portal front with complex logic. So something I would need, and I do not know if FortiADC can do that, or if things would have to be designed differently: On BIG-IP I have an Access Profile, an equivalent I assume to HTLM Forms, where I have a form with CAPTCHA, user name and password, which then goes to AD/LDAP, then a second dialog for internal MFA authenticating over RADIUS, and then it saves the successful auth state as a user session variable, which is then used in a script for Remote Desktop Gateway clearance in the background. The BIG-IP then internally transitions to a forwardable Kerberos ticket for the user to access all the publish
Hi,FortClient for Android asks for “Overlay permissions” when starting the App during initial setup. For ZEBRA Scanners there is an option to pre-grant this permission via OEMConfig: Enabling Display Over Other Apps Permission via MDM/EMM OEMConfigTherefore, the “Package Signing Certificate Fingerprint” of FortClient App is required. Can you please provide is with this? Since the APK isn’t available for public download, it cannot be extracted via ZEBRA’s SigTools utility by customers.Thanks!
Hi,we have such problem that fortigate fortios 7.4.11 is blocking copilot.microsoft.com the error we get in the browser is:net::ERR_CERT_AUTHORITY_INVALIDSubject: Fortiguard SDNS Blocked PageIssuer: Fortiguard SDNS Blocked PageWhat we did:1.in DNS profile --> static filter we created:- wildcard name *.microsoft.com and allowed it-allowed regex .*bing\.com-allowed regex .*trafficmanager\.net2.In the deep ssl inspection profile, we created the exempts:-wildcard *.microsoft.com-wildcard *.bing.com-*.trafficmanager.netBut all the time, this site is blocked by SDNS, any help?
Hi,I'm new on Fortinet products recent I have obtained FCAI am preparing to take NSE4 exam(FCP)! Is it compassory to purchase both LAB and Instructor.led so as I can get my certificate after passing the exam?Thanks
Question: FIPS-CC is enabled. The interface is up. Why can’t I set allowaccess to permit https on port 1 for GUI access? The Background: I don’t have any FortiOS experience. I’ve been given a 71F to configure. The documentation describes enabling FIPS-CC, setting a new administrator password, and enabling the ports via config system interfaceedit internal1set status upend followed by changing the allowaccess attributes to add https via set or appendset allowaccess ping https Neither append nor set allow me to do so, and set ? doesn’t list allowaccess as an option. the internal1 (port1) was part of a virtual switch. i’ve since removed it: config system virtual-switchedit “internal”config portdelete internal1end a ‘show’ command after each ‘end’ reflects that the configurations were accepted - internal1 is up and removed from the virtual-switch. if i `show full-configuration system interface | grep -f internal1’, i get the following attributes. config system interface edit "internal1"
Good afternoonDoes anyone know what happened to the release of version 7.6.7? It was supposedly coming out on Thursday, May 21st, but it's already the 29th and there's still no news. I'm having the DNS proxy bug, so I absolutely have to stay on 7.6.4 and can't risk upgrading to 8.0.
Set up an Invitation to use (on-prem) Domain (LDAP) FortiClient Sign-in fails with this error : from EMS log :Registration attempt by Endpoint was denied due to LDAP authentication failure for user 'test-user'. Server: test.local, , Reason: Authentication error: User not found in DB with [test-user] The user is part an LDAP group that is AuthorizedAlso, The credentials work in Administration / Authentication Servers when tested Where have I gone wrong ? Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.