Mark a Best Answer
Fortinet Community
Recently active
Hello, is there any option to set QR Code URL Scan?we had today an incident, that e-mail was having a QR code which has leading to malicious webpage.is there any option to scan those images with QR code with fortimail?
Hello,I have configured a network share and would like any file added to the folder to be scanned automatically. I noticed that a schedule can be set, but the shortest available interval is every 15 minutes.Is there a way to configure it so that a file is scanned as soon as it is placed in the folder? Alternatively, can the scan be set to run every minute?Thanks
Hello,We have deployed EMS 7.4.7 and we need to deploy client to about 300 endpoints via Intune. But Im missing option to choose the Invitation code during installer creation. In creation is only option to “override invitation code during upgrade”. And under Invitation page when I create an invitation code it is not possible to link it to existing Forticlient installer. Is there a way how to do it? Main thing we are fighthing right now is that after installation of Client to endpoints, it is not automatically registered to EMS. I have found out this topic, where its said that we shouldnt using “enforce user verification” so I have disabled it. But still im confused about invitation codes.Thanks for help!
Hello, I’m applying to a few Inside Sales Representative roles at Fortinet and would like some insight when it comes to the interview process, culture in the sales org, how strict WFH/in office is, and anything of that mature.Context, I have just under one year of experience at a large VAR. Thank you.
Hi Everyone,I have some problem when integrating a standalone FortiSwitch (S148FFTF series) with Cisco ISE. During deployment, authentication was completely successful on Cisco ISE (Access-Accept returned), but the endpoint would fail to receive a DHCP address and drop into an "Unidentified Network" status.Environment Details Switch Model: FortiSwitch 148F (Standalone Mode) RADIUS Server: Cisco ISE Dynamic VLAN Assignement not work properly.
Hi Support, I would like to know where I can find an official UAT reference for the 2601F. The firewall has been mounted, and the customer performed the configuration themselves. Therefore, I will only perform a basic check and then submit a UAT report to the customer to close the project. Could you please provide any professional guidelines? Thank you.
Hello Fortinet Community,I would like to seek assistance regarding an issue I am currently facing with FortiClient IPSec VPN.My laptop is running Windows 11 with an Intel network adapter, using FortiClient version 7.0.14 managed by FortiEMS 7.0.13.The issue is as follows:SSL VPN connection works perfectly without any problems. However, when attempting to connect to an IPSec VPN, the connection fails with the error message: “IKE negotiation failed” / VPN connection failure.Interestingly, when I use the FortiClient free (standalone) version and import the same IPSec configuration file, the connection works successfully on both Wi-Fi and LAN.Other colleagues using the same EMS-managed FortiClient version are able to connect without any issues.Based on my initial observation, I suspected it might be related to the network adapter; however, this seems unlikely since the IPSec connection works correctly when using the free version of FortiClient.I would appreciate any insights or suggestions
I login to this portal (Fortinet Community) and the vertification code sent to the email. How i can change the vertification code from email to authenticator app?
We are working on replacing Aruba switches with FortiSwitches. We have HA firewalls and currently use a VLAN on the Aruba to pass the ISP link to the WAN ports on the firewalls. We've run into an issue at a couple of sites where the ISP device refuses to communicate with the FortiGate when passing through an unnumbered VLAN configured on the FortiLink connection. If we put the Aruba back in, the WAN links can then talk to the ISP gateway again. It's only happened at a couple of our sites, so I suspect it's specific to certain brand ISP devices. At the first site it happened at, we resolved it by moving the WAN IP to the VLAN Interface under Fortilink and eliminated the uplinks to the WAN ports. At the current site we're working on, there are hundreds of IPSec tunnels and policies tied to the WAN interfaces, so moving to a VLAN interface under FortiLink would be a time-consuming endeavor. Any idea on what may be causing this?
Hi Community I need to understand how to bypass microsoft.com from the SASE SWG proxy configuration. Thank you UdaM
the two FG in the cluster give the same role (primary) and same hostname, although the setting of HA is corectlysystem > HA, i see two serials, synced, mode is active passive, and priority is different
Hi,Recently we upgraded our FGT 200F from 7.4.7->7.6.4->7.6.6. In the new version we noticed that we lost Packets(sent/Received) and Errors(sent/received) FILTER options in FortiGate firmware version 7.6.6? we had this filter option in previous version 7.4.7.Can someone help/clarify why this happened, which we don't have any more this option and how we can add this feature back? I checked the known issue for 7.6.6 and changes in default behavior. Please find the attached photo which indicate that Packets(sent/Received) and Errors(sent/received) FILTER option disappeared.Thanks in advance!
Hello everyone,I would like to get some feedback from the community regarding a design decision between using a Hardware Switch interface or an LACP Aggregate interface in a FortiGate HA deployment.ScenarioI have two Active-Passive FortiGate HA clusters interconnected directly, similar to the topology below:The objective is to maintain connectivity during a failover event on either cluster while keeping the design as simple and stable as possible.Current DesignWe are currently using a Hardware Switch interface across the participating ports. The solution has been operating correctly and failover testing has been successful.QuestionFrom a Fortinet best-practice perspective: Would you prefer Hardware Switch or LACP for this topology? If LACP is preferred, would you configure lacp-ha-secondary disable on both clusters? Have you experienced any MAC flapping, convergence, or failover issues when using LACP directly between HA clusters? One of the reasons I am evaluating both options is
Hello fellow networking folks,I'm curious if anyone has had to pivot from FortiClient with the new Remote Access VPN setup on 7.6.x since they are basically forcing everyone to purchase EMS. Unfortunately we have to ask for $$ from the higher ups so I wonder if anyone has used / knows of a good alternative. I know that there is a free version but it seems that it is in the process of being grandfather'd out
I've been tossing around the idea of doing a series of posts, maybe bi-weekly or monthly, highlighting a Fortinet product that isn't as well known... before I start putting in a bunch of work on this, is there an appetite for it? It would probably be pretty high level, but I run into situations all the time talking to customers about projects/concerns and mention a product in the FortiVerse they didn't know existed.
Hello Wi-Fi adminsThis tech tip explains how to allow a VPN user change his LDAP password when it expires.I tried do the same for my Wi-Fi (managed FortiAP), same described config on FGT and FAC, but when user with expired password tries to connect it just fails to connect, and FAC shows the following message.Windows AD user authentication from (null) (mschap) with no token failed: user password change requiredThe user password must be changed before logging on the first time. (0xc0000224)Any idea what I might have missed?
Hi,I've been setting up alot of Forticlient with SSL-VPN but now when it's depricated I've need to set it up with IPSEC.When doing the SSL-VPN option we had the possibility to map different usergroups to different IP subnets with the "SSL-VPN Portals".Is there a way of doing this with IPSEC VPN?What I want to accomplish is to have Forticlient users connected to a central FG and that FG works as the HUB in a HUB n SPOKE topology.At the spokes be able to assign different firewall policys based on source IP subnet.
Hello,I am reviewing the FortiOS 7.6 administration guide regarding inspection modes (pages 233–234), and I need clarification on the following point:The documentation states that proxy-based mode provides more feature configuration options and is security-focused, while flow-based mode is designed to optimize performance.However, it also mentions that flow-based mode can consume more CPU cycles than proxy-based mode in some cases, which appears contradictory: page 233 ..... While both modes offer significant security, proxy-based mode provides more feature configuration options,while flow-based mode is designed to optimize performance .....If security is your priority, proxy-based inspection mode—with client comforting disabled—is more appropriate.If performance is your top priority, then flow-based inspection mode is more appropriate..........page 234 ...... Because the file is transmitted at the same time, flow-based mode consumes more CPU cycles than proxy-based mode. However, depe
Hello, I am reading the FortiOS admin guide and I saw that the antivirus checking order is:Antivirus local database → EMS threat feed → external malware blocklist → FortiGuard outbreak prevention databaseBut I have a few questions.1. What about the other inspection engines?Where do the following fit in the inspection flow?Content Disarm and Reconstruction (CDR) Behavior-based detection CIFS/SMB scanning AI/ML detectionMy question is:👉 If a file is NOT detected by:signature-based AV database EMS threat feed external malware blocklist outbreak prevention / hash reputationthen will FortiGate check the engines above afterwards?Or do these engines run in parallel / separate pipelines?What is the actual processing order?2. Signature-based detection clarificationThe guide says:“Antivirus scan detects viruses that are an exact match for a signature in the antivirus database.”So I want to confirm:Does “signature” here mean a hash value (exact file match)? Or is it a pattern-based rule (byte se
I just installed FortiClient VPN only.But when I press the three-line menu, I only see the interactive option "View the selected connection," so I'm blocked from manually adding or editing connections.I've tried uninstalling and reinstalling it, using administrator privileges, and even deleting any trace of a previous version that might exist for some reason.It still doesn't work.I would appreciate your help.
Hi everyone,We are troubleshooting a FortiGate-6000F running FortiOS 7.6.6 build3652 GA.Two FPC blades, slot 2 and slot 3, are stuck in Dead state with:Status Message: "Waiting for configuration sync."Heartbeat Data: FailedThe other FPCs are working normally.Current load-balance statusFortiGate-6000F (global) # diagnose load-balance status==========================================================================MBD SN: F6KF30T018900031 Primary FPC Blade: slot-1 Slot 1: FPC6KFT018900628 Status:Working Function:Active Link: Base: Up Fabric: Up Heartbeat: Management: Good Data: Good Status Message:"Running" Slot 2: Status:Dead Function:Active Link: Base: Up Fabric: Up Heartbeat: Management: Good Data: Failed Status Message:"Waiting for configuration sync." Slot 3: Status:Dead Function:Active Link: Base: Up Fabric: Up Heartbeat: Management: Good Data
Hello all, I am looking for some assistance regarding using AD groups in EMS policies. My scenario is as follows: I have created a security group for people allowed to use dropbox and configured the web filter and application filter appropriately. I have also created a security group to be allowed to use certain AI applications only and configured the filters appropriately. Based on what I have read is where I am hitting an issue: “Priority-Based Evaluation: EMS typically allows administrators to assign priority levels to different policies. If a user belongs to multiple groups (e.g., both "Standard Staff" and "Remote Workers"), EMS applies the configuration set by the policy with the highest priority.”If reading this correctly, if I am a member of both security groups, I will use the first policy I match with highest priority. So if I put the “allow dropbox” rule first that also blocks the AI Apps, I will not hit the “allow AI apps profile” that follows. Is there a way to control this
Hello,I have been trying to get into the FortiEDR Workflow, but I can’t seem to create or manage the Collector Groups in the FortiEDR Cloud with a FortiEndpoint license. I know that FortiEndpoint EDR is different from the normal FortiEDR, but I have not found a document which said you can’t manage Collector Groups with FortiEndpoint EDR. Even the Administrator Guide for FortiEndpoint does not mention that you can’t configure Collector Groups.
I work for a school that is requesting us to block the Fornite game from being played. However it appears using the Web Filter and reclassifying the Epicgames.com URL only solves users from browsing to that website. I am trying to block the Fortnite game from connecting to the EpicGames servers, It appears they use Amazon Web services which seems to be tricky when blocking applications. I do see that Fortinet has Epic.Games listed as an Application finally. I have blocked this under application control, now half of the students that try to play cant and the other half still can. I'm new to this stuff so this has been a fun experience. Any one have any luck blocking this? If so what did you do to achieve this?
Hi All, I have issue with F50G automatically upgrade to the latest patch 7.4.11 to 7.4.12 while the contract is expired.It keep sending Email with message “This installation is forced and cannot be cancelled”. It has failed to install multiple times and keeps rescheduling. I checked the system events, which show that the download failed. Do you have any ideas on how to fix this?I tried with this guide , and no lucks.https://docs.fortinet.com/document/fortigate/7.4.11/administration-guide/320693/required-firmware-upgrades-for-fortigate-appliances-with-invalid-support-contracts-or-that-have-reached-eoesDiagnose log:[989] fds_load_upg_matrix_map_img_id: Same major.minor: Patch 11 leads to Patch 12[999] fds_load_upg_matrix_map_img_id: Auto-upg chooses patch 7.4.12 (b2902)[1002] fds_load_upg_matrix_map_img_id: This upgrade will not be forced upgrade[989] fds_load_upg_matrix_map_img_id: Same major.minor: Patch 10 leads to Patch 12[1013] fds_load_upg_matrix_map_img_id: Auto-upgrade has chosen
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.