Mark a Best Answer
Fortinet Community
Recently active
Hello,I would like to know whether it is possible to activate service contracts for two FortiGate 121G devices in the same HA cluster using different licensing methods.One device already has an active traditional UTP contract, while the other device's contract has expired. I would like to activate a UTP bundle for the second unit using FortiFlex tokens.Is this configuration supported?Thank you.Farshid
Hi everyone,We are experiencing an issue with FortiClient VPN (free version) and wanted to check if anyone else has encountered something similar.Here is the situation:We have two computers in the same domain, on the same network, using the same internet connection. The same security and domain policies apply to both machines. They are connecting to the same IPsec VPN tunnel using the same user account.One machine connects without any issues, while the other consistently gets stuck on “Connecting” and eventually the application has to be killed from the process.We have tested multiple versions of FortiClient (7.4.0, 7.4.2 and 7.4.3), but the behavior remains the same.We also contacted Fortinet support, and they confirmed that the issue is most likely related to the FortiClient application itself. However, since we are using the free version, they are not able to escalate the case further.Additional note: the same issue occurs with different user accounts and from different networks (tr
Hi, The security auditor came to our office to check the Firewall Policies. The guy suggests to configure the Firewall Access Rule to "DROP" the unwanted traffic instead of "DENY". When setup Firewall Access Rule, I can select "ACCEPT" or "DENY" only. Is it possible to configure the Fortinet Firewall do "DROP" instead of "DENY" ? Regards,
Hi All,Long back I was using fortigate 600C firewall. Now i want to login that device. but i have no password.So, for resetting the configuration it require TFTP along with suitable firmware. based on boot-louder.But while re-loading the firewall, could not see Boot-room version, Only i can see below. HOSTNAME login: FortiGate-600C (15:49-10.24.2012)Ver:04000010Serial number:FG600CXXXXXXX. Please anyone can help for resting the configuration and is there any better way for the same.
How to apply the Replacement Message in Security Profile in your Policy when accessing the blocked websites?
Is there a method to update a batch of FortiWiFis using a TFTP server?I know i can use a TFTP server to recover bricked FortiWiFis, but is there a method or tool that does the same but for a batch of FortiWiFis?In my case I want to update as many as possible and then put them aside as stock for future device deployments. And so I think adding them to FortiManager is. not ideal. Basically I intend to downgrade from 7.0 as that is what they now come out of the box to 6.4.14.
Hello,I’ve trying for a long time this kind of upgrade.GUI doesn’t upgrade, and i tried using CLI i got this error.After updating the linux package i got this another one.I’ve seen this Bulletin → CSB-260410-1In my case, i installed this EMS as VM not using Linux, so i can’t make any changes in the Linux shell as it says.Could anyone help me?thank you
IntroductionAre you alerted when or if a rogue AP broadcasts your companies SSID? Are you alerted when or if large volumes of de-authentication packets are sent to your wireless clients? These are some questions I've been asking recently as I've researched WIDS and how Fortinet can help. This isn't really a support request for the forum; it's more of an information sharing post for those interested. Generally, most wireless deployments I see using Wireless Intrusion Detection Systems (WIDS) or Wireless intrusion Prevention System (WIPS) are using default vendor setting rather than fine tuning the settings to suite your business needs or align with your company cyber security policies. In some cases, WIDS may be disabled all together due to concern of resource usage on the AP hardware itself or limiting the available radios of the AP by using radios as dedicated monitors. Most of what can be found via a quick google search regarding wireless security is more centered around u
On FortiAnalyzer, the devices added under Device Manager show "Last Log Time: N/A". However, when checking the dashboard, logs appear to be arriving normally. At the same time, the Log Viewer cannot be opened, and the Reporting section is also inaccessible.The currently used version is 7.4.2, and it seems that there are known issues related to this behavior in this release. Could you please confirm whether this is a known bug and advise on any available workaround or recommended upgrade path?
Hi,after installing the FortiClientVPNSetup_7.4.3.4726_x64.msi with option “Enable Local Lan” and after established ipsec connection the client loose connectivity to local installed HP Network printer with address 192.168.8.105 (pings are not working, and all prints stay in the queue).After disconnect from the tunnel printer is working ok.I see on print route something like this: Config of the tunnel:
Target Audience: Linux System Administrators, DevOps Engineers, Virtualization SpecialistsEnvironment: Proxmox VE 8.4.2, Ubuntu 22.04 LTS (Workstation), FortiVoice 7.2.3 for KVM deployment package Introduction While Fortinet provides comprehensive documentation for deploying FortiVoice on vanilla KVM (FortiVoice Private Cloud KVM Deployment Guide), translating these instructions to Proxmox VE (PVE) requires careful adaptation. A direct translation of KVM settings results in a critical failure where the appliance enters a reboot loop immediately after decompressing the root filesystem. This article details the troubleshooting methodology used to identify the root cause—a combination of entropy starvation and disk bus mismatches—and provides the configuration required to stabilize the deployment. The Symptom When deploying the FortiVoice 7.2.3build0507 qcow2 images on Proxmox 8.4.2 using default settings, the VM fails to boot. The console displays a kernel pan
Hello Guys,i’m moving from a Fortigate 500E to a 400F and need to copy all the configuration through Fortimanger (version 7.4.10).The customer is using the Vpn Manager tool on Fortimanger to manage all the Vpn, where i’m stuck, is that i can’t understand where i can add the new firewall to setup the vpn.I’m only able to edit the existing tabs but not able to insert the new firewall, how can i do it?I’d like to do something like for the policy package, insert the new firewall in the installation target and fortimanger will install everything smoothly.For now i’ve imported all the vpns configuration manually via cli, but would like to allign the vpn manager…..Any tips? Thank youRegards
Hello everyone, I would like to know if there is an available read only demo for FortiSASE, i would like to see whats on the interface, the available functionnalities etc. BR,
Hello everyone, Fortinet used to provide demos of Fortinet solutions in read-only mode. You would simply submit your information and receive the access credentials by email. However, for the past couple of months, I’ve no longer been able to do so.I always receive the automated email saying :“We've received your request for a product demo! A Fortinet sales rep will contact you soon to confirm your demo and find a time that fits your schedule.”But after that, I never get any follow-up or credentials.Could someone from the staff please confirm whether the read-only demos have been discontinued?Thanks in advance.BR,
Configs "RealVNC" or "fmwp" have been added without noticing. Such as..“RealVNC-Other”, “RealVNC-Web”, “RealVNC-ICMP”, and so on.“config rule fmwp FortiOS.SSL-VPN.Enc.Buffer.Overflow”, “config rule fmwp FortiOS.SSL.VPN.Custom.Information.Disclosure”. Why did this happen?
Hello, My Firmware is 7.4.11 I managed to get SSO authentication working correctly via EntraID. The last thing I wanted to do was connect it to the FQDN and run it via my own SSL certificate. I have the certificate imported and it works correctly on the Fortigate login page. I can't get this certificate to work on the authentication port. The default certificate is still visible.FortiGate-60F # get vpn certificate local== [ Fortinet_Factory ]name: Fortinet_Factory == [ Fortinet_Factory_Backup ]name: Fortinet_Factory_Backup == [ Fortinet_CA_SSL ]name: Fortinet_CA_SSL == [ Fortinet_CA_Untrusted ]name: Fortinet_CA_Untrusted == [ Fortinet_SSL ]name: Fortinet_SSL == [ Fortinet_GUI_Server ]name: Fortinet_GUI_Server == [ Fortinet_SSL_RSA1024 ]name: Fortinet_SSL_RSA1024 == [ Fortinet_SSL_RSA2048 ]name: Fortinet_SSL_RSA2048 == [ Fortinet_SSL_RSA4096 ]name: Fortinet_SSL_RSA4096 == [ Fortinet_SSL_DSA1024 ]name: Fortinet_SSL_DSA1024 == [ Fortinet_SSL_DSA2048 ]name: Fortinet_SS
I create intune policy to push 802.1x wired configuration but after more than one week the policy not pushed any devices. Anyinw know why?
Hello Fortinet Community,I would like to understand more about MFA implementation on FortiGate.When a customer purchases a FortiGate and the corresponding licenses, is any additional license required to enable MFA, or is MFA functionality already included?I would also appreciate clarification on the following points:What are the most common use cases for MFA in FortiGate environments? Is Active Directory integration required, or can MFA be deployed with local users as well? What authentication methods are typically used (FortiToken Mobile, email, third-party MFA, etc.)? Are there any limitations or best practices to consider when planning an MFA deployment?I am interested in hearing from community members who have already implemented MFA in production environments and can share their experience and recommendations.Thank you in advance for your insights.
I'm using a FortiGate device, but I can't make calls to others via Zalo. I can still send messages, upload files, and others can call me via Zalo. I've checked the logs and debugged, and everything seems to be allowed; there are no logs of rejected or blocked calls.The behavior: When I try to call someone, the call disconnects immediately.Can you give me some advice on this issue?
I have a Fortinet 101F firewall setup with VPN IPsec running. I have a FortiVoice 101, and I want to setup Fortiphone Softphone through the VPN. The Fortiphone Softphone runs fine with the LAN network, but when I try logging in through the VPN. I need some guidance to get it implemented please.
I am working on establishing vpn from android device using forticlient app with no avail. However, everything works fine with windows 11 machine. Forticlient app version : 7.4.3VPN type : IKEV2 (EAP-MSCHAPv2 with Certificate as authmethod) Android Device: Honor MagicOS 8 (Android version 14) From the forticlient android, the error immediately shows "IKE authentication failed" where in fortigate debug last log says sent IKE msg (AUTH_RESPONSE). Appreciated any help on this, thanks
Hello everyone,I'm deploying 2 VPN configs in EMS to a group of devices, users have no control over Forticlient, I want to force connection to both VPNs automatically once connected to the network.It seems that only one VPN can connect automatically, while the user has to click on connect for the second VPN to come UP. Already enabled Multi VPN Auto connect option in Forticlient EMS but it has no effect (both VPNs are IKE v2)We are using Forticlient EMS 7.4.5 Any idea ?
Hi All,Has anyone noticed issues with IPSec site to site tunnels on 7.4.9?We have one vendor who has been working fine before we upgraded a couple weeks back to version 7.4.9 in our Azure FG. Oddly enough our one firewall in HQ location which still is on 7.2.12 works fine.When comparing the 2 tunnels from Azure FG and HQ FG doing pings to the vendor I noticed the HQ doesn't lose pings at all. Whereas the one in Azure will intermittently lose the pings and then come back on its own.VPN settings for both FGs are the same along with vendor side.Has anyone run into this so far? Any workarounds?Happy Holidays All!
good morning everyone, i have a fortinet 60F. unfortunately, a junior member did the upgrade from 6.4 to 7.15. when i try to log in console to fix it, i get this:▒▒▒▒▒▒▒▒ђ▒▒▒▒ѥ▒▒▒ɩ▒͕▒ѥ▒▒▒ɩ▒▒▒ѥ▒ѕ▒▒▒▒Ҫ▒▒▒▒▒▒▒▒▒▒▒ɂ▒▒▒▒▒▒▒▒▒ɥ▒▒յ▒▒▒ԕ▒▒ʥ▒▒▒▒▒▒х▒(▒ѥ▒▒▒饹▒▒▒ѕ٥▒▒▒▒a▒ѥ▒▒▒饹▒s▒L▒᱕▒͕▒▒▒▒▒ɢ▒▒▒▒ɂɕ▒▒墽▒▒▒▒▒˙▒▒▒Ʌѥ▒▒▒▒▒▒▒▒▒▒▒▒ѥ▒▒▒ɩ▒ʥѥ▒▒▒饹▒▒ɕ݅▒▒▒ɩ▒failed verification on /data/datafs.tar.gzfos_ima: System Integrity check failed....CPU5: stoppingCPU6: stoppingCPU1: stoppingCPU3: stoppingCPU7: stoppingCPU0: stoppingCPU2: stopping sadly, it keeps repeating this message and it doesnt let me type commands. any advice? i tried changing the speed and flow control of my console cable with no better result than this one. my current best settings are:speed 9600 - 8n1, no flow controls
Hi,according to this article: webpages blocked by DNS-Profile should be redirected to FortiGate DNS block IP 208.91.112.55 and display a warning like this:However in my config when I enter to category blocked on the DNS-Profile like “Games” then I have red certificate warning, the certificate isissued by Fortiguard SDNS Blocked Page:every clients PC have imported Fortigate_CA_SSL certificate in Trusted Root Certification Authorities store.How to restore this blocked page when webpage is blocked by DNS-profile?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.