Mark a Best Answer
Fortinet Community
Recently active
Hello Fortinet Support, We are facing an issue where EMS logs are not being ingested into Forti Analyzer. At present, only FortiClient logs are visible, but EMS server activity/logs are not showing up.Details:Product: Forti Analyzer & FortiClient EMSIssue: EMS logs not ingesting/forwarding to Forti AnalyzerObserved: Only FortiClient logs are displayedExpected: Both FortiClient and EMS logs should be ingested for full visibilityRequest:Could you please assist us in troubleshooting and resolving this? If any specific configuration or version requirements are needed for EMS log forwarding, kindly provide guidance.
Hello,I am trying to test if I can configure endpoint users to connect to a certain PoP in FortiSASE instead of the one nearest to their location. This is needed as some of our users have clients that enforce GeoIP filtering. An example is we need some of our users in the APAC need to connect to our US PoPs as their client only allow US and Canada IPs in their system.Pleas help.Thank you!
Hi everyoneWe are trying to block users from bypassing our web filter using Cloudflare WARP (1.1.1.1).We do not have Active Directory (AD) or GPO controls. Users are running WARP as portable apps directly from USBs (or people who’s already downloaded it before we noticed) so endpoint/execution-level blocking is out of the question.Our network architecture is constrained: a WatchGuard firewall NATs all LAN traffic into a single IP address before passing it to our core FortiGate.The problem we blocked the standard Cloudflare CDN IP lists, but already-registered/installed WARP clients bypass App Control by falling back to TCP/UDP 443.What are the exact destination IP ranges and custom ports used strictly by the WARP client/WireGuard/MASQUE tunnels (and not standard Cloudflare CDN web traffic) that we can deny on both firewalls?Any advice on blocking this connection fallback without breaking standard web traffic to sites hosted on Cloudflare? Thanks!
Hello everyone, We have been trying for weeks to establish a stable connection between two data centres. Our router is the Sophos Appliance and the remote site uses the Fortinet cluster. The connection is established successfully. Ping works, but then timeouts occur, meaning ping is no longer possible – for 2 minutes, then it works again for 30–40 minutes, then a timeout for approx. 10 minutes, then it works again for 30–40 minutes, then a timeout for approx. 20 minutes, and so on. We have established that Phase 2 seems to be causing the problem here during ‘re-keying’. We have already tried all possible settings here. Without success. Does anyone here have any idea what the problem might be, or has anyone perhaps encountered a similar scenario before? I would be grateful for any assistance. Peter
Hello Team,I am facing an issue with the Fortinet FortiGate 30G firewall during the firmware upgrade process.Error Message:"Image upgrade failed. This firmware image didn't pass the signature verification."
In an HA setup using FortiGate 200F, if the primary firewall is connected from the LAN port to the server, should the secondary firewall also be connected the same way?
Hi all, I am using Forticlient EMS cloud with Fortigate to achieve ZTNA. We have some endpoints tag changed for some reason, and we wanna know the reason to resolve the issue. But seems the Fortinet log only told that tag was assigned/unaissgned to a EMS client. How could I know the details rather then “guess how” or “open ticket tac” ?
Many internal systems are querying public DNS servers, but it’ll probably take a year before we can address off of these. Consequently, we are investigating if it’s possible to NAT all outbound queries to a pool of 4 different public DNS servers and use something like the health check monitor to ensure the servers are up. I see how to do this for a single public DNS, but I don’t see how to get all the way through the configuration. We’re using central NAT. Thank you.
Hi, i have installed FortiClient 7.4.3.4726, and configure vpn to connect in customer vpn, but the connection don’t works, i have bellow error:[2026-05-27 12:01:21.6932022 UTC-03:00] [12040:11004] [FortiVPN 2041 error] fortivpn::StateMachine::HandleTunnelConnectFailed session 1's (.\josan) vpn connection failed (reason: "Failed Unknown")[2026-05-27 12:01:21.6958494 UTC-03:00] [12040:11004] [FortiVPN 2370 info] fortivpn::StateMachine::HandleTunnelDisconnected "Agrex do Brasil LTDA" is disconnected.[2026-05-27 12:01:21.6968655 UTC-03:00] [12040:11004] [FortiVPN 2406 info] fortivpn::StateMachine::HandleTunnelDisconnected disconnection reason: 13, ("Failed Unknown")[2026-05-27 12:01:21.6968739 UTC-03:00] [12040:11004] [FortiVPN 2432 error] !!! fortivpn::StateMachine::HandleTunnelDisconnected session 1 (.\josan) "Agrex do Brasil LTDA" disconnected unexpectedly![2026-05-27 12:01:21.6973074 UTC-03:00] [12040:11004] [FortiVPN 2446 info] fortivpn::StateMachine::HandleTunnelDis
Hello everyone,I am working on a FortiAuthenticator 8.0.3 deployment and I need to apply a usage limit to AD users authenticated through FortiAuthenticator.The goal is simple: after the user logs in to the captive portal using their Active Directory credentials, they should be allowed to use the network for only 1 hour.I found this old Fortinet KB article from 2019:https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-RADIUS/ta-p/198682In the article, there is a note saying that Usage Profiles can only be applied to local users and, starting from version 6.5, to manually imported LDAP users.My question is:Does this limitation still apply in FortiAuthenticator 8.0.3?Or is it now possible to apply a Usage Profile directly to a Remote LDAP group, LDAP directory group, or LDAP filter, without manually importing each LDAP user into FortiAuthenticator?In the current FortiAuthenticator documentation, the Usage Profile option appears available under
HelloI have issue with registring trial license in my FortiGate VM in Hyper-V. I’m registred product and download lic license from portal but when I import license, VM don’t recognize license.Version in my Hyper-V is FortiGate-VM64-HV v8.0.0,build0167,260420 (GA.F).Can you help me to install license successfully?Best regards,Marin Mihajlovic
Environment: FortiGate VM v7.6 Lab environment, no actual WAN connectivityBackground: I have configured static routes using Internet Service (ISDB). FortiGate internally treats these as policy-based routes. I also have a link-monitor configured with update-static-route enable, update-policy-route enable, and update-cascade-interface enable.Expected behavior: When the link-monitor detects a failure, I expected the ISDB-based static route to appear as flags=0x8 disable in the output of diagnose firewall proute list, which is the same behavior described in the official documentation for standard policy-based routes.Actual behavior: When I simulate a link-monitor failure, manually configured policy routes (config router policy) correctly show flags=0x8 disable as expected. However, the ISDB-based static route continues to show flags=0x0 with no change.Output of diagnose firewall proute list after link-monitor failure:id=2113929218(0x7e000002) static_route=2 dscp_tag=0xfc 0xfc flags=0x0 tos
Hi,I am looking at using a small FortiGate setup on Azure for lab practice. I have found this to be relatively simple and looks like I can use the PAYG model to simply create a VM and use it.What I am struggling with is FortiManager, all the guides indicate a BYOL licence is needed, but during the setup it gives the option for FortiFlex which looks to be the right idea but I have no idea if I can buy a small number of points anywhere or do PAYG… Also this marketplace item exists and I am not sure if this is what I should be using as a way to pay all through Azure? Fortinet FortiFlex Usage-based Licensing - Microsoft AzureI can see this has a purchase option which then gives an option of 1,2,3 years but also it gives the create option which does create a VM?
Hello,While configuring Administrator Profile Mappings on FortiNAC, I accidentally associated all administrator profiles, including local administrator accounts, with a limited “Device Manager” type profile group. Since this change, I no longer have Full Admin privileges.I only created a profile mapping, is there a way to delete this Administrator Profile Mapping from the CLI?I found the following CLI command that allows restoring a previous configuration backup:execute restore config local <backup_name>If I restore a backup taken before this misconfiguration, will it restore the previous administrator mappings and resolve the issue? best regards.
Is TPlink wireless controller (Omoda) can be managed by FNAC?
Hi everyone,I need to upgrade a FortiGate-VM64 currently running FortiOS 7.0.19.Relevant output from get system status:Version: FortiGate-VM64 v7.0.19, build0696, 260129 (GA.M)License Status: ValidVM Resources: 2 CPU / 2 allowed, about 4 GB RAMCurrent HA mode: standaloneRelease Version Information: GAFortiOS x86-64: YesI also checked the active firmware image with diagnose sys flash list:Partition Image Active1 FGVM64-7.00-FW-build0696-260129 YesMy doubt is about the Fortinet Upgrade Path Tool.In the product list I see several similar VM options, such as:FortiGate-VMFortiGate-VM-KVMFortiGate-VM-HVFortiGate-VM-AWSFortiGate-VM-AZUREFortiOS-VMFortiOS-VM-HVFortiOS-VM-KVMFor this firewall, should I simply select FortiGate-VM in the Upgrade Path Tool?Also, for a manual upgrade, should the correct firmware image be from the FGT_VM64 family, for example:FGT_VM64-vX.X.X-buildXXXX-FORTINET.outThis one to be precise in this case:FGT_VM64-v7.2.13.M
I’m kind of at a loss as to how to make this work. I’m configuring a new FortiGate 90G, and what I’d like to do is connect a cable to an access port on my existing Dell network to a WAN port on the firewall, so it can get a DHCP IP, so I can register it. The problem is that I can’t get layer 1 to work at all. No link lights. I plug a PC into the same cable; it gets an IP just fine. The cable works. The Dell switch works. The FortiGate is brand new out of the box. I had the exact same issue when I was configuring my new 120G firewalls as well. Here’s something weird. I can connect a dumb unmanaged 5 port switch in between the Dell and the FortiGate, and everything connects and works perfectly fine. The firewall gets an IP perfectly fine. I disconnect the unmanaged switch, and go straight from the Dell to the FortiGate, and I get nothing. I’ve been on this for weeks, with no resolution, or even understanding, as to why this is happening. I’ve also tried putting a FortiSwitch inline betwe
We use captive portal for contractor and they should enter the entra id to connect to the network.We have some entra id group, example contractor_IT and contractor_SALES and each group have their own vlan.When the contractor authenticated successfully then the contractor still sit in isolation vlan and not changed to the respective vlan. My fnac vendor say when user authenticated thru entra id captive portal then fnac cannot bring entra group ID, is that true
I have guest ssid on the cisco wlc9800 and if there are user want connect to this ssid then the user will authenticate by captive portal with entra id.After the authentication successfull the client should be move from isolation network to guest network, in my case the client was moved to guest network if i see from fortinac policy but the client itself still connect to isolation network.Already ask to cisco support then they said the cisco not receive the coa to change the vlan. Anyone know here how to change thje vlan to teh cisco wlc9800?
Hi ,I would like to ask for some clarification regarding Flow-Based Antivirus behavior and architecture on FortiGate.I reviewed the Administration Guide and several technical documents, but I could not find detailed explanations for some internal Flow AV processing behaviors.I would highly appreciate it if you could clarify the following points or provide any related technical documentation, KB articles, technical tips, or architecture references.In Flow-Based Antivirus mode, is there still a file size limit / oversize handling mechanism similar to Proxy-Based AV, or is the oversize behavior only applicable to Proxy mode? In Flow mode, when scanning large files, does FortiGate bypass scanning after reaching a specific internal threshold, or can it continue scanning regardless of file size? Does Flow-Based Antivirus use the same Antivirus databases (Normal / Extended / Extreme) as Proxy-Based AV, or does Flow mode use a different AV engine/database architecture? If Flow mode does not fu
Hi everyone, do you know if it's possible to downgrade FortiClient from 7.4.5 to 7.2.10 directly from ForticlientEMS v7.4.5?Unfortunately, a colleague of mine accidentally pushed the 7.4.5 update and now we lost compatibility with all our ikev1 vpn.Thanks
Why oh why does Fortinet make all this so difficult, it seems like they actually don't want people to even use the trials… I finally have a FortiGate trial VM and a FortiManager trial VM, but can I get them talking? No! Lots of commands that are no longer valid etc... FortiManager reports a probe fail, from online searches, I have tried lowering the encryption settings and allowing VM registration on the FortiManager. I have tried registering from the FortiGate side also.Now it transpires that my FortiGate trial VM does not have the right factory cert because it is does not contain the serial of the virtual appliance, just a generic "Fortinet". I have tried regenerating the certs, tried re-execting the VM commands but it does not accept them either… To be honest it feels like a battle just to make the trials work, which is hardly a good starting point.
Fabric contains a FortiGate cluster and managed FortiSwitches for internal and external purpose. Is there any solution to shut down all the devices from the downstream connected device such as a desktop. As per my understanding, the challenge is the FortiGate is the brain here. so I am facing a chicken and egg problem. Please let us know if there is a good solution for this. Thank you
After a change in the provider of wan2, I try to login to the fortigate direct with the ip adres of it.I get the login page with user and password after that i get the token login screen. (wan 1 adres)But then nothing autersation error that is all.But i log in as always eff was logt in this morning but now…...nothingI really do not want to reset.If anybody got a id plz.BTW login with forticoud is also not working now
Hello Fortinet team and community,I am looking to install FortiClient VPN version 7.0.12.0572. Could you please help me with the official download link for this release? Since this is a free VPN-only version, I would appreciate guidance on where I can access it directly from Fortinet’s site or repository.Thank you in advance for your support.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.