Mark a Best Answer
Fortinet Community
Recently active
Setting up an IPSec VPN Tunnel between a Fortigate 90g and another device. On the Fortigate, I setup the tunnel, settings are good.Setup the firewall policies, I see the created network names (local_subnet_1 and remote_subnet_2) that the Fortigate creates.When I go to Static Routes, I cannot select, nor can I even see, the remote_subnet_2 as a selection when I set Destination to Named Address.I CAN see names of other remote networks named with the creation of previous tunnels. Previous tunnels setup, uses the named network, without issue. Does the Fortigate create the name automatically? and If so, why isn’t this one showing up in the list? I can manually add the subnet, but for consistency in setup with the other tunnels on the device (2), I’d like to use the same method.
Hi,Looking for a guide to deploy Forticlient VPN with Intune for MacOS,Did anyone succeed? I haven't found an official guide for this
Not working FortiClient 7.4.6.0218 android 17 with fortios 7.6.7 =( When update in google play store? PC/Mac works good
Hi, I’m trying to register a fortigate cluster (A-P) with a SKU HA license in an air-gapped environment but facing this issue.Environment FortiManager-VM: v8.0.0 Firewalls: FortiGate 101F in HA Active-Passive cluster Licensing: HA Cluster SKU (generates a virtual serial number: FGT101FHAxxxxxx) Deployment type: Air-gapped / Isolated network (FMG acting as a local FDS) Description & Steps FollowedI am attempting to register and license a FortiGate 101F HA cluster in a closed network using an HA cluster SKU via FortiManager. I have run into issues both during the offline workflow and when testing outbound connectivity.1. Asset Portal & Licensing Files Registered the HA cluster in FortiCloud Asset Management, obtaining the virtual serial number (FGT101FHAxxxxxx). No downloadable .lic file was provided for this SKU. TAC supplied an Entitlement Export file instead. 2. Offline Registration via FMG (Local FDS) Configured FortiManager to operate as a local FDS in a closed netwo
Hi AllI would like to know if there is a method to export FGT Policies into Excel (csv) format.Please advise any available options. Am using FortiOS v7.4.12 Many thanks
I was stuck on this for a while, so deciding to create a post and answering it for future Forti-newbies that experience the same issue.On the VM Images page, you have to look carefully at the FILE INFO and choose an image that starts with FGT, and NOT FFW.see image for clarity,
Hi everyone, I’m having an odd issue with Minecraft and FortiGate and wanted to see if anyone here has run into something similar. I read this thread https://community.fortinet.com/t5/Support-Forum/Unblock-certain-game/m-p/390777/highlight/true and it reminded me of what I’m dealing with, but the solutions there didn’t quite fit my situation. When I try to join certain Minecraft multiplayer servers (especially public ones), the connection either times out or I get disconnected after a few seconds. Singleplayer works fine, and some servers connect without any problem, which makes it confusing. I checked basic settings like allowed ports and application control, and nothing obvious is being blocked. I’m wondering if FortiGate might be identifying some Minecraft traffic incorrectly or if there’s a specific profile or setting that usually causes issues with game traffic. If anyone has experience running Minecraft behind FortiGate, I’d really appreciate hearing
Hi ALL, Do wish you DO NOT have this low level issue. Symptoms: Upgrade from FortiSASE 7.2.14 to 7.4.8 then use 7.4.8 FCT version will have error when try connect VPN (Refer attachment) while old 7.2.14 FCT version no issue. Culprit: Because default install PATH no under C: DriveWorkaround:Create a PATH (C:\Program Files\Fortinet\FortiClient) → Tested it work Rollback old FCT version Background Story:As Fortinet force customer upgrade to 7.4.8, we been force upgrade our FSASE 7.4.8 Tested few user on 7.4.8 on FCT client 7.4.8 which working fine so far Plan roll out batch bulk upgrade Notice partial user start to have issue (Error as in attachment) Contacted Fortinet support, FSASE engineer suspect connection issue FortiClient senior engineer come in and claim 7.4.8 had been roll out more than a month did not receive any complain Performed 3 hour of troubleshooting (DING DONG-ing) and related FCT senior engineer said also no clue Eventually one of my Backend developer used AI and found
Hi,I would like to understand whether FortiClientVPNInstaller 7.4.3.4726 requires version 7.4.3.8758 to be installed in order to fix vulnerabilities.I’m using ManageEngine Patch Manager, and it says that I need to upgrade to version 7.4.3.8758. However, I cannot find this version anywhere.
For those who are trying to get the VMware and setting up EVE-NG , the problems are real .I tried to deploy FortiOS v7.6.7 but the Putty on EVE-NG CE said no bootable image or device found , even though the file was there in the EVE-NG but the putty for the FortiGate couldn't find it.The Problem is the Version and EVE-NG CE itself , EVE-NG doesn't support version 7.6.x versions and beyond.it supports 7.4.x sothose who are trying to set up a lab on EVE-NG CE just get a older image. only that is supportable.
Greetings Forti Community, I use a web application that I reach on a IP address in my company network over IPsec VPN.It appears that the application sends a HTTP POST request to the server that can't get through the VPN tunnel, because the package is to big. After I change my client VPN network interface to MTU 1350, it can send the package and the access works. I change it with the following command:netsh interface ipv4 set subinterface "Ethernet 3" mtu=1350 store=persistent After that I've tried to set the MTU of the VPN IPsec Tunnel to 1350 and restart my client, I still couldn't access the web application. I've also tried different MTU values on the Firewall, but it didn't really change anything. Only if I do it on the client per command line.If I restart my client and start the FortiClient VPN, it seems that this resets my MTU on my client VPN network interface. So I'd have to execute the command to change my client MTU every time after I start the FortiClient. 
I have already defined a URL exclusion rule for URLs containing wildcards and selected the “exempt from action” option. However, access permission for these URLs is still not working.
Hi Fortinet Community,I’m facing an issue where all REST API requests to our FortiGate are returning HTTP 401 Unauthorized, even though the same integration is able to successfully communicate with our FortiAnalyzer.Environment FortiGate management/API endpoint: https://172.20.69.50 FortiAnalyzer endpoint: https://172.20.69.51 API client: Python using httpx HTTP method: GET API paths: /api/v2/monitor/*, /api/v2/cmdb/*, and /api/v2/log/* Observed behaviorEvery request to the FortiGate REST API returns:HTTP/1.1 401 UnauthorizedThis happens consistently across multiple unrelated endpoints, including:GET /api/v2/monitor/vpn/sslGET /api/v2/monitor/vpn/ipsecGET /api/v2/monitor/system/statusGET /api/v2/monitor/system/arpGET /api/v2/monitor/system/dhcpGET /api/v2/cmdb/system/interfaceGET /api/v2/cmdb/device/access-deviceGET /api/v2/cmdb/router/staticGET /api/v2/cmdb/firewall/addressGET /api/v2/cmdb/firewall/addrgrpGET /api/v2/cmdb/firewall/ippoolGET /api/v2/log/eventGET /api/v2/log/tra
I have 2 spoke, one using one internet connection and other spoke using two internet connection.When all internet connection is running then there a shortcut between spoke1 and spoke2 using internet1. When internet1 on spoke2 down then the spoke loss connectivity. Is there anyway to create shortcut between spoke1 (internet1) to spoke2 (internet2)?
Subject:[FortiOS 7.6.7] Policy GUI infinite loading and missing policies in By-Sequence viewDescription:We currently have a total of 514 firewall policies (Policy IDs 2 through 515). Due to a GUI bug causing an infinite loading loop, we switched the view to By Sequence and applied a filter to force-load the policies.Although the filter counter indicates that all 514 policies exist, the rendering goes through 4 separate loading passes, during which exactly 4 policies fail to render and are omitted from the display. In FortiOS 7.6.7, 4 out of 514 policies are rendered as duplicates on the GUI, causing 4 actual policies to remain hidden. Additionally, an infinite loading bug occurs during initial page load—similar to the Interface Pair View issue—which can only be temporarily bypassed by removing table columns.
Hi Fortigate Team,The branch currently has a single static ISP connection, while the HO has two independent static ISP connections. Internet traffic at both locations uses their respective local ISPs.We need to configure a redundant IPsec VPN between the branch and HO so that the branch can access internal subnets and servers at the HO through either ISP connection. SD-WAN should be configured at the HO to provide ISP failover and maintain VPN connectivity if the primary ISP fails.SD-WAN should also be configured at the branch. Currently, the branch has only one ISP, but a secondary ISP may be added in the future. The configuration should therefore support ISP failover at the branch when the second ISP becomes available.
Monthly Active User (MAU) Enforcement in FortiAuthenticator v8.0.4This article provides an overview of the Monthly Active User (MAU) licensing enforcement introduced in FortiAuthenticator v8.0.4, including the rationale behind the change, how MAU is calculated, enforcement behavior, exemptions, and monitoring options.BackgroundFortiAuthenticator is Fortinet's comprehensive Identity and Access Management (IAM) platform, providing a broad range of authentication and identity services, including: Fortinet Single Sign-On (FSSO) RADIUS and TACACS+ services Certificate Authority (CA) LDAP server SAML Single Sign-On (SSO) Multi-factor authentication (MFA) Remote authentication with Microsoft Active Directory and other identity providers Historically, FortiAuthenticator licensing has been based on the number of licensed users. However, some deployments have significantly exceeded their licensed user count by purchasing a small user license while authenticating a much larger number
Hi Team, Currently we are running FG-1500D in HA & we have purchased FG-1000F in HA.Using Forti Converter we are planning migrate config file from FG-1500D to FG-1000F, having below few queries:Will FortiConverter migrate all the configration like VDOM, IPSec Tunnel, HA, etc…. Source fortigate (FG-1500D) config file includes HA setting, while restoring config file to target fortigate (FG-1000F), can we restore the config into standalone fortigate? Any the steps we have to take into consideration while performing migration?
Unable to connect to FortiGuard servers.
Hi all,We're migrating a FortiGate-80F to FortiOS 8, and as part of this we need to move our remote VPN access from SSL-VPN to IPsec/IKEv2. Our affected fleet is 50 workstations running Linux/Ubuntu 22.04.The free FortiClient VPN edition on Linux doesn't support IPsec/IKEv2 (only the licensed FortiClient Standalone edition does, as far as we understand), so we're evaluating FortiClient Standalone.We're trying to figure out the licensing requirements for:- FortiClient on Ubuntu 22.04, establishing an IPsec/IKEv2 tunnel to a FortiGate 80F;- Authentication using the FortiGate's local user accounts (not a remote/cloud identity source);- 50 Linux users.A few open questions, in case anyone here has hands-on experience:1. Does FortiClient Standalone on Linux fully support IPsec/IKEv2 VPN tunnels to a FortiGate, and is this supported when using the FortiGate's own local user accounts for authentication (rather than a remote/cloud identity source)? 2. According to the FortiClient Standalone Use
Hello,I am facing an error code to a random number of windows hosts (approximately 30/400 windows 11 home & windows 11 pro devices).The mentioned devices has recently appeared in the state " Running (OS settings outdated" and the error code is "OS settings outdated". I have tried to reload & uninstall and re install the collector with no luck. The collector version is 5.2.6.0065.Any ideas will be helpful in order to further troubleshoot the issue.BR
Hello!I just recently downloaded the Hyper-V image for FortiGate-VM, version 8.The VM boots fine, no issues, the CLI is accessible through SSH.When comes time to apply the evaluation license, it seems to fail (using the “exec vm-license-options” command).On the Web GUI, the evaluation license seems to apply (by logging in with my Fortinet account) but after a reboot, it says “No License” in the system status.Then, in the Web GUI, I login, briefly see the “what’s new” video pop up and then it pops back to the login screen.Any ideas?Thanks!EDIT: I forgot to add that when running “exec vm-license” it requires a token, which I do not have.
This update covers four connector releases. Microsoft SharePoint is rebuilt on the Microsoft Graph API as a major version, Microsoft Graph Mail widens what it can do with mailboxes and calendars, and Fortinet FortiAuthenticator and Splunk each add a new capability. The table at the end links each release to its listing on the Content Hub, where you can review the full release notes.Fortinet FortiAuthenticator v1.1.0 adds an Execute an API Request action, with a corresponding playbook. Microsoft Graph Mail v2.0.0 adds an Email Address configuration parameter and extends the mailbox actions. Get Unread Emails and Search Emails now extract additional email headers, parse content from .eml and .msg attachments, and handle inline Base64 content so that it renders correctly in FortiSOAR. Send Email and Send Mail as Reply support inline images, and the data ingestion playbooks are simplified because the connector actions now handle EML and MSG extraction. New actions cover marking email as re
Hello Fortinet Community,I have an HA cluster with two FortiGate 1800F units FortiOS v7.6.7. The primary and secondary are communicating, but the HA status shows Not Synchronized because the wireless-controller.wtp-profile table is out of sync.I would like to understand why this specific WTP profile table is not synchronizing between the HA members and whether there is a way to resolve the synchronization issue without manually restoring or copying the entire primary configuration to the secondary.Also, does the wireless-controller.wtp-profile table have any special behavior in HA that would prevent or delay synchronization?Any guidance on the root cause and the safest way to bring the HA pair back into sync without manually restoring the primary configuration would be appreciated.
Hello,Has anyone experienced an Internet access issue after upgrading FortiProxy from version 7.4.9 to a 7.6.x version?We are currently facing the following situation:FortiProxy 7.4.9: Internet access works normally. After upgrading to 7.6.x, Internet access is no longer available (only fortinet domain). We reproduced the issue on a new FortiProxy VM running 7.6.7. We also tested with a clean configuration, using a simple policie. The issue persists.In our case, any version newer than 7.4.9 that we have tested results in the loss of Internet access.Has anyone encountered a similar behavior when upgrading from 7.4.9 to 7.6.x?If so, were any specific configuration changes required, or is there a known issue related to this upgrade path?Any feedback or experience would be greatly appreciated.Thank you.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.