Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hello, Trying to understand what happened and how to prevent it in the future: - Running FortiGate-VM in an Azure VM.- This FG has a custom site-to-site IPSec tunnel to on-prem. This effectively connects the virtual data centre to the on-premises data centre. Tunnel is initiated from Azure.- Suddenly, the tunnel no longer works. Phase 2 will not go up.- The first sign of trouble is this: Unavailable : Live Migration (Unplanned)At Thursday, October 13, 2022 at 7:29:19 PM EDT, the Azure monitoring system received the following information regarding your Virtual machine:This virtual machine was paused for 0.675000 seconds due to a memory-preserving Live Migration operation. No additional action is required from you at this time. Recommended StepsNo action is required - A couple of minutes after this, alerts start going off that connectivity has been lost.- After some trouble shooting, pinging, checking routes, connectivity, rebooting, firmware upgrade,
Hello, installation of FortiClient VPN ends in an error "FortiClient VPN Wizard ended prematurely because of an error." I am running Windows 11 home on my new surface 11 pro. I executed Installation .exe as Administrator, i disabled Windows Defender temporarily. Any further ideas?
EnvironmentPlatform: FortiGate (hardware appliance)HA mode: Active / PassiveFortiOS current version: 7.4.8Target version: 7.4.10HA priorities:Unit A (Master): priority 200Unit B (Slave): priority 100Expected upgrade behavior (normal case)Based on Fortinet documentation and past experience, the expected HA upgrade sequence is:Firmware upgrade starts on the slave unit (B).Slave reboots and temporarily disconnects from HA.Cluster fails over to the upgraded slave.Firmware upgrade is then applied to the former master (A) in background.Final failback occurs according to HA priority (unit A becomes master again).Observed behavior / Issue descriptionDuring the upgrade from 7.4.8 to 7.4.10 (firmware uploaded via GUI using .out file downloaded from fortinet official source):The upgrade process took more than 20 minutes, significantly longer than usual.HA became disconnected, and unit B (slave) was no longer visible from the cluster GUI.Accessing unit B directly via Console & Management
Hi!I’ve been testing Fortinac 7.6.7 in lab. It seems, that they did major changes to the RADIUS configurations. Changes are welcome, if you have not implemented Fortinac yet, but for existing installation, it might cause some work.I have been told, that nothing changes when I’m using Fortinet only devices (Fortigate, Fortiswitches and FortiAPs).That’s not true, if you are using RADIUS (in practise 802.1x)Or we can say, that nothing changes in 7.6.7 for existing devices, but if you are going to add new devices, you have to use the new selector based method. And later you have to migrate all existing devices.(https://docs.fortinet.com/document/fortinac-f/7.6.7/support-for-radius-only-devices/276659/overview)You have to migrate all existing devices to the new method before future release, because the support for the legacy method will be removed. There is a great migration tool, but it creates individual configurations for every device. It works, yes, but is quite a big mess.Missing best
I have many event like below picture, can we troubleshoot from where the mac address is come? On my L3 switch i can’t see this mac.
Hi Fortinet Support,We're looking for guidance on deploying and configuring the FortiClient VPN application on Apple iOS devices managed through SOTI MobiControl.Our Android devices are working as expected, where the VPN configuration and authentication are deployed through SOTI. However, the process appears to differ on iOS, and we're looking for the recommended approach.Specifically, we'd like to know:Whether the FortiClient VPN configuration can be deployed automatically through SOTI MDM on iOS. Whether VPN profiles and authentication settings can be pre-configured using Managed App Configuration or another supported method. If there are any limitations on iOS compared with Android regarding deployment or user interaction. Whether there is any official Fortinet documentation or best practice guidance for deploying FortiClient VPN on iOS using SOTI MobiControl.Our environment:MDM: SOTI MobiControl Devices: Apple iPhone and iPad (iOS/iPadOS) VPN Client: FortiClient Android deployment
It seems IPSEC MFA via FortiToken requires FortiClient 7.4.4 when using LDAP, so no free FortiClient version then.Are there any other options for MFA with FortiClient VPN Only 7.4.3? Does it still work with SAML, or Radius via Windows NPS perhaps?
How to generate a FortiAnalyzer report to get ISP uptimes?
Hello guys, I would like to understand whether anyone has experienced a similar issue and, if possible, identify the root cause.I recently performed a migration from a pair of FortiGate 501E devices to a pair of FortiGate 401F devices. Both the FortiGates and FortiManager were running version 7.4.11.The firewalls being migrated were the central hub of our entire infrastructure.They were managed by FortiManager and used SD-WAN Templates extensively.In addition, they were acting as the VPN hub through VPN Manager, with approximately 100 remote FortiGate devices connected to them.To prepare for the migration, I brought the new 401F devices online and initially configured only the primary unit.At that stage, the two new firewalls were not yet configured in an HA cluster.I imported the complete configuration from the old 501E and assigned the new device to the existing SD-WAN template in FortiManager.The only step I intentionally postponed until the migration day was adding the new firewall
Hi FAZ、FMG created same ADOM name for manage FAZfollow this guidehttps://docs.fortinet.com/document/fortimanager/7.4.0/examples/289359/adding-fortianalyzer-to-fortimanager at FAZ, ADOM name ”ADOM_v74” have one device at FMG, have same ADOM name”ADOM_v74”, and same devicebut in this ADOM, the left sidebar doesn't even have a Log View or FortiView to check traffic or other logs.only “FAZ” ADOM have Log View and Forti View
Hi everyone, I have this issue with a FortiManager I have deployed in Eve-NG. It’s just used for labbing and playing around with config etc, so its intended to be very simple at the moment.It’s a brand new deployment and licensed using the free license with FortiCloud. Yesterday I was able to log into the manager with no problem, worked fine and then I started experiencing the issue with logging in and getting the ‘Rejected’ message. I have done the basic config such as routing and admin access.The same creds work via the CLI. It is a local account, with no trusted hosts or 2FA.My next thoughts are to just wipe the config and redo the deployment as there is nothing of value on it at the moment and it is probably just easier, but thought it would be worth asking and getting this on the community incase anyone else has the issue.
Hello,I've a newly deployed Fortigate 200F in my LAN. I've an internet souscription bandwith of 16M.Recently I've been realizing that my bandwith is constantly saturated, but Fortiview doesn't show me the applications that saturate the bandwith. As you can see on the images above, the total bw of the internet applications displayed by the firewall (4Mbps) is much lower than our subscription (16Mbps) but it still displays our bw saturated, and the internet service is slow.Please note that this is not permanent. It happens constantly.When look to the security report, the firewall doesn't indicate any malicious attack.Please any help will be very appreciated.Thanks
People on Fortigate 7.4.12 using FAC as the Captive Portal are all working fine, I built some new sites on 7.6.7 and the config is identical, only now they cant Authenticate, they hit the Exempt rule to get to the FAC on https, and they register and get approved, but they cannot authenticate when logging in to the page.I've never liked the logs on FAC, they are not helpful at all! but most of the messages are “Guest portal authentication request failed, then says please check the Radius Auth logs, but there are none! as they don't Auth! Has something changed in the way 7.6.X Authenticates now? The EAP-TLS is working fine for the other SSID, its just Captive portals (Once again!) even in debug mode there is nothing when I search for the failed user, its most annoying, I am using “set require message authenticator enabled” but on 7.4.12 its disabled as its disabled on the FAC, is this enforced now?In short it works on 7.4.12 but not 7.6.7. , Scowered the release notes and cant see anyt
Hi allI have noticed a weird issue, client had a power outage over the weekend as the redid the server room UPS.Now my AP’s show “Connected VIA” my VOIP interface on the FortiGate, even tough they are connected via FortiSwitches and the LLDP Neighbors are correct, also the IP’s they get are from my DATA VLAN.They use to say connected via DATA VLAN and once rebooted they now show VOIP. all troubleshooting points to they are indeed connect via DATA VLAN.GUI BUG? FortiGate 7.4.12 , FortiSwitches 7.4.8 and FortiAP’s 7.4.6Please let me know if anyone has experienced this and why now all of the sudden?
Hi TeamI have around 200 VPN users. It requires monthly administration tasks to ensure VPN access is revoked timely for resigned leavers, interns and staffs no longer require VPN access. It is for IT Audit Policies.On Fortigate firewall, this is not a helpful task. My Fortigate (FortiOS 7.2 & 7.4), have not that option of per-user vpn account expiry date !!However, on Cisco Meraki MX, it allows configuring an account expiration date on VPN users directly. This was very useful since 1st Covid 2020 to date.Are there any workaround?
Hello, we have an issue about forticlient application, 1. installed application2. imported configuration file successfully3. while entering username and password and click connect button, app does not do nothing, just clearing username and password also, tried to uninstall, clean reinstall of application with revo uninstaller pro, but didn't work, also trierd to debug on firewall and there was no any traffic matching. application version is 7.4.3.4726 We tried the same installer file and the same vpn configuration file on other desktop and it worked successfully, the main thing is that we can not reinstall windows but need to setup the forticlient vpn urgently.
Hello everyone,Can anyone confirm whether FortiNAC-F fully supports (or has been successfully integrated) with the following:Aruba 1930 switches TP-Link TL-SG1016PE switches Sophos AP55C access points UniFi U6 Mesh Pro access pointsSpecifically, I’m interested in understanding:Level of support (CLI/SNMP/API… etc) Visibility and control capabilities (profiling, enforcement, VLAN assignment, etc.) Any known limitations or required workaroundsThanks in advance.
Hi Everyone,I have a FortiSIEM HA deployment with the following architecture:3 Supervisors (with DB) in HA 2 Workers 2 CollectorsI have a few questions regarding backup and disaster recovery:Which nodes should I back up? Do I need backups of all Supervisors, Workers, and Collectors, or only specific nodes? Which databases are critical to back up (CMDB, PostgreSQL, ClickHouse metadata, etc.)? My Event DB is already stored on NFS. Is an NFS backup sufficient for Event DB, or is any additional backup required? If a VM crashes, can I deploy a new VM with the same FortiSIEM version and restore the backup, or must it be restored on the original VM? What are the most critical components to back up in FortiSIEM (configuration, CMDB, ETCD/Keeper, custom parsers, rules, dashboards, reports, certificates, license, etc.)? Does anyone have a recommended backup/restore SOP or best practices for a FortiSIEM HA deployment?
Hi Fortinet Team, Good day! We’d like to confirm behavior of DOS policy on fortigate, we have initially created a policy from internal network to public with set the UDP_Flood as blocked, initially set the threshold to 5000 and is reached. what are the expected experienced
What can i do if endpoint ip address on the device inventory and on the adapter showing wrong ip?actually the endpoint get ip 10.100.50.168
Request to get pkg file of Forticlient VPN Only for MacOS to use with Intune in Download page it is online installer I cannot use with Intune I need to real file of it
HiHow many SSIDs are recommended?I read that only 3 are needed. Okay, I understand that one for IoT/External, one for Internal and one for Guest.My challenge is about the ssid pasword. I will have around 600 users using ssid External.How to manage if the password has been shared or leaked?
Can we identify how many users is active and authenticated to fortinac?
I would like to clarify the behavior regarding the display of warning and block screens in the Web Filter.We are currently configuring a system using FortiOS v7.6.7 and applying Web Filtering to internet-bound traffic.When a client device—with the CA certificate installed—attempts to access a site falling under a blocked category, the connection fails.* The error message "Your connection to this site is not secure (ERR_SSL_PROTOCOL_ERROR)" is displayed.We performed troubleshooting by changing the inspection mode setting for the relevant policy, with the following results:- Flow-based: The block page is not displayed.- Proxy-based: The block page is displayed.The Web Filter feature set within the security profile is configured for flow-based inspection in both cases.My understanding is that warning and block screens should normally be displayed even with flow-based settings in FortiOS v7.4.Have you encountered similar inquiries or issues?Also, could you provide any information regarding
We have policy only device managed by Intune can be conenct to the network.In the intune i have host below, the endpoint only showing wirelesss mac address, but actually the endpoint have 2 mac address (wired and wireless). This make the user can’t access to the network because wired mac is detected not managed by MDM. Anyone know why?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.