Mark a Best Answer
Fortinet Community
Recently active
Hello Fortinet team and community,I am looking to install FortiClient VPN version 7.0.12.0572. Could you please help me with the official download link for this release? Since this is a free VPN-only version, I would appreciate guidance on where I can access it directly from Fortinet’s site or repository.Thank you in advance for your support.
Hi,I am using a personal account, as the company I work for has lost access to the forticloud portal. This is because we requested a transfer from the master account to another existing account. The transfer was approved but it looks like something went wrong along the way. Nobody within the company that had access can access the forticloud portal. So access to fortimailcloud, asset manage etc. I have been emaling cs@fortinet.com but so far without any response.Can you some provide a procedure, a link, phone number I can call to rectify this?Advice will be greatly appreciatedKind regards
Hi all, on our infrastructure we have a forti Manager on 7.4.10 version. We have multiples Fortigate on 7.4.11 release.We tried in different ways to set expiration date on Polici Packages but the feature does not work. Either on forti manager and fortigate firewalls. A collegue of us works for another company with the same infrastructure. Same issue. Does someone know if it is a known issue? I checked on documentation, and the issue was not mentioned.We also opened a ticket to Fortinet support. They did not know about the isue and they don’t know how to resolve it. Maybe updating to the last relase solve it? Thanks for your help
Hi all, when I try to add a firmware template to a FG80F the Fortimanager Cloud returns me the following error: "[-9001] invalid template assignment - conflicting template assignment scope: device FG-BENIARJO, vdom root, firmware template object [(null)] and [Template_Upgrade_Beniarjo]" (attached screenshot). As you can see the template has no device assigned. The FG does not have any firmware or provisioning template configured. On the other hand, another FG with the same characteristics, and being the template a clone, I have not had any problem. Any ideas? Best regards!
Hi, I am running FortiOS 7.4.7 on a FortiGate-60F and am trying to migrate from SSLVPN to IPsec VPN. I've managed to configure IPsec (IKEv2) dial-up to work fine, but I notice that when I set the mode to IPSec over TCP, FortiClient (v7.4.3) does not connect and times out. UDP mode works perfectly fine. I also notice that TCP 4500 is not one of the local-in policies on the firewall. Does a local-in policy need to be configured for this to work? Has anyone had any experience with this? Thank you!
We have dedicated ssid for contractor where the contractor user will connect to the isolation then enter the entra id by captive portal then fnac checking the antivirus by posturing. When posturing result is ok then the device will move from rogue host to registered host.With this condition when next day the contractor connect to the network then the posturing is not executed because the posturing only will be executed for rouge host.So can we move the devices from registered host to rouge host for contractor if the device not connect to the newtork for some period?
We have policy to allow all servers access to microsoft then i have a firewall policy and set the destination to all microsoft internet service.However i found some microsoft url still blocked by implicit denied and this mean microsoft internet service not contains all microsoft url. Anyone know how to solve this?
We migrated the FW from SonicWall to Fortigate 201G after completing all configuration it’s working fine but the SAP tunnel having issue on migrating time we resolved it, but after 1 week facing flapping issue continously . Using ikev2 and pfs disable as recommended by SAP cloud.Also we are using separate subnets in phase2. Attached VPN logs.Our device Fortigate and SAP device Cisco ASA Kindly recommend if any things need to be check on Fortigate.current version fortiOS v7.4.11 build2878 (Mature)
Hey everyone,I'm currently working on my PFE (Graduation Project) focused on deploying a Zero Trust Architecture using the Fortinet Security Fabric. I’m finalizing the deployment strategy for the FortiClient custom installer distribution, and I'd love to get some architectural feedback from the community.The Goal: Securely distribute the custom installer generated in EMS to remote endpoints during an initial onboarding period, and then tightly lock down registration afterward.The Environment: My core EMS server lives inside the secure Server LAN.For both options below, the download page is protected by a FortiWeb WAF that requires Active Directory (AD) pre-authentication before a user can access the installer. However, given the recent high-severity vulnerabilities (like the 8013 auth bypass CVEs), I am highly paranoid about zero-days and expanding the internal attack surface unnecessarily.Here are the two design paths I am debating:Option 1 (Dedicated DMZ Server + WAF + AD Auth)
Hello,I’m facing an issue with EMS endpoint alert emails. The email includes a report link for full details, but when I open it, I get the following message:“Redirect Notice – The page you were on is trying to send you to an invalid URL.”Has anyone faced this issue before or found a solution for it?
I have configured the following in a new Active-Passive setupUnit A (setup as Active 120 HA) - mgmt IP address 10.1.1.5/24 (set management ip and dedicated-management)Unit B (setup as Passive 115 HA) - Mgmt IP address 10.1.1.6/24(set management ip and dedicated-management) HA on both group ID 1tracking port2“port2” configured on both units as IP address 10.1.1.10/24 Both units are only pingable sometimes, MAC flapping messages appear every 5 seconds on both Arista switches setup as a MLAGBoth units have the same virtual MAC address (get hardware nic mgmt) other units I have setup exactly the same a-p, have different mgmt MAC’s between A and B! If I remove the group-id from Unit B, everything works, both units pingable and accessible. When I add the group-id back into Unit B, problem persists. I have even changed the group-id on both from 1 to 256, same problem. How can this be, I have checked pretty much everything but obviously there is sometime I am missing? Thanks all for any inpu
I have requirement to use one SSID for employee and guest, the employee will use EAP-TLS for authenticate and if authentication failure because the client no have certificate then the endpoint will access to guest network.This was done for wired connection (employee and guest) but on wireless connection only employee was work, if the wireless client not have certificate then the client is asked to enter the username and password. Anyone know how to achieve this?
I got a FS108D from work nothing crazy about it. I created a VLAN on it but after I did that it doesn’t show anything else on the page I inspected the browser and it says 500 Server error. It has 8 ports and I want to create some VLAN for my devices.Whats is the issue here?
This week’s updates focus on strengthening automation across the Fortinet ecosystem while expanding operational visibility and deployment workflows in FortiSOAR™.The release introduces enhancements to multiple Fortinet Fabric connectors, including Fortinet FortiAnalyzer, Fortinet FortiManager, Fortinet FortiNDR Cloud, and Fortinet FortiSIEM, improving integration depth and orchestration capabilities across security operations workflows.On the solution side, FortiManager ZTP Flow v1.2.0 and its accompanying Feature Examples pack extend zero-touch provisioning workflows and provide additional implementation guidance for automated device onboarding scenarios.Additional updates include improvements to the Code Snippet connector for custom automation use cases, expanded support for SonicWall Firewall integrations, and updates to the SLA Count Down Timer widget to enhance operational tracking and analyst visibility.The following table summarizes the changes since the last announcement. #
HI All I need to get some guidance on how we can deploy below network Firewall HA ( 2 LAN port1 and port2 in same hardware switch), Port 1 on both FG connect to cisco switch 1 and cisco switch 2 respectively. Port 2 on both FG connect to cisco switch 1 and 2 respectively alsoCisco Switch 1 and 2 also interconnected(trunk port). Cisco runs RPVST+. Switch1 runs as STP root primary, Switch 2 runs as STP root secondaryAbove topology eventually create loop network. How should it be configured to avoid the loopFortigate hardware switch if disable STP, it eventaally create loop, and broadcast storm starts. Enable STP on FG hardware , eventually the broadcast stops. But i found some weird result. When i check Switch2 STP, it blocks the port connect to FG1, but port connect to FG2 becomes root, and forward state. Switch2 can still somehow reach FG IP, the mac-address also shows it learned from port to FG2. But FG2 runs as HA passive state. i try diagnose sniffer on FG2, nothing captured. How
I'm struggling a bit with my performance SLAs and SDWAN Rules. My typical branch office will have 2 internet connections, one is usually better than the other (i.e., Verizon FiOS plus Comcast or true DIA Fiber plus a business broadband).What's the best-practice strat for SDWAN rule? I've been mostly relying on Best Quality rule with a performance SLA that pings Google DNS (8.8.8.8), but I'm seeing more flapping than I would expect.I think my first question is: Do the Performance SLA settings under Link Status (Check Interval and Failure before inactive) affect the SLAs themselves? If I have my latency SLA set at 250ms, is the interface in violation of the SLA the first time if sees latency greater than 250ms or if my check interval is 1000ms and failure before inactive is 5, does it take 5 seconds of 250ms latency to violate the SLA?Any best-practice recommendations on these rules and Perf SLAs? I'm starting to think that Google DNS might not be the best candidate host for my probe. Do
I setup a lab environment with a FortiGate evaluation. All good… I needed to blow it all away and start again… I can see the asset in my portal, and I can download the lic file, but on a new install it does not accept it and gives me: Am I missing something here?
Hi,One of my clients have sip traffic passing through firewall. When we view forward logs firewall shows lots of logs with "0 Bytes sent/received". What does it mean?.
Hi, i have a Fortigate 200D Firewall with FortiOS 6.0.16 and a Huawei 4G Webstick Modell 3372h. I can't bring the Connection to the LTE-Network up. I searched around and found this https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-Huawei-E3372-h-modem-stick/ta-p/193600 The Problem is, that i have the AT-Command Version of this Stick and this HowTo is for the Web-Interface Version. When i try to configure the Stick as lte-modemdiagnose sys lte-modem infosays, that the Modem is not connected. So i tried to configure the Stick as "normal" Modem. The Modem itself seems to work properly: diagnose sys modem queryUSB status: Connectedmanufacturer: huaweimodel: E3372IMEI number: 868230032061123SIM state: Validservice status: Valid Servicesignal level: 3/4network name: E-Plusnetwork type: E-UTRANlocation area code:active profile(AT&V):COMMAND NOT SUPPORT^RSSI:18^HCSQ:"LTE",45,47,136,26 But in the Debug Messages a Timout occures (At
Hello FortiPeople, I’m checking if there’s a possibility to create a “recipient verification” exception for a particular source IP address. Let me explain:We have a particular client application, which sends e-mails to multiple addresses in one SMTP session.Whenever there’s a bad recipient address in the list of recipients, the application logically gets a “550 5.1.1 ... User unknown” reply from the FortiMail, via the recipient verification options set in the domain settings.However, where this SMTP client differs compared to other SMTP clients like Exchange Online, is that it quits the session after this reply and will not send the mail for ANY of the recipient, so no one receives the e-mail when only 1 address is bad.Exchange Online, for example, will continue on the same session (verified in the logs by session ID) and just continue for all the good addresses, which will then receive the mail. We tested with Thunderbird as an SMTP client, which also gives the same behaviour (SMTP se
Got a batch of forti switch 124g.Has anyone else got them?Do they also make an extremely high pitched whine like the capacitors about to blow?I've raised a ticket with support as these are brand new but wondered if this was a commonly known issue with them or I'm just unlucky?
Hi everyone,I am using 1 Hub, 2 spokes, FortiOS 7.6.3, ADVPN 2.0, BGP loopback peering without overlay IP.So, every things is good, ADVPN works right, just a problem for peering dynamic BGP between spokes.When spoke to spoke wants to speak (test by loopback addresses), auto shortucky is established, Good, but spokes cannot established BGP peering, based on my diagnose, TCP 179 will be drop due no match selector in IPsec, it seems that problem is the Tunnel between spokes but no, tunnel will established without any problem, but BGP cannot.I should note that if I use 'execute restart router' , so spokes start to establish BGP peering! it means that tunnel is not problem.The main problem is that BGP peering starts to etablish between spokes before complete establishing tunnel.So, I am looking for a way to make some delay, just a second or 2 second in BGP peering process or restart BGP peering establishing between spokes after ADVPN establishing.Can you help me how can I do it ?
Static ip update on ISP then Fortidydns is not working
I was curious if anyone was already ingesting the Malicious IP and/or Domain Lists from their MS-ISAC membership? Someone asked in another community thread if those were included in the Fortigate threat feeds somewhere, but didn't get a response. I’ve gone through the steps in several documents from support, but keep running into an Internal Error on my Fortigate when I refresh the object. I figured I would check and see if someone had already figured this out and would mind sharing the configuration settings they used to create their successful objects. I’m running a case with support but it’s slow going.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.