Mark a Best Answer
Fortinet Community
Recently active
I’ve just rolled out 802.1x for the first time and it ~~appears~~ as if reauth causes disconnects. In the log it says the port is no longer authorised and then reauthenticates. Is that correct?I’d have expected the reauth to work similar to IPSEC, where it does it before the expiry time, so that things don’t drop? If it does then fail, then deauthorise the port.
We have a couple of internal CAs here and with a new setup of a FGT 100F on 7.6.6 and several FSW 148Fs on 7.6.6 we noticed that the CA certificates (and user peers) are not syncing to the FortiSwitches. This is with tunnel-mode compatible set already.To work around this I created several fortiswitch custom-scripts that create CAs and peers and an automation that looks for FortiSwitch Connected events and runs those scripts on the connecting switch.Is this a known issue on this release? Did I miss something in the initial setup? Is this standard behavior?
Hi all, could you tell me where I can find the link to operate queries regarding S/N to see active contracts and so on?I remember that it was something like "Find Asset" or similar but I'm not able to find it anymore... Thanks in advance
I wrote a Fortigate Administrator exam the previous week, and mid exam my pc restart and I had to login in again to continue but I was unable to continue because the Exam did not want to open again, the pearsonvue app was only showing the my video, and no chat option was available, after a while I got disconnected from the exam and I was told that I violated a policy when I contact the support team. I am reaching out because I lost my voucher and 200usd for a system that didn’t work properly. Please hep!
I’m running v7.6.6 on FortiNAC. When I issue ‘backup now’ on the system backup using the GUI, it seems to work. However, the file never shows up on FTP server. In fact, no packets are generated at all towards the FTP server, thus ruling out syntax.When I run the command from the CLI, I see the packets and the file is accepted by the FTP server.execute backup config ftp / 10.99.3.206:21 <user> <password> Any ideas why GUI not working?
We are running a Forticlient EMS Server 7.0.9 with ~350 Forticlient 7.0.9 endpoints in use. In recent weeks we have received more complaints from Windows 11 users on our network that picture files (jpg, png) become corrupt when copied or opened from the network drive. They can open them, but the pictures are "corrupted". Windows 10 users are not affected by the problem. If we disable FortiClient and copy the files again, no errors occur. We already deactivated the option "Scan Network files" in the corresponding Malware Protection Endpoint Profile, but this didn't help. Does anyone have a similar problem and a solution?
Hi ti all, Our FortiGate 50G is protecting 2 different routers from 2 different ISPs. One is plugged to Wan and the other to Lan1 (=Wan2). Domestic use network. Only ethernet. No WiFi. A few days ago, I tried to protect a TV decoder with the FortiGate. Creating the multicast policies, I have surely changed something I should not have to. The TV decoder was plugged into lan 2 which belongs to a Vlan switch (called "lan". Members: lan 2 + lan 3). This Vlan provides internet from only one of the routers Now I have the following symptoms: - When using this routers's internet and plugging the ethernet cable to my computer, my Airbook gets an auto-assigned IP first (yellow led) and, after 30 seconds, it switches to a normal IP (green led): Internet is available then. This symptom happens only with one of the routers (plugged to lan2 or lan3... Where the TV decoder was plugged to). I tried to disconnect "STP". then the symptom disappears. But comparing with the old configuration file, I notic
Hey everyoneI’m deploying FortiSandbox for the first time and integrating it with FortiGate, F5 Load Balancer, and an internet modem.Before starting, I want to make sure the environment is ready.What are the required network prerequisites and ports that should be open?Also, are there any common mistakes or best practices I should be aware of for a first-time deploymentn?
Hello, I'm trying to do a lab with a trial version of fortianalizer (7.4.10) and fortigate (7.4.11) and I can't do the connection. When setting the IP of the analizer on the logging settings on the fortigate I get "no connection".They are on the same network, already enable the fgfm on the interface. Can ping both analizer from fortigate and vice versa. The config that I have on Fortigate:config log fortianalyzer setting set status enable set server "192.168.0.102" set certificate-verification disable set ssl-min-proto-version TLSv1end The config that I have on Analizer:config system global set adom-status enable set enc-algorithm low set global-ssl-protocol tlsv1.0 set hostname "FAZ-01" set oftp-ssl-protocol tlsv1.0 set ssl-low-encryption enable set timezone 91 set usg enableend Log from analizer
Hello, I am trying to update FortiSIEM content version from 901 to 908, but I receive a “server unreachable” error during the update.For testing, I allowed all-all access on the firewall for FortiSIEM, but the issue still persists.Has anyone experienced a similar issue? Are there any specific URLs/FQDNs, ports, or log files that should be checked for FortiSIEM content updates? Best Regards,İsmail ÜREK
Hello :)I have a question about connecting via Putty or PowerShell. How do I clear the history of entered commands that are substituted after pressing the up and down keys? Connecting via SSH to the FG900, I don't know where the history of such commands is located. Please help.
I want to make Forti Sandbox take copy of all internal mail which sent between the staff internally and scan it “URL & Attachments”How can I do this step by step on Forti Sandbox ?
Hello, Can the regulatory domain be changed on an FortiAP form -E (sweden) to -S (Philippines). Or does the sale have to be done locally in Philippines through local partner on local pricelist? BR Andreas
I was able to establish a connection for a very long time, but it then suddenly stopped working. The connection is established, but no data is received. The connection then closes after about 25 seconds.I noticed the following in the fortitray log which only appear after the time it stopped working:[2026-04-30 07:21:32.5496135 UTC+02:00] [17640:15916] [sslvpnlib 510 error] [ERROR]SslvpnAgent: Pipe is broken for writing. Error=233[2026-04-30 07:21:32.5532904 UTC+02:00] [17640:15916] [sslvpnlib 510 error] DoSendSslvpnReq() failed. Need to restart Pipe.[2026-04-30 07:21:32.5534866 UTC+02:00] [17640:15916] [sslvpnlib 510 error] Failed to connect to SslvpnDaemon, LastError=2[2026-04-30 07:21:32.5535905 UTC+02:00] [17640:15916] [sslvpnlib 510 error] CSslvpnAgent::SendSslvpnReq() 447 InitPipeHandle() failed.[2026-04-30 07:21:32.5537786 UTC+02:00] [17640:15916] [sslvpnlib 1261 error] CSslvpnBase::UpdateFortiSslvpnStatus() GetSslvpnStatus() failed.[2026-04-30 07:21:32.5538736 UTC
Hello Team, I have Fortinet firewall configure on Azure cloud as Active-passive with more than 400 Tunnels, Now i want to change mode from Active-passive to Active-Active. Any official documentation to achieve the same ?
I need help understanding an unexpected FortiEDR Manager restart.We observed the following event:Component: ManagerComponent Name: FortinetDescription: Server was restartedBefore this event, several FortiEDR components changed state to Disconnected:XX:XX:XX - Aggregator [aggregator-cloud] changed to DisconnectedXX:XX:XX - Core [core-cloud] changed to DisconnectedXX:XX:XX - Core [fortiedr-core-jumpbox-onprem] changed to DisconnectedXX:XX:XX - Warning: The following connectors will become inactive: Firewall FW (name)Then the services recovered after 20 seconds:YY:YY:YY - Manager: Server was restartedYY:YY:YY - Connection to Syslog succeeded: FAZ1YY:YY:YY - Connection to Syslog succeeded: FortiSIEMYY:YY:YY - Aggregator [aggregator-Cloud] changed to RunningYY:YY:YY - Core [core-cloud] changed to RunningYY:YY:YY - Core [core-onprem] changed to RunningWhat can cause the FortiEDR Manager to restart with the message “Server was restarted”?Any guidance on where to investigate further would be a
I am working as an intern at a startup and the website I am handling https://www.gazfull.com/ is being flagged as malicious by FortiGuard and getting blocked.There is no intentional malicious content on the site. We want to fix the root cause instead of just requesting whitelisting.What are the common reasons FortiGuard flags a website as malicious?Are there specific security loopholes, misconfigurations, headers, SSL issues, third-party scripts, or deployment patterns that typically trigger this?Also, after resolving potential issues, what is the correct process for requesting reclassification/whitelisting with FortiGuard?Any guidance on debugging this systematically would be really helpful.
Hello COMMUNITY,I am facing some problems, I would really appreciate if you can assist me with that. I have installed fortigate on vmware on ubuntu and configured it per this document (https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/545125/ztna-agentless-web-based-application-access).I added the fortigate ip (172.169.173.132) as portal.ztna.com to /etc/hosts to resolve the DNS. The issue is that web portal is not accessible. when I wrote the address to the browser, it shows with HTTP This page isn’t workingportal.ztna.com didn’t send any data.ERR_EMPTY_RESPONSE with HTTPSThis site can’t be reachedportal.ztna.com unexpectedly closed the connection.Try:Checking the connection Checking the proxy and the firewallERR_CONNECTION_CLOSED-----------------------------------------------------------THIS IS MY CONFIGURATION FGVMEVYLSWRHYA98 # show firewall vip config firewall vip edit "ZTNA-web-proxy" set uuid 65006b6c-42f6-51f1-97c1-5c559a60d09e set type
I have yet to find a working solution for what seems like a normal networking scenario. Here are the requirements:ports 1-5: port1: access vlan 5 (untagged vlan 5) should share l3 gateway with any hosts connected to trunks port2: access vlan 10 (untagged vlan 10) should share l3 gateway with any hosts connected to trunks port3: access vlan 15 (untagged vlan 15) should share l3 gateway with any hosts connected to trunks port4: trunk all vlans, native vlan 99. non-aggregate port5: trunk all vlans, native vlan 99. non-aggregatel3 interfaces of some kind. cannot be under a physical interface because two trunks must carry vlans: vlan5: 10.0.5.1/24 vlan10: 10.0.10.1/24 vlan15: 10.0.15.1/24 vlan99: 10.0.99.1/24 (native)I’ve read the documentation. I’ve asked open.ai several different times, I’ve had Claude read through multiple FortiOS version documentation. The documentation is not great in this area. So no great that claude cannot figure it out.I can make something like this work w
We are using a FortiGate-200G running FortiOS v7.6.6.We would like to know if there is a way to send alert email notifications when there is a sudden increase in the number of sessions, such as RDP sessions, passing through the FortiGate.If there is a method using FortiAnalyzer, please let us know.Alternatively, a solution using only the FortiGate would also be acceptable.
Go stdlib vulnerability detected in FortiTcs.exe (possible GO‑2026‑4865). Version Forticlient: 7.2.13.1287. Is there a fix that will release soon? Does the version 7.2.14 can fix this vulnerability?
We have deployed fortianalyzer on VM & currently it is in production.We have given 500GB of disk space first & currently we need to add 500GB size additionally.Can anybody help me on how can we add the diskspace & what all needs to be done before proceeding with the addition.
Hello everyone,I am planning a firmware upgrade for a FortiSandbox currently running 4.0.9. My target is 4.4.9.Since this is a jump across several versions, I'm looking for a validated Method of Procedure (MOP). Specifically: Upgrade Path: Based on the release notes, is a direct jump supported, or do I need to step through 4.2.x first? Cluster Impact (If applicable): If I'm in a Primary/Worker setup, should I expect significant downtime for the Rating Engine sync between these versions? Are there any known issues in the target versions that needed to consider? If anyone has a step-by-step checklist or "gotchas" for this specific path, I’d appreciate the help!
We are currently using two FortiGate-200G units in an HA configuration with the ha-direct feature enabled.After applying the following NetFlow configuration, we were unable to execute the set netflow-sampler command on the target interface.If there is any way to achieve this, we would greatly appreciate your advice.NetFlow Configurationconfig system netflow config collectors edit 1 set collector-ip "x.x.x.x" set collector-port 9996 next endendAttempted Command on the Target Interfacefw # config system interface fw (interface) # edit port1fw (port1) # set netflow-sampler bothcommand parse error before 'netflow-sampler'Command fail. Return code -61
Hi all,I built a captive portal at the fortiauthenticator and integrated it with MFA.The saml process works well when tested separately in a browser but when the user connect to the SSID it’s not getting redirected properly, an error pops up says “pretty print”.I have only basics in fortinet, can someone help ?fortiauth in Azure , EntraId in Azure, fortigate onprem.User(SSID)—-(AP)——-Fortigate ——-(IPsec)——Azure(Fortiauth+EntraID)
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.