Your feedback drives change, make your voice count
Fortinet Community
Recently active
I would like to clarify the behavior regarding the display of warning and block screens in the Web Filter.We are currently configuring a system using FortiOS v7.6.7 and applying Web Filtering to internet-bound traffic.When a client device—with the CA certificate installed—attempts to access a site falling under a blocked category, the connection fails.* The error message "Your connection to this site is not secure (ERR_SSL_PROTOCOL_ERROR)" is displayed.We performed troubleshooting by changing the inspection mode setting for the relevant policy, with the following results:- Flow-based: The block page is not displayed.- Proxy-based: The block page is displayed.The Web Filter feature set within the security profile is configured for flow-based inspection in both cases.My understanding is that warning and block screens should normally be displayed even with flow-based settings in FortiOS v7.4.Have you encountered similar inquiries or issues?Also, could you provide any information regarding
We have policy only device managed by Intune can be conenct to the network.In the intune i have host below, the endpoint only showing wirelesss mac address, but actually the endpoint have 2 mac address (wired and wireless). This make the user can’t access to the network because wired mac is detected not managed by MDM. Anyone know why?Â
Hello Fortinet Community,We recently upgraded our FortiGate to FortiOS 8.0.0. Before the upgrade, the device was running FortiOS 7.2.13 7.4.12 7.6.7, and we created a full configuration backup.After the upgrade, we experienced an unexpected internet outage. During the incident, the FortiGate had a high number of active sessions, and users lost internet connectivity. A reboot temporarily restored the service.At this time, we cannot confirm whether the issue was caused by FortiOS 8.0.0 or another factor. However, since the environment was stable before the upgrade, we are considering downgrading to the previous stable version while continuing our investigation.We would appreciate your advice on the following:Is it recommended to downgrade from FortiOS 8.0.0 to FortiOS 7.6.7, or would FortiOS 7.4.12 be a better long-term stable version?Since we have a configuration backup created while running FortiOS 7.6.7, can we safely downgrade and restore that backup?Are there any known issues or pre
Hello Techies i have 15 fortigate firewall that is getting authenticated by cisco ise tacacs, now i want to enable MFA for all firewalls is there any possibility to set asingle code for all firewalls.i have tried fortitoken but that require different otp for each firewall
overlay working but underlay under the members i dont see the physcial port 1 an port 2I have config SDWAN ADVPN 2.0 i was able to to setup the overlay SDWAN but when trying to config the undelay SDWAN, i have created a Zone for underlay, but when i am trying to add the ports to the underlay zone the ports which the ISP are connected dosent show (port13 and port14)
Using the standard Portal templates, just adding custom logo etc, it isnt responsive to mobile phones, Apple or Android, I have tried to add extra CSS to the template for login, registration , disclaimer etc. but it just doesnt lay out right, Does Fortinet not have a fix for this or a guide for the best way to add viewport in the CSS? I did CHATGPT it, but it still not quite right, I mean this is standard stuff these days right?ForiAuth 8.0.3Â Thanks
Hi everyone, I'm experiencing a strange issue with an IPsec Dial-up VPN after migrating users from SSL VPN. The environment is FortiGate 400F with FortiClient VPN 7.4.3.4323 on macOS Sonoma 14.1. The problem only affects macOS clients; Windows clients using the same VPN configuration and user account work correctly. Split tunneling is enabled, and all firewall address objects are configured correctly as /24. However, after connecting from macOS, one of the split-tunnel routes is installed with an incorrect mask (for example, 10.10.10.0/24 becomes 10.10.10.0/31). If I remove that subnet from the split-tunnel group, the issue moves to the next subnet (10.10.11.0/24 becomes 10.10.11.0/31), so the problem follows the route order rather than a specific network. I also tested with a split-tunnel group containing only three networks, and everything works correctly on macOS. The production split-tunnel group contains around 190–200 routes. Has anyone encountered a similar issue or knows wheth
Hello.Working as a Telecom user, I can only use Putty and similar software for SSH and Telnet connectivity with the Dacon VPN, but not with the Planet VPN.From IAM support, they replied that I am enabled without hindrance with both SSH and Telnet.Can anyone help me? Thanks in advance.Â
Hello Fortinet Team,I would like to report a False Positive occurring in FortiClient. The antivirus engine is flagging and quarantining legitimate .jar files that belong to Microsoft Power Automate Desktop.These files are required by the Microsoft application to interact with Java-based interfaces for automation purposes.Software: Microsoft Power Automate Desktop Flagged Files: PAD.JavaBridge.jar PAD.JavaBridge.A11y.jar Some of the File Hashes (SHA256) involved: CF531D64F2445BD6149EF018D41C6B6EDC2185461100998DFF8204... 0887F61DB05200C724DF9E0700F63B98145E47C69FB98258323AB6... EB935EB8D28CDBA566CBACDA023E02FCD4A9DB0535893B5B8699E7... I have attached a screenshot ("Captura de pantalla 2026-07-20 110922.png") showing the multiple detections and the exact hashes provided by the FortiClient logs.Could you please review these files and update the definitions to whitelist them?Thank you.
I am considering changing the username of the default "admin" user on FortiGate.I understand that it is possible to create a new superuser and change the "admin" username, but will changing the default "admin" username affect other settings?
Â
I have difficult to add switch Alcatel omniswitch 6860 can some one help.When I configure credential snmp is OK but CLI I can't connect it. When I test in fortinac console cli all is ok but in gui no.
Hi Fellas,I'm deploying FortiClient EMS 8.0 using Microsoft Intune (Win32 app) and have run into an issue.Environment FortiClient EMS 8.0.x Microsoft Intune (Win32 app) Deployment package generated from EMS with MSI Installer Files enabled EMS generated: forticlient.msi forticlient.mst PackagingBoth files were placed in the same source folder and packaged into a single .intunewin using IntuneWinAppUtil.exe.The install command in Intune is:msiexec.exe /i "forticlient.msi" TRANSFORMS="forticlient.mst" /qn /norestart /L*v "%ProgramData%\Microsoft\IntuneManagementExtension\Logs\FortiClientInstall.log"IssueThe installation completes successfully, but when FortiClient launches, it still displays the "Enter Invitation Code or IP Address" screen.Even when I manually enter the Invitation Code or the EMS IP address, the client does not register with EMS.Additionally, the folder:C:\Windows\FortiEMSInstaller_logsis not created, so there are no EMS installer logs to review.Expected B
hello all,We attacked by ransomware and unfortunately all our file and also backup are encrypted.I want to know if someone advise me how to find from where or witch direction, computer, lan or site - From where it attacked usHow i can create report or see the logs.We have fortinet e200 model.ASP Best Regards,
Today i check our users can’t connect to the fnac and i got this error. I check service connector to the entra is have pronle, where i test to poll and test connection but always loading. The i reboot the nac and the error was gone and the authentication is successful.Something wrong in my fnac?Â
when we use authentication host-mode multi-domain on the port switch, this mean only one vlan data mac address and one vlan voice mac address is accepted. If there 2 mac address of vlan data then the port switch will be shutdown.Below log from the switch%PM-4-ERR_DISABLE: security-violation error detected on Gi1/0/1, putting Gi1/0/1 in err-disable state The interesting is for iphone deployment. When there are new ip phone connected to the nac then nac will put this host to registration vlan and if this ip phone have endpoint conected then from switch perspective there are 2 valid vlan data mac address and security violation is ocurred.Anyone know how we can deal with this situation?
Hi,Environment: EMS 7.4.7, FortiClient mobile (iOS/Android) 8.0.0, FortiOS 7.6.7. ZTNA access proxy already used by Windows/macOS endpoints.ZTNA certificate signing works automatically for Windows/macOS on telemetry connect. For mobile, EMS only offers ZTNA certificate provisioning via MDM (Intune/Jamf/Workspace ONE, SCEP). We have no MDM for these users.Questions:1. Is manual (non-MDM) ZTNA certificate installation supported on FortiClient iOS/Android? If not, is it a hard limitation or roadmap?2. If supported, what is the correct procedure (cert format, storage location, how FortiClient uses it for ZTNA)?Thanks.
Hi, I have a Fortigate and 4 FortiSwitches connected via fortilink and there are 5 VLANs operating.I also have some devices connected (in every switch on VLAN_20) that communicate with a controller via mDNS packets. They’re broadcasting so the controller can list every device found in the network. This works only if the controller and a device are connected to the same Fortiswitch (in two ports of the same VLAN). If connected to another Switch (to a port of the same VLAN) the packets do not arrive at the controller.Any clue why this happens?Thank you
Hi,FortiGate 7.6.7, IKEv2 dialup with EAP, mode-cfg and IPv4 split tunnel enabled. internal-domain-list is configured, but split DNS never takes effect: every DNS query from the client reaches the FortiGate, not only the two internal domains.config vpn ipsec phase1-interface  edit "<tunnel>"    set type dynamic    set interface "<wan-if>"    set ike-version 2    set peertype one    set net-device disable    set mode-cfg enable    set ipv4-dns-server1 <internal-dns-ip>    set internal-domain-list "domain1.local" "domain2.local"    set eap enable    set eap-identity send-request    set ipv4-split-include "<split-group>"  nextendVerified with: diagnose sniffer packet any "port 53" 4 0 l — public domains such as google.com show up as well. Same result on FortiClient (Windows) 7.4.3 and FortiClient mobile 8.0.0. VPN was fully reconnected after each change.Questions:1. Anything else required in 7.6.7 for internal-domain-
Hello,I am designing a VPN topology for approximately 10 branch offices.Current environment:- FortiGate at the headquarters- Two ISPs at HQ- Two ISPs at every branch- Some branches use FortiGate- Some branches use other firewall/router brands- Each branch has multiple VLANs- Automatic VPN failover is required- Central monitoring is available through ZabbixI am considering the following design:1. Two dial-up IPsec hubs at HQ, one on each ISP2. Two route-based IPsec tunnels from every FortiGate branch3. SD-WAN overlay zone with Performance SLA4. BGP over the VPN tunnels5. Unique Peer ID and PSK for every branch6. Separate standard IKEv2 tunnels for non-Fortinet branchesMy questions are:- Is the dial-up Hub-and-Spoke design recommended for this environment?- Should I use two tunnels or four tunnels per critical branch?- Is BGP worth using for approximately 10 branches, or would static routing be simpler?- What limitations should I expect with mixed-vendor branches?- Should FortiGate and t
EnvironmentFortiGate: FG-60F FortiOS: 7.2.13 (Build 1762) FortiAP: FAP-231K-E (Brand New) Switch: Cisco Catalyst C1300 (L3 Switch)FortiGate 60F  |  |-->L3 P2P LinkCisco Catalyst 1300 (L3) (WIFI-VLAN gateway and DHCP configured here, interface vlan 30)  |FortiAPCurrent BehaviourAP successfully receives an IP address from the Cisco DHCP server.AP can ping the FortiGate.FortiGate can ping the AP.No Local-In Policies are configured.Two different brand-new FAP-231K-E units have been tested.However, the AP never appears under WiFi & Switch Controller → Managed FortiAPs. Current BehaviourAP successfully receives an IP address from the Cisco DHCP server. AP can ping the FortiGate. FortiGate can ping the AP. No Local-In Policies are configured. Two different brand-new FAP-231K-E units have been tested.However, the AP never appears under WiFi & Switch Controller → Managed FortiAPs.diagnose wireless-controller wlac -c wtpTotal 0 WTPsget wireless-controller statuswtp-session-count: 0
ENVIRONMENTFortiOS: 7.6.x (FortiGate 120G)FortiClient EMS: 7.4.x (FortiCloud SaaS)FortiClient: 7.4.7 (Windows)Authentication: IKEv2 EAP-SAML via Microsoft Entra ID---ISSUEFortiClient endpoints managed by EMS fail to complete IKEv2 IPsec VPN tunnel establishment after successful SAML authentication. The EMS-managed client sends an EAP NAK (type 08) in response to the FortiGate's EAP Identity Request, causing the FortiGate to tear down the IKE SA with 'unexpected payload type 41'.A non-EMS-managed FortiClient with an identical manually-configured tunnel connects successfully every time. The failure is specific to EMS-managed clients.---FORTIGATE IKE DEBUG (EMS-MANAGED CLIENT)The sequence on every EMS-managed connection attempt: responder received AUTH msg responder preparing EAP identity request responder received EAP msg unexpected payload type 41 schedule delete of IKE SA connection expiring due to phase1 downThe client response decodes as EAP type 08 (EAP NAK) — the client is re
I often facing issue where the gui is not responding for some minutes. Anyone else have same issue with me?Â
Hi,I have this scenario.I tried to register using the captive portal via self-registration but encountered the error "Physical Address not found".This is via wired connection registering from the isolation vlan/network. Configuration:L3 SetupFNAC-F VM - v7.6.5FGT is the L3 deviceTraffic is not being NAT'edFNAC has read-only access in FGT Is there anything else I need to check?Any insights/suggestions?Thank you.
I upgarde fnac to v7.6.7 and found issue with teh MDM integration.When i try to poll then i the poll alsways loading, but test connection is working fine. Also every second there are event ‘destroyed’ like below pic. Anyone know why?Â
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.