Mark a Best Answer
Fortinet Community
Recently active
Subject:[FortiOS 7.6.7] Policy GUI infinite loading and missing policies in By-Sequence viewDescription:We currently have a total of 514 firewall policies (Policy IDs 2 through 515). Due to a GUI bug causing an infinite loading loop, we switched the view to By Sequence and applied a filter to force-load the policies.Although the filter counter indicates that all 514 policies exist, the rendering goes through 4 separate loading passes, during which exactly 4 policies fail to render and are omitted from the display. In FortiOS 7.6.7, 4 out of 514 policies are rendered as duplicates on the GUI, causing 4 actual policies to remain hidden. Additionally, an infinite loading bug occurs during initial page load—similar to the Interface Pair View issue—which can only be temporarily bypassed by removing table columns.
Hi Fortigate Team,The branch currently has a single static ISP connection, while the HO has two independent static ISP connections. Internet traffic at both locations uses their respective local ISPs.We need to configure a redundant IPsec VPN between the branch and HO so that the branch can access internal subnets and servers at the HO through either ISP connection. SD-WAN should be configured at the HO to provide ISP failover and maintain VPN connectivity if the primary ISP fails.SD-WAN should also be configured at the branch. Currently, the branch has only one ISP, but a secondary ISP may be added in the future. The configuration should therefore support ISP failover at the branch when the second ISP becomes available.
Monthly Active User (MAU) Enforcement in FortiAuthenticator v8.0.4This article provides an overview of the Monthly Active User (MAU) licensing enforcement introduced in FortiAuthenticator v8.0.4, including the rationale behind the change, how MAU is calculated, enforcement behavior, exemptions, and monitoring options.BackgroundFortiAuthenticator is Fortinet's comprehensive Identity and Access Management (IAM) platform, providing a broad range of authentication and identity services, including: Fortinet Single Sign-On (FSSO) RADIUS and TACACS+ services Certificate Authority (CA) LDAP server SAML Single Sign-On (SSO) Multi-factor authentication (MFA) Remote authentication with Microsoft Active Directory and other identity providers Historically, FortiAuthenticator licensing has been based on the number of licensed users. However, some deployments have significantly exceeded their licensed user count by purchasing a small user license while authenticating a much larger number
Hi Team, Currently we are running FG-1500D in HA & we have purchased FG-1000F in HA.Using Forti Converter we are planning migrate config file from FG-1500D to FG-1000F, having below few queries:Will FortiConverter migrate all the configration like VDOM, IPSec Tunnel, HA, etc…. Source fortigate (FG-1500D) config file includes HA setting, while restoring config file to target fortigate (FG-1000F), can we restore the config into standalone fortigate? Any the steps we have to take into consideration while performing migration?
Unable to connect to FortiGuard servers.
Hi all,We're migrating a FortiGate-80F to FortiOS 8, and as part of this we need to move our remote VPN access from SSL-VPN to IPsec/IKEv2. Our affected fleet is 50 workstations running Linux/Ubuntu 22.04.The free FortiClient VPN edition on Linux doesn't support IPsec/IKEv2 (only the licensed FortiClient Standalone edition does, as far as we understand), so we're evaluating FortiClient Standalone.We're trying to figure out the licensing requirements for:- FortiClient on Ubuntu 22.04, establishing an IPsec/IKEv2 tunnel to a FortiGate 80F;- Authentication using the FortiGate's local user accounts (not a remote/cloud identity source);- 50 Linux users.A few open questions, in case anyone here has hands-on experience:1. Does FortiClient Standalone on Linux fully support IPsec/IKEv2 VPN tunnels to a FortiGate, and is this supported when using the FortiGate's own local user accounts for authentication (rather than a remote/cloud identity source)? 2. According to the FortiClient Standalone Use
Hello,I am facing an error code to a random number of windows hosts (approximately 30/400 windows 11 home & windows 11 pro devices).The mentioned devices has recently appeared in the state " Running (OS settings outdated" and the error code is "OS settings outdated". I have tried to reload & uninstall and re install the collector with no luck. The collector version is 5.2.6.0065.Any ideas will be helpful in order to further troubleshoot the issue.BR
Hello!I just recently downloaded the Hyper-V image for FortiGate-VM, version 8.The VM boots fine, no issues, the CLI is accessible through SSH.When comes time to apply the evaluation license, it seems to fail (using the “exec vm-license-options” command).On the Web GUI, the evaluation license seems to apply (by logging in with my Fortinet account) but after a reboot, it says “No License” in the system status.Then, in the Web GUI, I login, briefly see the “what’s new” video pop up and then it pops back to the login screen.Any ideas?Thanks!EDIT: I forgot to add that when running “exec vm-license” it requires a token, which I do not have.
This update covers four connector releases. Microsoft SharePoint is rebuilt on the Microsoft Graph API as a major version, Microsoft Graph Mail widens what it can do with mailboxes and calendars, and Fortinet FortiAuthenticator and Splunk each add a new capability. The table at the end links each release to its listing on the Content Hub, where you can review the full release notes.Fortinet FortiAuthenticator v1.1.0 adds an Execute an API Request action, with a corresponding playbook. Microsoft Graph Mail v2.0.0 adds an Email Address configuration parameter and extends the mailbox actions. Get Unread Emails and Search Emails now extract additional email headers, parse content from .eml and .msg attachments, and handle inline Base64 content so that it renders correctly in FortiSOAR. Send Email and Send Mail as Reply support inline images, and the data ingestion playbooks are simplified because the connector actions now handle EML and MSG extraction. New actions cover marking email as re
Hello Fortinet Community,I have an HA cluster with two FortiGate 1800F units FortiOS v7.6.7. The primary and secondary are communicating, but the HA status shows Not Synchronized because the wireless-controller.wtp-profile table is out of sync.I would like to understand why this specific WTP profile table is not synchronizing between the HA members and whether there is a way to resolve the synchronization issue without manually restoring or copying the entire primary configuration to the secondary.Also, does the wireless-controller.wtp-profile table have any special behavior in HA that would prevent or delay synchronization?Any guidance on the root cause and the safest way to bring the HA pair back into sync without manually restoring the primary configuration would be appreciated.
Hello,Has anyone experienced an Internet access issue after upgrading FortiProxy from version 7.4.9 to a 7.6.x version?We are currently facing the following situation:FortiProxy 7.4.9: Internet access works normally. After upgrading to 7.6.x, Internet access is no longer available (only fortinet domain). We reproduced the issue on a new FortiProxy VM running 7.6.7. We also tested with a clean configuration, using a simple policie. The issue persists.In our case, any version newer than 7.4.9 that we have tested results in the loss of Internet access.Has anyone encountered a similar behavior when upgrading from 7.4.9 to 7.6.x?If so, were any specific configuration changes required, or is there a known issue related to this upgrade path?Any feedback or experience would be greatly appreciated.Thank you.
Hi everyone,Today, I upgraded two FortiGate units in an active-passive HA setup from 7.6.6 to 7.6.7.After the upgrade, I tested HA failover and noticed that the secondary IP did not move to the passive FortiGate as expected.When I downgraded back to 7.6.6, everything worked normally again.Has anyone experienced a similar issue with FortiOS 7.6.7? If so, is there any known fix or workaround?Thanks!
Hello, I am testing dynamic MAP-E connectivity on a FortiGate-100F running FortiOS 8.0.0 build 0167. The Internet service is So-net over the NTT East FLET'S network in Japan. The VNE service appears to be JPIX “v6 Plus.” DHCPv6-PD is working. The FortiGate receives a /56 delegated prefix and the WAN interface receives an IPv6 address derived from that prefix. The relevant WAN configuration is: config system interface edit "x1" set mode dhcp set role wan config ipv6 set ip6-mode delegated set dhcp6-prefix-delegation enable set ip6-delegated-prefix-iaid 1 set ip6-upstream-interface "x1" set ip6-subnet ::1/64 config dhcp6-iapd-list edit 1 set prefix-hint ::/56 next end end nextend After applying this configuration, the VNE diagnostic correctly recognizes the delegated prefix and WAN IPv6 address: end user ipv6 prefix: 240b:10:xx
Hi all, I was looking at quoting the ADOM Subscription License for FortiManager S-Series, but noticed it’s no longer in the current price book and is marked: “End of Order Announcement – Will be removed from 2026 Q3 pricelist.”Does anyone know if this means FortiManager S-Series no longer needs a separate licence for additional ADOMs?If that’s the case, what is the maximum number of ADOMs supported now?Just trying to work out whether the licensing model has changed or if there’s a replacement SKU I should be using.Thanks.
I try to build VPN remote access using ipsec to preparing upgrade my fortigate production from 7.2 to 7.6 on my lab.My fortigate lab use version 7.6.4 and after i create vpn tunnel, the forti client is connected and get the ip address but the client is not able to reach to anywhere. The firewall policy and static routing was working fine.Open case to the fortigate support and they also feel strange with this issue. Someone here can help how to toubleshoot?Here my VPN config===========================config vpn ipsec phase1-interfaceedit "VPN-RA"set type dynamicset interface "port1"set ike-version 2set peertype anyset net-device disableset mode-cfg enableset proposal aes128-sha1set add-route disableset comments "VPN Remote Access"set dhgrp 5 20set wizard-type dialup-forticlientset transport autoset fortinet-esp enableset ipv4-start-ip 10.64.200.20set ipv4-end-ip 10.64.200.50set dns-mode autoset save-password enableset client-auto-negotiate enableset client-keep-alive enableset psksecret
I've noticed an extremely strange thing upon upgrading some test FortiGates to the new version 7.6.7: the upgrade goes fine, and the FortiGate is happily online and is routing/firewalling-just fine. However, when trying to load the GUI it is just a blank page.I can see the little favicon loading for the FortiGate login page, but its just blank otherwise. I can SSH in just fine, so that is good. I do not see any settings reset in global settings, and strangely going to the http login instead of https sometimes works (I have https redirect turned on).As the FortiGate seems to be perfectly fine otherwise, I thought I'd see if anyone else has experienced this?Also I have tried multiple browsers with privacy/incognito mode on, so I don't think it is a cache issue.
For cost tracking purpose then i need to capture how much data transferred (in and out) from my onprem to the azure and vice versa. Can we capture it from tunnel interface? If yes then can i know how?
Hello,I am consistently unable to activate my FortiGate VM evaluation license,despite multiple attempts using different versions andconfirmed network connectivity. License information:- Serial number: FGVMEVKLM66LZP57- Type: VM (KVM) evaluation license Versions tested:- FortiGate-VM64-KVM v7.4.12, build 2902 (GA.M)- FortiGate-VM64-KVM v8.0.0, build 0167 (GA.F) Observed symptoms:- The “execute vm-license” command (permanent trial) runs normally, prompts for confirmation, reboots the system, but then fails with: “curl forticare failed, 28” / “Failed to download VM license.”- The output of “get system status” consistently displays: Serial-Number: FGVM00UNLICENSED License Status: No License / Invalid Diagnostics already performed:- Internet connectivity confirmed (pings to 8.8.8.8 and 1.1.1.1 are working, 0% packet loss)- DNS resolution working (resolution of fortiguard.com confirmed)- Network capture (diagnostic packet sniffer on port 1 ‘TCP port 443’) showing a complete TCP handsha
Hello,I took the recertification assessment. I completed the course and passed the exam, but my certificates have not been updated. It shows that they are set to expire on September 21.What should I do?Thank you for your help.Best regards,
https://cybersecuritynews.com/hackers-selling-fortinet-fortigate-1-day-vulnerability/Do we know if there's any truth behind this claim?
Hi all,Independent security researcher here (published CISA advisories, ICS/OT focus). I'm building out a local lab with various Fortinet VM images for firmware analysis and vulnerability research.I've been able to pull FortiGate, FortiAnalyzer, FortiManager, FortiADC, FortiWeb, and FortiFirewall KVM images through the standard support portal with a basic FortiCare account. However, I'm hitting a wall on products that require an active support contract to download:- FortiProxy (FPX_KVM)- FortiMail (FML_VM64_KVM)- FortiSandbox (FSA_KVM)- FortiSIEM- FortiNDR- FortiDDoS-FA few questions for the community:1. Is there an evaluation or researcher program that provides access to VM images for these products? I've looked at FNDN but haven't dug deep enough yet.2. For anyone doing RE on FortiProxy or FortiMail specifically - where did you start? Any recommended tooling, known filesystem structures, or resources (Fortinet Gurus, writeups, etc.)?3. Has anyone used the FortiSandbox or FortiSIEM KV
This was working fine until I upgraded the firmware to v8.0.0 B0167. It’s an IKEv1 using 3DES/SHA1 both phases. Now this one particular node will not connect. ike V=root:0:IPSec2xxxx:IPSec2xxxx: IPsec SA connect 5 xxx.xxx.xxx.xxx->xxx.xxx.xxx.xxxike V=root:0:IPSec2xxxx: ignoring request to establish IPsec SA, no policy configured
Hi Everyone,We have a predefined list of company-owned MAC addresses. We want FortiNAC to classify devices whose MAC addresses are in this list as Company Devices, while devices whose MAC addresses are not in the list should be classified as Personal/BYOD Devices.After classifying the devices into these two groups, we would like to apply different compliance policies to each group based on their device ownership. What is the recommended way to implement this in FortiNAC 7.6.x?
Dear Community Team,Could you please confirm the current Product Lifecycle status of the FortiSwitch FS-124F-POE?Specifically, I would like to confirm: Has an End of Order (EOO) date been officially announced for the FS-124F-POE? Has an End of Support (EOS) date been officially announced for this model? Based on Fortinet's current Product Life Cycle Policy, what is the expected remaining technical support period for the FS-124F-POE, and will technical support, FortiCare services, firmware updates, and security fixes remain available for at least the next three years? Is there any official Fortinet document confirming the above lifecycle and support period? The units under consideration are FS-124F-POE manufactured in 2025.I would appreciate an official confirmation and, if available, a link to the relevant Fortinet Product Lifecycle documentation.Best regards,
We are trying DOT1x auth via AD user .Endpoint going in dot1x process and Cisco Switch forward the request to Fortinac but the authentication process is not completing .Continuously showing “RADIUS not enabled on device”.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.