Mark a Best Answer
Fortinet Community
Recently active
Hello,We are using a FortiGate device integrated with a Kubernetes Connector. The system was working properly on FortiOS 7.2.12, but after upgrading to 7.4.11, we started experiencing the following issues:SDN Connector errors The following errors are observed in the GUI: Invalid SDN filter: K8S label node.kubernetes.io/exclude-from-external-load-balancers Invalid SDN filter: K8S label node-role.kubernetes.io/control-planeWe are experiencing 504 Gateway Timeout errors on outbound traffic to servers running behind Kubernetes. Based on checks performed on the Kubernetes side: There is a noticeable latency/performance degradation in the environment However, after downgrading back to FortiOS 7.2.12, these issues are no longer observed. Therefore, we suspect that the 504 errors and performance degradation are related to FortiOS 7.4.11.Rollback result After downgrading back to 7.2.12: All issues are resolved Kubernetes services are reachable again SDN connector errors disappear.Additionally;D
Hey everyone,We’re getting ready to deploy a new site and I’m looking for some guidance on choosing the right FortiGate model.Environment details:~300 users8 FortiSwitches over FortiLinkPlanning to enable SSL Deep InspectionUsing full security profiles (IPS, AV, App Control, Web Filter, etc.)Average traffic mix: Office 365, web browsing, VPN, internal appsAverage of 25,000–30,000 concurrent sessionsI know deep inspection significantly reduces throughput, so I want to size the appliance properly to avoid bottlenecks once everything goes live.For anyone who has deployed FortiGate models in similar environments, which model would you recommend?Any real‑world performance insights or warnings are also appreciated!Thanks!
Hello, We have 3 Management IPs configured for a Fortigate device. Only one is polling on Solarwinds, 2 are failing with SNMP. MGMT-01 is .227 and MGMT-02 is .226 Here are the trace results (omitted and edited some characters): id=65308 trace_id=21 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=17, 10.x.x.88:62985->10.x.x.227:161) tun_id=10.0.0.2 from MGMT-02. "id=65308 trace_id=21 func=init_ip_session_common line=5995 msg="allocate a new session-08f7faa3"id=65308 trace_id=21 func=iprope_dnat_check line=5276 msg="in-[MGMT-02], out-[]"id=65308 trace_id=21 func=iprope_dnat_tree_check line=834 msg="len=0"id=65308 trace_id=21 func=iprope_dnat_check line=5288 msg="result: skb_flags-02000008, vid-0, ret-no-match, act-accept, flag-00000000"id=65308 trace_id=21 func=vf_ip_route_input_common line=2611 msg="find a route: flag=80000000 gw-10.x.x.227 via root"id=65308 trace_id=21 func=iprope_access_proxy_check line=439 msg="in-[MGMT-02], out-[],
I am using MDaemon as my Email host behind fortigate 100f. I am able to connect to my mdaemon server using webmail as well as outlook desktop however facing issues with outlook android. I am able to sync imap emails but unable to send email from outlook android. all recommended ports are open and accessible from outside. what could be the reason fortigate blocking outlook android traffic and how can I solve this step by step. urgent response will be appreciated. (Note: All ports are open, SSL configured and working, webmail and outlook desktop working fine even adding accounts in Gmail is working fine).Only outlook android not sending mail say "error sending mail please try again"
Hello, I am having difficulty to understanding how the captive portal works with LDAP authentication with FortiNAC, as I could not find any clear documentation for this.Could anyone help me understand the workflow and the steps involved in user authentication using LDAP?So far, I have completed the following steps, but it is not working:Configured LDAP integration — it appears to be workingChanged the standard user login method to LDAP.I am not sure if there are any additional steps required. later testing I was able to resolve the issue with help from the community.What I did:I initially added LDAP to FortiNAC and configured the standard user login type to use LDAP. However, that alone was not sufficient. Winbind is also required—without it, the setup does not function properly.Key Notes:Ensure FortiNAC is added as a computer object in Active Directory.If you are using an LDAP group for GUI administrator access, delete and recreate the LDAP user group with administrator priv
Dear Team,One of our customer upgraded the FortiClient version from 7.4.3 to 7.4.5 which is managed by EMS.After that most of the users facing to connect the VPN.By default, the FortiClient installer contains 9 VPN URLs or Gateway defined in EMS.When the user tried to connect any of the VPN gateway by clicking 'connect' button it does not react anything.For some users, the issue resolved by reinstalling the FortiClient, Re-register the zero trust telemetry with invitation code, restarting the laptop and connecting to different Wifi or network.For few users, did not helped any of the above workaround.From the user machine we collected the FortiClient log and found below logs.Could any one help with below logs to sort out the issue.sslvpndaemon_1.log[2026-04-07 08:36:49.9130356 UTC+02:00] [10616:6788] [sslvpndaemon 285 debug] TunnelInitiator::StartConnection() called.[2026-04-07 08:36:49.9134374 UTC+02:00] [10616:6788] [sslvpndaemon 287 debug] TunnelInitiator::StartConnection() tunnel: &
HiIm trying to connect two core switches to out Fortigates that running in HAThe Fortigates have been running for 3 years together with some old Alcatel Lucent switches, and now I want to upgrade to FortiSwitchThis is my setup. Best RegardsThomas
Hello, I am trying to convert incoming port 22 to 2222 with a VIP rule. However I want to keep the same external and internal IP address. The VIP will not accept this.Is there any way to only convert incoming ports with the same address ?
Hi everyone,I’m currently trying to connect to an older FortiGate device (FortiOS 5.4), so I need to use an older version of FortiClient (6.0 or 6.2).Since the device is EOL, I’m unable to download the installer from the official Fortinet support portal. I managed to get the 6.2 online installer, but it fails during installation with errors related to an invalid digital signature and MSI error code 2711.Would anyone be able to share a FortiClient VPN 6.0 or 6.2 offline installer (full package) or point me to a reliable source?I would really appreciate your help.Thanks in advance!
How do i find the status of All VPNs in FortiAnalyzer ?
Hello Fortinet Community, I would like to inquire whether it is possible to implement a VPN chaining (nested VPN) scenario using FortiClient. Use case:We have a requirement where access to a client VPN is restricted to a specific public IP address (e.g., 193.40.X.X). When connecting from our office network, we are able to access the client VPN successfully because our traffic originates from this whitelisted IP. However, we would like to achieve the following setup: Connect from a remote location (home) to our office VPN using FortiClient.Once connected, establish a second VPN connection (also via FortiClient) to the client environment.Ensure that the second VPN connection is seen as originating from the office public IP (193.40.X.X). Questions: Does FortiClient support running multiple VPN tunnels simultaneously (VPN over VPN / nested VPN)?Are there any supported configurations or best practices to achieve this setup?Are there specific requirements (e.g.,
When using the ACME client in FortiWeb v8, does it automatically re-use the same private/public key for renewals? or does it issue a new key on each renewal?
In FortiAnalyzer, I have one ADOM with 200 firewalls and another ADOM with 5 firewalls, but on all the firewalls regardless of the ADOM, I can't see the logs in security events > WebFilter, for example, only from memory.Also, in FortiAnalyzer, in FortiView the tabs Traffic, Shadow IT, Applications and Websites, VPN, and System are grayed out, making it impossible to select them.Could this be a license issue or some configuration parameter?
I have just acquired a fg60e, i realise it's end of life but i plan on using it just for learning firewalls, vlans etc so don't need full licence for extras, i plan on doing cisco & fortinet free courses to understand more about networking & security.Tonight i have got it setup & connected to the internet & noticed it's running fw v 6.0.3, i realise it's old but in your opinions would this be adequate for learning the basics of fortinet OS or can you suggest a more up to date stable fw version.
We have just migrated to FortiClient EMS 7.4.5 LinuxVM from FortiClient 7.2.12 WindowsVM. In that process we are trying to move from Active Directory to Microsoft Entra for controlling Manage Deployments. While deployments are working fine from the Active Directory side, the issue we are seeing is that Windows devices from the Entra side are not and showing "Unsupported Operating System"All these devices are Windows and have been onboard from Intune and as this is a hybrid environment. The same device works fine on the Active Directory side.I am sure I am missing something, but I have been through it a few times and I can see nothing wrong from the setup documents.Anyone have any idea what I am missing?
Hi Everyone.I have a customer who has a FGT 80E with full UTM features. The main web policy has Web Filtering, IPS, AV and SSL inspection Security Profiles assigned. The end users are reporting that randomly they will get redirected to gstatic.com/generate_204. Looking the browser history under gstatic.com/generate_204 it references "Fortinet DNS Service" which made me wonder if it was one of the Security Profiles causing the issue. I removed all profiles from the web rule and the issue still occurred. I then came across this KB (https://kb.fortinet.com/kb/documentLink.do?externalID=FD36680) regarding QUIC (Quick UDP Internet Connections) and as the customer had reported that the issue was with Google Chrome, I asked them to implement Method 1 from the KB on a machine that was experiencing the issue. Unfortunately this did not resolve the issue. I have looked at the logs on the FGT and there is nothing there to help me. I am not convinced its a FGT issue (although the r
I have a question regarding the Web Filter Function.Currently, I have enabled the Web Filter Function by configuring "certificate-inspection" as the SSL inspection.However, because the FortiGate certificate has not been manually imported to the client PCs, a certificate error screen is displayed when communication is blocked.Therefore, I have configured the following settings to prevent the alternative message screen from being displayed:[Settings]config web-proxy explicit set https-replacement-message disableend Since the connecting client PCs are numerous and unspecified, I do not want to manually import certificates individually.I would like to display an alternative message screen instead of a certificate error when communication is blocked.If there is a way to achieve this, could you please advise me?
Hi Fortigate,My fotigate is 7.2.11 build 1740.I understand 7.2 is out of support in September. How do we upgrade from 7.2 to 7.4?regardsJohn Zen@@
Hi All, I have doubt if we can achieve below requirement. Fortigate integrate with Clearpass/ISE for ZTNA authentication , but the user identity is at Entra ID(no local AD). I knew that Fortigate can direct integrate with Entra ID using SAML, but client insist to use Clearpass/ISE as authentication server(lets not challenge client why at this moment). Flow should be ZTNA Client > Fortigate > Clearpass/ISE > Entra ID Question : Can this be done ? Or can i say this can be only done if FortiAuthenticator is used instead of Clearpass/ISE ?
Hello,I've deployed policies from my FMG to my FG, and although the deployment was successful, the changes aren't “visible” on the FortiGate.Is this normal?I'm working in a lab environment where my FMG is running version 7.41 and my FG is running version 7.2.5.Cheers :)
Can Site-to-Site VPN between HQ and a Branch be implemented with overlapping subnets? In this case, four subnets are going to be used at each site. Therefore, I would like to know if overlapping works fine for more than one single subnet. Thanks.
do the fortiswitch's support stacking ? i am speaking of traditional stacking where all switch are managed via single ip address and I can configure ports from any stack member thru a single mgmt ip . what about stacking bandwidth? do we have any dedicated stacking ports or is everything done thru the ports on the front of the switch? example if i have a 3 x 24 port 1G copper switch with no uplink ports how would i stack these 3 switches? Is daisy chain my only option?
Hello, I'm running FortiManager-VM64-KVM v7.4.10 build2278.I was wondering how to create an correlation handler event to trigger for when a specific account logs into FortiManager. I've tried getting it to work from this log entry (FortiManager > System Settings > Event Logs), but it's not triggering the event even though the account successfully logs in. 2026-03-31 08:18:00 tz="+0100" log_id=0001010018 type=event subtype=system pri=information desc="User login/logout successful" user="myuser@domain.com" userfrom="SSO(IP_address)" msg="User 'myuser@domain.com' (myuser@domain.com) with profile 'Super_User' login accepted from SSO(IP_address)." adom="root" adom_oid=0 session_id=62498 operation="login" performed_on="SSO(IP_address)" changes="'myuser@domain.com' login accepted from SSO(IP_address)" adminprof="Super_User"Does anyone have a template for this to work?
Based on this article herehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602 I know you've tried more than once to make the tunnel up with IKEv2 and with LDAP Authentication and it didn't work. First I would like to thank to my friend @Mohamedh219 for his amazing effort getting such article Here is a solution that worked out with me based on this Japanese article:https://licensecounter.jp/engineer-voice/blog/articles/20260331_fortigate_ipsec_vpnikev2_-_ldapforticlient_vpn_-.html All you have to do is enabling the transport protocol to be using TCP instead of UDP for the tunnel's configuration, and set the ike tcp port to a port that you're 100% sure it's opened by the ISPs (for example 443 which is used for web browsing) .. Check image below Also from the FortiClient perspective .. go to the VPN settings for the configured IPSEC VPN .. Go to Advanced settings under p
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.