Mark a Best Answer
Fortinet Community
Recently active
Based on this article herehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602 I know you've tried more than once to make the tunnel up with IKEv2 and with LDAP Authentication and it didn't work. First I would like to thank to my friend @Mohamedh219 for his amazing effort getting such article Here is a solution that worked out with me based on this Japanese article:https://licensecounter.jp/engineer-voice/blog/articles/20260331_fortigate_ipsec_vpnikev2_-_ldapforticlient_vpn_-.html All you have to do is enabling the transport protocol to be using TCP instead of UDP for the tunnel's configuration, and set the ike tcp port to a port that you're 100% sure it's opened by the ISPs (for example 443 which is used for web browsing) .. Check image below Also from the FortiClient perspective .. go to the VPN settings for the configured IPSEC VPN .. Go to Advanced settings under p
We're setting up ZTNA and one of the hurdles we have run in to is file shares - currently we're mapping network drives to our local domain name (eg \\contoso.lan\Share)I've been able to verify share access via a specific server FQDN but when i try to set up "contoso.lan" as a FQDN address on the firewall (verified it appears in HOSTS file), access is lost which was expected. Contoso.lan resolves to the DCs and not the file share servers.I didn't find any documentation or examples for this specific scenario and scratching my head how I could get this to work.Has anyone run in to this or have any suggestions to look in to or try?
Hello,Does anyone have the official list of FortiGate models supported by FortiOS 8.0.0?Also looking for the recommended upgrade path to reach 8.0.0 from 7.0.x and 7.2.x.Thanks in advance.
I've a question regarding the Transparent proxy policy and Proxy-based inspection policy, since the Transparent proxy policy and the proxy-based policy are doing the same thing i mean the FortiGate buffering the traffic and the client communicate with the FortiGate and the FortiGate communicate with the remote server (2 Connections - Man in the middle topology) Why we use Transparent proxy then since the proxy-based inspection mode policy has the same function?
Hello everyone,I am currently experiencing an intermittent connectivity issue affecting multiple macOS devices in our environment.The devices connect successfully to the WiFi network through FortiAP units (mostly model 231K). However, after some time, they suddenly lose network connectivity and internet access, even though they still appear as connected.From the FortiGate perspective, the affected devices are still visible under the WiFi Clients list, but they are unable to pass traffic properly.We have already performed extensive troubleshooting, including:Reviewing logs and event records on the FortiGateOpening a ticket in TACTesting different configuration adjustments on the SSIDModifying FortiAP operational profiles and performance-related settingsDespite all these efforts, the issue persists.It is also important to highlight that this behavior has been observed across different MacBook models, which suggests it is not hardware-specific.Has anyone experienced a similar issue with m
Hi Team,We would like to highlight a recurring security concern we’ve observed across multiple FortiGate deployments and incident investigations.During the initial setup of FortiGate (FortiOS), the device allows login without a predefined password and prompts the user to set one. In practice, many users end up configuring very weak passwords such as:adminadmin@123P@sswordpass@123These passwords are already available in public leaked credential lists and are commonly used in brute-force attacks.In our recent investigations, we have seen multiple FortiGate firewalls get compromised due to weak admin passwords.Attackers were able to:1.Gain admin access2.Create full-access SSL VPN configurations3.Execute ransomware inside the networkWhen these incidents happen, most customers assume:“FortiGate firewall got hacked”However, the actual root cause is weak password configuration, not a product vulnerability.This creates a reputation issue where the product is blamed instead of the misconfigurat
I've followed the instructions in https://docs.fortinet.com/document/forticlient/7.2.0/new-features/792170/entra-id-integration-7-2-1 and ended up creating 2 separate Enterprise Applications where one was used to configure the Client Secret (for the Administration > Authentication Server), and the other was used for the SAML URLs (for User Management > SAML Configuration). While this works, and I am able to register FortiClients by authenticating against Entra ID, I wonder if I did it correctly. Could this have been a single Enterprise Application? Or if not, and they had to be separate, what is the Enterprise Application with the Client Secret used for?And what is the Enterprise Application with the SAML URLs used for? Also what is this?To configure the Azure tenant app for initiating passthrough (domain):Is this an alternative to registering an Entra ID user's endpoint to EMS using SAML (which is my goal)?
What is difference in kvm image
Hi everybody, Since a few days ago, when scanning with nmap, 2 ports appear as open:PORT STATE SERVICE53/tcp open domain dnsmasq 2.90113/tcp closed ident853/tcp open domain-s I run scanning regularly. I do not understand how this could happen. I am trying to close them but no success. I do not use Override authentication. If somebody could help, I would appreciate.Thank you @AEK@mpapisetty
Hi, I have an issue regarding a Forti 60F on which i tried doing a quick install that wasn't working. I deleted the task but later on, after trying a full Install Wizard, i realized it was blocked due to that one task i deleted (Blocked by session id(xxxx), task(xxxx)).Now that i have deleted the task, i can no longer do any install wizard as long as it is running.I looked up all of fortinet documentation and ran the commands on command line, but all the commands that could delete the task are no longer supported by Fortimanager 7.6.6Is there any other solution to stop the task completely, or recover it ?
Hi all,I currently have the following setup:FortiManager Cloud → FortiGate → FortiLink → FortiSwitchAll configuration is pushed via FortiManager templates.What would be the best practice to safely remove a FortiSwitch from the FortiGate in this scenario? Thanks.
HiI upgraded the 60F from version 7.0.5 to 7.2 three days ago. The system looks very promising but has a problem with a new feature in Log & Report. The "Summary" page in "System Events" and "Security Events" is blank - no data exists (it is not grayed out, only all tables are empty). When I go to the "Details" tab, all logs of individual modules are in place, regardless of whether I choose "FortigateCloud" or "Memory". I have a licensed version of "Standalone FortiGate Cloud account" - 1 year log retention.Can anyone, are there any specific requirements to run this function (maybe Fortianalizer?).Or is it an early version of the system bug?Does it work for someone?Thanx
FortiVPN client is compatible with MacOS Tahoe 26.4? I tried install but getting below error.
Hello team!!! Some time ago I asked some questions here about FGT-Entra ID synchronization using SAMLNow finally I could make it work with Fortinet Support.Just 1 question about this:When the user will be prompted to enter credentials again? I tried restarting the Client OS and the credentials were not asked, just were asked the first time I tried to navigate. Thanks in advance.Regards,Damián I just tes
Hello, in one of our branches we have this FG60F cluster and we have problems. It is a critical one, not more than 20 users but it is a warehouse with antennas and we need 24x7. Some months ago it entered in conserve mode and we dont really know what the people there did, but we had problems to get the HA working again. After that we deactivated IPS, SSL, etc. and some other memory issued configurations but at the end we updated the cluster to 7.4.5 and after that the memory usage in general was much lower. We checked and it was always between 50-55%. This morning it happened again and right now they are using the slave unit (we dont know yet what the guys did). I wanted to check System Events in Forticloud since we removed local logging but I dont see any information there for the master unit. Any suggestions? It seems crazy that we use a cluster and with this conserve mode issue we loose basically both FGs. Thanks!
Hi Team,I am currently using:-Device: FortiGate 60F-FortiOS Version: 6.4.6 build 1879 (GA)Current AP: FAP-221C (unstable / planning to replace)I would like to know:1. Which FortiAP models are fully compatible with FortiOS 6.4.6?2. Is WiFi 6 AP (like FAP-231F / FAP-234F) supported without issues?3. Will existing FortiAP profiles auto-apply to new AP?Environment:- Medium office- Using FortiGate as wireless controllerAny recommendations for stable AP models would be appreciated.
I am just looking for any insight and tips to focus on that don’t violate anyone’s NDAs. I have some practice exams that I have been spamming on Udemy. I note down anything I have no idea about and do a deep dive on it via YouTube, Google etc. just as much reading as I can to learn about the concept. Practice exams are scoring anywhere between 48-59% so not insanely far off the passing mark but definitely not in a position to sit for this exam (if I want to not lose my money and pass it on the first go). Any advice on GNS3 lab images that helped shore things up for you all or really any resources that helped you all dial in to get to a point where you were ready and passed the exam, please send them my way. Been playing in FortiGates for 6+ years for various outfits and I know I am close to really nailing this thing. There are just a lot of features in these things that I never touch because the customers I am working for aren’t using them. Honestly never really saw a customer use a Fo
So we finally pulled out the fortiwifi 40f that's been causing so much grief and replaced it with a consumer router that actually works and before binning the fortiwifi decided to factory reset, upgrade to latest firmware and see if a fortigate device can actually do something useful. First thing I noticed was it's now claiming to be on the 'Latest' update v7.0.12 and furthermore it won't do any firmware updates without a paid subscription (which is odd because it was running without a subscription prior to the resel and was always complaining about needing updates).Now since it is April Fools day I just wanted to clarify I'm not imagining this or misunderstanding something. Fortigate sells devices chock-full of security holes and withholds the fixes unless you pay in perpetuity for a subscription? Really? Or did the factory reset update to the latest stable version of the 7.0 branch and is merely refusing to update the major version? Which would be slightly more reasonable albei
Anybody doing any multiple ISPs with DHCP-PD for IPv6 and SD-WAN with failover and NATting on the fother PPPoE + DHCP-PD interface?Seems that 7.6.3 don't have NAT66 options (or I'm blind) and the "problem" is that my WAN/ppp interfaces don't have IPv6 IPs assigned from the PPPoE/DHCP and the gateways are the link-local FE80::1 IPsLooking for more/detail information to peruse on the FortiGate 7.6.x to configure... or is there a IPv6 "working group" I could join to assist in test case debugging?
Hello Hi Community, please I want to know if anyone has integrated misp feeds to Fortigate (I already have feeds for IP and URL from other sources) How can I consume this IOC from misp events.? Thank you! Regards.
Hi,Has Anyone deployed FortiDDoS in prevention mode? We will be switching the DDoS from Detection mode to prevention mode tomorrow. I have generated thresholds multiple times and now thresholds are not getting updated. SPP Profiles for DNS, NTP, ICMP, TCP and HTTP are applied after reviewing the Handbook. I'm seeing some drops in the incoming traffic against DNS data anomaly, DNS UDP Header anomaly, DNS query anomaly, DNS exploit anomaly. Should i uncheck these options in the field and then switch the mode of the DDoS? Any guide on how you guys worked your way toward switching from Detection to Prevention will be helpful.
I'm curious about how much of firewall throuput is consumed when UTM features are enabled. (IPS, AV, App Control, Web Filter) How much of a precentage from total firewall throughput consumes each feature ?
Good morning, when I try to install the program, it tells me that I must uninstall the current version. But the problem is that there is no program, no folder. I don't know what else to try. I tried with cdm or powershel and nothing worked either.
"Thank you all for your responses.Following up with additional questions:When is FortiOS 8.0 expected to be officially released for FortiGate hardware?Which FortiGate models will be supported?Will this upgrade have any impact on connected FortiSwitch and FortiAP devices? Will they require firmware updates as well?Thanks in advance
Hello everyone, I would like to know what's the network's behaviour when FortiNAC is down (unrecheable) or doing a firmware upgrade ? Are the users stuck in the isolation VLAN or the behaviour is as if FortiNAC never existed ? Is FNAC 7.2.7 version stable, or should I upgrade to the latest versions 7.6.x ? BR,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.