Mark a Best Answer
Fortinet Community
Recently active
"Thank you all for your responses.Following up with additional questions:When is FortiOS 8.0 expected to be officially released for FortiGate hardware?Which FortiGate models will be supported?Will this upgrade have any impact on connected FortiSwitch and FortiAP devices? Will they require firmware updates as well?Thanks in advance
Hello everyone, I would like to know what's the network's behaviour when FortiNAC is down (unrecheable) or doing a firmware upgrade ? Are the users stuck in the isolation VLAN or the behaviour is as if FortiNAC never existed ? Is FNAC 7.2.7 version stable, or should I upgrade to the latest versions 7.6.x ? BR,
Environment DetailsModel: FortiGate-VM (KVM)Firmware Version: 7.2.11Hypervisor: KVM (QEMU/Libvirt)Setup: Standard LAN-to-WAN routingProblem DescriptionI am experiencing a recurring issue where LAN-to-WAN connectivity functions perfectly upon initial configuration but fails consistently following a system reboot.Symptoms include:FortiGuard Disconnect: The dashboard shows a "Time Sync Error" or "Unable to connect to FortiGuard."Traffic Interruption: LAN users lose the ability to route traffic to the WAN.DNS Failures: DNS resolution via FortiGuard or system servers fails.Troubleshooting PerformedVerified basic firewall policies and static routes (all appear correct).Confirmed that the issue specifically triggers after a reboot.Attempted to manually set the time, but the error persists or returns. RegardsSantosh
Two new Outbreak Response Solution Packs address emerging threats, including Interlock ransomware, a modern double-extortion malware targeting both Windows and Linux environments with data theft and encryption capabilities, and Iran-linked cyber operations, which continue to leverage coordinated campaigns and evolving tactics to disrupt organizations and exploit exposed attack surfaces. In addition, the new and improved ANY.RUN Cloud Sandbox enhances dynamic malware analysis by enabling analysts to safely detonate and observe suspicious files and URLs in an interactive environment, accelerating threat validation and response. Together, these updates improve readiness against active threat campaigns while strengthening analysis depth and response speed within security operations. The following table summarizes the progress we have made since the last announcement. # Type Name 1 Solution Pack Outbreak Response - Interlock Ransomware Attack v1.0.0 [Doc]
Hello!I have recently begun to use FortiGate 7.2.13 for a school project and I might need some help.I want to create a policy on the GUI that blocks zip-files but so far I have not managed to get it to block any zip-files I download. I would really appreciate some help in any way for this problem, and if I need to upload more information regarding this please let me know.
If the device authenticated based on Entra ID using Captive Portal, then can we assign the vlan based on the Entra Group?
Centralized Control: Adding Remote FortiGate firewall to FortiManager In this video, we dive into the specifics of FortiGate SDWAN and demonstrate how to integrate your FortiGate devices with FortiManager. We cover the entire fortinet configuration process, ensuring a smooth setup for your network management. This guide is perfect for anyone looking to optimize their fortinet firewall setup within an SD-WAN environment. https://youtu.be/jw84ZuOn8zw
Hi everyone! I've been reading some articles and guides. But I am still not confident with what I have gathered. So I would like to kindly ask your experiences on proper setting up of HA for 100F (or any model if applicable)Long story short we will just reuse 2x 100Fs from one of our site which has been decommissioned to a new existing site. This is my plan: 1. Turn on Firewall-A2. Factory reset the firewall.3. Configure management interface IP via CLI4. Once reachable via GUI, configure the HA (mode, priority, group ID, group name, password, heartbeat interfaces, heartbeat interfaces priority, mgmt interface reservation and gateway)5. Save, turn off the firewall A.6. Turn on Firewall-B. Repeat all the steps above.7. Turn off firewall-B.8. Connect the HA1 interfaces of the cluster units together9. Connect the HA2 interfaces of the cluster units together10. Power on both of the FortiGates11. configure everything in the cluster as if it is a
Te lo dejo mejorado para foro (más claro, técnico y natural :backhand_index_pointing_down::(Hi all,I’m working on a Hub-and-Spoke IPsec VPN setup where the Spoke site is using a FortiExtender (LTE) as the WAN interface.I would like to know if there are any special considerations or required configurations when using a FortiExtender on the Spoke side.Currently, I’m facing the following error:"fext_wan IP is 0"It seems related to the LTE interface, which is expected to obtain its IP dynamically. Thanks in advance.
Hi.Here we are looking for a replacement of our working firewall 1200D model.last few days based on my firewall performance details• Inbound Traffic: 2.12 Gbps• Outbound Traffic: 1.1 Gbps• CPU Utilization: 12%• Memory Utilization: 47%• Session Rate: 91 sessions/sec• Concurrent Sessions: 88,562, New Sessions 1000+• HA A-A (Active to Active)• Firewall Policies: 245In this performance-based context, can you give me the best suggestions for which model I replaced it with?Note: Last year's renewal purchased the FortiCare Premium Package. This is based on the firewall running.
Hello,We are using a FortiGate with explicit proxy. It forwards requests to an upstream proxy.How can I exclude certain URLs so that they are not sent to the upstream proxy, but instead the FortiGate establishes the connection directly?I tried using the URL match list, but the FortiGate still sends the requests to the upstream proxy. We are on version 7.4.11
I have are two Fortigate firewall between model 50G and 50G-WIFI. Also use SD-WAN to created dual internet and its through SD-SLA mark the auto fail-over. In my case has an interesting problem occurred:***also use the same as police & static route Model 50G-WIFI:SD-WAN member: VPN_01, VPN_02 => enableWan, A=>enable that are two VPN tunnel & internet service also work as well.===============================Model 50G:SD-WAN member:VPN_01, VPN_02 =>enableWan, A=>enableVPN with Phase1 =>lost====SD-WAN member:VPN_01, VPN_02 =>enableWan, A=>disableVPN service work as normal====SD-WAN member:VPN_01, VPN_02 =>enableVPN service work as normal, internet service not workingas above case problem, how can to resolve it?
在 Fortinet 的 SASE 解决方案中,我看到主组件 FortiSASE 拥有自己的控制平台,也称为 FortiSASE,可用于管理 FortiGate、SD-WAN 等设备。我还注意到 FortiManager 也包含在 Fortinet SASE 解决方案中。FortiManager 是否也提供自己的控制台界面?它和 FortiSASE 控制台有什么区别?FortiSASE是否提供对设备本身(例如交换机)的配置控制?据我所知,FortiSASE可以配置和管理FortiGate设备。您的客户目前在部署 Fortinet SASE 解决方案时,主要使用 FortiSASE 控制台还是 FortiManager?
I'm unable to activate my trial license with my email address jmujica@outlook.com, I have an trial license assigned but unable to reuse the license
Hi everyone! We have an existing FG 501E which we'll be decommissioning in a few weeks. We plan on replacing it with FG 100F. In order to lessen the risk and errors, I plan on backing up the old firewall config and just restore it to a newly factory-reset FG100F.However, our existing 501E has Global, and 2 vdoms(including root). On the 100F, we plan on NOT using a vdom. Just put everything in global configuration. Question:1. Is it possible to backup and restore this properly?2. Is it possible to not use a VDOM and just put everything in global config?
This is the most frustrating experience that I ever had with a 30day eval license registration. My customer wants to evaluate Fortigate against another solution and I can't create a PoC without using 1vCPU and a 2GB ram?I have registered the license and the instance still requires a licenseDescriptionPartnerProduct ModelFortiGate VM TrialRegistration Date2026-04-03Lost more than 2 hours as the documentation is not clear (does not even have a link on what is the portal to create a user on how to get a 30 day license - I actually need it for a week)
How can I avoid issues with security profiles after the license expires?Web filter, IPS, DNS filter Is there a way for them to work offline without updating?
I'm using clearpass accounting with rsso to a fortigate 200g using aruba wifi. also have intrium updates enabled on clearpass.Athentications are working and RSSO is picked up correctly on the firewall however when roaming between access points I am prompted for captive portal. The connection doesnt drop and im using fast roaming on the wifi which would say its a firewall issue any settings to tweak on the firewall so it doesnt distrupt roaming.?
I installed FortiClient EPP/APT Edition for testing purposes, but I am now unable to uninstall it from my system.When I try to uninstall it from Control Panel → Programs and Features, the uninstaller only shows a Repair option and does not provide an option to uninstall.I also attempted to resolve this by downloading the FortiClient removal tool from the Fortinet Support Portal. However, I am facing issues there as well.When I navigate to:Support → Firmware Download → Product SelectionI encounter the following message:"Sorry, you don't have any product covered by a Fortinet support contract."Additionally, the product selection button is not working, so I am unable to select any firmware image or proceed further.For context:I downloaded FortiClient EPP/APT Edition(windows) online for testingI do not have a serial number or active support contractThe uninstall option is not available (only repair is shown)FortiClient #Windows #Uninstall #EPP/APT
Hello,I would like to understand the behavior of the network when FortiNAC becomes unreachable or stops (service down).In this scenario:What happens to the access ports on the switches?Do they fall back to the default VLAN automatically?Are already authenticated endpoints still allowed to communicate, or are they impacted?Also:What are the best practices or recommendations to handle this situation?Is there a way to ensure continuity (fail-open vs fail-close behavior)?Any feedback or real-world experience would be appreciated.Thank you.
Hello everyone,I am working on implementing FortiClient 7.2.4 trial.I did import a web filter profile from our FortiGate and enabled ssl deep inspection. Now it does not seem that FortiClient EMS imports the SSL inspection certificate which is used from FortiGate (and trusted by the clients). I did not find any setting to let me control the certificate used for ssl deep inspection in FortiClient EMS... Anyone knowing where to set the certificate used for deep inspection in FortiClient EMS? Edit: Ok seems like forcing to install the FortiClient extension gets rid of invalid ssl certificate warnings. Is this the way to go then?But I still get certificate warnings when starting Outlook... So how do I set this up correctly?
Hi, we want to create a site-to-site VPN via Fortimanager, but don't want to enable VPN community. Is the following procedure correct? our Fortimanager os version is 7.4.x. 1. login to Fortimanager Device Group2. choose the firewall 3. click VPN and choose interface mode4. create phase 1 5. create phase 26. install the config via installation wizardCan anyone please help to advise? Thanks in advance!
I am testing the IPSEC tunnel with the ztna client (unfortunately there is no forticlient vpn under linux that supports IPSEC), and had trouble with https sites, so I want to add some info for other victims.Somehow my ethernet interface picked a MTU of 1280 instead of the 1500 default for ethernet. This caused that the MTU for the sites behind the VPN was 1170, so I could do a telnet to check that the port was open but couldn't open any site. Forcing the MTU on the ethernet to 1500 fixed the issue and now I can browse all the sites without issue.
Just curious, would it be too much to ask that we be given materials that we can actually highlight and make notes on when studying for the NSE Exams? I have a PDF for the self-paced NS4, but I can't modify this document with personal notes or annotate sections that I need to call out to myself.
Details:Could you kindly explain fml cloud working with an on-prem exchange server?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.