Mark a Best Answer
Fortinet Community
Recently active
Hello there,We have a couple of challenges in deploying FortiGate and FortiWeb on EVE-NG Community in the Lab. As you know, the current exam version is based on FortiOS 7.6 and this renewing is probably going to continue, which means we have to get ready for next versions. The problem is:1. When we download FortiGate 7.6.4 & 7.6.3, both version looks incompatible with EVE-NG on VMWare workstation (25H2 and 17.5) and Hyper-V. The former hangs in "Formating shared partition and the later hangs in a stage ahead (somewhere logging about IPS..... ). Some folks advised using V7.2.x or... . But, this is not the answer I'm looking for. Same problem with last to versions of Fortiweb. 2. As you all may knows, Fortinet has made changes in licensing policies. Reports says V7.6 needs a valid license even for lab setup. This makes the case a little complicated, because we could use a 2-months Eval license before. If your recommend is to raise a ticket and asking for Evaluation license,
Hello community , If I use certificate inspection in an SSL/SSH inspection policy, users don’t need to have the certificate installed on their machines for basic URL filtering. However, for blocked pages, will users see the block banner? I assume they won’t. In that case, I would need to install the certificate on their devices, right? If so, does that mean there’s no real benefit to using certificate inspection if you don’t want to install certificates on guest machines? please suggest. basically customer want filtering but with no certifcate install.
Hi,I use the FortiClient Single Sign-On Mobility Agent and I am facing an issue: FAC registers all user IP addresses.Let’s consider two users: one connected remotely through VPN and one connected from the corporate LAN. The home network IP address of the remote user overlaps with the IP address of the user in the corporate LAN. As a result, one of the users is removed from FortiGate/FAC with the following error:Internally logoff and removing FortiClient item 11024-HR.xxx.xxx:192.168.12.26 [xxx.xxx/j**bleep**h] (all IPs conflicting).I believe that during the initial FAC/EMS configuration I chose the option to register all IP addresses, but now I cannot find this setting. I am not sure whether I am simply overlooking it or whether it disappeared after an update.How should this be handled?Regards,Lukasz
Hello everyone,We are currently in the design phase of an ingress security architecture in AWS and have not implemented anything yet. We are seeking guidance, reference architectures, and best practices to help us design this correctly.Proposed Architecture (Under Consideration)Internet → External NLB (TLS pass-through) → FortiGate-VM instances (inspection layer) → Internal ALB → Web applicationsThe external NLB would be internet-facing and handle TCP/TLS pass-through (no SSL termination).Traffic would be forwarded to FortiGate-VM (NGFW) instances for inspection.After inspection, traffic would be sent to an internal ALB, which would perform:HTTPS terminationHost-based routing (e.g., app1.example.com, app2.example.com, etc.)The internal ALB would route traffic to backend targets (EKS / ECS / EC2).GoalsAt the FortiGate layer, we aim to:Apply web filtering policiesPerform deep SSL inspection (if feasible)Allow only clean/validated traffic to reach the internal ALBAllow specific domains, U
We have enabled the explicit proxy feature to forward traffic to an upstream proxy saas provider.Is it possible to also enable the Inline CASB to work as well to help direct traffic? As an example, I want to bypass the upstream proxy for all Azure/M365 traffic and go direct rather than to our upstream proxy provider.
i have been trying to get demo account for fortisoar i have not recieved any email It has been 4 days since when i applied for demo account .I tried multiple work Emails and multiple times still no response
Dear Fortinet Team,Thank you for considering my suggestion. I would like to request that Fortinet develop a software solution similar to (Cisco Packet Tracer), designed for network simulation and training purposes. Such a tool would be highly valuable for learners and professionals who want to practice and strengthen their networking skills in a safe, virtual environment.I appreciate your attention to this idea and hope it may contribute to future developments. Best regards, Spoiler (Highlight to read)How CanI Learning Forti Product ?How CanI Learning Forti Product ?
Hi,We recently released two Linux VMs (Ubuntu 24.04 LTS) to configure the EMS server and external DB Postgres. The architecture is EMS with standalone remote DB without Docker (as reported on the Fortinet official document).With this introduction, I'll explain that the problem we encountered occurred 10 days after completing the configuration.Suddenly, the EMS GUI was no longer usable, displaying an error 500 (see image below). Both VMs, the one hosting the EMS and the one hosting the external DB, were correctly reachable via SSH. As additional information, I'd like to point out that the EMS server and external DB are on the same network and there are no network devices in between them. Furthermore, the hardware resources of both VMs are oversized compared to Fortinet's minimum requirements, and during the error, we didn't detect any problems or resource spikes on the VMs (e.g., disk full or resource spikes).Since the error persisted, we first attempted to restart the systems in t
We are experiencing a problem on an endpoint managed through FortiClient EMS. The PC is running Windows 11 updated to the latest available build, and the latest FortiClient version compatible with EMS is installed. The malfunction concerns the Web Filter extension on Google Chrome: • Randomly, the FortiClient extension disappears from Chrome. • When the extension is missing, the user is no longer able to browse (traffic blocked). • After one or more reboots, the extension reappears automatically and browsing works again normally. Issue to Resolve: The FortiClient Web Filter extension on Chrome is being removed randomly, preventing browsing. After a reboot, the endpoint restores the extension by itself. We request support to identify the cause and provide a definitive solution.
hi there,need advice, and some helps for best setup to my needs.I just bought Fortigate FG-71G.this fortigate will manage:- 4 ISP: ISP_1, ISP_2, ISP_3, ISP_4. only ISP_1 and ISP_2 have public IP.- this fortigate will connect to another fortigate use VPN IPSEC via ISP_1 (backup with ISP_2) if ISP_1 down.- also will use VPN SSL use connection ISP_1, backup with ISP_2 if ISP_1 down. - 5 unit floor (each floor can't communicate each others, unless require different, (unit_A to Unit_E) with:1. unit_A- don't have access internet- can communicate with unit_B, with limited services.2. unit_B- will have access internet via ISP_4.- can communicate with unit_A, with limited services.- if some case ISP_4 down, it may use ISP_3 (configure/ switch manually)3. unit_C- will have access internet via ISP_4- need divide into 3 groups, but can access 1 shared printer.- each groups can't communicate each other (except to shared printer). shared printer will be connect to Active directory in same netwo
Hi, I'm looking to update the firewall to remediate vulnerabilities currently on FGT60F-FW-7.00
Hello TAC,We are replacing 2 × FS-424D core switches (FortiLink-managed, configured as an MC-LAG pair with ICL) with 2 × FS-424E.When we attempted to replace the first switch, all downstream switches and APs went offline.Can you confirm the correct replacement sequence for this scenario, and whether the new 424E switches must be pre-configured before connection or if they will automatically inherit configuration from FortiLink after joining the fabric?Thanks.
Hello,I have an issue which I cannot find a solution to. I installed FortiClient VPN, created connection, imported certificate, and allowed disk access. After entering credentials for VPN I get prompt "Fortitray application ask to use keychain type "System"" - there I need to enter admin credetials. If I enter admin creds 5+times it will connect.How to allow it permanently?Certificate is trusted, Fortitray is allowed everywhere I could find.Macbook Air 2020macOS Tahoe 26.1Forticlient VPN 7.4.3.6667Thank you for your help
fortinet 60f no internet issue. need reboot fortinet some time unble to get login page
After Adding Acces spoints to FortiNAC (by discovery using SNMP strings), i can't see the virtualized devices tab , why ??
When I go to connect to my VPN and type in my password, a dialog opens for me to put in a token from my fortitoken app on my phone. The box does not focus the input box for text though, so I have to manually click in. It is not apparent, as the password dialog focuses the password field immediatly. I have had to input another token multiple times because it keeps not typing when I want to type. Please fix this.
I’ve got a couple servers at different sites that need to synchronize data between them on a set schedule over an HTTP/2 connection across a VPN tunnel.I’m having an issue where it appears that the FortiGates are marking the sessions as timed out (evidenced by action in logs) despite traffic actively flowing across the tunnel.I tried increasing the TCP timers on rhe service object, changing the policy to proxy mode, and disabling asic offload, but it still appears to be having issues.I also tried a diag debug session list but never saw anything about what’s causing the timeout.Any ideas?
Hi Everyone, I would like to setup Dual WAN ports with a single IPSec tunnel for redundancy on FortiGate Firewall. To configure dual WAN ports with a single IPSec tunnel for redundancy on FortiGate, create two separate IPSec tunnels (one for each WAN) and use SD-WAN to manage failover. Set up identical phase 1 and 2 parameters for both, but configure the remote gateway IP, and ensure static routes or BGP routes are managed via the SD-WAN interface, allowing the tunnel to fail over seamlessly if one ISP fails. Key Configuration Steps:SD-WAN Setup: Add both WAN ports (e.g., WAN1, WAN2) to an SD-WAN zone.Create Two Tunnels: Create "Tunnel_to_ISP1" (interface: WAN1) and "Tunnel_to_ISP2" (interface: WAN2).Routing: Create static routes for the VPN traffic, setting the SD-WAN interface as the gateway.Redundancy: Configure Dead Peer Detection (DPD) to detect tunnel failures.Policies: Create firewall policies to all
Dear All, I have a site in hk with subnet 192.168.1.0/24 this site using fortigate 60E, and in hk sitei have a openvpn appliance access server running , and also one openvpn access server with ip 192.168.1.72, and also I have another site in china with subnet 192.168.12.0/24 and also using fortigate as a internet firewall, a site to site vpn built between hk and china, openvpn appliance access server created an user account and exported .ovpn and import to a window server as openvpn client and the window server with ip 192.168.12.90 also running rras with lan routing enabled, and in hk fortigate having static route 192.168.12.0/255.255.255.0 with gateway address 192.168.1.72, whenever traffic toward 192.168.12.0/24 its will route via 192.168.1.72 (the openvpn appliance access server), and in china, there is a esxi with ip 192.168.12.103 and fortigate 192.168.12.99, I found that I can ping and telnet 443 with esxi and for
Please help me block logs saved to the SSD. I'm referring to "Local Traffic" and entries that appear even 2-3 times per second. For now, I've disabled "Local Traffic" logging on the SSD, but I'd like to see traffic from Fortigate (e.g., to globalguardservice, NTP, etc.). The FG61E is in transparent mode, connected to the internet via the Local Interface.This large number of entries concerns local network connections from some devices. These entries include:Source=192.168.3.XX (LAN addresses)Destination=255.255.255.255 or 192.168.3.255Application Name="DHCP/DHCP Relay" or "udp/15600"Destination Interface=[object Object]Source Interface=internalHow can I block this, but still allow other connections, such as those to Fortigate servers and other services, to be visible?
Hi everyone, I need your help.I have a Fortinac device with 200 licenses. However, I've purchased an additional 100 licenses, which should total 300. However, this total isn't displayed in the Fortinet GUI; only 200 licenses are shown. The additional 100 licenses are visible in the Fortinet support section, where the device is registered. How can I make them appear in the GUI? I understand that the additional licenses should be displayed automatically.
In Administration - Deployment - Collector, there are two available options: “Update Collectors” and “Request Collector Installer.”For Collector (Agent) deployment, the correct option to use is “Request Collector Installer.” Through the Update Collectors section, you can update the agent version for the relevant operating system by selecting either a single collector group or multiple collector groups. When deploying a Collector, after selecting the operating system, you can choose either the current version (n) or the previous version (n-1).For server systems, using the n-1 version is generally the safer option.Parameter descriptionsAggregator Address = Refers to the main server in the data collection and transmission layer that centrally processes telemetry collected from endpoints and forwards it to the FortiEDR management console.Organization = Represents the tenant identity and indicates w
Good morning, team,I have been experiencing a recurring issue within my infrastructure for some time.I have already opened a case with TAC; however, no definitive solution has been provided so far.Currently, I manage an environment consisting of approximately seven FortiAnalyzers, each with an associated FortiAnalyzer Collector.Until September 2025, there were no issues within this topology. However, at a certain point, the environment began to exhibit unexpected behavior.FortiGates started losing log visibility across multiple features, including Traffic Forward, FortiView, and any other functionality that relies on logs sourced from the FortiAnalyzer.The issue initially affected several FortiGates connected to FortiAnalyzer 01. After several hours of troubleshooting, we identified that restarting the FortiAnalyzer Collector linked to FortiAnalyzer 01 would temporarily restore functionality, allowing logs to be displayed again on the FortiGates. However, this proved to be only a tempo
FortiManager 7.4.9 Free Trial managing FortiGate 100F on 7.4.9 Config status: Synchronized On FortiManager I've created a new IP reservation under IP Assignment Rules, device global DB status changes to modified, yet when I use the install wizard I'm unable to push the reservation to the FortiGate 100F. The install preview is empty and it doesn't recognize the reservation. Either new one or deleting an old reservation.I have tried to modify a firewall policy along with the reservation but it only recognizes changed policy not the reservation.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.