User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
The FortiClient VPN-only version 7.4.3.4323 has been installed onto a MacBook running macOS 26. Full disk access has been given to fctservctl2 and the network extension FortiTray has been enabled although FortiClientProxy and FortiClientPacketFilter were not present to enable. The settings for this VPN use the public IP address of the FortiGate and various DH Group and encryption levels have been tried but all to no avail. The VPN connection is IPsec VPN and tries connecting for a while then comes back with a connection timeout error. The native IKEv2 client for macOS does not work either. I read somewhere that Fortinet added macOS Tahoe 26 support in FortiClient 7.4.5 but there is no VPN-only version later than 7.4.3. I have also read that SSL-VPN support is being stopped so surely there needs to a new VPN-only version where IPsec VPN can be used. Is there ever going to be a newer VPN-only version released? Or is the option available now FortiClient Standalone? This does not seem to b
My WAN utilization is full (total 20Mbps), how we can easily which source is consume high bandwidth?I try to block the graph and click fortiview source and destination and if i compare with the Netflow from my NPM then the source is different.
Hi I am using ssl inspection on my lab.I have downloaded the certificate from fortigate and installed it on windows trusted store and on Firefox.but still have the certificate warning problem ! What do i miss?
Hi FWB adminsFortiWeb 8.0.6, I set it up as SP.When I try run SAML debug as documented in admin guide and perform SAML authentication, I get redirection to SP but I get nothing in debug output.diagnose debug application samld -1 (or 7)diagnose debug enable<output empty>Is there something else to enable in order to make SAML debug work? Any help would be appreciated.
Hello, I have network of around 7 APs. FortiAP FAP431F. I manage them through forticloud. I have an SSID that I want all APs to broadcast it, except one. How can I do that? In the availability page in the SSID configuration, I have the option of “Available to all APs” or “Available to the APs with the following AP tags”. I could not find anywhere in forticloud anything about AP tags. How can I do this? Thank you.
I am looking to set up two separate SSL-VPN access connections, that would by used by two separate groups, both groups are using the same Fortinet device in one domain. (Example:) Group One: Bill is the admin of the Marketing group and supports 10 users.Group Two: Zach is the admin of the billing group and supports 10 users. I want to make sure that both groups can access the VPN through separate IP address and separate ports. Environment FortGate 101D, Firmware 7.2.10. Thank-you
Hello Fortinet community,I am a Systems and Network Administration student working on my final-year thesis on"Implementing sandboxing technology for proactive security of incoming network flows."I need access to a FortiSandbox image for lab testing and practical research. I do not have a commercial serial number with support.Could anyone advise if there is an academic or evaluation image available, or guide me on how to obtain one for student research purposes?Thank you very much for any assistance.
HelloI completed the NSE 2 course successfully, but my NSE 2 certificate/badge is still not showing in my account.More than 48 hours have passed since I completed the course.Thank you.
I have configured a FortiSwitch Dynamic Port Policy (DPP) to allow only 3 specific MAC addresses on a switch port. When one of the legitimate MAC addresses is connected, the DPP identifies the device and assigns the configured dynamic VLAN successfully.However, I am experiencing an issue when the legitimate device is disconnected and an unauthorized device is connected to the same port shortly afterward.My test scenario is:Connect legitimate device (Test_MAC1). DPP identifies Test_MAC1 and assigns the dynamic VLAN. Test_MAC1 is disconnected from the switch port. Within a few seconds, connect an unauthorized device (Test_MAC4). Test_MAC4 is not included in the DPP allowed MAC list. However, Test_MAC4 still receives an IP address from the previously assigned dynamic VLAN and can access the network.It appears that the dynamic VLAN assignment/state is not being flushed immediately when the legitimate device is removed from the port.Is there any way to Fix this?Dynamic port policy Configura
Some users need to access Tor, so I created a rule and set the destination to the Fortinet Internet Service Database (ISDB) associated with Tor. We tested it and saw that they could access Tor pages via the web. However, when the user tries to access the "tor.browser" application, it doesn't load. These users have internet access, but only through HTTP and HTTPS ports. Wasn't the TOR.BROWSER application part of the Fortinet Internet Service Database (ISDB)? Or is it necessary to add the ports used by TOR.BROWSER to the internet access policy? Do you know which ports that application uses, tor.browser?
Hi I'm trying to collect Palo Alto logs into FAZ.If I want to view the normalized logs, do I have to use the log parser?cause I use Log View --> Log Browse, it only showing raw log.
I would like to understand whether the following design is possible and, if so, how it can be configured on a FortiGate 200F or 600F.Current Topology:FortiSwitch 124F ── FLINK_INET_1 ────┐ FortiGate 200FFortiSwitch 548D ── fortilink ───────┘FortiSwitch 124F-POEVLAN 700 configured with IP address 11.11.11.1/30Connected to FortiGate 200F via a FortiLink-enabled interface i.e FLINK_INET_1.FortiGate 200FConnected to both FortiSwitches using separate FortiLink-enabled interfaces.Requirement is to configure VLAN 700 as a Layer 2 bridge only, without Layer 3 routing on the FortiGate.FortiSwitch 548D-FPOEVLAN 700 configured with IP address 11.11.11.2/30Connected to FortiGate 200F via another FortiLink-enabled interface i.e fortilink.RequirementI need VLAN 700 traffic to pass transparently through the FortiGate 200F, effectively allowing the two FortiSwitches to communicate as if they were on the same Layer 2 VLAN.QuestionHow can VLA
Hello,is there any way to get prepared for NSE1 other then Fortinet Learning Center ? Thanks
Dear Security Review Team, I am writing on behalf of IASC Ltd. (Indian Applied Science Corporation) regarding the security classification and/or blocking of our institutional domain: https://newiasc.com IASC Ltd. is an independent institution operating in the maritime security, competency, technology, research and engineering domain. Our website provides institutional information, professional publications, maritime research, technical material and related professional services. We have been informed that newiasc.com is currently subject to an adverse security or reputation classification within external security and website reputation systems. We respectfully dispute any such classification and request an immediate formal false-positive review of our domain. The domain is operated and controlled by IASC Ltd. and is not operated for phishing, fraud, malware distribution, scams, spam, gambling, adult content or other malicious activity. We have conducted server-side verification of our
Hi,I’m using fortimanager provisionning template to manager my IPSec VPN.I’m create a template.In this template I create a IPSec tunnel (Phase 1 and phase 2) with a name like myipsec_model.To create a second Ipsec tunnel, I’m click on clone option. A new tunnel it created with this name : clone_myipsec_model.I can’t rename the new IPSec configuration. I cleck on rename button change the name but this one is not change.I’m use fortimanager 7.6.7.Thanks you for your helpRegardsStéphane
Hi,For one of our customer, I have got the FortiGate 200G firewall as rented device as we are yet to receive our own new firewalls due to lead time. Meanwhile after changing the device password, firewall is asking for Forti care registration which I don't have as this been rental device, is there any way forward for this, I tried skipping the registration from bios but firewall does not boot further with error - Failed to boot the system.
I have two 5G modem with same IP ranges 192.168.0.1/24. When i change modem IP ranges, internet speed 1 out of 100 and very poor. I need solution to connect both modems to use as 50/50 weight. kindly guide me the steps. really i am fresher for network setup.
want download fortiauthenticator vm
Hi, I have a couple of related questions about FortiSIEM Windows Agent architecture:Is it possible to install the FortiSIEM Windows Agent and configure it to send event data directly to the Supervisor, without going through a Collector? Does an All-in-One Supervisor deployment have built-in Collector capabilities? In other words, can the Supervisor itself receive uploads from Windows Agents, or is a dedicated Collector node always required for Agent-based log collection? If a separate Collector is mandatory, is there any workaround for small/single-node deployments, or is a Collector required regardless of environment size?
I'm facing a strange issue with a new FortiGate VM instance running on Proxmox.EnvironmentHypervisor: Proxmox VE FortiGate: FortiGate VM Disk image: fortios.qcow2 Access: Web GUI over HTTPS Version: FortiGate-VM64-KVM v8.0.0.build0167.260420 (GA.F)IssueI created a new FortiGate VM using the fortios.qcow2 image.The VM boots successfully, and I can access the FortiGate GUI login page. I can also enter the admin credentials and authentication is successful.However, immediately after successful login, I am logged out and redirected back to the login page.So the behavior is:FortiGate GUI Login ↓Enter credentials ↓Authentication successful ↓GUI starts loading ↓Immediately logged out ↓Redirected back to Login pageThere is no normal session timeout involved because the logout happens immediately after login.Troubleshooting already attemptedI also tried increasing the administrator timeout:config system global set admintimeout 30endHowever, this did not res
Can you link your fortinet work account with your personal account so that the NSE’s transfer, kind of like microsoft’s way?Does it work all the time or does it depend on different factors, if so, what are the factors that make the process difficult or complicated?
Hello Fortinet Community,I have installed FortiGate-VM64 FortiOS 8.0.0 in my EVE-NG lab environment.The FortiGate VM boots normally, and I am able to access the GUI login page.Current IssueI can successfully enter my credentials and the GUI appears to authenticate successfully. However, immediately after login, I am logged out and redirected back to the login page.In other words:Open FortiGate GUI. Enter username and password. Authentication appears successful. GUI starts to load. Immediately after that, the session is terminated and I am returned to the login screen.EnvironmentPlatform: EVE-NG Device: FortiGate-VM64 FortiOS: 8.0.0 Build: 0167 Image: FGT_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvm.zip Deployment: KVM/EVE-NGLicense StatusThe FortiGate license is showing Up to Date / Active, so there does not appear to be an obvious licensing issue.What I have checkedFortiGate VM is booting normally. GUI is reachable. Username/password are accepted. License status shows up to date. The
Would it be possible to get more info logged on the reason why the disposition was deferred? is ther a setting in the configuration that regulates this? Can a whitelisted sender also be “blocked” like this? Would whitelisting of the domain or sender by the user be sufficient to avoid this? Could the receiver be informed when there is a mail stuck as "Accept; Defer disposition"? With the reason why?
Hi everyone,I’m having an issue when trying to activate the trial license on a FortiGate VM running on GNS3 (KVM).When I execute the following command:execute vm-licenseand confirm with y, I get this error:Requesting FortiCare Trial license, proxy:(null) curl forticare failed, 28 Failed to request forticare license 28. Failed to download VM license.Additional system information:FortiGate-VM64-KVM # get system status Version: FortiGate-VM64-KVM v7.2.13,build1762,260128 (GA.M) License Status: Invalid VM Resources: 1 CPU/1 allowed, 1992 MB RAM/2048 MB allowedThe VM image used:FFW_VM64_KVM-v7.2.13.M-build1762-FORTINET.out.kvm.zipThis is a fresh deployment on GNS3 using KVM.
Issue: my domain xyz.com is build on next js when webiste is loaded xyz.com/_next/static urls are loaded which loads multiple js files , waf ddos policy has threshold 50 req. and multiple js files are when loaded waf suspects it as DDOS attack.... now i cant increse threshold for whole domain xyz.comwhat is the solution ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.