Mark a Best Answer
Fortinet Community
Recently active
I have 2 cisco switch managed by fnac and i add the 3rd cisco switch.After i configure the dot1x on the 3rd switch then the authentication is rejected with below errorWhat mean of RADIUS not enabled on device? IN the inventory the RADIUS was enabled.Â
​mailfilterd stuck at ~100% CPU, FortiMail 8.0.0 build 183 — cause unclearFortiMail 8.0.0 build 183. mailfilterd sits at ~99.8% CPU continuously (not a spike), RSS grown to ~1.5GB (baseline is usually ~100MB). All other processes idle. Session count (24–50) and bandwidth are normal, so it's not a traffic flood.Enabled diagnose debug application mailfilterd level 8 + duration 30 and pulled the Trace Log. The only thing logged for 10 minutes was:FmailAIClient.cpp:931:ping():entryrepeating once a minute, on a single thread, with no other activity captured — looks like a routine heartbeat, not the actual hot path.I can't figure out what's actually causing the 100% CPU. Any help would be appreciated.
Hi Fortinet Community,I have a question regarding FortiToken Mobile and MFA recovery.I currently have more than 30 FortiTokens installed on my FortiToken Mobile application for different FortiGate/FortiAuthenticator accounts.My concern is the following:If my mobile phone is lost, damaged, reset, or becomes unusable for any reason, I may lose access to all of these tokens. In that situation, I would not be able to use the FortiToken Mobile app to generate OTPs and could potentially lose access to the protected accounts.I would like to know:Is there any official backup or recovery mechanism for FortiToken Mobile? Can FortiTokens be restored on a new phone if the original phone is lost or damaged? Is there any way to synchronize or back up FortiToken Mobile tokens securely? Can FortiGate/FortiAuthenticator MFA use Google Authenticator instead of FortiToken Mobile? Can Microsoft Authenticator be used for FortiGate/FortiAuthenticator MFA? Is it possible to configure MFA using TOTP in a way
ScenarioEnvironment with multiple FortiGate firewalls connected to a FortiAnalyzer VM for centralized log collection and analysis.Environment VersionsFortiAnalyzer VM: 7.4.11FortiGate: 7.2.13Fabric ADOM enabledSome FortiGate devices operating in HA cluster modeAfter upgrading the FortiAnalyzer from version 7.4.6 to 7.4.11, the FortiGate devices stopped displaying FortiAnalyzer logs directly from the FortiGate GUI.SymptomsWhen accessing logs from the FortiGate GUI:Log & Report → Forward Traffic / Event Logsthe page remained completely blank.However:FortiAnalyzer continued receiving logs normallyDevices remained online in Fabric View / Device ManagerLogs were visible directly in the FortiAnalyzer GUINo explicit communication or authorization errors were displayedAdditionally, the following behaviors were observed:Analytics (actual/config days) above 100%Archive Usage above 90%diagnose dvm device list showing:conn: unknownconf: unknowndev-db: unknownThis initially suggested a possible
Hello Team,Following a recent electric power outage, HA FortiGate 201G v7.4.11 build2878 (Mature) cluster displayed the attached alert:“File System Check Recommended"Both units in the HA cluster are synchronized and operating normally,What is the recommended best action to handle this alert in an HA environment?Appreciate your guidance to ensure system stability and prevent potential disk issues. Thank you,
Is it possible to modify the landing page when you open the client to be the Remote Access Tab with it defaulting to a specific connection? The policy calls a profile that has both IPsec and SSL vpn. Wanted to push users to start using the IPSec connection and would be simpler if they just opened the client to that section rather than having to explicitly select the IPsec vpn connection.Â
After I upgrade our FGT 100F from version 7.2.13 to version 7.4.12, I started having connectivity issues with some of our internal services. And since I did not have time to troubleshoot the issue we had to revert back to version 7.2.13...Has anyone had this experience before?  Thanks !
Hello Team I want to know for which conditions FortiGate can be blocked because of the licences?Â
We are in the process of switching to fortigate and fortiap, : we have an environment that we are testing on and the radius server is a Microsoft NPS server, when we use user certificates, the dynamic VLAN works, and the user ends up on the VLAN that the NPS provides, but if we set it so that via the policy it is the machine certificate that is to be used, then the client is not moved to the VLAN that the NPS says, but the client remains on what you can say "onboarding" the VLAN, so the CEO can be the difference from the user that works but not when the machine does not?
I've been requested to stretch a few VLANs across our two networks. Both networks live on the same Fortigate as different VDOMs. Each network has their own storage cluster, which our sys admin has requested I stretch their VLANs across to each other over an L2 connection as it would be faster than L3.Anyway, I'm not sure exactly how to accomplish this. None of the VXLAN diagrams look exactly like my setup. I'm thinking a VWP on the FG between two ports assigned to each network, but not sure where to go from there.Any help would be much appreciated. Also if this is a dumb idea please let me know that too.
Does anyone have the official MTBF figure for the FortiGate 200G?
I have a FortiGate VM deployed on Microsoft Azure, and I’m trying to configure an IPsec Client-to-Site VPN.The current situation is:* FortiGate VM is running on Azure.* UDP 500 and UDP 4500 are allowed in the Azure Network Security Group (NSG) and Azure networking.* The IPsec VPN client is able to reach the FortiGate.* Phase 1 is established successfully.* However, Phase 2 does not come up, and the VPN client cannot establish the VPN connection successfully.I have already verified that UDP 500 and 4500 are allowed, but the issue still occurs.My questions:1. What are the most common reasons for IPsec Phase 2 failing on a FortiGate VM running on Azure when Phase 1 is already established?2. Are there any Azure-specific requirements or settings that I should check for IPsec VPN, such as NSG rules, Public IP, routing, NAT-T, or IP forwarding?3. What FortiGate debug commands would you recommend to identify why Phase 2 is failing?Any guidance or troubleshooting steps would be highly appreciat
Starting with FortiOS 7.6.3, the SSL VPN tunnel mode has been replaced by IPsec. I have prepared a consolidated document that outlines the key steps and configuration required to set up IPsec VPN for remote users using SAML authentication. This single document can be used as a reference, eliminating the need to consult multiple sources.IPSEC Remote Access VPN with SAML AuthenticationThis document provides a summarized configuration guide for setting up an IPsec-based Remote Access VPN for users with SAML authentication. Starting from FortiOS 7.6.3, SSL VPN tunnel mode is replaced with IPsec.Reference Document:https://docs.fortinet.com/document/fortigate/7.4.4/ssl-vpn-to-ipsec-vpn-migration/446639/saml-based-user-authenticationSummary NotesIPsec supports SAML-based authentication on FortiClient version 7.2.4 and later.Only IPsec IKEv2 supports SAML authentication. IKEv1 is not supported.1. IDP Configuration (Okta)Create a new application in the Identity Provider (Okta).Assign the approp
Now that mouthful is out of the way - I'm having an issue only on MacOS FortiClient (of course). It was working, so I've no idea what has changed to suddenly have this behaviour. Windows clients are working fine. We're currently trying to migrate from SSL -> IPSec.For the record, I've tried 7.2.12 and 7.4.3 and both exhibit the same issue. I have a complicated auth of FortiClient -> DuoAuthProxy -> Radius -> LDAP. That works fine with EAP-TTLS all the way through. MacOS is 26.So when I connect via the MacOS client, auth work, duo push works, but then SA retransmits happen and whammy Connection Timeout. I finally found an error I could work with from the fortigate:2025-10-23 20:48:57.682116 ike V=root:0:ra-ops_1:343731: sent IKE msg (retransmit): xx.xx.xx.xx:4500->yy.yy.yy.yy:53479, len=9045, vrf=0, id=cbf670251e3656b1/ee13e00c20a25ee3:00000009, oif=6Which correlates to these lines in the iked.log from the FortiClient2025-10-
Hi together,I want to create a new SSID using Forti Management Cloud.I go to configuration/SSID (Beta)/ create new. Then I am asked to select a Template but the list is empty.Where can I create a template for that purpose?Thanks in Advance
Hi i have create lots of VPN definitions in the VPN Manager and assign them to Managed fortigates. When i try and install the policy i quickly get this error.  "cannot find addr xxxx" "load vpn node x failed".  the object is there but need to be loaded on the GW.  even tryig with a policy with no VPN in the rules also fails.  Any ideas? Â
Hello -   We are in the process of migrating from Cisco firewalls to Fortinet. We support a large medical system with 3 hospitals and many clinics. We have several NATs where certain subnets exit the firewall with specific external IP addresses based upon the traffic source networks. That seems pretty straightforward re-creating with the Central SNAT and overload IP Pools. After those conditions, our default outbound traffic is sent to the internet using a PAT pool of 4 IP addresses and it will also utilize the WAN interface IP address as well for usage and if there is an issue with the PAT pool, traffic will revert to the interface address. This will keep internet traffic flowing although there will be pool exhaustion. My question is on the Fortinet can I utilize the WAN interface IP address along with the IP Pools, or is the interface address not used at all? Thank you
Ran into an issue yesterday.Moving some services over to new datacenter everything seemed to work except traffic from VPN tunnel was being dropped because of reverse path fail. After looking at the routing table it was seen that the blackhole routes were still active so the return path was Null instead of the tunnel.After bouncing the tunnel, traffic started to flow normally.FortiOS version is 7.4.12 on 900G and I didn't notice any known issue which would fit to this. Previously similar moves with tunnels were successful without any issues, so it took a while to figure this out.Has anyone else seen this behavior?
I onboard my WLC to fnac and my WLC contains 5 SSID, let say SSID1 until SSID5.SSID1 to SSID4 using WPA-PSK and SSID5 is 802.1x enabled. With this scenario there is no authentication request from WLC to the NAC If the client connect from one from SSID1 to SSID4. But if i check in the license consumed then why some host which connected to SSID1 - SSID4 is consumed license?
upgraded my forticlient ems from 7.2.14 to 7.4.7 then 7.4.8 . upgrade was fine. have noticed some forticlient  infomation no longer appears on fortigate yet it was therein 7.2.14. e.g version and owner are blank on fortigate yet populated on ems. how do force sync this? this information was very helpful when analyzing ztna logs on fortigate.Â
Hi all,does anyone know if the MTBF info is public available? Thanks in advance
Hi all TL;DRDoes anyone know if the Fortigate trial licence limitations on encryption/decryption (which for example prevent the use of HTTPS) also prevent the SSL connections from Fortigate to FortiAnalyzer for the purposes of sending logs (via oftpd)? I was trying to test sending logs from a Fortigate VM (firmware 6.4) to FortiAnalyzer VM (firmware 6.4) but I just get "No connection" and if you hover the cursor over that you get "Error occurred:{0}". The goal is to test forwarding logs from the FortiAnalyzer to a third device but I can't get this far as the Fortigate won't send the logs to the FortiAnalyzer. A reddit post (www.reddit.com/r/...er_trial_ssl_error_3/) suggested this is probably a trial licence limitation but it would be good to confirm it here if possible. If anyone has found something similar please let me know. Thanks Testing steps:I've made sure to check the compatibility matrix and the FGT and FAZ are compatible. The F
 Environment2x FortiGate-VM64-KVM, v8.0.0, build0167 (GA.F) License Status: Invalid (permanent-trial / unlicensed mode — not a normal 15-day FortiCloud eval) Lab topology: two sites connected via two independent ISP paths, each carrying one IPsec VTI tunnel (VTI-A over path 1, VTI-B over path 2), both VTI interfaces as members of a single SD-WAN zonegw-site-01 (192.168.1.2/24) — fw-site-01 (port4: 192.168.1.1/24) — [ISP1/ISP2] — fw-site-02 (port4: 192.168.2.1/24) — gw-site-02 (192.168.2.2/24)VTI-A: 172.16.1.1 (fw-site-01) ↔ 172.16.1.2 (fw-site-02) VTI-B: 172.16.2.1 (fw-site-01) ↔ 172.16.2.2 (fw-site-02)IKEv2, proposal des-sha512 (forced by the eval-mode low-encryption restriction), dhgrp 29, net-device enable. Both tunnels status=up with active SAs (diagnose vpn tunnel list), real traffic counters climbing.GoalSimple: execute ping 192.168.1.1 from fw-site-02, reaching fw-site-01's LAN-facing interface (port4) through the tunnel. Not even LAN-to-LAN — just firewall-to-firewall, locally-
I've just installed FortiClient VPN the .deb package from here https://www.fortinet.com/support/product-downloads .installed with `sudo dpkg -i ...` Setupd the configuration ( as I have on my windows pc and on my android ) when I try to connect I get the following in the journal: iul 29 14:23:43 station1 kernel: iked[283119]: segfault at 28 ip 000000000045195d sp 00007ffe2a7e6900 error 4 in iked[400000+891000] iul 29 14:23:43 station1 kernel: Code: 4c 89 e5 48 89 44 24 38 48 8d 84 24 88 00 00 00 45 89 d4 45 89 de 48 89 44 24 50 48 8b 45 00 45 89 f5 31 ff 31 db 4a 8b 0c e8 <8b> 51 28 85 d2 74 42 48 8b 71 20 8d 7a ff 31 db 48 8d 46 08 4c 8d iul 29 14:23:43 station1 fctsched[283131]: /opt/forticlient/iked: invalid option -- 'P' iul 29 14:23:43 station1 regolith.desktop[281914]: 14:23:43.573 › VpnHandler UNHANDLED {"isTrusted":true} iul 29 14:23:43 station1 fctsched[283131]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus iul 29
Need FortiGate-side workaround: RDP disconnects when client FortiClient VPN connects on internal PCI have a FortiGate 40F running FortiOS 7.4.12.I need to RDP from outside the office to an internal Windows PC at 192.168.1.89. RDP works normally while the PC is not connected to a VPN.The issue is that the user must connect FortiClient VPN provided/configured by our client on the same Windows PC (192.168.1.89). As soon as the client FortiClient VPN connects, my existing RDP session disconnects.I have no control over the client's FortiClient configuration and cannot ask the client to change any settings on their side Basically, the IP is getting change after VPN is connected, what is the work around for this SSL VPN  Already verified192.168.1.89 is reachable from the FortiGate. TCP 3389 is listening on 192.168.1.89. RDP works correctly before the client FortiClient VPN is connected. Once the client FortiClient VPN connects on 192.168.1.89, the RDP session disconnects. I also tested FortiG
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.