Mark a Best Answer
Fortinet Community
Recently active
FortiManager 7.4.9 Free Trial managing FortiGate 100F on 7.4.9 Config status: Synchronized On FortiManager I've created a new IP reservation under IP Assignment Rules, device global DB status changes to modified, yet when I use the install wizard I'm unable to push the reservation to the FortiGate 100F. The install preview is empty and it doesn't recognize the reservation. Either new one or deleting an old reservation.I have tried to modify a firewall policy along with the reservation but it only recognizes changed policy not the reservation.
I created a LETS ENCRYPT Cert on my FortiAuthenticator and Fortigate that has the SSID for Guests, always had an issue with GODADDY on Apple devices, so we moved to LE. creating the cert via ACME was ll good, cert is valid , matches the FQDN etc, but now annoyingly the problem is worse, Apple and Android dont trust the cert! when they connect to the GUEST SSID, the phones browser says "Security Warning SSL_UNTRUSTED""This certificate isn't from a trusted authority" but the common name "myfortiauthenticator.mydomain.net" is signed by Lets Encrypt: Issued by:Common name:R13Organisation:Lets Encrypt and the cert is 100% valid. Fortinet support Lets Encrypt and ACME, and is a perfect solution, but whats the point if Apple and Android dont trust it? or am I missing something?
Hi, Can somebody please shed any light on this for me. I have configured Application Control to 'Block' the 'Proxy' category and I have 'Deep SSL Inspection' enabled on my firewall policy. When the firewall policy is set to 'Flow-mode' the NordVPN client on the PC is blocked, however when the exact same policy is set to 'Proxy-mode' NordVPN can connect successfully. I can see logged Security Events for Wireguard being blocked when in 'Proxy-mode' but eventually the NordVPN client passes through the UTM and connects. Can somebody please explain why this is the case? I thought 'Proxy-mode' was a more thorough inspection and would expect to see the opposite behaviour. Interestingly just to add to this, I see a lot more granularity in the Applications listed in the Security Event logs when using 'Flow-based' opposed to 'Proxy-based' inspection. Regards, Jonathan.
Hello Fortinet CommunityWe're facing a connection problem with an Fortigate60, on which no connection to any rusdesk Relay is possible. On the Firewall of the Target there is no traffic at all from the source, which means somehow the connection is still blocked. Does anyone know what could cause this?
Hi, We are investigating a strange failover issue with managed FortiSwitches by a HA pair of Fortigates 601F. We are having strange issues with traffic loss if we failover to the passive Fortigate. The issues are only on vlan's were we have intra vlan blocking enabled. If we disable this feature everything is working fine. The problem is that we have traffic loss from the clients to the gateway/fortigate for 2 minutes and 30 seconds after failover. Support found out that the mac adress for that Fortigate vlan is learned on the wrong trunks. We have switches in a ring connected to a pair of 1024E MCLAG core switches. I'm analyzing this issue and in the core switches logging I see the following messages during the failover/issue: 10: 2026-01-08 10:14:49 log_id=0103030700 tz=+0100 type=event subtype=system pri=information vd=root action="daemon-startup" user="init" ui="None" daemon="l2dbg" pid="2589" msg="Daemon l2dbg started"11: 2026-
I have a load of Proxy rules, and have placed them in a specific order, So that all the "UNAUTH" Rules are at the top and then the AUTH rules, Problem I have, I need an UNAUTH rule to catch the rest of the traffic using a webfilter, to block things, but if I place this rule at the end of the UNAUTH rules, the people who need to AUTH to certain sites will now hit this rule first, which i dont want, its for Apple IPHONE users, that cant AUTH but need to be allowed out. The Auth Rules are important to allow certain groups to certain sites, but as they will be below this UNAUTH catch all policy, they will hit that? I cant figure out how to arrange the rules! any advice appreciated.
Hardware: FortiGate 101F paired with FortiAP.Account: I have created a local user on the firewall.Goal: I want an Android tablet to connect to the Wi-Fi using TLS authentication.How do I generate the necessary client certificate for the Android tablet to authenticate and connect to the Wi-Fi? I've already asked Gemini and ChatGPT, but neither provided the correct procedure. Both of them just gave me AI hallucinations.
Hello,I am currently using FortiClient EMS version 7.2.4, while our field users are running version 7.2.5. Occasionally, some users encounter the 'Endpoint blocked by EMS' error.There are no issues regarding the device license status. I can resolve the issue temporarily by manually unblocking the user from the console, but this is not a permanent solution as the problem recurs. What could be the underlying causes of this issue?
Hi Community,Can anyone share me the configuration guide to configure Hub and spoke dialup VPN with BGP with Fortimanager.I wanted to configure this on Fortimanager.Issue is my Spokes are not getting a IP from Hub during Negotiation.I found the guide to do this via Firewall but not able to find any documentation to do this via fortimanager.
hi there,I need help please.I use FG60F with firmware 7.2.x I've created firewall policy with webfilter and ssh inspection. suddenly, some computers can't access certain https website, but the other PC still can access the web without issue. if the -problem computers- use direct internet (not via fortinet), they can access the website. where is the issue? anyone has same experience? thank you
I'm trying to allow CoPilot in office.outlook.com sessions, but block copilot.microsoft.com in general browser sessions, as well as all other LLMs My web filter has Artificial Intelligence Technology blocked in the Fortiguard category based filter, and a URL filter: *.google.com/*udm=50**.google.com/*udm=14*m365.cloud.microsoftbing.com/chatcopilot.microsoft.com*.bing.comcopilot.microsoft I also have an application control profile on the proxy policy, with the GenAI category blocked. The only way I can get it working is to have the AI blocking web filter in both the the firewall and proxy policies. Having the web filter in just the proxy policy works for most LLMs via browser, except CoPilot. It works, but I'd like to know why, as this goes against the admin guide on transparent proxies. https://docs.fortinet.com/document/fortigate/7.6.6/administration-guide/15908/transparent-proxy I don't like not understanding my firewall's config :(  
Hi Folks, This new thread is created to clarify if it possible to use the functionality Fortiguard DDNS to implement a domain name once that name is configured, that be use in a remote access VPN. As example:I configure and activate the DDNS domain XYZcompany.fortiddns.com in the fortiguard ddns. (Image Attached)Later, I want to use that DNS XYZCompany in our FortiClient. (Image Attached) Thanks for your answer. Best Regards,Joel
Fortigate firewall FG90G HA what are the must keep requirements to be kept ready before HA config including Licenses do I require single or two licenses
As part of investigation by checking sample of 100 Fortigate sites from 800+ sites. The data showed that 48 Fortigate sites out of 100 sites having memory conserve mode based on crashlogs. It appears that it took a second when entering and then existing memory conserve mode. Some nodes showed multiple conserve mode instances. Example:29: 2026-03-09 17:47:57 green="1572 MB" msg="Kernel enters memory conserve mode"63: 2026-03-09 17:47:58 service=kernel conserve=exit total="1918 MB" used="1541 MB" red="1687 MB" The customer has 800+ Fortigate sites. I'd like to be sure that no impact to the customer given their large deployment. I was told that the configuration below will help to resolve the conserve mode. Two questions are:Can someone help to explain what the configuration below does and how it will help? Is it the best solution to resolve or eliminate conserve mode? Are there any impacts and drawbacks?#----------------------------------------
Hi guys,I have a question about FCSS after july 15 2026.I was planning on FCSS Secure Networking.I passed NSE 7 - Enterprise Firewall Administrator 7.6 and was planning on NSE 6 - Network Security Support Engineer 7.6.After July 15 both of these exams being canceled.I couldn't figure out what will happen according to their new mappinghttps://www.fortinet.com/nse-training-updateWill it count for something ? am I gonna receive NSE 6 ? or I will need to do NSE 4 to get NSE 7?
Just a simple inquiry. We have a setup for Active-Passive (HA) in our remote site. Since fortiguard services are shared from Master, does it really necessary to avail full license to both primary and secondary firewall?
Hello, I'd like to move the WAN connection from WAN2 to WAN1 on some FortiGates managed by a FortiManager, just so the physical installation is the same on all gates. While I am aware that this will bring an outage, and that's OK as long as it is planned, I want to make sure that when the cable is connect to WAN1, internet traffic goes out as it should.So, ideally, I would prepare the following configuration on FortiManager:deconfigure IP of WAN2 (which is actually used as internet connection)reconfigure IP of WAN1 with the old IP of WAN2modify the gateway in SD-WAN BUT, logically, if you do step 1 above, connectivity of the FortiGate is lost, so, my question:Will the above configurations be fully loaded on the FortiGate, before getting fully applied, or will the each step be done one by one by the FortiManager, connectivity lost after step 1 and my install fail, requiring an on-site intervention of a FortiGate administrator? If it would be the first situation (conf
Hi,I am writing to request a review and whitelisting of my domain. Previously, my website had some security issues; however, I have completely rebuilt the website from scratch (+ better host, + new PHP version + FTP fix) and ensured that all malware and vulnerabilities have been fully removed.All necessary precautions have been taken to ensure that the website is now clean, secure, and compliant with best practices.URL: https://lesbateauxagathois.comI kindly request you to review my domain again and whitelist it at your earliest convenience.Please let me know if any further information or verification is required from my side.Thank you for your time and support.
I am working on relaxing our SSL VPN with IPSEC. currently running 7.2.12 on the FG (azure vm) and using the free FTC 7.4.3.IPSEC is configured with split tunneling, accessible networks is using an address group and all members are subnets. Connection on all FTC apps was imported from a config file.ISSUE: some devices are getting a 0.0.0.0 route pointing to the ipsec tunnel. other devices are getting the correct routes when connecting.any ideas what would cause some devices to not get the correct routes?
We have a Fortigate 200E, running firmware 7.6. IP address of 10.10.0.1 (Internal Software Switch).I deployed a Freeradius Server, IP 10.10.0.11, for RADIUS based 802.1x WPA-Enterprise authentication for Wifi. The Radius Server is up and running, I can run a radtest from my local machine on the network behind the Fortigate and get successful connections.This issue is when I go to add the FreeRadius information to the Radius Server section on the Fortigate, I am constantly hit with "Can't contact RADIUS server". My secret and IP are correct. I have tried to make a firewall allow rule from internal to internal, source all, and destination 10.10.0.11 with Radius services, but it didn't make any difference.I've gone through all the Googling I can, tried setting the Source-ip to the Fortigate, nothing I do is letting the Fortigate connect to the Radius Server.Any help would be appreciated.Thanks.
Hi all, I am calling the API of local users, license , interfaces etc . Getting response status - 429 with message "Too many requests" . How can it solve this.
Hey thereHow do you handle port security?Currently i use NAC Policies with Switches. Earlier i did also MAC Whitelist for dhcp Reservation, but it consumes to much time.Also in the automation we have if a switch port changes MAC it send an Alert mail to us.The nice thing is, if we replace the switch, user can just plug all cables random in it and the NACs kicks in.
Hi all,I’m running into an issue with FortiClient SAML authentication when working with multiple Entra ID tenants and wanted to ask if anyone has faced something similar.Environment:FortiClient 7.4.5 with SAML authentication (Azure / Entra ID)FortiClient EMS 7.4.5Authentication is handled via embedded WebView (not external browser)Endpoint is Azure AD joined (Entra ID) with user signed in as `user@tenantA.com`Scenario:When connecting to VPN using SAML against tenant A → everything works fineWhen connecting to VPN using SAML against tenant B → authentication failsObserved behavior:FortiClient does NOT display a login prompt or account selection, instead, it automatically tries to authenticate using the currently logged-in Windows account (`user@tenantA.com`)Since this user is not present (or not assigned) in tenant B, authentication fails with:AADSTS50105 (user not assigned / not found)Key point:It seems that FortiClient (WebView) is using Windows SSO (WAM) and silently reusing the exis
Hello everyone, Is there a way to export the FortiNAC config file on my local pc ?As well, is there a way to upload the config file on FortiNAC's GUI, or it's only via FTP/TFTP ? BR,
Hi everyone,I'm facing a persistent login loop with a Blazor Server (.NET Core) application hosted on IIS 10, sitting behind a FortiWeb appliance. The setup: External Traffic: HTTPS (SSL handled by FortiWeb).Internal Traffic: HTTP (between FortiWeb and IIS).Server Side: I have configured IIS URL Rewrite to force HTTPS=on server variable and enabled X-Forwarded-Proto support. The Problem:When users try to log in, the authentication cookie (.AspNetCore.Cookies or .AspNetCore.Identity.Application) is never stored in the browser, although other cookies like .AspNetCore.Session and FortiWeb's persistence cookies are present. This causes an infinite redirect loop back to the login page.Locally (bypassing FortiWeb), the application works perfectly and the authentication cookie is generated correctly. What I've tried so far: Enabled "Add X-Forwarded-Proto" and "Add X-Forwarded-For" in the FortiWeb X-Forwarded-For Rule.Verified that "Cookie Security" is disabled in the
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.