Mark a Best Answer
Fortinet Community
Recently active
Hello everyone, Is there a way to export the FortiNAC config file on my local pc ?As well, is there a way to upload the config file on FortiNAC's GUI, or it's only via FTP/TFTP ? BR,
Hi everyone,I'm facing a persistent login loop with a Blazor Server (.NET Core) application hosted on IIS 10, sitting behind a FortiWeb appliance. The setup: External Traffic: HTTPS (SSL handled by FortiWeb).Internal Traffic: HTTP (between FortiWeb and IIS).Server Side: I have configured IIS URL Rewrite to force HTTPS=on server variable and enabled X-Forwarded-Proto support. The Problem:When users try to log in, the authentication cookie (.AspNetCore.Cookies or .AspNetCore.Identity.Application) is never stored in the browser, although other cookies like .AspNetCore.Session and FortiWeb's persistence cookies are present. This causes an infinite redirect loop back to the login page.Locally (bypassing FortiWeb), the application works perfectly and the authentication cookie is generated correctly. What I've tried so far: Enabled "Add X-Forwarded-Proto" and "Add X-Forwarded-For" in the FortiWeb X-Forwarded-For Rule.Verified that "Cookie Security" is disabled in the
I’m fairly new in 3D animation, but the way I’ve always done a character modeling is:Either I get or I make a 2D character turnaround, import it into maya using the front, side and back cameras, and start modeling as if I was “tracing” the drawing (Idk if I’m making sense).I thought this was standard practice, and it’s the most comfortable way for me to model. But one of my professors always scolds me for importing the reference to maya, he says I should “understand the shapes and not copy them” and also “in a pipeline, the concept artist won’t always give you a turnaround” (isn’t that their job?)He’s also very against recording yourself or taking pictures of yourself to have a reference when animating.I get what he’s saying, but I thought the standard practice was to use as many references as possible. But then again, I’m a beginner. Can anyone weigh in on this?
Hello Team,I have already purchased the IPS license with the following details:Date: March 09, 2026Purchase Order #: POS 260XXXContract Registration Code: 1385TXXXQuote ID: 695XXXHowever, on my device dashboard, the IPS license is still not active.Could you please assist me in checking and activating the IPS license on my device? Thank you.Best regards,Aang
I have this policy to assign vlan 17 for devices which not managed by MDM.But the result why devices managed by MDM also hit this rule?
Hello everyone,I have a FortiGate 60F with a FortiSwitch 108E-POE running FortiOS 7.4.11.I changed the FortiLink management VLAN from the default (4094) to our university VLAN 1363 using the following commands:text config system interface edit fortilink set switch-controller-mgmt-vlan 1363 next end After applying the change, I can no longer access the FortiGate WebUI (neither HTTPS nor HTTP) from VLAN 1363. Interestingly, ping to the FortiGate IP on the 1363.fortilink sub-interface works fine.The only workaround I’ve found so far is to create an additional VLAN (1364) on top of fortilink exclusively for FortiGate management, assign the IP address there, and enable allowaccess.My question: Is there a way to access the FortiGate WebUI using only VLAN 1363 (the same VLAN used for FortiLink management) without having to create a second VLAN?I also tried disabling the client certificate requirement with:text config system global set admin-https-clien
I recently purchase some FortiAP-433G. I connected them to a Cisco 9200L PoE switch. The AP and switch negociate PoE succesfully at 802.3at, and the switch supplies 30W.This AP, according to the spec sheets can operate at 802.3at (30W) or 802.3bt (60W) When creating more than 2 SSIDs on the AP, ir begins to constantly reboot it self. Has anyone experience this issue as well?
Maybe I'm just being clueless...I want to explicitly allow a specific URL on the Fortigate,I want to allow certain URLs for the entire network (Source: all) – but only those specific ones, so that:Other domains that happen to be on the same IP address aren’t automatically allowed but are still checked by subsequent policies and can therefore be treated differently.How do I do that? I tried setting up a rule at the top that accesses a web filter which has stored these URLs as static addresses.But that just allows all URLs to be accessed. I want to ensure that this policy is effectively bypassed for other URLs and that the subsequent policies are applied.
Hi, I am looking for help.I am trying to add FortiGate 7.6.4 KVM to FortiManager 7.6.4 KVM, but it doesn't work. From FMG, I am getting the "Probe failed" error message for both OAuth Login (after successful login) and Legacy Login. From FG, I am getting the following errors:From GUI From CLI Connectivity test is OK:FG can ping FMG and vice versaFMG-Access is enabled on the FG interface connected to FMGTelnet to FMG IP 541 from FG is successful Other information:fgfm-allow-vm is enabled on FMGFAZ 7.6.4 KVM is successfully added to FMGexecute central-mgmt register-device on FG does nothingI am not using a custom certificate
Anything behind the firewall usually needs a refresh or two to get past the TLS handshake. Otherwise, Firefox sits there. Sometimes it goes through fine. Anything not behind the firewall doesn't have problems.Any suggestions? Thank you.
Hi,What model is a replacement for the FortiGate cluster HA A-P 300E devices?- 3k hosts- Partially Deep Inspection deploy , we want to implement extend even more DPI rules- routing beetwen vlans/ subnets on L3 not on FortiGate- 500 firewall policy flow mode, 300 firewall policy proxy mode, we want to switch policies with flow mode to proxy mode- 5 VPN IPsec S2S - a database application was running through tunnel- 10 IPsec dialup peak connection- 3 ISP connections that give a total summary speed of 3900 Mbps- FAZ, FCT, FML, FortiWeb Integration Stack
Hello,Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9Our authentication is direct from the fortigate to Active Directory (ldaps)It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602 BUT, it is not working when we add a FortiToken on the account I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/ta-p/420733The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Windows/ta-p/407272https://docs.fortinet
Hi everyone ! I'm facing a very strange issue. I'm running FortiOS 7.0.8. On some of my FortiGate, I can't access to web gui trough LAN interface. On my browser, I can see the certificate warning and after I accept it, the donut is running indefinitely.If a do a packet capture during this, I can see paquet transiting trough my FortiGate to web interface port. If i go trough wan interface, I can access to the login page without any problem and suddenly, I can access to web gui trough lan for a while... Very very strange no ? Someone can help me to understand what appends ? Thanks
Hello all,an administration team need access to Fortigate firewalls. In general, they only need read-only access, but they should be able to disable and enable interfaces. I configured a new accprofile, where all options are set to read only, but the access control for network is set to read-write. When the user logs in, he gets prompted to choose between "Login Read-Only" and "Log Out", The user does not get any write access with the custom profile. Implemented on a FG 101F, version 7.4.5. Any ideas, what is wrong? The relevant configuration:config system accprofileedit "net_admin"set scope globalset commentsset secfabgrp readset ftviewgrp readset authgrp readset sysgrp readset netgrp read-writeset loggrp readset fwgrp readset vpngrp readset utmgrp readset wanoptgrp readset wifi readset cli-get enableset cli-show enablenextend config system adminedit "net-admin"set accprofile "net_admin"set vdom "DATA" "root"set password ***nextend Kind regards, Hakan
Hi All, Does anyone know how to connect with the vpn from an iOS device using the fortitoken? Regards, Omar
Anyone experienced issues with FortiClient VPN not working on Windows 11 24H2? I have no issues on Windows 11 23H2. I've tried various versions with no luck connecting with stability. There is a lag once reaching 95-98%, hangs, then connects but disconnects immediately after. So far rolling back windows 11 23h2 is only fix so far. PS. Foritnet support has denied of any issues with windows 11 24h2. Current FortiClient 7.2.4 Any suggestions?
Hi,I am looking for older version of FortiClient VPN version 7.0.8.0427.Can someone please help me with the information about where I can get the software.Thanks,
Hope you are doing great , So my customer have fortigate NAC running version 7.2, customer wants to login the switches using a single LDAP group. LDAP is integrated with the NAC. can any one share me any tutorial or any step by step configuration link ?
Good Afternoon ColleaguesI hope you are doing well . When moving from a network with HQ (Datacenter) and many remote branches that using MPLS to Fortinet SD-WAN , Does HQ (Datacenter) & remote branches need to have static IP addresses ? Best Regards
We use LDAPS to check users belong to an AD group in our explicit proxy policies. Ever since we replaced our domain controllers with Server 2025, users receive a pop-up saying proxy authentication is required. We use regular bind type, with our AD CA's certificate. This test OK, and diagnose debug application fnbamd -1 shows the certificate working.The CNI is cn, but I've tried using sAMAccountName and uid. Looking in Event Viewer on the DCs, I see lots of event id 1216 and 15351535Internal event: The LDAP server returned an error.Additional DataError value:00000003: LdapErr: DSID-0C060666, comment: Error decrypting ldap message, data 0, v65f41216Internal event: An LDAP client connection was closed because of an error.Client IP: <ip of firewall>:17943Additional DataError value:3 The system cannot find the path specified.Internal ID:c06065f I briefly tried disabling ldapserverintegrity and LdapEnforceChannelBinding on the DCs to see if that was the cause, but no cha
Hello all,i'm trying to limit how much bandwidth my user can have for downloading. i have setup a per-ip-shaper at 30mb but it seems that the limitation randomly apply at 10-15mb instead. from what i can find online this seems to be the proper way to use it? i have set the web facing interface max bandwidth properly and can't think of why it wouldn't match the speed i set, any idea?
I’m facing an issue with connecting to the VPN using FortiClient.When I click on “Connect”, it does not show the username/password (or SSO) login prompt and nothing happens — the button stays in blue color.
Probably an easy question and after reading it seems Fortigate can do what I want.I have a couple secure networks that per our device onboarding process, I want to whitelist those MACs to have connectivity on their respective network (plug in device to wall, get internet. Plug any device not on address list that hits that network/vlan, no network). We have UniFi layer 2/layer3 switching and running into issues with wireless and downstream of allowed MAC lists.I can give more info if needed, just curious if my assumption on Fortigate functionality is accurate. Happy to read another linked thread if I missed it.
Hi, I need to create a launcher for the ASDM.Any suggestions? Thanks
Do I need an Advanced Bot Protection (ABP) license to enable biometric-based bot protection on FortiWeb?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.