Mark a Best Answer
Fortinet Community
Recently active
Users have experienced high latency when connecting to FortiClient IPSec (EMS) over Starlink. We have observed that users on Starlink connections encounter noticeable latency when establishing IPSec sessions through FortiClient.
Hi All, Is possible to disable the dynamic mapping object feature on Fortimanager? I have a customer that often change object configuration directly on Fortigate and after "import policy" in Fortimager and then "re-install pollicy". The problem is that after "import policy" it change the type of object from "address" to "dynamic address" and just that Fortigate that was changed is actualized on Fortimager. Regards,Claudio Rezende
Looking at buying some Fortinet kit, has anyone experienced failure within a year or two?Is the quality good, or does it improvement in terms of things failing?Whats your experience?
Hello, Apologies if this isn't the right place for this question, and I will say upfront I am somewhat of a novice with Fortigate. I am running a Fortigate 60D, I have two vlans, a private network for my PCs and an IoT VLAN where all my Google speakers connect to. I'd like to me able to manage/cast to my Google devices from the private network. I've tried adding a policy to allow MDNS traffic between the two networks, but I'm not sure I set it up right. Can someone please help with a step-by-step guide on how to set this up? Thanks!!
Hey thereHow do you handle port security?Currently i use NAC Policies with Switches. Earlier i did also MAC Whitelist for dhcp Reservation, but it consumes to much time.Also in the automation we have if a switch port changes MAC it send an Alert mail to us.The nice thing is, if we replace the switch, user can just plug all cables random in it and the NACs kicks in.
Hello, I downloaded FGT_VM64_KVM-v7.4.11.M-build2878-FORTINET.out.kvm from the Fortinet site but only thing in the extracted folder is the fortios.qcow2 file (103mb). Why doesn't admin or maintainer login work? I can't activate the free license or activation via web on VPC in Eve-ng . I dont know the ip of the firewall to even try. Could that be why I am not getting login info because wrapper.txt.is missing? I am unable to login to get to the web gui to activate license. Any help will be appreciated.
What could be causing the icons before to application names not to display?They disappear after a while.They don't show up in the "Application Signatures" or "Application Name" logs.Only a restart helps. Fortigate 61E firmware 7.2.13The signature databases are up to date.
Hello! There is a migration scenario where I am not sure 100% about the port-naming\mapping order.I have 2 FortiGate VM in a public cloud (some local Open-Stack\KVM based vendor). My case is moving VMs between AZs and it can be done only manually. So for now I have 5 interfaces\ports on each VM and whey were configured in an adding order (I added one by one and got "port1, port2, port3" etc). In the migration process I'll have to stop the VM, save the image and redeploy in another AZ (like moving an HDD) and attach the image. I will create the same networks with the same IP parameters , but my concern is that when I power on the VM ports can be1) the same 5, but mixed between each other2)First 5 ports got "empty" and new start from 6 to 10Both options are bad. Does anyone know anything about port naming\mapping and the correct order and how can I impact within KVM environment. I couldn't find anything except several reddit's posts 7ish years old.The ver is 7.4.11Thanks!
Hello everyone, Previously, Fortinet allowed customers to purchase a FortiGate-VM separately and renew only the license. However, this option has now been replaced with the FortiGate-VM subscription model, where both the VM and its licenses must be renewed together.My question is, when the VM subscription (including the license) expires, what exactly happens? Will the entire VM and its configuration be lost, or is there a way to retain the configuration (probably through snapshot) Kind regards,
I stepped away from Fortinet for a while and am coming back to find that there still seems to be no real solution to connecting the internal switch ports and external (FortiSwitch) switch ports on the same VLAN. You'd think that once you setup FortiLink, attach a FortiSwitch, and start making FortiSwitch VLANs that those VLAN interfaces would be available to add to either a software switch or hardware (vlan) switch. It doesn't seem that is the case though... Instead, it seems the only way to share traffic between internal ports and external ports is to PHYSICALLY connect between them? Is this really the best (only?) solution:Create virtual VLAN switch with VLAN ID of zero on Fortigate.Add all the ports you are going to use as membersCreate sub-interfaces for each VLAN ID that you are using on the networkDesignate a physical port on the firewall as the trunkCreate a trunk port on the switch controller for the FortiSwitchesPhysically connect the internal (fw) switch trunk
Hi,my network has a fortinet fortigate 200F firewall and active directory with windows server 2019 (DHCP and DNS) and is connected to the Internet via two different ISPs (A and B) with their respective routers/modems configured for load balancing. There is also an external web server connected to ISP A with a static IP. The ISP A router/modem is a netgate pfsense configured so that the web server uses public IP 1 for external connections (from the Internet) and private IP 2 for internal connections (LAN). Connections to the web server work fine from the external network, but from the internal network I am experiencing a potential DNS Rebind attack issue. After some research, I think this is due to the fact that sometimes internal connections use ISP B, which is the one that does not manage the web server.So I wonder what is the best way to force the firewall to route all internal connections to the web server URL to ISP A (excluding ISP2). Where can I find a guide?Thank you.
Hi All,What is exactly going on at Fortinet changing the certification levels every 2 years.So I have the following active:NSE 4 and NSE 5I completed the proctor exam Fortinet NSE 7 - Enterprise Firewall Administrator
Greetings I have recently got a second hand FortiGate 200D and because it was out of use for a couple of years the login and range is unknown. I tried to manual reset it but no luck and I cant discover the device I have tried multiple possible ranges. The device is not under support contract is there a way or place where I can download FortiOS to try and flash the device to factory settings with a usb? Thanks in advance
Hello everyone,I’m currently working on improving our guest WiFi captive portal logging on a FortiGate firewall and I’m trying to determine the best way to capture and later locate guest users if needed.Current SetupWe are using a FortiGate email collection captive portal for guest wireless access.I have customized the HTML replacement message so that the portal now asks for:Full NamePhone NumberEmail Address (existing FortiGate %%USERNAMEID%% field)The page functions correctly and users must fill in all fields before connecting.GoalThe main objective is to be able to identify a guest device later if there is a security or abuse issue.Ideally we would like to log the following information:NamePhone NumberEmail AddressDevice MAC addressIP addressDate/time of connectionThen be able to search FortiGate logs later to locate the user associated with a specific device or activity.QuestionIs there a supported way in FortiGate to log additional captive portal fields (such as name and phone num
Hello everyone,I need to perform a migration from a FortiSandbox VM (version 5.0.5) to a FortiSandbox 1500G hardware appliance (version 5.0.5).Does anyone have an official guide or documentation that explains the migration process from VM to hardware?I would also appreciate any technical tips or best practices for this type of migration.Additionally, are there any specific considerations or limitations that should be taken into account during this migration?Thank you in advance for your help.#FortiSandbox
Hello, Is it possible to customize the mail that will be sent to the user as soon as I provision a token to him? I didn't find an answer for that in the doc or this forum. Thanks in advance!
Hi,is there any possibility to modify the mail's text and languange, other than the ones used for the approvals?Thanks#fortiPAM
Hi everyone,I have a design question regarding connectivity between two FortiGate HA clusters.Currently, I have two FortiGate clusters configured in Active-Passive (A-P) mode. Instead of directly connecting the clusters, both are connected through a Cisco Core switch (Layer 2) using aggregated interfaces (port-channel). Under these aggregate interfaces, multiple VLAN subinterfaces are configured.Only one cluster (FG1101E) has a public IP address and is responsible for Internet access.The other cluster (FG100E) does not have a public IP and must route Internet-bound traffic through the FG1101E cluster.Additionally, some VLANs on both clusters need to communicate with each other (inter-VLAN/inter-cluster traffic).Given this setup, I am considering two design approaches:Assigning IP addresses from the same subnet on the aggregate interfaces of both clusters and using static routes.Running OSPF between the two clusters for dynamic routing.My main goal is to simplify routing, reduce the num
Hi, We are seeing a cross section of users getting the message, "Network error. Can not connect to vpn server." while trying to connect to VPN using FortiClient SSL VPN "free" version 7.2.12 and 7.4.3. The "fix" has been to downgrade them to an earlier version of the FortiClient (ex. 7.0.12). For some users it works fine connecting on the newer versions, for some it does not. Anyone else seeing this?
Hello,we have implemented FortiAuthenticator, but we have noticed that the emergency token only works when the PC is not connected to the FAC. Is there a way to perform an emergency login if someone forgets or loses their token? Are there fast recovery systems available?Thanks to anyone who can help me.
There is no EOS date for 601E equipment on the support site, is it still not decided?
We are currently using the FortiClient Windows free VPN client version 7.4.3. It has come to our attention that CVE‑2025‑62676 is reported to affect FortiClient Windows 7.4.0 through 7.4.4.Could you please confirm:Whether this CVE affects the latest free 7.4.3 build we are using.If a fixed build or patch is available for the free VPN‑Only client to mitigate this CVE.Whether Fortinet will continue to provide security updates for the VPN‑Only free client and how we can obtain any patched binaries if required.Thank you!
Hi Fortinet community, Good day and greetings! I would like to seek for your kind advise and suggestions. I have this pending changes on my managed fortigate and everytime I try to install it, it's giving me error.I cannot locate and track these policies. ++++++++++++++++++++++++++++++Starting log (Run on device) Start installingFIREWALL-1 $ config vdomFIREWALL-1 (vdom) $ edit rootcurrent vf=root:0FIREWALL-1 (root) $ config firewall policyFIREWALL-1 (policy) $ edit 1FIREWALL-1 (1) $ set uuid aaaaaaaaaFIREWALL-1 (1) $ unset actionFIREWALL-1 (1) $ unset srcintfFIREWALL-1 (1) $ unset dstintfFIREWALL-1 (1) $ unset srcaddrFIREWALL-1 (1) $ unset dstaddrFIREWALL-1 (1) $ unset scheduleFIREWALL-1 (1) $ unset serviceThe attribute can't be empty!command_cli_unset:6496 clear MEMBER table oper error. ret=-56Command fail. Return code -56FIREWALL-1 (1) $ unset utm-statusFIREWALL-1 (1) $
Hello,I’m looking for guidance on best practices to handle configuration rollbacks when working with FortiManager Cloud.In my current setup, I created an SD-WAN Overlay Orchestration with all the required configurations and assigned it to specific sites. Now, I need to remove or roll back that configuration (for example, deleting the overlay or reverting changes), and I want to understand the safest and most recommended approach.What would be the best way to handle this scenario?Thanks!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.