Mark a Best Answer
Fortinet Community
Recently active
Hi,is there any possibility to modify the mail's text and languange, other than the ones used for the approvals?Thanks#fortiPAM
Hi everyone,I have a design question regarding connectivity between two FortiGate HA clusters.Currently, I have two FortiGate clusters configured in Active-Passive (A-P) mode. Instead of directly connecting the clusters, both are connected through a Cisco Core switch (Layer 2) using aggregated interfaces (port-channel). Under these aggregate interfaces, multiple VLAN subinterfaces are configured.Only one cluster (FG1101E) has a public IP address and is responsible for Internet access.The other cluster (FG100E) does not have a public IP and must route Internet-bound traffic through the FG1101E cluster.Additionally, some VLANs on both clusters need to communicate with each other (inter-VLAN/inter-cluster traffic).Given this setup, I am considering two design approaches:Assigning IP addresses from the same subnet on the aggregate interfaces of both clusters and using static routes.Running OSPF between the two clusters for dynamic routing.My main goal is to simplify routing, reduce the num
Hi, We are seeing a cross section of users getting the message, "Network error. Can not connect to vpn server." while trying to connect to VPN using FortiClient SSL VPN "free" version 7.2.12 and 7.4.3. The "fix" has been to downgrade them to an earlier version of the FortiClient (ex. 7.0.12). For some users it works fine connecting on the newer versions, for some it does not. Anyone else seeing this?
Hello,we have implemented FortiAuthenticator, but we have noticed that the emergency token only works when the PC is not connected to the FAC. Is there a way to perform an emergency login if someone forgets or loses their token? Are there fast recovery systems available?Thanks to anyone who can help me.
There is no EOS date for 601E equipment on the support site, is it still not decided?
We are currently using the FortiClient Windows free VPN client version 7.4.3. It has come to our attention that CVE‑2025‑62676 is reported to affect FortiClient Windows 7.4.0 through 7.4.4.Could you please confirm:Whether this CVE affects the latest free 7.4.3 build we are using.If a fixed build or patch is available for the free VPN‑Only client to mitigate this CVE.Whether Fortinet will continue to provide security updates for the VPN‑Only free client and how we can obtain any patched binaries if required.Thank you!
Hi Fortinet community, Good day and greetings! I would like to seek for your kind advise and suggestions. I have this pending changes on my managed fortigate and everytime I try to install it, it's giving me error.I cannot locate and track these policies. ++++++++++++++++++++++++++++++Starting log (Run on device) Start installingFIREWALL-1 $ config vdomFIREWALL-1 (vdom) $ edit rootcurrent vf=root:0FIREWALL-1 (root) $ config firewall policyFIREWALL-1 (policy) $ edit 1FIREWALL-1 (1) $ set uuid aaaaaaaaaFIREWALL-1 (1) $ unset actionFIREWALL-1 (1) $ unset srcintfFIREWALL-1 (1) $ unset dstintfFIREWALL-1 (1) $ unset srcaddrFIREWALL-1 (1) $ unset dstaddrFIREWALL-1 (1) $ unset scheduleFIREWALL-1 (1) $ unset serviceThe attribute can't be empty!command_cli_unset:6496 clear MEMBER table oper error. ret=-56Command fail. Return code -56FIREWALL-1 (1) $ unset utm-statusFIREWALL-1 (1) $
Hello,I’m looking for guidance on best practices to handle configuration rollbacks when working with FortiManager Cloud.In my current setup, I created an SD-WAN Overlay Orchestration with all the required configurations and assigned it to specific sites. Now, I need to remove or roll back that configuration (for example, deleting the overlay or reverting changes), and I want to understand the safest and most recommended approach.What would be the best way to handle this scenario?Thanks!
Hi All I upgrede my Fortigate 80F to 7.0.6 and now my GUI is not working. I did a rollback to the the previous one and still having the same issueI got the warning about a non trust cert on the browser. Once I accept and , the login page is never display here is output of the debugFortiGate-80F # diagnose sys process pidof httpsd1235 Any ideas?1403140514061407140814091410 FortiGate-80F # [httpsd 1403 - 1660398975 info] fweb_debug_init[409] -- New GET request for "/api/v2/monitor/web-ui/extend-session" from "24.232.150.82:65512"[httpsd 1403 - 1660398975 info] fweb_debug_init[411] -- User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0"[httpsd 1403 - 1660398975 info] fweb_debug_init[413] -- Handler "api_monitor_v2-handler" assigned to request[httpsd 1403 - 1660398975 info] fweb_debug_final[298] -- Completed GET request for "/api/v2/monitor/web-ui/extend-session" (HTTP 401 Unauthorized)[httpsd 1410 - 1660
Hi all. I have an issue with one "dynamic" enviroment [dynamic it that sense that network admins are changing PC and other equipement adresses quit eoffen] that in Asset Identity Center on Fortigate (7.4.11) assets attributes like Address stay as they was identified on the first recognition. Address (ip address) is not changing in database. It is a little bit frustrated,because that functionality is used by admins to recognize assets connected to FortiSwitches port and in general to find where device is and how behave. How asset identity center update works?How to trigger asset attribute change? Of course i found otpion of remove assets from database, but it is done manually and hard to do that for specific devices.
I'm deploying an SD‑WAN configuration with BGP over loopback across my infrastructure.Some spokes have only one WAN link, while others have two.After configuring the dial‑up VPN on the hub (which only advertises the 10.200.0.0/16 network), and after creating the loopback interface used for BGP and the loopback used for health‑checks, I proceeded to configure the spokes.Unfortunately, I ran into the following issue on the spokes that have two WAN links.After creating the SD‑WAN rule that instructs all LAN traffic destined for the hub network (10.200.0.0/16) to use the VPN with the best latency, and after correctly configuring the SLA targets, only one of the two VPNs is detected as UP in the SLA targets.The second VPN never shows as UP.From my checks, it seems that only the first VPN is considered UP, because it is the only one responding to the SLA target ping.This makes me suspect that there may be a missing configuration command related to BGP or VPN on the spokes.Below is the config
Hi, I upgraded my Forticlient EMS to the 7.4.5 version and now i can't access to the web portal. When i try to run the command "service restart --all" in the linux console i have the next error:get services status: start apache2 service: exit status 1exit error: [exit status 1], exitStatus: 1Can someone help me with this issue please?
I want to update my FortiNAC 500F (from 7.2.4 to 7.4 ) ,are these steps correctI tried all the protocols
Hi, Since my upgrade from 7.2.9 to 7.2.10, I encounter somes difficulties to access certains parts of the GUI.I reach access to the firewall after a lot of time (5 minutes).I can't upgrade to 7.4.X because the GUI crash too (No upgrades available).Is there any way to solve this problem ? (Probably WebSocket). Best regards
Hi All,I am having some strange issue. Set up is a Hub and Spoke SD-WAN network and 120G cluster work as the hub 100F and 60F nodes are the spokes. Only 3 spokes have.(2x100F,1x60F).All the firewall OS version is 7.2.11 While working on the firewalls, not every time but can not say an exact time the GUI is going unresponsive. All the GUI getting freeze and when refresh, URL is searching on a white page.After sometime it got normal again.This issue not only happens when accessing the firewall from the public IP but the LAN IP too.This is not specify to one firewall. All the ones gave this issue time to time. But during this time period i can access the firewall by SSH and no traffic interruption. Firewall works fine without any complain. No RAM or CPU peaks even. TAC said even debug https also could not find any issue.A custom port is used for https and that port also open for the firewall accessing IP during the issue time. In the OS release note also i could not find th
I want to update my fortinac 500F from version 7.2.4 to 7.4.x , when i try to ping the host update.fortinet.net to test if it's reachable or not it failed
Hey,we have FortiClient EMS (Linux) running at version 7.4.5 build2111 (Mature)And recently we installed a small independent elasticsearch cluster that's only supposed to get the FortiClient Endpoint Events. The FortiClient EMS Administrator Guide is not helpful at all at explaining how to get EMS to connect to that elasticsearch cluster. It keeps complaining about the CA certificate:2026-03-18T15:07:43.445Z ERROR service/event.go:103 create indices: create all indices: check if index forticlientems_alerts_745-write exists: an error happened during the Exists query execution: tls: failed to verify certificate: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA") I used the emscli to give it the proper parameters including a path to the certificate, imported it to the ubuntu trust store and tried every possible way I can t
Probably since thursday when our VPN (Forticlient 7.0.7.0245) is connected we have assigned local DNS but when trying to access or ping some internal services/servers it doesnt resolve. Tried using command below and got our local DNS serverscutil --dns | grep 'nameserver\[[0-9]*\]'when I use nslookup with hostname it also does resolve to IP. Any ideas what could be wrong? Thanks,
Hi everyone! I am posting this again because for some reasons, my previous post was tagged as spam. I cannot push my installation on my fortigate firewall via fortimanager. It is giving me this error. No one among my team is aware who did the last config but they are certain that no one did this type of change. Most of the error is thiscommand_cli_unset:6496 clear MEMBER table oper error. ret=-56 For further logs, please refer to the attached image fileThe logs read from left to rightIf the image is un-readable, let me know for anyone interested and i will forward the actual logs text file Regards,Renz
What is best practice for TACACS+ Policies in the FortiAuthenticator regarding whether to have a single policy for all TACACS+ Clients or have separate policies for various groups of TACACS+ Clients?Would you only separate into multiple policies if you plan to segregate access by group? In other words, if we have routers, firewalls, and switches, then would you create a Router Group, Firewall Group, and Switch Group, and have the corresponding Group "assigned" to separate policies for each of these? Then a super user who needs access to all devices would have to be assigned to all groups?
Does anyone have the SNMP MIB for Fortiap that they could share with me, please?
Hello,I’m currently working with SD-WAN over IPsec, using a FortiExtender (FEX) with LTE connectivity.Since LTE does not provide a static default gateway, I’m unsure how to properly configure the “Local Gateway” setting.What should be defined in the Local Gateway field in this scenario?Thanks in advance.
Working on a unit running 7.4.4 with FIPS-CC enabled. Trying to get this integrated with Azure using SAML. I had seen this document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Unable-to-import-remote-certificate-to-FIPS-CC/ta-p/253435 so followed it as best I was able. Created a csr/key via OpenSSL, got a certificate from a local Windows server (used Webserver template) that is the CA for the domain. Created a PKCS12, imported that into Azure. Downloaded the certificate per the document. When I tried imported it into the FGT initially the firewall complained that it didn't trust the issuing CA. So I imported the root certificate from the CA. When I go back in to import the certificate now as a remote certificate, the GUI says it's importing, but it doesn't show up and isn't available in the cli or when trying to create a new SSO connection. I noticed that the certificate that was created doe
I installed the ESXi version of the FortiGate VM and added the FortiSwitch under FortiLink. However, the logs keep showing the following error. how can I resolve it??FortiLink: ISL timing-out for trunk(XXX) member port(24) did not receive ISL pkt for(10) sec
Good day. We have two FortiGate 40Fs and an IPSec tunnel between them. No issues accessing files across the tunnel. Tunnel Policies are set to allow ALL services. The customer has a VoIP system and they utilize the paging functionality. Paging is working locally per site but will not work over the tunnel, meaning, if Site A initiates a page, all phones in Site A can hear the page but none in Site B - and vice versa. We have multicast policies between the tunnel and can see byte counts. Has anyone done this setup successfully? Appreciate any guidance. Thank you.OD
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.