Mark a Best Answer
Fortinet Community
Recently active
Hi all. I have an issue with one "dynamic" enviroment [dynamic it that sense that network admins are changing PC and other equipement adresses quit eoffen] that in Asset Identity Center on Fortigate (7.4.11) assets attributes like Address stay as they was identified on the first recognition. Address (ip address) is not changing in database. It is a little bit frustrated,because that functionality is used by admins to recognize assets connected to FortiSwitches port and in general to find where device is and how behave. How asset identity center update works?How to trigger asset attribute change? Of course i found otpion of remove assets from database, but it is done manually and hard to do that for specific devices.
I'm deploying an SD‑WAN configuration with BGP over loopback across my infrastructure.Some spokes have only one WAN link, while others have two.After configuring the dial‑up VPN on the hub (which only advertises the 10.200.0.0/16 network), and after creating the loopback interface used for BGP and the loopback used for health‑checks, I proceeded to configure the spokes.Unfortunately, I ran into the following issue on the spokes that have two WAN links.After creating the SD‑WAN rule that instructs all LAN traffic destined for the hub network (10.200.0.0/16) to use the VPN with the best latency, and after correctly configuring the SLA targets, only one of the two VPNs is detected as UP in the SLA targets.The second VPN never shows as UP.From my checks, it seems that only the first VPN is considered UP, because it is the only one responding to the SLA target ping.This makes me suspect that there may be a missing configuration command related to BGP or VPN on the spokes.Below is the config
Hi, I upgraded my Forticlient EMS to the 7.4.5 version and now i can't access to the web portal. When i try to run the command "service restart --all" in the linux console i have the next error:get services status: start apache2 service: exit status 1exit error: [exit status 1], exitStatus: 1Can someone help me with this issue please?
I want to update my FortiNAC 500F (from 7.2.4 to 7.4 ) ,are these steps correctI tried all the protocols
Hi, Since my upgrade from 7.2.9 to 7.2.10, I encounter somes difficulties to access certains parts of the GUI.I reach access to the firewall after a lot of time (5 minutes).I can't upgrade to 7.4.X because the GUI crash too (No upgrades available).Is there any way to solve this problem ? (Probably WebSocket). Best regards
Hi All,I am having some strange issue. Set up is a Hub and Spoke SD-WAN network and 120G cluster work as the hub 100F and 60F nodes are the spokes. Only 3 spokes have.(2x100F,1x60F).All the firewall OS version is 7.2.11 While working on the firewalls, not every time but can not say an exact time the GUI is going unresponsive. All the GUI getting freeze and when refresh, URL is searching on a white page.After sometime it got normal again.This issue not only happens when accessing the firewall from the public IP but the LAN IP too.This is not specify to one firewall. All the ones gave this issue time to time. But during this time period i can access the firewall by SSH and no traffic interruption. Firewall works fine without any complain. No RAM or CPU peaks even. TAC said even debug https also could not find any issue.A custom port is used for https and that port also open for the firewall accessing IP during the issue time. In the OS release note also i could not find th
I want to update my fortinac 500F from version 7.2.4 to 7.4.x , when i try to ping the host update.fortinet.net to test if it's reachable or not it failed
Hey,we have FortiClient EMS (Linux) running at version 7.4.5 build2111 (Mature)And recently we installed a small independent elasticsearch cluster that's only supposed to get the FortiClient Endpoint Events. The FortiClient EMS Administrator Guide is not helpful at all at explaining how to get EMS to connect to that elasticsearch cluster. It keeps complaining about the CA certificate:2026-03-18T15:07:43.445Z ERROR service/event.go:103 create indices: create all indices: check if index forticlientems_alerts_745-write exists: an error happened during the Exists query execution: tls: failed to verify certificate: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA") I used the emscli to give it the proper parameters including a path to the certificate, imported it to the ubuntu trust store and tried every possible way I can t
Probably since thursday when our VPN (Forticlient 7.0.7.0245) is connected we have assigned local DNS but when trying to access or ping some internal services/servers it doesnt resolve. Tried using command below and got our local DNS serverscutil --dns | grep 'nameserver\[[0-9]*\]'when I use nslookup with hostname it also does resolve to IP. Any ideas what could be wrong? Thanks,
Hi everyone! I am posting this again because for some reasons, my previous post was tagged as spam. I cannot push my installation on my fortigate firewall via fortimanager. It is giving me this error. No one among my team is aware who did the last config but they are certain that no one did this type of change. Most of the error is thiscommand_cli_unset:6496 clear MEMBER table oper error. ret=-56 For further logs, please refer to the attached image fileThe logs read from left to rightIf the image is un-readable, let me know for anyone interested and i will forward the actual logs text file Regards,Renz
What is best practice for TACACS+ Policies in the FortiAuthenticator regarding whether to have a single policy for all TACACS+ Clients or have separate policies for various groups of TACACS+ Clients?Would you only separate into multiple policies if you plan to segregate access by group? In other words, if we have routers, firewalls, and switches, then would you create a Router Group, Firewall Group, and Switch Group, and have the corresponding Group "assigned" to separate policies for each of these? Then a super user who needs access to all devices would have to be assigned to all groups?
Does anyone have the SNMP MIB for Fortiap that they could share with me, please?
Hello,I’m currently working with SD-WAN over IPsec, using a FortiExtender (FEX) with LTE connectivity.Since LTE does not provide a static default gateway, I’m unsure how to properly configure the “Local Gateway” setting.What should be defined in the Local Gateway field in this scenario?Thanks in advance.
Working on a unit running 7.4.4 with FIPS-CC enabled. Trying to get this integrated with Azure using SAML. I had seen this document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Unable-to-import-remote-certificate-to-FIPS-CC/ta-p/253435 so followed it as best I was able. Created a csr/key via OpenSSL, got a certificate from a local Windows server (used Webserver template) that is the CA for the domain. Created a PKCS12, imported that into Azure. Downloaded the certificate per the document. When I tried imported it into the FGT initially the firewall complained that it didn't trust the issuing CA. So I imported the root certificate from the CA. When I go back in to import the certificate now as a remote certificate, the GUI says it's importing, but it doesn't show up and isn't available in the cli or when trying to create a new SSO connection. I noticed that the certificate that was created doe
I installed the ESXi version of the FortiGate VM and added the FortiSwitch under FortiLink. However, the logs keep showing the following error. how can I resolve it??FortiLink: ISL timing-out for trunk(XXX) member port(24) did not receive ISL pkt for(10) sec
Good day. We have two FortiGate 40Fs and an IPSec tunnel between them. No issues accessing files across the tunnel. Tunnel Policies are set to allow ALL services. The customer has a VoIP system and they utilize the paging functionality. Paging is working locally per site but will not work over the tunnel, meaning, if Site A initiates a page, all phones in Site A can hear the page but none in Site B - and vice versa. We have multicast policies between the tunnel and can see byte counts. Has anyone done this setup successfully? Appreciate any guidance. Thank you.OD
hi,i took FGT administrator 7.4 last 2025 and plan to take FMG to complete my FCP network security cert.do i go for the FMG 7.4 version or FMG 7.6?can FGT admin 7.4 compliment FMG 7.6 to complete the FCP network security cert requirement?can someone provide the latest links for training/certificate to achieve FCP network secrity?
I have the OT Applications add-on for Fortigate FG-70F firewall. I can create a profile, activate the OT signatures and use them to create a modbus specific profile. The issue is that when the firewall is power cycled, the OT application signatures disappear, meaning my rule isn't working. I then need to manually turn off and on OT signatures in the profile to make the profile work. These firewalls are going to be isolated with only local access, so this is going to cause issues in the event we advise the customer to reboot the devices or another technician unaware of this issue performs a reboot during maintenance. Is there any fix for this issue?
I have switched ISP from cable to fiber, which means I need to switch my 80F WAN connection from a cable modem to a Eero Max 7 router wired connection. I cannot get the 80F <-> Eero configuration to work (i.e., get internet connectivity), even though the Eero recognizes the 80F wired connection to its 2.5Gb port.Is anyone successfully using a 80F <-> Eero configuration?Any help on the setup, please?FortiGate
We ran and update on the 100 box last night.Out internal interface has two subnets, the primary is an old legacy one that three or four mission critical serves run on and the secondary is the new one that includes all work stations etc. After the update the secondary was fine but he primary lost all traffic. We rolled back to 7.49 and all is fine. Annoying bug that we have no way of testing as we have no test environment. We had held off till the mature release as we've been burned before.Just an FYI.
Hello,I would like to confirm the latest stable FortiOS version for the 101F, along with compatibility for FortiSwitches. unfortunately the compatibility matrix indicates 7.6, it has been experiencing several issues. so what is best stable version in 7.4.x series.thank you
I've connected all of my cameras to FortiRecorder but it shows 0/200 cameras that are not cloud managed. What do I need to do get them cloud ready and accessible?
Hello, Recently, within one week of one another, had a FGT60F and a FortiWiFi-60F boot with incorrect time and date after an unexpected and more than one hour power loss. Year was 1999 once and 2000 on the other device. Both devices are running firmware v7.4.11 build 2878 and connected to FortiGate cloud with valid subscriptions. After the power loss, local traffic is not able to communication with Fortiguard DNS due to the time issue. Therefore:Updating time via Fortiguard NTP servers fails.Fortilink devices show as offline.Fortigate Cloud MGMT down. Having to update devices to use 8.8.8.8, 8.8.4.4 for system DNS. NTP then updates using FortiGuard and after some time, FortiGuard DNS will allow communication again. One device is 3 years old and the other is around 5. Checked for a way to check the internal battery status but came up empty. Any help or thoughts are appreciated.
dash board is not opening after the log in on the web browser
Hello, is it possible to disable remotely LDAP global sensitivity? https://kb.fortinet.com/kb/documentLink.do?externalID=FD50400 we have a lot of user and for every user disable via cli is really crazy.... thanks in advance
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.