Mark a Best Answer
Fortinet Community
Recently active
I've connected all of my cameras to FortiRecorder but it shows 0/200 cameras that are not cloud managed. What do I need to do get them cloud ready and accessible?
Hello, Recently, within one week of one another, had a FGT60F and a FortiWiFi-60F boot with incorrect time and date after an unexpected and more than one hour power loss. Year was 1999 once and 2000 on the other device. Both devices are running firmware v7.4.11 build 2878 and connected to FortiGate cloud with valid subscriptions. After the power loss, local traffic is not able to communication with Fortiguard DNS due to the time issue. Therefore:Updating time via Fortiguard NTP servers fails.Fortilink devices show as offline.Fortigate Cloud MGMT down. Having to update devices to use 8.8.8.8, 8.8.4.4 for system DNS. NTP then updates using FortiGuard and after some time, FortiGuard DNS will allow communication again. One device is 3 years old and the other is around 5. Checked for a way to check the internal battery status but came up empty. Any help or thoughts are appreciated.
dash board is not opening after the log in on the web browser
Hello, is it possible to disable remotely LDAP global sensitivity? https://kb.fortinet.com/kb/documentLink.do?externalID=FD50400 we have a lot of user and for every user disable via cli is really crazy.... thanks in advance
Hi I want to connect Android to FortiSASE. I used the Default Invitation code to link EMS.When linked, one certificate is downloaded to my phone.If I go to the FortiClient's VPN and try to connect, it will be asked for a certificate.If I select the certificate that was downloaded a while ago, it will be asked to enter the password.How do I know what the password is?Is FortiSASE setting it up separately? If this situation is a structural problem with Android, is there any other solution? Thank you
So in my lab I have a hub and 3 spokes. Each have 2 WAN ports. I am testing testing failover senarios, and that seems to be working. The issue is kind of weird though. I have a computer connected to a spoke firewall and I set the computer it to ping the other 2 spokes (10.0.200.2 and 10.0.200.3(both are /32 subnets on a LoopBack interface). What I am seeing is when the computer is pinging only one of the spokes, everything is fine, but when I set the computer to ping both spokes at the same time, then I see shortcuts being created for one spoke, then delete and new shortcut created for the other spoke. It's like only one shortcut can be alive at one time. It just keeps flopping like this.     So I am not sure if this is an IPSec issue or routing issue. Any help understanding this would be appreciated. Thank you.
Hi!Issuing "execute fmpolicy print-adom-package ..." does not present an option to see "CLI Template". Is it possible using CLI?Thanks!
Hello,Can the EOS (End of Support) date for Fortinet products change after it is published?If yes, is the change usually only a few days? For example:I noticed the EOS date for FortiFone 380B changed from 4/3/2032 to 15/3/2032 Is this expected? Thanks.
Hello, I am wondering what the best practice is for hub to hub communication in an ADVPN 2.0 Dual Hub set up. The hubs are geographically separated and will be advertising their own IP space into the overlay. We're doing BGP per loopback. Normally with route reflectors, I just do an iBGP peering as non route-reflector clients. My thought was to create separate IPSEC tunnels, place them in a different SD-WAN Zone and peer via iBGP. There will absolutely be traffic between these two sites.
Hi,I noticed something strange in the built-in 360 Security Report in FortiAnalyzer.Between two weekly reports the number of detected devices increased from 2690 to 3707. Most of the increase is detected as Windows devices (from about 1398 to 2144).This does not match reality, because no large number of new Windows machines were added to the network.Another strange thing is that the report shows 561 devices detected on port6, but port6 is not used at all on my FortiGate.Versions:FortiAnalyzer: 7.4.10FortiGate / FortiOS: 7.4.11 Screenshots from both reports are attached.Thanks.
Is there a way to seach for conserve mode history in the past months in the large customer sites over 800 FortiGate devices? Trying to find if conserve mode might have happened on any sites. Thank you
Hi,We've been experiencing a significant number of security incidents involving websites categorized as "unrated" that are hosting malicious content and scripts.I'm curious how the community approaches web filtering policies specifically for unrated websites. I don't want to block the entire unrated category globally, as I suspect there will be impact on legitimate websites that fall into this classification. Ive noticed some MS IPs unrated, which Im concerned might impact O365, or other potential unknowns.Also, see below, if a website is categorized as unrated but has a risk level of "suspicious," how would I go about blocking those suspicious URLs specifically? Any guidance or best practices would be greatly appreciated.Example here:
I have ZTNA setup on a Fortigate, devices that connect through the ZTNA setup can reach everything they are suppose to on that Fortigate, where proxy policies use the EMS tags. I have an ipsec tunnel to another site and can route the proxy traffic to it. The EMS server is sharing all clients to all connected devices, but i can't use the tags on Site Bs firewall policies, because it only sees the clients external IP if i have transparent mode on or my WAN IP on site A if i don't. But neither of those are an ip the client has a tag for. I want to maintain a single fw rule, so that when clients are on site A, the same tags give them access as when they connect through ZTNA server on site A. The on site A works, because the IP matches what the client has. Is there anyway for the FW rule on site B to see this traffic is coming from a client from site A that matches the tag in the firewall rule?
I am trying to figure out how to add a web server certificate to Fortiems 7.4.5. to be used as the web server cert and the forticlient certificate. There are 3 options, Lets Encrypt, PKCS12 and PEM. I would like to use PKCS12. I use an outside vendor for this purpose. There does not appear to be a way to create a CSR on the FortiEMS server. There is not access to the Ubuntu server running on the backend. (using fortinet image). Its fully locked down. I thought we had to create the CSR on the server being used for Fortiems. So I tried creating the CSR using Openssl running on Windows 11. I was able to upload the CSR to the CA and then was able to download the certificates. 1. Do you need root, intermediate and server cert to create a single .pfx file for upload as PKCS12? Or do I only need the intermediate and server cert.? 2. IN what order should the certs appear in the PFX file? 3. For creating the CSR, what are the mandatory items required, common name. city,
Hi everyone, I am relatively new to the Fortinet world and I’m currently working on my first SD-WAN deployment exercise. I’m at the stage where I need to select the right FortiGate model to act as the Hub, but I want to make sure I don't under-provision the hardware or over-spend unnecessarily.Could you help me identify the critical variables I should consider for the correct sizing of the Hub? From my initial research, I’m looking into: Total Number of Spokes, Tunnel Count, Routing Table Size. Beyond these, what else am I missing? For example, how do I calculate the impact of security profiles (IPS, Antivirus, Application Control) when they are applied at the Hub level in an SD-WAN architecture? If there are any specific FortiGate Sizing Guides or "rules of thumb" you use when designing the Hub capacity, I would love to hear them.Thanks in advance for your patience and help!
Hello, I have HTTP (80) and HTTPS (443) open on the firewall. VIP made that points to the internal IP. Subdomain made that points to the VIP. A record works and I can navigate to the WebGUI. I can also view the /.well-known/acme-challenge/ directory. HTTP to HTTPS redirection is enabled in EMS. FQDN set in EMS.When I attempt a LE cert creation, I receive the error:A.C.M.E. Certificate request has failed. CA Authority is unable to make a connection with EMS. Check the logs for more details (/var/log/forticlientems/fcm). I can see multiple LE servers GET the challenge file from tcp dump, and multiple 200 OK responses from EMS. netstat -tulnp | grep :443 returns:tcp6 0 0 :::443 :::* LISTEN 3450/apache2 Any idea why this would be happening?
Hello Fortinet Community,I would like to share a scenario we are facing with a customer's FortiGate 40F (v7.2.13) and seek your advice on the best security strategy to implement.The Situation: We are seeing persistent and constant "Admin login failed" events in our logs. These are brute-force attempts targeting the WebGUI from various IP ranges and multiple countries.Current Approach: So far, my mitigation strategy has been:Creating Address Objects (Type: Subnet) for each attacking IP range.Grouping them into an Address Group.Applying a Local-In Policy to drop traffic from that group:This has turned into a "cat and mouse" game. As soon as I block one range, new ones appear. I considered Geographical Blocking, but it feels too aggressive since many attacking IPs originate from the USA, and I am concerned about inadvertently blocking essential services or legitimate traffic. I also researched this Technical Tip: Technical Tip: Block FortiGate Administrator Login with an automated sc
Looking at the utilization reports for our FortiGate we have decided to downgrade the license from 4vCPU to 2vCPU .. currently license gets synced from Portal via FortiGuard. Once the license is updated in the portal do i need to redownload and apply the license file again ? or will it auto synchronize.
I try to follow guide from 1. Generate TLS certificate for Microsoft Entra ID to do authentication | FortiNAC-F 7.6.5 | Fortinet Document Library to generate EAP-TLS from intune.In Method 2 Step 2 why i got error when Subject Name Format i fill to CN={{UserPrincipleName}} and the other attribut also have same error.Also whay i must fill in certification authority and certification authority name?
Hi everyone, I'm having an issue where I'm going over my daily limit for FortiAnalyzer logs and I'm looking into ways to minimize them without impacting visibility too much. I've already enabled reliable logging and I really don't want to entirely stop taking in interim logs for ongoing sessions. My thinking is that I can increase the interval from the default 2 minutes to make some impact on the amount of logs taken in daily while still providing visibilty If this is not possible, my next strategy would be to set the compression of logs to happen immediately instead of after the default 7 days with this command: config system sql set compress-table-min-age <days>endHowever, I would like to know if there would be any impact besides a small delay on alerts or reports, or higher use of VM resources. Thanks in advance for any assistance.
Hi,I couldn’t find any additional information or discussion about the bug mentioned in the 7.4.5 release notes.I’m currently doing a new EMS deployment connected to Microsoft Entra ID and I’m having issues with Invitation Code registration. The Invitation Code gets accepted, but the client never completes registration (it just keeps loading). EMS logs don’t show much.I tested disabling MFA for one user. After some time, I was able to successfully register one device using an Invitation Code, but I still could not register a second device with the same user (same tenant, same EMS settings, devices provisioned the same way via Intune).Because EMS can resolve and display the Entra ID domain user correctly for the device that registered, I assume the Entra connection/setup itself is basically working.Could this behavior be caused by the following known issue?1208862Entra ID user verification fails if MFA is made compulsory on Entra ID side.If yes: is there any ETA for an update or hotfix t
I know you need to be running v26.1.x in your SASE instance, and all your FortiClients running on 7.4.5, to set your clients VPNs to run connect IPsec over TCP. But in the SASE console I can find only one setting that affects encapsulation: under Endpoint Profiles/Global connection settings. There is one toggle next to FortiSASE Cloud Security Tunnel encapsulation and it's either Auto or UDP. UDP appears to be set as the default. The description of Auto is that the client will try UDP first and then falls back to TCP encapsulation. If you select Auto there is no apparent way to set the TCP port you want to use, and there appears to be no way to just force your clients to use TCP from the start. We want to force clients to always use IPsec over TCP and to force port 443. Does anyone know if this is currently possible given the versions l listed?
I have an issue where the FortiClient endpoint disconnects from EMS when a different user logs into the PC. I am using 7.4.3 build 1926 When installing FortiClient to the endpoint after entering the invitation code, it prompts for a username and password to complete the install. I have LDAP setup so I can use the credentials of the user of the PC or I can enter the domain admin and the install will complete and the endpoint connects to the EMS. The problem I have is that if I later come back to that PC and need to login as a different user or a domain admin; maintenance, troubleshooting, etc.., the endpoint will disconnect from the EMS. No prompt or warning, I just notice it the next time I go look at the EMS for whatever reason and see the endpoint is not connected. I opened a case with Fortinet and was told this is expected behavior if I RDP to the PC, but it doesn't matter if I RDP or login local, logging in as a different user will make the endpoint di
I'm working with a very simple network, comprised of a Fortinet Switch, Router, and some endpoints. The Fortinet switch is a FS-148F-POE (48-port), and the router is a FortiGate 70G. Both were purchased recently through BlueAlley via Amazon. The router is on firmware v7.4.11 build2878 (Mature). Initially, the switch was connected to the router through the router's port #5, a FortiLink port was not used. Everything was working fine but I thought it better to connect the switch to the router via a FortiLink port. So I moved the cable connecting the switch from the router's Port #5 to Port A. At this point, the router recognized the switch and I was able to Authorize and Register the switch. I was also able to upgrade the switch to the suggested latest firmware (v7.6.6 build1137). But after the firmware upgrade, the switch rebooted and then vanished under "Managed FortiSwitches," though it still appeared under System/Firmware &
Hi, One of my customers want to replace his Cisco Router, configured as DMVPN Hub, with a fortigate 1000D firewall.The cisco Router is used to create VPNs with other cisco router, in the spoc sites. Do Fortigate support DMVPN and is there a way to make this configuration running without replacing the cisco routers on the spoc sites. Best regards
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.