Mark a Best Answer
Fortinet Community
Recently active
Hi everyone, I'm having an issue where I'm going over my daily limit for FortiAnalyzer logs and I'm looking into ways to minimize them without impacting visibility too much. I've already enabled reliable logging and I really don't want to entirely stop taking in interim logs for ongoing sessions. My thinking is that I can increase the interval from the default 2 minutes to make some impact on the amount of logs taken in daily while still providing visibilty If this is not possible, my next strategy would be to set the compression of logs to happen immediately instead of after the default 7 days with this command: config system sql set compress-table-min-age <days>endHowever, I would like to know if there would be any impact besides a small delay on alerts or reports, or higher use of VM resources. Thanks in advance for any assistance.
Hi,I couldn’t find any additional information or discussion about the bug mentioned in the 7.4.5 release notes.I’m currently doing a new EMS deployment connected to Microsoft Entra ID and I’m having issues with Invitation Code registration. The Invitation Code gets accepted, but the client never completes registration (it just keeps loading). EMS logs don’t show much.I tested disabling MFA for one user. After some time, I was able to successfully register one device using an Invitation Code, but I still could not register a second device with the same user (same tenant, same EMS settings, devices provisioned the same way via Intune).Because EMS can resolve and display the Entra ID domain user correctly for the device that registered, I assume the Entra connection/setup itself is basically working.Could this behavior be caused by the following known issue?1208862Entra ID user verification fails if MFA is made compulsory on Entra ID side.If yes: is there any ETA for an update or hotfix t
I know you need to be running v26.1.x in your SASE instance, and all your FortiClients running on 7.4.5, to set your clients VPNs to run connect IPsec over TCP. But in the SASE console I can find only one setting that affects encapsulation: under Endpoint Profiles/Global connection settings. There is one toggle next to FortiSASE Cloud Security Tunnel encapsulation and it's either Auto or UDP. UDP appears to be set as the default. The description of Auto is that the client will try UDP first and then falls back to TCP encapsulation. If you select Auto there is no apparent way to set the TCP port you want to use, and there appears to be no way to just force your clients to use TCP from the start. We want to force clients to always use IPsec over TCP and to force port 443. Does anyone know if this is currently possible given the versions l listed?
I have an issue where the FortiClient endpoint disconnects from EMS when a different user logs into the PC. I am using 7.4.3 build 1926 When installing FortiClient to the endpoint after entering the invitation code, it prompts for a username and password to complete the install. I have LDAP setup so I can use the credentials of the user of the PC or I can enter the domain admin and the install will complete and the endpoint connects to the EMS. The problem I have is that if I later come back to that PC and need to login as a different user or a domain admin; maintenance, troubleshooting, etc.., the endpoint will disconnect from the EMS. No prompt or warning, I just notice it the next time I go look at the EMS for whatever reason and see the endpoint is not connected. I opened a case with Fortinet and was told this is expected behavior if I RDP to the PC, but it doesn't matter if I RDP or login local, logging in as a different user will make the endpoint di
I'm working with a very simple network, comprised of a Fortinet Switch, Router, and some endpoints. The Fortinet switch is a FS-148F-POE (48-port), and the router is a FortiGate 70G. Both were purchased recently through BlueAlley via Amazon. The router is on firmware v7.4.11 build2878 (Mature). Initially, the switch was connected to the router through the router's port #5, a FortiLink port was not used. Everything was working fine but I thought it better to connect the switch to the router via a FortiLink port. So I moved the cable connecting the switch from the router's Port #5 to Port A. At this point, the router recognized the switch and I was able to Authorize and Register the switch. I was also able to upgrade the switch to the suggested latest firmware (v7.6.6 build1137). But after the firmware upgrade, the switch rebooted and then vanished under "Managed FortiSwitches," though it still appeared under System/Firmware &
Hi, One of my customers want to replace his Cisco Router, configured as DMVPN Hub, with a fortigate 1000D firewall.The cisco Router is used to create VPNs with other cisco router, in the spoc sites. Do Fortigate support DMVPN and is there a way to make this configuration running without replacing the cisco routers on the spoc sites. Best regards
Hello everyone,I’m working on a FortiNAC 7.2 deployment and I’m trying to enforce a restriction specifically for guest users.GoalAllow each guest user to authenticate and access the network from only one device, preventing the same credentials from being used simultaneously on multiple devices.Current contextWe are using:Guest Registration / Guest Self-RegistrationCaptive Portal authenticationStandard FortiNAC host registrationIn Settings → User/Host Management there is a global parameter called “Allowed Hosts”, which defines how many devices a user can register.Additionally, the same parameter exists at the individual user level, where it can be manually overridden per user account.ProblemThe global setting applies to all users, which is not ideal in our scenario.What we would like to achieve instead is:Allowed Hosts = 1 only for users created through Guest or Guest Self-RegistrationInternal or managed users should not be affected by this limitation.QuestionsIs there a way in FortiNAC
What dot1x method can be used for seamless login?Currently i'm on PoC with Fortinet vendor to implement dot1x and when testing the user is prompted to signin and must enter credential when plugged to the wired.We want if the user login using company device which already joined to the Azure Active Directory then when the LAN plugged to the switch then the user can directly access to the netowrk without prompting to login.
Hello is it possible to use this feature on FortiGate 90G? which ports can be used for this purpose? I try to set port3 and got command parse error before 'dedicated-to'Command fail. Return code -61
I'm trying to automate FortiGate configuration backups by pulling them via SSH using a script. For security reasons, I want to use an account that has strictly read-only privileges (no write access).I created a custom Admin Profile with "Read" access to all modules and assigned it to my backup user. However, when the script runs show full-configuration, the output is incomplete. I noticed that FortiOS hides higher-privileged users (like super_admin accounts) from read-only users, presumably to prevent privilege escalation.Because of this limitation, the backup I pull via SSH is not a 100% complete configuration.I am already aware of alternative methods, such as using Automation Stitches to push the backup to an FTP/SFTP server, or using the REST API with a token. However, my current infrastructure heavily relies on a centralized server pulling configs via SSH.My question is: Is there any CLI trick, hidden setting, or specific configuration in FortiOS that allows a strictly read-only us
In the SDWAN rule what different if we put :Single Performance SLA but contain 2 serversDual Performance SLA but every SLA contain 1 server only?
Hey Guys, I have been struggling to push changes in User & Authentication (i.e creating new local users) from the FortiManager to the FG. Whenever i try to use the installWizard it says there are no changes to push?!I checked ADOM setting and all but im stuck. Policies etc. are being pushed just fine just the users are not Fortios: 7.4.8 Build2795 (mature)FortiManager: 7.47 mature
What is the best way to do RCA on memory conserve mode on FortiGate? The conserve mode happened on Feb 9, 2026 as shown in the output below. 215: 2026-02-09 19:00:05 service=kernel conserve=on total="1918 MB" used="1688 MB" red="1687 MB"216: 2026-02-09 19:00:05 green="1572 MB" msg="Kernel enters memory conserve mode"217: 2026-02-09 19:00:06 MemTotal: 1964180 kB218: 2026-02-09 19:00:06 MemFree: 30232 kB Thanks
I would like to have some informations to move reperedestempliers.fortiddns.com dyndns domain actualy on a fgt30e ) to other FGT60e can you help me ?
I built a FortiGate VM04 6.4.6 in Azure and ran into this nifty little bug that I wanted to document because I couldn't find anything on it. The configuration was all set in place and ready to go and we had just finished adding the last additional interfaces for HA and Management when I updated the static route for the LAN and lost connectivity to the device. I connected in through Azure's Console and saw that the configuration had took but I couldn't ping anything and the device said all interfaces were down. A reboot let me back in and the config had stuck. I assumed it was a bad VM and rebuilt it, pushed the old config and then added an address object. The VM went down again. Rebuilt the VM, added another address object, VM went down. After rebuilding the device another time using 6.4.5 and going into the events and debugging with Fortinet, we identified that DHCP was enabled on the HA and Management ports, which was not recommended. The technician then noticed that the route c
Hi, It seems that the FortiClient only performs automatic registration under the user under which the software is installed. We deploy the initial installation with Intune, which use the system user.When the user starts the client, no registration has taken place. How can I solve the problem?
Hi everyone,I am configuring a Dial-up IPsec VPN on FortiGate (FortiOS 7.6.6) and I want to restrict access based on the user group.RequirementI have two local user groups configured on the FortiGate RA-ADMIN-USER RA-CCTV-USERBoth groups should be able to connect to the same Dial-up IPsec VPN tunnel, but with different access permissions RA-CCTV-USER → should be able to access only the CCTV subnet RA-ADMIN-USER → should be able to access all internal subnets What is the recommended way to allow multiple user groups to authenticate to the same IPsec Dial-up VPN? If anyone has implemented a similar setup, I would appreciate guidance or example configuration.Thanks in advance.
Hi I'd like to know how to restrict encryption to TLS 1.2 / TLS 1.3 only when accessing the FortiADC WebUI.On FortiGate, this can be done by using the global setting set strong-crypto enable.However, on FortiADC (version 7.6.x), this command does not appear. Does anyone knows this ?
Hello,I’m currently staging a pair of FortiGate 90G firewalls and noticed the factory default configuration assigns the x1 and x2 interfaces as a FortiLink aggregate, while the A and B ports appear intended for WAN connectivity.From the default configuration I observed:x1 + x2 configured as an aggregate interface with FortiLink enabledA and B presented as standalone physical interfaces that can be used for WANport1/port2 included in the internal hardware switchMy questions are:Is the intended design on the FortiGate 90G that A/B are the preferred WAN interfaces, while x1/x2 are reserved primarily for FortiLink or high-speed LAN uplinks?If FortiSwitch is not being used, is it recommended to remove FortiLink from x1/x2 and repurpose those interfaces as normal 10G LAN or WAN ports?Is there any Fortinet best-practice guidance on which interfaces should be used for WAN vs LAN when FortiLink is not required on this model?This unit ships with FortiLink preconfigured on x1/x2, so I want to con
Dear expert,i am seeking your guidance and assistance to fix the routing problem. Recently we got direct-connect ( MPLS) link to connect AWS EC2 from on-prem data center. not configured yet. apart from that site-to-site IPsec VPN tunnel also established with AWS and working fine. All BGP handling is taken care by ISP with regards to direct-connect. The issue isoutgoing data from local lan ( port 9) is not going to AWS through port 4 (10.18.152.4/24). working From port4 to gateway of ISP router gateway 10.18.152.1 is reachable.From port4 to AWS EC2 subnet 10.18.144.0/24 is reachable. AWS EC2 subnet to ISP Router GW 10.18.152.1 is reachable.From port 9 to port 4 / 10.18.152.4 is reachable not workingLAN port 9 to port 4's gateway 10.18.152.1 is not reachable.AWS EC2 to port 4 (10.18.152.4) is not reachable. FW polices areport 9 to port 4 > all traffic allowedPort 4 t port 9 > all traffic allowed static route are configured in
So I finally upgraded to 7.6.6 on my FWF60F and initially things were running fine. But now that is has been up for a few days, the GUI loading has gotten really slow. Doing a diag sys top, I am seeing the httpsd process as zombie and on each update, the process id is incrementing.Anyone else seeing issues like this on the smaller units?
Hello Everyone: We need to reset an FAP-234F-A to factory defaults because we don't have the admin password. Here are the details: 1. We have the unit connected to a FortiGate 40F, which has the default IP address of 192.168.1.99 for now while we set things up. The FAP-234F-A is set to 192.168.1.2 and we can ping it and browse to the GUI. 2. The QuickStart Guide for this unit says that it comes with a special POE injector that has a reset button on it because the AP doesn't. Probably because it's a ruggedized outdoor unit and having a reset button would compromise the ruggedness. The model number of the PO injector that shows in the QSG is EPA5006GPR-4P. It's made by EnGenius, but the only one they have is the EPA5006GR, so we bought that one. It has a reset button on it but pressing it for more than 10 seconds doesn't reset the AP to factory defaults. It does nothing. Probably because it's slightly different than the EPA5006GPR-4P and the pinout
Been troubleshooting intermittent FortiClient VPN user issue for MONTHS. Finally caught it in the act with a TAC and MS Support. Still no answer so I'm sharing the oddity here. VPN Clients have traffic stop until DPD times them out. This happens to any user, on any ISP, at any time of day. Client is on Port 61020 to port 4500 on the Firewall... Typical NAT-T session.They were fully connected and working, then... Traffic stops. Here's the output of the sniffer 4 0 1 capture from the Client side FW:2026-03-09 14:47:24.661204 port3 out HQ-IP.61020 -> AZ-IP.4500: udp 3442026-03-09 14:47:24.688854 port3 in AZ-IP.4500 -> HQ-IP.61020: udp 5362026-03-09 14:47:24.733526 port3 out HQ-IP.61020 -> AZ-IP.4500: udp 882026-03-09 14:47:25.441206 port3 in AZ-IP.4500 -> HQ-IP.61020: udp 1042026-03-09 14:47:25.441821 port3 out HQ-IP.61020 -> AZ-IP.4500: udp 1042026-03-09 14:47:26.451448 port3 in AZ-IP.57802 -> HQ-IP.61020: udp 104 WTF?2026-03-09 14:47:27.963936 port3 out
Hi, I recieve this error when I'm trying connecting "Notification: Backup DNS failed" when I'm trying to connect. What's the problem? I installed the last version of Forticlient, I'm using Ubuntu 22.04
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.