Mark a Best Answer
Fortinet Community
Recently active
Good morning, First of all, I introduce myself: I belong to IT service in MN8Energy. We use Forticlient to connect with external services since many years. Act We have got installed many Forticlient version 7.4.2.1737, but this version will expire this summer. We have tried version 7.4.3.8758, but it doesn't work properly, and additionally, it suffers a vulnerability described at CVE-2025-62676. Is there any new version without that vulnerability and fully operational? Is there any other option? Thanks in advance, forum
Hi Is there a way to make a custom decoy with a Windows Server 2025? I have managed to get it installed, but is not booting... Any pointers?FortiDeceptor
I’m trying to configure remote administrator access via SSH on a FortiGate using RADIUS (FortiAuthenticator), where the admin privileges on the FortiGate depend on the user’s Fortinet VSA (e.g. Attribute: Fortinet-Group-Name, value: ADMIN_FORTIGATE) and corresponding remote-group mapping.Goal: allow different remote admins to log in via SSH with different admin access profiles, for example a read-only admin using the built-in super_admin_readonly (or a custom read-only accprofile).I noticed that:If the admin entry is configured with set accprofile "super_admin", SSH login works and the FortiGate does send RADIUS Access-Request to FAC.If the same admin is configured with any other accprofile , SSH login fails with a generic Failed password, and no RADIUS traffic is generated at all.So, it looks like remote admin authentication via SSH is only triggered when the admin has&nb
AI-Based Detection of Malicious Commands Recently, we released a new AI model as part of our FortiCNAPP product to further improve the resilience of our intrusion detection capability. The Anomalous Host Command detection uses small language models to identify shell command line strings that: differ significantly from those previously executed in the environment, and exhibit characteristics that are suggestive of malicious activity. This model contributes signals to FortiCNAPP Composite Alerts and makes our platform more robust to attempts to evade detection. Why Shell Commands? Reliable intrusion detection integrates signals from numerous data sources to distinguish malicious activity from benign background noise. Process data, including the command line string associated with each process, is one of the more valuable data sources we analyze. This command line data is so valuable because it has the potential to provide strong evidence of malicious intent.
I am trying to deploy an FNC-CA-500F.I changed the IP address of my network card to 192.168.1.10 so it matches the default address 192.168.1.99 of the NAC. I was able to access the device via PuTTY, and I configured allowaccess https-adminuiin port1.The ping to 192.168.1.99 is successful, but I am unable to access the graphical user interface (GUI).Do you know why this might be happening?
We currently use the FW-40f firewall in some branches. Its licenses expire on April 5, 2026, and we need to review the licenses to renew them or replace it with a newer firewall, such as the FW-50G. Please provide your suggestions on this matter.
Dear Community Please Guide How to access
We are running into an issue with our Fortivoice system where when someone calls our auto-attendant, and they dial the extension of the party they would like to speak to, they get an invalid extension message. When looking back through the logs, it is appearing that they are dialing too many digits. For example, I call in, dial extension 1523. When I look at the log, Fortivoice shows that I dialed 155523. Sometimes just one extra digit is inserted, and I have seen as many as 20 extra digits get inserted. Other times it works perfectly fine and dials the correct digits. Has anyone experienced this issue or know if any reason why this would be occurring?
When launching an RDP session using a stored Secret through FortiPAM (via Proxy mode and NLA mode), the connection does not automatically inject the stored password.Instead:The RDP client pre-populates the username field with the currently logged-in Windows user from the client machine.The session then prompts for a password.The stored Secret credentials in FortiPAM are not injected.Authentication must be completed manually.
Hi,We are looking into a solution for machine to machine traffic with FortiProxy. We saw that there is an option for oidc in recent versions of FortiProxy and were wondering if that is something we can use. The IdP we would like to use is Entra ID. As said, this is machine to machine, so no browser popup or user interaction should be required. Is this setup possible with FortiProxy?
In the VPN we can select Peer Option to 'Peer ID from dialup group'. How we can create the dialup group?When we create the group then which type should i select (Firewall, FSSO, RSSO, or Guest)?Also we must have the user and this user should be as member for above group. When create the user which user type should i select (Local User Remote Radius, Remote TACACS, Remote LDAP, FSSO or FortiNAC user)?
I have to deploy the Overlay Orch, the default ASN is 65000. The ASN should be private, or it can be public, this is because the customer is using the 65000. Thanks.
Hello,I wanted to replace our existing Aruba Core Switch with a FortiSwitch 148F.Currently the Aruba is connected to my Fortigate 100F via an LACP with different VLANS , the VLAN 1 is currently used by the network. Here's the screenshot of the existing conf with the Aruba switch connected to port1 and port2 I've tried to create a software switch with the Fortilink interface and the LACP but i can't use the LACP for the hd switch.So i attached the Fortiswitch to the Fortilink in order to preconfigure it but i can't create the same VLANS/Subnet on the Fortilink and the fortigate says that they are already used in the LACP.So i would like to know how to migrate this, i can't attach the fortiswitch directly to the LACP becouse it is a production environment and i have to minimize downtimes so i wanted to attach the Fortiswitch to the Fortlink, then preconfigure the Switch AND the Fortilink with the existing VLANS (but i can't create those networks...
Hello, Ive got this situation with a fortilink lacp already working but only 1 physical connection. I wan to add a new connection but I want to confirm if I can add the cable while hot-swapping without any disruption, and the business doesn't allow for a maintenance window, I'd like to know if adding a cable between the firewall and the switch would cause any problems. Additionally, I'd like to know if any further configuration is necessary, given that the firewall is already configured with the FortiLink LACP to use this new physical connection. Any suggestions or link would be really appreciated.
Geremy Condra, Nick Schmeller, Zeki Sherif, Zhenxiao Qi, Chris Horn, Shree Kumar, Tareq AlKhatib What Is RiskWatch? RiskWatch watches your running workloads and tells you which vulnerabilities attackers can actually exploit. Instead of flagging every package at a vulnerable version, RiskWatch detects when your systems execute known vulnerable code, then delivers precise evidence of exposure alongside clear steps to fix it. RiskWatch is a new capability within our FortiCNAPP Agent (formerly Lacework) that continuously monitors cloud workloads and surfaces actionable insights across your entire environment. Why This Changes Everything Security teams are drowning. Vulnerability backlogs grow faster than teams can remediate them, budgets are tight, and most tools do little more than repackage CVSS scores. The root problem: traditional vulnerability scanners compare packag
Hey guys, Is it correct to say that when I disable the password policy on my FortiGate, the IPSEC tunnels with PSK configured in it will remain up and no network impact? Background:I have an existing IPSEC tunnel configured with PSK, also password policy is enabled.I wanted to disable password policy. Thank you!
Hello, As a continuation of a previous thread that was marked as Solved by the person that opened it, the issue appears to be present on 7.4.3.6667 but on 7.4.1.1716 it was not present/affected by whatever is causing it. It happens when the lock screen is either manually initiated or the computer reaches the timer that is set to start it.The disconnect is almost instant as soon as the lock screen is being trigger with the laptop being connected to a power outlet so not on battery. At the previous version 7.4.1 it never disconnected even if the laptop was in lock screen for hours, it remained connected to the VPN. These are the only logs that I could find and maybe someone could help remediate this issue because it's quite annoying to be fair.We are aware that it's a free version of FortiClient w/o support but considering some vulnerabilities are fixed within the latest version and a downgrade to a previous one isn't a real option and neither deactivating lock screen
i cannot acces the FortiNAC UI, i executed this command:- execute service status nacthe output is:- Master Process is Down!
I have been trying to get Dialup VPN users connect via IPSec on a fortigate 80F firewall device but the vpn client cannot reach any internal network. Ping to 192.168.4.x shows request timed out. I have double checked the configurations thoroughly but could not find any issues on the ipsec tunnel setup or firewall policy. show vpn ipsec phase1-interface Dialup_VPN//config vpn ipsec phase1-interfaceedit "Dialup_VPN"set type dynamicset interface "wan1"set mode aggressiveset peertype anyset net-device disableset mode-cfg enableset ipv4-dns-server1 192.168.4.3set ipv4-dns-server2 10.61.50.3set proposal aes256-sha256set dpd on-idleset dhgrp 14set xauthtype autoset authusrgrp "vpngroup"set ipv4-start-ip 172.16.2.10set ipv4-end-ip 172.16.2.50set ipv4-netmask 255.255.255.0set ipv4-split-include "MAF_Servers"set psksecret ENC 1KvTP2fJpmTD24X4AvgNLfMByHhIF5Ajxnr4iofvNF0iXUQt0lxHgModqbtzPRg3Pw1W45otRTxZpRzpqh7pgGQ68CkUucW1pZMv82xUtwXxGqyyQEJqPXRh/QpUDf8OrOozkcpNE43+8ZhMMjUU187
Dear FortiGuard Support & Web Filtering Team,I am writing to urgently appeal the recent categorization of my website, thecupcut.com, which was mistakenly updated to the "Phishing" category by your automated system.This is a massive False Positive. I request a manual review by a security analyst based on the following facts:1. No Phishing Elements Exist: My website is a simple software informational blog. There are absolutely NO login forms, NO password fields, and NO credential-harvesting mechanisms anywhere on the site. It is physically impossible for this domain to be used for phishing.2. Cleared by Global Authorities:Google Safe Browsing has thoroughly scanned the domain and officially cleared it (Current Status: "No unsafe content found").Out of 94 global security vendors on VirusTotal, over 90 top-tier companies (including Kaspersky and McAfee) list the site as 100% Clean.Your automated scanner may have misinterpreted a standard layout, text, or an advertisement as a threat. C
I looking a way to fix the CVE-2025-31514 then i got this article PSIRT | FortiGuard Labs.Can i know what mean of 'Migrate to a fixed release'? My FGT running on version 7.4.11
Hi, I got and issue with my fortinet account, my third party authenticator not work and when i want to reset it, i received correctly the OTP code but when i add it on fortinet to reset, i got this ERROR Either your email or sms or password is incorrect. Please try again.
Been looking into conserve mode (on current versions, 5.6+, so only memory conserve mode) and to understand it better made the image above. Threshold values are based on the defaults. Some things I'm pretty sure about from documentation. But there are some things not clear to me, they either aren't described or at least I can't find that documentation. So primary question. Are the things shown in the image above how you believe conserve mode works? Anything which is wrong? Secondary question does anyone have any insight (preferably with links to documentation) on the question marks?* Are there other actions taken after entering conserve mode?* Does something change when dropped out of "extreme" conserve mode, or does that also have to return to green threshold before new sessions are allowed again? sources:changes (since 5.6...) : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Conserve-mode-changes-in-FortiGate-5-6-and-above/ta-p/198502tri
Is there a way to recover the deleted FortiToken, my colleague use Google authenticator (he's authenticator is already sync to cloud) and he accidentally deleted it. And he hold the master account on our Fortinet Support portal. He tried to use the Lost FortiToken in thrid party-app but no good, event the supplied information are all correct.
Hello,We have encountered an issue where FortiClient VPN Only clients are unable to connect, and the debug log shows the error "gw validation failed", whereas the full FortiClient EMS client works as expected. At the moment, the following setup is working correctly only with the paid FortiClient EMS:Remote Access VPN (IPsec)Certificate-based authenticationSAML authentication via Microsoft Entra ID (Azure AD)phase1-interface:config vpn ipsec phase1-interfaceedit "RA-VPN-IPSEC"set type dynamicset interface "wan2"set ike-version 2set authmethod signatureset net-device disableset mode-cfg enableset ipv4-dns-server1 10.102.xxx.xxxset ipv4-dns-server2 10.102.xxx.xxxset ipv4-dns-server3 10.100.xxx.xxxset proposal aes256-sha256set dhgrp 14set eap enableset eap-identity send-requestset eap-cert-auth enableset certificate "<our-worldwide-trusted-certificate>"set peer "RA-IPSEC-VPN-CLIENT"set ipv4-start-ip 10.102.251.10set ipv4-end-ip 10.102.251.200set ipv4-split-include "10.100.0.0-14
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.