Mark a Best Answer
Fortinet Community
Recently active
Is there a way to recover the deleted FortiToken, my colleague use Google authenticator (he's authenticator is already sync to cloud) and he accidentally deleted it. And he hold the master account on our Fortinet Support portal. He tried to use the Lost FortiToken in thrid party-app but no good, event the supplied information are all correct.
Hello,We have encountered an issue where FortiClient VPN Only clients are unable to connect, and the debug log shows the error "gw validation failed", whereas the full FortiClient EMS client works as expected. At the moment, the following setup is working correctly only with the paid FortiClient EMS:Remote Access VPN (IPsec)Certificate-based authenticationSAML authentication via Microsoft Entra ID (Azure AD)phase1-interface:config vpn ipsec phase1-interfaceedit "RA-VPN-IPSEC"set type dynamicset interface "wan2"set ike-version 2set authmethod signatureset net-device disableset mode-cfg enableset ipv4-dns-server1 10.102.xxx.xxxset ipv4-dns-server2 10.102.xxx.xxxset ipv4-dns-server3 10.100.xxx.xxxset proposal aes256-sha256set dhgrp 14set eap enableset eap-identity send-requestset eap-cert-auth enableset certificate "<our-worldwide-trusted-certificate>"set peer "RA-IPSEC-VPN-CLIENT"set ipv4-start-ip 10.102.251.10set ipv4-end-ip 10.102.251.200set ipv4-split-include "10.100.0.0-14
Hello,This is my current topology:FortiGate → FortiSwitch (FortiLink) with the following VLANs:DataVoiceThe FortiGate is also configured with SD-WAN using two MPLS interfaces.The issue I'm seeing is the following:When I connect a notebook to a port on the FortiSwitch, I can access all LAN devices without any problem. However, when I try to access the internet, for example by doing a ping, the traffic does not go beyond the Data VLAN gateway IP.Important detail:Both LAN and internet traffic should exit through the same MPLS path.To validate the issue, I reverted the MPLS interfaces back to the Huawei device, and in that scenario the customer has both LAN and internet connectivity working correctly.The configuration on the FortiGate is fairly straightforward, mainly BGP with SD-WAN, nothing unusual.Has anyone seen a similar behavior or have any ideas on what could be causing this?Thanks in advance.Si querés, también te puedo armar una
I have trouble connecting using FortiClient VPN version 7.4.3 hotfix 1.8758 and the latest Windows 11 25H2 update. After entering my login and password, I don't get any connection status feedback – I only get a "disconnect" button, which, when pressed, freezes the program and shows "disconnecting" all the time. I also have FortiClient VPN with an earlier hotfix version on other devices and have no connection issues but installing older version is not a solution, so I will be thankful for any advice.
RAM activationCPU(00:000106ca bfebfbff): MP initializationCPU(01:000106ca bfebfbff): MP initializationCPU(02:000106ca bfebfbff): MP initializationCPU(03:000106ca bfebfbff): MP initializationTotal RAM: 4096MBEnabling cache...Done.Scanning PCI bus...Done.Allocating PCI resources...Done.Enabling PCI resources...Done.Zeroing IRQ settings...Done.Verifying PIRQ tables...Done.Boot up, Initialize boot device failed. Changed Different Hard drives and still same error I cannot even get to the tftp configuration to install the latest OS Anyone have any insight about this error?
Hi,I'm new to Fortipam and I want to understand if there is a desktop application of Fortipam for the IT personal that connects to the fortipam and where you can create and use your secrets. Thanks in advance
HiI need to migrate all IPSec Tunnel to one zone to create a single policy.Now i can't migrate tunnel because "Integrate Interface" is gray and it can't select it.
Here is a cleaner and more professional version for your post:Hello everyone,I’m currently working with a FortiExtender (FEX) using LTE connectivity, and I’m facing an issue related to public IP changes.Every time the LTE provider assigns a new IP address, the connection drops completely. The only way to restore connectivity is by rebooting the FortiExtender.Has anyone experienced a similar behavior?I would like to understand:Is this expected behavior with LTE dynamic IP?Is there any configuration (keepalive, DPD, monitoring, etc.) that can prevent losing connectivity after an IP change?Would enabling specific SD-WAN or tunnel monitoring settings help in this case?Any recommendations or best practices would be greatly appreciated.Thanks in advance!
I would like to know if anyone has experience implementing guest authentication using QR codes or guest access codes through the FortiGate captive portal at the interface level.Currently, I am configuring a captive portal for guest WiFi access, and I would like to provide a more user-friendly authentication method for visitors. Ideally, I would like to implement one of the following options:Access through QR codes that redirect users directly to the captive portal login page.Guest access codes or vouchers that users can enter in the captive portal to gain temporary access
Hi,I tested a FortiExtender LAN Extension on an FGVM-02. After removing the Extender configuration, only the tunnel interface remains, which cannot be deleted. The error message is: (phase2-interface) # delete fext-ipsec-***Can not delete a static table entryCommand fail. Return code -61 Does anyone have an idea how I can remove it? Thanks.
Hello, We have FortiSwitch user ports configured with 802.1X authentication, using a Microsoft NPS server as the RADIUS server. We now need to ensure that IP phone ports and access point (AP) ports are also protected with 802.1X, so that if a device other than an AP or IP phone is connected, it must authenticate. I tried creating a dynamic port policy with the following logic: * The first three rules match APs based on vendor and device type, and assign them a VLAN policy without 802.1X.* The last rule assigns our 802.1X policy to any device that does not match the previous rules. However, when I connect a PC to these switch ports, it somehow receives the native VLAN configured in the VLAN policy used for the AP rules. This happens even though the PC does not appear as a matched device for those AP rules. Does anyone know why this might be happening? Or can you suggest another way to bypass 802.1X only for IP phones and APs without using MAB(without h
Last year we closed a location in the Eastern time zone and put the recovered AP's in storage. When a site in the Central time zone had an urgent need, we shipped them 5 AP's from this inventory, and now the site is complaining all their computers are defaulting to the Eastern Time Zone. Now the finger pointing is going on between the Windows desktop team and the Networking team. I discovered a portal MS provides where you can request your BSSIDs to not be tracked in their geo database, but it's an input only form that leaves you wondering if anything is really going to happen. It also provides no way to determine if BSSID is what is causing the incorrect time zone detection. The FortiGate is set to the correct time zone, has the correct time, and DHCP points clients to the internal NTP servers for centralized time. I am curious if anyone else has come across this and have any advice on resolving it? Denny
Hey guysI already know that we can update IPS Engine manually.https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-manually-upgrade-the-IPS-Engine/ta-p/194513https://community.fortinet.com/t5/FortiGate/Technical-Tip-Upgrading-IPS-Engine-on-the-primary-FortiGate-will/ta-p/202345But can we update IPS Engine automatically ? Are there any related document ?
Lab Setup:Host Machine:Connected to internet.Default gateway: 192.168.1.1/24Running VMware WorkstationVM Configurations:FortiWeb VM:Port1 (LAN segment: WAN): 10.10.10.10/24Port2 (LAN segment: Lan): 192.168.2.101/24Port3 (Management - Bridged): 192.168.1.121/24Windows Client VM:LAN segment: WANIP: 10.10.10.2/24Default gateway: 10.10.10.10Firewall disabledWindows Server_1 VM (IIS):LAN segment: LanIP: 192.168.2.250/24Default gateway: 192.168.2.101Windows Server_2 VM (IIS):LAN segment: LanIP: 192.168.2.240/24Default gateway: 192.168.2.101FortiWeb Configuration:Created VIP: 10.10.10.50/24 on Port1Created Virtual Server using this VIPCreated Server Pool:Type: Reverse ProxyServer Balance: enabledHealth Check: HTTPLoad Balancing: Round RobinAdded both servers (192.168.2.250 and 192.168.2.240)Port: 80Health check: InheritCreated Policy:Linked to Virtual ServerLinked to Server PoolProtocol: HTTPLog traffic: enabledIIS Configuration:IIS installed on both Windows ServersDefault website works when
Hi,I download the latest Fortinet VPN file.Trying to install it ion Windows 11 25H2The process seems working but at the end, application is not installed. no error message.I'm trying to supress microsoft visual C++ distirbution, then retry to install but same result.How to fix it & install the VPN client ?
these 2 microsoft team network are injected into mac route table to be sent over vpn tunnel and when it does this, user fails to join the meeting (see attached screenshot). Our vpn set up is ssl vpn and with split tunnel based on firewall policy destination with FQDN route injectionBelow are those network:Below are microsoft team network on netstat -nr above52.112.127.222Query name (QNAME):api.flightproxy.teams.microsoft.comAnswer (A record) name (RRNAME):epx-enterpriseproxy.d03-058.ic3-calling-enterpriseproxy.01-eastus-prod.cosmic.office.netReturned IP52.112.127.222 52.112.23.78Query name (QNAME):epx.usea-03.ic3-calling-enterpriseproxy.eastus-prod.cosmic.office.netAnswer (A record) name (RRNAME):epx-enterpriseproxy-1.d03-058.ic3-calling-enterpriseproxy.01-eastus-prod.cosmic.office.netReturned IP:52.112.23.78It appears so far only mac user having this issue . The issue is reproducible easily. We run through diagnose firewall fqdn list-all and the injec
Hello,I made a support ticket for this issue (=11577363) The combination we use :Forticlient-EMS with IKEv2(with EAP-TTLS) IPSEC dialup vpn with authentication via AD LDAP(S) , Fortigate v7.4.x does not seem to support the following : change the password when expired or change for the first time at login when checked.I've been asked to make a new feature request to allow this in future releases.I hope this can be done via this way.
Anyone seen a problem using FMG from Safari on MacOS where you occasionally (every few minutes) get a message saying connection to FMG was lost, usually counts down for a few seconds then reconnects. It's likely related to a tcp keep alive because it doesn't happen when I'm interacting, only when I'm idle for a few minutes. I'm just not sure if I should adjust Mac or FMG side. I only see this in FMG but it never happens on Windows machines, even using Safari.
Hello together, we are currently using free FortiClient VPN in our environment and have started experiencing a serious issue affecting multiple users.When users click “Connect” in the FortiClient VPN client, the connection progress does not start — no percentage counter appears and the login process does not proceed at all. In addition, the FortiClient icon is no longer visible in the system tray.We have already: Restarted all related servicesPerformed complete uninstallations and reinstallationsRebooted the affected machines multiple times None of these steps resolved the issue. The only thing that has worked so far is a full reinstallation of the operating system, which is obviously not a sustainable solution. The issue has already occurred on 6 machines and the number is increasing.We need assistance in identifying the root cause and a proper fix. Thanks for the Help. Ist an German Client.There is no percentage progress bar displayed during the connecti
Hi,When a user logs in to FortiSASE for the first time, the device is automatically placed in the Default Endpoint Group.Is there a way to make the device join a specific endpoint group immediately instead of going to the Default group first?I would like to avoid moving devices manually after first login.
Hello,I’m facing an issue with FSSO on FortiGate.Scenario:FSSO is configured and connected correctly.When I run: diagnose debug authd fsso listI can see all logged-in users that FSSO knows about.However:The firewall does not recognize these users in policies.The users are not usable for authentication-based rules.They only become available after I manually refresh/pull users from the GUI.this photo how i pulled into firewall My Question:Is there a way to pull/import FSSO users into FortiGate via CLI or API instead of using the GUI?Specifically:Is there a CLI command to force FortiGate to sync FSSO users?Can this be done via REST API?Is there a debug command that forces the firewall to populate the user table? Any guidance would be appreciated.Thank you.FortiGate #FSSO
Hi all,I need one clarity about captive portal option we have under user and authentication.i wanted to know the use case of this and by default it is disable still captive portal works in my environment.
Hi everyone! I am currently doing a clean-up on our FG501-E. Part of cleanup is to check whether the tunnels are still passing traffic. Where could I efficiently check this type of log? I did the 3 and no results came back1. diag vpn ike gateway list2. Went to the GUI > Dashboard > Network > IPSEC3. Went to FortiAnalyzer > Events > VPN It feels like I am doing wrong on checking. Could you kindly suggest other ways to check this? Regards!
Hi, I am currently migrating multiple Cisco ASA firewall to a single FortiGate (HA setup). I extracted multiple NTP server and DNS server, and all of them are requirement of the client for auditing. How can I configure this servers on the FortiGate?
Hi All,I need some expert opinion for my issue that is being caused by the FortiEMS Client. CPU behaviour:When downloading a test file, the CPU would remain at 100% consistently.Testing with another laptop performing the same download showed CPU around 45%, indicating normal behaviour.FortiClient observation:When FortiClient Fabric Agent (EMS) was enabled and the machine was on fabric, CPU usage during downloads would spike to ~100%.When FortiClient was disabled / off fabric, CPU usage dropped to ~40–50% during the same download test.This also causes network drop, teams issue and many more other problems that is related to network. The on-fabric feature currently has all modules disabled except for the system module, yet the CPU spike still occurs when the endpoint is connected to the fabric. The issue has been confirmed to be caused by the FortiEMS Client. My version is 7.2.8. Case has already been raised but I am not nearing or anywhere close to the solution. 
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.