Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hello,I currently have SSL VPN active and I want to switch to IPsec VPN (IKEv2 Remote Access).Environment:FortiGate model: FG-101FFortiOS version: 7.4.11VPN type: IKEv2 IPsec Remote AccessAuthentication: FortiAuthenticator 6.5.6 build 1391 (GA) with OTPDirectory: LDAP users and groups from Active DirectoryClient: FortiClient 7.4.3 Hotfix 1 (7.4.3.8758)I am configuring an IKEv2 IPsec remote access VPN that authenticates users via FortiAuthenticator using LDAP credentials and OTP.The VPN connection is not successfully established from FortiClient.Phase 1 (SA_INIT) completes successfully, but the connection fails during user authentication (EAP phase).FortiClient shows the following error:Wrong EAP credentialsHas anyone encountered this issue when using IKEv2 with EAP authentication and FortiAuthenticator OTP?Any suggestions or troubleshooting steps would be appreciated.Thank you.
I am setting up 802.1x with clearpass and most of my switch are running 7.6.1 or lower and are working fine. I upgraded 2 switches this morning to 7.6.6 and now they absolutely refuse to work if I have the 802.1x security policy on the ports. Worked fine on 7.6.1. Not even DHCP is getting passed to the native vlan.I've spend the majority of my day trying to find a way to work around this today and am at the end of my chain.I can't even roll back to 7.6.1 because I don't have switch support to download.I ran a sniffer on the fortigate and the switch doesn't send a single RADIUS packet when a port comes up.Anyone have any suggestions?
now i have situation i want to register ip phones in my company manually and if there is no registered ip phone as rogue i mean so i need to block its traffic but doesn’t block data traffic behind it how to achieve this using fortinac?
Dear Experts,I’m working with FortiWeb, which deployed 6-8 months ago and security policy in monitor mode. Now, customer decided to change security policy to Blocking Mode from Monitor mode.I have checked for Fortinet official document, but didn’t see any recommendation or workaround for such transition from Monitor mode to Blocking mode. Appreciate, if experts can advise on this. Regards, Faridul
Based on below article, can i know if every group in fnac inventory should have L3 device for L3 polling?
A FortiMail client, who uses the free tier of FortiSandbox SaaS, was informed about new vulnerabilities and intends to identify the version of FortiSandbox in use in order to assess whether there is any risk of exposure.
Hello everyone,I am running into an issue regarding a duplicate device in EMS , and I am unable to delete the stale record because of the Azure AD sync lock.Environment: FortiClient Version: 7.2.12 OS: Windows 11 Enterprise EMS Integration: Synced with Azure AD (Entra ID) The Current Issue: Telemetry is Connected: The clean reinstall fixed the WMI conflict. Forticlient Telemetry now successfully connects to EMS. Duplicate Device in EMS: Because of the clean reinstall, the endpoint generated a new UID. EMS now shows two records for the exact same Hostname/MAC Address. One is Offline (old UID) and one is Online (new UID). Cannot Delete the Stale Record , but the license was used twice on the same device My Questions:What is the best practice to remove or merge this stale duplicate device in EMS?Any insights or workarounds would be greatly appreciated. Thank you!
I want to test latest Fortigate VM image on Virtualbox. but I get error “Failed to start !”. Is there some way to start the VM locally?
It appears that if a person purchases a used Fortigate product, that they are unable to download firmware without paying for “support”.Is this the way it is? Or am I missing something?
Hi i have create lots of VPN definitions in the VPN Manager and assign them to Managed fortigates. When i try and install the policy i quickly get this error. "cannot find addr xxxx" "load vpn node x failed". the object is there but need to be loaded on the GW. even tryig with a policy with no VPN in the rules also fails. Any ideas?
How to Protect Fortigate from IPv6 Security Risks
Hi everyone,I'm currently testing the FortiNAC Persistent Agent in my lab environment. The agent is unable to establish a connection to the FortiNAC server. Below are the troubleshooting steps that I have already completed.Troubleshooting performedConfigured DNS and verified that the client can successfully resolve the FortiNAC FQDN. Modified the Windows registry on the client so that ServerIP, LastConnectedServer, and HomeServer all point to the FortiNAC FQDN (fnac.vss.com). Downloaded and installed the Persistent Agent certificate from FortiNAC on the client. Verified network connectivity: Client can successfully ping the FortiNAC server. FortiNAC can successfully ping the client. Verified that FortiNAC is listening on TCP port 4568. Tested TCP connectivity to port 4568 from the client. Captured traffic on FortiNAC using tcpdump.During the packet capture, I observed that the client sends TCP SYN packets to fnac.vss.com:4568, however FortiNAC never replies with a SYN-ACK, causing th
Hello traveler, I'm assuming you've stumbled upon this post after using very specific search terms and are perhaps now at the end of your rope. I hope I can maybe be your last stop. There's a lot that's going to depend on your own setup, such as which cipher suites you're using, your local and remote subnets, etc. I'm not posting this as a definitive guide to get your swanctl.conf perfect - I'm assuming you've already got it to a place where it "should be working". My goal is instead to draw attention to the changes that took my tunnel creation getting totally dropped and ignored by the FortiGate after first contact, to it actually trying to authenticate. It was of course, very simple, but took me hours upon hours to finally get right. The lynchpin was this: Set Remote auth to PSK. Set Local auth to EAP. Make sure Local is set to round 2, otherwise it sends your EAP credentials before it's asked and the Fortigate shrugs it off. Note that on my FortiGate side, I'm no
We’ve had several cases of memory exhaustion with different processes (node, wad, ips), and are using the “set failover-memory enable” setting to cause the Clusters to automatically fail-over when going into conserve mode. (as well as cpu-threshold)While this is fine as it no longer causes prolonged service disruptions, it does leave the clusters in a degraded state: the failed node usually does not recovery by itself and needs to be rebooted in order to recover from the cause of the memory consumption and restore the cluster redundancy.Is there a simple way (e.g. with automation stitches targeting only the currently active or passive node) to automatically trigger a reboot on the now passive node after such a failover event?Or do we need a feature request to allow automatic reboot of the failed node after a failover that was triggered by an internal event (memory, processes, RIB/FIB, cpu)? We probably don’t want to auto-reboot after an external event (link failure/ping-probe fail).
Hi everyone,I have installed the following FortiGate VM image in EVE-NG:Image: FFW_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvmAfter booting the VM, I don't see any option to add or upload an Evolution License during the initial setup.When I click Cancel on the Add License screen, it immediately returns me to the device login window, and I'm unable to proceed any further.Has anyone experienced this issue before?Could you please help me with the following questions:Is this VM image compatible with an Evolution License? How can I upload or activate the Evolution License on this image? Is there any additional configuration required for EVE-NG or the VM before licensing?I have attached a screenshot of the issue for reference.Any suggestions or guidance would be greatly appreciated.
Is anyone else seeing a large amount of “Domain was blocked by DNS botnet C&C” alerts for valid URLS?the commonality is that its akamai and the common 5 IP addresses are the following.23.223.209.3223.33.44.22823.44.201.23423.57.90.6823.33.40.7
Hi all, This is my first post on these forums, so hello to everybody :) I'm going to start by asking a question i don't expect many people to be able to answer but i hope somebody who is familiar with BGP and ADVPN can crack this one. I have labbed up the below scenario and its working great. Hub/spoke topology with direct spoke to spoke connectivity on demand. http://cookbook.fortinet.com/configuring-advpn-in-fortios-5-4-dynamic-hub-and-spoke-vpns/ I have got abit more adventurous and added a secondary WAN connection to each firewall and added a second round of ADVPN config/VPN's to establish tunnels over the new WAN connection in a bid to achieve ADVPN redundancy should the primary VPN's fail. The interesting bit is that it does work (kind of) - If i shut the VPN's down on the hub it works, both spokes will speak to the hub via the second VPN tunnel and agree new spoke to spoke connectivity over the secondary connection. However it does not
I am using console server to connect to all my network gears such as Aruba, Cisco, FortiAll Aruba can use micro usb console and some usb-cAll new Cisco can use mini usb console and some usb-cFew Forti can use mini usb console SerialtoUSB converter already $8 (not including console cable)Good one generic micro usb cable only $2. 4x cheaper SUGGESTIONS:1. could you make all new Forti has microusb or usbc console tq
Hi!I have to renew or replace a Fortigate 400F cluster, that is working as ISFW.Looking at the specs, the 200G seems to outperform the 400F while being cheaper (more RAM, higher NGFW-throughput.Did I miss anything, or would you prefer to take a pair of 200Gs?Best wishes
Hello Team I have configured ADVPN 2.0 between two 120G, BGP is up, i can ping both tunnels, but the issues are that i can ping the Hub loopback from the Spoke but unable the Hub loopback from the Spoke
The port switch connected to the ipphone and if i plug endpoint to the port of the ipphone then the port switch is shutdown even there are no port security in the port switch. Anyone know why?I can see the log from the switch Jul 20 14:30:13: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet2/0/1, new MAC address (f4a8.0d3d.5aeb) is seen.AuditSessionID 11C8640A000038317E6EAFB7 switchport access vlan 251 switchport mode access authentication host-mode multi-domain authentication order mab dot1x authentication priority dot1x mab authentication port-control auto authentication periodic authentication timer reauthenticate 180 mab snmp trap mac-notification change added snmp trap mac-notification change removed dot1x pae authenticator dot1x timeout quiet-period 10 dot1x timeout server-timeout 30 dot1x timeout tx-period 10 spanning-tree portfast
Hello everyone,I'm currently trying to integrate Cisco ISE with a FortiGate firewall for Captive Portal authentication, and I'm running into a couple of issues.FortiGate Network Device Profile In Cisco ISE, I cannot find a FortiGate Network Device Profile when adding the FortiGate as a Network Access Device (NAD). Is there an official FortiGate device profile that needs to be installed, or should I use a generic RADIUS device profile instead? Redirect ACL in Cisco ISE For the authorization profile used during captive portal authentication, Cisco ISE typically requires a Redirect ACL (DACL/ACL). Since the FortiGate is performing the captive portal redirection, what should be configured for the Redirect ACL in Cisco ISE? Should I leave it empty, create a permit ACL, or is there a FortiGate-specific configuration required? If anyone has successfully integrated Cisco ISE Guest/Captive Portal with FortiGate, I would really appreciate it if you could share how you configured it, includin
Hi Everyone,I am currently working on a FortiNAC deployment integrated with Cisco switches and FortiGate firewall, and I would appreciate some advice regarding the captive portal/isolation VLAN configuration.Environment: FortiNAC version: 7.6.x Cisco access switches FortiGate firewall acting as gateway 802.1X + MAB environment Isolation VLAN configured for unknown/non-domain devices Objective:When an unknown or non-domain device connects to the network: Device should fail 802.1X Fall back to MAB Be placed automatically into the isolation VLAN Receive an IP address Open browser and get redirected to FortiNAC captive portal Current Situation: VLAN assignment is working Device is successfully placed into the isolation VLAN Client receives IP address when DHCP is provided by FortiGate Browser can partially reach the FortiNAC isolation portal However, the captive portal redirection is not fully working correctly.Issues Observed: DNS resolution problem Client cannot re
Hi Team,I am facing an issue with my FortiGate VM running in my lab environment and would appreciate any guidance.Environment:FortiGate VM Image: FortiGate-VM64-KVM v6.2.3 EVE-NG installed on VMware Workstation License: Evaluation (Evolution) license installed via GUIIssue:The FortiGate VM was working normally before installing the evaluation license. After uploading and applying the license through the GUI, the VM initiated a reboot.Since then, the VM has been unable to boot successfully. Instead, it continuously crashes with a kernel panic (double fault) during startup and enters a reboot loop.Below is the console output:FortiGate-VM64-KVM #FortiGate-VM64-KVM # Requesting FortiCare Trial license, proxy:(null)The system is going down NOW !!Please stand by while rebooting the system.Restarting systemPANIC: double fault, error_code: 0x0Kernel panic - not syncing: Machine halted.CPU: 0 PID: 1 Comm: initXXXXXXXXXXX Tainted: P 4.19.13 #1Hardware name: Bochs Bochs, BIOS Boc
Hey guys, Lately Ive been struggling with certain configuration. In the environment that i am currently working we have around 450 clients in FortiClient EMS Cloud. These station are not user managed but more of the automated clients that need to automatically connect t vpn gw without user interaction.On two separate occasion when ISP flapped on the FortiGate side not all clients reconnected to the firewall.I can force the connection from EMS when disable/enable the endpoint policy but even then not all clients reconnected. I needed to manually connect to the endpoint and click “Connect” on the VPN tunnel to re-establish the connection.The cause is that when the ISP flaps on the FGT side the clients cannot connect to the VPN gateway and will instead show error. You need to manually press connect to try again when the firewall is reachable again, even tho we have persistent connection and auto-connect in the xml file configured. To workaround this I found some articles that there is way
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.