Mark a Best Answer
Fortinet Community
Recently active
Hello, Fairly new to Fortinet and I am looking to get some guidance. I currently have 2x FortiSwitch 148F and I am looking to get setup in my enviroment. What is the best route to get support with this?
We're an MSSP hosting our own on prem multi-tenant Fortimanager and a few thousand FortiGates out in the field and VMs in our datacenters / public cloud.Prior to CVE-2024-47575 we had our FMG exposed to the internet. Upon the news breaking we ACL'ed off the FMG to known FGT IPs. The problem with this is that we offer SD-WAN with LTE (behind CG-NAT) so static IP based ACLs (via threatfeed) which is creating massive operational headaches.I have some designs I've been considering on how to work around this, but I'd like to hear from you guys on how you've chosen to handle this.
Any strategies or advice you can give on adding the FortiSwitch to an existing FortiGate? I'm trying to avoid the removal of firewall policies, addresses, DHCP server, SNAT, essentially anything that ties back to where the switch will be plugged in at and converted to a FortiLink connection.
When we use IPSec for remote access with Split tunnel enabled, can we make the fortiget to not set dns in the client?Now when the forticlient connected to the VPN then the client can't access the local domain.
Hi everyone, Quick question: today we installed on an existing firewall a FortiGate FGT101F running firmware v7.4.8 build2795 (Mature), in NAT mode. The issue is that it always stays “Out of sync” — it looks like synchronization never actually starts. It’s odd because I followed the guide step by step, and I also performed a factory reset, but nothing changed: it still remains Out of sync. What’s even stranger is that with another customer, on a similar setup, the sync started immediately. Any ideas on what this could depend on, or has anyone run into this before? Thanks!
I recently bought a FortiGate 300D from Facebook Marketplace for really cheap. I’m planning to use it for my homelab while studying for CCNA and general networking practice.The problem is I don’t have access to firmware downloads since I’m not the original owner and don’t have a support contract tied to my account.Does anyone have experience with getting firmware access for second‑hand devices and registering older / EOL FortiGate units?
Hello Recently, we've been assigned for a PoC for one of our customers which is i financial institution. We've setup a hub & spoke topology with 2 Fortinet VMs in Active-Active scenario and External & Internal Load Balancers.Our main concern and issue is when for example vm01 on spoke01 vnet communicates with vm01 on spoke02 via fgt-1 and i perform a reboot on this specific firewall the RDP or SSH session is lost. Is there any solution or workaround where in situations like these the TCP sessions are smoothly transferred on the next fortinet ?Regards
I have a query about a FAC for a customer, it acts as a Captive Portal for Guest WIFI, and it works fine except for Apple Devices, there is an issue with GoDaddy and trust on IOS, which neither of the vendors seem to care about, so I need to move from GoDaddy, The reason I am using it is so that Guests don't get a secure warning when accessing the FAC portal page, The company has a domain, that I created a cert for and used DNS to point that FQDN internally to the FAC, this to me is very clumpy, but that's the way its done! The customer doesn't want to use the existing domain and will purchase a new one, "companyxyz.com" for example. How would this work? the FAC is on an internal IP, and if I create a CSR for "fac.companyxyz.com" and get it signed by lets encrypt. How will this resolve to an internal IP? would the DNS for the domain allow a Private IP? Has anyone ever done Lets Encrypt on a FAC? Ill be using this same domain to create certificates on th
Hello Supoort, I have a 80f fortigate that is connect to external customer (BOH) they a use Palto altoWe configured two VPN ( from my Fortigate to customer (1) using a private lease name NDMA as primary link and the other is an internet connectionBecause we are using policy base vpn am unable to configure SDWAN on the Fortigate.My challenge if the primary link (NDMA) drops how do I fail over seamlessly to the other secondary link.Thank you
Hi all,I’m looking for best practice advice.Topology:20 hubs2 branchesEach hub has:2x MPLS links (already in SD-WAN)1x FortiExtender (Internet link)My idea is to use Overlay Orchestration only over the Internet (FEX) link, since it will be used for Internet access and backup.Would it be better to:Use Overlay only on the Internet link and keep MPLS as regular SD-WAN transportorInclude MPLS + Internet in the Overlay?What would be the recommended design at this scale?Thanks.
Good Morning Community,I'm comparing solutions that can work as a mail server for an organization (previously had exchange server)so I would like to ask does anyone has a use-case of running FortiMail in server mode, and feed me back on his experience concerning the below points:Effectiveness of server mode, and does it provide a real dependable mail server solution for organization levelCons of the this solution, especially concerning user experience and administrator experienceApps (like outlook or others) that can be used on desktop and mobile devices to access this mail server, and support calendar and address book synchronization, and the user experience concerning those featuresAdministrator experience with LDAP authentication (if applicable)I would be glad to find a successful use-case using this solutionFortiMail
For these past two firmware releases, it looks like emails won't be sent out for 2FA and for Automation Stitching? I've tried our postfix relay and fortinet's email server and neither work. Sending a test email via diagnose log alertmail test shows nothing incoming on our postfix relay and no relevant logs. I know the release notes list 2FA emails not working for both versions but is it affecting all emails in general?Is there anyway to remediate this, or will I just need to wait for 7.6.7?
Voicemail audio is very low. When playing voicemail you have to turn volume control all the way up to hear audio
Does anyone here know what causes this error and how to fix it.I check the certificate for SSL VPN, and it still shows as valid. So, I'm sure where the error is from.Also note a few weeks ago I upgraded from 7.2.11 to 7.4.11
I can successfully connect to forticlient using all three but when i use the hotspot and wifi dongle the forticlient connects but there is no packet receive, which means I can not access my resources. I tried upgrading my forticlient, disabled ipv6 on dongle adaptor still doesn't work. the hotspot is for every one of the staffs, but the dongle is different from each pc. varying win 10 and 11. It's not specific to windows. There are critical remote users who are having trouble. How can I fix it.FortiClient
Hi all, We are building an automated pipeline to continuously collect SSL-VPN and IPSec debug logs from our FortiGate 90G devices, using:diagnose debug application sslvpn -1diagnose debug application fnbamd 8diagnose debug enable We specifically need the raw debug output (e.g. "SSL established: TLSv1.3 TLS_AES_256_GCM_SHA384") which is not present in structured logs and therefore not available via FortiAnalyzer or syslog. We have already gone through the following KB articles:• Continuous debug monitoring with Bash and Crontab:https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Continuous-debug-monitoring-with-Bash-and-Crontab/ta-p/305973 • FortiGate remote monitoring and logging CLI command output into a file:https://community.fortinet.com/t5/FortiGate/Configuration-Example-FortiGate-remote-monitoring-and-logging/ta-p/189892 Based on our research, it appears that the debug subsystem and the structured logging pipeline are architecturally separate, th
Can two FortiGate clusters (each configured in Active-Passive HA with 2 units) be interconnected through a Core switch?
I have a number of domain joined PCs that are either deleted or disabled that are still showing up in EMS. I have one in particular that keeps trying to push out a FortiClient upgrade but fails because it can't contact the computer. Shouldn't EMS automatically be updating against AD and removing computers that are either disabled or no longer exist?
I've got a strange issue with upstream HSRP Routers from the ISP. I've got a single /29 virtual IP configured on my Fortigate with HA set up.When I have Fortigate A connected to ISP router A, and Fortigate B connected to ISP router B the Internet dies.If I connect both Fortigate to ISP Router A everything works as normal including HA failover. The same is true for ISP Router B. Only when the Fortugates are connected to seaparte Routers does the Internet die.The ISP says they configured e0/1 and e0/2 on both Routers to be in the same L2 VLAN so in my mind this should work correctly.If I add a dumb switch into the mix with both fortigate then the Internet works fine.To me, the logical conclusion is that the ISP hasn't correctly configured their L2 VLAN but am I overlooking something in my config? The monitored interfaces don't trigger a failover so I know at least one thing is wrong somewhere.
FortiGate - 7.6.3FortiClient - 7.2.9 (Windows and Mac) I have been working with Support for weeks now with no success so hoping I can get help here.Fortigate config:config vpn ipsec phase1-interfaceedit "OpsIPSecVPN"set type dynamicset interface "port1"set ike-version 2set peertype anyset net-device disableset mode-cfg enableset proposal des-sha512 aes256-sha512set comments "VPN: OpsIPSecVPN -- Created by VPN wizard"set dhgrp 14set wizard-type dialup-forticlientset nattraversal disableset network-overlay enableset network-id 0set transport tcpset fortinet-esp enableset assign-ip-from nameset dns-mode autoset ipv4-split-include "OpsIPSecVPN_split"set ipv4-name "VPN_PCI_Operations_us2"set save-password enableset client-auto-negotiate enableset client-keep-alive enableset psksecret ENC *** FortiClient config:<connection><name>us2-LOACAL2</name><type>manual</type><ike_settings><keep_fqdn_resolution_consistency>0</keep_fqdn_resolution_c
Intruder Movement Cyber intruders gain access to cloud environments in a variety of ways, ranging from the exploitation of vulnerable software to the use of leaked or harvested access keys. In many cases, these intruders do not stay put; they move through the environment to expand their opportunities for exploitation and persistence. Evidence of this movement is essential for differentiating benign versus malicious behavior and for successfully remediating genuine intrusions. Composite Alerts FortiCNAPP presents suspected intrusions in the form of Composite Alerts. The aim with Composite Alerts is to assemble a complete narrative of suspicious activity, so that it may be triaged without your security team having to look elsewhere for more context. We have designed Composite Alerts to track within a single alert all entities and activity that may be associated with one another. Examples of what we look for include entities associated by suspected lateral movement, p
Je viens de créer un tunnel VPN IPsec grâce à l'option VPN Wizard qui a automatiquement créé les politiques et les objets. Quand je lance mon FortiClient, je n'arrive pas à me connecter : un message d'erreur apparaît. J'ai récupéré les logs mais je ne trouve toujours pas ce qui bloque. C'est un Fortinet 101F avec la version v7.6.6 build3652voici quelque partie des logs ike 0:VPN:64: out B264FC333EFD2592341205A9F51C32110110020000000000000000C80D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E008080030001800200048004000E0D0000144A131C8107035845 5C5728F20E95452F0D000014AFCAD71368A1F1C96B8696FC775701000D00000C09002689DFD6B7120D00001412F5F28C457168A9702D9FE274CC02040D0000144C53427B6D465D1B337BB755A37A7FEF000000148299031757A36082C6A621DE00000000 ike V=root:0:VPN:64 : envoi d'un message IKE (ident_r1send) : , longueur=200, vrf=0, id=b264fc333efd2592/341205a9f51c3211 ike : réduction de la mémoire de 159 744 octets ike V=root:0 : réception de, ifin
I'm trying to set up a dial-up IKEv2 IPsec VPN using the Windows Native VPN client for a "user-based" certificate authentication setup. Specifically, there is no RADIUS or third-party client involved in this setup. The authentication should be handled locally on the FortiGate using the certificate handshake between the client and the firewall. Are there any official or community-validated docs that show this specific configuration? I am specifically interested in the requirements for: The FortiGate Server Certificate: Are there specific SAN or EKU requirements for Windows Native to trust the gateway?The User Certificate: What is the correct way to present these to the FortiGate when using the Windows Native client?Local Authentication: How to properly map the user certificate to a PKI User or User Peer on the FortiGate side to avoid needing an external authentication server.Any CLI snippets or pointers to specific technical tips for the "Mutual Trust" between these two d
Hi,Anyone have any news around arm64 windows collector support?Best Regards,/R.FortiEDR
Azure Virtual FortiGate dropped SR-IOV Accelerated Networking interfaces Port1, Port2, Port3, Port4.More than 50 IPsec tunnels down & came up after restart. System Events logs device port1 loses a SR-IOV slave device sriovslv2.Hyper-V SR-IOV VF secondary is hot unpluggedI raised a ticket with Microsoft & Fortinet for RCA. Can someone helps me to understand root cause & prevent this issue for future.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.