Mark a Best Answer
Fortinet Community
Recently active
I’m trying to set up a full-tunnel SSL VPN on my Fortigate 60E running 7.4.6 and for what ever reason, when connected to Forticlient if I go to a website that shows your public IP (ie- www.whatismyipaddress.com), it is showing my laptop’s local internet connection’s public IP instead of the fortigate’s WAN IP. I have tried using the ‘full-tunnel’ portal, disabling the ‘tunnel-access’ portal, changing both to ‘full tunnel’ in the SSL VPN settings and disabling both and creating a new portal which is full tunnel, but whatever I do it keeps showing up with my laptop’s local internet connection. I did some packet traces and it *seems* to be egressing the Fortigate’s WAN interface but for whatever reason it keeps showing my laptop’s internet’s public IP. I can ping devices inside the network (behind the fortigate) just fine, so I know the VPN is working. It’s a real head-scratcher. Can anyone take a look at the config (attached to this post) and tell me what is going on? Of note, I did try
I was looking through the IPAM settings and saved a change accidentally. I lost network access to my 60F as a result. Windows Terminal isn’t working on my pc. I’m looking for a software recommendation to access the 60F from the console port and any advice on how to turn off IPAM from the command line. I’ve only used the GUI so far. Thank you in advance !!
I have 2 WAN links provided by 2 different ISPs with load balancing in HA, and as it happened one of them have been down for a couple of days and the other one is working but occasionally going down.As an emergency solution I plugged in a cellular 5G router to a free port and added the port to the SD-WAN zone.Would it affect the load balancing between the original links if I raised the cost of the cellular link and given it a lower priority? I don't want to keep the traffic going through it if either of the main links is working fine.
Hi all, I tried installing forticlient VPN onto my new computer - Surface Laptop 7. However, it shows the following error. Anyone able to support to rectify this issue?
Hi, I'm having a problem installing the VPN with Forticlient. The installation stops prematurely and displays this message. Have you experienced something similar?
Hi all, have an HA pair of 120G devices running 7.2.13 that use SDWAN to load balance internet traffic between two different fiber circuits. I recently added a cellular backup circuit, but because the cellular bandwidth is relatively low and it’s a metered connection I don’t want to add this to the same SDWAN group/rule as the 2 load-balanced fiber circuits (OutboundWAN_loadbalance). I ended up creating a new SDWAN group (5G_Failover) and all/all rule for the cellular circuit and placed it in the lowest priority position - my objective being that if both fiber circuits go down, traffic will be routed through the cellular backup automatically. Will this work the way I think it will? Hoping to get some insight from someone who has set up something similar before I test this. See screenshot for clarity.
i Download VM Forti 8 and istall it but license invalid
Hi guys, I’m writing here after few weeks of working with Fortigate support. We went into dead end. I have full admin right on Google Workspace and Fortigate 30G running 7.6.7 build 3704, I’ve configured the LDAP as follows:FortiGate-30G (G_Workspace) # showconfig user ldap edit "G_Workspace" set server "ldap.google.com" set cnid "uid" set dn "ou=users,dc=spxxxxxxx,dc=pl" set secure ldaps set port 636 set client-cert-auth enable set client-cert "G_LDAP2" nextendTest Connectivity always works (this is misleading), Test User Credentials work fine - on any user which exist on my Workspace.Problem is when I want to press Browse button, I’m getting error “Invalid LDAP server” while from Workspace logs related to LDAP I can see:Event:Search failedDescription: LDAP search with (objectClass=*) failed with INSUFFICIENT_ACCESS_RIGHTS.Similar error I’m getting when I try to configure User Group based on G_Workspace profile - “Invalid LDAP ser
Hello everyone,FortiGate devices are documented to support a maximum WAN throughput when all UTP layers are enabled.What happens if you connect a WAN with a higher throughput? Is the WAN throughput throttled? Does the firewall stop providing protection? Does the firewall slow down?Thanks
Randomly i got complain from user that they loss access to the network, and if i check on the fnac i got error belowand from endpoint o got this errorIs the error because the fnac wrong send the server certificate? If i replug the LAN cable then the connection is working back.
Hello Fortinet Community,We are currently experiencing an issue where users connecting through the FortiClient IPsec remote-access VPN do not receive their email OTP.Environment:FortiGate model: FortiGate 100F FortiOS version/build: v7.6.7 build3704 (Mature) VPN type: IPsec remote-access VPN Two-factor authentication: Email OTP Email service: fortinet-notifications.com Issue started: September 4–5, 2026 Impact: Multiple/all VPN usersThe VPN authentication process reaches the stage where the user is waiting for the email OTP, but no OTP email is received. This configuration was previously working normally.We enabled the following debug commands:diagnose debug resetdiagnose debug console timestamp enablediagnose debug application fnbamd -1diagnose debug application alertmail -1diagnose debug enableThe certificate authentication shown in the debug completes successfully with:Cert status: GOOD auth_cert_successHowever, we did not see an AuthCode being generated or an SMTP connection initia
Sharing this in case others run into the same thing, and to ask whetherthere is any plan to address it on the 7.4 branch.## SummaryOn a FortiAP-231K with region code "J" (Japan) managed by a FortiGaterunning FortiOS 7.4.x, only W52 channels (36/40/44/48) are selectablein the FortiAP Profile "Set Channels" screen.All DFS channels (W53: 52-64, W56: 100-144) and UNII-3 are greyed out.The "Toggle DFS Channels" and "Toggle Weather Radar Channels" buttonsare disabled as well.In Japan, 5 GHz regulations allow 20 channels in total (W52: 4, W53: 4,W56: 12). Being limited to 4 channels makes high-density design verydifficult, since the channel reuse distance collapses.## Environment and test results- FortiAP model: FAP-231K- Region code: J (Japan)- Country/Region on FortiGate: Japan- Management: FortiGate-managed (CAPWAP)- Radio: 5 GHz, 20 MHz widthI tested every FortiAP firmware from 7.4.5 through 7.6.5.Result: as long as the FortiGate is running FortiOS 7.4.x, the behaviourdoes not change at a
I asked for an extra IP from the ISP. For that they had given me /29 IP block.They said that they will work under the old pilot IP which was already given by ISP. That IP was configured WAN1 and internet are working well. But I need to use that additional IP under firewall.Because i am going to host one web application server. For that server i need to configure public IP directly.If it comes under the server means i can able manage and control who are all want access the app server. I am using FG101E.
LS,I have 2 questions with regards to Fortimanager and normalized interfaces.1. Is it possible, or will it be possible, to map 2 (or more) interfaces in the device mapping to 1 normalized interface. Example, VOICE (SSID) and VOICE (VLAN) interfaces being mapped in the Device Mapping to the normalized interface "Voice" 2. Assume I have a normalized interface Voice-ssid with in the device mapping all the fortigates(ssid) with an Voice SSID interface. I also have a normalized interface Voice-vlan with in the device mapping all the fortigates(vlan) with an Voice VLAN interface.Note that Fortigates(ssid) is not equal to fortigates(vlan).Some fortigates have only Voice-ssid, Some have Voice-vlan and some have both.My question is, can a policy-block where "incoming interface" has both the "Voice-ssid" and "Voice-vlan" applied on all the fortigates in my estate?
Hi all, I hope you're well. I'm currently investigating some connectivity issues users are reporting on AVD displaying 'Paused Connection'. At this site, we're running FortiSwitch 448E-FPOE's and in the system events I am seeing many 'port has come up' and 'port has come down' logs. I've reviewed the spanning-tree instance and confirmed that it is stable, root bridge is correct, no recent TCN's and no high usage of system resources (CPU/Memory) noted. There are no FCS errors or any other stats on the physical ports that would suggest faulty cables. All ports connect to Cisco IP phones and from the logs it looks like the physical port flaps first which then triggered STP port status changes. I'm going to test bypassing the phone and connecting the PC directly to our FortiSwitch to rule out the phone causing the issue but wanted to know if there are any other troubleshooting steps I can take to identify the route cause. Many thanks,&n
FortiGate-VMUL support unlimited vCPUs, but the datasheet does not tell how to calculate the throughput.I need a formula to calculate the throughput by vCPU number.And does the throughput grows linear by vCPU?Thank you.
For lab purpose i use VM with permanent eval license and want to know it use this license are we eligible tp upgrade the firmware? I want to test the v8 before going to production.
i have fortiweb 7.6 and fortigate 7.0 I configured the FortiWeb VIP as a virtual server on the FortiGate. However, when I enable `preserve-client` on the FortiGate, XFF stops working—even though I have configured XFF on the FortiWeb (and I have set up multiple FortiWebs that work correctly). When I disable `preserve-client`, XFF starts working properly again.in XFF enabled Delete Previous XFF Headers
We are using FortiClient SSL VPN (free version, no EMS) and facing an issue where the VPN disconnects within 1–2 minutes after locking Windows, even though the laptop remains powered on and connected to the internet. This issue was seen in version 7.4.3, and we are also experiencing the same behaviour in 7.2.x. Fortinet support could not confirm the root cause due to limited support for the free version. Has anyone faced this issue or found a fix or stable version recommendation?
Dear colleagues, Have any of you managed to register FortiClient in your EMS Cloud using the invitation code? I enter the correct invitation code (all in sequence and with capital letters only). After I entered the, I hope so, correct invitation code in FortiClient, the application minimizes and closes. As a result, it keeps writing that FortiClient is unlicensed and I do not have access to extended options, e.g. saving the password in the SSL VPN connection profile and Always-up connection feature. The FortiClient version is "FortiClient_v6.2.3-build0332-release.apk" downloaded from the support site in the FortiCloud panel. I will be very grateful for all hints. My Android version is 14. Best regards,Witek
Hi, does anyone found a solution, to hold the VPN up and running when the screen is locked? OS: MacOS Sequoia 15.4 and MacOS Sequoia 15.5FortiClient: VPN 7.4.3.1761I had to install the newest FortiClient VPN version after a firewall upgrade as the older versions running in some connection problems.The older versions were stable and connected when the screen was locked. With the new version, the VPN disconnect each time the screen locks. In fortitray.log it is good to see, a message is send to forticlient and immediately after the message, the ssl-vpn is disconnecting. 20250508 14:55:24.613 TZ=+0200 [FortiTray:DEBG] AppDelegate.swift:390 System is locked/sleep20250508 14:55:24.620 TZ=+0200 [FortiTray:DEBG] AppDelegate.swift:404 System is going to sleep20250508 14:55:24.646 TZ=+0200 [FortiTray:INFO] VpnManager.swift:2163 Check VPN Connect without Reauth20250508 14:55:24.657 TZ=+0200 [FortiTray:DEBG] VpnManager.swift:2174 VPN Connection without reauthenticati
HiI have a ticket with Fortinet in regards invitation emails from Forticlient EMS when creating invitations with custom install file for example 7.2.15 the text in the email says version 7.4 and download links points to exe file with capital letters in the file" FortiClientSetup_7.2.15_x64.exe". The problem is the link does not work, changing to small letters sorts it. When browsing the path one level up I clearly see the file name is forticlientsetup_7.2.15_x64.exe with only small characters. Anyone else seeing this?Fortinet frontend asks med do send debug after debug before they escalate it so I just wanted to see if anyone else has the issue. It seems straigh forward in my explanation to send to higher tier support or test locally.
Hi Fortinet Community,We are facing an issue with FortiGate Cloud logging on a FortiGate-100F.Device details:Model: FortiGate-100F FortiOS: 7.4.11 build 2878 Deployment: Standalone / NAT mode FortiCloud subscription: Basic/Free FortiCloud retention: 7 daysIssue:FortiGate Cloud stopped receiving new logs after 05-Sep-2026. The FortiGate GUI shows:"Log uploading has been suppressed. A valid FortiGate Cloud Standard subscription or the latest FOS patch is required to avoid service impact."The last Cloud log upload was recorded on 05-Sep-2026.We verified that FortiCloud logging is enabled: config log fortiguard setting set status enable set upload-option realtime set interface-select-method autoendFortiCloud account status: acct_id=itsupport@datatemplate.comacct_st=OKCloud controller status: Account: name=itsupport@datatemplate.com, status=200, type=basicHowever, fgtlogd shows: Server status: upServer log status: disabledFortiCloud controller connectivity is also working: 17
Although I have already whitelisted https://www.immd.gov.hk/, I would like to know why FortiGate DNS Filter categorized https://www.immd.gov.hk/ as a phishing website?
3400E, 7.4.12I have two VDOMs on the same firewall, root (Prod) and Enterprise. Each has their own WAN connection, networking, and storage assets. It has been requested that the storage assets from each VDOM be accessible from the other VDOM via L2 connection. I haven’t found any documentation that reflects this exact architecture. If anyone could provide some general direction or best practice that would be much appreciated.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.