Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hello Team I have configured ADVPN 2.0 between two 120G, BGP is up, i can ping both tunnels, but the issues are that i can ping the Hub loopback from the Spoke but unable the Hub loopback from the Spoke
The port switch connected to the ipphone and if i plug endpoint to the port of the ipphone then the port switch is shutdown even there are no port security in the port switch. Anyone know why?I can see the log from the switch Jul 20 14:30:13: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet2/0/1, new MAC address (f4a8.0d3d.5aeb) is seen.AuditSessionID 11C8640A000038317E6EAFB7 switchport access vlan 251 switchport mode access authentication host-mode multi-domain authentication order mab dot1x authentication priority dot1x mab authentication port-control auto authentication periodic authentication timer reauthenticate 180 mab snmp trap mac-notification change added snmp trap mac-notification change removed dot1x pae authenticator dot1x timeout quiet-period 10 dot1x timeout server-timeout 30 dot1x timeout tx-period 10 spanning-tree portfast
Hello everyone,I'm currently trying to integrate Cisco ISE with a FortiGate firewall for Captive Portal authentication, and I'm running into a couple of issues.FortiGate Network Device Profile In Cisco ISE, I cannot find a FortiGate Network Device Profile when adding the FortiGate as a Network Access Device (NAD). Is there an official FortiGate device profile that needs to be installed, or should I use a generic RADIUS device profile instead? Redirect ACL in Cisco ISE For the authorization profile used during captive portal authentication, Cisco ISE typically requires a Redirect ACL (DACL/ACL). Since the FortiGate is performing the captive portal redirection, what should be configured for the Redirect ACL in Cisco ISE? Should I leave it empty, create a permit ACL, or is there a FortiGate-specific configuration required? If anyone has successfully integrated Cisco ISE Guest/Captive Portal with FortiGate, I would really appreciate it if you could share how you configured it, includin
Hi Everyone,I am currently working on a FortiNAC deployment integrated with Cisco switches and FortiGate firewall, and I would appreciate some advice regarding the captive portal/isolation VLAN configuration.Environment: FortiNAC version: 7.6.x Cisco access switches FortiGate firewall acting as gateway 802.1X + MAB environment Isolation VLAN configured for unknown/non-domain devices Objective:When an unknown or non-domain device connects to the network: Device should fail 802.1X Fall back to MAB Be placed automatically into the isolation VLAN Receive an IP address Open browser and get redirected to FortiNAC captive portal Current Situation: VLAN assignment is working Device is successfully placed into the isolation VLAN Client receives IP address when DHCP is provided by FortiGate Browser can partially reach the FortiNAC isolation portal However, the captive portal redirection is not fully working correctly.Issues Observed: DNS resolution problem Client cannot re
Hi Team,I am facing an issue with my FortiGate VM running in my lab environment and would appreciate any guidance.Environment:FortiGate VM Image: FortiGate-VM64-KVM v6.2.3 EVE-NG installed on VMware Workstation License: Evaluation (Evolution) license installed via GUIIssue:The FortiGate VM was working normally before installing the evaluation license. After uploading and applying the license through the GUI, the VM initiated a reboot.Since then, the VM has been unable to boot successfully. Instead, it continuously crashes with a kernel panic (double fault) during startup and enters a reboot loop.Below is the console output:FortiGate-VM64-KVM #FortiGate-VM64-KVM # Requesting FortiCare Trial license, proxy:(null)The system is going down NOW !!Please stand by while rebooting the system.Restarting systemPANIC: double fault, error_code: 0x0Kernel panic - not syncing: Machine halted.CPU: 0 PID: 1 Comm: initXXXXXXXXXXX Tainted: P 4.19.13 #1Hardware name: Bochs Bochs, BIOS Boc
Hey guys, Lately Ive been struggling with certain configuration. In the environment that i am currently working we have around 450 clients in FortiClient EMS Cloud. These station are not user managed but more of the automated clients that need to automatically connect t vpn gw without user interaction.On two separate occasion when ISP flapped on the FortiGate side not all clients reconnected to the firewall.I can force the connection from EMS when disable/enable the endpoint policy but even then not all clients reconnected. I needed to manually connect to the endpoint and click “Connect” on the VPN tunnel to re-establish the connection.The cause is that when the ISP flaps on the FGT side the clients cannot connect to the VPN gateway and will instead show error. You need to manually press connect to try again when the firewall is reachable again, even tho we have persistent connection and auto-connect in the xml file configured. To workaround this I found some articles that there is way
Psec VPN Tunnel COLLINE-LUWUM Inactive Despite Matching Phase 1/Phase 2 Configuration.
Fortinet should review the release of assets not managed by partners, allow them to be included in new accounts, and make updates available to registered emails even if no assets are currently registered.
Hello,In Forticlient VPN for Linux (Ubuntu 22.04), the IPsec VPN tab does not appear.How can I connect Forticlient VPN IPSEC on Linux?
Hi Community expert, We have issue when connected to FSASE VPN then no internet access at all.Fortinet found the root cause which due to FSASE side had cached the Network ID and when user try reconnect back the VPN, due to different Network ID, it will block the internet connection.Fortinet did not provide workaround for more than 12 days while it affecting our production.We tried to disconnect Telemetry and VPN and reconnect back, but failed.Any expert have home cook workaround on this since Fortinet is not helping? Your kind insight will be really appreciated. Thank You
I have device profiling rule to move all ipphone to IPPhone group. Test the rule manually for one ipphone and the rule is matches, but why the IPPhone group not have any member?
Hey everyone, i'm sure the answer always depends but wondering who uses DARRP vs manual channel configuration. I've been using DARRP for a few years now and it works 'fine', but I have noticed sometimes it will over saturate a channel instead of using different ones. We typically reboot the AP and it will pick a different channel and things are fine. I've considered moving to a manual config. The only reason I don't is the obvious, it's manual and would love for DARRP to just work. For a scope we a few campuses and about 250APs.
if we want tio bulid HA for Fortinac then we need sopecial license? Currently my Fortinac located in on-prem and if i want to build the HA can i use 2nd Fortinac on Azure Cloud?
Hi everyone,We are troubleshooting what appears to be a Linux-specific FortiClient Enterprise issue and I would like to know if anyone has experienced something similar.Environment:FortiClient Enterprise Linux 7.4.7 build 5438 FortiGate 7.4.x IPsec VPN (IKEv2) RHEL 9.x and Ubuntu 24.04Behaviour:VPN authentication succeeds. Tunnel is established successfully. Approximately 9 seconds later the VPN disconnects. The timing is very consistent (always around 9 seconds).What we have already verified:Same FortiGate configuration works perfectly with FortiClient Enterprise for Windows. Reproduced on both RHEL 9 and Ubuntu 24.04. Reproduced on both physical and virtual machines. Reproduced on x86_64 (and also ARM64 with 7.4.7 where supported). Client is not registered to EMS. FortiGate logs do not show authentication failures, DPD timeout, IKE negotiation errors or peer-initiated disconnects. The Linux client appears to terminate the session locally after the tunnel has already been established.
Hello all,I'm using SSL deep inspection through my Fortigate (FGT70G with FortiOS 7.6.7). It works well. The only problem is when applications do things that can't be allowed by any rule. So I've configured an explicit proxy on the Fort that does not perform SSL inspection. Some apps have no way to configure a proxy for them. For example, Steam. So I've been experimenting with some Bash variables. My startscript:#!/bin/bashexport http_proxy=http://fw66.tux.lan:8081export https_proxy=http://fw66.tux.lan:8081export HTTP_PROXY=$http_proxyexport HTTPS_PROXY=$https_proxyexport no_proxy=localhost,127.0.0.1/usr/games/steamIt works also fine. The firewall log confirms this, too.My question is what do I need to watch out for to make sure that another application doesn't accidentally go through the proxy when it's not supposed to? Are there situations where this could happen?Best Regards :)
When I went from 6.4.1879 to 7.0.0601 last May I ended up with extra accounts that where setup with super_admin access, like the followingforticloud techadmin_vpn_access_workadmin_vpn_accessfortinet_techplus other ones does any one know how these got in there? I have since removed them and replaced the 100F to the 120G
Hello, how can one edit the names in their profile
We upgraded the firewalls from 7.4.2 to 7.6.6 and accessing anything internally over the forticlient connection is very slow. Prior to the upgrade everything was good. I have tried changing some of the tcp-mss-send/receive values but nothing seems to work. Anyone have any suggestions on what to look at next other than upgrading to 7.6.7?
Hi Team,I am facing an issue with password expiration on FortiGate.Environment:FortiGate with local users Password policy applied to the users (password expiration enabled) FortiClient on Windows and AndroidIssue:After applying a password policy and allowing the user's password to expire:Windows PC: When the user connects using FortiClient, they are prompted to change their expired password, and the password change works successfully. Android (FortiClient): There is no option or prompt to change the expired password. The login simply fails because the password has expired, leaving the user with no way to update it from the Android device. Is this expected behavior or a known limitation of FortiClient for Android?Screenshot of password policy: Environment:FortiGate Model: 1101E FortiOS Version: v7.4.11 build2878 (Mature) FortiClient Android Version: 7.4.6.0218
Does anyone know if the new exam is using Enteroruse Firewall Admin questions?NSE library has enterprise firewall admin and sdwan modules but nothing that lines up with name Network security architect or is it a whole new exam with both modules combined?
Hello.First, I apologize for my imperfect English. Recently, I started learning about networking using FortiGate.When running FortiOS v7.6.6, I configured IKEv2/IPsec VPN on a FortiGate 60F.At that time, the VPN connection worked correctly.However, after upgrading the FortiGate to FortiOS v7.6.7, the VPN connection stopped working.No VPN configuration changes were made between the upgrade and the failure.Based on the FortiGate logs and packet captures taken with Wireshark,I suspect that during the certificate authentication process,the intermediate certificate that should be sent from the server to the client is no longer being transmitted. After rolling back to FortiOS v7.6.6, the VPN connection started working again.I also confirmed that the VPN connection works on FortiOS v7.6.7when the R12 intermediate certificate is manually imported into Windows.This seems to indicate that the client is not receiving the intermediate certificate from the FortiGate during authentication.The follow
Where I can find click house schema file for FortiAnalyzer ?According to docs.fortinet.com:Each log table stored in an SQL database contains log fields that can be used in datasets.You can view a full list of the fields available for each log type in the FortiAnalyzer ClickHouse Schema file available from the FortiCloud Support page.But I cannot find it.
Hi All Community expert, Good day, looking for some insight that how do you guys reach Fortinet support?Background: FortiSASE have POP related issue while trying call Fortinet supportChallenges:Try to reach support through existing email but no one response Called with ticket number provided, after forward call, waited around 30minutes, No on pickup Try another under emergency impact, still no one pickup (Waited 15~ 25 minutes)Since the FSASE infra being handle by Fortinet, any way as user we can self help ourselves when such issue happen. Ticket (XXXX6250) Feeling helpless right now. Do look for better insight from the community on this.
We have one FG100E that is nearing end of product support coverage and is arranging for tech refresh.What happens if we cannot replace the firewall in time ?especially the online services ?Support Type Support Level FortiGuard IPS Service Web/Online FortiGuard URL, DNS & Video Filtering Service Web/Online FortiGuard AntiSpam Web/Online
Dears,Now i have Alcatel wireless controller omnivista 2500 and i want to make all users are connecting to ssid to authenticate from radius server on fortinac so i need to know what are the steps to do this and kindly be noted that fortinac is integrated successfully with ldap so i need to take the authentication request from radius and forward it to ldap. So i need to know should i add the omnivista to Fortinac and what are the steps should i follow to configure local radius server correctly.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.