Mark a Best Answer
Fortinet Community
Recently active
3400E, 7.4.12I have two VDOMs on the same firewall, root (Prod) and Enterprise. Each has their own WAN connection, networking, and storage assets. It has been requested that the storage assets from each VDOM be accessible from the other VDOM via L2 connection. I haven’t found any documentation that reflects this exact architecture. If anyone could provide some general direction or best practice that would be much appreciated.
Hi!Command "diagnose vpn ipsec status" shows “NP6_0”, “NP6_1”, .., “NPU Host Offloading”, “CP9” and “SOFTWARE” counters.Two questions:Question 1: what are the units of these counters - bytes, packets, traffic sessions, SAs?Question 2: what is “NPU Host Offloading:” and what kind of traffic causes this counter to increment compared to “NP6_0”, “NP6_1”, .., “CP9” and “SOFTWARE”?Thanks!
Hi team, requesting some support. I was able to successfully create a Ipsec tunnel into my company’s internal network, which connects and all however. I am unable to reach any of the company’s internal resources, and I have already attempted the Vpn connect, but traffic leaks into the internal network troubleshooting step.
Hello, everyone.I have an FG+FMG+FAZ environment in my infrastructure.I need to know if an FMG administrator (for example: admin01) has made configuration changes to “static routes” on the FMG.Is it possible to see this from the FMG itself?In which section could I view these changes? Is it possible to see them in the FMG’s “Event Logs” using a specific filter?Thank you for your comments.
Hello,In Forticlient VPN for Linux (Ubuntu 22.04), the IPsec VPN tab does not appear.How can I connect Forticlient VPN IPSEC on Linux?
Hello everyone, I recently deployed Fortigate v8.0.0 (FGT_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvm) on Eve NG. I acceed to the Web Gui, enter my forticloud account to valid my licence. Then the Fortigate vm is active and it pops me the authentication page. I enter my credentials, the dashbord showed and just after seconds it redirects me to the page login. And this story repeats every time I try to login. So i inspected the page and there is something marked as red: http://x.x.x.x/api/v2/service/security-rating/results?cmdb_tables=%5B%22CertificatesOmniSource%22%5D&scope=globalRequest MethodGETStatus Code401 Unauthorizedconnection keep-alivecontent-security-policy frame-ancestors 'self'date Thu, 10 Sep 2026 11:33:35 GMTkeep-alive timeout=5strict-transport-security max-age=0transfer-encoding chunkedwww-authenticate error="invalid_token"x-frame-options SAMEORIGINx-xss-protection 1; mode=block I don’t know what to do. Can someone help me, please??
This is a long shot, but I just wanted to check on here to be sure. I’m trying to troubleshoot some devices that are offline in difficult-to-access locations. I tried asking Fortinet tech support, and they said that no such database exists. Just wanted to check here just in case.
Hi everyone,Is it possible to register the FortiClient to EMS Cloud without needing the invitation code. We have more than 300 PCs to install the client and we dont want to enter the invitation to each of them. Bests,FortiEng
This just screwed the complete ip interface config on some of our managed FGT: with FMG 7.4 FOrtinet have changed the behaviour of resolving meta data variables!In 7.2. it primary uses vdom level in provisioning templates and global level in scripts.In 7.4. it primary uses global level everywhere! So be sure to change your per-device-mappings in variables to the global object before you first time deploy the config after you upgraded FMG to 7.4. To me this is a bit strange since Fortinet themselves in the FMG 7.4 release notes say FMG 7.4 is downwards compatible from 7.0 on.In case of variables used in scripts/templates its obviously not.
I have many event like this for cisco ipphone. Are this event say that we can enable device profile using CDP?
Hi all, I have an intervlan issue with fortinet firmware after upgraded from 7.4.9 to 7.4.11 , Kindly anyone has face issue please support for that
Hi Guys, My firewall did an update recently from 7.4.9 to 7.4.10 and since then my static routes have stopped working. I have a couple of internal routers that route between different subnets. They were configured a number of years ago, and since then I haven't had any issue with them until now. The routes are very straight forward - Destination (192.168.50.0/24** subnet at other side of router) Gateway (192.168.10.10 router IPt) Interface (LAN) (enabled). Clients gateways are set to the Fortigate device and everything was fine until the update. All clients could reach 192.168.50.x without issue. That's now stopped working. If I add a static route on the clients direct it works fine. So issue is definetly at Fortigate. Also all monitoring of the subnet stop at exact time of update. Tried removing and re-entering/rebooting, just doesn;t want to work. Anyone got a similar issue/fix? Many thanks &n
The FortiClient VPN-only version 7.4.3.4323 has been installed onto a MacBook running macOS 26. Full disk access has been given to fctservctl2 and the network extension FortiTray has been enabled although FortiClientProxy and FortiClientPacketFilter were not present to enable. The settings for this VPN use the public IP address of the FortiGate and various DH Group and encryption levels have been tried but all to no avail. The VPN connection is IPsec VPN and tries connecting for a while then comes back with a connection timeout error. The native IKEv2 client for macOS does not work either. I read somewhere that Fortinet added macOS Tahoe 26 support in FortiClient 7.4.5 but there is no VPN-only version later than 7.4.3. I have also read that SSL-VPN support is being stopped so surely there needs to a new VPN-only version where IPsec VPN can be used. Is there ever going to be a newer VPN-only version released? Or is the option available now FortiClient Standalone? This does not seem to b
I completed the NSE 2 a few years ago. I just checked my profile and I don’t see it in there anymore. Where did it go?
Hello, everyone. We currently have an HA cluster in Active-Active mode in Azure that is load-balanced by Azure Load Balancers.We need to change the HA type to Active-Passive mode and remove the load balancers from the architecture. Is this possible?Does making this type of change require evaluating any additional configuration?I understand that an SDN Connector could be used, but is this specific to Azure or Fortinet? Could this result in an additional “cost” that needs to be paid? Thanks for your comments.
We have a primary Fortigate that is used to control Internet access for several retirement communities across several campuses. We have traffic from all sites Hide-NAT’d to different IPs based on the type of traffic. Guest/public access from all sites get NAT’d to this IP, internal residents get NAT’d to that IP. Internal systems get NAT’d to a different public IP still. This helps when someone on the internal network has a system which has been compromised and is causing one of our public IPs to get blacklisted.However it is still a problem when one of our public IPs gets blacklisted because a system is doing something it shouldn’t. What is the best way on the Fortigate to identify problematic internal systems (particularly spam sources), and block their IP from being allowed public access?
HelloOn FortiGate 30E with FortiOS v6.2.3 build 1066 (GA), the administrator user name and password have been changed.Unfortunatly the credentials have been lost.The default admin account is disabled or deleted.There is no other account.is there a way to recover the administrator access, without losing the configuration?Thanks for your help.Philippe
In DoS Policy » tcp_src_session option.if i set Threshold = 30Is it mean 30 session per 60 seconds ?
We host a Norwegian sports club website that FortiGuard classifies as Malicious Websites, High Risk, "strong confidence of malicious intent". We have submitted it three times through the Web Filter rating request form and each time received the same automated reply keeping the rating, with no evidence given. Hoping someone from FortiGuard Labs can take a look. Domains: kveldeil.no and www.kveldeil.no - both have identical rating history. Rating history, from your own Web Filter Lookup:07 Dec 2016 - added as Malicious Websites29 Mar 2017 - updated as Sports23 Jan 2019 - removed as Sports So the site was flagged in 2016, corrected to Sports in 2017, and in January 2019 the Sports rating was removed, which reverted it to the 2016 entry. There is no detection newer than December 2016 in the history. That suggests the current rating is inherited from old data rather than from anything recently observed. What the site is: Kvelde Idrettslag, an amateur sports club. It runs on our CMS platform
In an Active-Active FGCP cluster, only the primary unit answers ARP requests using the HA virtual MAC address, while subordinate units retain their own physical/real MAC addresses.When the primary load-balances a session to a subordinate unit, could you confirm:Is the packet handed off to the subordinate over the same data/LAN interface (addressed to the subordinate's real MAC), or over the dedicated HA heartbeat link? Since the subordinate never responds to ARP requests, how does the upstream switch learn/populate its MAC table entry for the subordinate's physical MAC — is this purely through standard source-MAC learning when the subordinate transmits traffic (e.g., forwarding the processed packet to its next hop), or is there an additional FortiGate-specific mechanism (e.g., periodic announcement frames) to keep the switch's table populated? Does the subordinate's return/outbound traffic exit directly through its own interface to the destination, or does it always route back through
We currently have a FortiGate firewall running FortiOS version 7.2.11, and we are planning to upgrade the firmware to a recommended and supported version.Could you please share the recommended FortiOS version for our firewall model, along with the correct and supported upgrade path from FortiOS 7.2.11?
This is a head scratcher…..I am a network infrastructure professional services engineer. I support a few dozen customers, many of which use Fortinet products. I run VMware workstation on my laptop, and have a different VM dedicated to each of my customers with their VPN solution installed on their VM. Each VM is a clone of the same base Win11Pro system. My problem is specific to one and only one of my customers.I have no trouble connecting any of my customers except for one, Customer-X. Customer-X has two sites, each with a FortiGate and DIA. One of them is still running FortiOS 7.2 and is allowing SSLVPN (Site-A). The FortiGate at their other site (Site-B), has been upgraded to FortiOS 7.4 and has been configured to allow IPSec remote access VPN. The VM I run for this customer is a standalone Windows11 install (not domain joined). After launching the VM, I have full internet access without any detectable issues. Inside of Customer-X’s VM, the public IP reported by whatismyipa
Hi Guys, Has anyone sat the NSE4 exam so far? I’m taking this exam next month and feeling a bit nervous.Please share your experience how tough was it, which topics came up the most, and what helped you pass?Any tips would be appreciated for all the people like me preparing right now
Hello,In our company we have an EMS instance currently deployed in Azure and we need to move it out to another cloud service. Due to the security requirements given to us, each EMS client must be authenticated with SAML to connect to EMS for management. In the past we have migrated EMS 7.2 to 7.4 Windows → Linux deployment and this caused all of our 2000+ connected users to be thrown out of EMS and needed to be onboarded again. Perhaps someone has already successfully tried EMS migration to another instance (keeping the same FQDN) with SAML authentication enforced? Looking for ways to execute a seamless migration so that endpoints would not need to be onboarded to EMS again. Note that our SAML authentication goes through FortiAuthenticator. Endpoints are ~99% on MacOS. Support has recommended restoring the database/configuration on the new instance but could not definitively say if SAML re-authentication would kick in.Thanks
Hi everyone,We are currently using ExtremeCloud IQ Connect Cloud to centrally manage our Access Points.Our current environment has the following characteristics:We are using ExtremeCloud IQ Connect Cloud for centralized AP management. The cloud platform centrally manages the Access Points. SSIDs and VLANs are configured and managed through the cloud platform. There is no on-premises Wireless Controller deployed in the environment. ExtremeCloud IQ Connect Cloud does not provide a dedicated Management IP that can be directly added to FortiNAC as a network device. We have tested adding an individual AP to FortiNAC using the AP's Management IP. FortiNAC was able to connect to the AP and retrieve information such as the SSID.We would like to clarify the following points:Can ExtremeCloud IQ Connect Cloud be directly integrated with FortiNAC, or is it necessary to add/manage each individual AP in FortiNAC? If individual APs need to be added to FortiNAC, can FortiNAC control client access base
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.