Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hi everyone,I’m currently taking the NSE 1 – Cybersecurity training.I have completed Cybersecurity and Cloud Fundamentals 1.0, all modules are marked Done, including the Module 10 quiz, and I have received the Course Completion Certificate.However, my NSE 1 Certification status still shows “In Progress”.The certification page says I need to pass the NSE 1 online exam, but I don’t see any separate final exam in the course. The last activity is only the Module 10 quiz.Is this expected with the new training platform, or am I missing a step?Has anyone experienced the same issue? Any advice would be appreciated. Thank you!
Google came out with this great convenient feature that allows users to just play a game after a search.i.e. : searching Google for "snake game" will bring up an easily playable game right there in the search results. See attached photo. Is there a way for the Firewall Web Filtering to block this? Another option I had was to through out an AdBlocker extension and specifically block that element on all the student computers but they could just open another browser and it would be way too much work.
Technical Guide: Two Approaches to Blocking Google Arcade & Interactive Doodle GamesAdministrators frequently find that standard web filter categories fail to block Google's built-in browser games (like Solitaire, Snake, Popcorn, or Champion Island) because they are served directly from core Google domains. Below are two proven ways to successfully block these games depending on your current Web Filter architecture.Method 1: Global Wildcard Block (Fastest & Universal)If your organization permits the use of wildcard URL patterns on your Web Filter profiles, this is the most efficient method. It uses broad wildcard matching to catch every current and future game variant instantly.Configuration CLI:config webfilter urlfilteredit <your_url_filter_table_id>config entriesedit 0set url "*google.com/fbx*"set type wildcardset action blocknextedit 0set url "*google.com/logos*"set type wildcardset action blocknextendnextendWhy this works: /fbx* kills all standard overlay arcade game
Hi, I got this error when trying to SSH from a specific server: sshd -1 output shows,“This ip x.x.x.x is not blockedfd 7 is not O_NONBLOCK…Did not receive identification string from x.x.x.x” Any KBs related to this? Thank you!
Hey since Last Sunday we have been using 700G in a HA Cluster in our Environment.I do Not have a single Policy using IPS but the CPU Spikes extremly high because of this. After a restart using "Diagnose Test application ipsmonitor 99" the CPU goes down.Sadly we already see connections impacted by this issue. Websites and Services in out DMZ are extreme slow or timeouts.I already opened a Ticket at FortinetBut maybe there is Somebody with the Same issue and a solution for this topic?Edith: using Firmware 7.6.6
Hi everyone, I am trying to add a Fortigate VM eval, generated via the FortiCloud account to the FortiManager VM eval, also generated via the FortiCloud account. So, both units are "self-generated" evals. I am not talking about evals obtained through the local supplier. It is not working!!! From the debug output on FGM, it seems like the FG is not sending any certificate to the FGM while trying to setup communication via FGFM. This is a debug output from the FGM:2025-02-11 06:44:29 Use cert idx=0 by peer_ca = 1 2025-02-11 06:44:29 __info_callback,993: role=svr,state=23, TLSv1.3 SSLv3/TLS write certificate 2025-02-11 06:44:29 __info_callback,993: role=svr,state=40, TLSv1.3 TLSv1.3 write server certificate verify 2025-02-11 06:44:29 __info_callback,993: role=svr,state=36, TLSv1.3 SSLv3/TLS write finished 2025-02-11 06:44:29 __info_callback,993: role=svr,state=46, TLSv1.3 TLSv1.3 early data 2025-02-11 06:44:29 __info_callback,993: role=svr,state=46, TLSv1.3 TLSv1.3 early da
There is an analyzer with version 7.0.13. When you search fortigate log for the last 7 days on Analyzer, pages of logs come up. However, there is no total log count for the last 7 days anywhere on the page. How can I see the total number of traffic logs in any interval I enter.
Hello all. Looking for anybody who has run into this issue and may be able to provide guidance.We have a pair of FGT 70Gs running 7.4.9 connected to a stack of 148F FSWs running 7.2.5. This is our standard stack and we run it at dozens of sites.We have NAC enabled via the built in managed FSW setting (not FortiNAC). We add devices via NAC policies individually and via wildcard filters such as Vendor name and device type (Example: IP Phone). Our switchports are configured in NAC mode and based on the device that plugs in, the dynamic VLAN will assign to what's configured in the NAC policy.Anywhere from a couple to a few times a day, users with devices plugged into these NAC-mode switchports say their devices are doing network hard down, and then coming back up moments to minutes later. I checked logs and am seeing that the entire NAC MAC address cache appears to be deleted out and then added back, all at once but separated by short periods of time. This aligns exactly with when the issu
We've moved a bunch of PC's from Anyconnect to Fortclient which has gone well however the big thing we've noticed is that if a host is downloading/streaming something then the Forticlient is affected quite badly.So for example we use Forticlient to connect to our office and then RDP to a desktop machine on a private IP 192.168.1.1 for example. If I do a constant ping to 192.168.1.1 then the responses are fine. If I download anything then the response times climb so high as to be unuseable. It's only traffic to the 192.168.1.0/24 network which goes across the SSL-VPN. Any other traffic uses the home internet circuit gateway.Normally I'd be 'yea, this is fine, you are using all the bandwidth' but this doesn't happen with Anyconnect at all. It's like the Forticlient isn't splitting off some bandwidth to stay stable where as Anyconnect is?Is there a way to make Forticlient more stable if the host is using banwidth. I feel silly asking it as instintively I would say no of course not, tell y
Hey guys, Please bear with me here, as I work way more with couple other vendors, though I would say Im fairly verse when it comes to Fortinet : - ). Anyway, here is the scenario. Customer purchased 2 brand new 200F firewalls and we have really odd problem and my colleague (who btw is real Fortigate guru) are having heck of a time trying to fix this problem. Essentially, even if single person is connected to ssl vpn, responses to anything internal are real slow and ping times can go up to 2000 seconds. We tried failover, no luck, disabled assic offload for ssl vpn rule, tested multiple barebone forticlient versions (no luck), enabled DTLS tunnel option, same issue.Now, there are only maybe 6-7 security rules configured, so its super basic. We even have TAC case open for this for about a week, but since they cant replicate it, guy suggested to try reboot the current primary firewall. I have no clue if that will help, as it has been up for only 35 days, but it would need to be sched
FortiClient EMS Server 7.4.7Endpoint email alerts have been configured.Emails are sent to a mailbox, automatically generating a ticket for the Service Desk.I have a Test VM for testing FortiClient settings. It is inconvenient to have a ticket created every time I for example disconnect the FortiClient for testing purposes.Is it possible to exclude a single endpoint from all email notifications?Regards
Hi,What's the deal with the free version of the VPN agent? According to the documentation, it should be 7.4.3.4799, but only version 7.4.3.4726 is available.What's the deal?
Hi everyone,got a new 200G model, used the same firmware as on the 100F, took the config backup of the old device, updated the header in the config and used an usb-device to transfer it to the new device.After the reboot, no login is possible, wheather via GUI or console. Also the reset-button does not work (even after reboot). If I remove the admin-users from the config, it's the same https://speedtest.vet/ .So basically you have to wipe the image and reload it via TFTP, which is of course a pain.Anybody had similar issues? Does anybody know how to resolve the issue? Thanks!
This article describes what is the reason email got rejected by FortiMail, with the classifier showing as 'Access Control-Reject' in the history log.
Hello,We have an environment consisting of 100 endpoints. Approximately 70% of the endpoints are located in an air-gapped environment. To manage these endpoints, I have deployed FortiClient EMS version 7.4.7 in air-gapped mode, as there is no Internet connectivity within this network.The remaining 30% of the endpoints are located in a separate Internet-facing environment. These endpoints do not have connectivity to the air-gapped network, and similarly, the endpoints in the air-gapped network cannot communicate with the Internet-facing environment.Currently we have deployed FortiEMS in air-gap mode and air-gap connected endpoints are already connected. Now facing issue to connect internet facing endpoints.In this scenario, how can I manage the Internet-facing endpoints using FortiClient EMS?Additionally, is it possible to deploy a second FortiClient EMS instance under the same subscription to manage these endpoints separately?Environment Details:FortiClient EMS Version: 7.4.7 Total End
I'm trying to diagnose a FortiClient VPN issue with an IPsec vpn IKE v2. I have the forticlient vpn installed on my iphone 16, my coworker has it installed on his iphone 15, and its installed on a clients iphone 14. My coworker and I have been able to successfully connect to the vpn but the iphone 14 user gets an error -vpn credentials are invalid. I have reentered her username/password multiple times, i've verified the PSK and all other configurations are correct, and have attempted the connection over wifi and cellular on her device. I used the same wifi on my device to successfully connect. I also used her credentials on my device to successfully login. iOS and FortiClient are both up to date. The FortiGate logs reveal that its failing to negotiate phase 1.
Good morning, everyone. I have the following problem, but first, let me describe the scenario. I have a virtual FortiGate 8.0 installed (OVF file imported into VMware Workstation 25h2). It's already installed and configured correctly with web access. The issue arises when I try to install FortiManager, the same version as the FortiGate. The OVF file is available in the VM section of the Fortinet support page, and I can download and import it without problems. The problem starts when I launch the VM; it gets stuck in an infinite loop between 'vmlinuz' and then 'extracting the GZ file,' and it never gives me the login option. Can you help me with this?
Hello everyone, I am a student working on my final year thesis about "implementing sandboxing technology for proactive security of incoming network traffic". I would like to test FortiSandbox in my lab environment( ÈVE NG ), but I cannot find the image available for download. Could you please guide me on how to get access to it for academic purposes? I've already checked: · The official support portal· The Fortinet document library· Various resource sections Is there a specific academic program or evaluation license available for students? Any information about how students can access Fortinet technologies for research would be incredibly helpful for my work. Thank you in advance for your support! Best regards,HODOME Kokou AchilleIAI-TogoTOGO
Hi.Has someone done this smoothly who would be prepared to share their recommendations/runbook/checklist? We ideally want to run them parallel for a short period of time, inject the new VPN Connection into Forticlient on every machine and then have a few users at a time choose the IPSEC VPN.We also need to upgrade them from a 60F to a 70G and wondering if we should do the upgrade to VPN then the migration to new hardware or the other way around?Thanks in Advance.
Dear Fortinet Community.We have a small problem reagrding the authentication for WiFi against ldap. To be honest we have 2 problems and found workarounds that lead us to new problems. And at the moment I get a bit crazy and now I thought. Come back to my professional frieds in the fortinet community as they always have good hints to solve all the issues we have faced in the past.But first of all the environment we have for you:Firewall: Fortigate 401F (Version: 7.4.12)WiFi: WPA 3 Enterprise OnlyWiFi Access Points: FortiAP 231G (Version 7.4.7 0802) & FortiAP 2314G (Version newest... have not installed it yet)Authentication: WPA 3 Enterprise Only against LDAP with ldaps (two methods. 1. With user on firewall or with remote ldap group)LDAP Server: connected via LDAPS using userPrincipalNameWhat was the first problem?1) The ldap does not answered fast enough.So we tried to change global parameters like remoteauthtimeout to 30 and ldapconntimeout to 5000We see that the WiFi connection s
Hello,Could someone explain the differences from the FortiSwitch Feature Matrix for Device Detection vs Network Device Detection and the use cases for NAC Device Telemetry - is it only related to https://docs.fortinet.com/document/fortigate/7.2.0/new-features/612369/track-device-traffic-statistics-when-nac-is-enabled-7-2-4 , since I didnt find that much info that would give me a good understanding of the diff.We were thinking of implementing on a bunch of FSW 148F-POE w/ FortiLink (for which the 2 above features are not available) and use NAC Lite with EMS Tags for the policies but then saw the possibility of also using Device Patterns for Device Category such as Hardware Vendor, Device Familiy, Type, OS etc and would like to know if it would work w/o those 2 features on that model or should reconsider something in the 200 series.Thanks.
Hello,I am facing a persistent issue with a Dial-up IPSec VPN tunnel configuration on our HQ FortiGate.HQ Public IP -> 176.x.x.xLocation -> 91.x.x.xOur goal is to restrict IPSec VPN connections only to a specific list of public IP addresses. To achieve this, I've configured a local-in-policy to permit only our allowed IP group (Public_IPs) and deny IKE/ESP traffic from all other sources.Here is the current local-in-policy configuration:config firewall local-in-policy edit 1 set intf "FortiStore_WAN" set srcaddr "Public_IPs" set dstaddr "all" set action accept set service "IKE" "ESP" set schedule "always" next edit 2 set intf "FortiStore_WAN" set srcaddr "all" set dstaddr "all" set action deny set service "IKE" "ESP" set schedule "always" nextendAn unauthorized remote gateway (e.g., 91.x.x.x) that is not in the Public_IPs address group is still able to establish a VPN tunnel with our HQ
Hello,We recently installed 6 Fortigate 70G on the 3 sites of our enterprise. 2 per site for HA.The 3 sites are equals, connected by a BO VPN by the Internet provider.Do I configure only 1 Root-Fortigate (following de Fortinet administration guide) or 3 ?After some research, I found contradictory information online…Thank you by advance for your response.
Hello,Since I have this computer I've been having issues with the free FortiClient VPN software. The software works fine until you reboot the computer, then it won't open anymore. I get an error message saying "A javascript error occured in the main process" and "Uncaught exception: TypeError: Cannot read properties of null (reading 'TraceLog') at new logger (C:\ProgramFiles\Fortinet\FortiClient\resources\app.asar\assets\js\main.js:24121:36)..." Full error:https://imgur.com/a/0Frtoqq The only thing that seems to work is to delete the software and reinstall it, after that it keeps working fine until I restart the computer. After reboot, the same error appears. We use this software on 500+ computers in our company, although mine is the only one that has this issue. Any help is greatly appreciated.
Good evening everyone,I’m having an issue with the FortiGate VM I imported into GNS3.I can't manage it via the console interface; when I launch the console, it just hangs and nothing displays for several minutes.I’ve tried versions 7.4.11, 7.4.12, and 7.6.6, but none of them are working.I need some help!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.