User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hi everyone,Is it possible to register the FortiClient to EMS Cloud without needing the invitation code. We have more than 300 PCs to install the client and we dont want to enter the invitation to each of them. Bests,FortiEng
We are trying DOT1x auth via AD user .Endpoint going in dot1x process and Cisco Switch forward the request to Fortinac but the authentication process is not completing .Continuously showing “RADIUS not enabled on device”.
Hi everyone,We are running a FortiClient ZTNA Access Proxy deployment for our UAT environment and have run into a persistent connection loop immediately following the latest Fortinet ZTNA update. We are looking to see if anyone has hit this specific behavior or has a confirmed Bug ID/Workaround.🚨 The Symptoms Error Encountered: ZTNA Application Not Found (Error Code: 022) with the message Client certificate is not provided. Device Information: N/A. Behavior: It only affects users connecting from external networks (off-fabric). Internal corporate network connections work fine. The Loop: When we perform clean reinstalls or manual re-registrations, it works perfectly for exactly 2 hours, and then abruptly drops back into Error 022. 🛠️ Troubleshooting & Root Cause Analysis Done So FarWe have thoroughly mapped out the behavior and ruled out basic configuration errors: The 2-Hour Pattern & Compliance Discovered: * The 2-hour survival window strongly pointed to a periodic server
I recently bought a Fortigate 60F from Ebay. There is no firmware installed nor is there a backup firmware. How can I get a copy of a firmware to load for my lab? Or is it possible to get past this step to use for a lab?
Hello,I am experiencing a Security Fabric GUI issue on a FortiGate HA cluster after an HA failover and failback.Environment:- Root FortiGate: FortiGate 101F HA Active-Passive cluster- FortiOS: 7.4.11- Five downstream FortiGates- All FortiGates are running FortiOS 7.4.11- Security Fabric uses TCP/8013Issue timeline:1. Before the HA event, the original primary FortiGate displayed all downstream FortiGates correctly in the Security Fabric device dropdown and topology.2. The original primary FortiGate was powered off.3. The secondary FortiGate became the new primary.4. Immediately after logging in to the new primary, the Security Fabric device dropdown already displayed "No topology devices", and the topology could not be displayed correctly.5. The original primary later came back online and became primary again.6. The issue remained present after the failback.7. However, when logging in directly to any downstream FortiGate, the full Fabric Root and downstream device list is displayed corr
Hifound this https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwjWmp6foZuWAxUe1wIHHSbkAusQFnoECBsQAQ&url=https%3A%2F%2Fcommunity.fortinet.com%2Ffortimanager-27%2Ftechnical-tip-how-to-validate-a-provisioning-template-via-api-call-229028&usg=AOvVaw3Jc-lv31tjbMtHsp7LpW2V&opi=89978449only i don’t have access, does this aricle still exitst?
When I attempt to Telnet into a Cisco switch located downstream of a FortiGate 50G (FG-50G), the Telnet connection fails.However, through cross-testing, I discovered an odd workaround: Whenever I modify any Firewall Policy on the FG-50G (even an irrelevant change, such as removing a service from a disabled policy), the previously failed Telnet connection to the downstream switch suddenly starts working normally.Unfortunately, if the system is left idle for a while, the Telnet connection issue returns.Network Architecture & Environment Setup Upstream & Downstream Switches: Cisco switches, connected via LACP configured to allow all VLANs. Plaintext interface Port-channel1 switchport mode trunkend FortiGate 50G: Configured in Transparent Mode. Aggregate Interface Configuration: edit "downlink" set vdom "root" set allowaccess ping https ssh snmp radius-acct set broadcast-forward enable set l2forward enable set stpforward enable set type aggregate set me
Hello guys, I would like to understand whether anyone has experienced a similar issue and, if possible, identify the root cause.I recently performed a migration from a pair of FortiGate 501E devices to a pair of FortiGate 401F devices. Both the FortiGates and FortiManager were running version 7.4.11.The firewalls being migrated were the central hub of our entire infrastructure.They were managed by FortiManager and used SD-WAN Templates extensively.In addition, they were acting as the VPN hub through VPN Manager, with approximately 100 remote FortiGate devices connected to them.To prepare for the migration, I brought the new 401F devices online and initially configured only the primary unit.At that stage, the two new firewalls were not yet configured in an HA cluster.I imported the complete configuration from the old 501E and assigned the new device to the existing SD-WAN template in FortiManager.The only step I intentionally postponed until the migration day was adding the new firewall
I have a Fortigate FGT200F running 7.4.11.It has a large number of physical connections that I’d like to rationalize down to VLAN interfaces on a trunk of multiple 10G lines. As such, the “names” of many of my networks are going to change from “portx” to “some-name-I-pick”. This has follow-on consequences for firewall objects and policies. Naturally, I don’t really want to delete all my policies and objects to get this done.Many of the objects are tied to associated-interfaces. To ease the migration, I tried as a first step to reconfigure the objects by removing the “set associated-interface” command from each object in a backup of the config, then restoring the altered backup.The firewall accepted the altered configuration and booted, however it permitted no traffic to traverse any policies while in this state. During this time it logged errors such asaction="connect" status="failure" reason="SSL accept failed" msg="40B84138E57F0000:error:0A000416:SSL routines:ssl3_read_bytes:ssl/tls
Hello everyone! I'm looking for a way to make FortiClient (the free one, VPN only) save user password. When I fresh install FortiClient VPN (7.4.3 hotfix 1.8758), this checkbox is not present at all. I've read some manuals on XML configs and found configuration parameters that make this checkbox visible. I craft a .conf file with the parameters, import it, the checkbox I wanted is present, but once my connection is establishsed, the utility goes to tray, and then I untray it back (a lock sign in the top right corner is present even if I turned it off before), I break the connection I've just established, and all the checkboxes are gone from GUI.What am I doing wrong and how to fix it? It's just really frustrating to re-enter my password everytime. Any help is appreciated. Thanks in advance!
So i m doing a demo for a project i m doing for a client and i activated the free trial doe 200f series fortigate that work as HAtransfered the assets into another forticlould account but the ems free trial is still on the older accountCan anyome help me with this please an is the free trial can be activated just once even if i move the fortigateCan i remove the trial from the old account and activate on the new oneAny help is apperciated because i m stuck now and been ike this for 2 days
Hello everyone,I am currently working on a production firewall migration from a FortiGate 500D (FortiOS 5.6.x) to a FortiGate 1000F (FortiOS 7.6.x).After migrating the configuration, we are facing an issue where public traffic reaches the FortiGate 1000F but does not reach the internal server. If we reconnect the old FortiGate 500D with the same network topology, everything works normally.EnvironmentSource firewall: FortiGate 500D (FortiOS 5.6.4) Target firewall: FortiGate 1000F (FortiOS 7.6.6) Same public IP addresses Same ISPs Same internal servers BGP is used for routing VIPs are used for inbound servicesWhat has already been verifiedWe have carefully compared the configurations of both firewalls and checked the following:VIP configuration Firewall policies Address objects and address groups Static routes BGP routing Interface mapping Central NAT and Policy NAT Security policies Traffic logs diagnose debug flow Routing tableWe also disabled Central NAT and tested Policy NAT, but the
So for whatever reason on new devices that we have set up the past couple of months we cannot seem to connect to our VPN at all on these new devices. However, the older devices seemingly have no issue. We have tried reinstalling the C++ libraries, reinstalling FortiClient, and updating the NIC driver but have had no luck. All of these new devices are running Windows 11 Pro 24H2 and its a mix of 2 Dell Latitude laptops and one Microsoft Surface Pro 9 if that helps with anything. Also tried looking for some of the older versions on the support page but we don't have the firewall tied to our account so it doesn't let us search through the download page. I have tried version 5.4.3.0870 of FortiClient that we had saved but that didn't work either although I am not sure if that version is Windows 11 compatible or not. Not sure where to go from here any help is appreciated!
Hi everyone,I’m trying to understand whether there is a way to log some TLS/SSL handshake information when using an SSL/SSH profile configured with Certificate Inspection, rather than Full/Deep Inspection.I tested the following settings:set ssl-handshake-log enableset ssl-server-cert-log enableset ssl-negotiation-log enablebut, from my tests, these logs seem to be generated only when the SSL/SSH profile is configured for Full/Deep Inspection.What I would specifically like to retrieve, even when using Certificate Inspection, is information such as:the SNI (Server Name Indication) sent by the client; the negotiated TLS version; ideally, other basic TLS handshake metadata that FortiGate can observe without decrypting the session.Since SNI and TLS version are available during the handshake and do not necessarily require payload decryption, it would be very useful to have them available in the traffic/SSL logs also with Certificate Inspection.Thanks in advance for any suggestions or clarifi
Hi, I need to ask regarding default configuration for FortiClient EMS. In FortiClient EMS 7.2.12 did the “Let EMS schedule automatic upgrade” option under menu System Settings > EMS Settings is enabled by default?I don’t think that I explicitly enabled this option, but I received notification EMS upgrade is available and the scheduled upgrade also has been set.From the following documentation, there is no information that automatic upgrade option is enabled by default.https://docs.fortinet.com/document/forticlient/7.2.13/ems-administration-guide/371397
Hello,I have a FortiGate with two WAN connections, and I am trying to establish two separate site-to-site IPsec tunnels to the same 3rd-party firewall.The design as below;Currently, I have the following issue:IPsec Tunnel 1 over WAN-A → Established IPsec Tunnel 2 over WAN-B → Not Established The same remote peer IP is used for both tunnels.My questions are:Is this design supported without any conflict when using two different WAN interfaces? Is there anything specific I need to configure on FortiGate when both tunnels use the same remote peer IP? Since Tunnel 1 is working but Tunnel 2 is not, what should I check first? Could this be caused by the ISP blocking IPsec/IKE traffic, especially UDP/500 or UDP/4500? What is the best way to verify whether the WAN-B ISP is blocking the IPsec traffic?I have already checked the FortiGate side and would appreciate any advice on what else I should investigate.Thank you.
What is the latest version of FSSO agent for Microsoft Server 2025 AD?We are planning to upgrade our AD to Server 2025 as the existing on is on Server 2016.what are the things we need to take note of
Hi all, We don't have EMS and I've managed to push out a new IPSEC connection to the machines via group policy but obviously as the pre-shared key is encrypted it then creates a random one on each machine so has anyone found a way to do this using group policy at all. We are using the free VPN from Fortinet and not the Windows native one.Thanks
Fortinet TAC has also reviewed the case and confirmed that they cannot see any SMTP traffic leaving the FortiGate.At this point, it appears that the email notification process is never invoked even though authentication reaches the "Token is needed" stage.Hi everyone,I am facing a very strange issue on a FortiGate 601E running FortiOS 7.4.12 (build 2902).Environment- FortiGate 601E- FortiOS v7.4.12 GA build 2902- Multi-VDOM enabled- Root VDOM hosts the SSL VPN- SSL VPN authentication uses Local User + Email-based Two-Factor AuthenticationSymptomsThe SSL VPN login works normally.After entering the username and password, the SSL VPN client displays:"An email message containing a Token Code will be sent..."The System Event log also records:"Send two-factor authentication token code"However, the user never receives the email.What makes this strange is that FortiGate never attempts to establish any SMTP connection.Troubleshooting performed✓ Local user configured with:set two-factor email✓ E
Hello everyone,We’re currently preparing to deploy a larger FortiSwitch environment and are discussing the best way to get started with Dynamic Port Policies.The environment consists of two FortiSwitch 2048F switches as the core and about 20 access switches. The access switches will connect primarily standard clients, printers, Swyx DECT base stations, Raspberry Pi systems, a total of about 40 FortiAPs, and other IoT Devices. However, the APs are distributed very unevenly across the access switches—some have no APs, while others have five, for example.Currently, network segmentation is still very straightforward. The majority of the servers, clients, printers, etc., are still all located within the same network 172.16.0.0/16. Although there is already an organizational address allocation within this network—for example, servers are primarily in 172.16.0.x and clients starting at 172.16.100.x—technically, it is still the same network.A few true VLANs already exist, for example, for Wi-F
so i just got a free ems cloud license using my fortigate cloud and it gave me 3 endpoint i was asking if i transfere the fgt to another account do i lose the trial license or not or could i just activate it again i hope someone have a clear answer i m doing a demo for a client any help is appreciat
Greetings,Looking for advice on best way to migrate from current Palo Alto in Azure to FortiGate.Can it be deployed into the same subnets, or does it need to be in new subnets same vnet?Thanks!-Greg
So how are we all doing SSO user authentication on InTune/Entra joined clients going through an on-prem Fortigate?For many years we've been using the DC SSO agent to authenticate users on domain-joined devices, but now with clients moving away from local AD and so no longer domain-joined so not authenticating on the on-prem DC, this obviously makes the DC agent redundant.I'd rather avoid a captive portal if possible since that's a bit of a step backwards from the nice slick SSO solution we're used to, so what's the most elegant way to do SSO authentication to an Entra 365 account?
Hi,Has anyone else experienced traffic issues with FortiOS 7.6.6 on hardware models other than the 201G?On our 201G, we experienced delays and random disconnections, and Support recommended setting no-acceleration on the specific policies where the issue occurred.We are planning to deploy the 701G soon, so I would like to understand whether similar issues have been reported on other hardware models as well, especially the 700G/701G.
We're building a cryptographic-discovery capability that ingests firewall SSL/TLS-inspection logs. The device is a FortiGate 90G (we don't have the exact FortiOS version yet, so please note any version dependencies).Could you confirm:With SSL/SSH inspection enabled, what cryptographic detail do the UTM/SSL logs contain — TLS version, negotiated cipher, key-exchange protocol/curve, auth/signature algorithm, and server-certificate details (subject, issuer, validity, fingerprint, key alg/size)? Which FortiOS version is required for the full SSL certificate/handshake/negotiation logging (the ssl-server-cert-log / ssl-handshake-log / ssl-negotiation-log options)? Do the logged fields differ between certificate inspection (no decryption) and deep inspection, and what is logged for TLS 1.3? Export options for these logs — syslog (JSON/CEF), FortiAnalyzer, and any REST API for pulling logs — plus the field names/format so we can parse them.A sample log line or a link to the field reference wou
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.