User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hi everyone,We are currently using ExtremeCloud IQ Connect Cloud to centrally manage our Access Points.Our current environment has the following characteristics:We are using ExtremeCloud IQ Connect Cloud for centralized AP management. The cloud platform centrally manages the Access Points. SSIDs and VLANs are configured and managed through the cloud platform. There is no on-premises Wireless Controller deployed in the environment. ExtremeCloud IQ Connect Cloud does not provide a dedicated Management IP that can be directly added to FortiNAC as a network device. We have tested adding an individual AP to FortiNAC using the AP's Management IP. FortiNAC was able to connect to the AP and retrieve information such as the SSID.We would like to clarify the following points:Can ExtremeCloud IQ Connect Cloud be directly integrated with FortiNAC, or is it necessary to add/manage each individual AP in FortiNAC? If individual APs need to be added to FortiNAC, can FortiNAC control client access base
Hi all... I was using FortiClient VPN on MacOS Sequoia and all was working fine, but after update for MacOS 26 Tahoe, I'm experiencing several issues on applications that not recognizes the VPN. For example, I have a Java development environment configured on my Mac, but after update, when I start a Spring Boot backend application, it does not can reach database on Azure. Same for older Java applications using Wildfly 17. Error massage points to my local IP, not for VPN IP. VPN is connected, routes appears as result for netstat command, but I can't connect do my databases because allways returns erros saying my local IP is not on firewall. Anyone has an idea to solve this? Regards,Bruno
Is there any temporary extension, grace period, or interim support option available for our FortiGate 100E while we are waiting for the FortiGate 120G delivery? Can Fortinet verify whether there is an active order for the FortiGate 120G through our vendor or distributor and provide an estimated delivery status? Is there a Trade-Up option available from our existing FortiGate 100E to the FortiGate 120G? If a Trade-Up is available, can any applicable services or remaining entitlements be transferred to the new device?
Hi, would like to ask if the forticare license can be purchased regardless of fortigate version, if there is no some constraint while making the order in base of the device model/version? Many thanks
Hi,I've already set up my FortiNAC scenario with FortiGate and FortiSwitch in the lab, where it worked. Now I'm doing the same in production, but it doesn't want to work no matter what I troubleshoot.I have access value VLAN 31 for my guest network, where I want all users that have MAB to fall into.I have correctly configured the RADIUS attributes, and the logical networks are mapped to VLAN IDs in FG Virtualized Devices > Model Configuration. My host in Policy Details matches the MAB policy, and the logs show that it is matched to go under VLAN 31.My FortiSwitch port has Group Membership Role Based Access and Reset Forced Registration. I've also tried adding Forced Registration/Forced Authentication, and it doesn't work. In my RADIUS logs, I don't know if it's bugged, but FortiNAC RADIUS keeps sending VLAN 1 even though it should match VLAN 31. Why is that happening? REST-HTTP-Status-Code = 204, REST-HTTP-Status-Code = 204, REST-HTTP-Status-Code = 200, Tunnel-Type = VLAN, Tunnel-
Hello everyone,Can anyone confirm whether FortiNAC-F fully supports (or has been successfully integrated) with the following:Aruba 1930 switches TP-Link TL-SG1016PE switches Sophos AP55C access points UniFi U6 Mesh Pro access pointsSpecifically, I’m interested in understanding:Level of support (CLI/SNMP/API… etc) Visibility and control capabilities (profiling, enforcement, VLAN assignment, etc.) Any known limitations or required workaroundsThanks in advance.
We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document LibraryThat last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registrat
Hi everyone, I am trying to add a Fortigate VM eval, generated via the FortiCloud account to the FortiManager VM eval, also generated via the FortiCloud account. So, both units are "self-generated" evals. I am not talking about evals obtained through the local supplier. It is not working!!! From the debug output on FGM, it seems like the FG is not sending any certificate to the FGM while trying to setup communication via FGFM. This is a debug output from the FGM:2025-02-11 06:44:29 Use cert idx=0 by peer_ca = 1 2025-02-11 06:44:29 __info_callback,993: role=svr,state=23, TLSv1.3 SSLv3/TLS write certificate 2025-02-11 06:44:29 __info_callback,993: role=svr,state=40, TLSv1.3 TLSv1.3 write server certificate verify 2025-02-11 06:44:29 __info_callback,993: role=svr,state=36, TLSv1.3 SSLv3/TLS write finished 2025-02-11 06:44:29 __info_callback,993: role=svr,state=46, TLSv1.3 TLSv1.3 early data 2025-02-11 06:44:29 __info_callback,993: role=svr,state=46, TLSv1.3 TLSv1.3 early da
Using Automatic Patching for any vulnerabilities found but it never actually patches anything. Tried even from the actually desktop inside the forticlient to select the vulnerability and then "installed selected", it starts and scan and asks for a reboot but nothing changes/installs. Any help would be greatly appreciated FortiClient
We’ve setup Fortitoken for VPN users. The Ldap authentication suceeds and the fortitoken works when the user enters username as listed in useraccount section. However its failing when the user enters a mixed case username. I’ve read on previous bugs/issues that this is a bug. is this still the case in 7.4.12 (FGT90G) Local user : Testuser Testuser works, fortitoken mfa is presented and the vpn connects. testuser does not work, 2fa token window is presented but when you enter the token (EAPtoken error) is this bug still present in the new version? is the only way to make it work is by making sure users login correctly?
Hi, does anyone found a solution, to hold the VPN up and running when the screen is locked? OS: MacOS Sequoia 15.4 and MacOS Sequoia 15.5FortiClient: VPN 7.4.3.1761I had to install the newest FortiClient VPN version after a firewall upgrade as the older versions running in some connection problems.The older versions were stable and connected when the screen was locked. With the new version, the VPN disconnect each time the screen locks. In fortitray.log it is good to see, a message is send to forticlient and immediately after the message, the ssl-vpn is disconnecting. 20250508 14:55:24.613 TZ=+0200 [FortiTray:DEBG] AppDelegate.swift:390 System is locked/sleep20250508 14:55:24.620 TZ=+0200 [FortiTray:DEBG] AppDelegate.swift:404 System is going to sleep20250508 14:55:24.646 TZ=+0200 [FortiTray:INFO] VpnManager.swift:2163 Check VPN Connect without Reauth20250508 14:55:24.657 TZ=+0200 [FortiTray:DEBG] VpnManager.swift:2174 VPN Connection without reauthenticati
Good day Please assist , I have installed fortigate vm64 version 7.6.7, when trying to access the gui and logging in it says license is being validated I can ping google , dns working fine What could be the issue
Fortiwifi 30E is about to end of support, So can I continue without license. Is any issue will come.
Hi,I have device FG100E which will end of live on this August, but the firmware still old v6.0.2. From upgrade path i did not see currently firmware i used, it’s only show v6.0.18.The question, it’s safe upgrade direct to v.6.0.18 and then follow the upgrade path? Thank you and appreciate
Privileged Access Management keeps getting more demanding. Between hybrid cloud sprawl, contractor and vendor access, and regulatory pressure to prove least-privilege everywhere, PAM platforms have to do a lot more than just vault a password anymore. Fortinet's latest release,FortiPAM 1.9.0, reflects that shift — it's a substantial update that touches secret launching, Just-In-Time privilege, identity federation, network architecture, and hardware scale all at once.Here's a breakdown of what's actually new, and why it matters if you're running (or evaluating) FortiPAM.Secret Launch & Session ImprovementsThe bulk of this release is focused on how secrets get used — not just stored.TCP forwarding for native RDP. Native RDP launches can now route through TCP forwarding instead of the standard native path. This exists mainly to work around real-world friction: certificate revocation check failures, legacy/3rd-party RDP servers that only speak plain-text RDP, and RDP protocol changes th
UNAUTHORIZED Your account cannot be found. Your email address () is not associated with our Customer Service and Support site account. Make sure you use the correct email address or register your account on our Customer Service and Support website by clicking the "Create new customer account" button below. Code: A02E03-151 I want to learn, but my account doesn't exist, yet it lets me log in, and I can't even create another account.
Is anyone able to provide me with the firmware for a Fortinet 60F firewall?
We have a FortiGate-VM running on a trial/evaluation license that expired on July 2 (about 2 months ago). We're planning to deploy a new FortiGate-VM instance (same IPs) and push the existing configuration backup to it, then license the new instance properly.Is it possible to restore a config backup taken from an expired trial VM onto a newly deployed VM instance with a different serial number?
Hello buddies,I’m new to the Fortinet community and would like to start learning how to properly configure and manage FortiGate.My goal is to set up a small hands-on lab where I can learn about firewall policies, VLANs, VPNs, web filtering, and basic network security without affecting the production environment.Could you recommend a learning path, course, documentation, or lab setup suitable for beginners? Would FortiGate-VM be suitable for this purpose? What networking knowledge should I have before getting started?Thanks for any guidance or recommendations here.
I hve a FortiGate 60F and when I console to it I have a message that Password reset functionality is disabled. WhenI try using maintenance mode or the hard reset button it does not working. What options do I have to get in this device? If I have to reset it fully I will as long as I can get into it.
Securing AI at Runtime: Closing the Gap Between AI Adoption and SecurityAI adoption is accelerating across the enterprise. Organizations are using private AI and large language models (LLMs) for software development, research, workflow automation, customer engagement, and other business-critical applications.But as AI moves from experimentation into production, security teams face a growing challenge: traditional security controls were not designed to understand how AI applications process prompts, data, and model responses. Organizations need a security approach that can protect AI workloads while allowing teams to continue adopting the technology at scale.AI Adoption Is Creating New Security RisksMany organizations begin with small AI pilots before expanding AI into critical workflows. As deployments grow, however, the security requirements become more complex. Security teams need to understand who is using AI, what information is being submitted, what the model can access, and what
Hey everybody I'm new . currently I'm working as a desktop engineer and I'm planning to start studying. In a fortigate firewall now can anyone tell me where to start this course any free resources youtube channel n all.
Hello, I need your consultation and help. I want to install FSSO AGENT on my AD server so that Fortigate can see users. There are several installation options for this program:FSSO_Setup_5.0.0289_x64.exeDCAgent_Setup_5.0.0289_x64.exeTSAgent_Setup_5.0.0289.exeCould you explain the differences between them and which one is best? Also, if successful, how can I use web filtering to prevent users from accessing specific websites?#FortiGate
Hello,We are moving store suites and AT&T is changing their IP address.So we need help updating the new IP address configurations.The move occurs this Saturday, 29th at 5 PM PST.Can we schedule a time to make changes?
Hello,I would like to ask if anyone has experienced a similar issue with FortiOS 7.4.12 build 2902.I have a FortiGate 100F, and I upgraded FortiOS from 7.4.11 build 2878 to 7.4.12 build 2902.Before the upgrade, I had configured a Traffic Shaper to be applied only to the **SNS (Social Networking) category** in Web Filter.After upgrading to FortiOS 7.4.12 build 2902, the Traffic Shaper was unexpectedly applied to **all web traffic**, not only the SNS category.The configuration itself appeared to be unchanged.I then disabled the Traffic Shaper and enabled it again. After doing this, the Traffic Shaper returned to the expected behavior and was applied only to the SNS category.The sequence was:1. FortiOS 7.4.11 build 28782. Upgrade to FortiOS 7.4.12 build 29023. Traffic Shaper unexpectedly applied to all traffic4. Disable the Traffic Shaper5. Enable the Traffic Shaper again6. Traffic Shaper correctly applied only to the SNS categoryHas anyone experienced a similar issue with FortiOS 7.4.12?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.