Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi,I’m using fortimanager provisionning template to manager my IPSec VPN.I’m create a template.In this template I create a IPSec tunnel (Phase 1 and phase 2) with a name like myipsec_model.To create a second Ipsec tunnel, I’m click on clone option. A new tunnel it created with this name : clone_myipsec_model.I can’t rename the new IPSec configuration. I cleck on rename button change the name but this one is not change.I’m use fortimanager 7.6.7.Thanks you for your helpRegardsStéphane
This article describes how to identify and correct SNMPv3 discovery or polling failures when multiple FortiLink-managed FortiSwitch devices have the same SNMP Engine ID.Possible symptoms include:Some FortiSwitch devices cannot be discovered by an SNMPv3-based NMS or CMDB. SNMPv3 polling works for one switch but fails for another using the same credentials. The SNMP manager reports notInTimeWindow, USM not in time window, authentication errors, or intermittent timeouts. Changing the device hostname does not resolve the issue. All devices are synchronized through NTP, but SNMPv3 discovery continues to fail. The OID usmStatsNotInTimeWindows increases during failed polling attempts.A difference in NTP stratum may initially appear related to the error; however, SNMPv3 USM timeliness does not use the device’s UTC wall clock or NTP stratum.ScopeFortiGate managing FortiSwitch devices through FortiLink. FortiSwitchOS. SNMPv3 authNoPriv or authPriv. Third-party NMS, monitoring, inventory, or CMD
Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.Am I missing something in t
I add Fortigate to the Fortinac and why i get below event? Actually the Fortinac connect to the Fortigate using SSH and not telnet.
What is the latest version of FSSO agent for Microsoft Server 2025 AD?We are planning to upgrade our AD to Server 2025 as the existing on is on Server 2016.what are the things we need to take note of
Hi All, VersionFortiGate-81F v7.4.8,build9191,260511 (FIPS-CC-74-8)FIPS-CC mode: enableFortiSwitch-148F-FPOE v7.4.8,build0929,250909 (GA)Security mode: none In our environment, Federal Information Processing Standards (FIPS) is required due to the contract we have. I have been running into the following issues while testing FIPS mode on our equipment.The FortiSwitches appear under Managed FortiSwitches. I can see the firmware version, status, and join time, but I cannot SSH into the switches from the GUI. It also does not show the Connecting From status or the switch IP address.Under FortiSwitch Ports, the port connecting the FortiGate and the FortiSwitch shows as down. When I assign a VLAN to a FortiSwitch port, the VLAN assignment is accepted, but it does not actually take effect on the connected device.However, from the FortiGate CLI, I can SSH into the switch without any issues. The switch status is visible, but it appears that the configuration is not being fully synchronized to t
So how are we all doing SSO user authentication on InTune/Entra joined clients going through an on-prem Fortigate?For many years we've been using the DC SSO agent to authenticate users on domain-joined devices, but now with clients moving away from local AD and so no longer domain-joined so not authenticating on the on-prem DC, this obviously makes the DC agent redundant.I'd rather avoid a captive portal if possible since that's a bit of a step backwards from the nice slick SSO solution we're used to, so what's the most elegant way to do SSO authentication to an Entra 365 account?
I believe when we add the switch to the fnac for 1st time then fnac inventory will collect below data such as Name, Default Vlan, Current Vlan from the switch. When we have changes on the switch, example i make port description and change the default vlan then why in the fnac is not updated? Resync the interface is not helping
Hello, I would like to clarify the expected FortiGate behavior when a FortiGuard/UTM license expires. Our FortiGate 81F had a UTM contract that expired on August 6, 2026. A new license contract was purchased/renewed on Friday, but the new contract has not yet been activated. After the previous contract expired, Internet traffic through one of our existing firewall policies was blocked. Basic websites could not be accessed. The affected firewall policy had the following security profiles enabled: - AntiVirus - Web Filter - DNS Filter - Application Control - IPS - File Filter When we disabled these security profiles, Internet connectivity immediately returned to normal. Fortinet Customer Service stated in the support ticket: “internet connectivity will not be affected due to the absence of a license.” They also stated that basic firewall policies that do not rely on subscription-based security services should continue to function. Therefore, I would like to understand the technical behav
I would like to understand whether the following design is possible and, if so, how it can be configured on a FortiGate 200F or 600F.Current Topology:FortiSwitch 124F ── FLINK_INET_1 ────┐ FortiGate 200FFortiSwitch 548D ── fortilink ───────┘FortiSwitch 124F-POEVLAN 700 configured with IP address 11.11.11.1/30Connected to FortiGate 200F via a FortiLink-enabled interface i.e FLINK_INET_1.FortiGate 200FConnected to both FortiSwitches using separate FortiLink-enabled interfaces.Requirement is to configure VLAN 700 as a Layer 2 bridge only, without Layer 3 routing on the FortiGate.FortiSwitch 548D-FPOEVLAN 700 configured with IP address 11.11.11.2/30Connected to FortiGate 200F via another FortiLink-enabled interface i.e fortilink.RequirementI need VLAN 700 traffic to pass transparently through the FortiGate 200F, effectively allowing the two FortiSwitches to communicate as if they were on the same Layer 2 VLAN.QuestionHow can VLA
Greetings,Looking for advice on best way to migrate from current Palo Alto in Azure to FortiGate.Can it be deployed into the same subnets, or does it need to be in new subnets same vnet?Thanks!-Greg
Hello,I am experiencing a Security Fabric GUI issue on a FortiGate HA cluster after an HA failover and failback.Environment:- Root FortiGate: FortiGate 101F HA Active-Passive cluster- FortiOS: 7.4.11- Five downstream FortiGates- All FortiGates are running FortiOS 7.4.11- Security Fabric uses TCP/8013Issue timeline:1. Before the HA event, the original primary FortiGate displayed all downstream FortiGates correctly in the Security Fabric device dropdown and topology.2. The original primary FortiGate was powered off.3. The secondary FortiGate became the new primary.4. Immediately after logging in to the new primary, the Security Fabric device dropdown already displayed "No topology devices", and the topology could not be displayed correctly.5. The original primary later came back online and became primary again.6. The issue remained present after the failback.7. However, when logging in directly to any downstream FortiGate, the full Fabric Root and downstream device list is displayed corr
so i just got a free ems cloud license using my fortigate cloud and it gave me 3 endpoint i was asking if i transfere the fgt to another account do i lose the trial license or not or could i just activate it again i hope someone have a clear answer i m doing a demo for a client any help is appreciat
Hello, I am able to configure OSPF over IPSec tunnel, but: - I have another OSPF interface (through a physical interface) with lower cost that is Up and routes in the routing table are using this preferred link with correct cost.- When the IPSec tunnel comes Up, the routing table is modified; routes are now using the IPSec interface although I have defined a higher cost for the VPN interface... looks like something is forced. Has anyone come across a similar situation? Thanks, Monty.
When I attempt to Telnet into a Cisco switch located downstream of a FortiGate 50G (FG-50G), the Telnet connection fails.However, through cross-testing, I discovered an odd workaround: Whenever I modify any Firewall Policy on the FG-50G (even an irrelevant change, such as removing a service from a disabled policy), the previously failed Telnet connection to the downstream switch suddenly starts working normally.Unfortunately, if the system is left idle for a while, the Telnet connection issue returns.Network Architecture & Environment Setup Upstream & Downstream Switches: Cisco switches, connected via LACP configured to allow all VLANs. Plaintext interface Port-channel1 switchport mode trunkend FortiGate 50G: Configured in Transparent Mode. Aggregate Interface Configuration: edit "downlink" set vdom "root" set allowaccess ping https ssh snmp radius-acct set broadcast-forward enable set l2forward enable set stpforward enable set type aggregate set me
Hello. I have some Ubuntu 26.04 servers configured in FortiPAM. When I set up Web-SSH access, I enable the "SSH auto-password" option so that FortiPAM can pass the password when I connect and need to run a "sudo" command. The problem is that with this version of Ubuntu, FortiPAM does not pass the password.
Good morning teams 😊;For FortiClient EMS Trial, I created an IPsec VPN tunnel.However, I cannot export the XML configuration file with the VPN password included.Is there a way to export the VPN XML configuration with a password?What I would like is that when the user imports the XML configuration file (with forticlient) , they are required to enter a password before they can access the VPN.thanks for you support 😊
Hello everyone,I am currently working on a production firewall migration from a FortiGate 500D (FortiOS 5.6.x) to a FortiGate 1000F (FortiOS 7.6.x).After migrating the configuration, we are facing an issue where public traffic reaches the FortiGate 1000F but does not reach the internal server. If we reconnect the old FortiGate 500D with the same network topology, everything works normally.EnvironmentSource firewall: FortiGate 500D (FortiOS 5.6.4) Target firewall: FortiGate 1000F (FortiOS 7.6.6) Same public IP addresses Same ISPs Same internal servers BGP is used for routing VIPs are used for inbound servicesWhat has already been verifiedWe have carefully compared the configurations of both firewalls and checked the following:VIP configuration Firewall policies Address objects and address groups Static routes BGP routing Interface mapping Central NAT and Policy NAT Security policies Traffic logs diagnose debug flow Routing tableWe also disabled Central NAT and tested Policy NAT, but the
Hello PAM adminsFortiPAM 1.4.1.I'm very new in FortiPAM and I have questions regarding Web launcher.When I'm in company's local network all works fine, Web launcher, RDP launcher and SSH launcher.However when I'm outside and connect from public IP and try run Web launcher it doesn't work, while SSH launcher and RDP launcher still work fine.I noticed that for both RDP and SSH launcher, PAM opens the browser tab with address bar contains a public address like https://pam.mycompany.com/someaddress.While for Web launcher it opens the private IP of the target, which naturally can't work from WAN without some proxy on the client.If I'm not wrong I think it needs FortiClient in order to work, right?So my question:Does it work with FortiClient for Windows, Linux & MacOS?Does it require EMS?Is there a plan to make it work in future release without FortiClient? (other PAM products can do it without agent)
We encountered some issues accessing some URLs after upgrading from 7.2.12M to 7.4.12M using FGT401E on HA.applications like MS Teams get disconnected suddenly and users reported that access to some external portal become very laggy.upon checking the traffic log, we noticed that the Application name was classify as 2x which is a service group in our firewall.under this group, there is HTTP, HTTPs, TDP, 2X publishing agent port and 2X terminal server agent port.due to the many issues encountered, we have rollback to 7.2.12M
We have identified duplicate endpoint entries in our EMS console and, to manage them, we created two separate groups: one group in Domain and another group in Workgroup.We are able to delete the endpoints that are listed under the Workgroup group without any issues. However, for the endpoints that are present in the Domain group, we do not see an option to delete them. Additionally, we are unable to move these endpoints from the Domain group to the Workgroup group.Could you please let us know:Is there a way to delete the endpoints that are currently listed under the Domain group in the EMS console? What is the recommended process for moving endpoints from the Domain group to the Workgroup group?Any guidance or best practices to resolve these duplicate entries would be greatly appreciated.Thank you.
When i have a new ipphone connected to the network then fnac will move this ipphone to registration vlan before device profiling is running. After device profilling run then i can see the ipphone move to host role ‘IP Phone’ and registered’But after the devices was profiled then how the vlan can be changed automatically to voice vlan? The only way the ip phone get the voice vlan after the ip phone registered by profiling is reboot the ip phone.
Hello,I followed this technical tip:Fortinet Technical Tip – Quickly isolate hosts that have disabled or uninstalled the Persistent AgentIt works very well when I stop and restart the Persistent Agent. The host is correctly detected as At-Risk, and I can see the VLAN change from the remediation VLAN back to the production VLAN as expected.However, when I completely uninstall the Persistent Agent and then reinstall it, the host remains in "Agent Not Communicating" status. The status does not change after the agent has been reinstalled.After reinstalling the agent, I have to delete the host from FortiNAC and restart the workstation before it is detected correctly again.Is this expected behavior?I also have a question regarding the following statement from the technical tip:"An Event Mapping can be created that immediately changes the host status to 'At-Risk' as soon as an event 'Persistent Agent Not Communicating' is created."Does this Event Mapping apply to all hosts, regardless of thei
Hi everyone,I am attempting to set up a new IPsec VPN connection using the standalone FortiClient VPN only v7.2.1.0779 app, but several configuration options appear to be missing from the user interface: Missing Single Sign-On (SSO): When creating an IPsec VPN profile, there is no option or toggle for Single Sign-On (SSO / SAML) anywhere in the GUI. Missing Mode Config Parameters: Under Address Assignment, selecting Mode Config does not reveal options for Encapsulation, IKE UDP port, or IKE TCP port. Any insights or guidance would be greatly appreciated. Thanks!Missing option in my appSSO setting i expectedMode configuration setting i expected
My Fnac license 106 is in use, how we can know detail which endpoint is consume the license?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.