Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello Team,Following a recent electric power outage, HA FortiGate 201G v7.4.11 build2878 (Mature) cluster displayed the attached alert:“File System Check Recommended"Both units in the HA cluster are synchronized and operating normally,What is the recommended best action to handle this alert in an HA environment?Appreciate your guidance to ensure system stability and prevent potential disk issues. Thank you,
Is it possible to modify the landing page when you open the client to be the Remote Access Tab with it defaulting to a specific connection? The policy calls a profile that has both IPsec and SSL vpn. Wanted to push users to start using the IPSec connection and would be simpler if they just opened the client to that section rather than having to explicitly select the IPsec vpn connection.
After I upgrade our FGT 100F from version 7.2.13 to version 7.4.12, I started having connectivity issues with some of our internal services. And since I did not have time to troubleshoot the issue we had to revert back to version 7.2.13...Has anyone had this experience before? Thanks !
Hello Team Je veux savoir dans quelle condition une box forinet peut etre bloqué a cause des licences
We are in the process of switching to fortigate and fortiap, : we have an environment that we are testing on and the radius server is a Microsoft NPS server, when we use user certificates, the dynamic VLAN works, and the user ends up on the VLAN that the NPS provides, but if we set it so that via the policy it is the machine certificate that is to be used, then the client is not moved to the VLAN that the NPS says, but the client remains on what you can say "onboarding" the VLAN, so the CEO can be the difference from the user that works but not when the machine does not?
I've been requested to stretch a few VLANs across our two networks. Both networks live on the same Fortigate as different VDOMs. Each network has their own storage cluster, which our sys admin has requested I stretch their VLANs across to each other over an L2 connection as it would be faster than L3.Anyway, I'm not sure exactly how to accomplish this. None of the VXLAN diagrams look exactly like my setup. I'm thinking a VWP on the FG between two ports assigned to each network, but not sure where to go from there.Any help would be much appreciated. Also if this is a dumb idea please let me know that too.
I have already defined a URL exclusion rule for URLs containing wildcards and selected the “exempt from action” option. However, access permission for these URLs is still not working.
Hi Everyone,We have a predefined list of company-owned MAC addresses. We want FortiNAC to classify devices whose MAC addresses are in this list as Company Devices, while devices whose MAC addresses are not in the list should be classified as Personal/BYOD Devices.After classifying the devices into these two groups, we would like to apply different compliance policies to each group based on their device ownership. What is the recommended way to implement this in FortiNAC 7.6.x?
Does anyone have the official MTBF figure for the FortiGate 200G?
I have a FortiGate VM deployed on Microsoft Azure, and I’m trying to configure an IPsec Client-to-Site VPN.The current situation is:* FortiGate VM is running on Azure.* UDP 500 and UDP 4500 are allowed in the Azure Network Security Group (NSG) and Azure networking.* The IPsec VPN client is able to reach the FortiGate.* Phase 1 is established successfully.* However, Phase 2 does not come up, and the VPN client cannot establish the VPN connection successfully.I have already verified that UDP 500 and 4500 are allowed, but the issue still occurs.My questions:1. What are the most common reasons for IPsec Phase 2 failing on a FortiGate VM running on Azure when Phase 1 is already established?2. Are there any Azure-specific requirements or settings that I should check for IPsec VPN, such as NSG rules, Public IP, routing, NAT-T, or IP forwarding?3. What FortiGate debug commands would you recommend to identify why Phase 2 is failing?Any guidance or troubleshooting steps would be highly appreciat
Hi everyone, I'm Sarah, just joined this community. We've been running a site-to-site VPN on FortiGate and occasionally notice intermittent drops, especially during peak traffic hours. Has anyone tuned specific settings (dead peer detection, keepalive intervals) to make tunnels more stable? Would appreciate any troubleshooting tips before opening a support ticket.
I have 2 cisco switch managed by fnac and i add the 3rd cisco switch.After i configure the dot1x on the 3rd switch then the authentication is rejected with below errorWhat mean of RADIUS not enabled on device? IN the inventory the RADIUS was enabled.
We are trying DOT1x auth via AD user .Endpoint going in dot1x process and Cisco Switch forward the request to Fortinac but the authentication process is not completing .Continuously showing “RADIUS not enabled on device”.
Starting with FortiOS 7.6.3, the SSL VPN tunnel mode has been replaced by IPsec. I have prepared a consolidated document that outlines the key steps and configuration required to set up IPsec VPN for remote users using SAML authentication. This single document can be used as a reference, eliminating the need to consult multiple sources.IPSEC Remote Access VPN with SAML AuthenticationThis document provides a summarized configuration guide for setting up an IPsec-based Remote Access VPN for users with SAML authentication. Starting from FortiOS 7.6.3, SSL VPN tunnel mode is replaced with IPsec.Reference Document:https://docs.fortinet.com/document/fortigate/7.4.4/ssl-vpn-to-ipsec-vpn-migration/446639/saml-based-user-authenticationSummary NotesIPsec supports SAML-based authentication on FortiClient version 7.2.4 and later.Only IPsec IKEv2 supports SAML authentication. IKEv1 is not supported.1. IDP Configuration (Okta)Create a new application in the Identity Provider (Okta).Assign the approp
Now that mouthful is out of the way - I'm having an issue only on MacOS FortiClient (of course). It was working, so I've no idea what has changed to suddenly have this behaviour. Windows clients are working fine. We're currently trying to migrate from SSL -> IPSec.For the record, I've tried 7.2.12 and 7.4.3 and both exhibit the same issue. I have a complicated auth of FortiClient -> DuoAuthProxy -> Radius -> LDAP. That works fine with EAP-TTLS all the way through. MacOS is 26.So when I connect via the MacOS client, auth work, duo push works, but then SA retransmits happen and whammy Connection Timeout. I finally found an error I could work with from the fortigate:2025-10-23 20:48:57.682116 ike V=root:0:ra-ops_1:343731: sent IKE msg (retransmit): xx.xx.xx.xx:4500->yy.yy.yy.yy:53479, len=9045, vrf=0, id=cbf670251e3656b1/ee13e00c20a25ee3:00000009, oif=6Which correlates to these lines in the iked.log from the FortiClient2025-10-
Hi together,I want to create a new SSID using Forti Management Cloud.I go to configuration/SSID (Beta)/ create new. Then I am asked to select a Template but the list is empty.Where can I create a template for that purpose?Thanks in Advance
Hi AllI would like to know if there is a method to export FGT Policies into Excel (csv) format.Please advise any available options. Am using FortiOS v7.4.12 Many thanks
Hi i have create lots of VPN definitions in the VPN Manager and assign them to Managed fortigates. When i try and install the policy i quickly get this error. "cannot find addr xxxx" "load vpn node x failed". the object is there but need to be loaded on the GW. even tryig with a policy with no VPN in the rules also fails. Any ideas?
Hello,Our client used to be able to connect to our website but is now blocked since the end of July.The error:Fortinet" wasn't installed properly on your computer or the network. Ask your IT administrator to resolve this issue.NET::ERR_CERT_AUTHORITY_INVALIDPlease install a root certificate for "Fortinet". We recommend your IT administrator read the configuration instructions for "Fortinet" to resolve this issue. Antivirus, firewall, and web filtering or proxy software are among the applications that can cause this issue. What could be the reason? How can we debug it with our client? Thanks
Hello - We are in the process of migrating from Cisco firewalls to Fortinet. We support a large medical system with 3 hospitals and many clinics. We have several NATs where certain subnets exit the firewall with specific external IP addresses based upon the traffic source networks. That seems pretty straightforward re-creating with the Central SNAT and overload IP Pools. After those conditions, our default outbound traffic is sent to the internet using a PAT pool of 4 IP addresses and it will also utilize the WAN interface IP address as well for usage and if there is an issue with the PAT pool, traffic will revert to the interface address. This will keep internet traffic flowing although there will be pool exhaustion. My question is on the Fortinet can I utilize the WAN interface IP address along with the IP Pools, or is the interface address not used at all? Thank you
Subject:[FortiOS 7.6.7] Policy GUI infinite loading and missing policies in By-Sequence viewDescription:We currently have a total of 514 firewall policies (Policy IDs 2 through 515). Due to a GUI bug causing an infinite loading loop, we switched the view to By Sequence and applied a filter to force-load the policies.Although the filter counter indicates that all 514 policies exist, the rendering goes through 4 separate loading passes, during which exactly 4 policies fail to render and are omitted from the display. In FortiOS 7.6.7, 4 out of 514 policies are rendered as duplicates on the GUI, causing 4 actual policies to remain hidden. Additionally, an infinite loading bug occurs during initial page load—similar to the Interface Pair View issue—which can only be temporarily bypassed by removing table columns.
Ran into an issue yesterday.Moving some services over to new datacenter everything seemed to work except traffic from VPN tunnel was being dropped because of reverse path fail. After looking at the routing table it was seen that the blackhole routes were still active so the return path was Null instead of the tunnel.After bouncing the tunnel, traffic started to flow normally.FortiOS version is 7.4.12 on 900G and I didn't notice any known issue which would fit to this. Previously similar moves with tunnels were successful without any issues, so it took a while to figure this out.Has anyone else seen this behavior?
I onboard my WLC to fnac and my WLC contains 5 SSID, let say SSID1 until SSID5.SSID1 to SSID4 using WPA-PSK and SSID5 is 802.1x enabled. With this scenario there is no authentication request from WLC to the NAC If the client connect from one from SSID1 to SSID4. But if i check in the license consumed then why some host which connected to SSID1 - SSID4 is consumed license?
upgraded my forticlient ems from 7.2.14 to 7.4.7 then 7.4.8 . upgrade was fine. have noticed some forticlient infomation no longer appears on fortigate yet it was therein 7.2.14. e.g version and owner are blank on fortigate yet populated on ems. how do force sync this? this information was very helpful when analyzing ztna logs on fortigate.
Hi all,does anyone know if the MTBF info is public available? Thanks in advance
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.