Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
If i want to make traffic shaper to prioritize traffic from LAN to host 10.10.10.10 located on datacenter for example,then are i need to create the traffic shapper only for this specific host? Or I need to make another traffic shaper for other traffic with medium priority?
If i look from authentication log one host have some authentication request and if we see from below pic there are 4 authentication request.Three of that is failed and one is success. Failed authentication due to timeout and this timeout mean the network devices can’t connect to the fortinac?
Hello, I have a fortigate 100 e physical firewall in my firm and when we play some games, we get dropped randomly, but consistently. Sometimes it takes one minute, sometimes 10, 15, but sooner or latter it happens.Some games are fine - nothing happens, others display this behaviour consistently.We are on a domain but the same happens with local users connected through the firewall. I am not sure what settings in the admin panel could interefere with this but help is appreciated.
I am writing to submit a critical product architectural improvement request regarding how FortiClient EMS 8.0.0 on Linux establishes secure directory integrations.During our recent deployment of FortiClient EMS 8.0.0 on Ubuntu 24, we encountered persistent authentication failures when connecting EMS to our Windows Server Domain Controllers via secure LDAPS (Port 636). Real-time debugging via the adconnector.log file revealed that the authentication loop continuously failed with the following explicit Windows SChannel error wrapper:LDAP Result Code 49 "Invalid Credentials": 80090302: LdapErr: DSID-0C09089D, comment: AcceptSecurityContext error, data 1In the Windows security subsystem, Windows Error Code 80090302 translates directly to SEC_E_UNSUPPORTED_FUNCTION. This protocol violation occurs because the FortiClient EMS backend engine is compiled to automatically encapsulate its Active Directory GUI bind traffic using an NTLM/SPNEGO negotiated token handshake.The Troubleshooting Barrier
Hello,I have an FMG running version 7.4.7 on Azure, and this FMG has 2 ADOMS, each of which manages a “pair” of FortiGate devices operating in HA (via an Azure ELB).We need to perform scheduled backups once a week from the FMG.Is this possible?Is it possible to export the backups to a TFTP server from the FortiGates, but with everything managed through the FMG?Thank you for your feedback.
Hola, Acabo de descargar FortigateOS 7.6.7 en mi Vmware, pero cuando uso la CLI, logro ingresar con mi usuario y contraseñaNombre de usuario:adminContraseña: Contraseña asignada Pero cuando intento autenticarme por la interfaz WEB me sale error de credenciales¿Alguien tiene alguna idea?
We have experienced what appears to be a chronic problem with the 40F routers crashing and dumping their firmware entierly when they lose power unexpectedly. In the last year I would say 8-10 of our deployed 40F routers have dumped firmware, forcing an on-site trip to connect physically and attempt a TFTP load of firmware just to get the box to boot again. I just did one this morning, and another before that just last week. I haven’t gotten anyone from Fortinet to acknowledge an issue, they just ask me to buy more support contracts. Has anyone else had this experience? Is there a paritcular firmware minumum that resolves this issue? We’re setting them all at 7.4.12M which seems to be quite stable on the 60E, 60F, and 80E units we have in the field. I’d like to proactively address this issue if possible.
We have become aware of the following security advisories regarding a vulnerability in FortiClient:https://fortiguard.fortinet.com/psirt/FG-IR-26-156https://advisories.ncsc.nl/2026/ncsc-2026-0296.htmlWithin our organization, we exclusively use FortiClient VPN-only for Windows. We do not use the full FortiClient client or FortiClient EMS.Therefore, we would like to know whether the vulnerability described in FG-IR-26-156 also affects the FortiClient VPN-only client.Additionally, we would appreciate clarification on the following:* Is FortiClient VPN-only affected by this vulnerability?* If so, which versions are affected?* Which version does Fortinet recommend installing to address the vulnerability?* Is an updated version of FortiClient VPN-only currently available?* Does the VPN-only client update automatically, or do we need to manually deploy the updated version to all our laptops?We would appreciate your clarification so that we can take the appropriate measures if necessary.Kind r
Hello,We are using the free FortiClient Windows VPN-only agent, version 7.4.3.Regarding Fortinet PSIRT advisory FG-IR-26-156 / CVE-2026-70465, the advisory lists FortiClient Windows 7.4.0 through 7.4.3 as affected and recommends upgrading to 7.4.4 or later. However, the FortiClient Windows release notes state that versions 7.4.4 through 7.4.7 do not include a new release of the free VPN-only agent, and that users can continue using the 7.4.3 free VPN-only agent. Could a Fortinet representative please clarify the following?Is the latest available free FortiClient Windows VPN-only 7.4.3 build affected by CVE-2026-70465? References:FG-IR-26-156: https://fortiguard.fortinet.com/psirt/FG-IR-26-156FortiClient 7.4.7 release notes: https://docs.fortinet.com/document/forticlient/7.4.7/windows-release-notes/683433/special-notices This is a request for clarification of the public PSIRT advisory’s impact and remediation path for the free VPN-only edition
We have trouble with Forticlient vpn only 7.4.3 on Mac OS 27 Golden State. If we are trying to establish vpn connection, every time we recived time out. Oure Macbook Air is staight from suplier with clean preinstaled Mac Os Golden State. Vpn is configured as IPSec. Firewall is disabled.The same config we are using on Windows and it is working just fine.
An incident occurred involving the FortiMail RAID configuration (RAID60-S) where multiple disks simultaneously switched to "UNKNOWN" status, subsequently transitioned to "REBUILDING," and finally recovered to "OK."Have there been any similar incidents in the past?Does anyone know the cause?Model: FortiMail 3000FFirmware: v7.4.2 (GA-Maturity), build583, 2024.02.07RAID SystemModel: AVAGO MegaRAID SAS 9460-16iDriver: 07.714.04.00-rc1Firmware: 5.170.00-3483u0 (RAID60)├ u0-0 (RAID6)│ ├ p0│ ├ p1│ ├ p2│ ├ p3│ └ p4│└ u0-1 (RAID6)├ p5├ p6├ p7├ p8└ p9p10: SPAREp11: SPARE 3,"2026-09-26","21:07:33.594","system","Disk p3 has changed status from 'REBUILDING' to 'OK'.","warning","0702003084"4,"2026-09-26","21:07:33.594","system","RAID device has changed status from 'REBUILDING' to 'OK'.","warning","0702003084"13,"2026-09-26","17:08:48.462","system","Disk p7 has changed status from 'REBUILDING' to 'OK'.","warning","0702003084"19,"2026-09-26","16:32:54.634","system","Disk p2 has changed status fr
I replaced the secondary unit of a FortiMail (3000F) configured in a primary-secondary setup and rebuilt it using the old secondary unit's configuration.Before connecting it to the primary unit, the following entries appeared in the "Mail Event" logs:/var/spool/etc/mail/submit.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail_ec.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail.cf: WARNING: dangerous write permissionsDoes FortiMail use sendmail for email transmission and reception?For the time being, I have connected it to the primary unit, and data synchronization is complete.If the primary unit were to fail in this state, causing the secondary unit (which generated these error logs) to take over as the primary,would email transmission and reception function correctly?I am concerned about this point. Do you have any information regarding these logs?When I tested sending an email via Webmail from this secondary unit,the following entry appeared in
Hi allNothing important or urgent.According to Fortiguard RSS feed about updates, a new version of FAC (8.0.4) has been released over 24h ago.However, I am not seeing any release notes on the fortiauthenticator page or see a download folder for 8.0.4 (so no firmware or release notes there either).Usually it doesn't take that long after a release info to see downloads and release notes. So, I am not sure if I am just impatient.Anyone know if the info and firmware files have been withdrawn?Thanks
Hi Guys,We are facing a wireless authentication issue specifically with hybrid Entra ID users.Fully cloud-based Entra ID users are able to authenticate and connect to the wireless network without any issues. However, hybrid users are unable to connect.We tested the affected user's credentials directly from FortiGate, and the credential test is successful. But when the same user attempts to connect through the SSID, Windows immediately shows “Can’t connect to this network.”From the RADIUS logs, we can see: RADIUS Access-Request → RADIUS Access-Reject It looks like the credentials/authentication source is working during the FortiGate test, but something is causing the actual wireless RADIUS request to be rejected.Has anyone faced a similar issue with FortiNAC 7.6.7 and hybrid Entra ID users?Also, what would be the best FortiNAC debug/logs to check to determine the exact reason for the RADIUS Access-Reject?Thanks in advance.
Hi community, I have a question about FAZ logging. Which I can’t seem to find the right answer to and I’m hoping you guys may have experienced something similar.Basically I need to undertake some work on a FAZ VM itself where I don’t want new logs to be ingested to the database for a few hours while I do some work. It will be coming up and down so I don’t want it to start taking new logs when it boots up again.I have about 50 Gates logging to this FAZ and it is not feasible to go to each one and turn off the FAZ logging. I’m ideally looking for something like a pause button on the FAZ if it were to exist. I’m on a VM running 7.4.10. I have seen some recommendations about disabling the port on the FAZ used by the Gates so traffic can’t make it through and using a separate management port to continue to connect to the device which I believe is potentially my only option.Any other thoughts?
Hi Community,I am reaching out because I am hitting a wall with a specific client installation and I suspect a hardware/driver conflict, but I need confirmation or ideas on how to debug this further.The Scenario: I am deploying an IPsec VPN configuration with SAML Authentication (Entra ID / Azure AD).Success: The exact same configuration works perfectly on an HP PC.Failure: It fails consistently on a specific Dell Laptop.Environment (Failing Machine):Hardware: Dell LaptopNetwork Adapter: MediaTek Wi-Fi 6E MT7922 (Wireless LAN Card)OS: Windows 10/11 [Please confirm your OS version here, e.g., 22H2]FortiClient Version: VPN-only Client 7.4.3 (Build 1790) / Hotfix 1.8758The Symptoms:The user starts the VPN connection.SAML Authentication window pops up (Microsoft Entra ID).Authentication is successful.The Issue: Immediately after the auth window closes, the FortiClient status hangs (stalls). It does not establish the tunnel.After a short moment, nothing happens, or the connection attempt si
I would like to Integrate Tufin with Remedy in such a way that the CRQs requesting Fortimanager security policies configurations get automated, meaning that Tufin would be able to see the CRQs on Remedy and automatically configure the rules on Fortimanager:Tufin pick up Remedy ticket, figure out which firewall, check for conflicts, push rule to FortiManager. FNDN/API comes in is for the extra checks — like checking FortiAnalyzer logs to confirm the traffic is blocked, verifying policy package sync status, catching duplicate objects with different names, etc. Basically the stuff we'd manually check before making changes. FNDN/API comes in is for the extra checks — like checking FortiAnalyzer logs to confirm the traffic is blocked, verifying policy package sync status, catching duplicate objects with different names, etc. Basically the stuff we'd manually check before making changes.Is there any documentation or support that I could have access to accomplish this? Thank you & best re
Has anyone run into this error when registering FortiClient to EMS Cloud using Google Workspace SAML?Error: 403 - app_not_configured_for_userEnvironment:FortiClient EMS Cloud Google Workspace SAML authentication FortiGate 90G HA pairAlready verified:User access set to ON for all users in Google Admin Attribute mapping is correct ACS URL and Entity ID match between EMS and Google SAML app Not in test modeStill getting the 403 on registration. Anyone else hit this and found a fix?
Hi,What issues could there be in a split-brain scenario? I realize the raw logs sync wouldn't be a problem, but what about configs? For instance, an admin adds some devices to one node while another admin adds new devices to the other node. How can the Geo-redundant HA reconcile those changes? Can that damage Analyzers and Collectors?
Hello everyone,I need assistance with configuring FortiNAC guest self-registration to assign different VLANs based on the location of the Cisco access point.Environment:FortiNAC: Version 7.6.7, deployed at HQ. Cisco WLC: Catalyst C9800 running version 17.9.4a, deployed at HQ. Access Points: Deployed at both HQ and Site A. Guest SSID: Configured for FlexConnect, with local switching at Site A. FortiNAC: Guest self-registration and the relevant policies are already configured.Issue:I want guest clients connecting through APs at HQ to be assigned to the HQ guest registration and guest VLANs, while clients connecting through APs at Site A should be assigned to the corresponding Site A VLANs.Currently, when a guest connects through an AP at Site A and completes the self-registration process, FortiNAC assigns the client to the HQ guest VLAN. I have already created the necessary policies in FortiNAC, but I am unable to get the VLAN assignment to work correctly according to the AP's location.M
Sometime we facing issue the client suddently disconnect from the network and i got below error.Is the fnac reject the client request? This is not permanent issue because if i re-plug the cable then the client can connect again
Hi, Initially, several FortiGate 70G HA pairs became out of sync due to an unknown FortiAP entry, AP-11N-SERIAL-0001, appearing under Managed FortiAPs. Deleting the unknown AP entry from the primary FortiGate resolves the HA synchronization issue. Eventually, I found another entry in System Event log on FortiGate showing that the unknown AP was added after a discovery request was received. Source IP: 66.132.224.63 Event: AP AP-11N-SERIAL-0001 added Reason: Discovery request was received Any insights or relevant known issues would be appreciated. Thank you!
https://fortiguard.fortinet.com/psirt/FG-IR-26-156FG-IR-26-156 (CVE-2026-70465) advisory states the fix is available in FortiClient Windows 7.4.4 / 7.2.12 and later. However, the free VPN-only agent has not received a new release since 7.4.3 (per the community note that v7.4.4–7.4.8 include no new free VPN-only build).Could you confirm: 1. Is FortiClient Free VPN-only 7.4.3 (build 4726) vulnerable to CVE-2026-70465? 2. If yes, will a patched free VPN-only build be released, or is upgrading to a licensed version the only path to remediation? Thanks in advance.
We are currently evaluating our options and already have a quotation prepared for a licensed FortiClient solution, which is awaiting final approval and signature. Our organization has two FortiGate firewalls with active licenses and has been using FortiClient VPN Free Edition 7.4.3.4726 as our VPN client.Approximately 20 days ago, one of our security partners advised us to remove or upgrade FortiClient VPN 7.4.3 due to a reported vulnerability. As a result, we upgraded to FortiClient VPN 7.4.8. However, we later discovered that this version appears to require FortiClient EMS for ongoing management, leaving us uncertain about the most appropriate temporary solution.We have been unable to determine whether FortiClient VPN Free Edition 7.4.3.4726 remains secure for continued use. The software is still available for download, and discussions in community forums appear to reference different CVEs than the ones currently under review.As part of our evaluation process, we would like to unders
Hello,We have a large amount of FortiGates running 7.4 with automatic patch updates.Different kinds of models, but mostly entry-level ranging from 40F to 100F and 50G to 90G.We are looking to upgrade these manually to 7.6 and keeping automatic patch updates on.I am going back an forth between 7.6.6 and 7.6.7, as public opinion varies greatly between these, and according to release notes they both have different issues.Anyone out there know if 7.6.7 is included in the automatic patch updates, or if this still sits with 7.6.6?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.