Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello,We are experiencing an issue in our environment with FortiNAC and would like to understand the root cause.EnvironmentFortiNAC Aruba Access Switches 802.1X enabled on switch ports Printers and endpoints authenticated through FortiNAC Wired environmentIssue DescriptionWe have several devices, including network printers and some user laptops, that intermittently lose network access.Symptoms:Device works normally for a period of time. After some time (sometimes a couple of days), the device loses network connectivity. The switch port remains physically up. Reconnecting the cable does not resolve the issue. As soon as we manually perform "Register as Device" (or re-register the host/device) in FortiNAC, connectivity is immediately restored. No switch configuration changes are required for recovery.This behavior affects both:Printers Wired laptopsObservationsDuring troubleshooting, we noticed that some affected hosts show:Last Modified By: Systemshortly before or around the time the de
Hello all. We are rolling out 7.4.2 to our Mac fleet. We are seeking a way to do this via automation to auto-enable the system extensions so that when our JAMF instance touches our devices, it will install automatically. We are seeking to do this via PKG or DMG. Is this possible?
Hi,Is there a way to get report through fortianalyzer about rules on the firewall, not the usage of those rules?We have shared firewall for some users, and customers would like to receive reports of rules associated with their networks.It seems I can only get them to the report if there is either all logging enabled on the rules, or MTU filters record the event. I would like to have just rows of the rules, but afaik it isn't possible what I have searched?All loggin is the only way?
I am trying to create a FortiAnalyzer report that displays Sent and received interface bandwidth utilization over time for the Fortigates.The existing reports available in FortiAnalyzer provide data utilization using 5-minute averages, but they do not clearly identify the utilization for each individual interface.Below are multiple topics in the community:https://community.fortinet.com/support-forum-92/need-bandwidth-utilization-report-between-two-fortigate-devices-specific-interface-time-range-224155https://community.fortinet.com/fortianalyzer-6/technical-tip-how-to-generate-throughput-utilization-billing-report-98335https://community.fortinet.com/support-forum-92/fortianalyzer-how-to-generate-a-report-for-real-time-bandwidth-out-to-in-33756https://community.fortinet.com/support-forum-92/generate-bandwidth-utlization-report-for-specify-interface-in-faz-197578?tid=197578&fid=92As a possible solution, I enabled performance statistics on the FortiGate. FortiAnalyzer is now receiving
Dear All, Anybody can explain in laymon term what is under lay and over lay in SDWAN concept and how does it work. Why under lay and over lay need. Thank you in advanced for sharing the knowledge.
Hi,I've already set up my FortiNAC scenario with FortiGate and FortiSwitch in the lab, where it worked. Now I'm doing the same in production, but it doesn't want to work no matter what I troubleshoot.I have access value VLAN 31 for my guest network, where I want all users that have MAB to fall into.I have correctly configured the RADIUS attributes, and the logical networks are mapped to VLAN IDs in FG Virtualized Devices > Model Configuration. My host in Policy Details matches the MAB policy, and the logs show that it is matched to go under VLAN 31.My FortiSwitch port has Group Membership Role Based Access and Reset Forced Registration. I've also tried adding Forced Registration/Forced Authentication, and it doesn't work. In my RADIUS logs, I don't know if it's bugged, but FortiNAC RADIUS keeps sending VLAN 1 even though it should match VLAN 31. Why is that happening? REST-HTTP-Status-Code = 204, REST-HTTP-Status-Code = 204, REST-HTTP-Status-Code = 200, Tunnel-Type = VLAN, Tunnel-
Hi everyone, The UniFi OS GUI currently has limitations regarding routing traffic coming from an inbound VPN tunnel into an outbound VPN tunnel (VPN-to-VPN routing). If you have a Route-Based IPsec (VTI) tunnel and want to route its traffic through an outbound WireGuard client connected to a VPS/VPN provider, the standard Traffic Routes won't catch it. After some debugging via `iptables` and `tcpdump`, I've managed to build a reliable solution using Linux **Policy-Based Routing (PBR)** and `systemd` persistence that survives UDM Pro reboots and firmware updates. Here is a step-by-step guide on how to achieve this. --- ### Prerequisites Before starting, connect to your UDM Pro via SSH and find your exact interface names:1. **Inbound IPsec VTI Interface:** Run `iptables-save | grep vti` to find it (e.g., `vti64`).2. **Outbound WireGuard Interface:** Run `wg show` to find it (e.g., `wgclt1`).3. **Inbound Subnet:** The network behind your IPsec tunnel that needs internet access through Wi
Hello, I recently updated FortiClient on a laptop to version 7.4.3.1790. Since then, the VPN has been unable to connect, and the Fortinet virtual adapters show as "Unknown Device" in the Windows 11 Device Manager. Every time I reboot the laptop, a FortiClient popup appears and says that FortiClient drivers have been installed that require a restart to finish. Each restart adds two more Unknown Devices in Device Manager. A reinstall or repair of FortiClient doesn't fix the issue. I've tried reinstalling Visual C++ 2015-2022, but no luck there either. The two virtual adapters are supposed to show as:- Fortinet SSL VPN Virtual Ethernet Adapter- Fortinet Virtual Ethernet Adapter (NDIS 6.30) How can I fix these two virtual adapters? Thanks,Simon
Environment: FortiGate-VM64-OPC on OCI, FortiOS 7.6.7, A-P unicast HA, ha-mgmt-status enabled on port1 (reserved management interface, config ha-mgmt-interfaces with its own gateway).Two related issues, same root cause suspected:1. FortiToken Cloud MFA fails when logging into a unit directly via its own management IP - works on one unit, fails on the other. Traced to: the unit whose management interface needs to reach FortiGuard/FortiToken Cloud for validation has no outbound path. Confirmed via execute ping-options source <port1 IP> + ping 8.8.8.8 -> 100% loss, on both HA members (tested independently, not just the HA secondary).2. Separately, our OCI SDN connector (used for HA VIP failover) never completes the "refreshing IP info of instance / checking secondary ip" step in its debug output - it finishes generic resource inventory and just loops, never attempting the actual private IP move. Wondering if this is related to the same interface/routing gap.What we've confirmed:-
Is there anyway for RSAT tools to work with ZTNA? Users can get to domain controller via ZTNA but RSAT tools is not working.
Our company is transitioning from SSL-VPN to ZTNA. We currently have Microsoft conditional acess policies allowing certain public IP addresses configured for SSL VPN allowing the public IP of the VPN firewall. Is there anyway for this to work with ZTNA? Currently, the microsoft logs are showing the public IP of individual users instead of the firewall.
HI all, I’m deploying a couple of 701G fortient onver an inter DCI (one fortinet on each DC) using vxlan (on a nexus 9k) and I found that when HA is enabled the same MAC are generated and for this reason this MAC’s are getting dropped from vxlan table and HA is not forming. If HA is disabled and I leave them as stand alone and put IP’s on the interfaces they can ping each other (the same for mgmt) once HA is enabled and the virtual MAC’s come in the connectivity on HA is not working and both MGMT can’t ping each other anymore and I have a duplicated messaje on my nexus logs. Does anyone know what could be wrong? Working on a 7.4.11 Regards
Hi erveryone,We use the FortiMail only as a filter.The MTA is provided by an external service provider.The FortiMail is therefore between our service provider and our internal mail server.We have deactivated the SPF check in the Antispam and in the Session Profile, because this is not needed in our construct.Nevertheless we get in the log for most mails a SPF Fail/Softfail with the message "that MTA (IP address) is/may not permitted to send email for ....".The mails are processed and sent correctly but this log entry bothers us.We are aware that the external MTA will normally trigger SPF since the mail is not sent from the original mail server to FortiMail.Is it possible to disable the entry, it is not relevant for us or is there another hidden setting somewhere that enables SPF checking?Are any of you aware of a similar problem or could it be something else? Thank you in advance!!
I have a strange case with some fortiAPs right now. 1x FAP 231G and 1x431F both on 7.6.4. I want to set a VLAN ID to have the management tagged but the variable is missing when typing cfg -s. Then i connected to the HTTPS GUI and the field is also missing. I typed in the command cfg -a AP_MGMT_VLAN_ID=200 on the CLI and I got no error. cfg -c for commit to flash. Nothing happened. Reboot and still no change, the AP won't take the VLAN ID. I have 100 more 231G on this site and also 20x431F and they all have the variable and it works fine. How is this possible? Anyone else encountering this problem?
I have a problem with FortiClient VPN 7.0.8.0427 on a few Windows PCs. When trying to connect I get:‘VPN Connection Failure - VPN connection failed. Please check your configuration, network connection and pre-shared key then retry your connection. If the problem persists, contact your network administrator for help.’The VPN does not work with any user account on the affected PC. The same users, the same VPN profile and the same FortiClient version work correctly on other computers. The problem was already present on a fresh Windows installation, so it is not caused by software installed later. Reinstalling FortiClient also did not help.Basic network connectivity looks fine. Internet connection works, the FortiGate is reachable and the client can communicate with the VPN gateway. I tested both Ethernet and Wi-Fi with the same result. Packet capture confirms that UDP/500 traffic reaches the FortiGate and the FortiGate response comes back to the affected PC.I also tested several other lap
Hi all, I have peaks of high CPU usage on the FortiSwitches FS-248E model. Theses FortiSwitch are in modo fortilink.The event is the following: How can I lower CPU usage? Currently very few customer traffic.Thanks,
SUMMARYOn FortiClient for Linux, an IPsec IKEv2 + SAML tunnel imported from an exported XML configuration always fails at IKE_AUTH, even though SAML authentication completes successfully and the encrypted PSK field, password, and profile are all correct. Root-cause analysis shows the client never decrypts the field-level encrypted preshared key (EncX... format) before handing it to iked - it passes the raw encrypted blob through as if it were the plaintext key. ENVIRONMENTFortiClient (Linux), tested and reproduced identically on:- 7.4.3.5411- 7.4.4.1796 (includes the fix for Bug ID 1035496, connection problems with SAML, multifactor authentication, and Linux CLI options)- 7.4.8.1904OS: Debian 13 (Trixie), amd64 - same .deb package family as the supported Ubuntu builds.Connection type: IPsec IKEv2, Preshared Key + SAML/SSO (sso_enabled=1, ike_saml_port=9443), imported via Configure VPN > XML > Import XML Configuration from a profile exported on a Windows FortiClient install. STEPS
Download links for FortiClient EMS invitations are not working because the filename in the invitation are Initial Cap, while the filenames are all lower case. Running version 7.4.8. This was working up to yesterday.
This is a head scratcher…..I am a network infrastructure professional services engineer. I support a few dozen customers, many of which use Fortinet products. I run VMware workstation on my laptop, and have a different VM dedicated to each of my customers with their VPN solution installed on their VM. Each VM is a clone of the same base Win11Pro system. My problem is specific to one and only one of my customers.I have no trouble connecting any of my customers except for one, Customer-X. Customer-X has two sites, each with a FortiGate and DIA. One of them is still running FortiOS 7.2 and is allowing SSLVPN (Site-A). The FortiGate at their other site (Site-B), has been upgraded to FortiOS 7.4 and has been configured to allow IPSec remote access VPN. The VM I run for this customer is a standalone Windows11 install (not domain joined). After launching the VM, I have full internet access without any detectable issues. Inside of Customer-X’s VM, the public IP reported by whatismyipa
I am using FortiGate as aDHCP Server and Windows Serve as DNS (Active Directory). Clients are getting IP addresses correctly, but DNS records are not being created or updated automatically in WINDOWS DNS.So:DHCP works fineBut no A or PTR records are created in DNSIs this expected behavior with FortiGate DHCP, or is there a way to enable dynamic DNS updates?Any help would be appreciated.
I am having 4 VMs 2 each for FortiNAC and FortiAuth, reachability is completed, all kinds of https or http accesses are allowed from CLI, but still unable to access GUI of any machine
Hello, I would like to know if anyone in the community has any AutoCAD document with drawings of the devices, any of them really, but if I had to ask for just one, it would be the FGR-60F. If anyone has something like that, I would really appreciate it.
Hi,I have a strange case with some fortiAPs right now. 1x FAP 231G and 1x431F both on 7.6.4. I want to set a VLAN ID to have the management tagged but the variable is missing when typing cfg -s. Then i connected to the HTTPS GUI and the field is also missing. I typed in the command cfg -a AP_MGMT_VLAN_ID=200 on the CLI and I got no error. cfg -c for commit to flash. Nothing happened. Reboot and still no change, the AP won't take the VLAN ID. I have 100 more 231G on this site and also 20x431F and they all have the variable and it works fine. How is this possible? Anyone else encountering this problem?
Hey everybody I'm new . currently I'm working as a desktop engineer and I'm planning to start studying. In a fortigate firewall now can anyone tell me where to start this course any free resources youtube channel n all.
how can implement
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.