Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
This isn't as dumb as it sounds at first glance, I promise! No, I'm not trying to print to a printer that is wirelessly connected to the same SSID, which would obviously be blocked by this setting.I'm trying to set up a wireless network for guests to be able to print to one of our printers, which is wired to a "printers" VLAN. I've set up a tunnel-mode SSID with the relevant multicast firewall policies for mDNS and WSD/SSDP, unicast policies for IPP and RAW, and a Bonjour profile for printers.So far, so good. iOS, Android, and Windows devices can all discover the printer and print. Until I enable the setting to block intra-SSID traffic, at which point none of them can see the printer anymore.Is that setting simply incompatible with multicast forwarding, or what might be going on here? I really want it enabled since I don't want guest devices to be able to communicate with each other. Would an L3 firewall profile potentially work instead?
I'm developing a custom IPS signature for FortiOS 7.4 and want to understand the Lua scripting support in custom IPS rules. Specifically:(1) Can custom IPS rules written in Lua access the os and io modules?(2) Are there any sandboxing restrictions on what Lua code can do in a custom IPS rule handler?(3) Is the Lua state for IPS rules a shared state or per-session isolated state?
Hello,I'm deploying a trusted CA certificate to a number of Fortigates devices that are in sync with FortiManager.This is not for full SSL inspection, but for trusting SSL connections to internal servers (the ones that go into Remote CA Certificates).Right now I'm using a script since I didn't find such functionality in 7.4.11. Dynamic Local Certificate seems to be only for full SSL inspection.bDid I miss anything or scripting is the way to go?Thanks
hi, we have recently upgraded our foritmanager, this fortimanager is already present as our asset in forticloud. When we upgraded our fortimanager, we checked it was not registered. when we enter the credentials to register it, it said the serial number is already present which means communication does not have any issue, but it is not being registered, can someone please help me to check would could be the possible reason or what to check ?
I onboard my WLC to fnac and my WLC contains 5 SSID, let say SSID1 until SSID5.SSID1 to SSID4 using WPA-PSK and SSID5 is 802.1x enabled. With this scenario there is no authentication request from WLC to the NAC If the client connect from one from SSID1 to SSID4. But if i check in the license consumed then why some host which connected to SSID1 - SSID4 is consumed license?
Not working FortiClient 7.4.6.0218 android 17 with fortios 7.6.7 =( When update in google play store? PC/Mac works good
Has the problem with FortiClient VPN for Android been fixed? v7.6.5 causes Error: Could not establish session on the IPsec daemon'. This was reported months ago and now we are being told we have to go to 7.6.7 to remain compliant.
Hello, I run this VM New deployment of FortiAnalyzer for VMware FAZ_VM64-v7.6.4.F-build3579-FORTINET.out.ovf.zip (477.27 MB) on VMware but I'm getting this error not sure what might be the reason.Any help would be appreciated.
Hey everyone,We use FortiClient for VPN and web filtering, managed by EMS across a few hundred endpoints. On one workstation, the FortiClient Web Filter extension shows in Edge as "Managed by your organization" and can't be removed. No other endpoint has it — our own devices don't show it at all.Same FortiClient version, same EMS group and profile as the others, and there's no GPO pushing it.What causes FortiClient to force-install that extension on its own, and where would I look to find what triggered it on just that one machine?Thank you.
Can anybody help me get FortiClient version 6.2.6.0 for linux (debian), please?
Need FortiGate-side workaround: RDP disconnects when client FortiClient VPN connects on internal PCI have a FortiGate 40F running FortiOS 7.4.12.I need to RDP from outside the office to an internal Windows PC at 192.168.1.89. RDP works normally while the PC is not connected to a VPN.The issue is that the user must connect FortiClient VPN provided/configured by our client on the same Windows PC (192.168.1.89). As soon as the client FortiClient VPN connects, my existing RDP session disconnects.I have no control over the client's FortiClient configuration and cannot ask the client to change any settings on their side Basically, the IP is getting change after VPN is connected, what is the work around for this SSL VPN Already verified192.168.1.89 is reachable from the FortiGate. TCP 3389 is listening on 192.168.1.89. RDP works correctly before the client FortiClient VPN is connected. Once the client FortiClient VPN connects on 192.168.1.89, the RDP session disconnects. I also tested FortiG
I’m trying to set up a full-tunnel SSL VPN on my Fortigate 60E running 7.4.6 and for what ever reason, when connected to Forticlient if I go to a website that shows your public IP (ie- www.whatismyipaddress.com), it is showing my laptop’s local internet connection’s public IP instead of the fortigate’s WAN IP. I have tried using the ‘full-tunnel’ portal, disabling the ‘tunnel-access’ portal, changing both to ‘full tunnel’ in the SSL VPN settings and disabling both and creating a new portal which is full tunnel, but whatever I do it keeps showing up with my laptop’s local internet connection. I did some packet traces and it *seems* to be egressing the Fortigate’s WAN interface but for whatever reason it keeps showing my laptop’s internet’s public IP. I can ping devices inside the network (behind the fortigate) just fine, so I know the VPN is working. It’s a real head-scratcher. Can anyone take a look at the config (attached to this post) and tell me what is going on? Of note, I did try
Hi everyone, I'm Sarah, just joined this community. We've been running a site-to-site VPN on FortiGate and occasionally notice intermittent drops, especially during peak traffic hours. Has anyone tuned specific settings (dead peer detection, keepalive intervals) to make tunnels more stable? Would appreciate any troubleshooting tips before opening a support ticket.
I have been running FortiClient 7.4.8 on my endpoints, all of which are Windows 11 devices fully compatible with the FortiClient agent.Recently, I have been experiencing an issue with Google Chrome. Whenever FortiClient requires an update and prompts for a system reboot, after the endpoint restarts, the Chrome configuration appears to be partially reset. It seems as though the browser's local data or cache has been cleared, causing some settings to be lost.The behavior is almost as if Chrome had been reinstalled or its user profile had been recreated after the reboot. The most noticeable impact is that browser extensions lose their configuration and must be set up again.Has anyone else experienced a similar issue with Chrome following a FortiClient update? Does anyone know what could be causing this behavior?I suspect it may be related to the Anti-Exploit feature or possibly the Web Filter browser extension, but I have not been able to confirm the root cause yet.Any insights or recomme
Hello, I am testing dynamic MAP-E connectivity on a FortiGate-100F running FortiOS 8.0.0 build 0167. The Internet service is So-net over the NTT East FLET'S network in Japan. The VNE service appears to be JPIX “v6 Plus.” DHCPv6-PD is working. The FortiGate receives a /56 delegated prefix and the WAN interface receives an IPv6 address derived from that prefix. The relevant WAN configuration is: config system interface edit "x1" set mode dhcp set role wan config ipv6 set ip6-mode delegated set dhcp6-prefix-delegation enable set ip6-delegated-prefix-iaid 1 set ip6-upstream-interface "x1" set ip6-subnet ::1/64 config dhcp6-iapd-list edit 1 set prefix-hint ::/56 next end end nextend After applying this configuration, the VNE diagnostic correctly recognizes the delegated prefix and WAN IPv6 address: end user ipv6 prefix: 240b:10:xx
I was looking through the IPAM settings and saved a change accidentally. I lost network access to my 60F as a result. Windows Terminal isn’t working on my pc. I’m looking for a software recommendation to access the 60F from the console port and any advice on how to turn off IPAM from the command line. I’ve only used the GUI so far. Thank you in advance !!
Subject:[FortiOS 7.6.7] Policy GUI infinite loading and missing policies in By-Sequence viewDescription:We currently have a total of 514 firewall policies (Policy IDs 2 through 515). Due to a GUI bug causing an infinite loading loop, we switched the view to By Sequence and applied a filter to force-load the policies.Although the filter counter indicates that all 514 policies exist, the rendering goes through 4 separate loading passes, during which exactly 4 policies fail to render and are omitted from the display. In FortiOS 7.6.7, 4 out of 514 policies are rendered as duplicates on the GUI, causing 4 actual policies to remain hidden. Additionally, an infinite loading bug occurs during initial page load—similar to the Interface Pair View issue—which can only be temporarily bypassed by removing table columns.
I have 2 WAN links provided by 2 different ISPs with load balancing in HA, and as it happened one of them have been down for a couple of days and the other one is working but occasionally going down.As an emergency solution I plugged in a cellular 5G router to a free port and added the port to the SD-WAN zone.Would it affect the load balancing between the original links if I raised the cost of the cellular link and given it a lower priority? I don't want to keep the traffic going through it if either of the main links is working fine.
Hi all, I tried installing forticlient VPN onto my new computer - Surface Laptop 7. However, it shows the following error. Anyone able to support to rectify this issue?
Hi, I'm having a problem installing the VPN with Forticlient. The installation stops prematurely and displays this message. Have you experienced something similar?
Hi all, have an HA pair of 120G devices running 7.2.13 that use SDWAN to load balance internet traffic between two different fiber circuits. I recently added a cellular backup circuit, but because the cellular bandwidth is relatively low and it’s a metered connection I don’t want to add this to the same SDWAN group/rule as the 2 load-balanced fiber circuits (OutboundWAN_loadbalance). I ended up creating a new SDWAN group (5G_Failover) and all/all rule for the cellular circuit and placed it in the lowest priority position - my objective being that if both fiber circuits go down, traffic will be routed through the cellular backup automatically. Will this work the way I think it will? Hoping to get some insight from someone who has set up something similar before I test this. See screenshot for clarity.
Hi Fortinet Community,I have a question regarding FortiToken Mobile and MFA recovery.I currently have more than 30 FortiTokens installed on my FortiToken Mobile application for different FortiGate/FortiAuthenticator accounts.My concern is the following:If my mobile phone is lost, damaged, reset, or becomes unusable for any reason, I may lose access to all of these tokens. In that situation, I would not be able to use the FortiToken Mobile app to generate OTPs and could potentially lose access to the protected accounts.I would like to know:Is there any official backup or recovery mechanism for FortiToken Mobile? Can FortiTokens be restored on a new phone if the original phone is lost or damaged? Is there any way to synchronize or back up FortiToken Mobile tokens securely? Can FortiGate/FortiAuthenticator MFA use Google Authenticator instead of FortiToken Mobile? Can Microsoft Authenticator be used for FortiGate/FortiAuthenticator MFA? Is it possible to configure MFA using TOTP in a way
i Download VM Forti 8 and istall it but license invalid
Hi guys, I’m writing here after few weeks of working with Fortigate support. We went into dead end. I have full admin right on Google Workspace and Fortigate 30G running 7.6.7 build 3704, I’ve configured the LDAP as follows:FortiGate-30G (G_Workspace) # showconfig user ldap edit "G_Workspace" set server "ldap.google.com" set cnid "uid" set dn "ou=users,dc=spxxxxxxx,dc=pl" set secure ldaps set port 636 set client-cert-auth enable set client-cert "G_LDAP2" nextendTest Connectivity always works (this is misleading), Test User Credentials work fine - on any user which exist on my Workspace.Problem is when I want to press Browse button, I’m getting error “Invalid LDAP server” while from Workspace logs related to LDAP I can see:Event:Search failedDescription: LDAP search with (objectClass=*) failed with INSUFFICIENT_ACCESS_RIGHTS.Similar error I’m getting when I try to configure User Group based on G_Workspace profile - “Invalid LDAP ser
Hello everyone,FortiGate devices are documented to support a maximum WAN throughput when all UTP layers are enabled.What happens if you connect a WAN with a higher throughput? Is the WAN throughput throttled? Does the firewall stop providing protection? Does the firewall slow down?Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.