Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Dear Community,I am writing you all because in my Company we have massive Issues with FortiClient (EMS) on the macOS Clients. I am working as IT Administrator and I am responsible for the MacBook’s.The problem:On the Mac Devices we have since many months the problem that when connected with the VPN the Download Speed is extremely low. We have an External Internet Connection at Work with 100 Mbit/s. With WiFi i get WITHOUT VPN like 80-100 Mbit/s. With VPN ON i get like 5 to 10 Mbit/s (with LAN connection it’s a little bit better). There were also days where it was more so its really inaccurate. The Upload Speed is the same with VPN ON and OFF. ~ 40 Mbit/s. For Windows VPN OFF and VPN ON is the same Download Speed. Some informations:EMS Policies are the same for the Windows- and the macOS Clients We have this features: Remote Access (SSLVPN with Split Tunneling, Webfilter and Vulnerability Scan) Windows Devices are still on 7.2.14 and macOS Devices are on 7.4.5 (I also tested today 7.4.7
ScenarioEnvironment with multiple FortiGate firewalls connected to a FortiAnalyzer VM for centralized log collection and analysis.Environment VersionsFortiAnalyzer VM: 7.4.11FortiGate: 7.2.13Fabric ADOM enabledSome FortiGate devices operating in HA cluster modeAfter upgrading the FortiAnalyzer from version 7.4.6 to 7.4.11, the FortiGate devices stopped displaying FortiAnalyzer logs directly from the FortiGate GUI.SymptomsWhen accessing logs from the FortiGate GUI:Log & Report → Forward Traffic / Event Logsthe page remained completely blank.However:FortiAnalyzer continued receiving logs normallyDevices remained online in Fabric View / Device ManagerLogs were visible directly in the FortiAnalyzer GUINo explicit communication or authorization errors were displayedAdditionally, the following behaviors were observed:Analytics (actual/config days) above 100%Archive Usage above 90%diagnose dvm device list showing:conn: unknownconf: unknowndev-db: unknownThis initially suggested a possible
Very simple vpn set up for my iPhone. I have a Fortigate 40F firewall. I'm able to access my movie server after successfully connecting to the vpn but not the hikvision cameras that I have configured on the Hik-Connect app. I can reach https://x.x.x.x:443 (camera1) on my iPhone using Safari while connected to the vpn. so that port is working.The live feed fails once it hits 80%. "device connection timed out" Please check its network connection. But I can reach my movie server and access the web sign in of the camera using https. Help? Cameras work flawlessly when on the local network through wifi. VPN is allowed to access my entire lan and "all" services (ports) Modem > Fortinet > Ubiquiti 24 Port PoE > connects all my ethernet, three aps and 5 cameras. All on 10.10.10.0/24. Flat network nothing else. NVR is a Windows 11 Pro Host running iVMS-4200. No VLANs, nothing. Flatter than Earth. Log Allowed Traffic is set to "All Sessions"
Hello everyone,I am facing an issue with a FortiLink deployment over a RADWIN 5000 Point-to-Multipoint (PtMP) wireless network and would like to know if anyone has experienced something similar.TopologyFortiGate |FortiLink |RADWIN 5000 HBS / \ SU-1 SU-2 | |FortiSwitch1 FortiSwitch2The RADWIN network is operating in Layer 2 Bridge mode. No routing or NAT is configured between the FortiGate and the remote FortiSwitches. The wireless network transports the required VLANs correctly.Current behavior If only one remote site is powered on, the FortiSwitch is discovered and managed successfully through FortiLink. If I power on the second remote site, both remote FortiSwitches appear as Offline in the FortiGate. Despite this, all end-user devices connected to both FortiSwitches continue to pass traffic normally on their VLANs. Data connectivity is not affected. In other words: FortiLink management fails. User traffic continues to work without issues. Additio
Hello everyone,Equipment:Model: FortiSwitch 124F-FPOE Firmware: 7.4.3 (Build 830) GAIssue:A CMK15 intercom/communicator device connected to a PoE port on the switch is not receiving any power. The device does not power on.Already checked:The Ethernet cable has been tested and is working correctly. A Wi-Fi access point connected to another port on the same switch receives PoE power correctly and works normally. The same phone device (CMK15), when connected to a different Fortinet-brand switch running the same firmware version, works correctly. It also works correctly when connected to a switch from a different brand.Could this be a hardware issue, or is there a missing configuration on the FortiSwitch? If not, what should my next step be?Thank you.
I upgrade our fortigate to v7.6.7 and after upgraded then the web admin gui if use mgmt ip address can’t be accessed from advpn, only can be accessed from local site and from hub only. If i using lan ip (not mgmt) then i can access. Anyone know why?SSH to the both port (mgmt and lan) is working fine.
Hi everyone,We recently ended our support contract with our previous vendor and decided to renew with a different support provider.Unfortunately, the previous vendor has refused to provide the FortiGate administrator credentials and has also refused to share the latest configuration backup.we tried using the maintainer account with the password format bcpb+<Serial Number>, but I received the following error:login: maintainerPassword:Verifying password...Login incorrectDevice Model: FortiGate 200FIs there any supported method to reset or recover the administrator password without performing a factory reset, so that the existing configuration is preserved?Any guidance or recommendations would be greatly appreciated.Thank you.
● Prerequisites・ FortiOS version: v7.6.7・ Inspection mode: Flow-based・ SSL inspection: certificate-inspection・ Browser: Google Chrome, (Firefox), (Microsoft Edge)・ Client certificate installed on the endpoint ● IssueWhen accessing a site categorized for "Block" or "Warning" actions, the FortiGate is expected to display replacement messages;however, a browser error (ERR_SSL_PROTOCOL_ERROR, or occasionally ERR_CONNECTION_RESET) appears instead of the replacement message.Switching the inspection mode to proxy-based resolves the issue, and replacement messages are displayed correctly.Note that this issue occurs on some endpoints but not others. ● Troubleshooting results・ Endpoints experiencing the issue produced the same results when inspected via a different FortiGate.・ Changing the FortiOS version (to 7.6.6 or 7.4.12) yielded the same results.・ Updating the browser to the latest version yielded the same results. ● QuestionBased on the troubleshooting results, I suspect the issue lies wit
I setup 1VM (FMG V8.0.0) and FW(V8.0.0) and trying to onboard fortigate firewall to manager but getting below error , is there any bug or do i need to make further changes in the configuration considering both VM Mgt subnet are in same subnet. Error “The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager.Could not connect to the FortiManager to retrieve its serial number.”
Hi, how do you set up a VXLAN when you have two locations? We're using FortiSwitches at both locations, and VLANs are also in use there.But we now have another location, and I'd like to know if it's possible to set up a VXLAN using the FortiLink VLAN as well?
Hi all,I am looking for FAZ resources which cover real world use cases or lab based scenario, I have checked on YouTube but not much available, checked their Fortinet Video Lib as well, I would appreciate you recommend some resources, thanksNote : I am focusing on FAZ, FSM
vpn ssl stop working but internet is reachable,my topology is a sdwan connection to internet from two wan sub interfaces joined as sdwan members into a sdwan-zone, we are using the fortigate lower models and firmware are 7.4.0 and 7.2.4, internet connection are asymmetric, home-residential massive internet. SLA health check is active but ramdonly after a couple of days internet connection is up but vpn ssl sub interface is down, no echo-ping goes back and sniffer also doesn´t show anything, only remote solution is to reset port and after that sub interface goes up again. Following current sdwan config edit 3 set interface "subinterface-primary-vpn" set zone "sdwan-to-remote-hub" next edit 4 set interface "subinterface-backup-vpn" set zone "sdwan-to-remote-hub" next... edit "vpn-health-check" set server <remote-looback-ip> set interval 1000 set failtime 10 set recoverytime 10 set source <local-lan-ip-all
Why link status for each port is different between the device and fortinac? On the device port g1/0/27 - 31 is up but in the NAC is different
I try to send CoA to the endpoint but we can see from below picture the CoA is failed, and from tcpdump there is no traffic to port 1700. Also in the cisco switch i already enable CoA debug but not receive any message. This mean the fortinac not send the CoA message?
Hi everyone,I have the topology below using Fortigate HA Active -Active Cluster Everything works normally until SW1 (the current STP root) is rebooted or powered off.After SW1 comes back (or after the topology reconverges), the topology does not recover correctly. One or more FortiSwitches may randomly become Offline, even though the physical links are up.The only workaround is to disable and enable FortiLink Split Interface, after which all FortiSwitches immediately come back online and the topology is rebuilt correctly.FortiOS 7.6.7 / FortiSwitchOS 8.0.0
Running FortiWeb KVM_PAYG on Proxmox (standalone, not a cloud marketplace deployment). Reproduced this identically on two separate fresh installs — 8.0.6 build0116 and 7.6.9 build1133. Running FortiWeb KVM_PAYG on Proxmox (standalone, not a cloud marketplace deployment). Reproduced this identically on two separate fresh installs — 8.0.6 build0116 and 7.6.9 build1133.Setup:Operation Mode: Reverse Proxy, standalone (no HA) port1 (external): static/DHCP IP, allowaccess includes http/https/ssh/ping port2 (internal): static IP, reaches backend fine Server Pool → backend IP:80, enabled Virtual Server → Use Interface IP enabled, bound to port1 Server Policy → links VS + Pool + HTTP Service (port 80) + a Web Protection Profile, status shows Running admin-port moved to 8080 beforehand, confirmed no port-in-use conflict when creating the policy License page: all green (VM License, Support Contract, etc.)Symptom:Client (Kali, same L2 segment) connects to the Virtual Server IP on port 80: curl -v
We have 2 internet connections terminated to our firewall with spare IPs, and SD-WAN is already configured outbound for load-balance/failover.We have a specific outbound service (SMTP) that we want to attach to a dedicated outbound IP address.Setting an outbound NAT policy with an IP Pool was easy enough, and that's working, but we only have it setup for one of the internet connections at the moment.How can we set this up with a dedicated outbound IP for each internet connection and have it failover if the main internet connection goes offline? (active/passive)
Hi everyone,I'm looking for the FortiAnalyzer 7.2.11 JSON-RPC API documentation. Does anyone have a copy or know where I can find the complete documentation?I'm currently integrating FortiAnalyzer with an external system and need information on the available JSON-RPC methods and objects.Any documentation, examples, or links would be greatly appreciated.Thanks in advance!
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
Hi everyone,I’d like to clarify something regarding the Intune deployment using the official bash script as it seems to be a bit problematic.I was following during configuration → Deploying FortiClient using a shell script | FortiClient 7.4.0 | Fortinet Document Library We are updating from 7.4.2 to a higher version. Issue I encountered are the following: *If the EMS is connected, the service does not run at all. No errors are show shown in the Intune portal. Which leaves me with the impression that the devices are not being reached. *Some newer OS versions -> macOS 26.5.2, assigned to the same group are not added to the list of “pending” (invisible, not in the list). And I don’t understand why. I am unsure if the script is even reaching them. The person in question had the older version, we removed it manually, and then we were waiting for the script to be executed. The person’s device was synced a few times (and restarted once) - no changes. *In some occasions, the script does n
Hi everyone,I'm trying to integrate FortiWLC 8.6-5 build-8 (FortiWLC-500D) with Aruba ClearPass Guest (ClearPass Policy Manager 6.12.7.308288 on C3010 platform) as an external captive portal.Current setupFortiWLC 8.6-5 build-8 External captive portal: Aruba ClearPass Guest Authentication type: RADIUS Captive Portal External Server Type: Fortinet-Presence External URL: https://<clearpass fqdn>/guest/guest_register_3.phpThe captive portal profile is configured as:Authentication Type: radiusCaptive Portal External Server Type: Fortinet-PresenceSuccess Redirect URL: https://<default redirect url>Login flowClient connects to SSID.FortiWLC redirects the client to the ClearPass Guest portal.The login page receives all FortiWLC parameters correctly, including:magicusermacuseripserveripapmacapidapnodeidssidpost=https://<controllerip>:8081/vpn/loginUser? User enters username/password.ClearPass successfully authenticates the user against the authentication source.After successf
Hello team, I have interesting situation. there are 4xFg900G in cluster. there is FTP server in vlan 100.L3 DG address for that vlan 100 is on Fortigate.When secondary 900G FGs from cluster want to reach ftp they can not.We also have cluster of 4xFG 400F for additional services, and they can all reach ftp server , no matter primary or one of 3 secondary FGs How to solve this situation?My final aim is to upgrade one of secondary FGs regarding MVC (Multi-version cluster) option, set upgrade-mode local-only, and upgrade one of secondaries and then reset ha uptime so that upgraded one become primary. Reason for that is because we must not have any downtime, and we want to take test after upgrade if all services are ok
Had multiple issues when adding a FortiGate using discover device. It always said device serial number does not match Only once I updated to 7.4.11 did it finally add First post here and its the end of my day so I’ll add more later, just don’t want someone to lose an entire day to this like I did.
hi,i’d like to setup a remote syslog server to collect NAT 5 tuple logs (source/dest IP, source/dest port and service/app).i have a multi VDOM FGT and would like to setup syslog server config in a non root/MGMT VDOM.my VDOM setup is i have an upstream ‘internet-gw’ VDOM and several downstream ‘nat-client’ VDOMs.goal is to setup syslog in ‘internet-gw’ VDOM and ‘nat-client-a’, ‘nat-client’b’ VDOM to send NAT log that’s filtered based on 5 tuple info.can someone advise on this? my google search only points to non VDOM FGT syslog and i already configured/enabled syslog in ‘global’ VDOM.
Hi Community, As per title “How to get Fortinet higher up to review related TAC Manager ticket”In ticket (11996986), we had factually proven the issue and the TAC Manager do acknowledge on it.Suddenly the TAC Manager (Jonathan) twist the fact on what discussed.Luckily we had video call recorded. How can we further submit to Fortinet higher up to review this TAC Manager whether these action is being approved? Thank You Best Regards,YK
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.