Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Sometime we facing issue the client suddently disconnect from the network and i got below error.Is the fnac reject the client request? This is not permanent issue because if i re-plug the cable then the client can connect again
An incident occurred involving the FortiMail RAID configuration (RAID60-S) where multiple disks simultaneously switched to "UNKNOWN" status, subsequently transitioned to "REBUILDING," and finally recovered to "OK."Have there been any similar incidents in the past?Does anyone know the cause?Model: FortiMail 3000FFirmware: v7.4.2 (GA-Maturity), build583, 2024.02.07RAID SystemModel: AVAGO MegaRAID SAS 9460-16iDriver: 07.714.04.00-rc1Firmware: 5.170.00-3483u0 (RAID60)├ u0-0 (RAID6)│ ├ p0│ ├ p1│ ├ p2│ ├ p3│ └ p4│└ u0-1 (RAID6)├ p5├ p6├ p7├ p8└ p9p10: SPAREp11: SPARE 3,"2026-09-26","21:07:33.594","system","Disk p3 has changed status from 'REBUILDING' to 'OK'.","warning","0702003084"4,"2026-09-26","21:07:33.594","system","RAID device has changed status from 'REBUILDING' to 'OK'.","warning","0702003084"13,"2026-09-26","17:08:48.462","system","Disk p7 has changed status from 'REBUILDING' to 'OK'.","warning","0702003084"19,"2026-09-26","16:32:54.634","system","Disk p2 has changed status fr
Hello,I am trying to activate the Permanent Trial / Evaluation license for FortiGate-VM 7.6.6 running on Microsoft Hyper-V.When I run:execute vm-licenseI receive:Failed to download VM license.The VM license status is:diagnose hardware sysinfo vm fullvalid: 0status: 3code: 502The VM itself is recognized as an Evaluation VM:diagnose debug vm-print-licenseModel: EVAL (1)CPU: 1MEM: 2048I have tested the license activation in two different network environments:Corporate network using an HTTP proxy Mobile hotspot without the corporate proxyOn the mobile hotspot, the FortiGate could successfully reach both 8.8.8.8 and usupdate.fortiguard.net, but execute vm-license still returned Failed to download VM license.I also ran:diagnose hardware sysinfo vm setupbut the license status remained:valid: 0status: 3code: 502Fortinet Customer Service confirmed that FortiOS 7.6.6 supports the Permanent Trial license and that there is no issue with the Evaluation license activation or registration on the Fort
Hello Team,can anyone help me with dial up vpn configuration with PKI user.It is working fine with radius user but the requirement is for internal users vpn should be connected with certificate instead of username and password. any step by step configuration guide and troubleshooting links would be helpful
Hi I am trying to install my FortiClient but I am getting this error. I have had it installed before but then I had to uninstall it due to issues.
Hello,We have a large amount of FortiGates running 7.4 with automatic patch updates.Different kinds of models, but mostly entry-level ranging from 40F to 100F and 50G to 90G.We are looking to upgrade these manually to 7.6 and keeping automatic patch updates on.I am going back an forth between 7.6.6 and 7.6.7, as public opinion varies greatly between these, and according to release notes they both have different issues.Anyone out there know if 7.6.7 is included in the automatic patch updates, or if this still sits with 7.6.6?
Hello,I have an FMG running version 7.4.7 on Azure, and this FMG has 2 ADOMS, each of which manages a “pair” of FortiGate devices operating in HA (via an Azure ELB).We need to perform scheduled backups once a week from the FMG.Is this possible?Is it possible to export the backups to a TFTP server from the FortiGates, but with everything managed through the FMG?Thank you for your feedback.
Hey guys, Am facing issue with one of my fortigate device. The config status is shown as conflict. After a commit. The changes are reflected in the device level. Also once am trying to retrieve the config it is stuck. Does anyone had this issue before FMG version : v7.4.9Fortigate version : v7.4.7
Hello Fortinet Community,I have installed FortiGate-VM64 FortiOS 8.0.0 in my EVE-NG lab environment.The FortiGate VM boots normally, and I am able to access the GUI login page.Current IssueI can successfully enter my credentials and the GUI appears to authenticate successfully. However, immediately after login, I am logged out and redirected back to the login page.In other words:Open FortiGate GUI. Enter username and password. Authentication appears successful. GUI starts to load. Immediately after that, the session is terminated and I am returned to the login screen.EnvironmentPlatform: EVE-NG Device: FortiGate-VM64 FortiOS: 8.0.0 Build: 0167 Image: FGT_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvm.zip Deployment: KVM/EVE-NGLicense StatusThe FortiGate license is showing Up to Date / Active, so there does not appear to be an obvious licensing issue.What I have checkedFortiGate VM is booting normally. GUI is reachable. Username/password are accepted. License status shows up to date. The
Download links for FortiClient EMS invitations are not working because the filename in the invitation are Initial Cap, while the filenames are all lower case. Running version 7.4.8. This was working up to yesterday.
Is there a way to restrict vpn traffic from my external ip to IP that vpn would connect to using fortigate?
Hi everyone,We are experiencing an issue with FortiClient VPN 7.4.3.1790 on some PCs belonging to one of our customers.After Windows starts, the following error message is displayed:“A JavaScript error occurred in the main process”The VPN itself continues to work correctly despite the error.We have searched online and found a possible workaround that seems to resolve the issue: Uninstall the existing FortiClient installation using Revo Uninstaller. Remove any old Microsoft Visual C++ Redistributable packages (e.g. 2008, 2013) using Revo Uninstaller. Restart the PC. Install the latest Microsoft Visual C++ Redistributable. Reinstall FortiClient. This procedure worked on some of the affected PCs.However, we now have a different limitation: FortiClient can no longer be installed manually using the installer. It must be deployed through Microsoft Company Portal, and the issue has started occurring again on the affected PCs.The environment is also EMS-managed.Has anyone experienced t
Environment:- FortiClient VPN (free, VPN-only) 7.4.3.4323- macOS Tahoe 26.7.1 (iMac)- IPsec IKEv2 tunnel with SAML SSO/MFA, NAT-T (UDP 4500)- Not connected to EMS (log shows "Ignore Secure compliance Check as FCT is not connected to EMS")Problem:The VPN tunnel is disconnected by FortiClient itself less than one second after the macOS screen is locked. This happens even when the system is prevented from sleeping (display sleep and screensaver disabled, sleep prevented with a keep-awake utility) and while traffic is actively flowing through the tunnel.Steps to reproduce:1. Connect the IPsec IKEv2 tunnel with SAML SSO.2. Keep traffic flowing through the tunnel (e.g. a TCP check every 60 seconds to an internal host).3. Disable screensaver and display sleep, prevent system sleep.4. Lock the screen (Ctrl+Cmd+Q).5. The tunnel is disconnected within ~0.7 seconds.If the screen is not locked, the tunnel stays up indefinitely, so this is not an idle timeout, a network issue, or a gateway-side dis
Hi,I am troubleshooting an N+1 synchronization issue on FortiWLC 8.6-5build-8.The N+1 status currently shows Healthy, but configuration changes are not being synchronized to the secondary.I found the following error in the primary controller logs:Oct 1 2026 11:30:59 <controllername> nplus1_Primary:ERROR: Error: Ignored (/opt/meru/np1/scripts/np1-files)(np1sync_files.tgz) in middle of making sync package.I would like to understand exactly what this error means.In particular: Why is np1sync_files.tgz being ignored while the N+1 sync package is being created? Is /opt/meru/np1/scripts/np1-files a normal FortiWLC N+1 directory? Is np1sync_files.tgz a temporary file generated during the synchronization process? Could this "Ignored" message cause the N+1 configuration synchronization to fail? Is there a supported way to access or inspect /opt/meru/np1/scripts/np1-files on a FortiWLC controller? If shell/SSH access is available, what account or method should be used to inspect
Hi community, I have a question about FAZ logging. Which I can’t seem to find the right answer to and I’m hoping you guys may have experienced something similar.Basically I need to undertake some work on a FAZ VM itself where I don’t want new logs to be ingested to the database for a few hours while I do some work. It will be coming up and down so I don’t want it to start taking new logs when it boots up again.I have about 50 Gates logging to this FAZ and it is not feasible to go to each one and turn off the FAZ logging. I’m ideally looking for something like a pause button on the FAZ if it were to exist. I’m on a VM running 7.4.10. I have seen some recommendations about disabling the port on the FAZ used by the Gates so traffic can’t make it through and using a separate management port to continue to connect to the device which I believe is potentially my only option.Any other thoughts?
Hi, I’m having an issue where users are missing from groups synchronized with Entra ID. I can browse and import groups from Entra ID, but when I go to System > Groups > Remote Groups and select "Show members," the list is empty. I suspect a missing API permission, but I’ve checked everything and the configuration looks correct. Has anyone encountered this problem before?P.S. The connection to Intune is configured and working without issues.
I replaced the secondary unit of a FortiMail (3000F) configured in a primary-secondary setup and rebuilt it using the old secondary unit's configuration.Before connecting it to the primary unit, the following entries appeared in the "Mail Event" logs:/var/spool/etc/mail/submit.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail_ec.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail.cf: WARNING: dangerous write permissionsDoes FortiMail use sendmail for email transmission and reception?For the time being, I have connected it to the primary unit, and data synchronization is complete.If the primary unit were to fail in this state, causing the secondary unit (which generated these error logs) to take over as the primary,would email transmission and reception function correctly?I am concerned about this point. Do you have any information regarding these logs?When I tested sending an email via Webmail from this secondary unit,the following entry appeared in
We use FortiMail’s webmail for IBE secure mail exchange.The Webmail interface allows users to download the de-crypted emails using “save as” without any encryption. These mails are saved as decrypted plain email format (.eml)How can we disable this function in Webmail?Is piping the WebGUI through a reverse proxy/WAF to block this particular button the only way?
Hi,What issues could there be in a split-brain scenario? I realize the raw logs sync wouldn't be a problem, but what about configs? For instance, an admin adds some devices to one node while another admin adds new devices to the other node. How can the Geo-redundant HA reconcile those changes? Can that damage Analyzers and Collectors?
Has anyone run into this error when registering FortiClient to EMS Cloud using Google Workspace SAML?Error: 403 - app_not_configured_for_userEnvironment:FortiClient EMS Cloud Google Workspace SAML authentication FortiGate 90G HA pairAlready verified:User access set to ON for all users in Google Admin Attribute mapping is correct ACS URL and Entity ID match between EMS and Google SAML app Not in test modeStill getting the 403 on registration. Anyone else hit this and found a fix?
I have one FGT node in one data center and another node in a different data center. Currently, each one has its own management IP: 10.10.10.1 and 10.10.10.2.This is a deployment from scratch, so we are going to connect a cable between the HA ports of both nodes.My question is: I now need to configure an A-P HA cluster between the two nodes. However, in the past, when I enabled HA Reserved Management in an attempt to keep both management IPs independently accessible, I lost access to the firewalls through their management interfaces.What would be the correct steps to set up an A-P HA cluster between these two nodes without losing access to either of them through their respective management interfaces?
Currently, I have a FortiGate configured with two ISPs, with WAN1 as the primary connection and WAN2 as the secondary connection.For the LAN-to-Internet policy, I have a fixed IP pool NAT configured using the usable IP provided by WAN1. When I introduced an additional IP pool NAT on the LAN-to-Internet policies using the WAN2 Interface IP, users reported that they were unable to access the internet.After reverting the change and removing the WAN2 IP pool, internet connectivity was immediately restored for the users.My question would be:- What is the recommended NAT design for a FortiGate with DUAL ISP connectivity when an existing IP pool nat is already in use?- Are there known considerations or limitations when using fixed IP pool NAT address in a multi-WAN deployent?- Are there any FortiGate best practices for maintaining internet connectivity while introducing NAT rules in a dual ISP environment?
I have enabled pmtu-discovery as per instructions from this topic Dynamic MTU Configuration in SD-WAN Deplo... - Fortinet Community but MTU on the GRE tunnel remains 1476. I want it to be 1356 for this state when ipsec is off. one side of that mikrotik - fortigate link is discarding ldap traffic so domain users are unable to log into their computers because of problem in communication between computers and domain controllers... ldap traffic from windows 11 clients to domain controller on port tcp88 and vice-versa has DF bit set and traffic may not be fragmented..
Hello,I’m creating this Topic because I’m facing an issue that neither me, Dell or our Forticlient provider faced before and we both have no idea what exactly is going on. We ordered a batch of Dell Computer Pro 3 14260. Those computers are facing kernel boot trap double fault with fortishield.sys. It occurs most of the time when the computer is booting with Forticlient 7.2.15.1309, but also very often when connecting or disconnecting of Forticlient. We also tried with 7.2.14 and 7.2.13 with same issueOur EMS is in 7.2 so we can’t try 7.4 for now it’s ongoing we have to build a linux machine for the upgrade.We don’t have this problem with any other dell computer model Of course if I don’t have Forticlient installed I don’t have any issueI’m trying to compare the components for those computers and see what could be conflicting but extremely difficult I just know it’s something with fortishield.sys as it is mentioned in the minidumps If anyone faces this (no result on forum search) or h
Hi Team,We plan to deploy a FortiPortal Scalable Cluster with two nodes in one DC and one node in the other. If the DC with the two nodes goes down, the single node can operate independently per the configuration:config system ha set min_nodes 1endWhat will happen when the two-node DC is brought up? Will it be enough to change the single configuration to a scalable cluster? Will the changes made on the single node during the outage be replicated to the other nodes?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.