Celebrating our Community: Thank You for an Incredible Month
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Good morning, everyone. I have the following problem, but first, let me describe the scenario. I have a virtual FortiGate 8.0 installed (OVF file imported into VMware Workstation 25h2). It's already installed and configured correctly with web access. The issue arises when I try to install FortiManager, the same version as the FortiGate. The OVF file is available in the VM section of the Fortinet support page, and I can download and import it without problems. The problem starts when I launch the VM; it gets stuck in an infinite loop between 'vmlinuz' and then 'extracting the GZ file,' and it never gives me the login option. Can you help me with this?
Hi everyone,We are troubleshooting what appears to be a Linux-specific FortiClient Enterprise issue and I would like to know if anyone has experienced something similar.Environment:FortiClient Enterprise Linux 7.4.7 build 5438 FortiGate 7.4.x IPsec VPN (IKEv2) RHEL 9.x and Ubuntu 24.04Behaviour:VPN authentication succeeds. Tunnel is established successfully. Approximately 9 seconds later the VPN disconnects. The timing is very consistent (always around 9 seconds).What we have already verified:Same FortiGate configuration works perfectly with FortiClient Enterprise for Windows. Reproduced on both RHEL 9 and Ubuntu 24.04. Reproduced on both physical and virtual machines. Reproduced on x86_64 (and also ARM64 with 7.4.7 where supported). Client is not registered to EMS. FortiGate logs do not show authentication failures, DPD timeout, IKE negotiation errors or peer-initiated disconnects. The Linux client appears to terminate the session locally after the tunnel has already been established.
Hello everyone, I am a student working on my final year thesis about "implementing sandboxing technology for proactive security of incoming network traffic". I would like to test FortiSandbox in my lab environment( ÈVE NG ), but I cannot find the image available for download. Could you please guide me on how to get access to it for academic purposes? I've already checked: · The official support portal· The Fortinet document library· Various resource sections Is there a specific academic program or evaluation license available for students? Any information about how students can access Fortinet technologies for research would be incredibly helpful for my work. Thank you in advance for your support! Best regards,HODOME Kokou AchilleIAI-TogoTOGO
We upgraded the firewalls from 7.4.2 to 7.6.6 and accessing anything internally over the forticlient connection is very slow. Prior to the upgrade everything was good. I have tried changing some of the tcp-mss-send/receive values but nothing seems to work. Anyone have any suggestions on what to look at next other than upgrading to 7.6.7?
Hi.Has someone done this smoothly who would be prepared to share their recommendations/runbook/checklist? We ideally want to run them parallel for a short period of time, inject the new VPN Connection into Forticlient on every machine and then have a few users at a time choose the IPSEC VPN.We also need to upgrade them from a 60F to a 70G and wondering if we should do the upgrade to VPN then the migration to new hardware or the other way around?Thanks in Advance.
Hi Fortinet Support,We're looking for guidance on deploying and configuring the FortiClient VPN application on Apple iOS devices managed through SOTI MobiControl.Our Android devices are working as expected, where the VPN configuration and authentication are deployed through SOTI. However, the process appears to differ on iOS, and we're looking for the recommended approach.Specifically, we'd like to know:Whether the FortiClient VPN configuration can be deployed automatically through SOTI MDM on iOS. Whether VPN profiles and authentication settings can be pre-configured using Managed App Configuration or another supported method. If there are any limitations on iOS compared with Android regarding deployment or user interaction. Whether there is any official Fortinet documentation or best practice guidance for deploying FortiClient VPN on iOS using SOTI MobiControl.Our environment:MDM: SOTI MobiControl Devices: Apple iPhone and iPad (iOS/iPadOS) VPN Client: FortiClient Android deployment
Dear Fortinet Community.We have a small problem reagrding the authentication for WiFi against ldap. To be honest we have 2 problems and found workarounds that lead us to new problems. And at the moment I get a bit crazy and now I thought. Come back to my professional frieds in the fortinet community as they always have good hints to solve all the issues we have faced in the past.But first of all the environment we have for you:Firewall: Fortigate 401F (Version: 7.4.12)WiFi: WPA 3 Enterprise OnlyWiFi Access Points: FortiAP 231G (Version 7.4.7 0802) & FortiAP 2314G (Version newest... have not installed it yet)Authentication: WPA 3 Enterprise Only against LDAP with ldaps (two methods. 1. With user on firewall or with remote ldap group)LDAP Server: connected via LDAPS using userPrincipalNameWhat was the first problem?1) The ldap does not answered fast enough.So we tried to change global parameters like remoteauthtimeout to 30 and ldapconntimeout to 5000We see that the WiFi connection s
Hello,Could someone explain the differences from the FortiSwitch Feature Matrix for Device Detection vs Network Device Detection and the use cases for NAC Device Telemetry - is it only related to https://docs.fortinet.com/document/fortigate/7.2.0/new-features/612369/track-device-traffic-statistics-when-nac-is-enabled-7-2-4 , since I didnt find that much info that would give me a good understanding of the diff.We were thinking of implementing on a bunch of FSW 148F-POE w/ FortiLink (for which the 2 above features are not available) and use NAC Lite with EMS Tags for the policies but then saw the possibility of also using Device Patterns for Device Category such as Hardware Vendor, Device Familiy, Type, OS etc and would like to know if it would work w/o those 2 features on that model or should reconsider something in the 200 series.Thanks.
Hi FAZ、FMG created same ADOM name for manage FAZfollow this guidehttps://docs.fortinet.com/document/fortimanager/7.4.0/examples/289359/adding-fortianalyzer-to-fortimanager at FAZ, ADOM name ”ADOM_v74” have one device at FMG, have same ADOM name”ADOM_v74”, and same devicebut in this ADOM, the left sidebar doesn't even have a Log View or FortiView to check traffic or other logs.only “FAZ” ADOM have Log View and Forti View
FortiClient EMS Server 7.4.7Endpoint email alerts have been configured.Emails are sent to a mailbox, automatically generating a ticket for the Service Desk.I have a Test VM for testing FortiClient settings. It is inconvenient to have a ticket created every time I for example disconnect the FortiClient for testing purposes.Is it possible to exclude a single endpoint from all email notifications?Regards
Hi allI have noticed a weird issue, client had a power outage over the weekend as the redid the server room UPS.Now my AP’s show “Connected VIA” my VOIP interface on the FortiGate, even tough they are connected via FortiSwitches and the LLDP Neighbors are correct, also the IP’s they get are from my DATA VLAN.They use to say connected via DATA VLAN and once rebooted they now show VOIP. all troubleshooting points to they are indeed connect via DATA VLAN.GUI BUG? FortiGate 7.4.12 , FortiSwitches 7.4.8 and FortiAP’s 7.4.6Please let me know if anyone has experienced this and why now all of the sudden?
We’ve had several cases of memory exhaustion with different processes (node, wad, ips), and are using the “set failover-memory enable” setting to cause the Clusters to automatically fail-over when going into conserve mode. (as well as cpu-threshold)While this is fine as it no longer causes prolonged service disruptions, it does leave the clusters in a degraded state: the failed node usually does not recovery by itself and needs to be rebooted in order to recover from the cause of the memory consumption and restore the cluster redundancy.Is there a simple way (e.g. with automation stitches targeting only the currently active or passive node) to automatically trigger a reboot on the now passive node after such a failover event?Or do we need a feature request to allow automatic reboot of the failed node after a failover that was triggered by an internal event (memory, processes, RIB/FIB, cpu)? We probably don’t want to auto-reboot after an external event (link failure/ping-probe fail).
Hello,I am facing a persistent issue with a Dial-up IPSec VPN tunnel configuration on our HQ FortiGate.HQ Public IP -> 176.x.x.xLocation -> 91.x.x.xOur goal is to restrict IPSec VPN connections only to a specific list of public IP addresses. To achieve this, I've configured a local-in-policy to permit only our allowed IP group (Public_IPs) and deny IKE/ESP traffic from all other sources.Here is the current local-in-policy configuration:config firewall local-in-policy edit 1 set intf "FortiStore_WAN" set srcaddr "Public_IPs" set dstaddr "all" set action accept set service "IKE" "ESP" set schedule "always" next edit 2 set intf "FortiStore_WAN" set srcaddr "all" set dstaddr "all" set action deny set service "IKE" "ESP" set schedule "always" nextendAn unauthorized remote gateway (e.g., 91.x.x.x) that is not in the Public_IPs address group is still able to establish a VPN tunnel with our HQ
Hello,We recently installed 6 Fortigate 70G on the 3 sites of our enterprise. 2 per site for HA.The 3 sites are equals, connected by a BO VPN by the Internet provider.Do I configure only 1 Root-Fortigate (following de Fortinet administration guide) or 3 ?After some research, I found contradictory information online…Thank you by advance for your response.
Hello,Since I have this computer I've been having issues with the free FortiClient VPN software. The software works fine until you reboot the computer, then it won't open anymore. I get an error message saying "A javascript error occured in the main process" and "Uncaught exception: TypeError: Cannot read properties of null (reading 'TraceLog') at new logger (C:\ProgramFiles\Fortinet\FortiClient\resources\app.asar\assets\js\main.js:24121:36)..." Full error:https://imgur.com/a/0Frtoqq The only thing that seems to work is to delete the software and reinstall it, after that it keeps working fine until I restart the computer. After reboot, the same error appears. We use this software on 500+ computers in our company, although mine is the only one that has this issue. Any help is greatly appreciated.
Good evening everyone,I’m having an issue with the FortiGate VM I imported into GNS3.I can't manage it via the console interface; when I launch the console, it just hangs and nothing displays for several minutes.I’ve tried versions 7.4.11, 7.4.12, and 7.6.6, but none of them are working.I need some help!
Good morning, I'd like to be able to send the Forti logs to a Wazuh server. I'm already sending them to a syslog server, but only one log is visible through the GUI. How do I configure the other redirection (to Wazuh)? I'd like to have both options: syslog and Wazuh. Thanks!!
I'm trying to diagnose a FortiClient VPN issue with an IPsec vpn IKE v2. I have the forticlient vpn installed on my iphone 16, my coworker has it installed on his iphone 15, and its installed on a clients iphone 14. My coworker and I have been able to successfully connect to the vpn but the iphone 14 user gets an error -vpn credentials are invalid. I have reentered her username/password multiple times, i've verified the PSK and all other configurations are correct, and have attempted the connection over wifi and cellular on her device. I used the same wifi on my device to successfully connect. I also used her credentials on my device to successfully login. iOS and FortiClient are both up to date. The FortiGate logs reveal that its failing to negotiate phase 1.
Hi,We're reviewing our VPN authentication setup and would like to add MFA for remote users.At the moment, OpenVPN authenticates users against our on-premises Active Directory. Because some parts of our environment don't have reliable Internet access, we're trying to avoid cloud-based MFA platforms.I'd be interested to hear how others have approached this.Did you integrate MFA through RADIUS, LDAP, or another method? Which solution has been the most reliable in production? Any issues with OpenVPN authentication or user experience after enabling MFA? Anything you'd recommend before rolling it out?Thanks in advance for sharing your experience.
I’m using the 3-seat free FortiClient EMS Cloud offering that came with my FortiGate licensing and have run into a strange issue enrolling an iPhone.My Fedora 43 Linux laptop registers successfully to the same EMS Cloud tenant, so the tenant and license appear to be working, at least in general. However, my iPhone will not register and always gives:“Registration Failed, Error: The invitation code is invalid.”What makes this confusing is that the invitation code does not seem to be truly invalid, because every failed iPhone attempt still causes the invitation Use Count to increase in EMS Cloud. At the same time, the failed attempt does not consume a license seat.What I’ve already tried:confirmed I am using the full FortiClient iOS app, not VPN-onlytried multiple invitation typestried existing and newly generated invitation codestried bulk invitationstried QR code onboardingtemporarily disabled Enforce User Verificationsigned out and back into EMS Cloudconfirmed EMS now shows user v
Hi all, I hope you're well. I am having trouble renewing my Let's Encrypt certificate with the ACME protocol. My FortiGate is currently running 7.4.8 and I have gone through the requirements checklist for ACME renewal and has local-in and other restriction disabled and attempting to run the command: diagnose sys acme purge-archiveI've ran a sniffer, and it doesn't seem as though the manual commands and initiating any process. Can anyone please confirm that I have the right command for 7.4.8 or provide any additional information for any steps that I may have missed? Thanks, Dan.
When i move endpoint to another host role the on the policy the endpoint should get a new vlan (37) but why in the inventory the endpoint still use old vlan (32) and i must wait up to 3 minutes then the vlan is changed?
If the endpoint was idle for some time then when i change the group on the NAC, I can see the fortinac not send the CoA to the switch.We can see here the last fnac send the CoA is 14:02:18 then i change the group for that host at 14:30 and there is no CoA bsend to the switch
Hi everyone,On my FortiGate running v7.4.9, I have a specific VDOM configured for one of my clients.Currently, this VDOM is integrated with a FortiAuthenticator (FAC), which in turn queries two remote LDAP servers to handle MFA for client VPNs. I now need to configure these same two remote LDAP servers directly on the FortiGate (under User & Authentication -> LDAP Servers) so I can use Active Directory groups in our firewall policies. I would like to know if there are any specific best practices to follow, and I have a couple of questions: LDAP Query Load: Are these two remote LDAP servers at risk of being overloaded with too many queries due to this dual integration (FAC for VPN + FortiGate direct for security policies) ? Cache Management: Would you recommend enabling and tuning the cache on the FortiGate (increasing `set cache-ttl` to 300 or higher) ?If so, what is your recommended value for a production environment ? Thanks in advance to everyone for any advice or insights !
Hello dear community, I got a new customer that has an unlicensed FortiGate 50E and FortiAPs 221E on firmware 6.0.x. They want to replace the FortiGate with the 50G model but want to keep the APs for now. The target FortiOS for 50G would be 7.4.12. As the config would be converted/migrated, what would be the best upgrade path to avoid losing the APs management?Put the 50G on 7.4.12 and convert the 50E configuration as is Upgrade the 50E and 221E APs to latest possible 6.2 branch and then convert the 50E configuration for 7.4.12 Upgrade the 50E and 221E APs to latest possible 6.2 branch, convert the 50E configuration for 7.0.19, then upgrade the 50G to 7.4.12 Please let me know if more details are needed. Best Regards
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.