Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi all,We're looking at FortiSASE to possibly replace Cato SASE (a different debate).What mechanisms does FortSASE have to ensure only corporate devices connect? Does it support Entra Conditional Access Policies and Compliance checks?Can we use our machine certificate and authenticate based on that?
OS - 6.4 I am trying to understand the behavior with this setting and when it should be used. Assuming we have multiple Internet healthchecks with this setting enabled across multiple SD WAN rules we use for steering, what would the impact be? Based on the this article it sounds like it would remove our default route which we probably don't want.https://kb.fortinet.com/kb/documentLink.do?externalID=FD44679 I am probably missing something here. Any guidance would be much appreciated.
Hi @community,We are using the external manual input feature via email links in FortiSOAR and When a user clicks the link, it opens the standard manual input pop-up window. We are facing a couple of UI limitations and wanted to check if there are any workarounds: Pop-up Size: Is there a way to increase the dimensions (width and height) of the input template? The current text area is quite small for analysts to provide detailed inputs. Draggable Window: Is it possible to make this pop-up window draggable? We want analysts to be able to drag the popup aside so they can read the underlying alert data while filling out the form. Any suggestions or guidance on this would be greatly appreciated.Thank you.
We pay for premium support. One of the reasons is when we have an issue with a firewall or device, we can call in to get help and resolve the issue immediately. This especially important in an MSP setting, where we have to go on-site for troubleshooting and don't have the luxury of waiting until they call us back. We can’t leave the site (which sometimes are hours away) and then travel back to the site when they call back. This is very concerning and a very bad support move.
Hello everyone,At the moment i experience an issue with the FortiMail API when trying to retrieve the artifacts of a specific incident using it's session ID.When I try to send request, the API returns all incidents from the selected directory instead of the specific incident associated with the session ID.Could someone please advise on the correct way to retrieve a single incident by its session ID? Am I missing a required parameter or using the wrong endpoint?Any help would be greatly appreciated. Thank you!
Hi everyone,I am looking for the FortiClient VPN v6.0 (or any stable 6.x version) 32-bit installer.I need this specific 32-bit version to manage deployments and clean up large-scale uninstallations via Microsoft Intune on our remaining 32-bit Windows PCs.I've searched through previous community posts, but unfortunately, all the shared download links for the older v6 32-bit installers have expired.
I updated the FortiGate from FortiOS 7.6.6 to 7.6.7 and am experiencing issues with SSL inspection certificates.After the update, the firewall started dropping all traffic. Even traffic matching firewall policies without SSL inspection enabled is being dropped.As a temporary workaround, you can disable SSL inspection globally to restore connectivity.Has anyone else encountered this issue after upgrading to version 7.6.7? Is there a known bug or a recommended fix?Update:Not logging dropped packetsFirewall memory usage reaching 90%Thousands of active sessions (compared to normal levels)
I'm having an issue with devices accessing internal netowrk equipment using IPSec VPN and connected to the Guest WiFi of the same Firewall we're trying to remote in. Some details about the setup, we have a firewall in place and we're broadcasting LAN and Guest WiFi SSIDs.The Guest WiFi is isolated and can only reach the internet with some webfiltering and ssl inspection.Devices that are connected to the Guest WiFi cannot communicate with the LAN Network, setup by a Firewall policy. Dialup IPSec VPN has been setup so the remote users can access a spesific server to the internal network (LAN).This is working as a charm when we're using mobile hotspot or another ISP connection outside the office's building. The problem is when we're at the office we have some personal devices we have to connect to the Guest WiFi for security purposes and althought we're able to esablish a connection using our Dialup IPSec VPN our computers cannot reach the spesified server on the inte
Hi! I’m seeking clarification of KB 96255. I read it as that there are two different types of triggers for a session drop due to idle-timeout - (a) for a session in TCP Established state - resulting in log message with “action=close”; and (b) TCP session in an embryonic state resulting in log message with “action=timeout”. However, this contradicts my experience - for Log message logid=0000000013 with “duration=4376”, “rcvdbyte=64713”, “sentbyte=29953” (ie. not an embryonic session) I see “action=timeout”, implying timeout due to trigger (a), not (b). That is, the opposite of what the KB documents, (albeit, I am assuming it’s referring to Log message logid=0000000013). Anyone can vouch for veracity of the KB, and if so, explain why I’m seeing a log message with “action=timeout” for non-embryonic session?Thanks!
Hello Everyone, I'm currently experiencing an issue logging into the FortiGate VM GUI.The GUI remains stuck on the license validation process, attempting to verify the license with FortiGuard. The FortiGate VM license expired four days ago. Based on my understanding and Fortinet's licensing behavior, even if the license has expired, I should still be able to access the GUI. Only subscription-based services should be affected.I have already verified the following:All required ports are open. The FortiGate VM has successful connectivity to the FortiGuard servers. DNS resolution and internet connectivity are working correctly.Also, i’ve attached the ping and system dns status for FortiGuard. Despite this, the GUI remains stuck during the login process.Has anyone experienced this issue before, or does anyone have any suggestions on how to resolve it?Any advice would be greatly appreciated. Thank you in advance
Good day Please assist , I have installed fortigate vm64 version 7.6.7, when trying to access the gui and logging in it says license is being validated I can ping google , dns working fine What could be the issue
Hello, We are currently deploying Cisco ISE as Radius server for user 802.1X auth and device (printers,cameras,iphones) with MAB. We have a site which is composed with Fortinet devices (Fortinet Firewall, FortiSwitch & FortiAP). While i am testing mab authentication everything works fine, my main issue is that on Cisco ISE i can't get endpoint ip address.DHCP snooping is enabled on Fortiswitch Interfaces, Fortinet Firewall is on 7.2.8, i've done packet captures and see that fortiswitch is not sending framed-ip-address towards ISE. Any idea why this happens and how can i resolve it ?
Hi Team,We are using FortiClient EMS-managed IPsec Remote Access VPN (IKEv2) with split tunneling.Our FortiGate Phase 1 is configured with:mode-cfg enableipv4-split-include containing only RFC1918 networksNo full-tunnel configurationAfter connecting, the Windows routing table shows two default routes:0.0.0.0/0 -> 192.168.1.1 Metric 40 (Local Gateway)0.0.0.0/0 -> 10.68.1.14 Metric 9001 (VPN Gateway)The local gateway has the lower metric, so Internet traffic should continue to use the local ISP, which appears to be working correctly.However, we occasionally observe some Internet-bound traffic in the FortiGate traffic logs from VPN users, even though only RFC1918 routes are configured in the split tunnel.My questions are:Yes, this is expected behavior. FortiClient installs a secondary default route with a very high metric as part of its standard IKEv2/IPsec split tunneling implementation. This route acts as a fallback or "trap" route and does not override the primary local ga
Hi all,I read this article about restricting ipsec connections to certain countries.https://community.fortinet.com/fortigate-3/technical-tip-restrict-ipsec-vpn-access-to-certain-countries-94688When I attempt to implement it, I find that I cannot select any wan interfaces in an address object.In the article example (below image) it shows External (wan1) in the interface field but when I create a new address object it doesn’t show any active physical wan interfaces in the interface field.Would using the Zone that contains the wan interface work? We are running a Fortigate 81F with 7.4.12thanks
In what FortiOS version did this last work? The AI chatbots of the day insist it should still work, but the CLI is a mess.I need to monitor in real time interface OSI layer1 state change (simplest of requests)What is the best replacement in in version 7.2, 7.4, 7.6? diagnose debug console timestamp enable!diagnose debug disablediagnose debug reset!diagnose debug application linkd -1 diagnose debug application netlink -1!diagnose debug duration 0diagnose debug enable!
I am experiencing recurring FortiGuard DDNS failures causing VPN outages. Our FortiGate-100F (v7.2.12 build 1761) cannot update DDNS when our dynamic PPPoE IP changes.Issue:GUI shows "Unable to load FortiGuard DDNS servers list" error DDNS updates fail intermittently When IP changes, DDNS doesn't propagate new IP to public DNS Remote VPN users cannot connect via hostnameDebug output shows root cause:Certificate verification failed, error 62 (hostname mismatch) depth 0 Expected: ddns.fortinet.net Received: CN=sdns.fortinet.netFortiGuard DDNS servers (173.243.138.226) are presenting certificates for sdns.fortinet.net instead of ddns.fortinet.net, causing SSL verification to fail? Impact:Second VPN outage in 4 days Every IP change requires manual client updates Production access affectedTicket opened since May 21 - support has not addressed the certificate mismatch issue shown in debug logs.Is anyone else experiencing this? Is this a known FortiGuard infrastructure issue? Any workarounds
Hello Community, I would link to know does ull ports (x5-x6) can be use as fortilink interface in production? I am bit confuse because of this official document mentationed that x1-x4 can be use for the fortilink however I also read some other doc mentatined that any port can be use for the fortilik. And ull ports are not part of the Integrated switch fabric. https://docs.fortinet.com/document/fortigate/7.4.12/hardware-acceleration/589036 Fortigate 600f: v7.4.12Manage Fortiswitch:7.6.6Can some expert please confirm on this, I appreciate your guidance here.
We have some reports set up for specific devices and I went to add some newly installed devices to the reports. No matter if I edit, clone or create them all over again I get the same error: "The data is invalid for selected url". Does anyone know what the cause could be?(FortiAnalyzer version is the same as Fortimanager)
Greetings Im having some problems with my VXLAN over IPSec implementation. Im able to establish connection to the remote site. Telnet, SSH, RDP, VOIP is working fine but Outlook and some HTTP or HTTPS application don't work. I have read many article about this issue and all says that is a MTU or fragmentation issue. But I follow all the recommendation and nothing seems to work. First thing I notice is that VPN interface, Software-switch and vxlan mtu were set to 1370. I manage to bring the VPN and vxlan mtu to 9000 and Software-switch to 1500. My physical interface are all set to max mtu (9216). I also disable the honor-df bit but the maximum mtu that i can pass without fragmentation is 1472. And I think that is fine because 1472 + 28(header overhead) = 1500. But still cant get Outlook to work. I also adjust the mss in the policy to 1432 (1472-40). Also I lower my encryption to 3DES SHA1.My main FW is a 100F and the remote is a 60F. Im runnig 7.2.4. I will appreciate any
Hi guys, I hope you’re well. I have deployed a single FAP-241K-A unit and have configured the AP profile for both 5GHz and 6GHz radios. All the APs I currently have deployed are running dual 5GHz radio with 2.4GHz set as dedicated monitor with WIDS profile configured and I do not have this issue. I have the same SSIDs manually set on both the 5GHz and 6GHz radio but doing this causes issues with clients being able to connect to the SSID. At first this worked and the client connected but now I am unable to connect and receive an ‘access denied’. All SSIDs are WPA3 SAE with a mix of both bridged and tunnelled. If I disable the 6GHz radio I can connect with no issues so I know that this is the root cause. The device I am testing with doesn’t support 6GHz, but what is the best practice with this radio when you have a mix of devices with some being able to support and others not. Do I create a dedicated 6GHz SSID or are there settings that I can configure so that devices can select the
I have difficult to add switch Alcatel omniswitch 6860 can some one help.When I configure credential snmp is OK but CLI I can't connect it. When I test in fortinac console cli all is ok but in gui no.
Hi, I want to install FortiAuthenticator v8.x in Microsoft Windows Server 2025.Is this supported? Because in KB only Windows Server 2022 is mentioned.Thank you.
When you run a script on the web GUI/interface:If it fails, it provides absolutely no diagnostic debugging output to the user about why/where? I implore Fortinet, I beg you, please provide diagnostic output about the line number and/or command line that fails. Otherwise, we’re just guessing by taking shots in the dark; not a professional troubleshooting technique. Pasting the same script into the CLI is not the same execution environment as uploading it via the GUI. So one cannot reliably assume that warnings and errors will manifest the same. BONUS: It creates a historical event object (pass or fail run record), so why not save/cache the script code itself, and allow the user to “re-run” it ?
Hi, I can see from KB that the minimum VM specs for FortiAuthenticator installation is CPU 8, Storage 1TB, Memory 16GB.However, we only have 200 users. Can we reduce the specs to 500GB storage and 8GB memory? Anyone has done this? and is there any impact?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.