User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
How we can successfully send CoA to gthe endpoint behind ip phone? Now the CoA is success only if the endpoint connect to the port switch.Open case to Cisco TAC and them say FNAC should send SessionId inside the radius attribute but still not work. Has anyone here succeeded?
Hi,FortiClient VPN on Android 16 disconnects immediately after a successful IKEv2 certificate authentication against a FortiGate 101F running FortiOS 7.4.12.FortiGate debug shows:certificate validation succeededsignature verification succeededauthentication succeededmode-cfg assigned IPv4 address 10.242.221.100added IPsec SAtunnel up event assigned address 10.242.221.100 Immediately after that, the Android client sends:received informational requestprocessing delete request (proto 1)deleting IKE SAFortiClient Android only shows:START → STARTED → TUNNELLING → ERROR → DISCONNECTED No useful error is displayed. Logs show:authenticationFailure falseconnectionFailure falsefailureReason null The same VPN configuration works perfectly from Windows.DNS changes, send-cert-chain disable, and fragmentation changes did not change the behaviour. The FortiGate uses a wildcard server certificate. Client certificate authentication is successful.Has anyone seen Android 16 / FortiClient Android immediat
Hello Guys,I need your insights in a challenge i face with our FortiNAC Deployment.Just a brief explanation of the topology and the case at first. We have a NAC VM Cluster, in which we have enrolled our inventory switches. we want dynamic vlan assignment for the users, based on an the Role attribute that each user has ( attribute 60 = vlan 60). Switches (Cisco) has the respective AAA config and i can see on the NAC that the radius accept is sent when the user is connected to the port. Users have the supplicant configuration for the Radius authentication as well.Issue:In scenarios where a laptop is connected through an IP phone, we’ve noticed that when the laptop is disconnected and reconnected, the IP phone restarts due to a port shut/no shut. Is there a recommended way to prevent the IP phone from restarting during this process? We managed to change some port settings, and the restart is not constant, but if the laptop is not connected to the IP Phone for more than 10 minutes, when we
We recently upgraded our FortiGate firewall firmware from version 7.6.6 to 7.6.7.After the upgrade, we started experiencing issues with several applications, including WhatsApp Web, Canva, Figma, and Microsoft 365 Copilot. Users receive the following error message:"Please check your network and try again."As part of our troubleshooting, we manually added the required FQDNs to the SSL/SSH Deep Inspection profile within the security policies. However, Microsoft 365 Copilot is still not functioning properly.Could you please advise on any additional configurations, known issues, or recommended troubleshooting steps for resolving this problem?
Hi everyone,We are experiencing persistent performance degradation and connection drops (client-rst) when downloading apps from the Apple App Store, updating iOS/macOS, or streaming Apple Music across our multi-WAN enterprise environment running FortiGate.Network Architecture:Firewall: FortiGate (Multi-WAN SD-WAN deployment) WAN Links: 1 Gbps Fiber, Metro Ethernet, RadioLink Clients: macOS and iOS devices across multiple enterprise LANsThe Issue:During Apple-bound downloads, Apple devices initiate multi-stream parallel connections. While 17.0.0.0/8 traffic matches our designated Apple SD-WAN rules, traffic destined for local/global CDN nodes—specifically Fastly (151.101.x.x) and Akamai (185.158.x.x)—fails to match ISDB / FQDN objects.As a result, these CDN flows hit our default multi-WAN load balancing rules, splitting packets across different WAN interfaces (port1, port3, port4). This IP switching mid-session breaks SSL/session persistence and triggers action="client-rst" on the Forti
Hi! I would like to install the FortiClient VPN including the VPN settings with Microsoft Intune. We have more than 150 Windows PCs for installation.So, is it possible to do this? Note please, the vpn settings for remote access is IPSec. Bests,FortiEng
Since deploying FortiClient 7.4.7 some users are reporting that external USB scanners and web cams are no longer working. In device manager we are seeing error code 19. We are assuming that this is linked to the known bug around the 3M PRF UMDF USB driver, however there doesn't seem to be a fix or published workaround for it.As we do not use the specific protection element that would allow us to maybe whitelist the affected driver/USB device we have found that a lower filters driver FortiRMA.sys seems to be the culprit located at the following place in the registry for usHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}Deleting the local filters from this area does then allow the affected USB attached device to work ( following hardware rescan, device reboot or disconnecting and reconnecting affected USB device) and as we do not believe that this filter is anything we actually need we believe its safe to do so. Have anybody else come w
Why link status for each port is different between the device and fortinac? On the device port g1/0/27 - 31 is up but in the NAC is different
Hello everyone,Equipment:Model: FortiSwitch 124F-FPOE Firmware: 7.4.3 (Build 830) GAIssue:A CMK15 intercom/communicator device connected to a PoE port on the switch is not receiving any power. The device does not power on.Already checked:The Ethernet cable has been tested and is working correctly. A Wi-Fi access point connected to another port on the same switch receives PoE power correctly and works normally. The same phone device (CMK15), when connected to a different Fortinet-brand switch running the same firmware version, works correctly. It also works correctly when connected to a switch from a different brand.Could this be a hardware issue, or is there a missing configuration on the FortiSwitch? If not, what should my next step be?Thank you.
After successfully log in via web. The browser gets redirected to login screen and it keep doing this forever. When asked for a license i chose evaluation license and fill the Form with my Fortinet account. Different commands gives me different outputs, i.e get system status shows:FGxxxxx # get system statusVersion: FortiGate-VM64-KVM v8.0.0,build0167,260420 (GA.F)First GA patch build date: 260420Current Security Level: HighFirmware Signature: certifiedVirus-DB: 1.00001(2026-04-02 13:48)Extended DB: 1.00001(2026-04-02 13:48)Extreme DB: 1.00001(2026-04-02 13:48)OCR DB: 0.00000(2001-01-01 00:00)AV AI/ML Model: 0.00000(2001-01-01 00:00)IPS-DB: 6.00741(2015-12-01 02:30)IPS-ETDB: 6.00741(2015-12-01 02:30)IPS-MLDB: 0.00000(2001-01-01 00:00)APP-DB: 6.00741(2015-12-01 02:30)AIAP-DB: 0.00000(2001-01-01 00:00)Proxy-IPS-DB: 6.00741(2015-12-01 02:30)Proxy-IPS-ETDB: 6.00741(2015-12-01 02:30)Proxy-APP-DB: 6.00741(2015-12-01 02:30)Proxy-AIAP-DB: 0.00000(2001-01-01 00:00)FMWP-DB: 0.00000(2001-01-01 00
Hi everyone,We recently ended our support contract with our previous vendor and decided to renew with a different support provider.Unfortunately, the previous vendor has refused to provide the FortiGate administrator credentials and has also refused to share the latest configuration backup.we tried using the maintainer account with the password format bcpb+<Serial Number>, but I received the following error:login: maintainerPassword:Verifying password...Login incorrectDevice Model: FortiGate 200FIs there any supported method to reset or recover the administrator password without performing a factory reset, so that the existing configuration is preserved?Any guidance or recommendations would be greatly appreciated.Thank you.
Good day, i have block instagram from application Control. it works in laptop or pc that connected through this network. but for user who using mobile phone with Wifi access, still able to access Instagram application smoothly. my question is, how to block instagram for user access from mobile phone Iphone or Android. Thank you for Help
Hi Everyone,How can I configure HA on FortiClient EMS 7.4 devices? The device I will run as Passive will be in the FKM (Disaster Recovery Center), so they will not be on the same network. Is this possible? How does the licensing work? I couldn't find a document for the 7.4 version on the Fortinet side; there is only one for 7.2. Can anyone provide information on this?
HI,I have fortigate model 100E which is will end of support. The question due to this model not support anymore with UTM, can we still use this hardware without UTM active? with this model i already configure basic configuration like policy base route, vlan, nat, and firewall. if we not upgrade this, what service will not working? Thank you and appreciate for the feedback.
I enrolled my forticlient with the EMS, it shows “connected”.When I try to connect to the VPN (SAML Login), it’s stuck “connecting”.Two problems come to mind:* It doesn’t show the SAML popup (auth through azure) as it does on windows.* when looking at service log, last line says /opt/forticlient/iked: invalid option -- 'P'I tried a number of things, starting the session with X or Wayland, no change, setting the open in external browser setting flag … with no success.Help
Hi all,just started my first FortiSwitchNMS deployment with about 50 FortiSwitch Rugged at a customer site and am now planning further steps to improve the whole setup.Since the product is quite new and community resources are limited, I wanted to reach out and see if anyone here has done something similar or already deployed the product in general.I'm planning to use ZTP via DHCP option 138 to onboard the switches.Has anyone actually used this in production? Curious whether it works reliably out of the box or if there are quirks to watch out for.I'm also trying to figure out what good day-to-day operations would look like or which features you like.There are functions for backup management that sound quite useful for device replacement scenarios, and I'm wondering how others handle firmware rollouts across a larger switch fleet without things going sideways.The VLAN management in the NMS web UI is a bit confusing and not as intuitive as I'm used to in FortiOS...But maybe I'm missing s
Dear Community,I am writing you all because in my Company we have massive Issues with FortiClient (EMS) on the macOS Clients. I am working as IT Administrator and I am responsible for the MacBook’s.The problem:On the Mac Devices we have since many months the problem that when connected with the VPN the Download Speed is extremely low. We have an External Internet Connection at Work with 100 Mbit/s. With WiFi i get WITHOUT VPN like 80-100 Mbit/s. With VPN ON i get like 5 to 10 Mbit/s (with LAN connection it’s a little bit better). There were also days where it was more so its really inaccurate. The Upload Speed is the same with VPN ON and OFF. ~ 40 Mbit/s. For Windows VPN OFF and VPN ON is the same Download Speed. Some informations:EMS Policies are the same for the Windows- and the macOS Clients We have this features: Remote Access (SSLVPN with Split Tunneling, Webfilter and Vulnerability Scan) Windows Devices are still on 7.2.14 and macOS Devices are on 7.4.5 (I also tested today 7.4.7
Very simple vpn set up for my iPhone. I have a Fortigate 40F firewall. I'm able to access my movie server after successfully connecting to the vpn but not the hikvision cameras that I have configured on the Hik-Connect app. I can reach https://x.x.x.x:443 (camera1) on my iPhone using Safari while connected to the vpn. so that port is working.The live feed fails once it hits 80%. "device connection timed out" Please check its network connection. But I can reach my movie server and access the web sign in of the camera using https. Help? Cameras work flawlessly when on the local network through wifi. VPN is allowed to access my entire lan and "all" services (ports) Modem > Fortinet > Ubiquiti 24 Port PoE > connects all my ethernet, three aps and 5 cameras. All on 10.10.10.0/24. Flat network nothing else. NVR is a Windows 11 Pro Host running iVMS-4200. No VLANs, nothing. Flatter than Earth. Log Allowed Traffic is set to "All Sessions"
● Prerequisites・ FortiOS version: v7.6.7・ Inspection mode: Flow-based・ SSL inspection: certificate-inspection・ Browser: Google Chrome, (Firefox), (Microsoft Edge)・ Client certificate installed on the endpoint ● IssueWhen accessing a site categorized for "Block" or "Warning" actions, the FortiGate is expected to display replacement messages;however, a browser error (ERR_SSL_PROTOCOL_ERROR, or occasionally ERR_CONNECTION_RESET) appears instead of the replacement message.Switching the inspection mode to proxy-based resolves the issue, and replacement messages are displayed correctly.Note that this issue occurs on some endpoints but not others. ● Troubleshooting results・ Endpoints experiencing the issue produced the same results when inspected via a different FortiGate.・ Changing the FortiOS version (to 7.6.6 or 7.4.12) yielded the same results.・ Updating the browser to the latest version yielded the same results. ● QuestionBased on the troubleshooting results, I suspect the issue lies wit
I setup 1VM (FMG V8.0.0) and FW(V8.0.0) and trying to onboard fortigate firewall to manager but getting below error , is there any bug or do i need to make further changes in the configuration considering both VM Mgt subnet are in same subnet. Error “The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager.Could not connect to the FortiManager to retrieve its serial number.”
Hi, how do you set up a VXLAN when you have two locations? We're using FortiSwitches at both locations, and VLANs are also in use there.But we now have another location, and I'd like to know if it's possible to set up a VXLAN using the FortiLink VLAN as well?
Hi all,I am looking for FAZ resources which cover real world use cases or lab based scenario, I have checked on YouTube but not much available, checked their Fortinet Video Lib as well, I would appreciate you recommend some resources, thanksNote : I am focusing on FAZ, FSM
vpn ssl stop working but internet is reachable,my topology is a sdwan connection to internet from two wan sub interfaces joined as sdwan members into a sdwan-zone, we are using the fortigate lower models and firmware are 7.4.0 and 7.2.4, internet connection are asymmetric, home-residential massive internet. SLA health check is active but ramdonly after a couple of days internet connection is up but vpn ssl sub interface is down, no echo-ping goes back and sniffer also doesn´t show anything, only remote solution is to reset port and after that sub interface goes up again. Following current sdwan config edit 3 set interface "subinterface-primary-vpn" set zone "sdwan-to-remote-hub" next edit 4 set interface "subinterface-backup-vpn" set zone "sdwan-to-remote-hub" next... edit "vpn-health-check" set server <remote-looback-ip> set interval 1000 set failtime 10 set recoverytime 10 set source <local-lan-ip-all
I try to send CoA to the endpoint but we can see from below picture the CoA is failed, and from tcpdump there is no traffic to port 1700. Also in the cisco switch i already enable CoA debug but not receive any message. This mean the fortinac not send the CoA message?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.