User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi everyone,I have the topology below using Fortigate HA Active -Active Cluster Everything works normally until SW1 (the current STP root) is rebooted or powered off.After SW1 comes back (or after the topology reconverges), the topology does not recover correctly. One or more FortiSwitches may randomly become Offline, even though the physical links are up.The only workaround is to disable and enable FortiLink Split Interface, after which all FortiSwitches immediately come back online and the topology is rebuilt correctly.FortiOS 7.6.7 / FortiSwitchOS 8.0.0
We have 2 internet connections terminated to our firewall with spare IPs, and SD-WAN is already configured outbound for load-balance/failover.We have a specific outbound service (SMTP) that we want to attach to a dedicated outbound IP address.Setting an outbound NAT policy with an IP Pool was easy enough, and that's working, but we only have it setup for one of the internet connections at the moment.How can we set this up with a dedicated outbound IP for each internet connection and have it failover if the main internet connection goes offline? (active/passive)
Hi everyone,I'm trying to integrate FortiWLC 8.6-5 build-8 (FortiWLC-500D) with Aruba ClearPass Guest (ClearPass Policy Manager 6.12.7.308288 on C3010 platform) as an external captive portal.Current setupFortiWLC 8.6-5 build-8 External captive portal: Aruba ClearPass Guest Authentication type: RADIUS Captive Portal External Server Type: Fortinet-Presence External URL: https://<clearpass fqdn>/guest/guest_register_3.phpThe captive portal profile is configured as:Authentication Type: radiusCaptive Portal External Server Type: Fortinet-PresenceSuccess Redirect URL: https://<default redirect url>Login flowClient connects to SSID.FortiWLC redirects the client to the ClearPass Guest portal.The login page receives all FortiWLC parameters correctly, including:magicusermacuseripserveripapmacapidapnodeidssidpost=https://<controllerip>:8081/vpn/loginUser? User enters username/password.ClearPass successfully authenticates the user against the authentication source.After successf
Hello team, I have interesting situation. there are 4xFg900G in cluster. there is FTP server in vlan 100.L3 DG address for that vlan 100 is on Fortigate.When secondary 900G FGs from cluster want to reach ftp they can not.We also have cluster of 4xFG 400F for additional services, and they can all reach ftp server , no matter primary or one of 3 secondary FGs How to solve this situation?My final aim is to upgrade one of secondary FGs regarding MVC (Multi-version cluster) option, set upgrade-mode local-only, and upgrade one of secondaries and then reset ha uptime so that upgraded one become primary. Reason for that is because we must not have any downtime, and we want to take test after upgrade if all services are ok
Had multiple issues when adding a FortiGate using discover device. It always said device serial number does not match Only once I updated to 7.4.11 did it finally add First post here and its the end of my day so I’ll add more later, just don’t want someone to lose an entire day to this like I did.
hi,i’d like to setup a remote syslog server to collect NAT 5 tuple logs (source/dest IP, source/dest port and service/app).i have a multi VDOM FGT and would like to setup syslog server config in a non root/MGMT VDOM.my VDOM setup is i have an upstream ‘internet-gw’ VDOM and several downstream ‘nat-client’ VDOMs.goal is to setup syslog in ‘internet-gw’ VDOM and ‘nat-client-a’, ‘nat-client’b’ VDOM to send NAT log that’s filtered based on 5 tuple info.can someone advise on this? my google search only points to non VDOM FGT syslog and i already configured/enabled syslog in ‘global’ VDOM.
Hi Community, As per title “How to get Fortinet higher up to review related TAC Manager ticket”In ticket (11996986), we had factually proven the issue and the TAC Manager do acknowledge on it.Suddenly the TAC Manager (Jonathan) twist the fact on what discussed.Luckily we had video call recorded. How can we further submit to Fortinet higher up to review this TAC Manager whether these action is being approved? Thank You Best Regards,YK
After correct configuration ddns for DynDNS (not Forti-DDNS) is there any CLI-command to check the status for this service ? My firmware version = 5.0.1.
For FortiEdge Cloud, how do you assign different user accounts to have access to different networks?I believe this used to be accomplished using the Multi Tenancy license and sub accounts, correct?Since this can’t be ordered anymore and is going away, how do you do it using the new organization method?
Dear Community, We have this case where we want to configure two different IP Addresses as destination for our fortigate to be monitored as part of our link health monitoring. Our Cariteria is like this:First Destination is the next hop ISP IP AddressSecond Destination is our Server on the Internet Now we want the link to monitor both IP Addresses and if any of these two IP Addresses are not reachable then the link should be detected as down. Can anyone help me how to do this one.I have also read this on the internet can you all confirm if this is true?Someone suggested using the OR logic and configure two separate SDWAN performance SLA one for each Destination Server and if an interface participates in multiple Performance SLA (health-check) probes, it's only considered "up" if it passes ALL of them. So failing even one the interface marked down = SD-WAN swings traffic to the Backup. This is exactly the OR-failure logic you want. Best Regards,Shah.
Hello, Trying to understand what happened and how to prevent it in the future: - Running FortiGate-VM in an Azure VM.- This FG has a custom site-to-site IPSec tunnel to on-prem. This effectively connects the virtual data centre to the on-premises data centre. Tunnel is initiated from Azure.- Suddenly, the tunnel no longer works. Phase 2 will not go up.- The first sign of trouble is this: Unavailable : Live Migration (Unplanned)At Thursday, October 13, 2022 at 7:29:19 PM EDT, the Azure monitoring system received the following information regarding your Virtual machine:This virtual machine was paused for 0.675000 seconds due to a memory-preserving Live Migration operation. No additional action is required from you at this time. Recommended StepsNo action is required - A couple of minutes after this, alerts start going off that connectivity has been lost.- After some trouble shooting, pinging, checking routes, connectivity, rebooting, firmware upgrade,
Hello, installation of FortiClient VPN ends in an error "FortiClient VPN Wizard ended prematurely because of an error." I am running Windows 11 home on my new surface 11 pro. I executed Installation .exe as Administrator, i disabled Windows Defender temporarily. Any further ideas?
EnvironmentPlatform: FortiGate (hardware appliance)HA mode: Active / PassiveFortiOS current version: 7.4.8Target version: 7.4.10HA priorities:Unit A (Master): priority 200Unit B (Slave): priority 100Expected upgrade behavior (normal case)Based on Fortinet documentation and past experience, the expected HA upgrade sequence is:Firmware upgrade starts on the slave unit (B).Slave reboots and temporarily disconnects from HA.Cluster fails over to the upgraded slave.Firmware upgrade is then applied to the former master (A) in background.Final failback occurs according to HA priority (unit A becomes master again).Observed behavior / Issue descriptionDuring the upgrade from 7.4.8 to 7.4.10 (firmware uploaded via GUI using .out file downloaded from fortinet official source):The upgrade process took more than 20 minutes, significantly longer than usual.HA became disconnected, and unit B (slave) was no longer visible from the cluster GUI.Accessing unit B directly via Console & Management
I have many event like below picture, can we troubleshoot from where the mac address is come? On my L3 switch i can’t see this mac.
Hi Fortinet Support,We're looking for guidance on deploying and configuring the FortiClient VPN application on Apple iOS devices managed through SOTI MobiControl.Our Android devices are working as expected, where the VPN configuration and authentication are deployed through SOTI. However, the process appears to differ on iOS, and we're looking for the recommended approach.Specifically, we'd like to know:Whether the FortiClient VPN configuration can be deployed automatically through SOTI MDM on iOS. Whether VPN profiles and authentication settings can be pre-configured using Managed App Configuration or another supported method. If there are any limitations on iOS compared with Android regarding deployment or user interaction. Whether there is any official Fortinet documentation or best practice guidance for deploying FortiClient VPN on iOS using SOTI MobiControl.Our environment:MDM: SOTI MobiControl Devices: Apple iPhone and iPad (iOS/iPadOS) VPN Client: FortiClient Android deployment
It seems IPSEC MFA via FortiToken requires FortiClient 7.4.4 when using LDAP, so no free FortiClient version then.Are there any other options for MFA with FortiClient VPN Only 7.4.3? Does it still work with SAML, or Radius via Windows NPS perhaps?
How to generate a FortiAnalyzer report to get ISP uptimes?
Hi FAZ、FMG created same ADOM name for manage FAZfollow this guidehttps://docs.fortinet.com/document/fortimanager/7.4.0/examples/289359/adding-fortianalyzer-to-fortimanager at FAZ, ADOM name ”ADOM_v74” have one device at FMG, have same ADOM name”ADOM_v74”, and same devicebut in this ADOM, the left sidebar doesn't even have a Log View or FortiView to check traffic or other logs.only “FAZ” ADOM have Log View and Forti View
Hi everyone, I have this issue with a FortiManager I have deployed in Eve-NG. It’s just used for labbing and playing around with config etc, so its intended to be very simple at the moment.It’s a brand new deployment and licensed using the free license with FortiCloud. Yesterday I was able to log into the manager with no problem, worked fine and then I started experiencing the issue with logging in and getting the ‘Rejected’ message. I have done the basic config such as routing and admin access.The same creds work via the CLI. It is a local account, with no trusted hosts or 2FA.My next thoughts are to just wipe the config and redo the deployment as there is nothing of value on it at the moment and it is probably just easier, but thought it would be worth asking and getting this on the community incase anyone else has the issue.
Hello,I've a newly deployed Fortigate 200F in my LAN. I've an internet souscription bandwith of 16M.Recently I've been realizing that my bandwith is constantly saturated, but Fortiview doesn't show me the applications that saturate the bandwith. As you can see on the images above, the total bw of the internet applications displayed by the firewall (4Mbps) is much lower than our subscription (16Mbps) but it still displays our bw saturated, and the internet service is slow.Please note that this is not permanent. It happens constantly.When look to the security report, the firewall doesn't indicate any malicious attack.Please any help will be very appreciated.Thanks
People on Fortigate 7.4.12 using FAC as the Captive Portal are all working fine, I built some new sites on 7.6.7 and the config is identical, only now they cant Authenticate, they hit the Exempt rule to get to the FAC on https, and they register and get approved, but they cannot authenticate when logging in to the page.I've never liked the logs on FAC, they are not helpful at all! but most of the messages are “Guest portal authentication request failed, then says please check the Radius Auth logs, but there are none! as they don't Auth! Has something changed in the way 7.6.X Authenticates now? The EAP-TLS is working fine for the other SSID, its just Captive portals (Once again!) even in debug mode there is nothing when I search for the failed user, its most annoying, I am using “set require message authenticator enabled” but on 7.4.12 its disabled as its disabled on the FAC, is this enforced now?In short it works on 7.4.12 but not 7.6.7. , Scowered the release notes and cant see anyt
Hi allI have noticed a weird issue, client had a power outage over the weekend as the redid the server room UPS.Now my AP’s show “Connected VIA” my VOIP interface on the FortiGate, even tough they are connected via FortiSwitches and the LLDP Neighbors are correct, also the IP’s they get are from my DATA VLAN.They use to say connected via DATA VLAN and once rebooted they now show VOIP. all troubleshooting points to they are indeed connect via DATA VLAN.GUI BUG? FortiGate 7.4.12 , FortiSwitches 7.4.8 and FortiAP’s 7.4.6Please let me know if anyone has experienced this and why now all of the sudden?
Hi TeamI have around 200 VPN users. It requires monthly administration tasks to ensure VPN access is revoked timely for resigned leavers, interns and staffs no longer require VPN access. It is for IT Audit Policies.On Fortigate firewall, this is not a helpful task. My Fortigate (FortiOS 7.2 & 7.4), have not that option of per-user vpn account expiry date !!However, on Cisco Meraki MX, it allows configuring an account expiration date on VPN users directly. This was very useful since 1st Covid 2020 to date.Are there any workaround?
Hello, we have an issue about forticlient application, 1. installed application2. imported configuration file successfully3. while entering username and password and click connect button, app does not do nothing, just clearing username and password also, tried to uninstall, clean reinstall of application with revo uninstaller pro, but didn't work, also trierd to debug on firewall and there was no any traffic matching. application version is 7.4.3.4726 We tried the same installer file and the same vpn configuration file on other desktop and it worked successfully, the main thing is that we can not reinstall windows but need to setup the forticlient vpn urgently.
Hello everyone,Can anyone confirm whether FortiNAC-F fully supports (or has been successfully integrated) with the following:Aruba 1930 switches TP-Link TL-SG1016PE switches Sophos AP55C access points UniFi U6 Mesh Pro access pointsSpecifically, I’m interested in understanding:Level of support (CLI/SNMP/API… etc) Visibility and control capabilities (profiling, enforcement, VLAN assignment, etc.) Any known limitations or required workaroundsThanks in advance.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.