Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi,I have device FG100E which will end of live on this August, but the firmware still old v6.0.2. From upgrade path i did not see currently firmware i used, it’s only show v6.0.18.The question, it’s safe upgrade direct to v.6.0.18 and then follow the upgrade path? Thank you and appreciate
Dears when the hosts in registration or quarantine vlan persistent agent can’t communicate to fortinac because can’t resolve srv record and retrieve info about fortinac ip address but it retrieves portal and i think it is default in fortinacand when i search in this file i can’t find resolution for srv record except the portal.cat /var/named/chroot/etc/domain.zone.reg cat /var/named/chroot/etc/domain.zone.remso how can resolve this problem as when i search i find that for isolation VLANs it should there is record hosted locally in the fortinac
Hi everyone,We are currentrly switching SSL-VPN to IPsec on our good old FG-200e (v7.4.12)The problem I am facing is that we have a few VPN > SD-WAN rules with NAT enabled, so that the traffic goes trough the tunnel and arrives destinations (IP adresses of AWS servers and some other FQDN's) with our main link IP address.It works fine on SSL-VPN, but I can't make it work with IPsecAny ideas why this happens? Really need to sort this out ASAPThank you
Hi people ,i have in office Fortigate with ip public 87.xx.xx.xx, policy created for internet,for ipsec between other fortigate with ip public 193.xx.xx.xx. I created in windows vpn conection l2tp other ipsec for conect my pc office to mikrotik .Issue is when i try to conect vpn windows(client) to mikrotik(server l2tp/ipsec) this conection is down ,but when i try conect pc office to hotspot conection is successfully vpn l2tp/ipsec to mikrotik.Can anybody help with this issue,why my pc canont conect l2tp/ipsec to mikrotik?
Hello Community, We have a Fortigate 201G with firmware version of v7.2.x we have done some risk assessments on the fortigate and most of the risks identified shows all versions 7.2.x are affected by specified vulnerability, and need move to another version now we wanted to move to the version 7.6.x before we do that I wanted to confirm if our hardware can fully support it. and there wont be any issues or problems we might face later after the update.
Sporadically our Fortianalyzer (7.4.9) will stop sending logs to our main syslog log collector (Is still collecting from other systems). The “Log Insert Lag Time” will get up to 18 or so hours and keep climbing, when it should be like 20-30 seconds. When the analyzer is rebooted, logs start to flow and the time slowly starts to normal, and everything is ok. I’ve been trying to get that value via a command line, or SNMP to feed our PRTG system to monitor when it happens before it gets out of control. But, it seems to be allusive. Maybe I’m missing something? Perhaps there is another tell sign that I can look at? Or is it a feature request?Thanks!
Hi Team,We are planning to deploy FortiAuthenticator On-Premises for a client.Client Requirement: When users register their endpoint with FortiClient EMS (ZTNA), MFA should be enforced. The client wants users to have either SMS OTP or Google Authenticator (TOTP) as the second factor, with both options available for redundancy. Could you please confirm the following: Is this requirement supported with FortiAuthenticator? What are the prerequisites for implementing this setup? For SMS OTP, does FortiAuthenticator require a third-party SMS gateway/provider? If yes, which integrations are supported or recommended? Are there any licensing or configuration considerations we should be aware of before deployment? Any implementation guidance or best practices would be appreciated.Thanks!
Hi,I now create additional dialup tunnels on second wan for failover, but we use ftm to get notifications during login on mobile smartphones, the config looks like:FGT (ftm-push) # show full-configuration config system ftm-push set proxy enable set interface '' set server "PUBLIC_IP_OF_WAN1" set server-port 4433 set server-cert "Fortinet_Factory" set status enableendhow to configure ftm to have it working on WAN1 and WAN2 interfaces, because If I’m trying to configure it on both wan ports I get an error: FGT (ftm-push) # set interface "port24" "port23"command parse error before 'port23'Command fail. Return code -61
We have FortiManager 7.6.7 and two FortiGates running FortiOS 7.4.11.Under Security Profiles > SSL/SSH Inspection, we have an object named “SSL-EXCEPT” with set cert-probe-failure allow, and this profile is used in several firewall policies.In FortiManager, the same object also has allow configured. However, whenever we make any change in FortiManager, it applies unset cert-probe-failure, which is preventing us from managing changes on these FortiGates through FortiManager.How can we fix this?
Hello,I am using FortiOS 7.6.x. According to the documentation, I can block traffic based on both category and URL.Specifically, my URL filters use the *FQDN wildcard block. It works well with a few exceptions such as: *worldguesser.io or *crossyroadgame.io or *crossy-road.io. I don’t understand why these are getting through the firewall. Am I missing something?Category-based filtering is very broad and blocks two interesting domains:Group: General Interest - Personal https://boinc.berkeley.edu/General Interest - Business https://worldcommunitygrid.org/Is there a way to exclude certain domains from a category?Thank you
Hello , can we do user based ztna web proxy with using local user of Fortigate local database with mac binding , mean ztna web proxy is opened with only same user with same mAc of machine , otherwise rejected
Hi everyone,I'm running into a frustrating issue with the Device Identification (IoT/OT detection) feature on our FortiGate. Multiple Windows laptops on our network are being incorrectly identified as Samsung Galaxy Android 5.0 devices.Because of this, FortiGate is flagging a randomly list of potential IoT/OT vulnerabilities associated with Android Lollipop, which is obviously a huge false positive (especially since no one is bringing Android 5.0 devices to the network in 2026!). Here are some key details about our environment: The affected clients are purely Windows machines. There are no Android emulators installed on these laptops. This is happening across several different devices, which rules out a simple stale DHCP IP cache/re-use issue. Checking the CLI (diagnose user device), the MAC OUI belongs to Cloud Network Technology (standard for laptop Wi-Fi adapters), not Samsung. Has anyone else encountered this specific false positive recently? Any insights on which common Wind
API-TEST
Hello, I apologize in advance if this sounds like a stupid question. I passed the NSE4 Certification Exam on June 18, 2024. I very recently heard that my certification would run out of validity if it’s 2 years old. I have to take the NSE5 Certification Exam, as I was unable to take it before, but I am unsure if my NSE4 Certification is still valid. Please let me know and thanks for your help!
My Fortinac was integrated to Entra ID for 802.1x authentication, now i want to know can we use entra id to login to the web admin of fortinac?
Verify policy match (Policy Match): diagnose debug flow filter addr <IP_ORIGEM>diagnose debug flow filter addr <IP_DESTINO>diagnose debug flow show console enablediagnose debug enable diagnose debug flow trace start 10 Validate NAT (SNAT/DNAT):show firewall policy <ID> Verify Routing:get router info routing-table all
Validate Status of two SD-WAN Linksdiagnose sys sdwan health-check
Hi Fortinet Community,Could you please provide some guidance on the following scenario?I currently have a single IPsec VPN tunnel configured, and the accessible networks include Servers 1, 2, 3, 4, 5, and 6.I have different users who need access to specific servers only:UserA should be able to access Servers 1, 2, 3, and 4. UserB should be able to access Servers 5 and 6 only.Should I create separate firewall policies for each user while using the same IPsec tunnel, or should I create additional IPsec tunnels?I have noticed that when I create another IPsec tunnel, one of the tunnels sometimes goes down. What could be the possible causes of this issue, and what troubleshooting steps should I take?Any advice or best practices would be greatly appreciated.Thank you!
Hey guys,I'm failrly new to terraform and I was curious if fortigate managed app deployment within Azure vWAN is a good option/approach? Keeping in mind that rest of the infrastructure (vWAN, HUB/s, VNETs, NSGs, subnets..etc) is deployed using terraform, would there be any harm if NVAs are deployed manually?ps NVA deployment would be one time setup, no multiple environments (dev, prod, test) nor requirements for NVAs to be deployed more oftenEvery comment is appreciated
I am currently trying to see the limits of Terraform in deploying configuration in Fortimanager and Fortigates. My goal is to beable to implement a webfilter on policies and install those policies and the package (FortiManager) related on the required target (Fortigate).Everything was working correctly until I added the webfilter profile. Terraform execution is working correctly. But in Fortimanager the taskfor installing the package results every time in "Error".I tried to push it using manually using the gui with the web filter profile created by terraform. There is no erro. I also tried to implement this partin Ansible and the problem is exactly the same.The module for implementing the firewall policies :resource "fortimanager_packages_firewall_policy" "tunnelInternet" { for_each = var.InternetPolicies scopetype = "adom" adom = local.get_adom_from_pkg_internet[each.key] pkg = each.value.pkg name = each.value.name policyid = each.value.policy_id srcintf = ea
If i connect S1 “Fortiswitch” to S2 “Cisco ” Using trunk port and in trunk port I allowed VLAN 20 only on FortiGate i create policy to route between VlAN 10 and VLAN 20 Can PC1 in VLAN 10 ping to PC2 in VLAN 20 and if yes why and if no Why ? 2. Is trunk port control traffic between different Vlan when i allowed VLAN 20 only in trunk or FortiGate will control traffic between different vlan ?
Hi everyone,I'm running a FortiGate VM v7.6.2 in EVE-NG and I'm unable to activate the Evaluation License.EnvironmentFortiGate-VM64-KVM v7.6.2 EVE-NG Community Edition Port1 connected to Cloud1 (management network) VM Resources: 1 CPU 2 GB RAM Serial Number: FGVMEVSS0CLPWM3A What I've configuredPort1 IP: 10.136.208.183/24 Default Gateway: 10.136.208.215 Static Route: 0.0.0.0/0 via 10.136.208.215 DNS resolution appears to be working.Connectivity TestsWorking: execute ping 8.8.8.8Working: execute ping 1.1.1.1Working: execute ping google.comNot Working: execute ping forticare.comNot Working: execute ping forticloud.comLicense IssueWhen I go to:System → FortiGate VM License → Evaluation LicenseI enter my FortiCare account credentials and click OK.The GUI shows:"Requesting FortiCare Trial license, proxy:(null)"but nothing happens afterward and the license remains invalid.Current status: License Status: InvalidVM Resources: 1 CPU/1 allowed, 985 MB RAM/2048 MB allowedQuestionsDoes Forti
hi,we’ll loan a FG 100 F from our DC colo vendor to build a temporary IPSec VPN back to our HQ.this might run for 2-3 months that’s why we’ll only “rent’ the FW.my questions are:1.do i need to register the device to our FortiCloud asset?2.do i need to apply FortiFlex license for HW/OS coverage in order to use “higher” crypto protocols, i.e. AES 256, SHA 256, or do these come free?can i just skip items 1 and 2 since this is just a “loan” and temporary build?
Hi,I have an issue with the evaluation license of my new FortiGate v7.4.1 VM, I am trying to license my new FortiGate and I am using my account credentials to connect to the forticare server but it fails, I did some troubleshooting and I notice that I can't ping the forticare.fortinet.com but instead the service.fortiguard.net and update.fortiguard.net were pinged successfully. can you please assist me with this problem.
Environment:FortiClient VPN 7.4.3.4726 (free/standalone)SSL-VPN to remote gateway: vpn5.go.com.mt:443OS: WindowsVPN Configuration:Type: SSL-VPNPort: 443 (custom)Authentication: Prompt on loginSingle Sign On (SSO): DisabledClient Certificate: NoneIPv4/IPv6 dual-stack: DisabledIssue:When attempting to connect via SSL-VPN, the connection progress bar reaches 48% and then fails with a popup: "SSL connection is down".Credentials have been verified and reset multiple times. MFA is active and functioning correctly. VPN configuration appears correct.Errors observed in Notifications log:Too many bad login attempts. Please try again in a few minutes. (-455) — repeated multiple times throughout the dayToken denied or timeout. (-7105) — appeared earlier in the sessionWhat was already checked/tried:Password confirmed correct and reset multiple timesUsername confirmed correctMFA (token) is active and generating codes normallyVPN gateway and port (443) confirmed correctNo FortiClient EMS in use (stan
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.