User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I have difficult to add switch Alcatel omniswitch 6860 can some one help.When I configure credential snmp is OK but CLI I can't connect it. When I test in fortinac console cli all is ok but in gui no.
Hi Fellas,I'm deploying FortiClient EMS 8.0 using Microsoft Intune (Win32 app) and have run into an issue.Environment FortiClient EMS 8.0.x Microsoft Intune (Win32 app) Deployment package generated from EMS with MSI Installer Files enabled EMS generated: forticlient.msi forticlient.mst PackagingBoth files were placed in the same source folder and packaged into a single .intunewin using IntuneWinAppUtil.exe.The install command in Intune is:msiexec.exe /i "forticlient.msi" TRANSFORMS="forticlient.mst" /qn /norestart /L*v "%ProgramData%\Microsoft\IntuneManagementExtension\Logs\FortiClientInstall.log"IssueThe installation completes successfully, but when FortiClient launches, it still displays the "Enter Invitation Code or IP Address" screen.Even when I manually enter the Invitation Code or the EMS IP address, the client does not register with EMS.Additionally, the folder:C:\Windows\FortiEMSInstaller_logsis not created, so there are no EMS installer logs to review.Expected B
hello all,We attacked by ransomware and unfortunately all our file and also backup are encrypted.I want to know if someone advise me how to find from where or witch direction, computer, lan or site - From where it attacked usHow i can create report or see the logs.We have fortinet e200 model.ASP Best Regards,
Today i check our users can’t connect to the fnac and i got this error. I check service connector to the entra is have pronle, where i test to poll and test connection but always loading. The i reboot the nac and the error was gone and the authentication is successful.Something wrong in my fnac?
when we use authentication host-mode multi-domain on the port switch, this mean only one vlan data mac address and one vlan voice mac address is accepted. If there 2 mac address of vlan data then the port switch will be shutdown.Below log from the switch%PM-4-ERR_DISABLE: security-violation error detected on Gi1/0/1, putting Gi1/0/1 in err-disable state The interesting is for iphone deployment. When there are new ip phone connected to the nac then nac will put this host to registration vlan and if this ip phone have endpoint conected then from switch perspective there are 2 valid vlan data mac address and security violation is ocurred.Anyone know how we can deal with this situation?
Hi,Environment: EMS 7.4.7, FortiClient mobile (iOS/Android) 8.0.0, FortiOS 7.6.7. ZTNA access proxy already used by Windows/macOS endpoints.ZTNA certificate signing works automatically for Windows/macOS on telemetry connect. For mobile, EMS only offers ZTNA certificate provisioning via MDM (Intune/Jamf/Workspace ONE, SCEP). We have no MDM for these users.Questions:1. Is manual (non-MDM) ZTNA certificate installation supported on FortiClient iOS/Android? If not, is it a hard limitation or roadmap?2. If supported, what is the correct procedure (cert format, storage location, how FortiClient uses it for ZTNA)?Thanks.
Hi, I have a Fortigate and 4 FortiSwitches connected via fortilink and there are 5 VLANs operating.I also have some devices connected (in every switch on VLAN_20) that communicate with a controller via mDNS packets. They’re broadcasting so the controller can list every device found in the network. This works only if the controller and a device are connected to the same Fortiswitch (in two ports of the same VLAN). If connected to another Switch (to a port of the same VLAN) the packets do not arrive at the controller.Any clue why this happens?Thank you
Hi,FortiGate 7.6.7, IKEv2 dialup with EAP, mode-cfg and IPv4 split tunnel enabled. internal-domain-list is configured, but split DNS never takes effect: every DNS query from the client reaches the FortiGate, not only the two internal domains.config vpn ipsec phase1-interface edit "<tunnel>" set type dynamic set interface "<wan-if>" set ike-version 2 set peertype one set net-device disable set mode-cfg enable set ipv4-dns-server1 <internal-dns-ip> set internal-domain-list "domain1.local" "domain2.local" set eap enable set eap-identity send-request set ipv4-split-include "<split-group>" nextendVerified with: diagnose sniffer packet any "port 53" 4 0 l — public domains such as google.com show up as well. Same result on FortiClient (Windows) 7.4.3 and FortiClient mobile 8.0.0. VPN was fully reconnected after each change.Questions:1. Anything else required in 7.6.7 for internal-domain-
Hello,I am designing a VPN topology for approximately 10 branch offices.Current environment:- FortiGate at the headquarters- Two ISPs at HQ- Two ISPs at every branch- Some branches use FortiGate- Some branches use other firewall/router brands- Each branch has multiple VLANs- Automatic VPN failover is required- Central monitoring is available through ZabbixI am considering the following design:1. Two dial-up IPsec hubs at HQ, one on each ISP2. Two route-based IPsec tunnels from every FortiGate branch3. SD-WAN overlay zone with Performance SLA4. BGP over the VPN tunnels5. Unique Peer ID and PSK for every branch6. Separate standard IKEv2 tunnels for non-Fortinet branchesMy questions are:- Is the dial-up Hub-and-Spoke design recommended for this environment?- Should I use two tunnels or four tunnels per critical branch?- Is BGP worth using for approximately 10 branches, or would static routing be simpler?- What limitations should I expect with mixed-vendor branches?- Should FortiGate and t
EnvironmentFortiGate: FG-60F FortiOS: 7.2.13 (Build 1762) FortiAP: FAP-231K-E (Brand New) Switch: Cisco Catalyst C1300 (L3 Switch)FortiGate 60F | |-->L3 P2P LinkCisco Catalyst 1300 (L3) (WIFI-VLAN gateway and DHCP configured here, interface vlan 30) |FortiAPCurrent BehaviourAP successfully receives an IP address from the Cisco DHCP server.AP can ping the FortiGate.FortiGate can ping the AP.No Local-In Policies are configured.Two different brand-new FAP-231K-E units have been tested.However, the AP never appears under WiFi & Switch Controller → Managed FortiAPs. Current BehaviourAP successfully receives an IP address from the Cisco DHCP server. AP can ping the FortiGate. FortiGate can ping the AP. No Local-In Policies are configured. Two different brand-new FAP-231K-E units have been tested.However, the AP never appears under WiFi & Switch Controller → Managed FortiAPs.diagnose wireless-controller wlac -c wtpTotal 0 WTPsget wireless-controller statuswtp-session-count: 0
I often facing issue where the gui is not responding for some minutes. Anyone else have same issue with me?
Hi,I have this scenario.I tried to register using the captive portal via self-registration but encountered the error "Physical Address not found".This is via wired connection registering from the isolation vlan/network. Configuration:L3 SetupFNAC-F VM - v7.6.5FGT is the L3 deviceTraffic is not being NAT'edFNAC has read-only access in FGT Is there anything else I need to check?Any insights/suggestions?Thank you.
I upgarde fnac to v7.6.7 and found issue with teh MDM integration.When i try to poll then i the poll alsways loading, but test connection is working fine. Also every second there are event ‘destroyed’ like below pic. Anyone know why?
in the radius log i can see mac address 9C:57:AD:B5:E3:2A got vlan 37But on host detail the endpoint got vlan 38And the client is not geeting ip, anyone know why?
What are these highlighted labels??? All testing passed???Seen after upgrading from 7.6.6 to 7.6.7 (Azure)
Hello,I need to grant a specific USER/IP access to a specific path, which is as follows:https://dl.k8s.io/release/v1.36.1/bin/windows/amd64/kubectl.exeI usually use STATIC URL entries, where I typically set the FQDN to “SIMPLE” and “MONITOR” modes—meaning I just use dl.k8s.io—but in this case, I’m required to ensure that only the specified source has access to the URL I’ve provided.Is there anything specific I need to do to achieve this?What are the correct “Type” and “Action” to use in this scenario?Do I need to take the “SSL/SSH Inspection” configuration into account?Thanks for your feedback.
Hi, When trying to renew the server certificate (or create a new one) using the automated option. I get this error: "EMS Invalid certificate and private key: argument 'data' Cannot convert "<class 'str'>" instance to a buffer. Did you mean to pass a bytestring instead?" EMS 7.4.5 build2111 (Mature) Any ideas on what could be causing this? thanks
Hi everyone,I wanted to know if it's possible to manually edit these parameters on the unlicenced FortiClient (VPN Only) version for MacOS ?See the image below: In particular, I need to be sure whether the <eap_method>2</eap_method> parameter (which corresponds to EAP-TTLS/PAP) can actually be configured.I'd like to know if anyone on MacOS has managed to apply these settings, or if I'm forced to purchase the FortiClient Standalone Edition (the client doesn't have the option to buy an EMS server).For additional context regarding my question: currently, we have an IPsec Remote Access VPN setup using IKEv2 + LDAP + MFA (via SMS).Thank you all in advance.
Hello,I have migrate company to the new FortiGate, but without FortiConverter (mine reasoning it that the config is really old, and has some really weird issues that I don't see on other devices). My main issue is that old FortiGate has connection to FortiExtender, and I'm wondering how to properly migrate that config snippet without loosing remote site MGMT/connection to it.What should be transfer to new device? Also is this even valid approach, should I expect any bugs or connection issues after migration?
We're using Fortigate 7.0.12 and most of our FortiAPs are at version 7.0.0. Our main models are 421E and 221E. Our building has two floors. With two AP, on each floor located at the front corners. We've set specific channels and power levels. Everything was fine until this week.Our Guest Wi-Fi (SSID) uses WPA2-Personal PSK.Lately, we've noticed a problem. Some clients, like Windows, Android, and IOS devices, are having trouble finishing the 4-way handshake randomly. Looking at the logs, it seems like the AP and client start talking, but when the AP sends the first message in the 4-way handshake, the client doesn't respond. The AP tries three more times, but the client stays quiet. In the end, the client's device shows an authentication error, and our Fortigate log says there's a client-deauthentication error.The weird part is, if we take the same device to another part of the building and connect to a different AP of the same model and firmware, it works fine.This situation has us scra
Hello,I am trying to deploy the FortiFirewall-VM64-KVM v7.6.7 (build 3704) permanent evaluation on Proxmox VE (KVM).After the initial boot, the GUI always redirects to:/prompt/fortigate-setup?viewOnly=1&startup=1but the page remains completely white and the setup wizard never loads.The CLI shows:License Status: InvalidRunning:exec vm-licensereturns:This VM is using the evaluation license.Failed to download VM license.Output of:diagnose hardware sysinfo vm fullshows:valid: 0status: 3code: 0Things I have already tried: Deployed multiple fresh VMs. Factory reset. Tested with multiple browsers. Verified Internet connectivity and DNS. Successfully pinged update.fortiguard.net and support.fortinet.com. Followed the suggestions from this Community post:https://community.fortinet.com/support-forum-92/issue-installing-a-vm-fortigate-223043?postid=223128#post223128 The behavior remains exactly the same.I also found posts mentioning activation via TFTP using a .lic file, but since I
What am i missing with the configuration:I get the dialup VPN to connect(i.e i am connecting from the PC at port 5 and using 10.10.0.1 as my gateway in forticlient, and i can see that it assigns the correct VPN according to my mode cfg, but when i inspect the vpn logs for the vpn_user_site, there is no traffic traversing the vpn. And even if i do a packet capture of the s2s tunnel interface, or port 5 interface, or both port 1 interfaces on the firewalls, i get no instance of 10.101.101.254 as the destination address. I am new to this and don’t understand the tunnel within a tunnel concept really that well, hence the lab setup i have.To my understanding the only thin i need is a policy that allows the traffic from the remote access vpn to the LO0 interface? I am missing something (since it is not currently working haha, so if anyone has insights or can explain to me how this would be setup correctly. It would be much appreciated.
A couple days ago, I helped one of my clients with installing the FortiClient v7.4.5 on his computer using the FortiClientSetup_7.4.5_x64.exe file. But after the setup process was completed, we noticed that the domain name was not correct; it was showing the domain name of his current company that he works for instead of the domain name of his contractor’s company. So I tried to uninstall the program from Windows Control Panel → Programs and Features → Select FortiClient, but it did not let me uninstall the program. I tried clicking the Repair button, too, but it also did not work.I tried browsing to https://support.fortinet.com -> Support -> Firmware Downloads -> Products, but I got the following message: Sorry, you don't have any product covered by Fortinet support contract.Please contact Fortinet partners to purchase Fortinet support contract or Fortinet customer service team at cs@fortinet.com.And I asked my client if he knew who to contact to download the FortiClientTools
Hello to Everyone, I am playing with the trial VM and I am wondering except doing tcpdump packetsniffer what are the options to debug ssl hanshake issues like unsuppored ciphers ? I am interested for proxy mode rules and flow mode rules and if there is an option when you enable debug flow simillar to fortiweb (Diagnosing SSL/TLS handshake failures | FortiWeb 7.6.0 | Fortinet Document Library) to see such information? Maybe also a "debug application" option as mentioned in Solved: debug SSL inspection for flow based vs proxy based... - Fortinet Community as for proxy mode "wad" process is used. I am wondering for the ips and wad what debug to enable to see the ssl handshake. I enabled the options in Extended logging for SSL traffic - Fortinet Community and I see unsupported ciphers error for 7.2 that is the last trial VM version having flow and proxy mode and I see the issue with SSL failing for proxy mode. Maybe this is why it i
Hi everyone,I'm just starting my journey with Fortinet and studying for the NSE4, so I'm still learning how some concepts differ from Cisco.I have a quick question:Is there a way to configure a physical interface as an access port, similar to Cisco switches using switchport mode access and switchport access vlan <VLAN_ID>?For example, can a FortiGate interface be configured to carry only a single untagged VLAN without using a trunk or VLAN subinterfaces? Or is the recommended approach always to use 802.1Q VLAN interfaces on top of a physical interface?I'd really appreciate any explanation or best practices. Thanks in advance!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.