User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We're using Fortigate 7.0.12 and most of our FortiAPs are at version 7.0.0. Our main models are 421E and 221E. Our building has two floors. With two AP, on each floor located at the front corners. We've set specific channels and power levels. Everything was fine until this week.Our Guest Wi-Fi (SSID) uses WPA2-Personal PSK.Lately, we've noticed a problem. Some clients, like Windows, Android, and IOS devices, are having trouble finishing the 4-way handshake randomly. Looking at the logs, it seems like the AP and client start talking, but when the AP sends the first message in the 4-way handshake, the client doesn't respond. The AP tries three more times, but the client stays quiet. In the end, the client's device shows an authentication error, and our Fortigate log says there's a client-deauthentication error.The weird part is, if we take the same device to another part of the building and connect to a different AP of the same model and firmware, it works fine.This situation has us scra
Hello,I am trying to deploy the FortiFirewall-VM64-KVM v7.6.7 (build 3704) permanent evaluation on Proxmox VE (KVM).After the initial boot, the GUI always redirects to:/prompt/fortigate-setup?viewOnly=1&startup=1but the page remains completely white and the setup wizard never loads.The CLI shows:License Status: InvalidRunning:exec vm-licensereturns:This VM is using the evaluation license.Failed to download VM license.Output of:diagnose hardware sysinfo vm fullshows:valid: 0status: 3code: 0Things I have already tried: Deployed multiple fresh VMs. Factory reset. Tested with multiple browsers. Verified Internet connectivity and DNS. Successfully pinged update.fortiguard.net and support.fortinet.com. Followed the suggestions from this Community post:https://community.fortinet.com/support-forum-92/issue-installing-a-vm-fortigate-223043?postid=223128#post223128 The behavior remains exactly the same.I also found posts mentioning activation via TFTP using a .lic file, but since I
What am i missing with the configuration:I get the dialup VPN to connect(i.e i am connecting from the PC at port 5 and using 10.10.0.1 as my gateway in forticlient, and i can see that it assigns the correct VPN according to my mode cfg, but when i inspect the vpn logs for the vpn_user_site, there is no traffic traversing the vpn. And even if i do a packet capture of the s2s tunnel interface, or port 5 interface, or both port 1 interfaces on the firewalls, i get no instance of 10.101.101.254 as the destination address. I am new to this and don’t understand the tunnel within a tunnel concept really that well, hence the lab setup i have.To my understanding the only thin i need is a policy that allows the traffic from the remote access vpn to the LO0 interface? I am missing something (since it is not currently working haha, so if anyone has insights or can explain to me how this would be setup correctly. It would be much appreciated.
A couple days ago, I helped one of my clients with installing the FortiClient v7.4.5 on his computer using the FortiClientSetup_7.4.5_x64.exe file. But after the setup process was completed, we noticed that the domain name was not correct; it was showing the domain name of his current company that he works for instead of the domain name of his contractor’s company. So I tried to uninstall the program from Windows Control Panel → Programs and Features → Select FortiClient, but it did not let me uninstall the program. I tried clicking the Repair button, too, but it also did not work.I tried browsing to https://support.fortinet.com -> Support -> Firmware Downloads -> Products, but I got the following message: Sorry, you don't have any product covered by Fortinet support contract.Please contact Fortinet partners to purchase Fortinet support contract or Fortinet customer service team at cs@fortinet.com.And I asked my client if he knew who to contact to download the FortiClientTools
Hello to Everyone, I am playing with the trial VM and I am wondering except doing tcpdump packetsniffer what are the options to debug ssl hanshake issues like unsuppored ciphers ? I am interested for proxy mode rules and flow mode rules and if there is an option when you enable debug flow simillar to fortiweb (Diagnosing SSL/TLS handshake failures | FortiWeb 7.6.0 | Fortinet Document Library) to see such information? Maybe also a "debug application" option as mentioned in Solved: debug SSL inspection for flow based vs proxy based... - Fortinet Community as for proxy mode "wad" process is used. I am wondering for the ips and wad what debug to enable to see the ssl handshake. I enabled the options in Extended logging for SSL traffic - Fortinet Community and I see unsupported ciphers error for 7.2 that is the last trial VM version having flow and proxy mode and I see the issue with SSL failing for proxy mode. Maybe this is why it i
Hi everyone,I'm just starting my journey with Fortinet and studying for the NSE4, so I'm still learning how some concepts differ from Cisco.I have a quick question:Is there a way to configure a physical interface as an access port, similar to Cisco switches using switchport mode access and switchport access vlan <VLAN_ID>?For example, can a FortiGate interface be configured to carry only a single untagged VLAN without using a trunk or VLAN subinterfaces? Or is the recommended approach always to use 802.1Q VLAN interfaces on top of a physical interface?I'd really appreciate any explanation or best practices. Thanks in advance!
Hello,If we need to deploy a cluster of two FortiGate firewalls as VMs without using the virtual MAC (vMAC), and instead use the hypervisor-assigned MAC address of each firewall interface, I would like to confirm whether this type of cluster configuration is supported.In other words, is it possible to operate a FortiGate HA cluster without using the vMAC mechanism and have each firewall use its own physical/virtual interface MAC address during a failover event?Thank you for your clarification.
Hi,I would like to just ask around (not going to open an official case with fortinet just now) if any of you have noticed something similar recently.I have a very low but increasing number of users that start up their laptops in the morning and the Forticlient ZTNA has lost it's license resp. the affiliation to the EMS cloud. No config left, not connected.The respective laptops do not show up in EMS any longer. When I enter a new invitation code in the Forticlient incl. User verification, it connects again and receives config and all is good.I can rule out that the user hit the "disconnect" button on the ems connection because that is password protected.The only thing common, that I think I identified, is that all affected users don't connect to the vpn daily.
Product: FortiGate-101FFortiOS Version: 7.6.6, build 3652HA Mode: Active-Active (A-A), ha-direct enabledCluster Members: Primary / SecondaryCluster Status: Healthy, in-sync, uptime 86+ daysSyslog traffic configured under config log syslogd setting is not reaching our syslog collector (10.0.0.151:514/UDP), despite the syslog daemon reporting successful log processing. No syslog packets are observed on any interface via packet sniffer, even though routing to the destination is confirmed correct and other traffic to the same host (ICMP, TCP/5986) is confirmed working.config log syslogd setting set status enable set server "10.0.0.151" set mode udp set port 514 set facility local7 set format default set priority default set interface-select-method auto set vrf-select 0endconfig router static edit 2 set dst 10.0.0.0 255.255.255.0 set gateway 10.37.81.2 set device "port4" next edit 3 set dst 10.0.0.151 255.255.255.255 se
I have 2 FortiGate 100F firewall setup in HA A-P and dedicated HA-MGMT interface is configured with dedicated OoB interface, I have a internal webproxy server in Layer 2 VLAN with DNS and FGT is also in the same VLAN and is pinging Proxy and I want to setup those firewall to use that proxy server to connect to fortiguard, I am trying to setup but it is not working through OoB interface. Appreciate support here.
I couldn’t find much information on enabling the all events portion of FortiClient EMS (I’m running 7.4.7). After a couple of weeks playing with it I finally got it working. But just a quick overview I wanted to post in case others have tried and failed at setting this up. So what you need to do is setup a Linux VM (I used Debian 13 Trixie) and install ElasticSearch. Then you have to make sure its reachable on the network by modifying the YML file. Then install Kibana and do the same for it. Kibana is the GUI management tool that makes working with ElasticSearch easier. Then you create an API Key for FortiEMS. Then you upload the http_ca.crt to FortiEMS. Then you run the emscli command for enabling ElasticSearch. That is pretty much the overall process.
Hello,I currently have SSL VPN active and I want to switch to IPsec VPN (IKEv2 Remote Access).Environment:FortiGate model: FG-101FFortiOS version: 7.4.11VPN type: IKEv2 IPsec Remote AccessAuthentication: FortiAuthenticator 6.5.6 build 1391 (GA) with OTPDirectory: LDAP users and groups from Active DirectoryClient: FortiClient 7.4.3 Hotfix 1 (7.4.3.8758)I am configuring an IKEv2 IPsec remote access VPN that authenticates users via FortiAuthenticator using LDAP credentials and OTP.The VPN connection is not successfully established from FortiClient.Phase 1 (SA_INIT) completes successfully, but the connection fails during user authentication (EAP phase).FortiClient shows the following error:Wrong EAP credentialsHas anyone encountered this issue when using IKEv2 with EAP authentication and FortiAuthenticator OTP?Any suggestions or troubleshooting steps would be appreciated.Thank you.
I am setting up 802.1x with clearpass and most of my switch are running 7.6.1 or lower and are working fine. I upgraded 2 switches this morning to 7.6.6 and now they absolutely refuse to work if I have the 802.1x security policy on the ports. Worked fine on 7.6.1. Not even DHCP is getting passed to the native vlan.I've spend the majority of my day trying to find a way to work around this today and am at the end of my chain.I can't even roll back to 7.6.1 because I don't have switch support to download.I ran a sniffer on the fortigate and the switch doesn't send a single RADIUS packet when a port comes up.Anyone have any suggestions?
now i have situation i want to register ip phones in my company manually and if there is no registered ip phone as rogue i mean so i need to block its traffic but doesn’t block data traffic behind it how to achieve this using fortinac?
Dear Experts,I’m working with FortiWeb, which deployed 6-8 months ago and security policy in monitor mode. Now, customer decided to change security policy to Blocking Mode from Monitor mode.I have checked for Fortinet official document, but didn’t see any recommendation or workaround for such transition from Monitor mode to Blocking mode. Appreciate, if experts can advise on this. Regards, Faridul
Based on below article, can i know if every group in fnac inventory should have L3 device for L3 polling?
A FortiMail client, who uses the free tier of FortiSandbox SaaS, was informed about new vulnerabilities and intends to identify the version of FortiSandbox in use in order to assess whether there is any risk of exposure.
Hello everyone,I am running into an issue regarding a duplicate device in EMS , and I am unable to delete the stale record because of the Azure AD sync lock.Environment: FortiClient Version: 7.2.12 OS: Windows 11 Enterprise EMS Integration: Synced with Azure AD (Entra ID) The Current Issue: Telemetry is Connected: The clean reinstall fixed the WMI conflict. Forticlient Telemetry now successfully connects to EMS. Duplicate Device in EMS: Because of the clean reinstall, the endpoint generated a new UID. EMS now shows two records for the exact same Hostname/MAC Address. One is Offline (old UID) and one is Online (new UID). Cannot Delete the Stale Record , but the license was used twice on the same device My Questions:What is the best practice to remove or merge this stale duplicate device in EMS?Any insights or workarounds would be greatly appreciated. Thank you!
I want to test latest Fortigate VM image on Virtualbox. but I get error “Failed to start !”. Is there some way to start the VM locally?
It appears that if a person purchases a used Fortigate product, that they are unable to download firmware without paying for “support”.Is this the way it is? Or am I missing something?
Hi i have create lots of VPN definitions in the VPN Manager and assign them to Managed fortigates. When i try and install the policy i quickly get this error. "cannot find addr xxxx" "load vpn node x failed". the object is there but need to be loaded on the GW. even tryig with a policy with no VPN in the rules also fails. Any ideas?
How to Protect Fortigate from IPv6 Security Risks
Hi everyone,I'm currently testing the FortiNAC Persistent Agent in my lab environment. The agent is unable to establish a connection to the FortiNAC server. Below are the troubleshooting steps that I have already completed.Troubleshooting performedConfigured DNS and verified that the client can successfully resolve the FortiNAC FQDN. Modified the Windows registry on the client so that ServerIP, LastConnectedServer, and HomeServer all point to the FortiNAC FQDN (fnac.vss.com). Downloaded and installed the Persistent Agent certificate from FortiNAC on the client. Verified network connectivity: Client can successfully ping the FortiNAC server. FortiNAC can successfully ping the client. Verified that FortiNAC is listening on TCP port 4568. Tested TCP connectivity to port 4568 from the client. Captured traffic on FortiNAC using tcpdump.During the packet capture, I observed that the client sends TCP SYN packets to fnac.vss.com:4568, however FortiNAC never replies with a SYN-ACK, causing th
Hello traveler, I'm assuming you've stumbled upon this post after using very specific search terms and are perhaps now at the end of your rope. I hope I can maybe be your last stop. There's a lot that's going to depend on your own setup, such as which cipher suites you're using, your local and remote subnets, etc. I'm not posting this as a definitive guide to get your swanctl.conf perfect - I'm assuming you've already got it to a place where it "should be working". My goal is instead to draw attention to the changes that took my tunnel creation getting totally dropped and ignored by the FortiGate after first contact, to it actually trying to authenticate. It was of course, very simple, but took me hours upon hours to finally get right. The lynchpin was this: Set Remote auth to PSK. Set Local auth to EAP. Make sure Local is set to round 2, otherwise it sends your EAP credentials before it's asked and the Fortigate shrugs it off. Note that on my FortiGate side, I'm no
We’ve had several cases of memory exhaustion with different processes (node, wad, ips), and are using the “set failover-memory enable” setting to cause the Clusters to automatically fail-over when going into conserve mode. (as well as cpu-threshold)While this is fine as it no longer causes prolonged service disruptions, it does leave the clusters in a degraded state: the failed node usually does not recovery by itself and needs to be rebooted in order to recover from the cause of the memory consumption and restore the cluster redundancy.Is there a simple way (e.g. with automation stitches targeting only the currently active or passive node) to automatically trigger a reboot on the now passive node after such a failover event?Or do we need a feature request to allow automatic reboot of the failed node after a failover that was triggered by an internal event (memory, processes, RIB/FIB, cpu)? We probably don’t want to auto-reboot after an external event (link failure/ping-probe fail).
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.