Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi everyone,I’m reaching out because I’m a bit stuck. I've taken the Fortinet NSE 5 - Secure Wireless LAN 7.4 Administrator exam (FCP_FWF_AD-7.4) three times now and haven’t been able to pass it .To prepare, I’ve gone through all the official study materials, watched the training videos, and done practice exams multiple times. I feel like I understand the concepts, but something isn't clicking on the actual exam.For those who have successfully passed, what did you do differently?I have a few specific questions: Exam Content: The exam has a "Pass/Fail" grading system . Does anyone have insight into how the questions are weighted or what the score distribution looks like? Study Strategy: The official course recommends a background in FortiGate and FortiAuthenticator, as well as basic wireless knowledge . I have a foundation there, but what are the "make or break" topics to focus on? Practice Exams: I've been using practice tests, but I saw a recent post mentioning that many exam ques
We recently upgraded from 7.4.4 to 7.4.5.In the meantime, the workstations have also been replaced with Windows 11 and are now Azure AD (Entra ID) Joined instead of AD joinedDeployment at workplaces is done via Intune / Patch my PCWhen I currently do a search in the Forticlient EMS console for an endpoint, I see the endpoint, but also 3 or 4 other endpoints in the search result. These "extra" endpoints can be seen with every searchI only expect to see the one endpoint I'm looking forIs there a duplicate GUID, Hash, or something like that somewhere?
I have a question, maybe for a mod. Thursday morning I started seeing fortibleed posts being flagged and deleted by mods. That was the earliest I ever heard of it.Is there a reason for this? This obviously was very valid and could have helped the fortinet community be one step ahead of the intruders that would abuse it.Why were those posts deleted ? It was our earliest warning to defense.
Good day everyone,I have been trying to look for this or googling it.However, one of our non-production firewalls was hit by this FortiBleed. unfortunatly the logging does not show much.I've gone through the firewall to see what exciting things was done. and I noticed the firewall has 13 administrator accounts now. (It's connected to FortiGate Cloud)Did anyone else experience that accounts was created? and any other things to look out for?Hope you could share some experiences!
Hi , would like to ask if there is a way to edit interface name on fortigate. In particular in configuration of 4 fortigates with High Availability, where one is master other slaves. If in this configuration the method used to change interface name is to download backup configuration file of master FW edit the configuration file and load it with interface name changes, would this be a correct approach? Or maybe something should be done also on the slaves configuration? Or the best way would be to delate interface and re do it with the new name? Many thanks!
FortiGate 90G (FortiOS 7.4.12) - FortiClient IPsec VPN (7.4.3) Times Out, No UDP 500/4500 Traffic SeenI am configuring a remote-access IPsec VPN using the FortiClient Dialup VPN Wizard on a FortiGate 90G running FortiOS 7.4.12.Environment: WAN Interface (x1): 184.180.43.35/28 Gateway: 184.180.43.33 Dynamic DNS/FQDN: vpn2.dhansol.com FortiClient VPN Version: 7.4.3.4726 Testing from home Internet (external network) VPN Configuration: IKE Version 1 Aggressive Mode XAuth enabled User Group: VPN_ONSITE_USERS Client IP Pool: 10.10.70.10 - 10.10.70.99 Split Tunnel enabled VPN Policy created by wizard: Source Interface: DHN-ONSITE Destination Interface: VPN_VLAN50 Destination Subnet: 10.10.50.0/24 Phase1 Configuration: type dynamic interface x1 mode aggressive mode-cfg enable xauthtype auto authusrgrp VPN_ONSITE_USERS Verification Performed: WAN connectivity verified. FortiGate can ping Internet. vpn2.dhansol.com resolves correctly to 184.180.43.
Hi everyone,I'm trying to change the redirect IP address of the authentication portal on a FortiGate running version 7.4.12.I currently have a captive portal that intercepts user traffic and authenticates users via SAML with Entra ID.The issue is that after changing the IP address under: FGT_1 (auth-portal) # showconfig firewall auth-portal set portal-addr "10.0.0.1:1003"endand, of course, updating the SAML configuration on both the FortiGate and Entra ID, when a user tries to log in using the new IP address (10.2.0.1), the FortiGate redirects them to: https://10.2.0.1:1003/fgtauthHowever, the connection just times out, as if port 1003 isn't listening.If I switch everything back to the original IP address, the authentication works normally again.I inherited this firewall already configured this way, so I'm not sure if there's another setting I should be checking.Has anyone experienced this before or knows what else I should look at?Thanks in advance!
Hi all,I’m troubleshooting a remote access IPsec issue on a FortiGate 200F running FortiOS 7.4.12 and wanted to see if anyone else has run into something similar.When NAT-T is enabled, remote users get noticeable packet loss / stalls over the tunnel during normal traffic — pings, file transfers, throughput tests, that kind of thing. When NAT-T is disabled, it gets a lot better.A few things I’ve already confirmed:the tunnel comes up fine the issue is reproducible when NAT-T is enabled the issue improves significantly when NAT-T is disabled I tested with NPU offload both enabled and disabled with offload enabled, tunnel error counters were higher on the problematic tunnel with offload disabled, those RX errors were much lower or zero in my captures, but the user-visible stalls still weren’t fully explained by the lower-level counters PDQ snapshots looked balanced during testing HPE dropping stayed at 0 in the snapshots I collected anomaly-drop output was empty we also contacted our ISP a
Fortigate 40F firewall upgrade firmware 7.2.12 to 7.4.12 then firewall goes to memory conserve mode issue how to reslove
WAN1 STOPPED WORKING- I have two FortiGate 60F setups as stack (HA1 and HA2)- I have Juniper router - I have a Rogers modem with 2 public IP 187.x.x.x/30 and 184.x.x.x/30- link 1: Rogers modem port1 > FG60F WAN1- link 2: Rogers modem port2 > Juniper router- I also have a 2nd ISP (TELUS) for failover- WAN1 link shows Green UP in the GUI; WAN1 led light is blinking green/yellowProblem: WAN1 is not pulling the public ip whether in static or DHCPTS:- reboot the modem, connect my laptop with correct IP details used in FG60F (SM, GW and IP) = WORKING- leave Juniper plugged in = WORKING- turned off the modem for 10mins, removed the laptop, reconnected the FG60F = FAILED- Juniper still working- Replaced modem, reprovisioned and performed laptop testing again and still working. - Tried disconnecting Juniper from Rogers modem and leave only FG60F connected = FAILED- Internet works because of WAN2 (TELUS)Question:1. Why WAN1 not pulling the public IP? why there is no internet from WAN1? 2.
Based on the news by SOC Radar I have a customer asking what should he do. In spite of the news I was not able to find any, let´s call it official, comment from Fortinet.I had the customer to open a ticket.Has anyone any experience or knowledge of this Fortibleed?Thanks
How to push Fortinac persistent agent to all Windows PCs using group policy on Fortinac 7.6 and also disable windows popup for credentials using registry keys ?
I passed my exam 7 days ago. I made mistakes with the registered email on PearsonVUE. I know know that was the problem. I should have used my company's email when I registered. I contacted Fortinet support to associate my FortiID but no response.https://ftnt.freshdesk.com/support/solutions/articles/73000524133 I contacted PearsonVUE, but they asked me to contact Fortinet. How? How can I reach Fortinet training support?They said I can create a ticket with them on the above link. But nobody is monitoring that ticketing system. Just wait for another 2-3 weeks? I need to provide it to my company. :(
HI everyone i am deploying Hub and Spoke ADVPN BGP over Loopback Topology in Real Environemnt . After Deploy full configuration follow by Fortinett Documents i can see Spoke A can talk to Hub and Spoke B can talk to Hub but when Spoke A try to Talk to Spoke B it create Shortcut Tunnel but after shortcut they cannot talk to Each other... When i check in Spoke A routes for Spoke B it showing next hope Underlay/WAN not Overlay/VPN. same at Spoke B for Spoke A . can anyone know that in BGP Over loopback what could be the issue that Spoke to Spoke cannot send traffic via Overlay after shortcut?Port1 and Port2 are WAN Underlay Ports .Spoke-A-Dent # get router info routing-table allCodes: K - kernel, C - connected, S - static, R - RIP, B - BGPO - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area* - candidate defaultRouting table for
Hello everyone!I have a question: What is the difference between Fortinet Single Sign-On (FSSO) and Radius Single Sign-On (RSSO)? What are the biggest differences between them? In what situations should I use FSSO and RSSO? Can I combine both?If I want to use them for user authentication during VPN connections, which one is best?Thank you!
Hi Fortinet team,So, we are upgrading our VPN to the latest software version, and we are changing from SSL VPN to IPSEC VPN, and we are thinking to deploy it via Intune, but we have encountered failures when trying to install the package.We follow the next steps:Changed the encrypted Preshared Key inside the conf file for the actual Preshared key Create Installer.ps1 with the following command: Start-Process -FilePath "C:\Program Files\Fortinet\FortiClient\FCConfig.exe" -ArgumentList "-m vpn -f <"$ConfigFile"> -o import -i 1 -p <"ConfigPassword"> -Wait Inside Intune we set up detection rule for the reg key: “HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\IPSec\Tunnels\IPSEC VPN” The weird part is that if we try running the Installer.ps1 locally/manually it works perfectly fine and it imports the conf file without issue but if we runs it via Intune, it directly says Installation Failed Can you please help us?
Can we use third party authenticator like google auth in Fortigate?
Currently using FortiToken for MFA on our fleet of gates and been looking at switching over to SAML via Entra to take advantage of conditional access policies + our ITDR against the accounts.Looking for other experiences to see if people are currently doing this and if they are any known issues or drawbacks to this change.
I try to build a new box of model 601F. Firstly, when i tried to manual upload license, it showed upload fail. please help
Hello, for the last two weeks I have been trying to connect FCEMS (7.4.4) to Intune to deploy ztna certificate to Android devices (Samsung S25, Android 16, work profile). I have ran into a brick wall of device being stuck in „MDM Deployment Status Pending“ and the intune polocy to deploy SCEP certificate having error without any further details. I have been following this guide Provisioning ZTNA certificates to FortiClient mobile using Intune | FortiClient 7.4.0 | Fortinet Document LibraryI walked through it multiple times with the same result. Maybe I am missing something? Can someone please help, if you have such setup in working order? :) I have configured the app with correct permisisons in intune and set up MDM integration in FCEMS. Have user with correct licences.In intune app configuration policies have set up:Go to Apps > App configuration policies. Create a new policy.Add key-value pairs. The intune_device_id key is mandatory. All other keys are optional
Hello Team,We are currently attempting to deploy FortiManager 7.6.6 on a Nutanix-hosted virtual machine by following the official Fortinet documentation:https://docs.fortinet.com/document/fortimanager-private-cloud/7.6.0/nutanix-administration-guide/118677/deploying-fortimanager-on-nutanixDeployment DetailsPlatform: Nutanix VM Image Used: FortiManager 7.6.6 (KVM qcow2 image) Reference Guide: As mentioned aboveIssue DescriptionWe have followed all the steps from the documentation and successfully deployed the VM. However, the FortiManager appliance does not boot correctly.From our observations (see attached screenshots), it appears that:The operating system present on the attached disk is not loading/booting properly. The system seems stuck during the boot process or fails to initialize.ObservationsThe qcow2 image used is the latest recommended version for FortiManager (7.6.6). The deployment steps were executed as per the official guide. No obvious configuration errors were identified
Dear Community,I have cluster on siteA with primary and secondary. Their ha interface connected with a direct cable. Also there are x1 ports in the hbdev configuration via a switch. Now I would like to add a third fortigate to the cluster but this is on siteB. The x1 ports are connected via switch on L2 between siteA and siteB. While the hb interfaces are only connected on siteA devices (primary and secondary) with direct cable without switch. Because the hbdv setting mirroring between the primary and secondary units, I think the x1 should be the higher priority in the hbdv setting. But what should I do with the dircet ha config? Should I have to remove it? Or should it remain in the hbdev config with lower priority as a “backup between devices on siteA”? In this last case the remote siteB new fortigate (subordinate secondary) will see its hb interface as permanent dead, and will ignore it?thank you
Can we use wildcard certificate for persistent agent? I have this log from the client when the Persisten Agent using valid wildcard certificate.Wildcard cert!Peername “nac.mydomain.com” matches wilcard “*.mydomain.com”Refusing to connect to trust_DISTRUST nac.mydomain.com|*.mydomain.comConnection failed! 1SslStreamtransport::disconnect()SslStreamtransport::disconnect() NOT joined rxBoostThread because this IS the receive threadSslStreamtransport::disconnect() joined threads, free-ing the SSL State
When configuring a FortiClient EMS server (v.7.4.1b1872) on Linux for Administrator SAML SSO with Entra/Azure it works if I use the default SP Address (<FQDN>), but we'll be locking down port 443 from external access and I would like to use 10443 for the SAML SSO. When configured the same way adding 10443 per the small blurb of instructions (<FQDN>:10443) it returns an EMS 404 error stating "The requested URL was not found on this server." If I reconfigure that same SAML entry to just the <FQDN>, updating the appropriate fields and certificate, it works. I have confirmed that port 10443 is open. The URL in the browser looks correct for the ACS link (https://<FQDN>:10443/saml/default/<UniqueKey>/acs). I don't see any issues off hand, and MS does report a successful log in. Attempting to log in as a unapproved user does result in the expected O365 "you do not have permission to log in" page. The server has been rebooted with the desired settings in
I need A support to get a fortigate VM Evaluation license for FFUMEUREFUFF9554
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.