Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Previously i have 5 AP under my WLC9800, then i add some APs and some existing APs is renamed. How Fortinac can sync with the new name and add new APs to the inventory?
Dear community, I am working on a design where the customer wants 3 Fortigate units to be placed in their 3 DC’s and want them to be in HA(A/A or A/P).Is this achievable, as i see the FGCP needs less latency also even if i tweak in the HB counts and Dead timer, what other factors to be considered.Is there an alternative approach that can achieve this or a better other solution that may fit this scenario. Devices: 101 F , 400F
Please tell me.Until recently, the following KB article, which describes a workaround for automatic firmware upgrades after End of Streaming (EoES), was available.However, it now displays "Access Denied." Technical Tip: Disable auto-upgrade for unlicensed FortiGateshttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Disable-auto-upgrade-for-unlicensed-FortiGates/ta-p/414696 Please tell me why it has been made private.
Having an issue I’ve never seen before, I have a ticket open with TAC but figured I’d see if anyone has ever seen this before. As soon as I plug the modem into my Fortigate, the modem crashes constantly and will never get a lock on the ISP signal. As soon as I unplug it and connect a laptop directly to the modem, it is able to establish a lock and I get a public IP. This occurs both if I try to get a public IP using DHCP or if I try to set one of our static IPs. The ISP has tried two of their Router/Modem combo units, as well as we have tried two Arris Surfboards, one of which is known working on a different circuit. Thanks for any help!
After upgrading our FortiGate device from FortiOS version 7.6.6 to 7.6.7, users at the branch lost internet access when the BambiDeep SSL/SSH Inspection profile (Deep Inspection) was used in the firewall rule.Traffic is allowed by the firewall rule, and NAT is working properly. However, HTTPS connections fail when Deep Inspection is enabled.As a temporary solution, we changed the SSL/SSH Inspection profile from BambiDeep (Deep Inspection) to Certificate Inspection, and internet access was immediately restored. The first rule includes certificate inspection, and internet access works fine, but the second rule is the old one and includes “BambiDeep” SSL inspection; after the firmware upgrade, internet access is not working. Also ı tested the problem on new rule by adding BambiDeep SSL inspection ant internet acces is not working. Are they any known issue about 7.6.7 version for tihs topic ?
Hi,For training purposes, I have installed FortiManager 8.0.0 on VMware and FortiGate 8.0.0, but I am encountering the following problem: I have already tried using the SSL certificate whose serial number is specified in the CN field, but the issue still persists. fgfm-allow-vm is enabled
Can we use forticasb solution as standalone without fortigate, sase, or others?
Hey everyone I have been trying to login to our FortiCloud account to register couple of new FortiGates and im unable to because they security codes aren't being sent to our email. Also I did an passwort reset already and then I received an email. But I still dont receive the security code email while trying to login. Any ideas?
Following table outline’s, a set of Dependencies and Key points to be considered and useful with planning a migration of SSL-VPN deployment to IPSEC-VPN based deployment. Below Table is an effort of consolidating the functionalities and capabilities for effective planning of a migration. Content has been extracted from official Fortinet documentations and have put into a table for quick reference. FortiClient Version Dependencies Free Version - up to client Version 7.4.3 1. User Authentication through Local user database - IKEv1 - supported with XAUTH framework* - IKEv2 - Supported with EAP 2. User Authentication through LDAP - IKEv1- supported with XAUTH framework * - IKEv2 - Limitations with the way EAP framework operates EAP-TTLS method has to be used. FortiClient Free version has limitations of changing the EAP method. ** 3. User Authentication through RADIUS - IKEv1 - Supported with XAUTH Framework * - IKEv2 - Supported with EAP-MSCHAPv2
We use 600F and hosted switches and APs in the 7.2.13 system.After testing and TAC confirmation, the 600Fwith7.2 system will discard multicast of tunnel SSIDs.Users cannot use Airplay to discover Apple TV through tunnel SSID,even though I have already configured multicast and IPv4 policies according to KB.We have two suggestions, either use 'set capwap-offload disable' or try upgrading to 7.4 or higher for testing.But we currently do not plan to upgrade to 7.4 because it is not possible to directly configure switch ports such as "loop gurad" and "stp budp guard" on the web management page, and these features are precisely the reasons why we chose Fortinet.I would like to know if Fortinet will fix this bug in FortiiOS7.2?Thanks.
Servus Community,I'm trying to add a FortiGate-VM HA cluster (A-P) running FortiOS 7.4.11 to a FortiManager VM running 7.4.11. Both FortiGate VMs and the FortiManager VM are running in evaluation/trial mode.The cluster itself is healthy and synchronized. Network connectivity is fine and TCP/541 is reachable. I have also enabled:config system global set fgfm-allow-vm enableendWhen I try to add the FortiGate to FortiManager, the device discovery fails with "Probe failed".After enabling FGFM debugging, I noticed that the TLS handshake actually completes successfully. The FortiGate then sends its authentication information including the serial number:serialno=FGVMEVO4T9J2-XXXAt that point FortiManager rejects the session and logs:serial number (FGVMEVO4T9J2-XXX) in 'get' message doesn't match the subject CN (FortiGate) in peer's certificate.I then checked the certificates on both HA members.Both nodes have the same Fortinet_Factory certificate:Subject:CN = FortiGateThe certificate fingerpr
FortiWeb exporting and import ML learnings through API. I need to check the Fortinet Developer Network (FNDN) as to have FortiWeb in a staging environment that has ML enabled and then to export the ML learnings through API and import them on the production FortiWeb again through API will be really powerful thing. The production FortiWeb in this case does not need ML learning enabled actually enabled as maybe limiting on production the learning to fake IP as it is not needed and on Staging to the Staging Jump host or staging subnet or not limiting at all if the network is safely designed.
Hi All,I would like to ask your help about BGP with my scenario.I have FG1 connect with some FG Spoke via MPLS and VPN tunnel. I configured BGP peer for each link with the neighbor is the ip of each link.I want to prevent FG1 advertise route learned from MPLS back to FG2 via VPN tunnel and vice versa. I tried with route map out and comminity and it work for mpls because there are separate mpls for spoke but for vpn tunnel I cant because the VPN tunnel is peering with other Spoke.Could someone advise me the solution for the scenario?
Dear Fortinet Community,I am currently experiencing an issue with a FortiOS upgrade. I have unboxed two newly acquired FortiGate devices (200G and 90G), both of which are not yet license-activated.I attempted to upgrade their firmware to version 7.4.12. The FortiGate 200G was initially running 7.2.11, and I was able to upgrade it to 7.4.11, but the upgrade to 7.4.12 did not succeed. The FortiGate 90G was running 7.4.8, and I was unable to upgrade it to any other version.I am aware that from the 7.4.x branch onward, upgrades are generally limited to patch-level changes. However, in my case, this behavior is not consistent as expected.Any assistance in resolving this issue would be greatly appreciated.Best regards.
I have successfull sync my entra id group to the fortinac, however if i add someone to the group then why the user is not synced in fortinac?Example i add user1 to group IT then if i go to System-Groups-Remote Groups then the member still empty.
Hi, i tried to deploy FortiManager following this doc: https://docs.fortinet.com/document/fortimanager-private-cloud/8.0.0/microsoft-hyper-v-administration-guide/449452/creating-the-virtual-machineAdded a second Hard Disk in “IDE 0” Show me this error, i tried to create Fixed and Dynamically (in differents clear installations) but same error appears even when i have enough space.After this error i cant type in terminal. Any suggestion?
FG-80FでHA構成を構築したが、「config firewall ssh local-key」の状態がPrimaryとSecondaryで異なるのはなんで?? #Primaryconfig firewall ssh local-key edit "Fortinet_SSH_RSA2048" set password ENC AAAAELE8NqYyMBgEhQ7grTfXnpgDb0j1zQrGm/aSSQ1sqReRT3VeDXYDl6GmJTfjifhoYZqMV94zwzYt3BI8Li3/XhV3YaPXywj7lf2VBcKfDSbZbTvJO/8fw2pN25HAxq6I4/cd3ZX90abcxiEdz3oQ1adKVpy/75tzDx95iKJ04o6uTMByeivFhMvKizbm2xAEE1lmMjY3dkVA unset private-key unset public-key set source built-in next #Secondaryconfig firewall ssh local-key edit "Fortinet_SSH_RSA2048" set password ENC AAAAELE8NqYyMBgEhQ7grTfXnpgDb0j1zQrGm/aSSQ1sqReRT3VeDXYDl6GmJTfjifhoYZqMV94zwzYt3BI8Li3/XhVKqNqqBKwoZqTJvhlyp3Zj30tjCJrI4bRFjiacIgfgGLajHp73E3BtG700kjxkxzUMlTFHFg7OPISbONaK1IoYVL17IOcl6QzL6wR9NJMnLVlmMjY3dkVA set private-key "-----BEGIN OPENSSH PRIVATE KEY-----b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABCEPyKnpOC7AuAUn8wkg717AAAAEAAAAAEAAAEXAAAAB3NzaC1yc2EAAAADAQABAAABAQC37dLSRQBZoOb49bsDn/YVhLuGlHio5XLLl9Dzy
I am automatically updating FortiClient for Windows from version 7.4.5 to 7.4.6. On about 50% of the test computers, the installation process stops at: “Stop services.” I also tried doing it manually by running the installer file, but in that case it also gets stuck at “Stop services.” How can I work around this issue?I have updated versions 7.0.x and 7.2.x many times before and never had this problem. Now I’m updating to version 7.4.x for the first time. Has anyone had a similar issue?
I installed FortiClient VPN 7.4.3.1736 (forticlient_vpn_7.4.3.1736_amd64.deb) on Ubuntu 24.04 using the package downloaded from the official Fortinet website.The VPN itself appears to work correctly and I can successfully connect to my VPN gateway.However, every time I start FortiClient VPN, I always receive one or more popup messages reporting conflicts or errors related to NetworkManager. The popup then asks whether I would like to upload the error report.Although the VPN is functional, these error popups appear every time the application starts, which suggests there may be a compatibility issue or a missing component.I have already tried several troubleshooting steps suggested by ChatGPT, but none of them resolved the problem.I was also told that FortiClient VPN 7.4.4 or 7.4.5 might contain fixes for Ubuntu 24.04, but I cannot find these versions on the Fortinet download site.Could anyone please advise:- Is this a known issue with FortiClient VPN 7.4.3 on Ubuntu 24.04?- Are FortiCli
Hello,According to the FortiGate Administration Guide, https://docs.fortinet.com/document/fortigate/8.0.0/administration-guide/155426web filters are applied in this order:URL filter FortiGuard Web Filtering Web content filter Web script filter Antivirus scanningI'm confused about the last step. Antivirus is a separate security profile, not a web filtering feature. Why is it included in the web filtering order? Is this order only relevant when both Web Filter and Antivirus profiles are applied to the same policy?also i see that:…...The FortiGate’s WAD daemon sends the URLs to FortiGuard in real-time for category determination.is that the webfilter process by wad even if it in flow or proxy mode?
Good day,I would like to verify that whether the local network configuration, such as static route, traffic with security files, will stop when deregister the device from Cloud managment, no not.BrgdsLiu Wei
I may have missed this and hope this is not a repost. In the screenshot, we have isolated a custom view of 10 mins and the graph is showing the Bytes in GB. Is this right?
Fortigate Automation Stich is great! If you have a security fabric configured you can automate a lot of stuff. You can automate a process restart if there is high CPU or memory :) Example: High CPU event trigger is already existing but for the memory it is called Conservative mode. You can probably use also Playbooks if FortiAnalyzer is licensed for them or FortiManager to push a CLI script to all firewalls if you have no security fabric configured. Posts from which I got the idea: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-restart-WAD-process-on-a-specific-day-and/ta-p/329282#M8818 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Execute-a-CLI-Script-based-on-High-Memory-using/ta-p/197758 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Execute-a-CLI-script-based-on-high-CPU/ta-p/195103
As someone who played with the Declarative API here are some tips and tricks. The declarative API can be used for General System settings and creating VirtualServer/RealServer/Pool objects in the default root VDOM or even in specific Vdoms for multitenant systems. You can do manual changes with GUI/CLI or REST-API and they are reflected in the Declarative API when you do GET requests. As the documentation for it is not much I am making this article. First see Does FortiADC support Declarative API for VirtualServers? | Community as I have added some useful stuff there as well. Send all specific vdom real servers and server pools in a single declaration as if not you can get an error that the declarative API is trying delete previously send realservers and pools in a previous declaration. You can send virtualserver config in the same declarations as the real server and real server pool but the declaration needs to start with the virtual servers first or you can first send all the real s
I have a printer located in one VLAN and a macOS laptop connected to another VLAN.The printer is connected via Ethernet, while the laptop connects through a FortiAP (Wi-Fi).As both devices are on different VLANs, the laptop fails to automatically discover the printer and displays a “Check Internet Connectivity” message. However, when I manually add the printer’s IP address, it connects successfully. There is a firewall policy to allow traffic between thoses two VLANs (Any services).It appears that the discovery packets (likely mDNS / AirPrint traffic) are not being forwarded between the two VLANs.Can you please help how to solve this issue ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.