User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We upgraded the firewalls from 7.4.2 to 7.6.6 and accessing anything internally over the forticlient connection is very slow. Prior to the upgrade everything was good. I have tried changing some of the tcp-mss-send/receive values but nothing seems to work. Anyone have any suggestions on what to look at next other than upgrading to 7.6.7?
Hi Team,I am facing an issue with password expiration on FortiGate.Environment:FortiGate with local users Password policy applied to the users (password expiration enabled) FortiClient on Windows and AndroidIssue:After applying a password policy and allowing the user's password to expire:Windows PC: When the user connects using FortiClient, they are prompted to change their expired password, and the password change works successfully. Android (FortiClient): There is no option or prompt to change the expired password. The login simply fails because the password has expired, leaving the user with no way to update it from the Android device. Is this expected behavior or a known limitation of FortiClient for Android?Screenshot of password policy: Environment:FortiGate Model: 1101E FortiOS Version: v7.4.11 build2878 (Mature) FortiClient Android Version: 7.4.6.0218
Does anyone know if the new exam is using Enteroruse Firewall Admin questions?NSE library has enterprise firewall admin and sdwan modules but nothing that lines up with name Network security architect or is it a whole new exam with both modules combined?
Hello.First, I apologize for my imperfect English. Recently, I started learning about networking using FortiGate.When running FortiOS v7.6.6, I configured IKEv2/IPsec VPN on a FortiGate 60F.At that time, the VPN connection worked correctly.However, after upgrading the FortiGate to FortiOS v7.6.7, the VPN connection stopped working.No VPN configuration changes were made between the upgrade and the failure.Based on the FortiGate logs and packet captures taken with Wireshark,I suspect that during the certificate authentication process,the intermediate certificate that should be sent from the server to the client is no longer being transmitted. After rolling back to FortiOS v7.6.6, the VPN connection started working again.I also confirmed that the VPN connection works on FortiOS v7.6.7when the R12 intermediate certificate is manually imported into Windows.This seems to indicate that the client is not receiving the intermediate certificate from the FortiGate during authentication.The follow
Where I can find click house schema file for FortiAnalyzer ?According to docs.fortinet.com:Each log table stored in an SQL database contains log fields that can be used in datasets.You can view a full list of the fields available for each log type in the FortiAnalyzer ClickHouse Schema file available from the FortiCloud Support page.But I cannot find it.
Hi All Community expert, Good day, looking for some insight that how do you guys reach Fortinet support?Background: FortiSASE have POP related issue while trying call Fortinet supportChallenges:Try to reach support through existing email but no one response Called with ticket number provided, after forward call, waited around 30minutes, No on pickup Try another under emergency impact, still no one pickup (Waited 15~ 25 minutes)Since the FSASE infra being handle by Fortinet, any way as user we can self help ourselves when such issue happen. Ticket (XXXX6250) Feeling helpless right now. Do look for better insight from the community on this.
We have one FG100E that is nearing end of product support coverage and is arranging for tech refresh.What happens if we cannot replace the firewall in time ?especially the online services ?Support Type Support Level FortiGuard IPS Service Web/Online FortiGuard URL, DNS & Video Filtering Service Web/Online FortiGuard AntiSpam Web/Online
Dears,Now i have Alcatel wireless controller omnivista 2500 and i want to make all users are connecting to ssid to authenticate from radius server on fortinac so i need to know what are the steps to do this and kindly be noted that fortinac is integrated successfully with ldap so i need to take the authentication request from radius and forward it to ldap. So i need to know should i add the omnivista to Fortinac and what are the steps should i follow to configure local radius server correctly.
Hi everyone,I’m currently taking the NSE 1 – Cybersecurity training.I have completed Cybersecurity and Cloud Fundamentals 1.0, all modules are marked Done, including the Module 10 quiz, and I have received the Course Completion Certificate.However, my NSE 1 Certification status still shows “In Progress”.The certification page says I need to pass the NSE 1 online exam, but I don’t see any separate final exam in the course. The last activity is only the Module 10 quiz.Is this expected with the new training platform, or am I missing a step?Has anyone experienced the same issue? Any advice would be appreciated. Thank you!
Google came out with this great convenient feature that allows users to just play a game after a search.i.e. : searching Google for "snake game" will bring up an easily playable game right there in the search results. See attached photo. Is there a way for the Firewall Web Filtering to block this? Another option I had was to through out an AdBlocker extension and specifically block that element on all the student computers but they could just open another browser and it would be way too much work.
Technical Guide: Two Approaches to Blocking Google Arcade & Interactive Doodle GamesAdministrators frequently find that standard web filter categories fail to block Google's built-in browser games (like Solitaire, Snake, Popcorn, or Champion Island) because they are served directly from core Google domains. Below are two proven ways to successfully block these games depending on your current Web Filter architecture.Method 1: Global Wildcard Block (Fastest & Universal)If your organization permits the use of wildcard URL patterns on your Web Filter profiles, this is the most efficient method. It uses broad wildcard matching to catch every current and future game variant instantly.Configuration CLI:config webfilter urlfilteredit <your_url_filter_table_id>config entriesedit 0set url "*google.com/fbx*"set type wildcardset action blocknextedit 0set url "*google.com/logos*"set type wildcardset action blocknextendnextendWhy this works: /fbx* kills all standard overlay arcade game
Hi, I got this error when trying to SSH from a specific server: sshd -1 output shows,“This ip x.x.x.x is not blockedfd 7 is not O_NONBLOCK…Did not receive identification string from x.x.x.x” Any KBs related to this? Thank you!
Hey since Last Sunday we have been using 700G in a HA Cluster in our Environment.I do Not have a single Policy using IPS but the CPU Spikes extremly high because of this. After a restart using "Diagnose Test application ipsmonitor 99" the CPU goes down.Sadly we already see connections impacted by this issue. Websites and Services in out DMZ are extreme slow or timeouts.I already opened a Ticket at FortinetBut maybe there is Somebody with the Same issue and a solution for this topic?Edith: using Firmware 7.6.6
There is an analyzer with version 7.0.13. When you search fortigate log for the last 7 days on Analyzer, pages of logs come up. However, there is no total log count for the last 7 days anywhere on the page. How can I see the total number of traffic logs in any interval I enter.
Hello all. Looking for anybody who has run into this issue and may be able to provide guidance.We have a pair of FGT 70Gs running 7.4.9 connected to a stack of 148F FSWs running 7.2.5. This is our standard stack and we run it at dozens of sites.We have NAC enabled via the built in managed FSW setting (not FortiNAC). We add devices via NAC policies individually and via wildcard filters such as Vendor name and device type (Example: IP Phone). Our switchports are configured in NAC mode and based on the device that plugs in, the dynamic VLAN will assign to what's configured in the NAC policy.Anywhere from a couple to a few times a day, users with devices plugged into these NAC-mode switchports say their devices are doing network hard down, and then coming back up moments to minutes later. I checked logs and am seeing that the entire NAC MAC address cache appears to be deleted out and then added back, all at once but separated by short periods of time. This aligns exactly with when the issu
We've moved a bunch of PC's from Anyconnect to Fortclient which has gone well however the big thing we've noticed is that if a host is downloading/streaming something then the Forticlient is affected quite badly.So for example we use Forticlient to connect to our office and then RDP to a desktop machine on a private IP 192.168.1.1 for example. If I do a constant ping to 192.168.1.1 then the responses are fine. If I download anything then the response times climb so high as to be unuseable. It's only traffic to the 192.168.1.0/24 network which goes across the SSL-VPN. Any other traffic uses the home internet circuit gateway.Normally I'd be 'yea, this is fine, you are using all the bandwidth' but this doesn't happen with Anyconnect at all. It's like the Forticlient isn't splitting off some bandwidth to stay stable where as Anyconnect is?Is there a way to make Forticlient more stable if the host is using banwidth. I feel silly asking it as instintively I would say no of course not, tell y
Hey guys, Please bear with me here, as I work way more with couple other vendors, though I would say Im fairly verse when it comes to Fortinet : - ). Anyway, here is the scenario. Customer purchased 2 brand new 200F firewalls and we have really odd problem and my colleague (who btw is real Fortigate guru) are having heck of a time trying to fix this problem. Essentially, even if single person is connected to ssl vpn, responses to anything internal are real slow and ping times can go up to 2000 seconds. We tried failover, no luck, disabled assic offload for ssl vpn rule, tested multiple barebone forticlient versions (no luck), enabled DTLS tunnel option, same issue.Now, there are only maybe 6-7 security rules configured, so its super basic. We even have TAC case open for this for about a week, but since they cant replicate it, guy suggested to try reboot the current primary firewall. I have no clue if that will help, as it has been up for only 35 days, but it would need to be sched
FortiClient EMS Server 7.4.7Endpoint email alerts have been configured.Emails are sent to a mailbox, automatically generating a ticket for the Service Desk.I have a Test VM for testing FortiClient settings. It is inconvenient to have a ticket created every time I for example disconnect the FortiClient for testing purposes.Is it possible to exclude a single endpoint from all email notifications?Regards
Hi,What's the deal with the free version of the VPN agent? According to the documentation, it should be 7.4.3.4799, but only version 7.4.3.4726 is available.What's the deal?
Hi everyone,got a new 200G model, used the same firmware as on the 100F, took the config backup of the old device, updated the header in the config and used an usb-device to transfer it to the new device.After the reboot, no login is possible, wheather via GUI or console. Also the reset-button does not work (even after reboot). If I remove the admin-users from the config, it's the same https://speedtest.vet/ .So basically you have to wipe the image and reload it via TFTP, which is of course a pain.Anybody had similar issues? Does anybody know how to resolve the issue? Thanks!
This article describes what is the reason email got rejected by FortiMail, with the classifier showing as 'Access Control-Reject' in the history log.
Hello,We have an environment consisting of 100 endpoints. Approximately 70% of the endpoints are located in an air-gapped environment. To manage these endpoints, I have deployed FortiClient EMS version 7.4.7 in air-gapped mode, as there is no Internet connectivity within this network.The remaining 30% of the endpoints are located in a separate Internet-facing environment. These endpoints do not have connectivity to the air-gapped network, and similarly, the endpoints in the air-gapped network cannot communicate with the Internet-facing environment.Currently we have deployed FortiEMS in air-gap mode and air-gap connected endpoints are already connected. Now facing issue to connect internet facing endpoints.In this scenario, how can I manage the Internet-facing endpoints using FortiClient EMS?Additionally, is it possible to deploy a second FortiClient EMS instance under the same subscription to manage these endpoints separately?Environment Details:FortiClient EMS Version: 7.4.7 Total End
I'm trying to diagnose a FortiClient VPN issue with an IPsec vpn IKE v2. I have the forticlient vpn installed on my iphone 16, my coworker has it installed on his iphone 15, and its installed on a clients iphone 14. My coworker and I have been able to successfully connect to the vpn but the iphone 14 user gets an error -vpn credentials are invalid. I have reentered her username/password multiple times, i've verified the PSK and all other configurations are correct, and have attempted the connection over wifi and cellular on her device. I used the same wifi on my device to successfully connect. I also used her credentials on my device to successfully login. iOS and FortiClient are both up to date. The FortiGate logs reveal that its failing to negotiate phase 1.
Good morning, everyone. I have the following problem, but first, let me describe the scenario. I have a virtual FortiGate 8.0 installed (OVF file imported into VMware Workstation 25h2). It's already installed and configured correctly with web access. The issue arises when I try to install FortiManager, the same version as the FortiGate. The OVF file is available in the VM section of the Fortinet support page, and I can download and import it without problems. The problem starts when I launch the VM; it gets stuck in an infinite loop between 'vmlinuz' and then 'extracting the GZ file,' and it never gives me the login option. Can you help me with this?
Hello everyone, I am a student working on my final year thesis about "implementing sandboxing technology for proactive security of incoming network traffic". I would like to test FortiSandbox in my lab environment( ÈVE NG ), but I cannot find the image available for download. Could you please guide me on how to get access to it for academic purposes? I've already checked: · The official support portal· The Fortinet document library· Various resource sections Is there a specific academic program or evaluation license available for students? Any information about how students can access Fortinet technologies for research would be incredibly helpful for my work. Thank you in advance for your support! Best regards,HODOME Kokou AchilleIAI-TogoTOGO
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.