Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Fortigate Automation Stich is great! If you have a security fabric configured you can automate a lot of stuff. You can automate a process restart if there is high CPU or memory :) Example: High CPU event trigger is already existing but for the memory it is called Conservative mode. You can probably use also Playbooks if FortiAnalyzer is licensed for them or FortiManager to push a CLI script to all firewalls if you have no security fabric configured. Posts from which I got the idea: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-restart-WAD-process-on-a-specific-day-and/ta-p/329282#M8818 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Execute-a-CLI-Script-based-on-High-Memory-using/ta-p/197758 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Execute-a-CLI-script-based-on-high-CPU/ta-p/195103
As someone who played with the Declarative API here are some tips and tricks. The declarative API can be used for General System settings and creating VirtualServer/RealServer/Pool objects in the default root VDOM or even in specific Vdoms for multitenant systems. You can do manual changes with GUI/CLI or REST-API and they are reflected in the Declarative API when you do GET requests. As the documentation for it is not much I am making this article. First see Does FortiADC support Declarative API for VirtualServers? | Community as I have added some useful stuff there as well. Send all specific vdom real servers and server pools in a single declaration as if not you can get an error that the declarative API is trying delete previously send realservers and pools in a previous declaration. You can send virtualserver config in the same declarations as the real server and real server pool but the declaration needs to start with the virtual servers first or you can first send all the real s
I have a printer located in one VLAN and a macOS laptop connected to another VLAN.The printer is connected via Ethernet, while the laptop connects through a FortiAP (Wi-Fi).As both devices are on different VLANs, the laptop fails to automatically discover the printer and displays a “Check Internet Connectivity” message. However, when I manually add the printer’s IP address, it connects successfully. There is a firewall policy to allow traffic between thoses two VLANs (Any services).It appears that the discovery packets (likely mDNS / AirPrint traffic) are not being forwarded between the two VLANs.Can you please help how to solve this issue ?
Probably the most bizarre IT problem I've ever come across. We are in the process of migrating from Aruba to Fortinet, wired and wireless. One building has now been completely moved to FortiAPs and since day one we've been experiencing random disconnections from our WPA2-Enterprise SSID.The initial symptoms were these: out of the blue, without moving, a device would lose internet connection, showing the 'globe' in the bottom right corner (Windows), claiming to still be connected to the network, but with no internet and with an auto-assigned APIPA address.Having done A LOT of investigation, most of the time with little to no result, I have noticed that clients are very frequently re-associating (often with the same AP), sometimes failing (hence the 'disconnections'). The signal is high, APs are generally a few feet away, it happens on both 2.4 and 5Ghz. We have done a lot of tweaking, including changes recommended by Fortinet Support, which included disabling fast roaming, PMF
how is working this rule executable_windows?? FortiMail Attachment Scan Rules (executable_windows), was catched this file 1.pdf:( detected by Content Filter, filetype application/javascript filename ABC.js in file ABC2 Integration Document - Phase 1.pdf, attachment scan rule: executable_windows). but when downloaded that file to scan by Sandbox, the file was clean result?? Any one had same this problem, and was solved?
after Upgrading From 7.4.12 to 7.6.7 on FGT70G all users with Fortitoken Cloud cannot connect IPSEC VPN IKE2 , the only way is to remove the token.
Hi All,We just opgraded a few sites to FortiOS 7.6.7 on the Gates running as Wireless Controllers (VMs), and then a few FortiAP 23JK (Inroom) to FW 7.6.5.That breaks PoE Passthrough on port3.Downgrading the AP to 7.6.4 again, brings back the PoE passthrough on port3.
Hi, I would like to filter out all the IP from network 192.168.11.0. Could you guide what is value should I input? I try type 192.168.11.* , or 192.168.11.0 or 192.168.11.1-192.168.11.100. no correct result. BrgdsLiu Wei
Hello everyone, I encountered issue where after I reload on of my core switches I lose connection to Access Switch even tho its connected redundantly to my other Core switch. This is diagram of the connection:Network diagramI am running 400F in HA cluster in Active-Passive mode. From both Fortigates I have Fortilink towards my Core switches. The switches are in MCLAG stack with Fortilink split interface disabled. We connected multiple access switches to the Core stack and they all link up correctly, they have been discovered by Switch Controller on 400F and they created the trunk interfaces towards the Core switches. (automatically)When we reload CORE1 for example we lose connection to the access switch for the time the CORE is being reloaded. We did some troubleshooting and were checking STP states on CORE2 and state of the trunks during the reload. We noticed weird thing when connected to CORE2 via CLI while CORE1 was reloading → We ran some diag commands for trunks and the trunk inf
Hello Everyone, I see that /api/declarative is desribed in fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/7a380719-1f54-11ed-9eba-fa163e15d75b/fortiadc-v7.1.0-handbook.pdf The example is for posting system configuration (Simmilar to F5 DO declarative onboarding) but what about Virtual Servers to be created declaratively ? Something like F5 AS3 way to deploy Virtual Servers. Also is there such options for the WAF?
Could you help me with a suggestion?We have a FortiGate HA setup with two ISP links. The customer wants the SSL VPN service to remain available regardless of which ISP link goes down, so that user connectivity is not impacted.One option is to configure SSL VPN access on both ISP connections. However, I have a question regarding routing behavior. If I configure two default routes for WAN1 and WAN2, with WAN1 as the preferred route, what happens when a user connects to the SSL VPN using the public IP address associated with WAN2? edit 1set dst 0.0.0.0/0set gateway <ISP1_GW>set device "wan1"set distance 10nextedit 2set dst 0.0.0.0/0set gateway <ISP2_GW>set device "wan2"set distance 20next Will the SSL VPN connection work correctly, or could there be issues due to the return traffic being routed out through the preferred WAN1 interface instead of WAN2, or it will be return via wan2 maintain symmetry.similarly., customer want to have DNAT polices for internal services to remain
I have a FortiWeb that is used for our QA environment that is not exposed to the internet. I need to be able to manage certificates on it automatically to avoid having to manually replace them every month as the lifecycle shortens. DNS-01 is completely manual so that's out. I tried HTTP-01 using an internal private ACME server, but the Fortiweb rejects the certificate when making the https request to the ACME server because it is signed by our internal CA. Does anyone have a method they are happy with for managing certificates in this situation?
Dear forti users,I would like to ask why the hb_packet_version number is different on a primary and secondary member in a ha cluster?We have 4 cluster and this is the exact same situation in every one. The devices ordered in pair for cluster, so it hardware and config is matching.One cluster a little bit different in that term I tried to add a third member (which have different bios and part-number version number, but every other parameter is also the same). Unfortunaty there very problems in syncing so I removed it from cluster. Can be the source of the hb_packet_version differences on those cluster? The support said the the version numbers must match. Really should match?fortios 7.0.17Thank you
Dear All,I had to configure Site 2 site IPsec tunnel with cisco router with using OSPF protocol so I thought, First do the lab then implement. I was doing lab to configure IPsec tunnel with cisco (CISCO CONFIG (VTI + IPsec + OSPF). but unfortunately Fortigate does not support AES encryption in config phase 1 and 2 setting. on the other side cisco router support AES encryption does not support legacy encryption like DES. Fortigate proposal setting - BR1-FW1 (phase2-interface) # edit BR12BR1BR1-FW1 (BR12BR1) # set proposalnull-md5 null-md5null-sha1 null-sha1null-sha256 null-sha256null-sha384 null-sha384null-sha512 null-sha512des-null des-nulldes-md5 des-md5des-sha1 des-sha1des-sha256 des-sha256des-sha384 des-sha384des-sha512 des-sha512BR1-FW1 (BR12BR1) # set proposalexitcisco router phase 2 proposal ( cisco router setting)BR2(config)#crypto ipsec transform-set MY_TRANSFORM_SET ? ah-md5-hmac AH-HMAC-MD5 transform ah-sha-hmac
Can you help me to find the FortiGate logs?
Hello, I have a 200F fortigate and it's working with 7.6.4 firmware. After I upgraded, I can't see some SSID (WPA2 Personal).But WPA2 Enterprise and Open Guest SSID are working. Why might this happen?Thank you.
Hi,I have been following the KB articles and forum comments for months, but I still don’t see a workable solution for us.We are using a FG90G (FortiOS 7.4.7) with SSL VPN, around 100 LDAP users, FortiClient VPN-only, and FortiToken for MFA. This setup worked very well for many years, but due to OS-related requirements, we now need to move to a new solution.First, we configured IPSec IKEv1 with around 10 of our LDAP users. Some of them work fine, but others experience significant issues, mainly frequent disconnections — approximately 1–2 disconnects per hour. With 100 users, this is not a viable long-term solution. We then tested IKEv2 on a FG80F. It works fine with local users + FortiToken, but with LDAP + FortiToken + FortiClient VPN-only, we receive an EAP failure message. I’m not sure whether there is a proper solution via FortiClient XML configuration that could resolve this, or whether there are other limitations we are facing.A more drastic option would be to replace the FG90G wi
Hello everyone, I just encountered issue while connected Access Switches (specifically 148F and 124G) to our core switch 2048F. In our enviroment we have FGT 120G as perimeter firewall which is connected to 400F that serves as segmentation firewall and also as switch controller. 2048F is main core switch from which I have connected few access switches (148F and 124G). For some strange reason out of 9 switches only 6 came online without issue. The other 3 did not show up. Strangely I can see the ports leds blinking and if I go to FortiSwitch Ports and roll out the ports of the 2048F I can see the ports online with the missing switches serial numbers shown. The 3 missing switches would show up for authorzation I have waited approx. 30+mins. I have tried to add the FortiSwitches manually but they are still shown as “Offline”.Attaching screenshot from FortiSwtich Controler → Managed SwitchesThis is how it looks from Fortiswitch Ports menu (I circled the switches which I added manually and
Hello everybody,I hope you all doing well,I have some question for Forti web a-a setup as this is my first time updating I did my research and found that both nodes will be updated at the same time and there will be down time so is there any way like splitting the HA connection and try to update one of them then swap the traffic or am taking to much risk ? the upgrade path will be from 7.4.8->7.6.2->7.6.7what is the best way to prepare for such kind of operations I have previously worked with FortiGate's but only in Active-Passive clusters.Please advise as this is my first time trying to prepare for this Forti Web updates.Also have anyone tried 7.6.7 in production env ? it seems for me the most stable one and has no CVEs or known issues.Thank you in advance.
Hello everyone,I am preparing to deploy a brand-new FortiGate appliance for a customer and I have a couple of questions regarding the initial setup process.When I connected to the management interface for the first time, I was presented with a screen requiring FortiCare registration before proceeding.My questions are:Should the FortiCare registration be performed using the customer's FortiCare account, or is it acceptable to use our company's FortiCare account as the implementation partner? What is considered best practice? Does the FortiGate license/support contract need to be activated before performing any configuration changes, or can the firewall be fully configured first and the license activated later? What is the recommended procedure for license activation on a new appliance? Where can the license be downloaded or claimed? Is there an official Fortinet process or best-practice guide for onboarding a new FortiGate? I would appreciate any recommendations based on real-world dep
Hi, Please, can you change my Fortinet Community Username to "FortiEng_345"?Bests,
Hi all, I saw a strange issue today when i was setting up a new VPN to a site. The site has one fiber connection and one 4G connection. I set the tunnel up as usual and i see both in the list under VPN. If i check the status och the VPN i only see the “primary” (fiber) connection and no 4G. If i the edit the firewall policy the secondary (4G) connection shows green/up.If i the run diagnose vpn tunnel list i getname=******-SEC ver=2 serial=52 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.10 tun_id6=::10.0.0.10 status=down dst_mtu=0 weight=1name=******-SEC ver=2 serial=54 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.11 tun_id6=::10.0.0.11 status=down dst_mtu=0 weight=1The site is not commissioned yet, hence the primary connection down.
I have several entra group and this group imported to the fortinac, then i add some user to group called IT.When some user IT connect to the network, some of them can connect and some of them cant connect.I do debug for user who can’t connect to the network and i found this message, seem fortinac see this user is member of another group so the policy is not working. 2026-06-11 06:19:23.911 7C:B5:66:6B:D7:F3 - [Policy] HostRecordUtil.getAbstractPolicy() HostRecord DBID: 1456217792417818 Policy ID 1464353948106780 Groups not matched: Required:OR[GroupId: 1464105708654608, GroupType: 1] Provided:[GroupId: 1454135121485837, GroupType: 0, GroupId: 1456635326402562, GroupType: 0]Below is my queris:The GroupID is id from fortinac? How i can know the group name from group id? What is 0 and 1 in the group id?
Hi!Supposedly, setting executing “diagnose vpn ike log filter name” with phase1 name as argument will confine “diagnose debug application ike 255” or “diagnose debug application ike -1” debug logs to only that tunnel. However, when I do it, I see debug logs for all tunnels. How to filter out all the tunnels’ debug logs?Thanks!
Hello guys! Users on a regular IP based firewall policy with no UTM profiles applied to it, are having problems when trying to access Faceboo. On IE the page appears as text only and on Google Chrome, the pictures are blank. If there is no UTM feature applied to this rule, what can be the cause of this behaviour? Thanks in advanced guys!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.