User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi, I'm using FortiClient VPN for conneticting to a customer's VPN but I can't receive any bytes: Same username and password on other PC work and every username and password on my PC don't work.I tried disabling/closing: firewall, antivirus, teams, onedrive, ...I have the default settings of Windows 11 and I'm using FortiClient 7.0.7.0345.VPN configuration is correct. Could someone help me please? Thanks in advanceFrancescoMAS Consulting
Hi..My FGT Hub and Spoke run under verrsion 7.2.11, the hub act as SSL VPN and connection from spoke to hub using ADVPN.As we know in new version of Fortigate then SSL VPN is retired and replaced by IPSEC VPN. Witht his condition i want to know :What latest version where SSL VPN still supported? If hub and spoke have different OS version, this is compatible?
Hello All Kindly i need admin guide for deploying SPA FortiSASE with 2 FortiGate devices HA active - passive So please advice with the steps and guide Thanks
so, i have existing ICX8200’s in this infrastructure and older ICX6450’s. we’re replacing the 6450’s with 124F-FPOE switches, but i’m having trouble getting the 124’s to talk to the 8200’s. the 124’s are running 8.0.0(47). the 124’s will uplink to the 6450’s with no trouble, but will not pass traffic to/from the 8200’s. the link and activity lights come on, and in the gui the link and speed/duplex are correct, but both switches claim they are sending but not receiving. neither have errors in the log. so,fn124 → icx6450 → icx8200 works finefn124 → icx8200 link but no stp/lldp/trafficno cdp/fdp/lldp neighbors listed on that port when the 8200 is plugged into the fortinet. on either switch. when the 6450 is plugged in the middle everybody sees the directly connected neighbors. i’ve tried this with 2 separate icx8200’s and 2 separate fn124f-fpoe’s. i’ve pulled one set and experienced the same behavior on my bench using fiber patch cables. the ports on both ends are set to native
Hi FGT adminsFortiOS 7.4.12. All HTTPS sited are blocked with error: “SSL connection is blocked due to unable to retrieve server's certificate”.In the latest FOS updates the FGT probes the certificate itself (self generated traffic) before allowing or denying the traffic, right.I checked this tech tip and I know we can change cert-probe-failure as workaround.But I my case I know the issue is caused by my WAN interface having one primary private IP and one public IP as secondary IP (ISP constraint). I had to change source-ip for many services like DNS and FortiGuard in order to make them reachable. But can’t find similar source-ip for certificate probe traffic.I know one other workaround is to make public IP primary and private IP secondary but I prefer avoid this change in case there is “source-ip” customization for cert probe.Any useful info would be appreciated.
Hello,I've been working on setting up an IPsec VPN on our FG200E after upgrading to FortiOS 7.6.7, mainly so we can take advantage of DNS suffix assignment from the firewall.Our environment has two separate Active Directory domains in a trust relationship: old-domain and new-domain. In the config vpn ipsec phase1-interface configuration, I've defined DNS suffixes for both domains and configured the DNS servers with the old-domain DNS first and the new-domain DNS second.Everything seems to be working correctly for resources in new-domain, but for anything in old-domain, I have to use the full FQDN to access it. This creates a major issue because some of our internal applications reference hosts by short name rather than a fully qualified DNS name.We're currently using Cisco AnyConnect, and it works perfectly—users can access shares and applications using just the host name without any DNS resolution issues.I've already opened a ticket with Fortinet, but I wanted to check if anyone else
Hello, we have several Fortgates, swites and AP. But one of my former collegues. has not written down which Contract Registration Code was used for which device. Is there a way to check which Contract Registration Code was used on a device. w.k.r.Patrick
Hi allI have updated to FortiOS 7.2.3.And then I realized following bad configuration.----FG60F # config system email-serverFG60F (email-server) ## set reply-to noreply@example.comcommand parse error before 'reply-to'Command fail. Return code -61FG60F (email-server) #----By this Document, I can set 'reply-to'.http://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/526019/email-alertssomeone have how to config 'reply-to' in FortiOS 7.2.3?thanks.
Fortigate can block the Tailscale application with policy and application control; it will block both inbound Tailscale sessions and outbound Tailscale sessions. Is it possible to block only inbound Tailscale sessions, and still allow outbound Tailscale sessions on the firewall?
Hello there,I want to update FortiClient EMS signature manually. FortiClient EMS 7.4.7. My deployment mode is airgap. I have downloaded the service updates from support.fortinet.com.Now how I can insert it to EMS server.Kindly help me on this.
Since last week we experiencing a lot of problems with Windows updates (mostly Windows 11, but there was one Windows 10 among them as well), specifically KB5040442. On about 10% of our Windows clients the update would start and go until 96% and stay there for 10-60 minutes, and then after a restart Windows would tell us that something did go wrong and it would reverse the update. This would require multiple restarts and anything in the order of 2-10h. The usual information sources did not reveal anything unusual with this update round, so it had to be some uncommon conditions here. When Windows was back online, it would sometimes (!) show an error code 0x800f0922, oftenly nothing, and on next restart it would try to install it again (and our employees losing again 4-10h with a working computer). First remedy, as described in the error code was to increase the size of the recovery partition to at least 250MB, but that helped only on one computer. No other things related to the code
Hello community, We are currently running Forti EMS Cloud 7.4.3 with several endpoint versions, mainly FortiClient 7.2.11 y 7.0.X on Windows 11 devices.We are working together with the customer and Microsoft support to troubleshoot an issue where Windows Update downloads do not complete and the update process becomes extremely slow or stuck. Issue Description:When endpoints have a FortiClient profile with Sandbox enabled, Windows Update shows the following symptoms:Update download does not completeIf we change the endpoint policy to Default profile (no Sandbox), the Windows Update process completes successfully. Tests Performed To verify this behavior, we performed the following tests: Disabled Sandbox profile → Windows Update completes normallyRe-enabled Sandbox profile → Windows Update fails or hangsWe tested with multiple Windows Update components excluded:TrustedInstaller.exeTiWorker.exe (Windows Modules Installer Worker)DISM.exeC:\Windows\WinSxS\C:\Windows
I have integrated Darktrace Syslog with FortiAnalyzer. When Darktrace sends logs in JSON format, the log messages are truncated in FortiAnalyzer. However, when I configure Darktrace to send logs in CEF format, the Message field in FortiAnalyzer is empty.Could you please advise on the cause of this behavior and recommend the appropriate configuration to ensure the complete log message is displayed in FortiAnalyzer?
Hi,I recently implemented FPAM and I have a strange behavior with all the web launching sessions.The FPAM is in a subnet dedicated.My pc is on another subnet and the internal services and external(obviously) are on other subnets.In the middle there’s a Fortigate.I have also an ACL for deny the traffic to the internal services from my pc, so I must traverse the FPAM to reach the services.I launch multiple web launching sessions to multiple sites internal and external and after so much time, I can’t define how much, I receive some ERR_CONNECTION_TIMED_OUT from random sites.If I try to reopen the site, I can no longer access it; I have to wait a long time before it starts working again.From what I've gathered so far, connections are more stable if I use the site's IP address directly instead of the FQDN, but sometimes are slowly(But at least they don't time out.)When I have the reset, the FPAM is capable of ping and resolve the destination internal or external site, seems to be a problem
Hi All Community member and expert. Do want to request whether you guys encounter or experience issue as below: Incident that when request change of FortiSASE POP, the Fortinet engineer change without validating the settings (Which require deletion of Geo Fencing), which have configuration dependencies causing our specific POP down including whole SAML service down in FortiSASE on production. (Ticket 11464065) While providing feedback on same ticket (11464065), the related Fortinet Manager promise to improve the procedure on next time check to check on the Geo Fencing and Fortinet engineer had log a bug in ticket (11398499) that will check whether there is existing Geo Fencing if customer request POP changes before implement. We trusted Fortinet on that at the moment regarding the fix and procedure improvement.Due to we have different Business Unit, we have another FortiSASE need request to change POP, then same issue happen causing production impact, further reported in ticket (114276
Hi,after upgrading our FortiGate HA cluster from 7.4.12 to 7.6.7, we noticed a significant increase in the daily log volume sent to FortiAnalyzer.Environment:FortiGate: 2x FG-200F in HAFortiOS: 7.6.7FortiAnalyzer: VM, currently 8.0.0Logging: FortiAnalyzerBefore the upgrade, our daily log volume was normally below the licensed GB/day limit (15 GB). After the upgrade, the daily log rate increased by approximately 8–10 GB per business day, without any intentional configuration changes on the FortiGate side.For a normal business day we now see approximately: Application Control log: ~10 GB/day, Traffic log: ~9 GB/dayNo firewall policies were intentionally changed, and we did not enable any additional logging options manually after the upgrade.We have already checked the following:- no known configuration change was made on the FortiGate before/after the upgrade- application Control logging is enabled as before- SSL inspection is enabled- FortiAnalyzer is receiving logs correctly- The inc
Hi,I’m trying to change default admin account, but after rename command in the cli I have error:fml (admin) # rename admin to admin_disabledCommand failed(-37). Error string:Is not possible to change this account on fortimail?
I've been experiencing a wide array of issues with FNAC lately.I won't get into them all, but one that is really irking me is when I browse to the FNAC home page via HTTPS, I login successfully, I click on any navigation item (i.e Inventory) and then I immediately lose connectivity to the UI and am not able to reconnect. Only via a reboot is the page restored.I also lose SSH access. The only remote access that remains is via console.We are in HA and that does not invoke either. FNAC still responds to ping so presentably that is why.Kinda getting sick of it.
I’m having issues establishing a connection when IPv6 is enabled on the Windows client’s Wi‑Fi interface. As soon as I activate IPv6, the connection to the Fortigate fails. Has anyone experienced this or knows what might be causing it?If you want it more technical or more detailed, I can refine it.
Regarding a FortiGate system configured in an active/standby high-availability (HA) setup,we initially set the Device Priority value for Unit 1 to 200 and the Device Priority value for Unit 2 to 128 (the default).However, even though we hadn’t made any changes, the priority value on the standby unit had changed to 200, the same as the active unit. We attempted to manually change the priority value on the standby unit back to its original value of 128, but an error message stating “The entered value is incorrect” appeared, and we were unable to make the change.The system recognizes the active/standby configuration and no abnormalities are apparent in the HA setup, but what is the cause and how should we proceed?
Working on a branch office to HQ redundant vpn setup. Each location has 2 ISPs and I had planned on following this: Manual redundant VPN configuration | FortiGate / FortiOS 8.0.0 | Fortinet Document Library just using 2 tunnels (primary ISP to primary iSP, backup ISP to backup ISP) with static routes to force the backup tunnel over the secondary WAN at each location. Is there any drawback to this approach? I had considered using SD-WAN for the vpn traffic or possibly BGP but wasn’t sure if either offered a significant advantage in this situation. The branch office has a single /23 network and HQ has only 3 or 4 networks that need to be accessible. And the request is for the tunnels to utilize ISP1 as the primary when available.
Good day, everyone.I have been experiencing intermittent SPF false positives in **FortiMail 8.0.0**. In some cases, FortiMail reports that the sender's domain does not have an SPF record. However, after verifying the domain manually using both our internal DNS servers and public DNS servers, the SPF record is available and resolves correctly.I would like to know if there is any configuration or best practice that could help reduce these false positives. For example:* Is it possible to increase the DNS query timeout used by FortiMail?* Is it possible to adjust or reduce the DNS cache timeout?* Are there any recommended DNS-related settings for improving SPF validation reliability?One behavior I have noticed is that multiple emails from the same sender domain, received at nearly the same time, may produce different SPF results. Some messages pass SPF successfully, while others are rejected because FortiMail reports that no SPF record was found.Our environment consists of **two FortiMail
Hello everyone,I am using a FortiGate 40F running FortiOS 7.4.12.I would like to know if there is any supported or unsupported method to prevent the FortiGate from saving Alert, Error, and Critical logs in the local memory.My goal is to stop these logs from being written to the internal log storage, not just hide them in the GUI or change their display.Has anyone found a solution, workaround, hidden CLI command, or TAC recommendation that can completely prevent these logs from being stored locally?Any help or experience would be greatly appreciated.Thank you.
Hi I tried migrating the FAZ-400E config to a FAZ-1000G, but after rebooting, the configuration wasn't applied.but migrating the same config to a FAZ-VM works without any issues.(OS versions are identical).
Can Fortinac do the Revocation List to block certificate was revoked?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.