Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi!Supposedly, setting executing “diagnose vpn ike log filter name” with phase1 name as argument will confine “diagnose debug application ike 255” or “diagnose debug application ike -1” debug logs to only that tunnel. However, when I do it, I see debug logs for all tunnels. How to filter out all the tunnels’ debug logs?Thanks!
Hello guys! Users on a regular IP based firewall policy with no UTM profiles applied to it, are having problems when trying to access Faceboo. On IE the page appears as text only and on Google Chrome, the pictures are blank. If there is no UTM feature applied to this rule, what can be the cause of this behaviour? Thanks in advanced guys!
Hi Everyone. today we was encountered the Fortigate Dynamic DNS issue in firmware 7.4.11 and 7.4.12. Restart the firewall few time still unable to access even ping google.com also unable to resolve but when PING 8.8.8.8 from Fortigate is reachable. In the Network → DNS → DNS server show Primary DNS and Secondary DNS server is unreachable. Even the host name unable to resolve
Hi everyone,I’m working with FortiADC 7.6.4 and would like to ask about a couple of CLI commands. If anyone has information, I’d appreciate your help. 1. Checking interface link status Is there a CLI command that shows the actual link status of an interface? According to the documentation, the command "get system interface" only provides the enabled/disabled status, so I understand it does not show the real-time link state. I also looked at the following command: "diagnose hardware get deviceinfo nic-detail" which appears to offer detailed NIC information, but it does not show the link status for aggregated (LAG) interfaces. 2. Deleting backup configuration files I know that configuration backups can be created using: "execute restore config disk <name>" However, I haven’t been able to find a CLI command that deletes configuration backu
Dear Team, When a FortiEMS virtual machine is deployed using OVA file, it loads with one interface and the default gateway pointing to the same interface. Can we have an additional interface ? Because there is a requiremet for dedicated OOB management and Dataplane interface for Forticlient telemetry connction.https://docs.fortinet.com/document/forticlient/7.4.0/new-features/182605/deploying-ems-as-a-vm-image-7-4-1
We have multiple IPSEC VPN dial up customer sites with SAML.One of our clients sites, requires NAT to be turned OFF in the Forticlient profile to connect, and all the rest require it ON. Mostly it's the same or similar ISP, NAT in the Phase 1 policy on the Firewalls are set to the same on the two examples I tested, so I don't think it's that.FortiOS 7.2.13 on a 60F for both.Any ideas where or how I can figure out why this setting requirement differs between this site and the others?TIA
I try to add my tplink to the FNAC and in the inventory the port showing 6 from 12. Where i can see the rest of 6 ports?
I am trying to migrate a switch port from root vdom to inside. When I do that the port it does not appear in the inside VDOM and it does not accept any commands in root vdom and it gives the error:“Invalid switch portobject set operator error, -651 discard the settingCommand fail. Return code -651”I managed to bring the port back if I make the change in the config file and then upload the file to the fortigate. However, when I try to move the port again to inside I have the same issue. Also made the corrections mentione in: Fortigate 400E version 7.4.11 build2878FortiSwitch: S224DF-v7.4.6-build895,250129 (GA)
Microsoft Hyper-VAfter successfully logging in to FortiCloud, the session is automatically logged out after a short period. The logout occurs repeatedly, preventing stable access and management through FortiCloud.Troubleshooting Performed:* Verified internet connectivity* Cleared browser cache and cookies* Tried different web browsers* Confirmed correct system date and time settingsanyone manage to resolve this problem?
HelloWe are using a FortiWeb cluster as a VM for our customer. The backend servers of our customer's customers are gradually being migrated to this FortiWeb cluster from a Sophos UTM 9. We also operate the Sophos UTM 9. The first backend servers are already running on the FortiWeb VM and access is successful. The challenge now is to migrate the backend servers that use SSO login via KeyCloak with Azure to the FortiWeb cluster. We have configured a test backend server for this purpose. Our customer has configured KeyCloak (plain vanilla without any special configuartions) on his environment. We have configured the Azure parameters on our side in Azure. When accessing the test backend server via Sophos UTM 9, everything works without any problems. When accessing via FortiWeb, I can authenticate and then it's pending. After round about 20 seconds comes '404 Not Found'. What did we overlook or configure incorrectly in the FortiWeb cluster configuration?Thank you in advance for
I have an email notification set up to alert when one of our ISP’s goes down. The problem I’m having is the Minimum interval setting is not working. I have it currently set for 2 minutes and it immediately alerts me when this happens when no delay. I’m getting way more notifications than i need to for this. The model is a 60e and the firmware is 7.2.8. Does anyone have any suggestions in order for this to work properly?
HiDue to the reduction in the maximum certificate lifetime, we need to frequently upload local certificates to FortiWeb in the future.My environment uses a true transparent proxy mode, can I change it to use Let's Encrypt? If I do so, the certificates used on FortiWeb and the real server will be different. Will this cause any connection issues?Or is there a way to upload a local certificate and have it automatically applied to all server pool members?Thanks.
Do you use any AI tools for troubleshooting problems with FG's? If so, which ones work best for you and in what situations?I mean, for example, the approach in which you write: "hey, here are the logs, give me the next steps of troubleshooting to determine what is the cause and how to fix it."
One of our clients has a user he's suspicious of browsing social media consistently during work-hours. He's wanting to catch this user-out with logs/reports of the the internet traffic. How would we go about doing this? Did a quick look around, is the FortiAnalyzer the best tool for the job?
Hello,has anyone experienced issues with RADIUS authentication for IPv6 clients on a captive portal interface?Setup: FortiGate 200F, FortiOS 7.4.8, interface with security-mode captive-portal + security-mac-auth-bypass enable.IPv4 MAB works flawlessly — FortiGate sends an Access-Request with the client MAC as username, RADIUS responds with Access-Accept, and the auth entry appears in diagnose firewall auth list. No issues. config authentication rule edit "TEST Radius" set srcintf "50 Lan" set srcaddr "all" set srcaddr6 "all" nextend For IPv6, FortiGate sends no RADIUS request at all (confirmed via tcpdump). The diagnose firewall auth ipv6 list remains empty regardless of configuration.What was tested without success:1. config authentication rule with srcaddr6 "all" — CLI accepts and saves it, but the daemon never processes IPv6 sources.2. Framed-IPv6-Address (RFC 3162) in Access-Accept reply — FortiGate receives the attribute (confirmed via tcpdump, packet le
I'm trying to setup a POC to demo ZTP.....Using the Fortigate Cloud service, I was able to provision a Fortigate to it's proper On-Prem FMG. However I was unable to get the gate provisioned to the proper CLOUD FMG. (Even though it says it's supported). I then tried using FortiZTP service and was able to provision to the CLOUG FMG successfully. Has anyone else run into this ? Should we be using the FortiZTP since it's still in beta ? Tom
Anyone using FortiManager cloud with multiple FortiGates? I’m new to FortiManager Cloud and I’m having trouble streamlining FortiGate onboarding. I have about 30 firewalls to deploy.What methods are you using? We’re trying to go down the CSV upload method with several configuration variables defined in the CSV file
Hello FTNTI see in known issues of FortiOS 7.4.11 the following bug id. 1256278 Packet loss occurs when asic-offloading is enabled on FortiGate. Can anyone explain in which models and/or circumstances this can happen?
Hello,Would really appreciate it if someone can point me to the right direction or help me with the following. Using DoS policy would like to know if its possible to create 2 polices with source like soPolicy#1 IPs from specific country. The limits are set higher or set to disable.Policy#2 All other IPs . The limits are set very low The questions are Does Fortigate support anything similar to the above? If both policies are enabled Will this lead to an increase in the resource usage of the Fortigate firewall? Thank you in advance.
Is it possible to configure link aggregation on wan1 of the FG-80F? It was possible on the FG-80E.
Anyone experiencing this issue with FortiClient 7.4.7 and the latest macOS? I had to prep a new MacBook for one of my people and upon installing FortiClient from my EMS (Cloud) installer, it just will not register from the still good invite code bundled in the installer nor will it accept the invite code trying to manually enter and connect. It does not give me an error or anything, it just does nothing. Invite code is still good as I used it with a Windows PC afterwards and no issues. I have went through the release notes for 7.4.7 in regards to macOS and ensure disk permission access and system extension activations were good, etc… and all are on/allowed based on the release notes requirements.
Hello community. I will have to work on a deployment of a FortiADC to publish internal applications to our users. The existing (non-Fortinet) solution is publishing the internal app with the following values: App PATH: C:\red\blue\app.exeStart in folder: C:\myfolderParameters: -an entry -b entryb -c entryc.... On FortiADC I do have the fields for App Path and parameters, however im not seeing where to place the "start in folder" info on FortiADC. Any ideas here, what to do?
Hi there, due to crazy pricing in subscription models and such we're considering FortiADC as a possible replacement for our F5 BIG-IP 2-node-cluster. I have FortiADC v7.4.4 running in an eve-ng lab and some questions arose. We have BIG-IP LTM & APM but we do nothing with App Portals, we just use 1:1 mappings (almost) with a portal front with complex logic. So something I would need, and I do not know if FortiADC can do that, or if things would have to be designed differently: On BIG-IP I have an Access Profile, an equivalent I assume to HTLM Forms, where I have a form with CAPTCHA, user name and password, which then goes to AD/LDAP, then a second dialog for internal MFA authenticating over RADIUS, and then it saves the successful auth state as a user session variable, which is then used in a script for Remote Desktop Gateway clearance in the background. The BIG-IP then internally transitions to a forwardable Kerberos ticket for the user to access all the publish
We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document LibraryThat last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registrat
Hi,FortClient for Android asks for “Overlay permissions” when starting the App during initial setup. For ZEBRA Scanners there is an option to pre-grant this permission via OEMConfig: Enabling Display Over Other Apps Permission via MDM/EMM OEMConfigTherefore, the “Package Signing Certificate Fingerprint” of FortClient App is required. Can you please provide is with this? Since the APK isn’t available for public download, it cannot be extracted via ZEBRA’s SigTools utility by customers.Thanks!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.