Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi,I am troubleshooting an N+1 synchronization issue on FortiWLC 8.6-5build-8.The N+1 status currently shows Healthy, but configuration changes are not being synchronized to the secondary.I found the following error in the primary controller logs:Oct 1 2026 11:30:59 <controllername> nplus1_Primary:ERROR: Error: Ignored (/opt/meru/np1/scripts/np1-files)(np1sync_files.tgz) in middle of making sync package.I would like to understand exactly what this error means.In particular: Why is np1sync_files.tgz being ignored while the N+1 sync package is being created? Is /opt/meru/np1/scripts/np1-files a normal FortiWLC N+1 directory? Is np1sync_files.tgz a temporary file generated during the synchronization process? Could this "Ignored" message cause the N+1 configuration synchronization to fail? Is there a supported way to access or inspect /opt/meru/np1/scripts/np1-files on a FortiWLC controller? If shell/SSH access is available, what account or method should be used to inspect
Hi community, I have a question about FAZ logging. Which I can’t seem to find the right answer to and I’m hoping you guys may have experienced something similar.Basically I need to undertake some work on a FAZ VM itself where I don’t want new logs to be ingested to the database for a few hours while I do some work. It will be coming up and down so I don’t want it to start taking new logs when it boots up again.I have about 50 Gates logging to this FAZ and it is not feasible to go to each one and turn off the FAZ logging. I’m ideally looking for something like a pause button on the FAZ if it were to exist. I’m on a VM running 7.4.10. I have seen some recommendations about disabling the port on the FAZ used by the Gates so traffic can’t make it through and using a separate management port to continue to connect to the device which I believe is potentially my only option.Any other thoughts?
Hi, I’m having an issue where users are missing from groups synchronized with Entra ID. I can browse and import groups from Entra ID, but when I go to System > Groups > Remote Groups and select "Show members," the list is empty. I suspect a missing API permission, but I’ve checked everything and the configuration looks correct. Has anyone encountered this problem before?P.S. The connection to Intune is configured and working without issues.
I replaced the secondary unit of a FortiMail (3000F) configured in a primary-secondary setup and rebuilt it using the old secondary unit's configuration.Before connecting it to the primary unit, the following entries appeared in the "Mail Event" logs:/var/spool/etc/mail/submit.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail_ec.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail.cf: WARNING: dangerous write permissionsDoes FortiMail use sendmail for email transmission and reception?For the time being, I have connected it to the primary unit, and data synchronization is complete.If the primary unit were to fail in this state, causing the secondary unit (which generated these error logs) to take over as the primary,would email transmission and reception function correctly?I am concerned about this point. Do you have any information regarding these logs?When I tested sending an email via Webmail from this secondary unit,the following entry appeared in
We use FortiMail’s webmail for IBE secure mail exchange.The Webmail interface allows users to download the de-crypted emails using “save as” without any encryption. These mails are saved as decrypted plain email format (.eml)How can we disable this function in Webmail?Is piping the WebGUI through a reverse proxy/WAF to block this particular button the only way?
Hi,What issues could there be in a split-brain scenario? I realize the raw logs sync wouldn't be a problem, but what about configs? For instance, an admin adds some devices to one node while another admin adds new devices to the other node. How can the Geo-redundant HA reconcile those changes? Can that damage Analyzers and Collectors?
Has anyone run into this error when registering FortiClient to EMS Cloud using Google Workspace SAML?Error: 403 - app_not_configured_for_userEnvironment:FortiClient EMS Cloud Google Workspace SAML authentication FortiGate 90G HA pairAlready verified:User access set to ON for all users in Google Admin Attribute mapping is correct ACS URL and Entity ID match between EMS and Google SAML app Not in test modeStill getting the 403 on registration. Anyone else hit this and found a fix?
I have one FGT node in one data center and another node in a different data center. Currently, each one has its own management IP: 10.10.10.1 and 10.10.10.2.This is a deployment from scratch, so we are going to connect a cable between the HA ports of both nodes.My question is: I now need to configure an A-P HA cluster between the two nodes. However, in the past, when I enabled HA Reserved Management in an attempt to keep both management IPs independently accessible, I lost access to the firewalls through their management interfaces.What would be the correct steps to set up an A-P HA cluster between these two nodes without losing access to either of them through their respective management interfaces?
Currently, I have a FortiGate configured with two ISPs, with WAN1 as the primary connection and WAN2 as the secondary connection.For the LAN-to-Internet policy, I have a fixed IP pool NAT configured using the usable IP provided by WAN1. When I introduced an additional IP pool NAT on the LAN-to-Internet policies using the WAN2 Interface IP, users reported that they were unable to access the internet.After reverting the change and removing the WAN2 IP pool, internet connectivity was immediately restored for the users.My question would be:- What is the recommended NAT design for a FortiGate with DUAL ISP connectivity when an existing IP pool nat is already in use?- Are there known considerations or limitations when using fixed IP pool NAT address in a multi-WAN deployent?- Are there any FortiGate best practices for maintaining internet connectivity while introducing NAT rules in a dual ISP environment?
I have enabled pmtu-discovery as per instructions from this topic Dynamic MTU Configuration in SD-WAN Deplo... - Fortinet Community but MTU on the GRE tunnel remains 1476. I want it to be 1356 for this state when ipsec is off. one side of that mikrotik - fortigate link is discarding ldap traffic so domain users are unable to log into their computers because of problem in communication between computers and domain controllers... ldap traffic from windows 11 clients to domain controller on port tcp88 and vice-versa has DF bit set and traffic may not be fragmented..
Hi Team,We plan to deploy a FortiPortal Scalable Cluster with two nodes in one DC and one node in the other. If the DC with the two nodes goes down, the single node can operate independently per the configuration:config system ha set min_nodes 1endWhat will happen when the two-node DC is brought up? Will it be enough to change the single configuration to a scalable cluster? Will the changes made on the single node during the outage be replicated to the other nodes?
We currently use FortiClient EMS 7.4.7 and want to assign the endpoint profiles with userbased AzureAD groups. Currently it works only with devicebased AzureAD groups. When I add user to to the AzureAD group und resync I noticed the the user is synced with the EMS, but the device from the user is not assigned to the profile.The Fortinet Support means that it is a bug, but perhabs it is a incorrect configuration in the claims or anything else.Has anyone use userbased AzureAD groups with the version?
Can we query fortinac license usage using snmp? I need historical license consumption every hours.
We are observing an issue with FortiClient authentication where the expected “Wrong Password/Invalid Credentials” popup is not displayed when an incorrect password is entered.The issue is a for both local and remote users,Kindly assist us in troubleshooting this issue and identifying the root cause.
Hello, our organization recently obtained a few MacBook Neos and Airs to test, running on macOS 27 Golden Gate. However, after installing FortiClient and connected to the office network, at random times, the Wi-Fi and Bluetooth would switch off and cannot be turned back on manually. After 2-3 minutes of this, the MacBook will then freeze then immediately restart on it’s own. Following a restart, everything seems normal, but this issue can repeat multiple times in a day, but as the day goes on, it becomes stable. This happens the moment I disconnect and reconnect back to the office network. Especially after bringing home and returning to the office with the MacBook. This issue does not happen with a private home network or hotspot. Resetting the MacBook does not resolve the issue either. When FortiClient is not installed, the MacBook behaves normally. 2 older MacBooks obtained last year does not experience this issue. We have disabled / blocked Apple Account login, Mail, Calendar, iClou
Hi everyone,we using a Fortigate G900 with v7.6.7 as explicit proxy.Since a couple of weeks, we have the problem that, when using Firefox, we can’t use the Google Search.After we type anything in the search bar, we get the following error:502 unknown content-encodingThe webserver reported that an error occurred while trying to access the website. Please return to the previous page.URL https://www.google.com/search?client=firefox-b-d&q=fortigate Other Websites / Search-Engines with Firefox are working fine. With Edge or Chrome Browser Google works as well.Have somebody an idea? Regards, Michel
Drear colleagues, please confirm if Fortigate FG-120G, (SN FG120GTK25005307 and SN FG120GTK25005240) allow redundant AC power supply with different 220 VAC sources, that is , from different UPS 220 VAC equipments.
I currently block the advertising categories in our DNS and URL Filtering Profiles. We are starting to get a small but increasing number of websites that are blocking access unless we allow access to the Ad network they are using (Screenshot attached below). I am hesitant to allow access to the ad network, however I am getting pressure to do so. What are others thoughts on this. Is it truly a security risk? Is there away to continue to block the ads and allow the website?
Hello I want to update my license
My email already exists in FortiCare, but signing in shows “UNAUTHORIZED — Your account cannot be found”, error A02E03-151. Creating a customer account fails because the user already exists. Please check my account and its association with Customer Service & Support.
Can anyone provide any guidelines for remote ipsec VPN with fortigate 7.6.6 os & its integrate with LDAP local user many more members ?
I would like to Integrate Tufin with Remedy in such a way that the CRQs requesting Fortimanager security policies configurations get automated, meaning that Tufin would be able to see the CRQs on Remedy and automatically configure the rules on Fortimanager:Tufin pick up Remedy ticket, figure out which firewall, check for conflicts, push rule to FortiManager. FNDN/API comes in is for the extra checks — like checking FortiAnalyzer logs to confirm the traffic is blocked, verifying policy package sync status, catching duplicate objects with different names, etc. Basically the stuff we'd manually check before making changes. FNDN/API comes in is for the extra checks — like checking FortiAnalyzer logs to confirm the traffic is blocked, verifying policy package sync status, catching duplicate objects with different names, etc. Basically the stuff we'd manually check before making changes.Is there any documentation or support that I could have access to accomplish this? Thank you & best re
Is it possible to Gre over Dynamic IPsec between Fortigate & mikrotik.Can any one give me configuration sample for gre over dynamic ipsec for fortigate firewall?
i have one Entra ID single subscription and single tenant but in this entra ID contains 3 of companies. In Entra i have 3 groups indicated their company such as group Corp-1, Corp-2 and Corp-3. In the fortigate can we make a firewall rule based on Entra ID group and not using IP address as the source?
I am automatically updating FortiClient for Windows from version 7.4.5 to 7.4.6. On about 50% of the test computers, the installation process stops at: “Stop services.” I also tried doing it manually by running the installer file, but in that case it also gets stuck at “Stop services.” How can I work around this issue?I have updated versions 7.0.x and 7.2.x many times before and never had this problem. Now I’m updating to version 7.4.x for the first time. Has anyone had a similar issue?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.