Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi all TL;DRDoes anyone know if the Fortigate trial licence limitations on encryption/decryption (which for example prevent the use of HTTPS) also prevent the SSL connections from Fortigate to FortiAnalyzer for the purposes of sending logs (via oftpd)? I was trying to test sending logs from a Fortigate VM (firmware 6.4) to FortiAnalyzer VM (firmware 6.4) but I just get "No connection" and if you hover the cursor over that you get "Error occurred:{0}". The goal is to test forwarding logs from the FortiAnalyzer to a third device but I can't get this far as the Fortigate won't send the logs to the FortiAnalyzer. A reddit post (www.reddit.com/r/...er_trial_ssl_error_3/) suggested this is probably a trial licence limitation but it would be good to confirm it here if possible. If anyone has found something similar please let me know. Thanks Testing steps:I've made sure to check the compatibility matrix and the FGT and FAZ are compatible. The F
What would cause apple devices running ARD to disappear in network list when there are more devices connected and reappears when there are less devices? This is a FortiAPs/FortiSwitches environment.
Environment2x FortiGate-VM64-KVM, v8.0.0, build0167 (GA.F) License Status: Invalid (permanent-trial / unlicensed mode — not a normal 15-day FortiCloud eval) Lab topology: two sites connected via two independent ISP paths, each carrying one IPsec VTI tunnel (VTI-A over path 1, VTI-B over path 2), both VTI interfaces as members of a single SD-WAN zonegw-site-01 (192.168.1.2/24) — fw-site-01 (port4: 192.168.1.1/24) — [ISP1/ISP2] — fw-site-02 (port4: 192.168.2.1/24) — gw-site-02 (192.168.2.2/24)VTI-A: 172.16.1.1 (fw-site-01) ↔ 172.16.1.2 (fw-site-02) VTI-B: 172.16.2.1 (fw-site-01) ↔ 172.16.2.2 (fw-site-02)IKEv2, proposal des-sha512 (forced by the eval-mode low-encryption restriction), dhgrp 29, net-device enable. Both tunnels status=up with active SAs (diagnose vpn tunnel list), real traffic counters climbing.GoalSimple: execute ping 192.168.1.1 from fw-site-02, reaching fw-site-01's LAN-facing interface (port4) through the tunnel. Not even LAN-to-LAN — just firewall-to-firewall, locally-
I've just installed FortiClient VPN the .deb package from here https://www.fortinet.com/support/product-downloads .installed with `sudo dpkg -i ...` Setupd the configuration ( as I have on my windows pc and on my android ) when I try to connect I get the following in the journal: iul 29 14:23:43 station1 kernel: iked[283119]: segfault at 28 ip 000000000045195d sp 00007ffe2a7e6900 error 4 in iked[400000+891000] iul 29 14:23:43 station1 kernel: Code: 4c 89 e5 48 89 44 24 38 48 8d 84 24 88 00 00 00 45 89 d4 45 89 de 48 89 44 24 50 48 8b 45 00 45 89 f5 31 ff 31 db 4a 8b 0c e8 <8b> 51 28 85 d2 74 42 48 8b 71 20 8d 7a ff 31 db 48 8d 46 08 4c 8d iul 29 14:23:43 station1 fctsched[283131]: /opt/forticlient/iked: invalid option -- 'P' iul 29 14:23:43 station1 regolith.desktop[281914]: 14:23:43.573 › VpnHandler UNHANDLED {"isTrusted":true} iul 29 14:23:43 station1 fctsched[283131]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus iul 29
Need FortiGate-side workaround: RDP disconnects when client FortiClient VPN connects on internal PCI have a FortiGate 40F running FortiOS 7.4.12.I need to RDP from outside the office to an internal Windows PC at 192.168.1.89. RDP works normally while the PC is not connected to a VPN.The issue is that the user must connect FortiClient VPN provided/configured by our client on the same Windows PC (192.168.1.89). As soon as the client FortiClient VPN connects, my existing RDP session disconnects.I have no control over the client's FortiClient configuration and cannot ask the client to change any settings on their side Basically, the IP is getting change after VPN is connected, what is the work around for this SSL VPN Already verified192.168.1.89 is reachable from the FortiGate. TCP 3389 is listening on 192.168.1.89. RDP works correctly before the client FortiClient VPN is connected. Once the client FortiClient VPN connects on 192.168.1.89, the RDP session disconnects. I also tested FortiG
Hi Fortinet Community,I’m facing an issue where all REST API requests to our FortiGate are returning HTTP 401 Unauthorized, even though the same integration is able to successfully communicate with our FortiAnalyzer.Environment FortiGate management/API endpoint: https://172.20.69.50 FortiAnalyzer endpoint: https://172.20.69.51 API client: Python using httpx HTTP method: GET API paths: /api/v2/monitor/*, /api/v2/cmdb/*, and /api/v2/log/* Observed behaviorEvery request to the FortiGate REST API returns:HTTP/1.1 401 UnauthorizedThis happens consistently across multiple unrelated endpoints, including:GET /api/v2/monitor/vpn/sslGET /api/v2/monitor/vpn/ipsecGET /api/v2/monitor/system/statusGET /api/v2/monitor/system/arpGET /api/v2/monitor/system/dhcpGET /api/v2/cmdb/system/interfaceGET /api/v2/cmdb/device/access-deviceGET /api/v2/cmdb/router/staticGET /api/v2/cmdb/firewall/addressGET /api/v2/cmdb/firewall/addrgrpGET /api/v2/cmdb/firewall/ippoolGET /api/v2/log/eventGET /api/v2/log/tra
Hi Fortinet Community,I have a question regarding FortiToken Mobile and MFA recovery.I currently have more than 30 FortiTokens installed on my FortiToken Mobile application for different FortiGate/FortiAuthenticator accounts.My concern is the following:If my mobile phone is lost, damaged, reset, or becomes unusable for any reason, I may lose access to all of these tokens. In that situation, I would not be able to use the FortiToken Mobile app to generate OTPs and could potentially lose access to the protected accounts.I would like to know:Is there any official backup or recovery mechanism for FortiToken Mobile? Can FortiTokens be restored on a new phone if the original phone is lost or damaged? Is there any way to synchronize or back up FortiToken Mobile tokens securely? Can FortiGate/FortiAuthenticator MFA use Google Authenticator instead of FortiToken Mobile? Can Microsoft Authenticator be used for FortiGate/FortiAuthenticator MFA? Is it possible to configure MFA using TOTP in a way
Hi Everybody,We are running a Kubernetes cluster on Rocky Linux 10.2 VMs, with the FortiEDR Linux Collector installed on the host OS.When FortiEDR Communication Control was changed from Simulation to Prevention, the entire Kubernetes cluster became unavailable. After changing the policy back to Simulation, the cluster recovered and became operational again.I have allowed everything regarding the connections to the outside after checking with my Dev Ops Engineer and we see no new logs regarding the communication control. The affected nodes reported this kernel message:Failed to initialize the IGMP autojoin socket (err -1)FortiEDR Collector version: 6.2.0.1350I double-checked the FortiEDR Events and Communication Control logs, but there were zero events showing that anything was blocked or denied by FortiEDR.Has anyone experienced a similar issue with FortiEDR Communication Control and Kubernetes? If you have any ideas or troubleshooting recommendations, I would really appreciate your he
Can anybody help me get FortiClient version 6.2.6.0 for linux (debian), please?
I'm developing a custom IPS signature for FortiOS 7.4 and want to understand the Lua scripting support in custom IPS rules. Specifically:(1) Can custom IPS rules written in Lua access the os and io modules?(2) Are there any sandboxing restrictions on what Lua code can do in a custom IPS rule handler?(3) Is the Lua state for IPS rules a shared state or per-session isolated state?
We keep losing the sync between the active and standby yesterday we get working just this morning its out of sync again
I am having an issue with the FortiClient IPsec IKEv2 VPN connection on Android. I entered all the required information correctly and tried many configuration changes, but the issue still persists. When I attempt to connect, I receive a “Null” error message.At the same time, I tested the same VPN configuration on my iPhone, and the connection works perfectly without any issues. Iphone Settings Android Phase2 Settings Andorid VPN Settings
Hi all,I've made a free firewall migration tool, now available on GitHub: https://github.com/gateshift/gateshiftIt's still in beta, and feedback from people who actually do this work would be welcome.If you run firewall migrations or optimizations, give it a try and let me know where it falls short.
dear im going to deployed FortiAuthenticator as external captive portal , guest user will connect to Aruba WLC please guide me to achieve this
This isn't as dumb as it sounds at first glance, I promise! No, I'm not trying to print to a printer that is wirelessly connected to the same SSID, which would obviously be blocked by this setting.I'm trying to set up a wireless network for guests to be able to print to one of our printers, which is wired to a "printers" VLAN. I've set up a tunnel-mode SSID with the relevant multicast firewall policies for mDNS and WSD/SSDP, unicast policies for IPP and RAW, and a Bonjour profile for printers.So far, so good. iOS, Android, and Windows devices can all discover the printer and print. Until I enable the setting to block intra-SSID traffic, at which point none of them can see the printer anymore.Is that setting simply incompatible with multicast forwarding, or what might be going on here? I really want it enabled since I don't want guest devices to be able to communicate with each other. Would an L3 firewall profile potentially work instead?
Hello, I run this VM New deployment of FortiAnalyzer for VMware FAZ_VM64-v7.6.4.F-build3579-FORTINET.out.ovf.zip (477.27 MB) on VMware but I'm getting this error not sure what might be the reason.Any help would be appreciated.
Hello,I'm deploying a trusted CA certificate to a number of Fortigates devices that are in sync with FortiManager.This is not for full SSL inspection, but for trusting SSL connections to internal servers (the ones that go into Remote CA Certificates).Right now I'm using a script since I didn't find such functionality in 7.4.11. Dynamic Local Certificate seems to be only for full SSL inspection.bDid I miss anything or scripting is the way to go?Thanks
hi, we have recently upgraded our foritmanager, this fortimanager is already present as our asset in forticloud. When we upgraded our fortimanager, we checked it was not registered. when we enter the credentials to register it, it said the serial number is already present which means communication does not have any issue, but it is not being registered, can someone please help me to check would could be the possible reason or what to check ?
Not working FortiClient 7.4.6.0218 android 17 with fortios 7.6.7 =( When update in google play store? PC/Mac works good
Has the problem with FortiClient VPN for Android been fixed? v7.6.5 causes Error: Could not establish session on the IPsec daemon'. This was reported months ago and now we are being told we have to go to 7.6.7 to remain compliant.
Hey everyone,We use FortiClient for VPN and web filtering, managed by EMS across a few hundred endpoints. On one workstation, the FortiClient Web Filter extension shows in Edge as "Managed by your organization" and can't be removed. No other endpoint has it — our own devices don't show it at all.Same FortiClient version, same EMS group and profile as the others, and there's no GPO pushing it.What causes FortiClient to force-install that extension on its own, and where would I look to find what triggered it on just that one machine?Thank you.
I’m trying to set up a full-tunnel SSL VPN on my Fortigate 60E running 7.4.6 and for what ever reason, when connected to Forticlient if I go to a website that shows your public IP (ie- www.whatismyipaddress.com), it is showing my laptop’s local internet connection’s public IP instead of the fortigate’s WAN IP. I have tried using the ‘full-tunnel’ portal, disabling the ‘tunnel-access’ portal, changing both to ‘full tunnel’ in the SSL VPN settings and disabling both and creating a new portal which is full tunnel, but whatever I do it keeps showing up with my laptop’s local internet connection. I did some packet traces and it *seems* to be egressing the Fortigate’s WAN interface but for whatever reason it keeps showing my laptop’s internet’s public IP. I can ping devices inside the network (behind the fortigate) just fine, so I know the VPN is working. It’s a real head-scratcher. Can anyone take a look at the config (attached to this post) and tell me what is going on? Of note, I did try
I have been running FortiClient 7.4.8 on my endpoints, all of which are Windows 11 devices fully compatible with the FortiClient agent.Recently, I have been experiencing an issue with Google Chrome. Whenever FortiClient requires an update and prompts for a system reboot, after the endpoint restarts, the Chrome configuration appears to be partially reset. It seems as though the browser's local data or cache has been cleared, causing some settings to be lost.The behavior is almost as if Chrome had been reinstalled or its user profile had been recreated after the reboot. The most noticeable impact is that browser extensions lose their configuration and must be set up again.Has anyone else experienced a similar issue with Chrome following a FortiClient update? Does anyone know what could be causing this behavior?I suspect it may be related to the Anti-Exploit feature or possibly the Web Filter browser extension, but I have not been able to confirm the root cause yet.Any insights or recomme
Hello, I am testing dynamic MAP-E connectivity on a FortiGate-100F running FortiOS 8.0.0 build 0167. The Internet service is So-net over the NTT East FLET'S network in Japan. The VNE service appears to be JPIX “v6 Plus.” DHCPv6-PD is working. The FortiGate receives a /56 delegated prefix and the WAN interface receives an IPv6 address derived from that prefix. The relevant WAN configuration is: config system interface edit "x1" set mode dhcp set role wan config ipv6 set ip6-mode delegated set dhcp6-prefix-delegation enable set ip6-delegated-prefix-iaid 1 set ip6-upstream-interface "x1" set ip6-subnet ::1/64 config dhcp6-iapd-list edit 1 set prefix-hint ::/56 next end end nextend After applying this configuration, the VNE diagnostic correctly recognizes the delegated prefix and WAN IPv6 address: end user ipv6 prefix: 240b:10:xx
I was looking through the IPAM settings and saved a change accidentally. I lost network access to my 60F as a result. Windows Terminal isn’t working on my pc. I’m looking for a software recommendation to access the 60F from the console port and any advice on how to turn off IPAM from the command line. I’ve only used the GUI so far. Thank you in advance !!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.