Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I want to test latest Fortigate VM image on Virtualbox. but I get error “Failed to start !”. Is there some way to start the VM locally?
Is anyone able to provide me with the firmware for a Fortinet 60F firewall?
It appears that if a person purchases a used Fortigate product, that they are unable to download firmware without paying for “support”.Is this the way it is? Or am I missing something?
Hi i have create lots of VPN definitions in the VPN Manager and assign them to Managed fortigates. When i try and install the policy i quickly get this error. "cannot find addr xxxx" "load vpn node x failed". the object is there but need to be loaded on the GW. even tryig with a policy with no VPN in the rules also fails. Any ideas?
How to Protect Fortigate from IPv6 Security Risks
Hello Fortinet Team,I would like to report a False Positive occurring in FortiClient. The antivirus engine is flagging and quarantining legitimate .jar files that belong to Microsoft Power Automate Desktop.These files are required by the Microsoft application to interact with Java-based interfaces for automation purposes.Software: Microsoft Power Automate Desktop Flagged Files: PAD.JavaBridge.jar PAD.JavaBridge.A11y.jar Some of the File Hashes (SHA256) involved: CF531D64F2445BD6149EF018D41C6B6EDC2185461100998DFF8204... 0887F61DB05200C724DF9E0700F63B98145E47C69FB98258323AB6... EB935EB8D28CDBA566CBACDA023E02FCD4A9DB0535893B5B8699E7... I have attached a screenshot ("Captura de pantalla 2026-07-20 110922.png") showing the multiple detections and the exact hashes provided by the FortiClient logs.Could you please review these files and update the definitions to whitelist them?Thank you.
Hi everyone,I'm currently testing the FortiNAC Persistent Agent in my lab environment. The agent is unable to establish a connection to the FortiNAC server. Below are the troubleshooting steps that I have already completed.Troubleshooting performedConfigured DNS and verified that the client can successfully resolve the FortiNAC FQDN. Modified the Windows registry on the client so that ServerIP, LastConnectedServer, and HomeServer all point to the FortiNAC FQDN (fnac.vss.com). Downloaded and installed the Persistent Agent certificate from FortiNAC on the client. Verified network connectivity: Client can successfully ping the FortiNAC server. FortiNAC can successfully ping the client. Verified that FortiNAC is listening on TCP port 4568. Tested TCP connectivity to port 4568 from the client. Captured traffic on FortiNAC using tcpdump.During the packet capture, I observed that the client sends TCP SYN packets to fnac.vss.com:4568, however FortiNAC never replies with a SYN-ACK, causing th
We recently started investigating roaming behaviour on a customer environment using FortiAPs with WPA3-Enterprise and an external RADIUS server.The initial observation was that roaming did not appear to behave like a Fast Transition (802.11r) roam. During movement between access points, clients seemed to perform a complete authentication process again instead of using a fast handoff. This resulted in noticeable delays compared to what we would normally expect from an 802.11r-enabled deployment.To validate this, we captured both beacon frames and association traffic on the customer environment. In the captures, we noticed that clients were performing normal WPA3-Enterprise authentication exchanges after roaming. When we examined the beacon frames more closely, we found that the WPA3-Enterprise SSID advertised only the standard WPA3 Enterprise AKM. We could not find any indication of FT over IEEE 802.1X or a Mobility Domain (Tag 54) element.To rule out environmental factors, we rebuilt t
Hello traveler, I'm assuming you've stumbled upon this post after using very specific search terms and are perhaps now at the end of your rope. I hope I can maybe be your last stop. There's a lot that's going to depend on your own setup, such as which cipher suites you're using, your local and remote subnets, etc. I'm not posting this as a definitive guide to get your swanctl.conf perfect - I'm assuming you've already got it to a place where it "should be working". My goal is instead to draw attention to the changes that took my tunnel creation getting totally dropped and ignored by the FortiGate after first contact, to it actually trying to authenticate. It was of course, very simple, but took me hours upon hours to finally get right. The lynchpin was this: Set Remote auth to PSK. Set Local auth to EAP. Make sure Local is set to round 2, otherwise it sends your EAP credentials before it's asked and the Fortigate shrugs it off. Note that on my FortiGate side, I'm no
We’ve had several cases of memory exhaustion with different processes (node, wad, ips), and are using the “set failover-memory enable” setting to cause the Clusters to automatically fail-over when going into conserve mode. (as well as cpu-threshold)While this is fine as it no longer causes prolonged service disruptions, it does leave the clusters in a degraded state: the failed node usually does not recovery by itself and needs to be rebooted in order to recover from the cause of the memory consumption and restore the cluster redundancy.Is there a simple way (e.g. with automation stitches targeting only the currently active or passive node) to automatically trigger a reboot on the now passive node after such a failover event?Or do we need a feature request to allow automatic reboot of the failed node after a failover that was triggered by an internal event (memory, processes, RIB/FIB, cpu)? We probably don’t want to auto-reboot after an external event (link failure/ping-probe fail).
Hi everyone,I have installed the following FortiGate VM image in EVE-NG:Image: FFW_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvmAfter booting the VM, I don't see any option to add or upload an Evolution License during the initial setup.When I click Cancel on the Add License screen, it immediately returns me to the device login window, and I'm unable to proceed any further.Has anyone experienced this issue before?Could you please help me with the following questions:Is this VM image compatible with an Evolution License? How can I upload or activate the Evolution License on this image? Is there any additional configuration required for EVE-NG or the VM before licensing?I have attached a screenshot of the issue for reference.Any suggestions or guidance would be greatly appreciated.
Hi Fortinet Support,We're looking for guidance on deploying and configuring the FortiClient VPN application on Apple iOS devices managed through SOTI MobiControl.Our Android devices are working as expected, where the VPN configuration and authentication are deployed through SOTI. However, the process appears to differ on iOS, and we're looking for the recommended approach.Specifically, we'd like to know:Whether the FortiClient VPN configuration can be deployed automatically through SOTI MDM on iOS. Whether VPN profiles and authentication settings can be pre-configured using Managed App Configuration or another supported method. If there are any limitations on iOS compared with Android regarding deployment or user interaction. Whether there is any official Fortinet documentation or best practice guidance for deploying FortiClient VPN on iOS using SOTI MobiControl.Our environment:MDM: SOTI MobiControl Devices: Apple iPhone and iPad (iOS/iPadOS) VPN Client: FortiClient Android deployment
when we use authentication host-mode multi-domain on the port switch, this mean only one vlan data mac address and one vlan voice mac address is accepted. If there 2 mac address of vlan data then the port switch will be shutdown.Below log from the switch%PM-4-ERR_DISABLE: security-violation error detected on Gi1/0/1, putting Gi1/0/1 in err-disable state The interesting is for iphone deployment. When there are new ip phone connected to the nac then nac will put this host to registration vlan and if this ip phone have endpoint conected then from switch perspective there are 2 valid vlan data mac address and security violation is ocurred.Anyone know how we can deal with this situation?
Is anyone else seeing a large amount of “Domain was blocked by DNS botnet C&C” alerts for valid URLS?the commonality is that its akamai and the common 5 IP addresses are the following.23.223.209.3223.33.44.22823.44.201.23423.57.90.6823.33.40.7
Hi all, This is my first post on these forums, so hello to everybody :) I'm going to start by asking a question i don't expect many people to be able to answer but i hope somebody who is familiar with BGP and ADVPN can crack this one. I have labbed up the below scenario and its working great. Hub/spoke topology with direct spoke to spoke connectivity on demand. http://cookbook.fortinet.com/configuring-advpn-in-fortios-5-4-dynamic-hub-and-spoke-vpns/ I have got abit more adventurous and added a secondary WAN connection to each firewall and added a second round of ADVPN config/VPN's to establish tunnels over the new WAN connection in a bid to achieve ADVPN redundancy should the primary VPN's fail. The interesting bit is that it does work (kind of) - If i shut the VPN's down on the hub it works, both spokes will speak to the hub via the second VPN tunnel and agree new spoke to spoke connectivity over the secondary connection. However it does not
I am using console server to connect to all my network gears such as Aruba, Cisco, FortiAll Aruba can use micro usb console and some usb-cAll new Cisco can use mini usb console and some usb-cFew Forti can use mini usb console SerialtoUSB converter already $8 (not including console cable)Good one generic micro usb cable only $2. 4x cheaper SUGGESTIONS:1. could you make all new Forti has microusb or usbc console tq
Hi!I have to renew or replace a Fortigate 400F cluster, that is working as ISFW.Looking at the specs, the 200G seems to outperform the 400F while being cheaper (more RAM, higher NGFW-throughput.Did I miss anything, or would you prefer to take a pair of 200Gs?Best wishes
I enrolled my forticlient with the EMS, it shows “connected”.When I try to connect to the VPN (SAML Login), it’s stuck “connecting”.Two problems come to mind:* It doesn’t show the SAML popup (auth through azure) as it does on windows.* when looking at service log, last line says /opt/forticlient/iked: invalid option -- 'P'I tried a number of things, starting the session with X or Wayland, no change, setting the open in external browser setting flag … with no success.Help
Hello Team I have configured ADVPN 2.0 between two 120G, BGP is up, i can ping both tunnels, but the issues are that i can ping the Hub loopback from the Spoke but unable the Hub loopback from the Spoke
The port switch connected to the ipphone and if i plug endpoint to the port of the ipphone then the port switch is shutdown even there are no port security in the port switch. Anyone know why?I can see the log from the switch Jul 20 14:30:13: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet2/0/1, new MAC address (f4a8.0d3d.5aeb) is seen.AuditSessionID 11C8640A000038317E6EAFB7 switchport access vlan 251 switchport mode access authentication host-mode multi-domain authentication order mab dot1x authentication priority dot1x mab authentication port-control auto authentication periodic authentication timer reauthenticate 180 mab snmp trap mac-notification change added snmp trap mac-notification change removed dot1x pae authenticator dot1x timeout quiet-period 10 dot1x timeout server-timeout 30 dot1x timeout tx-period 10 spanning-tree portfast
Hi everyone,I wanted to know if it's possible to manually edit these parameters on the unlicenced FortiClient (VPN Only) version for MacOS ?See the image below: In particular, I need to be sure whether the <eap_method>2</eap_method> parameter (which corresponds to EAP-TTLS/PAP) can actually be configured.I'd like to know if anyone on MacOS has managed to apply these settings, or if I'm forced to purchase the FortiClient Standalone Edition (the client doesn't have the option to buy an EMS server).For additional context regarding my question: currently, we have an IPsec Remote Access VPN setup using IKEv2 + LDAP + MFA (via SMS).Thank you all in advance.
Why link status for each port is different between the device and fortinac? On the device port g1/0/27 - 31 is up but in the NAC is different
Can we identify how many users is active and authenticated to fortinac?
Hello everyone,I'm currently trying to integrate Cisco ISE with a FortiGate firewall for Captive Portal authentication, and I'm running into a couple of issues.FortiGate Network Device Profile In Cisco ISE, I cannot find a FortiGate Network Device Profile when adding the FortiGate as a Network Access Device (NAD). Is there an official FortiGate device profile that needs to be installed, or should I use a generic RADIUS device profile instead? Redirect ACL in Cisco ISE For the authorization profile used during captive portal authentication, Cisco ISE typically requires a Redirect ACL (DACL/ACL). Since the FortiGate is performing the captive portal redirection, what should be configured for the Redirect ACL in Cisco ISE? Should I leave it empty, create a permit ACL, or is there a FortiGate-specific configuration required? If anyone has successfully integrated Cisco ISE Guest/Captive Portal with FortiGate, I would really appreciate it if you could share how you configured it, includin
Hi Everyone,I am currently working on a FortiNAC deployment integrated with Cisco switches and FortiGate firewall, and I would appreciate some advice regarding the captive portal/isolation VLAN configuration.Environment: FortiNAC version: 7.6.x Cisco access switches FortiGate firewall acting as gateway 802.1X + MAB environment Isolation VLAN configured for unknown/non-domain devices Objective:When an unknown or non-domain device connects to the network: Device should fail 802.1X Fall back to MAB Be placed automatically into the isolation VLAN Receive an IP address Open browser and get redirected to FortiNAC captive portal Current Situation: VLAN assignment is working Device is successfully placed into the isolation VLAN Client receives IP address when DHCP is provided by FortiGate Browser can partially reach the FortiNAC isolation portal However, the captive portal redirection is not fully working correctly.Issues Observed: DNS resolution problem Client cannot re
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.