Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We need your urgent assistance in troubleshooting an issue with our ADVPN deployment.Network Topology1 Data Center1 Head Office6 Branch Offices (Total: 8 locations)We have configured ADVPN for Hub-to-Spoke connectivity. Initially, each spoke had a single leased line, while the hub had dual leased lines. Two Hub-to-Spoke IPsec tunnels were established from the hub side, and the spoke had a single ISP. This setup worked without any issues.Recently, we added a second leased line at every spoke site for redundancy. Now, each spoke has dual ISPs, and both Hub-to-Spoke IPsec tunnels are established successfully. Routing is configured using loopback interfaces over iBGP.Issue DescriptionThe issue occurs only when the old ISP at a spoke goes down and traffic fails over to the new ISP.Although the IPsec tunnels remain UP, Hub-to-Spoke communication becomes unstable. During failover, we observe the following behavior:Sometimes the spoke loses reachability to the Data Center Hub, while the Head O
I've noticed an extremely strange thing upon upgrading some test FortiGates to the new version 7.6.7: the upgrade goes fine, and the FortiGate is happily online and is routing/firewalling-just fine. However, when trying to load the GUI it is just a blank page.I can see the little favicon loading for the FortiGate login page, but its just blank otherwise. I can SSH in just fine, so that is good. I do not see any settings reset in global settings, and strangely going to the http login instead of https sometimes works (I have https redirect turned on).As the FortiGate seems to be perfectly fine otherwise, I thought I'd see if anyone else has experienced this?Also I have tried multiple browsers with privacy/incognito mode on, so I don't think it is a cache issue.
Hi,I’m using fortimanager provisionning template to manager my IPSec VPN.I’m create a template.In this template I create a IPSec tunnel (Phase 1 and phase 2) with a name like myipsec_model.To create a second Ipsec tunnel, I’m click on clone option. A new tunnel it created with this name : clone_myipsec_model.I can’t rename the new IPSec configuration. I cleck on rename button change the name but this one is not change.I’m use fortimanager 7.6.7.Thanks you for your helpRegardsStéphane
Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.Am I missing something in t
Hi All, VersionFortiGate-81F v7.4.8,build9191,260511 (FIPS-CC-74-8)FIPS-CC mode: enableFortiSwitch-148F-FPOE v7.4.8,build0929,250909 (GA)Security mode: none In our environment, Federal Information Processing Standards (FIPS) is required due to the contract we have. I have been running into the following issues while testing FIPS mode on our equipment.The FortiSwitches appear under Managed FortiSwitches. I can see the firmware version, status, and join time, but I cannot SSH into the switches from the GUI. It also does not show the Connecting From status or the switch IP address.Under FortiSwitch Ports, the port connecting the FortiGate and the FortiSwitch shows as down. When I assign a VLAN to a FortiSwitch port, the VLAN assignment is accepted, but it does not actually take effect on the connected device.However, from the FortiGate CLI, I can SSH into the switch without any issues. The switch status is visible, but it appears that the configuration is not being fully synchronized to t
I believe when we add the switch to the fnac for 1st time then fnac inventory will collect below data such as Name, Default Vlan, Current Vlan from the switch. When we have changes on the switch, example i make port description and change the default vlan then why in the fnac is not updated? Resync the interface is not helping
Hello, I would like to clarify the expected FortiGate behavior when a FortiGuard/UTM license expires. Our FortiGate 81F had a UTM contract that expired on August 6, 2026. A new license contract was purchased/renewed on Friday, but the new contract has not yet been activated. After the previous contract expired, Internet traffic through one of our existing firewall policies was blocked. Basic websites could not be accessed. The affected firewall policy had the following security profiles enabled: - AntiVirus - Web Filter - DNS Filter - Application Control - IPS - File Filter When we disabled these security profiles, Internet connectivity immediately returned to normal. Fortinet Customer Service stated in the support ticket: “internet connectivity will not be affected due to the absence of a license.” They also stated that basic firewall policies that do not rely on subscription-based security services should continue to function. Therefore, I would like to understand the technical behav
I would like to understand whether the following design is possible and, if so, how it can be configured on a FortiGate 200F or 600F.Current Topology:FortiSwitch 124F ── FLINK_INET_1 ────┐ FortiGate 200FFortiSwitch 548D ── fortilink ───────┘FortiSwitch 124F-POEVLAN 700 configured with IP address 11.11.11.1/30Connected to FortiGate 200F via a FortiLink-enabled interface i.e FLINK_INET_1.FortiGate 200FConnected to both FortiSwitches using separate FortiLink-enabled interfaces.Requirement is to configure VLAN 700 as a Layer 2 bridge only, without Layer 3 routing on the FortiGate.FortiSwitch 548D-FPOEVLAN 700 configured with IP address 11.11.11.2/30Connected to FortiGate 200F via another FortiLink-enabled interface i.e fortilink.RequirementI need VLAN 700 traffic to pass transparently through the FortiGate 200F, effectively allowing the two FortiSwitches to communicate as if they were on the same Layer 2 VLAN.QuestionHow can VLA
Hello,I am experiencing a Security Fabric GUI issue on a FortiGate HA cluster after an HA failover and failback.Environment:- Root FortiGate: FortiGate 101F HA Active-Passive cluster- FortiOS: 7.4.11- Five downstream FortiGates- All FortiGates are running FortiOS 7.4.11- Security Fabric uses TCP/8013Issue timeline:1. Before the HA event, the original primary FortiGate displayed all downstream FortiGates correctly in the Security Fabric device dropdown and topology.2. The original primary FortiGate was powered off.3. The secondary FortiGate became the new primary.4. Immediately after logging in to the new primary, the Security Fabric device dropdown already displayed "No topology devices", and the topology could not be displayed correctly.5. The original primary later came back online and became primary again.6. The issue remained present after the failback.7. However, when logging in directly to any downstream FortiGate, the full Fabric Root and downstream device list is displayed corr
Hello, I am able to configure OSPF over IPSec tunnel, but: - I have another OSPF interface (through a physical interface) with lower cost that is Up and routes in the routing table are using this preferred link with correct cost.- When the IPSec tunnel comes Up, the routing table is modified; routes are now using the IPSec interface although I have defined a higher cost for the VPN interface... looks like something is forced. Has anyone come across a similar situation? Thanks, Monty.
When I attempt to Telnet into a Cisco switch located downstream of a FortiGate 50G (FG-50G), the Telnet connection fails.However, through cross-testing, I discovered an odd workaround: Whenever I modify any Firewall Policy on the FG-50G (even an irrelevant change, such as removing a service from a disabled policy), the previously failed Telnet connection to the downstream switch suddenly starts working normally.Unfortunately, if the system is left idle for a while, the Telnet connection issue returns.Network Architecture & Environment Setup Upstream & Downstream Switches: Cisco switches, connected via LACP configured to allow all VLANs. Plaintext interface Port-channel1 switchport mode trunkend FortiGate 50G: Configured in Transparent Mode. Aggregate Interface Configuration: edit "downlink" set vdom "root" set allowaccess ping https ssh snmp radius-acct set broadcast-forward enable set l2forward enable set stpforward enable set type aggregate set me
Hello. I have some Ubuntu 26.04 servers configured in FortiPAM. When I set up Web-SSH access, I enable the "SSH auto-password" option so that FortiPAM can pass the password when I connect and need to run a "sudo" command. The problem is that with this version of Ubuntu, FortiPAM does not pass the password.
Good morning teams 😊;For FortiClient EMS Trial, I created an IPsec VPN tunnel.However, I cannot export the XML configuration file with the VPN password included.Is there a way to export the VPN XML configuration with a password?What I would like is that when the user imports the XML configuration file (with forticlient) , they are required to enter a password before they can access the VPN.thanks for you support 😊
Hello PAM adminsFortiPAM 1.4.1.I'm very new in FortiPAM and I have questions regarding Web launcher.When I'm in company's local network all works fine, Web launcher, RDP launcher and SSH launcher.However when I'm outside and connect from public IP and try run Web launcher it doesn't work, while SSH launcher and RDP launcher still work fine.I noticed that for both RDP and SSH launcher, PAM opens the browser tab with address bar contains a public address like https://pam.mycompany.com/someaddress.While for Web launcher it opens the private IP of the target, which naturally can't work from WAN without some proxy on the client.If I'm not wrong I think it needs FortiClient in order to work, right?So my question:Does it work with FortiClient for Windows, Linux & MacOS?Does it require EMS?Is there a plan to make it work in future release without FortiClient? (other PAM products can do it without agent)
We encountered some issues accessing some URLs after upgrading from 7.2.12M to 7.4.12M using FGT401E on HA.applications like MS Teams get disconnected suddenly and users reported that access to some external portal become very laggy.upon checking the traffic log, we noticed that the Application name was classify as 2x which is a service group in our firewall.under this group, there is HTTP, HTTPs, TDP, 2X publishing agent port and 2X terminal server agent port.due to the many issues encountered, we have rollback to 7.2.12M
We have identified duplicate endpoint entries in our EMS console and, to manage them, we created two separate groups: one group in Domain and another group in Workgroup.We are able to delete the endpoints that are listed under the Workgroup group without any issues. However, for the endpoints that are present in the Domain group, we do not see an option to delete them. Additionally, we are unable to move these endpoints from the Domain group to the Workgroup group.Could you please let us know:Is there a way to delete the endpoints that are currently listed under the Domain group in the EMS console? What is the recommended process for moving endpoints from the Domain group to the Workgroup group?Any guidance or best practices to resolve these duplicate entries would be greatly appreciated.Thank you.
When i have a new ipphone connected to the network then fnac will move this ipphone to registration vlan before device profiling is running. After device profilling run then i can see the ipphone move to host role ‘IP Phone’ and registered’But after the devices was profiled then how the vlan can be changed automatically to voice vlan? The only way the ip phone get the voice vlan after the ip phone registered by profiling is reboot the ip phone.
Hi everyone,I am attempting to set up a new IPsec VPN connection using the standalone FortiClient VPN only v7.2.1.0779 app, but several configuration options appear to be missing from the user interface: Missing Single Sign-On (SSO): When creating an IPsec VPN profile, there is no option or toggle for Single Sign-On (SSO / SAML) anywhere in the GUI. Missing Mode Config Parameters: Under Address Assignment, selecting Mode Config does not reveal options for Encapsulation, IKE UDP port, or IKE TCP port. Any insights or guidance would be greatly appreciated. Thanks!Missing option in my appSSO setting i expectedMode configuration setting i expected
My Fnac license 106 is in use, how we can know detail which endpoint is consume the license?
hello everyone,i am setting up a home lab and recently acquired a fortigate 60d rugged.i tried to reset it using coolterm on my mac and after the proccess it just got stuck on system halted, now its “bricked”i am trying to find a way to get it back up and running and i am fully aware that this product is an end of life model. tried also customer service and dident help. any help will be great!
So i m doing a demo for a project i m doing for a client and i activated the free trial doe 200f series fortigate that work as HAtransfered the assets into another forticlould account but the ems free trial is still on the older accountCan anyome help me with this please an is the free trial can be activated just once even if i move the fortigateCan i remove the trial from the old account and activate on the new oneAny help is apperciated because i m stuck now and been ike this for 2 days
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
I upgrade our fortigate to v7.6.7 and after upgraded then the web admin gui if use mgmt ip address can’t be accessed from advpn, only can be accessed from local site and from hub only. If i using lan ip (not mgmt) then i can access. Anyone know why?SSH to the both port (mgmt and lan) is working fine.
Hi, we were an on-prem only company. Earlier this year we went hybrid with 365.For VPN earlier we had our clients connecting through forticlient with AD credentials leveraging RADIUS. No MFA.We then configured a parallel setup using IPSec ike v2 and authentication with EntraID, adding the MFA feature then.My question is: is this the natural approach that most of the former on-premise companies adopt once moved to Cloud or are there other suggested setups, maybe leveraging already existent on-premise RADIUS infrastructure?
We can select 802.1x authentication set to user or computer if we use wired. How about for wifi? There is no option to select that option on the wireless card properties.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.