Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document LibraryThat last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registrat
Hi,FortClient for Android asks for “Overlay permissions” when starting the App during initial setup. For ZEBRA Scanners there is an option to pre-grant this permission via OEMConfig: Enabling Display Over Other Apps Permission via MDM/EMM OEMConfigTherefore, the “Package Signing Certificate Fingerprint” of FortClient App is required. Can you please provide is with this? Since the APK isn’t available for public download, it cannot be extracted via ZEBRA’s SigTools utility by customers.Thanks!
Hi,we have such problem that fortigate fortios 7.4.11 is blocking copilot.microsoft.com the error we get in the browser is:net::ERR_CERT_AUTHORITY_INVALIDSubject: Fortiguard SDNS Blocked PageIssuer: Fortiguard SDNS Blocked PageWhat we did:1.in DNS profile --> static filter we created:- wildcard name *.microsoft.com and allowed it-allowed regex .*bing\.com-allowed regex .*trafficmanager\.net2.In the deep ssl inspection profile, we created the exempts:-wildcard *.microsoft.com-wildcard *.bing.com-*.trafficmanager.netBut all the time, this site is blocked by SDNS, any help?
Hi,I'm new on Fortinet products recent I have obtained FCAI am preparing to take NSE4 exam(FCP)! Is it compassory to purchase both LAB and Instructor.led so as I can get my certificate after passing the exam?Thanks
Question: FIPS-CC is enabled. The interface is up. Why can’t I set allowaccess to permit https on port 1 for GUI access? The Background: I don’t have any FortiOS experience. I’ve been given a 71F to configure. The documentation describes enabling FIPS-CC, setting a new administrator password, and enabling the ports via config system interfaceedit internal1set status upend followed by changing the allowaccess attributes to add https via set or appendset allowaccess ping https Neither append nor set allow me to do so, and set ? doesn’t list allowaccess as an option. the internal1 (port1) was part of a virtual switch. i’ve since removed it: config system virtual-switchedit “internal”config portdelete internal1end a ‘show’ command after each ‘end’ reflects that the configurations were accepted - internal1 is up and removed from the virtual-switch. if i `show full-configuration system interface | grep -f internal1’, i get the following attributes. config system interface edit "internal1"
Good afternoonDoes anyone know what happened to the release of version 7.6.7? It was supposedly coming out on Thursday, May 21st, but it's already the 29th and there's still no news. I'm having the DNS proxy bug, so I absolutely have to stay on 7.6.4 and can't risk upgrading to 8.0.
Set up an Invitation to use (on-prem) Domain (LDAP) FortiClient Sign-in fails with this error : from EMS log :Registration attempt by Endpoint was denied due to LDAP authentication failure for user 'test-user'. Server: test.local, , Reason: Authentication error: User not found in DB with [test-user] The user is part an LDAP group that is AuthorizedAlso, The credentials work in Administration / Authentication Servers when tested Where have I gone wrong ? Thanks
Hello, is there any option to set QR Code URL Scan?we had today an incident, that e-mail was having a QR code which has leading to malicious webpage.is there any option to scan those images with QR code with fortimail?
Hello,I have configured a network share and would like any file added to the folder to be scanned automatically. I noticed that a schedule can be set, but the shortest available interval is every 15 minutes.Is there a way to configure it so that a file is scanned as soon as it is placed in the folder? Alternatively, can the scan be set to run every minute?Thanks
Hello,We have deployed EMS 7.4.7 and we need to deploy client to about 300 endpoints via Intune. But Im missing option to choose the Invitation code during installer creation. In creation is only option to “override invitation code during upgrade”. And under Invitation page when I create an invitation code it is not possible to link it to existing Forticlient installer. Is there a way how to do it? Main thing we are fighthing right now is that after installation of Client to endpoints, it is not automatically registered to EMS. I have found out this topic, where its said that we shouldnt using “enforce user verification” so I have disabled it. But still im confused about invitation codes.Thanks for help!
Hello, I’m applying to a few Inside Sales Representative roles at Fortinet and would like some insight when it comes to the interview process, culture in the sales org, how strict WFH/in office is, and anything of that mature.Context, I have just under one year of experience at a large VAR. Thank you.
Hi Everyone,I have some problem when integrating a standalone FortiSwitch (S148FFTF series) with Cisco ISE. During deployment, authentication was completely successful on Cisco ISE (Access-Accept returned), but the endpoint would fail to receive a DHCP address and drop into an "Unidentified Network" status.Environment Details Switch Model: FortiSwitch 148F (Standalone Mode) RADIUS Server: Cisco ISE Dynamic VLAN Assignement not work properly.
Hi Support, I would like to know where I can find an official UAT reference for the 2601F. The firewall has been mounted, and the customer performed the configuration themselves. Therefore, I will only perform a basic check and then submit a UAT report to the customer to close the project. Could you please provide any professional guidelines? Thank you.
Hello Fortinet Community,I would like to seek assistance regarding an issue I am currently facing with FortiClient IPSec VPN.My laptop is running Windows 11 with an Intel network adapter, using FortiClient version 7.0.14 managed by FortiEMS 7.0.13.The issue is as follows:SSL VPN connection works perfectly without any problems. However, when attempting to connect to an IPSec VPN, the connection fails with the error message: “IKE negotiation failed” / VPN connection failure.Interestingly, when I use the FortiClient free (standalone) version and import the same IPSec configuration file, the connection works successfully on both Wi-Fi and LAN.Other colleagues using the same EMS-managed FortiClient version are able to connect without any issues.Based on my initial observation, I suspected it might be related to the network adapter; however, this seems unlikely since the IPSec connection works correctly when using the free version of FortiClient.I would appreciate any insights or suggestions
I login to this portal (Fortinet Community) and the vertification code sent to the email. How i can change the vertification code from email to authenticator app?
We are working on replacing Aruba switches with FortiSwitches. We have HA firewalls and currently use a VLAN on the Aruba to pass the ISP link to the WAN ports on the firewalls. We've run into an issue at a couple of sites where the ISP device refuses to communicate with the FortiGate when passing through an unnumbered VLAN configured on the FortiLink connection. If we put the Aruba back in, the WAN links can then talk to the ISP gateway again. It's only happened at a couple of our sites, so I suspect it's specific to certain brand ISP devices. At the first site it happened at, we resolved it by moving the WAN IP to the VLAN Interface under Fortilink and eliminated the uplinks to the WAN ports. At the current site we're working on, there are hundreds of IPSec tunnels and policies tied to the WAN interfaces, so moving to a VLAN interface under FortiLink would be a time-consuming endeavor. Any idea on what may be causing this?
Hi Community I need to understand how to bypass microsoft.com from the SASE SWG proxy configuration. Thank you UdaM
the two FG in the cluster give the same role (primary) and same hostname, although the setting of HA is corectlysystem > HA, i see two serials, synced, mode is active passive, and priority is different
Hi,Recently we upgraded our FGT 200F from 7.4.7->7.6.4->7.6.6. In the new version we noticed that we lost Packets(sent/Received) and Errors(sent/received) FILTER options in FortiGate firmware version 7.6.6? we had this filter option in previous version 7.4.7.Can someone help/clarify why this happened, which we don't have any more this option and how we can add this feature back? I checked the known issue for 7.6.6 and changes in default behavior. Please find the attached photo which indicate that Packets(sent/Received) and Errors(sent/received) FILTER option disappeared.Thanks in advance!
Hello everyone,I would like to get some feedback from the community regarding a design decision between using a Hardware Switch interface or an LACP Aggregate interface in a FortiGate HA deployment.ScenarioI have two Active-Passive FortiGate HA clusters interconnected directly, similar to the topology below:The objective is to maintain connectivity during a failover event on either cluster while keeping the design as simple and stable as possible.Current DesignWe are currently using a Hardware Switch interface across the participating ports. The solution has been operating correctly and failover testing has been successful.QuestionFrom a Fortinet best-practice perspective: Would you prefer Hardware Switch or LACP for this topology? If LACP is preferred, would you configure lacp-ha-secondary disable on both clusters? Have you experienced any MAC flapping, convergence, or failover issues when using LACP directly between HA clusters? One of the reasons I am evaluating both options is
Hello fellow networking folks,I'm curious if anyone has had to pivot from FortiClient with the new Remote Access VPN setup on 7.6.x since they are basically forcing everyone to purchase EMS. Unfortunately we have to ask for $$ from the higher ups so I wonder if anyone has used / knows of a good alternative. I know that there is a free version but it seems that it is in the process of being grandfather'd out
I've been tossing around the idea of doing a series of posts, maybe bi-weekly or monthly, highlighting a Fortinet product that isn't as well known... before I start putting in a bunch of work on this, is there an appetite for it? It would probably be pretty high level, but I run into situations all the time talking to customers about projects/concerns and mention a product in the FortiVerse they didn't know existed.
Hello Wi-Fi adminsThis tech tip explains how to allow a VPN user change his LDAP password when it expires.I tried do the same for my Wi-Fi (managed FortiAP), same described config on FGT and FAC, but when user with expired password tries to connect it just fails to connect, and FAC shows the following message.Windows AD user authentication from (null) (mschap) with no token failed: user password change requiredThe user password must be changed before logging on the first time. (0xc0000224)Any idea what I might have missed?
Hi,I've been setting up alot of Forticlient with SSL-VPN but now when it's depricated I've need to set it up with IPSEC.When doing the SSL-VPN option we had the possibility to map different usergroups to different IP subnets with the "SSL-VPN Portals".Is there a way of doing this with IPSEC VPN?What I want to accomplish is to have Forticlient users connected to a central FG and that FG works as the HUB in a HUB n SPOKE topology.At the spokes be able to assign different firewall policys based on source IP subnet.
Hello,I am reviewing the FortiOS 7.6 administration guide regarding inspection modes (pages 233–234), and I need clarification on the following point:The documentation states that proxy-based mode provides more feature configuration options and is security-focused, while flow-based mode is designed to optimize performance.However, it also mentions that flow-based mode can consume more CPU cycles than proxy-based mode in some cases, which appears contradictory: page 233 ..... While both modes offer significant security, proxy-based mode provides more feature configuration options,while flow-based mode is designed to optimize performance .....If security is your priority, proxy-based inspection mode—with client comforting disabled—is more appropriate.If performance is your top priority, then flow-based inspection mode is more appropriate..........page 234 ...... Because the file is transmitted at the same time, flow-based mode consumes more CPU cycles than proxy-based mode. However, depe
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.