User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Dear community, I need you support on the following itemsI have been asked to configure link health monitoring for our networks, now I have already setup the Performance SLA using ICMP Ping to check if the link is up and/or down. this will check if the link is up alright, now if the link goes down then using the SD-WAN rules the connection should swing the other ISP link and avoid any distruptions that might happen or it should not require manual switch.Now first question is here that what do you suggesst be the minimum link status to avoid any kind of routing issues later  Now the second issue is that when configure SD-WAN rules which interface selection strategy should I use because when I read through the docs they mentioned to use the Manual but it does not allow for selecting any SLA rules you have configured, now out of the Best Quality and Lowest cost which one should I use?Can you please advise on this as well.  I am looking forward to hearing from you.  Best Regards,Shah.
Forti voice is 7.4.1 Is there a way to mass or change the 4 digit caller ID when doing local calls to other 4 digit extensions?i.e. I have 2 front Desk Phones both have Primary Extension (Main Phone and Aux Phone) 1234 and then have the Departments line 4444 has a SLA.When they call from these phones to just a 4 digit internal extension Caller ID shows ‘Desk Phone 1234’, I would like to hide the 1234 and just have Desk Phone show up, since everyone knows to just call 4444 locally to get to the front desk. Having 1234 show up can be confusing.  I cant make the 2 desk phones just 4444 because placing calls on hold doesn't show up on AUX phones or any other phones that might also have that SLA mapped.  We also plan to always have call forwarding enabled on 1234 to 4444, but I still would like to completely hide the number if possible. Â
Dear Security Team,We respectfully request that you review our domain and remove it from your blacklist if appropriate.We have completed a comprehensive security audit of our website and have fully resolved all previously identified security issues. All malware, malicious files, and any potentially harmful content have been completely removed.In addition, our website has been scanned by multiple trusted security services, all of which confirm that the site is clean and free of malware, phishing, and other malicious activity. Google Safe Browsing also reports our domain as safe and does not detect any security threats.We kindly ask you to re-evaluate our domain based on its current clean status and update its reputation accordingly.Thank you for your time, consideration, and assistance. We appreciate your review and look forward to your response.Best regards,Website Administratorhttps://dorottyanadorfi.com/ https://lantosfestes.com/ https://dirdurr.eu/ https://balanceyourlife.hu/ ht
I have a bridged AP that is tied to the DATA interface that cannot get to the Internet. The DATA interface works for the ports on the switch with no problem.
Does Fortitoken MFA support the server that running on Windows server 2012?
Now i have Fortinac with version 7.6.5 Fortinac-os and i have agent is 9.4.0.93 i need to know if this is most suitable version for agent or not and if i plan to upgrade it what should i do if i made in the scan policy check latest persistent agent and i also edit the registery key of LoginDialogDisabled
I use persistent agent to checking antivirus on the client before the client can connect to the network.My question is what parameter will be checking by PA? Is antivirus realtime protection is on/off, is antivirus batabase signature updated or not, or something else?
Hello dears,I hope you are all doing well.I am facing an issue with FortiClient VPN in our organization. Every time an employee tries to open FortiClient, they are prompted to enter administrator credentials.Has anyone encountered this issue before or knows how to resolve it?Â
Hello,I am connect to mobile hotspot rogers and my internet speed is very very good no doubt. I did every thinh minimize the wifi MTU in laptop. disable ipv6 and other stuff but still after 98% it restarted.Need urgent help in that please. Thank you,
good morningThe requirement is to create two physical ports for the firewall: one dedicated to the entire internal network, from which all data flows, and the other one dedicated solely to the Fortigate firewall's settings, updates, databases, and communications with its servers and online services.How can I properly isolate these two ports to prevent any data leakage from the first port to the second? Can I get a detailed, practical guide to the process?
Hello everyone,I'm experiencing an intermittent issue with an IPsec Remote Access VPN.The VPN tunnel establishes successfully (IKE and IPsec SAs are up), and the client authenticates successfully. However, in some cases:TX (sent) packets increase normally. RX (received) packets remain at 0 bytes / 0 packets. No internal resources are reachable.One interesting observation is that the issue depends on the ISP. If I switch to another Internet provider, the VPN works immediately.A few months ago, I had a similar issue that was resolved by setting the MTU to 1350, but this workaround no longer solves the problem.I have reproduced the same behavior with:FortiGate 7.4.x FortiGate 8.0.0This makes me suspect an MTU, fragmentation, or ISP-related issue, but I'm not sure where to investigate next.Has anyone encountered a similar behavior?
Setting up new Fortigate and prefer to start from scratch as old gate was breached several times most recently during the SSO vulnerability and changes were made. Instructions that I could find recommended deregistering and wiping configuration on the old gate and resetting and programming on the new gate or transferring the relevant configuration to the new gate. Is it possible to leave everything as is on the new gate, wiping switch and ap (resetting) and then attach to the new gate and setting up from scratch or will the fact that it is still set up on the old gate interfere with the process? Would just prefer that I have the option to put them back on the old gate if I run into difficulties with the new set up. Clearly not a network engineer! Rolling back to 7.4.12 on new gate because of glitchiness on 7.6.7 and switch is on 7.6.6 and ap is on 7.6.5 - should I drop back firmware on switch and ap when I transfer them?
Forticloud Support gave me this as a solution: Well, this did NOT work. Could anyone here provide a solution/fix for this?Can this be ignored?Will it have impact on performance?How can one reduce the amount back to max 110?How can i prevent further growth? N.B. I am seeing weird variations of a work email address, with different characters added in the email address itself thus creating multiple copies. For example: jbrown@work.edu.ca is the official email address. Now i am seeing in the FM cloud active user mailbox list j-brown@work.edu.ca, jbrown123@work.edu.ca , j.brown@work.edu.ca and it goes on and on for others. This is unacceptable.
Hi guysFGT A with WAN 1 and WAN 2 interfaces with direct public addressFGT B with only WAN1 Created nr 2 tunnel ipsecTunnel 1 = FGT A WAN1  to  FGT B WANTunnel 2 = FGT A WAN2  to  FGT B WAN Created policy and static route with administrative distance = 10 (Tunnel 1) and = 20 (Tunnel 2) When tunnel 1 is DOWN I get strange output on routing interface.Picture 1, static route works, I can reach LAN on FGT BPicture 2, static route doesn’t work, I can’t reach LAN on FGT B. I get strange IP address on static route, 10.0.04 is not public IP of FGT B Someone can suggest me any other checks?What could it be?
The FortiEMS server is running version 7.4.7, while the client version on the workstations and servers is 7.4.5.We plan to upgrade soon.In the clients' "Notifications" tab, I see many "Patching Failed" alerts.The installers were never created with the "Auto update to the Latest Patch" option enabled."Automatic Patching" is also disabled in the Vulnerability Scan settings.We never perform upgrades or patching automatically; we prefer to manage that process ourselves.So, what is triggering these "Patching Failed" alerts?Thanks
 URL: https://incoso.co.za/>> This is a false positive. incoso.co.za is the legitimate website of INCOSO (Inhouse Conference Solutions), an established South African event-management company operating since 2007, based in Bellville, Western Cape. The site contains standard business content only: company profile, services, portfolio, testimonials, and a basic name/email contact form. It has no login area, no password fields, and no payment processing, so there is no phishing surface.>> We believe the detection originated from Avast Web Shield running on the machine of the web administrator who deployed the site. During go-live there was a brief window before the site was fully configured and secured, and we believe Avast automatically sampled the site in that state and submitted it to your cloud database, classifying it before the finished, live site existed. The live production site has been complete and secure since launch.>> Avast/AVG is flagging both the homepage a
Hi community,i have in office Fortigate with ip public 87.xx.xx.xx, policy created for internet, I created in windows (PC office)- vpn client conection l2tp other ipsec for conect to mikrotik(home) ip public 193.xx.xx.xx .Issue is when i try to conect vpn windows(client) to mikrotik(server l2tp/ipsec) this conection is down ,but when i try conect pc office to hotspot vpn l2tp/ipsec  conection is  successfully to mikrotik.Can anybody help with this issue,why my pc canont conect l2tp/ipsec to mikrotik? beetwen MIKROTIK and FORTIGATE not set ,not config any vpn,mikrotik is outside, is in my home.Â
Hello Community, I hope you're well I stay in process to deploy Fortiweb 400 F, but I have doubts about whether it is advisable to place the Frontend and Backend interfaces in separate VLANs, and if you recommend this topology for a future deployment of Adoms, or if the design should be rethought.I attach the Topology.Greetings!!!!  Â
Can anyone confirm me if FortiGate 70G Firewall requires a separate license to operate or does the product comes with a base license when purchased new.
Hi FWB adminsAccording to FWB’s CLI ref we can access to traffic logs and attack logs via CLI.https://docs.fortinet.com/document/fortiweb/7.6.6/cli-reference/561209/logThe user is admin and its profile is prof_admin (has all rights).However when the mentioned command seems not available.fwb01 # diag log all startParsing error at 'log'. err=1Command fail. CLI parsing error.Any idea?
We manage a multi-branch network with FortiGates centrally managed via FortiManager, all running the same policy package. At specific branches, users attaching 2-3MB files to email through OWA (Outlook Web) experience 20-30 minute upload delays, while other branches on the identical policy are unaffected.Our SSL/SSH Deep Inspection profile already exempts the Finance & Banking and Health & Wellness categories, plus around 20 Microsoft/Outlook-related FQDNs. We confirmed via FortiManager that this exempt list is identical across affected and unaffected branches. Setting the policy to "No Inspection" resolves the issue immediately, confirming deep inspection is the cause.Since the exempt list is the same everywhere but the problem is branch-specific, we suspect some URLs or hostnames used by OWA for attachment upload (possibly Microsoft's Azure Front Door / M365 substrate/CDN endpoints, not just outlook.office.com) are missing from our exempt list and differ depending on branch e
I'm lab testing a few different ADVPN setups and noticed the Cross-regional spoke to hub shortcuts:https://docs.fortinet.com/document/fortigate/7.6.0/sd-wan-architecture-for-enterprise/242856/using-ibgp-between-regions-with-inter-region-advpnThe docs are missing at lot of details so I'm wondering if anyone knows how this dynamic tunnel from Branch 1 (Region A) to HUB in region B is created? Which tunnel interface is used on Region B HUB.Does the static VPN tunnel between the hubs need any ADVPN specific config rather than just standard static tunnels?I have dynamic tunnels working ok within the same region so I have a basic understanding of how the tunnel is formed. Just not clear on when it comes to Multi region, specifically the SPOKE to the HUB in the other region. Â
Hello, I opened a case with support asking about a 7.4.4 version of Forticlientvpn only for windows , they suggested we post here. My questions are:1) Is there a version of forticlient vpn only 7.4.4 coming out for windows?2) If no can you verify if forticlient vpn only 7.4.3 for windows is not susceptible to https://fortiguard.fortinet.com/psirt/FG-IR-25-685 Thanks!
We use the fortiPAM solution, but it only works in a web browser (so it won’t work on servers and will most likely be useless in this situation).Is there another way to grant access directly from the Linux console? For example:Would it be possible for the company to install FortiClient on Linux (Red Hat or Oracle Linux) and configure FortiGate to grant them access only to selected subnets?It’s the simplest idea I’ve come up with recently. Since FortiPAM is useless for running on a server without a UI, I suppose this would be the best solution.The only question is, will FortiClient work in such an environment?
current version start from 6.0.18My current version of FG-60E is 5.6.10Â how can I upgrade this to 7.4.11?there is no path of 5.6.10~6.0.18
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.