Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I've been tossing around the idea of doing a series of posts, maybe bi-weekly or monthly, highlighting a Fortinet product that isn't as well known... before I start putting in a bunch of work on this, is there an appetite for it? It would probably be pretty high level, but I run into situations all the time talking to customers about projects/concerns and mention a product in the FortiVerse they didn't know existed.
Hello Wi-Fi adminsThis tech tip explains how to allow a VPN user change his LDAP password when it expires.I tried do the same for my Wi-Fi (managed FortiAP), same described config on FGT and FAC, but when user with expired password tries to connect it just fails to connect, and FAC shows the following message.Windows AD user authentication from (null) (mschap) with no token failed: user password change requiredThe user password must be changed before logging on the first time. (0xc0000224)Any idea what I might have missed?
Hi,I've been setting up alot of Forticlient with SSL-VPN but now when it's depricated I've need to set it up with IPSEC.When doing the SSL-VPN option we had the possibility to map different usergroups to different IP subnets with the "SSL-VPN Portals".Is there a way of doing this with IPSEC VPN?What I want to accomplish is to have Forticlient users connected to a central FG and that FG works as the HUB in a HUB n SPOKE topology.At the spokes be able to assign different firewall policys based on source IP subnet.
Hello,I am reviewing the FortiOS 7.6 administration guide regarding inspection modes (pages 233–234), and I need clarification on the following point:The documentation states that proxy-based mode provides more feature configuration options and is security-focused, while flow-based mode is designed to optimize performance.However, it also mentions that flow-based mode can consume more CPU cycles than proxy-based mode in some cases, which appears contradictory: page 233 ..... While both modes offer significant security, proxy-based mode provides more feature configuration options,while flow-based mode is designed to optimize performance .....If security is your priority, proxy-based inspection mode—with client comforting disabled—is more appropriate.If performance is your top priority, then flow-based inspection mode is more appropriate..........page 234 ...... Because the file is transmitted at the same time, flow-based mode consumes more CPU cycles than proxy-based mode. However, depe
Hello, I am reading the FortiOS admin guide and I saw that the antivirus checking order is:Antivirus local database → EMS threat feed → external malware blocklist → FortiGuard outbreak prevention databaseBut I have a few questions.1. What about the other inspection engines?Where do the following fit in the inspection flow?Content Disarm and Reconstruction (CDR) Behavior-based detection CIFS/SMB scanning AI/ML detectionMy question is:👉 If a file is NOT detected by:signature-based AV database EMS threat feed external malware blocklist outbreak prevention / hash reputationthen will FortiGate check the engines above afterwards?Or do these engines run in parallel / separate pipelines?What is the actual processing order?2. Signature-based detection clarificationThe guide says:“Antivirus scan detects viruses that are an exact match for a signature in the antivirus database.”So I want to confirm:Does “signature” here mean a hash value (exact file match)? Or is it a pattern-based rule (byte se
I just installed FortiClient VPN only.But when I press the three-line menu, I only see the interactive option "View the selected connection," so I'm blocked from manually adding or editing connections.I've tried uninstalling and reinstalling it, using administrator privileges, and even deleting any trace of a previous version that might exist for some reason.It still doesn't work.I would appreciate your help.
Hi everyone,We are troubleshooting a FortiGate-6000F running FortiOS 7.6.6 build3652 GA.Two FPC blades, slot 2 and slot 3, are stuck in Dead state with:Status Message: "Waiting for configuration sync."Heartbeat Data: FailedThe other FPCs are working normally.Current load-balance statusFortiGate-6000F (global) # diagnose load-balance status==========================================================================MBD SN: F6KF30T018900031 Primary FPC Blade: slot-1 Slot 1: FPC6KFT018900628 Status:Working Function:Active Link: Base: Up Fabric: Up Heartbeat: Management: Good Data: Good Status Message:"Running" Slot 2: Status:Dead Function:Active Link: Base: Up Fabric: Up Heartbeat: Management: Good Data: Failed Status Message:"Waiting for configuration sync." Slot 3: Status:Dead Function:Active Link: Base: Up Fabric: Up Heartbeat: Management: Good Data
Hello all, I am looking for some assistance regarding using AD groups in EMS policies. My scenario is as follows: I have created a security group for people allowed to use dropbox and configured the web filter and application filter appropriately. I have also created a security group to be allowed to use certain AI applications only and configured the filters appropriately. Based on what I have read is where I am hitting an issue: “Priority-Based Evaluation: EMS typically allows administrators to assign priority levels to different policies. If a user belongs to multiple groups (e.g., both "Standard Staff" and "Remote Workers"), EMS applies the configuration set by the policy with the highest priority.”If reading this correctly, if I am a member of both security groups, I will use the first policy I match with highest priority. So if I put the “allow dropbox” rule first that also blocks the AI Apps, I will not hit the “allow AI apps profile” that follows. Is there a way to control this
Hello,I have been trying to get into the FortiEDR Workflow, but I can’t seem to create or manage the Collector Groups in the FortiEDR Cloud with a FortiEndpoint license. I know that FortiEndpoint EDR is different from the normal FortiEDR, but I have not found a document which said you can’t manage Collector Groups with FortiEndpoint EDR. Even the Administrator Guide for FortiEndpoint does not mention that you can’t configure Collector Groups.
I work for a school that is requesting us to block the Fornite game from being played. However it appears using the Web Filter and reclassifying the Epicgames.com URL only solves users from browsing to that website. I am trying to block the Fortnite game from connecting to the EpicGames servers, It appears they use Amazon Web services which seems to be tricky when blocking applications. I do see that Fortinet has Epic.Games listed as an Application finally. I have blocked this under application control, now half of the students that try to play cant and the other half still can. I'm new to this stuff so this has been a fun experience. Any one have any luck blocking this? If so what did you do to achieve this?
Hi All, I have issue with F50G automatically upgrade to the latest patch 7.4.11 to 7.4.12 while the contract is expired.It keep sending Email with message “This installation is forced and cannot be cancelled”. It has failed to install multiple times and keeps rescheduling. I checked the system events, which show that the download failed. Do you have any ideas on how to fix this?I tried with this guide , and no lucks.https://docs.fortinet.com/document/fortigate/7.4.11/administration-guide/320693/required-firmware-upgrades-for-fortigate-appliances-with-invalid-support-contracts-or-that-have-reached-eoesDiagnose log:[989] fds_load_upg_matrix_map_img_id: Same major.minor: Patch 11 leads to Patch 12[999] fds_load_upg_matrix_map_img_id: Auto-upg chooses patch 7.4.12 (b2902)[1002] fds_load_upg_matrix_map_img_id: This upgrade will not be forced upgrade[989] fds_load_upg_matrix_map_img_id: Same major.minor: Patch 10 leads to Patch 12[1013] fds_load_upg_matrix_map_img_id: Auto-upgrade has chosen
Hello,I would like to know whether it is possible to activate service contracts for two FortiGate 121G devices in the same HA cluster using different licensing methods.One device already has an active traditional UTP contract, while the other device's contract has expired. I would like to activate a UTP bundle for the second unit using FortiFlex tokens.Is this configuration supported?Thank you.Farshid
Hi everyone,We are experiencing an issue with FortiClient VPN (free version) and wanted to check if anyone else has encountered something similar.Here is the situation:We have two computers in the same domain, on the same network, using the same internet connection. The same security and domain policies apply to both machines. They are connecting to the same IPsec VPN tunnel using the same user account.One machine connects without any issues, while the other consistently gets stuck on “Connecting” and eventually the application has to be killed from the process.We have tested multiple versions of FortiClient (7.4.0, 7.4.2 and 7.4.3), but the behavior remains the same.We also contacted Fortinet support, and they confirmed that the issue is most likely related to the FortiClient application itself. However, since we are using the free version, they are not able to escalate the case further.Additional note: the same issue occurs with different user accounts and from different networks (tr
Hi, The security auditor came to our office to check the Firewall Policies. The guy suggests to configure the Firewall Access Rule to "DROP" the unwanted traffic instead of "DENY". When setup Firewall Access Rule, I can select "ACCEPT" or "DENY" only. Is it possible to configure the Fortinet Firewall do "DROP" instead of "DENY" ? Regards,
Hi All,Long back I was using fortigate 600C firewall. Now i want to login that device. but i have no password.So, for resetting the configuration it require TFTP along with suitable firmware. based on boot-louder.But while re-loading the firewall, could not see Boot-room version, Only i can see below. HOSTNAME login: FortiGate-600C (15:49-10.24.2012)Ver:04000010Serial number:FG600CXXXXXXX. Please anyone can help for resting the configuration and is there any better way for the same.
How to apply the Replacement Message in Security Profile in your Policy when accessing the blocked websites?
Is there a method to update a batch of FortiWiFis using a TFTP server?I know i can use a TFTP server to recover bricked FortiWiFis, but is there a method or tool that does the same but for a batch of FortiWiFis?In my case I want to update as many as possible and then put them aside as stock for future device deployments. And so I think adding them to FortiManager is. not ideal. Basically I intend to downgrade from 7.0 as that is what they now come out of the box to 6.4.14.
Hello,I’ve trying for a long time this kind of upgrade.GUI doesn’t upgrade, and i tried using CLI i got this error.After updating the linux package i got this another one.I’ve seen this Bulletin → CSB-260410-1In my case, i installed this EMS as VM not using Linux, so i can’t make any changes in the Linux shell as it says.Could anyone help me?thank you
IntroductionAre you alerted when or if a rogue AP broadcasts your companies SSID? Are you alerted when or if large volumes of de-authentication packets are sent to your wireless clients? These are some questions I've been asking recently as I've researched WIDS and how Fortinet can help. This isn't really a support request for the forum; it's more of an information sharing post for those interested. Generally, most wireless deployments I see using Wireless Intrusion Detection Systems (WIDS) or Wireless intrusion Prevention System (WIPS) are using default vendor setting rather than fine tuning the settings to suite your business needs or align with your company cyber security policies. In some cases, WIDS may be disabled all together due to concern of resource usage on the AP hardware itself or limiting the available radios of the AP by using radios as dedicated monitors. Most of what can be found via a quick google search regarding wireless security is more centered around u
On FortiAnalyzer, the devices added under Device Manager show "Last Log Time: N/A". However, when checking the dashboard, logs appear to be arriving normally. At the same time, the Log Viewer cannot be opened, and the Reporting section is also inaccessible.The currently used version is 7.4.2, and it seems that there are known issues related to this behavior in this release. Could you please confirm whether this is a known bug and advise on any available workaround or recommended upgrade path?
Has the problem with FortiClient VPN for Android been fixed? v7.6.5 causes Error: Could not establish session on the IPsec daemon'. This was reported months ago and now we are being told we have to go to 7.6.7 to remain compliant.
Hi,after installing the FortiClientVPNSetup_7.4.3.4726_x64.msi with option “Enable Local Lan” and after established ipsec connection the client loose connectivity to local installed HP Network printer with address 192.168.8.105 (pings are not working, and all prints stay in the queue).After disconnect from the tunnel printer is working ok.I see on print route something like this: Config of the tunnel:
Hello Guys,i’m moving from a Fortigate 500E to a 400F and need to copy all the configuration through Fortimanger (version 7.4.10).The customer is using the Vpn Manager tool on Fortimanger to manage all the Vpn, where i’m stuck, is that i can’t understand where i can add the new firewall to setup the vpn.I’m only able to edit the existing tabs but not able to insert the new firewall, how can i do it?I’d like to do something like for the policy package, insert the new firewall in the installation target and fortimanger will install everything smoothly.For now i’ve imported all the vpns configuration manually via cli, but would like to allign the vpn manager…..Any tips? Thank youRegards
Hello everyone, I would like to know if there is an available read only demo for FortiSASE, i would like to see whats on the interface, the available functionnalities etc. BR,
Hello everyone, Fortinet used to provide demos of Fortinet solutions in read-only mode. You would simply submit your information and receive the access credentials by email. However, for the past couple of months, I’ve no longer been able to do so.I always receive the automated email saying :“We've received your request for a product demo! A Fortinet sales rep will contact you soon to confirm your demo and find a time that fits your schedule.”But after that, I never get any follow-up or credentials.Could someone from the staff please confirm whether the read-only demos have been discontinued?Thanks in advance.BR,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.