Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Is there a method to update a batch of FortiWiFis using a TFTP server?I know i can use a TFTP server to recover bricked FortiWiFis, but is there a method or tool that does the same but for a batch of FortiWiFis?In my case I want to update as many as possible and then put them aside as stock for future device deployments. And so I think adding them to FortiManager is. not ideal. Basically I intend to downgrade from 7.0 as that is what they now come out of the box to 6.4.14.
Hello,I’ve trying for a long time this kind of upgrade.GUI doesn’t upgrade, and i tried using CLI i got this error.After updating the linux package i got this another one.I’ve seen this Bulletin → CSB-260410-1In my case, i installed this EMS as VM not using Linux, so i can’t make any changes in the Linux shell as it says.Could anyone help me?thank you
IntroductionAre you alerted when or if a rogue AP broadcasts your companies SSID? Are you alerted when or if large volumes of de-authentication packets are sent to your wireless clients? These are some questions I've been asking recently as I've researched WIDS and how Fortinet can help. This isn't really a support request for the forum; it's more of an information sharing post for those interested. Generally, most wireless deployments I see using Wireless Intrusion Detection Systems (WIDS) or Wireless intrusion Prevention System (WIPS) are using default vendor setting rather than fine tuning the settings to suite your business needs or align with your company cyber security policies. In some cases, WIDS may be disabled all together due to concern of resource usage on the AP hardware itself or limiting the available radios of the AP by using radios as dedicated monitors. Most of what can be found via a quick google search regarding wireless security is more centered around u
On FortiAnalyzer, the devices added under Device Manager show "Last Log Time: N/A". However, when checking the dashboard, logs appear to be arriving normally. At the same time, the Log Viewer cannot be opened, and the Reporting section is also inaccessible.The currently used version is 7.4.2, and it seems that there are known issues related to this behavior in this release. Could you please confirm whether this is a known bug and advise on any available workaround or recommended upgrade path?
Has the problem with FortiClient VPN for Android been fixed? v7.6.5 causes Error: Could not establish session on the IPsec daemon'. This was reported months ago and now we are being told we have to go to 7.6.7 to remain compliant.
Hi,after installing the FortiClientVPNSetup_7.4.3.4726_x64.msi with option “Enable Local Lan” and after established ipsec connection the client loose connectivity to local installed HP Network printer with address 192.168.8.105 (pings are not working, and all prints stay in the queue).After disconnect from the tunnel printer is working ok.I see on print route something like this: Config of the tunnel:
Hello Guys,i’m moving from a Fortigate 500E to a 400F and need to copy all the configuration through Fortimanger (version 7.4.10).The customer is using the Vpn Manager tool on Fortimanger to manage all the Vpn, where i’m stuck, is that i can’t understand where i can add the new firewall to setup the vpn.I’m only able to edit the existing tabs but not able to insert the new firewall, how can i do it?I’d like to do something like for the policy package, insert the new firewall in the installation target and fortimanger will install everything smoothly.For now i’ve imported all the vpns configuration manually via cli, but would like to allign the vpn manager…..Any tips? Thank youRegards
Hello everyone, I would like to know if there is an available read only demo for FortiSASE, i would like to see whats on the interface, the available functionnalities etc. BR,
Hello everyone, Fortinet used to provide demos of Fortinet solutions in read-only mode. You would simply submit your information and receive the access credentials by email. However, for the past couple of months, I’ve no longer been able to do so.I always receive the automated email saying :“We've received your request for a product demo! A Fortinet sales rep will contact you soon to confirm your demo and find a time that fits your schedule.”But after that, I never get any follow-up or credentials.Could someone from the staff please confirm whether the read-only demos have been discontinued?Thanks in advance.BR,
Configs "RealVNC" or "fmwp" have been added without noticing. Such as..“RealVNC-Other”, “RealVNC-Web”, “RealVNC-ICMP”, and so on.“config rule fmwp FortiOS.SSL-VPN.Enc.Buffer.Overflow”, “config rule fmwp FortiOS.SSL.VPN.Custom.Information.Disclosure”. Why did this happen?
Hello, My Firmware is 7.4.11 I managed to get SSO authentication working correctly via EntraID. The last thing I wanted to do was connect it to the FQDN and run it via my own SSL certificate. I have the certificate imported and it works correctly on the Fortigate login page. I can't get this certificate to work on the authentication port. The default certificate is still visible.FortiGate-60F # get vpn certificate local== [ Fortinet_Factory ]name: Fortinet_Factory == [ Fortinet_Factory_Backup ]name: Fortinet_Factory_Backup == [ Fortinet_CA_SSL ]name: Fortinet_CA_SSL == [ Fortinet_CA_Untrusted ]name: Fortinet_CA_Untrusted == [ Fortinet_SSL ]name: Fortinet_SSL == [ Fortinet_GUI_Server ]name: Fortinet_GUI_Server == [ Fortinet_SSL_RSA1024 ]name: Fortinet_SSL_RSA1024 == [ Fortinet_SSL_RSA2048 ]name: Fortinet_SSL_RSA2048 == [ Fortinet_SSL_RSA4096 ]name: Fortinet_SSL_RSA4096 == [ Fortinet_SSL_DSA1024 ]name: Fortinet_SSL_DSA1024 == [ Fortinet_SSL_DSA2048 ]name: Fortinet_SS
I create intune policy to push 802.1x wired configuration but after more than one week the policy not pushed any devices. Anyinw know why?
Hello Fortinet Community,I would like to understand more about MFA implementation on FortiGate.When a customer purchases a FortiGate and the corresponding licenses, is any additional license required to enable MFA, or is MFA functionality already included?I would also appreciate clarification on the following points:What are the most common use cases for MFA in FortiGate environments? Is Active Directory integration required, or can MFA be deployed with local users as well? What authentication methods are typically used (FortiToken Mobile, email, third-party MFA, etc.)? Are there any limitations or best practices to consider when planning an MFA deployment?I am interested in hearing from community members who have already implemented MFA in production environments and can share their experience and recommendations.Thank you in advance for your insights.
I'm using a FortiGate device, but I can't make calls to others via Zalo. I can still send messages, upload files, and others can call me via Zalo. I've checked the logs and debugged, and everything seems to be allowed; there are no logs of rejected or blocked calls.The behavior: When I try to call someone, the call disconnects immediately.Can you give me some advice on this issue?
Hello Fortinet Community,I have a customer requirement regarding remote access VPN connectivity.My understanding is that FortiGate supports both SSL VPN and IPsec VPN for client-to-site connections. However, I have also seen recommendations to move away from SSL VPN in newer releases, and I am planning to deploy this solution on FortiOS 7.6.The customer's requirement is very specific: they want to ensure that only one concurrent VPN session is allowed per user account. For example, if a user connects through FortiClient using their username and password, a second person should not be able to use the same credentials simultaneously from another PC and establish another VPN session.Is this behavior supported natively by FortiGate/FortiClient? If so:Is there a specific setting to limit concurrent logins per user? Does it work for both IPsec and SSL VPN? Are there any best practices or recommended approaches to enforce this requirement?I would appreciate any guidance or configuration recom
I have a Fortinet 101F firewall setup with VPN IPsec running. I have a FortiVoice 101, and I want to setup Fortiphone Softphone through the VPN. The Fortiphone Softphone runs fine with the LAN network, but when I try logging in through the VPN. I need some guidance to get it implemented please.
I am working on establishing vpn from android device using forticlient app with no avail. However, everything works fine with windows 11 machine. Forticlient app version : 7.4.3VPN type : IKEV2 (EAP-MSCHAPv2 with Certificate as authmethod) Android Device: Honor MagicOS 8 (Android version 14) From the forticlient android, the error immediately shows "IKE authentication failed" where in fortigate debug last log says sent IKE msg (AUTH_RESPONSE). Appreciated any help on this, thanks
Hello everyone,I'm deploying 2 VPN configs in EMS to a group of devices, users have no control over Forticlient, I want to force connection to both VPNs automatically once connected to the network.It seems that only one VPN can connect automatically, while the user has to click on connect for the second VPN to come UP. Already enabled Multi VPN Auto connect option in Forticlient EMS but it has no effect (both VPNs are IKE v2)We are using Forticlient EMS 7.4.5 Any idea ?
Hi All,Has anyone noticed issues with IPSec site to site tunnels on 7.4.9?We have one vendor who has been working fine before we upgraded a couple weeks back to version 7.4.9 in our Azure FG. Oddly enough our one firewall in HQ location which still is on 7.2.12 works fine.When comparing the 2 tunnels from Azure FG and HQ FG doing pings to the vendor I noticed the HQ doesn't lose pings at all. Whereas the one in Azure will intermittently lose the pings and then come back on its own.VPN settings for both FGs are the same along with vendor side.Has anyone run into this so far? Any workarounds?Happy Holidays All!
good morning everyone, i have a fortinet 60F. unfortunately, a junior member did the upgrade from 6.4 to 7.15. when i try to log in console to fix it, i get this:▒▒▒▒▒▒▒▒ђ▒▒▒▒ѥ▒▒▒ɩ▒͕▒ѥ▒▒▒ɩ▒▒▒ѥ▒ѕ▒▒▒▒Ҫ▒▒▒▒▒▒▒▒▒▒▒ɂ▒▒▒▒▒▒▒▒▒ɥ▒▒յ▒▒▒ԕ▒▒ʥ▒▒▒▒▒▒х▒(▒ѥ▒▒▒饹▒▒▒ѕ٥▒▒▒▒a▒ѥ▒▒▒饹▒s▒L▒᱕▒͕▒▒▒▒▒ɢ▒▒▒▒ɂɕ▒▒墽▒▒▒▒▒˙▒▒▒Ʌѥ▒▒▒▒▒▒▒▒▒▒▒▒ѥ▒▒▒ɩ▒ʥѥ▒▒▒饹▒▒ɕ݅▒▒▒ɩ▒failed verification on /data/datafs.tar.gzfos_ima: System Integrity check failed....CPU5: stoppingCPU6: stoppingCPU1: stoppingCPU3: stoppingCPU7: stoppingCPU0: stoppingCPU2: stopping sadly, it keeps repeating this message and it doesnt let me type commands. any advice? i tried changing the speed and flow control of my console cable with no better result than this one. my current best settings are:speed 9600 - 8n1, no flow controls
Hi,according to this article: webpages blocked by DNS-Profile should be redirected to FortiGate DNS block IP 208.91.112.55 and display a warning like this:However in my config when I enter to category blocked on the DNS-Profile like “Games” then I have red certificate warning, the certificate isissued by Fortiguard SDNS Blocked Page:every clients PC have imported Fortigate_CA_SSL certificate in Trusted Root Certification Authorities store.How to restore this blocked page when webpage is blocked by DNS-profile?
I have a question, for NSE4 please.wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. Therequirement is that FortiGate sends DPD probes only when there is no inbound traffic.Which DPD mode on FortiGate meets this requirement?A. EnabledB. On IdleC. DisabledD. On Demand
Does FortiNAC 7.4.3 support Fortigate 8.0.0
I try to push 802.1x profile for wired connection from intune with below configuration but the profile not yet pushed even after more than 3 days.Anyonw know why?and for the client authentication should i choose PKCS or SCEP?
dear mam/sir, i need to upgrade the firmware of the fortinet this is my client’s fortinet to repair fortinet i want firmware of FWF40C3912006020 fortiwifi -40c thank you Tejesh Maharjan
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.