Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We are planning to migrate from SSL VPN to IPsec VPN using certificate-based (signature-only) authentication.Since the VPN will be used by both employees and contractors, we need to implement group-based policy controls similar to what we currently have with SSL VPN.I have configured the user peer with ldap-mode principal-name, which maps the certificate UPN to the LDAP user. This part is working as expected (if user is disabled, it won’t allow log in).However, I have not been able to get LDAP group-based matching working in firewall policies.I have 7.2.12 version at the moment, maybe newer version has this fixed?
Hello, I am preparing for my exam scheduled for July, but I am having trouble understanding this question. Could you please tell me the correct answer and explain why When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalidcertificate.Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate? (Choosethree.)A.AllowB.Trust & AllowC.Allow & WarningD.BlockE.Block & Warning
Hi,is any way to configure failed user login notification for dialup ipsec connection?For the ssl vpn failed login there is dedicated trigger name “SSL VPN login fail, ID 39426” and this is working fine, but I don’t have any similar for dialup Ipsec.This notification should only notify about wrong user password entered no matter is it authenticated using remote radius or this is local account on fortigate.I'm not interested in a log that reports the status of the phase1 as “failure,” because I have many other site-to-site IPsec tunnels, and that would cause confusion.Thanks.
How to implement of DNS and IP Address blocking in FortiGate?
Hi all, I hope you're well. I'm currently investigating some connectivity issues users are reporting on AVD displaying 'Paused Connection'. At this site, we're running FortiSwitch 448E-FPOE's and in the system events I am seeing many 'port has come up' and 'port has come down' logs. I've reviewed the spanning-tree instance and confirmed that it is stable, root bridge is correct, no recent TCN's and no high usage of system resources (CPU/Memory) noted. There are no FCS errors or any other stats on the physical ports that would suggest faulty cables. All ports connect to Cisco IP phones and from the logs it looks like the physical port flaps first which then triggered STP port status changes. I'm going to test bypassing the phone and connecting the PC directly to our FortiSwitch to rule out the phone causing the issue but wanted to know if there are any other troubleshooting steps I can take to identify the route cause. Many thanks,&n
Hello everyone,I'm working on a FortiGate device and need assistance with enabling communication between two interfaces on the same firewall. Here’s the network setup:Interface 1: Connected to the 192.168.1.0/24 network.Interface 2: Connected to the 172.16.0.0/24 network.Interface 2 also has an Access Point from Unifi connected to it, and I need this AP to communicate with the 192.168.1.0/24 network for remote management.I have already:Created firewall policies to allow traffic between the two networks. Both inbound and outbound rules are set to allow the communication.Set up static routes for both networks to ensure the traffic is routed correctly between the two interfaces:For the 192.168.1.0/24 network, I configured a route with gateway 192.168.1.1 and the interface set to Interface 2 (the one connected to the 172.16.0.0/24 network).For the 172.16.0.0/24 network, I configured the inverse: gateway 172.16.0.1 and the interface set to Interface 1.I also tested other variations, includi
Hii have fortigate 60f and fortiap 231k ios on fortigate 7.6.6i faced problem on ssid tunnel just lost connection and browsing But have ip on ios such as 7.4.11 no problem just 7.6.6thanks
Hi guys,Recently, i came across a technique called underminr which is a technique involved after domain fronting have been largely mitigated by several CDN provider. Reference - ADAMnetworks’ Research Uncovers Vulnerability in Internet Infrastructure, Affecting 88 Million Domains | MorningstarTLDR of the technique is as follows; exploiting the gap between the layers of a connection where different names live:DNS lookup / TLS SNI — uses an allowlisted front domain (e.g. a legitimate domain on a big CDN). This is typically what DNS filtering, proxy allowlists, and SNI-based inspection see and approve. HTTP Host header (inside the encrypted tunnel) — once TLS is established, the request is actually routed to a different backend on the same shared infrastructure — the attacker's real C2 endpointAnd the detection seems to require checking the DNS query and ensuring the thereafter TLS host header in the same session is the same as the DNS query which i believe FPX by right should have the ab
Hi, Does anyone experience based on this article?https://community.fortinet.com/t5/FortiGate/Technical-Tip-Understanding-the-log-message-User-shutdown-the/ta-p/301290 Scope is for 7.2.5 and above. The current version is 7.0.12 May I know if this is false positive? Thanks!
Hello,I am trying to assign a FortiToken Mobile to a local user via REST API on FortiOS v7.4.11 and getting error -651 "FortiToken is invalid".Environment:- FortiOS version: 7.4.11- Multiple VDOMs configured- Users are in VDOM "PO"- API admin profile scope: Global- API admin has User & Device: Read/WriteImportant note:We do not have direct access to the FortiGate GUI – only the customer does. Therefore we can only work via REST API and cannot verify the exact request that GUI sends when assigning a token.What works:- GET monitor/user/fortitoken?status=available → returns available tokens- GET cmdb/user/fortitoken/{serial} → works WITHOUT vdom parameter (root context)- GET cmdb/user/fortitoken?vdom=PO → returns empty / token not found- PUT cmdb/user/local/{login}?vdom=PO with two-factor: email → works fineWhat fails:- PUT cmdb/user/local/{login}?vdom=PO with fortitoken serial → error -651- PUT cmdb/user/local/{login} without vdom → HTTP 404 user not foundThe token exists in CMDB, st
Hi all, I am installing FortiNAC in a large environment and I added the Aruba WLC to FortiNAC without any issues. 3 days later, FortiNAC performed L2 pooling and discovered over 400,000 rogue hosts. After that, I disabled L2 pooling for the WLC, which stopped it from discovering.I use FortiNAC version 7.6.6 and have increased the VM to 16 CPUs and 32 GB of RAM.After that, I set the aging period to 1 day for the rogue hosts, but it did not work. I found this command, but it returned an error;> execute enter-shell# client -rog -op delete errorDuring this time, the FortiNAC RAM usage was at 92%, and the server was extremely slow.I could not find a way to get rid of these rogue hosts. While I was working, it did not affect the appliance, but when I configured PA for endpoint compliance checks, it did. While testing, I saw that many hosts were at risk, so I tried to mark them all as safe, but FortiNAC got stuck, so we had to restart the appliance.After that, I listed all the risky hosts
When using ipsec-vpn user IKEv1 dial-up VPN. Did all things still same issue also change wan interface still same issue. attached picture of the error. urgent support needed. forticlient version 7.4.3.4726
Hello,I would like to know if FortiClient EMS allows SQL queries using Windows authentication.I have created the policy to grant the endpoints the necessary access, but when a user logs in through the EMS administration interface, they receive the following error: If you've experienced something similar or encountered this same error, I would appreciate your help.Thank you very much.
Have a project to convert Meraki APs and Switches to FortiAP FAP-431F and 432F and FortiSwitch 100 managed by FortiEdge Cloud. Discovered Meraki have some filtering features like Wireless L7 rules and Content Filtering. Are these supported on the FortiLAN Cloud side? If so where will these filtering be happening? Does it require tunneling the traffic to the cloud? Thanks for the answer in advance!
I got a FS108D from work nothing crazy about it. I created a VLAN on it but after I did that it doesn’t show anything else on the page I inspected the browser and it says 500 Server error. It has 8 ports and I want to create some VLAN for my devices.Whats is the issue here?
Hi all,I have struggled with the above but now have this working on a 61F.However there are a few bits I am still struggling with that I am trying to work out if they are a limitation of Windows or how I am configuring…I need an IPSEC VPN with split tunnelling without requiring:Free Fortinet VPN client due to lack of admin rights External RADIUS/AuthenticationI have got this working using Machine certs as I believe the Windows client requires the use of EAP-TLS for a user account based tunnel which the FortiGate cannot directly achieve by itself?Once I got this working, I then wanted to enable split tunnelling, Windows appears to need DHCP option 249 to send over these routes, but also needs mode-config to assign the IP.I have tried to create a DHCP server on the VPN interface, dummy DHCP servers on loopbacks etc, but cannot seem to get this part working… is it even possible? If I change the IP address mechanism by specifying DHCP the client connects but never gets an IP, unless I enab
Hi all,Looking for input from anyone running FortiADC-220F in production. We are on a new active-passive HA deployment and we are seeing what looks like hardware-related problems on two different units, which is starting to worry us.Environment:- FortiADC-220F, HA active-passive- FortiADC OS 7.6.5- Brand-new deploymentWhat is happening on the original unit:- One node intermittently goes completely unresponsive — no GUI, no SSH, and the console is also dead (no output, no reaction to keystrokes)- Only a physical power-off / power-on recovers it- After the power-cycle it runs fine for around a day or more, then it freezes again the same way- This started showing up after we upgraded to 7.6.5, but we have not been able to confirm whether the upgrade is actually the triggerWhat happened with the RMA:- We opened a TAC case — no proper RCA so far- The RMA replacement unit Fortinet sent arrived faulty as wellQuestions for the community:1. Has anyone seen a similar complete freeze (including c
Hello, I’m a student studying FortiGate. I have an FG-80F, and I’m planning to upgrade from version 7.4.12 to 8.0.0. Are there any specific issues I should be aware of? Apart from SSL VPN, are there any other potential problems?
Hey everyone,I'm currently working on my PFE (Graduation Project) focused on deploying a Zero Trust Architecture using the Fortinet Security Fabric. I’m finalizing the deployment strategy for the FortiClient custom installer distribution, and I'd love to get some architectural feedback from the community.The Goal: Securely distribute the custom installer generated in EMS to remote endpoints during an initial onboarding period, and then tightly lock down registration afterward.The Environment: My core EMS server lives inside the secure Server LAN.For both options below, the download page is protected by a FortiWeb WAF that requires Active Directory (AD) pre-authentication before a user can access the installer. However, given the recent high-severity vulnerabilities (like the 8013 auth bypass CVEs), I am highly paranoid about zero-days and expanding the internal attack surface unnecessarily.Here are the two design paths I am debating:Option 1 (Dedicated DMZ Server + WAF + AD Auth)
Hi guys,anyone had any experience with cisco webex calling and fortigate. basically SIP traffic are encrypted and sent over tcp 8934 via fortigate to internet (webex). we have been experiencing, one way audio, transfer fails, unable to hold and resume , drop calls (all intermittent). These usually points to SIP ALG issue but it is disabled.am I missing anything on firewall? any other way to double confirm if those packets are dropped due to alg? i would really appreciate some insights pls.
Creating a bridge SSID with dynamic VLAN assignment. So far so good. Two wireless clients in that network. For the first period (some minutes) everything works ok, but then arp requests for the 2 devices are not answered. Setup:-FG61E 6.4,-FAP221E 6.4- FGT and FAP are connected over hw-switch internal,- FGT has VLAN interfaces on internal defined Troubleshooting:brctl showmacs br.2020 - lists all 3 MACs and their interfacesping from FAP works in the first perioddiag_sniffer br.2020 none - shows the arp requests from FAP or from FGT default gateway, but is not answered. Pinging from one WLAN Client to the other WLAN Client also seems to be affected, but sometimes it works for them but it does not work from FAP or FGT, or it works for all again for a period of time. Pinging IPv6 local-link addresses work without any issue? Last: If all WLAN Clients are put back into the standard Bridge SSID, this behavior does not happen. Strange is also tha
Hi there, Has anyone used Fortigate permanent license to take backup using automation stitch. Could you please if it works If am using permanent trail license feature. Thank you in advacned.
Hello, I have been experiencing the following phenomenon concerning multicast streams on a FortiGate 300E : - after a few hours or days of viewing multicast video streams, one stream (not always the same) will become unavailable on all firewall ports except for one port (but not always the same). The IGMP subscription and PIM route (dense mode) are still in the FortiGate's tables for all the ports requesting the stream. - I tried clearing multicast routes, igmp groups, multicast sessions and the command "execute router restart", none of this will get the multicast stream back. However, if I reboot the firewall or if it goes to the failover firewall, I will get the stream back. - If I use the "diag sniffer packet" to see the multicast stream on the one port where it is still available, there are no multicast packets (and no packets dropped by kernel, I tested with auto-offload enable and disabled). However I can see the multicast packets in wireshark on the cli
Hello Fortinet Support, We are facing an issue where EMS logs are not being ingested into Forti Analyzer. At present, only FortiClient logs are visible, but EMS server activity/logs are not showing up.Details:Product: Forti Analyzer & FortiClient EMSIssue: EMS logs not ingesting/forwarding to Forti AnalyzerObserved: Only FortiClient logs are displayedExpected: Both FortiClient and EMS logs should be ingested for full visibilityRequest:Could you please assist us in troubleshooting and resolving this? If any specific configuration or version requirements are needed for EMS log forwarding, kindly provide guidance.
Hello,I am trying to test if I can configure endpoint users to connect to a certain PoP in FortiSASE instead of the one nearest to their location. This is needed as some of our users have clients that enforce GeoIP filtering. An example is we need some of our users in the APAC need to connect to our US PoPs as their client only allow US and Canada IPs in their system.Pleas help.Thank you!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.