Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello,I am trying to assign a FortiToken Mobile to a local user via REST API on FortiOS v7.4.11 and getting error -651 "FortiToken is invalid".Environment:- FortiOS version: 7.4.11- Multiple VDOMs configured- Users are in VDOM "PO"- API admin profile scope: Global- API admin has User & Device: Read/WriteImportant note:We do not have direct access to the FortiGate GUI – only the customer does. Therefore we can only work via REST API and cannot verify the exact request that GUI sends when assigning a token.What works:- GET monitor/user/fortitoken?status=available → returns available tokens- GET cmdb/user/fortitoken/{serial} → works WITHOUT vdom parameter (root context)- GET cmdb/user/fortitoken?vdom=PO → returns empty / token not found- PUT cmdb/user/local/{login}?vdom=PO with two-factor: email → works fineWhat fails:- PUT cmdb/user/local/{login}?vdom=PO with fortitoken serial → error -651- PUT cmdb/user/local/{login} without vdom → HTTP 404 user not foundThe token exists in CMDB, st
Hi all, I am installing FortiNAC in a large environment and I added the Aruba WLC to FortiNAC without any issues. 3 days later, FortiNAC performed L2 pooling and discovered over 400,000 rogue hosts. After that, I disabled L2 pooling for the WLC, which stopped it from discovering.I use FortiNAC version 7.6.6 and have increased the VM to 16 CPUs and 32 GB of RAM.After that, I set the aging period to 1 day for the rogue hosts, but it did not work. I found this command, but it returned an error;> execute enter-shell# client -rog -op delete errorDuring this time, the FortiNAC RAM usage was at 92%, and the server was extremely slow.I could not find a way to get rid of these rogue hosts. While I was working, it did not affect the appliance, but when I configured PA for endpoint compliance checks, it did. While testing, I saw that many hosts were at risk, so I tried to mark them all as safe, but FortiNAC got stuck, so we had to restart the appliance.After that, I listed all the risky hosts
When using ipsec-vpn user IKEv1 dial-up VPN. Did all things still same issue also change wan interface still same issue. attached picture of the error. urgent support needed. forticlient version 7.4.3.4726
Hello,I would like to know if FortiClient EMS allows SQL queries using Windows authentication.I have created the policy to grant the endpoints the necessary access, but when a user logs in through the EMS administration interface, they receive the following error: If you've experienced something similar or encountered this same error, I would appreciate your help.Thank you very much.
Have a project to convert Meraki APs and Switches to FortiAP FAP-431F and 432F and FortiSwitch 100 managed by FortiEdge Cloud. Discovered Meraki have some filtering features like Wireless L7 rules and Content Filtering. Are these supported on the FortiLAN Cloud side? If so where will these filtering be happening? Does it require tunneling the traffic to the cloud? Thanks for the answer in advance!
I got a FS108D from work nothing crazy about it. I created a VLAN on it but after I did that it doesn’t show anything else on the page I inspected the browser and it says 500 Server error. It has 8 ports and I want to create some VLAN for my devices.Whats is the issue here?
Hi all,I have struggled with the above but now have this working on a 61F.However there are a few bits I am still struggling with that I am trying to work out if they are a limitation of Windows or how I am configuring…I need an IPSEC VPN with split tunnelling without requiring:Free Fortinet VPN client due to lack of admin rights External RADIUS/AuthenticationI have got this working using Machine certs as I believe the Windows client requires the use of EAP-TLS for a user account based tunnel which the FortiGate cannot directly achieve by itself?Once I got this working, I then wanted to enable split tunnelling, Windows appears to need DHCP option 249 to send over these routes, but also needs mode-config to assign the IP.I have tried to create a DHCP server on the VPN interface, dummy DHCP servers on loopbacks etc, but cannot seem to get this part working… is it even possible? If I change the IP address mechanism by specifying DHCP the client connects but never gets an IP, unless I enab
Hi all,Looking for input from anyone running FortiADC-220F in production. We are on a new active-passive HA deployment and we are seeing what looks like hardware-related problems on two different units, which is starting to worry us.Environment:- FortiADC-220F, HA active-passive- FortiADC OS 7.6.5- Brand-new deploymentWhat is happening on the original unit:- One node intermittently goes completely unresponsive — no GUI, no SSH, and the console is also dead (no output, no reaction to keystrokes)- Only a physical power-off / power-on recovers it- After the power-cycle it runs fine for around a day or more, then it freezes again the same way- This started showing up after we upgraded to 7.6.5, but we have not been able to confirm whether the upgrade is actually the triggerWhat happened with the RMA:- We opened a TAC case — no proper RCA so far- The RMA replacement unit Fortinet sent arrived faulty as wellQuestions for the community:1. Has anyone seen a similar complete freeze (including c
Hello, I’m a student studying FortiGate. I have an FG-80F, and I’m planning to upgrade from version 7.4.12 to 8.0.0. Are there any specific issues I should be aware of? Apart from SSL VPN, are there any other potential problems?
Hey everyone,I'm currently working on my PFE (Graduation Project) focused on deploying a Zero Trust Architecture using the Fortinet Security Fabric. I’m finalizing the deployment strategy for the FortiClient custom installer distribution, and I'd love to get some architectural feedback from the community.The Goal: Securely distribute the custom installer generated in EMS to remote endpoints during an initial onboarding period, and then tightly lock down registration afterward.The Environment: My core EMS server lives inside the secure Server LAN.For both options below, the download page is protected by a FortiWeb WAF that requires Active Directory (AD) pre-authentication before a user can access the installer. However, given the recent high-severity vulnerabilities (like the 8013 auth bypass CVEs), I am highly paranoid about zero-days and expanding the internal attack surface unnecessarily.Here are the two design paths I am debating:Option 1 (Dedicated DMZ Server + WAF + AD Auth)
Hi guys,anyone had any experience with cisco webex calling and fortigate. basically SIP traffic are encrypted and sent over tcp 8934 via fortigate to internet (webex). we have been experiencing, one way audio, transfer fails, unable to hold and resume , drop calls (all intermittent). These usually points to SIP ALG issue but it is disabled.am I missing anything on firewall? any other way to double confirm if those packets are dropped due to alg? i would really appreciate some insights pls.
Creating a bridge SSID with dynamic VLAN assignment. So far so good. Two wireless clients in that network. For the first period (some minutes) everything works ok, but then arp requests for the 2 devices are not answered. Setup:-FG61E 6.4,-FAP221E 6.4- FGT and FAP are connected over hw-switch internal,- FGT has VLAN interfaces on internal defined Troubleshooting:brctl showmacs br.2020 - lists all 3 MACs and their interfacesping from FAP works in the first perioddiag_sniffer br.2020 none - shows the arp requests from FAP or from FGT default gateway, but is not answered. Pinging from one WLAN Client to the other WLAN Client also seems to be affected, but sometimes it works for them but it does not work from FAP or FGT, or it works for all again for a period of time. Pinging IPv6 local-link addresses work without any issue? Last: If all WLAN Clients are put back into the standard Bridge SSID, this behavior does not happen. Strange is also tha
Hi there, Has anyone used Fortigate permanent license to take backup using automation stitch. Could you please if it works If am using permanent trail license feature. Thank you in advacned.
Hello, I have been experiencing the following phenomenon concerning multicast streams on a FortiGate 300E : - after a few hours or days of viewing multicast video streams, one stream (not always the same) will become unavailable on all firewall ports except for one port (but not always the same). The IGMP subscription and PIM route (dense mode) are still in the FortiGate's tables for all the ports requesting the stream. - I tried clearing multicast routes, igmp groups, multicast sessions and the command "execute router restart", none of this will get the multicast stream back. However, if I reboot the firewall or if it goes to the failover firewall, I will get the stream back. - If I use the "diag sniffer packet" to see the multicast stream on the one port where it is still available, there are no multicast packets (and no packets dropped by kernel, I tested with auto-offload enable and disabled). However I can see the multicast packets in wireshark on the cli
Hello Fortinet Support, We are facing an issue where EMS logs are not being ingested into Forti Analyzer. At present, only FortiClient logs are visible, but EMS server activity/logs are not showing up.Details:Product: Forti Analyzer & FortiClient EMSIssue: EMS logs not ingesting/forwarding to Forti AnalyzerObserved: Only FortiClient logs are displayedExpected: Both FortiClient and EMS logs should be ingested for full visibilityRequest:Could you please assist us in troubleshooting and resolving this? If any specific configuration or version requirements are needed for EMS log forwarding, kindly provide guidance.
Hello,I am trying to test if I can configure endpoint users to connect to a certain PoP in FortiSASE instead of the one nearest to their location. This is needed as some of our users have clients that enforce GeoIP filtering. An example is we need some of our users in the APAC need to connect to our US PoPs as their client only allow US and Canada IPs in their system.Pleas help.Thank you!
Hello,is there any way to get prepared for NSE1 other then Fortinet Learning Center ? Thanks
Hi everyoneWe are trying to block users from bypassing our web filter using Cloudflare WARP (1.1.1.1).We do not have Active Directory (AD) or GPO controls. Users are running WARP as portable apps directly from USBs (or people who’s already downloaded it before we noticed) so endpoint/execution-level blocking is out of the question.Our network architecture is constrained: a WatchGuard firewall NATs all LAN traffic into a single IP address before passing it to our core FortiGate.The problem we blocked the standard Cloudflare CDN IP lists, but already-registered/installed WARP clients bypass App Control by falling back to TCP/UDP 443.What are the exact destination IP ranges and custom ports used strictly by the WARP client/WireGuard/MASQUE tunnels (and not standard Cloudflare CDN web traffic) that we can deny on both firewalls?Any advice on blocking this connection fallback without breaking standard web traffic to sites hosted on Cloudflare? Thanks!
Hello everyone, We have been trying for weeks to establish a stable connection between two data centres. Our router is the Sophos Appliance and the remote site uses the Fortinet cluster. The connection is established successfully. Ping works, but then timeouts occur, meaning ping is no longer possible – for 2 minutes, then it works again for 30–40 minutes, then a timeout for approx. 10 minutes, then it works again for 30–40 minutes, then a timeout for approx. 20 minutes, and so on. We have established that Phase 2 seems to be causing the problem here during ‘re-keying’. We have already tried all possible settings here. Without success. Does anyone here have any idea what the problem might be, or has anyone perhaps encountered a similar scenario before? I would be grateful for any assistance. Peter
Hello Team,I am facing an issue with the Fortinet FortiGate 30G firewall during the firmware upgrade process.Error Message:"Image upgrade failed. This firmware image didn't pass the signature verification."
In an HA setup using FortiGate 200F, if the primary firewall is connected from the LAN port to the server, should the secondary firewall also be connected the same way?
Hi all, I am using Forticlient EMS cloud with Fortigate to achieve ZTNA. We have some endpoints tag changed for some reason, and we wanna know the reason to resolve the issue. But seems the Fortinet log only told that tag was assigned/unaissgned to a EMS client. How could I know the details rather then “guess how” or “open ticket tac” ?
Many internal systems are querying public DNS servers, but it’ll probably take a year before we can address off of these. Consequently, we are investigating if it’s possible to NAT all outbound queries to a pool of 4 different public DNS servers and use something like the health check monitor to ensure the servers are up. I see how to do this for a single public DNS, but I don’t see how to get all the way through the configuration. We’re using central NAT. Thank you.
Hi, i have installed FortiClient 7.4.3.4726, and configure vpn to connect in customer vpn, but the connection don’t works, i have bellow error:[2026-05-27 12:01:21.6932022 UTC-03:00] [12040:11004] [FortiVPN 2041 error] fortivpn::StateMachine::HandleTunnelConnectFailed session 1's (.\josan) vpn connection failed (reason: "Failed Unknown")[2026-05-27 12:01:21.6958494 UTC-03:00] [12040:11004] [FortiVPN 2370 info] fortivpn::StateMachine::HandleTunnelDisconnected "Agrex do Brasil LTDA" is disconnected.[2026-05-27 12:01:21.6968655 UTC-03:00] [12040:11004] [FortiVPN 2406 info] fortivpn::StateMachine::HandleTunnelDisconnected disconnection reason: 13, ("Failed Unknown")[2026-05-27 12:01:21.6968739 UTC-03:00] [12040:11004] [FortiVPN 2432 error] !!! fortivpn::StateMachine::HandleTunnelDisconnected session 1 (.\josan) "Agrex do Brasil LTDA" disconnected unexpectedly![2026-05-27 12:01:21.6973074 UTC-03:00] [12040:11004] [FortiVPN 2446 info] fortivpn::StateMachine::HandleTunnelDis
Hello everyone,I am working on a FortiAuthenticator 8.0.3 deployment and I need to apply a usage limit to AD users authenticated through FortiAuthenticator.The goal is simple: after the user logs in to the captive portal using their Active Directory credentials, they should be allowed to use the network for only 1 hour.I found this old Fortinet KB article from 2019:https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-RADIUS/ta-p/198682In the article, there is a note saying that Usage Profiles can only be applied to local users and, starting from version 6.5, to manually imported LDAP users.My question is:Does this limitation still apply in FortiAuthenticator 8.0.3?Or is it now possible to apply a Usage Profile directly to a Remote LDAP group, LDAP directory group, or LDAP filter, without manually importing each LDAP user into FortiAuthenticator?In the current FortiAuthenticator documentation, the Usage Profile option appears available under
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.