Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi, i have installed FortiClient 7.4.3.4726, and configure vpn to connect in customer vpn, but the connection don’t works, i have bellow error:[2026-05-27 12:01:21.6932022 UTC-03:00] [12040:11004] [FortiVPN 2041 error] fortivpn::StateMachine::HandleTunnelConnectFailed session 1's (.\josan) vpn connection failed (reason: "Failed Unknown")[2026-05-27 12:01:21.6958494 UTC-03:00] [12040:11004] [FortiVPN 2370 info] fortivpn::StateMachine::HandleTunnelDisconnected "Agrex do Brasil LTDA" is disconnected.[2026-05-27 12:01:21.6968655 UTC-03:00] [12040:11004] [FortiVPN 2406 info] fortivpn::StateMachine::HandleTunnelDisconnected disconnection reason: 13, ("Failed Unknown")[2026-05-27 12:01:21.6968739 UTC-03:00] [12040:11004] [FortiVPN 2432 error] !!! fortivpn::StateMachine::HandleTunnelDisconnected session 1 (.\josan) "Agrex do Brasil LTDA" disconnected unexpectedly![2026-05-27 12:01:21.6973074 UTC-03:00] [12040:11004] [FortiVPN 2446 info] fortivpn::StateMachine::HandleTunnelDis
Hello everyone,I am working on a FortiAuthenticator 8.0.3 deployment and I need to apply a usage limit to AD users authenticated through FortiAuthenticator.The goal is simple: after the user logs in to the captive portal using their Active Directory credentials, they should be allowed to use the network for only 1 hour.I found this old Fortinet KB article from 2019:https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-RADIUS/ta-p/198682In the article, there is a note saying that Usage Profiles can only be applied to local users and, starting from version 6.5, to manually imported LDAP users.My question is:Does this limitation still apply in FortiAuthenticator 8.0.3?Or is it now possible to apply a Usage Profile directly to a Remote LDAP group, LDAP directory group, or LDAP filter, without manually importing each LDAP user into FortiAuthenticator?In the current FortiAuthenticator documentation, the Usage Profile option appears available under
HelloI have issue with registring trial license in my FortiGate VM in Hyper-V. I’m registred product and download lic license from portal but when I import license, VM don’t recognize license.Version in my Hyper-V is FortiGate-VM64-HV v8.0.0,build0167,260420 (GA.F).Can you help me to install license successfully?Best regards,Marin Mihajlovic
Environment: FortiGate VM v7.6 Lab environment, no actual WAN connectivityBackground: I have configured static routes using Internet Service (ISDB). FortiGate internally treats these as policy-based routes. I also have a link-monitor configured with update-static-route enable, update-policy-route enable, and update-cascade-interface enable.Expected behavior: When the link-monitor detects a failure, I expected the ISDB-based static route to appear as flags=0x8 disable in the output of diagnose firewall proute list, which is the same behavior described in the official documentation for standard policy-based routes.Actual behavior: When I simulate a link-monitor failure, manually configured policy routes (config router policy) correctly show flags=0x8 disable as expected. However, the ISDB-based static route continues to show flags=0x0 with no change.Output of diagnose firewall proute list after link-monitor failure:id=2113929218(0x7e000002) static_route=2 dscp_tag=0xfc 0xfc flags=0x0 tos
Hi,I am looking at using a small FortiGate setup on Azure for lab practice. I have found this to be relatively simple and looks like I can use the PAYG model to simply create a VM and use it.What I am struggling with is FortiManager, all the guides indicate a BYOL licence is needed, but during the setup it gives the option for FortiFlex which looks to be the right idea but I have no idea if I can buy a small number of points anywhere or do PAYG… Also this marketplace item exists and I am not sure if this is what I should be using as a way to pay all through Azure? Fortinet FortiFlex Usage-based Licensing - Microsoft AzureI can see this has a purchase option which then gives an option of 1,2,3 years but also it gives the create option which does create a VM?
Hello,While configuring Administrator Profile Mappings on FortiNAC, I accidentally associated all administrator profiles, including local administrator accounts, with a limited “Device Manager” type profile group. Since this change, I no longer have Full Admin privileges.I only created a profile mapping, is there a way to delete this Administrator Profile Mapping from the CLI?I found the following CLI command that allows restoring a previous configuration backup:execute restore config local <backup_name>If I restore a backup taken before this misconfiguration, will it restore the previous administrator mappings and resolve the issue? best regards.
Is TPlink wireless controller (Omoda) can be managed by FNAC?
Hi everyone,I need to upgrade a FortiGate-VM64 currently running FortiOS 7.0.19.Relevant output from get system status:Version: FortiGate-VM64 v7.0.19, build0696, 260129 (GA.M)License Status: ValidVM Resources: 2 CPU / 2 allowed, about 4 GB RAMCurrent HA mode: standaloneRelease Version Information: GAFortiOS x86-64: YesI also checked the active firmware image with diagnose sys flash list:Partition Image Active1 FGVM64-7.00-FW-build0696-260129 YesMy doubt is about the Fortinet Upgrade Path Tool.In the product list I see several similar VM options, such as:FortiGate-VMFortiGate-VM-KVMFortiGate-VM-HVFortiGate-VM-AWSFortiGate-VM-AZUREFortiOS-VMFortiOS-VM-HVFortiOS-VM-KVMFor this firewall, should I simply select FortiGate-VM in the Upgrade Path Tool?Also, for a manual upgrade, should the correct firmware image be from the FGT_VM64 family, for example:FGT_VM64-vX.X.X-buildXXXX-FORTINET.outThis one to be precise in this case:FGT_VM64-v7.2.13.M
I’m kind of at a loss as to how to make this work. I’m configuring a new FortiGate 90G, and what I’d like to do is connect a cable to an access port on my existing Dell network to a WAN port on the firewall, so it can get a DHCP IP, so I can register it. The problem is that I can’t get layer 1 to work at all. No link lights. I plug a PC into the same cable; it gets an IP just fine. The cable works. The Dell switch works. The FortiGate is brand new out of the box. I had the exact same issue when I was configuring my new 120G firewalls as well. Here’s something weird. I can connect a dumb unmanaged 5 port switch in between the Dell and the FortiGate, and everything connects and works perfectly fine. The firewall gets an IP perfectly fine. I disconnect the unmanaged switch, and go straight from the Dell to the FortiGate, and I get nothing. I’ve been on this for weeks, with no resolution, or even understanding, as to why this is happening. I’ve also tried putting a FortiSwitch inline betwe
We use captive portal for contractor and they should enter the entra id to connect to the network.We have some entra id group, example contractor_IT and contractor_SALES and each group have their own vlan.When the contractor authenticated successfully then the contractor still sit in isolation vlan and not changed to the respective vlan. My fnac vendor say when user authenticated thru entra id captive portal then fnac cannot bring entra group ID, is that true
I have guest ssid on the cisco wlc9800 and if there are user want connect to this ssid then the user will authenticate by captive portal with entra id.After the authentication successfull the client should be move from isolation network to guest network, in my case the client was moved to guest network if i see from fortinac policy but the client itself still connect to isolation network.Already ask to cisco support then they said the cisco not receive the coa to change the vlan. Anyone know here how to change thje vlan to teh cisco wlc9800?
Hi ,I would like to ask for some clarification regarding Flow-Based Antivirus behavior and architecture on FortiGate.I reviewed the Administration Guide and several technical documents, but I could not find detailed explanations for some internal Flow AV processing behaviors.I would highly appreciate it if you could clarify the following points or provide any related technical documentation, KB articles, technical tips, or architecture references.In Flow-Based Antivirus mode, is there still a file size limit / oversize handling mechanism similar to Proxy-Based AV, or is the oversize behavior only applicable to Proxy mode? In Flow mode, when scanning large files, does FortiGate bypass scanning after reaching a specific internal threshold, or can it continue scanning regardless of file size? Does Flow-Based Antivirus use the same Antivirus databases (Normal / Extended / Extreme) as Proxy-Based AV, or does Flow mode use a different AV engine/database architecture? If Flow mode does not fu
Hi everyone, do you know if it's possible to downgrade FortiClient from 7.4.5 to 7.2.10 directly from ForticlientEMS v7.4.5?Unfortunately, a colleague of mine accidentally pushed the 7.4.5 update and now we lost compatibility with all our ikev1 vpn.Thanks
Why oh why does Fortinet make all this so difficult, it seems like they actually don't want people to even use the trials… I finally have a FortiGate trial VM and a FortiManager trial VM, but can I get them talking? No! Lots of commands that are no longer valid etc... FortiManager reports a probe fail, from online searches, I have tried lowering the encryption settings and allowing VM registration on the FortiManager. I have tried registering from the FortiGate side also.Now it transpires that my FortiGate trial VM does not have the right factory cert because it is does not contain the serial of the virtual appliance, just a generic "Fortinet". I have tried regenerating the certs, tried re-execting the VM commands but it does not accept them either… To be honest it feels like a battle just to make the trials work, which is hardly a good starting point.
Fabric contains a FortiGate cluster and managed FortiSwitches for internal and external purpose. Is there any solution to shut down all the devices from the downstream connected device such as a desktop. As per my understanding, the challenge is the FortiGate is the brain here. so I am facing a chicken and egg problem. Please let us know if there is a good solution for this. Thank you
After a change in the provider of wan2, I try to login to the fortigate direct with the ip adres of it.I get the login page with user and password after that i get the token login screen. (wan 1 adres)But then nothing autersation error that is all.But i log in as always eff was logt in this morning but now…...nothingI really do not want to reset.If anybody got a id plz.BTW login with forticoud is also not working now
Hello Fortinet team and community,I am looking to install FortiClient VPN version 7.0.12.0572. Could you please help me with the official download link for this release? Since this is a free VPN-only version, I would appreciate guidance on where I can access it directly from Fortinet’s site or repository.Thank you in advance for your support.
Hi,I am using a personal account, as the company I work for has lost access to the forticloud portal. This is because we requested a transfer from the master account to another existing account. The transfer was approved but it looks like something went wrong along the way. Nobody within the company that had access can access the forticloud portal. So access to fortimailcloud, asset manage etc. I have been emaling cs@fortinet.com but so far without any response.Can you some provide a procedure, a link, phone number I can call to rectify this?Advice will be greatly appreciatedKind regards
Hi all, on our infrastructure we have a forti Manager on 7.4.10 version. We have multiples Fortigate on 7.4.11 release.We tried in different ways to set expiration date on Polici Packages but the feature does not work. Either on forti manager and fortigate firewalls. A collegue of us works for another company with the same infrastructure. Same issue. Does someone know if it is a known issue? I checked on documentation, and the issue was not mentioned.We also opened a ticket to Fortinet support. They did not know about the isue and they don’t know how to resolve it. Maybe updating to the last relase solve it? Thanks for your help
Hi all, when I try to add a firmware template to a FG80F the Fortimanager Cloud returns me the following error: "[-9001] invalid template assignment - conflicting template assignment scope: device FG-BENIARJO, vdom root, firmware template object [(null)] and [Template_Upgrade_Beniarjo]" (attached screenshot). As you can see the template has no device assigned. The FG does not have any firmware or provisioning template configured. On the other hand, another FG with the same characteristics, and being the template a clone, I have not had any problem. Any ideas? Best regards!
Hi, I am running FortiOS 7.4.7 on a FortiGate-60F and am trying to migrate from SSLVPN to IPsec VPN. I've managed to configure IPsec (IKEv2) dial-up to work fine, but I notice that when I set the mode to IPSec over TCP, FortiClient (v7.4.3) does not connect and times out. UDP mode works perfectly fine. I also notice that TCP 4500 is not one of the local-in policies on the firewall. Does a local-in policy need to be configured for this to work? Has anyone had any experience with this? Thank you!
We have dedicated ssid for contractor where the contractor user will connect to the isolation then enter the entra id by captive portal then fnac checking the antivirus by posturing. When posturing result is ok then the device will move from rogue host to registered host.With this condition when next day the contractor connect to the network then the posturing is not executed because the posturing only will be executed for rouge host.So can we move the devices from registered host to rouge host for contractor if the device not connect to the newtork for some period?
We have policy to allow all servers access to microsoft then i have a firewall policy and set the destination to all microsoft internet service.However i found some microsoft url still blocked by implicit denied and this mean microsoft internet service not contains all microsoft url. Anyone know how to solve this?
Hi,I would like to understand whether FortiClientVPNInstaller 7.4.3.4726 requires version 7.4.3.8758 to be installed in order to fix vulnerabilities.I’m using ManageEngine Patch Manager, and it says that I need to upgrade to version 7.4.3.8758. However, I cannot find this version anywhere.
We migrated the FW from SonicWall to Fortigate 201G after completing all configuration it’s working fine but the SAP tunnel having issue on migrating time we resolved it, but after 1 week facing flapping issue continously . Using ikev2 and pfs disable as recommended by SAP cloud.Also we are using separate subnets in phase2. Attached VPN logs.Our device Fortigate and SAP device Cisco ASA Kindly recommend if any things need to be check on Fortigate.current version fortiOS v7.4.11 build2878 (Mature)
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.