Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Why oh why does Fortinet make all this so difficult, it seems like they actually don't want people to even use the trials… I finally have a FortiGate trial VM and a FortiManager trial VM, but can I get them talking? No! Lots of commands that are no longer valid etc... FortiManager reports a probe fail, from online searches, I have tried lowering the encryption settings and allowing VM registration on the FortiManager. I have tried registering from the FortiGate side also.Now it transpires that my FortiGate trial VM does not have the right factory cert because it is does not contain the serial of the virtual appliance, just a generic "Fortinet". I have tried regenerating the certs, tried re-execting the VM commands but it does not accept them either… To be honest it feels like a battle just to make the trials work, which is hardly a good starting point.
Fabric contains a FortiGate cluster and managed FortiSwitches for internal and external purpose. Is there any solution to shut down all the devices from the downstream connected device such as a desktop. As per my understanding, the challenge is the FortiGate is the brain here. so I am facing a chicken and egg problem. Please let us know if there is a good solution for this. Thank you
After a change in the provider of wan2, I try to login to the fortigate direct with the ip adres of it.I get the login page with user and password after that i get the token login screen. (wan 1 adres)But then nothing autersation error that is all.But i log in as always eff was logt in this morning but now…...nothingI really do not want to reset.If anybody got a id plz.BTW login with forticoud is also not working now
Hello Fortinet team and community,I am looking to install FortiClient VPN version 7.0.12.0572. Could you please help me with the official download link for this release? Since this is a free VPN-only version, I would appreciate guidance on where I can access it directly from Fortinet’s site or repository.Thank you in advance for your support.
Hi,I am using a personal account, as the company I work for has lost access to the forticloud portal. This is because we requested a transfer from the master account to another existing account. The transfer was approved but it looks like something went wrong along the way. Nobody within the company that had access can access the forticloud portal. So access to fortimailcloud, asset manage etc. I have been emaling cs@fortinet.com but so far without any response.Can you some provide a procedure, a link, phone number I can call to rectify this?Advice will be greatly appreciatedKind regards
Hi all, on our infrastructure we have a forti Manager on 7.4.10 version. We have multiples Fortigate on 7.4.11 release.We tried in different ways to set expiration date on Polici Packages but the feature does not work. Either on forti manager and fortigate firewalls. A collegue of us works for another company with the same infrastructure. Same issue. Does someone know if it is a known issue? I checked on documentation, and the issue was not mentioned.We also opened a ticket to Fortinet support. They did not know about the isue and they don’t know how to resolve it. Maybe updating to the last relase solve it? Thanks for your help
Hi all, when I try to add a firmware template to a FG80F the Fortimanager Cloud returns me the following error: "[-9001] invalid template assignment - conflicting template assignment scope: device FG-BENIARJO, vdom root, firmware template object [(null)] and [Template_Upgrade_Beniarjo]" (attached screenshot). As you can see the template has no device assigned. The FG does not have any firmware or provisioning template configured. On the other hand, another FG with the same characteristics, and being the template a clone, I have not had any problem. Any ideas? Best regards!
Hi, I am running FortiOS 7.4.7 on a FortiGate-60F and am trying to migrate from SSLVPN to IPsec VPN. I've managed to configure IPsec (IKEv2) dial-up to work fine, but I notice that when I set the mode to IPSec over TCP, FortiClient (v7.4.3) does not connect and times out. UDP mode works perfectly fine. I also notice that TCP 4500 is not one of the local-in policies on the firewall. Does a local-in policy need to be configured for this to work? Has anyone had any experience with this? Thank you!
We have dedicated ssid for contractor where the contractor user will connect to the isolation then enter the entra id by captive portal then fnac checking the antivirus by posturing. When posturing result is ok then the device will move from rogue host to registered host.With this condition when next day the contractor connect to the network then the posturing is not executed because the posturing only will be executed for rouge host.So can we move the devices from registered host to rouge host for contractor if the device not connect to the newtork for some period?
We have policy to allow all servers access to microsoft then i have a firewall policy and set the destination to all microsoft internet service.However i found some microsoft url still blocked by implicit denied and this mean microsoft internet service not contains all microsoft url. Anyone know how to solve this?
Hi,I would like to understand whether FortiClientVPNInstaller 7.4.3.4726 requires version 7.4.3.8758 to be installed in order to fix vulnerabilities.I’m using ManageEngine Patch Manager, and it says that I need to upgrade to version 7.4.3.8758. However, I cannot find this version anywhere.
We migrated the FW from SonicWall to Fortigate 201G after completing all configuration it’s working fine but the SAP tunnel having issue on migrating time we resolved it, but after 1 week facing flapping issue continously . Using ikev2 and pfs disable as recommended by SAP cloud.Also we are using separate subnets in phase2. Attached VPN logs.Our device Fortigate and SAP device Cisco ASA Kindly recommend if any things need to be check on Fortigate.current version fortiOS v7.4.11 build2878 (Mature)
Hey everyone,I'm currently working on my PFE (Graduation Project) focused on deploying a Zero Trust Architecture using the Fortinet Security Fabric. I’m finalizing the deployment strategy for the FortiClient custom installer distribution, and I'd love to get some architectural feedback from the community.The Goal: Securely distribute the custom installer generated in EMS to remote endpoints during an initial onboarding period, and then tightly lock down registration afterward.The Environment: My core EMS server lives inside the secure Server LAN.For both options below, the download page is protected by a FortiWeb WAF that requires Active Directory (AD) pre-authentication before a user can access the installer. However, given the recent high-severity vulnerabilities (like the 8013 auth bypass CVEs), I am highly paranoid about zero-days and expanding the internal attack surface unnecessarily.Here are the two design paths I am debating:Option 1 (Dedicated DMZ Server + WAF + AD Auth)
Hello,I’m facing an issue with EMS endpoint alert emails. The email includes a report link for full details, but when I open it, I get the following message:“Redirect Notice – The page you were on is trying to send you to an invalid URL.”Has anyone faced this issue before or found a solution for it?
I have configured the following in a new Active-Passive setupUnit A (setup as Active 120 HA) - mgmt IP address 10.1.1.5/24 (set management ip and dedicated-management)Unit B (setup as Passive 115 HA) - Mgmt IP address 10.1.1.6/24(set management ip and dedicated-management) HA on both group ID 1tracking port2“port2” configured on both units as IP address 10.1.1.10/24 Both units are only pingable sometimes, MAC flapping messages appear every 5 seconds on both Arista switches setup as a MLAGBoth units have the same virtual MAC address (get hardware nic mgmt) other units I have setup exactly the same a-p, have different mgmt MAC’s between A and B! If I remove the group-id from Unit B, everything works, both units pingable and accessible. When I add the group-id back into Unit B, problem persists. I have even changed the group-id on both from 1 to 256, same problem. How can this be, I have checked pretty much everything but obviously there is sometime I am missing? Thanks all for any inpu
I have requirement to use one SSID for employee and guest, the employee will use EAP-TLS for authenticate and if authentication failure because the client no have certificate then the endpoint will access to guest network.This was done for wired connection (employee and guest) but on wireless connection only employee was work, if the wireless client not have certificate then the client is asked to enter the username and password. Anyone know how to achieve this?
I got a FS108D from work nothing crazy about it. I created a VLAN on it but after I did that it doesn’t show anything else on the page I inspected the browser and it says 500 Server error. It has 8 ports and I want to create some VLAN for my devices.Whats is the issue here?
HI All I need to get some guidance on how we can deploy below network Firewall HA ( 2 LAN port1 and port2 in same hardware switch), Port 1 on both FG connect to cisco switch 1 and cisco switch 2 respectively. Port 2 on both FG connect to cisco switch 1 and 2 respectively alsoCisco Switch 1 and 2 also interconnected(trunk port). Cisco runs RPVST+. Switch1 runs as STP root primary, Switch 2 runs as STP root secondaryAbove topology eventually create loop network. How should it be configured to avoid the loopFortigate hardware switch if disable STP, it eventaally create loop, and broadcast storm starts. Enable STP on FG hardware , eventually the broadcast stops. But i found some weird result. When i check Switch2 STP, it blocks the port connect to FG1, but port connect to FG2 becomes root, and forward state. Switch2 can still somehow reach FG IP, the mac-address also shows it learned from port to FG2. But FG2 runs as HA passive state. i try diagnose sniffer on FG2, nothing captured. How
I'm struggling a bit with my performance SLAs and SDWAN Rules. My typical branch office will have 2 internet connections, one is usually better than the other (i.e., Verizon FiOS plus Comcast or true DIA Fiber plus a business broadband).What's the best-practice strat for SDWAN rule? I've been mostly relying on Best Quality rule with a performance SLA that pings Google DNS (8.8.8.8), but I'm seeing more flapping than I would expect.I think my first question is: Do the Performance SLA settings under Link Status (Check Interval and Failure before inactive) affect the SLAs themselves? If I have my latency SLA set at 250ms, is the interface in violation of the SLA the first time if sees latency greater than 250ms or if my check interval is 1000ms and failure before inactive is 5, does it take 5 seconds of 250ms latency to violate the SLA?Any best-practice recommendations on these rules and Perf SLAs? I'm starting to think that Google DNS might not be the best candidate host for my probe. Do
I setup a lab environment with a FortiGate evaluation. All good… I needed to blow it all away and start again… I can see the asset in my portal, and I can download the lic file, but on a new install it does not accept it and gives me: Am I missing something here?
Hi,One of my clients have sip traffic passing through firewall. When we view forward logs firewall shows lots of logs with "0 Bytes sent/received". What does it mean?.
Hi, i have a Fortigate 200D Firewall with FortiOS 6.0.16 and a Huawei 4G Webstick Modell 3372h. I can't bring the Connection to the LTE-Network up. I searched around and found this https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-Huawei-E3372-h-modem-stick/ta-p/193600 The Problem is, that i have the AT-Command Version of this Stick and this HowTo is for the Web-Interface Version. When i try to configure the Stick as lte-modemdiagnose sys lte-modem infosays, that the Modem is not connected. So i tried to configure the Stick as "normal" Modem. The Modem itself seems to work properly: diagnose sys modem queryUSB status: Connectedmanufacturer: huaweimodel: E3372IMEI number: 868230032061123SIM state: Validservice status: Valid Servicesignal level: 3/4network name: E-Plusnetwork type: E-UTRANlocation area code:active profile(AT&V):COMMAND NOT SUPPORT^RSSI:18^HCSQ:"LTE",45,47,136,26 But in the Debug Messages a Timout occures (At
Hello FortiPeople, I’m checking if there’s a possibility to create a “recipient verification” exception for a particular source IP address. Let me explain:We have a particular client application, which sends e-mails to multiple addresses in one SMTP session.Whenever there’s a bad recipient address in the list of recipients, the application logically gets a “550 5.1.1 ... User unknown” reply from the FortiMail, via the recipient verification options set in the domain settings.However, where this SMTP client differs compared to other SMTP clients like Exchange Online, is that it quits the session after this reply and will not send the mail for ANY of the recipient, so no one receives the e-mail when only 1 address is bad.Exchange Online, for example, will continue on the same session (verified in the logs by session ID) and just continue for all the good addresses, which will then receive the mail. We tested with Thunderbird as an SMTP client, which also gives the same behaviour (SMTP se
Got a batch of forti switch 124g.Has anyone else got them?Do they also make an extremely high pitched whine like the capacitors about to blow?I've raised a ticket with support as these are brand new but wondered if this was a commonly known issue with them or I'm just unlucky?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.