User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Can we use third party authenticator like google auth in Fortigate?
Currently using FortiToken for MFA on our fleet of gates and been looking at switching over to SAML via Entra to take advantage of conditional access policies + our ITDR against the accounts.Looking for other experiences to see if people are currently doing this and if they are any known issues or drawbacks to this change.
I try to build a new box of model 601F. Firstly, when i tried to manual upload license, it showed upload fail. please help
Hello, for the last two weeks I have been trying to connect FCEMS (7.4.4) to Intune to deploy ztna certificate to Android devices (Samsung S25, Android 16, work profile). I have ran into a brick wall of device being stuck in „MDM Deployment Status Pending“ and the intune polocy to deploy SCEP certificate having error without any further details. I have been following this guide Provisioning ZTNA certificates to FortiClient mobile using Intune | FortiClient 7.4.0 | Fortinet Document LibraryI walked through it multiple times with the same result. Maybe I am missing something? Can someone please help, if you have such setup in working order? :) I have configured the app with correct permisisons in intune and set up MDM integration in FCEMS. Have user with correct licences.In intune app configuration policies have set up:Go to Apps > App configuration policies. Create a new policy.Add key-value pairs. The intune_device_id key is mandatory. All other keys are optional
Hello Team,We are currently attempting to deploy FortiManager 7.6.6 on a Nutanix-hosted virtual machine by following the official Fortinet documentation:https://docs.fortinet.com/document/fortimanager-private-cloud/7.6.0/nutanix-administration-guide/118677/deploying-fortimanager-on-nutanixDeployment DetailsPlatform: Nutanix VM Image Used: FortiManager 7.6.6 (KVM qcow2 image) Reference Guide: As mentioned aboveIssue DescriptionWe have followed all the steps from the documentation and successfully deployed the VM. However, the FortiManager appliance does not boot correctly.From our observations (see attached screenshots), it appears that:The operating system present on the attached disk is not loading/booting properly. The system seems stuck during the boot process or fails to initialize.ObservationsThe qcow2 image used is the latest recommended version for FortiManager (7.6.6). The deployment steps were executed as per the official guide. No obvious configuration errors were identified
Dear Community,I have cluster on siteA with primary and secondary. Their ha interface connected with a direct cable. Also there are x1 ports in the hbdev configuration via a switch. Now I would like to add a third fortigate to the cluster but this is on siteB. The x1 ports are connected via switch on L2 between siteA and siteB. While the hb interfaces are only connected on siteA devices (primary and secondary) with direct cable without switch. Because the hbdv setting mirroring between the primary and secondary units, I think the x1 should be the higher priority in the hbdv setting. But what should I do with the dircet ha config? Should I have to remove it? Or should it remain in the hbdev config with lower priority as a “backup between devices on siteA”? In this last case the remote siteB new fortigate (subordinate secondary) will see its hb interface as permanent dead, and will ignore it?thank you
Can we use wildcard certificate for persistent agent? I have this log from the client when the Persisten Agent using valid wildcard certificate.Wildcard cert!Peername “nac.mydomain.com” matches wilcard “*.mydomain.com”Refusing to connect to trust_DISTRUST nac.mydomain.com|*.mydomain.comConnection failed! 1SslStreamtransport::disconnect()SslStreamtransport::disconnect() NOT joined rxBoostThread because this IS the receive threadSslStreamtransport::disconnect() joined threads, free-ing the SSL State
When configuring a FortiClient EMS server (v.7.4.1b1872) on Linux for Administrator SAML SSO with Entra/Azure it works if I use the default SP Address (<FQDN>), but we'll be locking down port 443 from external access and I would like to use 10443 for the SAML SSO. When configured the same way adding 10443 per the small blurb of instructions (<FQDN>:10443) it returns an EMS 404 error stating "The requested URL was not found on this server." If I reconfigure that same SAML entry to just the <FQDN>, updating the appropriate fields and certificate, it works. I have confirmed that port 10443 is open. The URL in the browser looks correct for the ACS link (https://<FQDN>:10443/saml/default/<UniqueKey>/acs). I don't see any issues off hand, and MS does report a successful log in. Attempting to log in as a unapproved user does result in the expected O365 "you do not have permission to log in" page. The server has been rebooted with the desired settings in
I need A support to get a fortigate VM Evaluation license for FFUMEUREFUFF9554
We just purchased a fortigate 70g firewall, and I am having some issues getting it connected to our existing network. For context the existing network consists of 3 cisco switches with multiple vlans setup. I have configured a Trunk port on the cisco switch and connected the fortigate to it, the issue I am having is getting the interface on the fortigate to talk to my network. What I want to have is 1 port act as the Mgmt port accessible by admin workstations thats on the "mgmt vlan", then have the various vlans added so i can give them internet access. What is the best way to go about this? Should i setup sub vlans interfaces on 1 physical port, or setup a vlan switch? This is my first fortigate so i am not familiar with it yet. Thanks.
Hi all,Yesterday I noticed that my FortiGate HA cluster went into an out-of-sync state.I tried recalculating the HA checksums on both nodes and also rebooted the secondary unit, but the cluster is still showing out of sync.Has anyone experienced this before? Is this a known bug in FortiOS 7.6.6, or is there another troubleshooting step I might be missing?FortiOS Version: 7.6.6 Build 3653Any advice would be appreciated. Thanks!
I’m trying to create a rule to allow traffic to a specific public domain or list of domains, from my internal users. Traffic that doesn’t match the “whitelisted” destination domain(s) should flow down through the existing rules. The following seems to be allowing all HTTP/HTTPS traffic, not just the traffic to the target domain. The Fortigate is running 7.2.13.If I enable the rule below, I see traffic in the log matching this rule, that is destined to all kinds of other domains. I don’t want to affect traffic to any other domains, and want traffic not destined to the “whitelisted” domains to just flow down through the other existing firewall rules.Ive tried using a “simple” URLfliter (as below) as well as a wildcard filter, but no matter what I’ve tried the rule seems to be matching way more traffic than I intend. config webfilter urlfilter............ edit 6 set name "Auto-webfilter-urlfilter_f7yxvxpub" config entries edit 1 set url "canv
Apologies for what I hope my struggles are merely from being a novice user of Fortigate products. I am now managing my first Fortigate 60E and trying to get port forwarding to work for a specific source. Actually, I do have port forwarding working for a specific source, but only one source. When I try to add any other source to a rule or even a separate rule for the source in question, it doesn’t work. I can’t remember if the source IP address that works was setup in some special way in the past, I am unable to find differences. So, I use the CLI to debug and really do not understand why the differences. First of all, here are the rules, both WebTent and WebTent DC are single IP addresses. As you can see, I am forwarding port 5022 to an internal IP port 22, this works from WebTent, but not WebTent-DC. So, for the debug, I see this for traffic when coming from WebTent and it works…FGT60ETK18001521 # diagnose debug flow filter saddr < my WebTent IP address >FGT60ETK18001521 # diagn
Hello everyone,I'm planning a maintenance window to upgrade the FortiGate firewalls in our environment, and I'd like to hear from those who have gone through a similar scenario.I've already completed an inventory of all devices, reviewed the Fortinet recommended firmware versions, and validated every upgrade path using the Fortinet Upgrade Path Tool. At this point, my questions are more about strategy than technical execution.Our current environment is as follows:Hostname Model Current Firmware Target Firmware FGT-HQ 70F 7.4.3 7.4.12 FGT-BR01 60E 7.4.3 7.4.12 FGT-BR02 60E 7.4.7 7.4.12 FGT-BR03 40F 7.4.11 7.4.12 FGT-BR04 40F 7.6.1 7.6.7 FGT-BR05 40F 7.6.6 7.6.7 FGT-BR06 40F 7.2.11 7.2.13 (or migrate to a newer branch) Additional information:Production environment. We use IPsec Site-to-Site VPNs, SD-WAN, security policies, NAT, VIPs, and SSL VPN. A full configuration backup will be taken before every upgrade. All firmware upgrades w
How do you transfer a call to someone’s voicemail? In this case, a secretary has her boss’ extension programmed as a soft key on her phone so she can answer it. A call comes in on her boss’ like, she answers, and would like to transfer it to her boss’ voicemail. Nothing I’ve found online seems to work (I’ve read dial *9 + extension, dial **9 + extension - neither work)…. Any suggestions?
Hi, I just downloaded the fortigateOS 7.6.7 into my GNS3,but when cli,i tryUsername:adminPassword:blank it fails to authenticateAnyone has any idea?
I have a Sectigo Certificate which i am trying to attach to admin GUI on port 443 ..i am not using any SSL VPN on the fortigates.. i built the file as leaf + intermediate + root and uploaded it under local → certificates.. additionally also uploaded intermediate separately under CA - Remote Certs .. but still when i try to check the cert validitiy via openssl or ssl labs it says that chain is missing and the chain is not reflecting at all.. i even tried attaching the certificate as a pfx but still the same issue.. any help is appreciated in resolving this.. Thanks
i purchased onr firewall model 40F before two days at 14-6-2026 , i found licenses activated since 2-2026 that mean i lost 4 months and i dont know that , seller did not tell me about that is there any solution please ?
Does agentless ZTNA work on Fortigate with eval license?because i am getting this error: wad_vs_find_cipher … ssl no matching CipherSuite
https://training.fortinet.com/
Hello everyone,I’m encountering an issue regarding batch account creation. I am using version v2.4.1-build0468. When I create a batch of users and try to email the created credentials, the email is sent correctly, but the attached Excel file is empty. It only contains the headers ('Username', 'Password') without any actual account data.%ACCOUNTLIST% in the email template doesn't seem to work either (it's blank in the email)In "Manage Account Batches", if I "Print account" it results in an error : "Unable to print/send details! Password not found for the user".So I literally have no way to get the password of the users.Surprisingly, “Random User Account Batch” works way better. The .csv contains the passwords & “Print account” actually works… Has anybody figured out how to create account batches using a .csv file (and get the list of the login/passwords)? Thanks in advance !
We have requirement to forward SD-WAN performance metrics, such as packet loss, latency, and threshold breach events, to the monitoring tool so that they can be effectively monitored and tracked.
Hi everyone,I have a question about renewing a Fortinet license that has been expired since 2024.My reseller is telling me that in order to regularize the situation, I have to take a license with 6 months of backdated prorata. Concretely, the license would start in January 2026, meaning that for a 1-year license purchased today (June 2026), I would only get 6 months of actual use until the end of 2026 — since the first 6 months (January to June 2026) have already passed.Is this really Fortinet's standard policy for expired licenses? Is it normal to have to pay for a period that has already elapsed when renewing late? Has anyone been in a similar situation, and is there any way to negotiate directly with Fortinet to get the start date set to the actual purchase date?Thanks in advance for your feedback!
Hi,I have FAZ FAZVM64-HV with v7.6.3 build3492 (Feature)when I login I see that nevest version is available to download - 7.6.7 (3737) I can’t upgrade this VM to nevest version.I am using FGT_VM64_HV-v7.6.7.M-build3704-FORTINET.out
I use FortiClient on Windows every day for VPN and other company resource access.When FortiClient opens in web browser, I type the one time password digit by digit and it works.When I connect to VPN with FortiClient, it opens from Windows system tray, and typing a digit doesn’t move to the next digit box, so I need to hit tab after each digit. I do this several times a day and it’s so annoying I felt I had to submit this. Please fix this!!!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.