Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
i purchased onr firewall model 40F before two days at 14-6-2026 , i found licenses activated since 2-2026 that mean i lost 4 months and i dont know that , seller did not tell me about that is there any solution please ?
Does agentless ZTNA work on Fortigate with eval license?because i am getting this error: wad_vs_find_cipher … ssl no matching CipherSuite
https://training.fortinet.com/
Hello everyone,I’m encountering an issue regarding batch account creation. I am using version v2.4.1-build0468. When I create a batch of users and try to email the created credentials, the email is sent correctly, but the attached Excel file is empty. It only contains the headers ('Username', 'Password') without any actual account data.%ACCOUNTLIST% in the email template doesn't seem to work either (it's blank in the email)In "Manage Account Batches", if I "Print account" it results in an error : "Unable to print/send details! Password not found for the user".So I literally have no way to get the password of the users.Surprisingly, “Random User Account Batch” works way better. The .csv contains the passwords & “Print account” actually works… Has anybody figured out how to create account batches using a .csv file (and get the list of the login/passwords)? Thanks in advance !
We have requirement to forward SD-WAN performance metrics, such as packet loss, latency, and threshold breach events, to the monitoring tool so that they can be effectively monitored and tracked.
Hi everyone,I have a question about renewing a Fortinet license that has been expired since 2024.My reseller is telling me that in order to regularize the situation, I have to take a license with 6 months of backdated prorata. Concretely, the license would start in January 2026, meaning that for a 1-year license purchased today (June 2026), I would only get 6 months of actual use until the end of 2026 — since the first 6 months (January to June 2026) have already passed.Is this really Fortinet's standard policy for expired licenses? Is it normal to have to pay for a period that has already elapsed when renewing late? Has anyone been in a similar situation, and is there any way to negotiate directly with Fortinet to get the start date set to the actual purchase date?Thanks in advance for your feedback!
Hi,I have FAZ FAZVM64-HV with v7.6.3 build3492 (Feature)when I login I see that nevest version is available to download - 7.6.7 (3737) I can’t upgrade this VM to nevest version.I am using FGT_VM64_HV-v7.6.7.M-build3704-FORTINET.out
I use FortiClient on Windows every day for VPN and other company resource access.When FortiClient opens in web browser, I type the one time password digit by digit and it works.When I connect to VPN with FortiClient, it opens from Windows system tray, and typing a digit doesn’t move to the next digit box, so I need to hit tab after each digit. I do this several times a day and it’s so annoying I felt I had to submit this. Please fix this!!!
Background: we've run out of 10gb ports on our switches and need to use on one the Fortigates.Was wondering if it's possible to bridge an existing Fortiswitch VLAN to one of the physical ports on the Fortigate.That way we can take advantage of the extra ports on the Fortigate.
Hello,I'm looking for an official clarification regarding the Layer 3 capabilities of the FortiSwitch FS-1048E.While reviewing the current FortiSwitch Campus Core and Data Center Series datasheet, I noticed what appears to be conflicting information:In the FortiLink Mode (with FortiGate) feature table, it states: "L3 Routing and Services (FortiGate)" "Policy-Based Routing (FortiGate)" This seems to imply that Layer 3 routing is only available when the switch is managed by a FortiGate through FortiLink.However, in the Layer 3 Features section, the FS-1048E is listed as supporting: Static Routing (Hardware-based) OSPF RIP VRRP BGP ISIS VRF ECMP Policy-Based Routing and other L3 capabilities (some requiring the Advanced Features License). The hardware specifications also explicitly list IPv4/IPv6 Routing for the FS-1048E.My question is:Does the FS-1048E support Layer 3 routing in standalone mode, without being managed by a FortiGate via FortiLink? If yes, are there any feature
Now i make authentication in fortinac using persistent agent and passive agent and i configure LoginDialogDisabled to hide the popup login credentials but it still appears for first time user appears although i configure everything as per below article can anyone advise if faces this problem
Hello everyone. We bought a Fortigate 71g (7.6.7). I have experience using OpenVPN on Mikrotik and Pfsense. It was very convenient for remote access and local DNS access. The point is, we need to provide remote access to people without providing a DNS domain and server; we bind users by IP addresses, and that was sufficient. The problem is that I can't get the IPSec Fortigate to work without providing clients with a DNS server. All requests start going through the VPN tunnel, and access to local domains and DNS is lost.Detecting the client's local DNS is not quite right. For example, OpenVPN has this block-outside-dns feature. Is there a solution?Tried:1) config vpn ipsec phase1-interface edit "test1" set dns-mode manual set ipv4-dns-server1 0.0.0.0 nextend2) I tried unset ipv4-dns-server1,2,33) ipsec Mode config - manual4) in the client's config in XML: <ipsecvpn> <options> <enabled>1</enabled>
Please help meI want to set it up like this: I have FortiGate, a Ruijie managed switch, and several APs. FortiGate port 3 will connect to the switch, and the APs will connect to the switch as well. I want mobile devices connected to the APs to be on the same IP subnet as the FortiGate and Ruijie.
Hi all,I can see lots of posts about dual wan connections on the Fortigate with lots of solutions for different scenarios, however I'd still like some advice with my situation.We have a Fortigate 81F (firmware 7.4.12) at the main office. It currently has one internet link (wan1). This is used for internet traffic, as well as ipsec vpn from 4 remote sites. These remote sites also use the Fortigate wan1 as their internet connection.We are using ospf to advertise routes between the main office and remote sites. The Fortigate's default route is via our isp.We wish to get a second internet connection to connect to wan2. This will be solely for the ipsec vpn; no link redundancy or load balancing (at this stage, perhaps in the future). All internet access will be via wan1.In what I hope is a simple situation like this, would setting static routes to both wan1 and wan2 but setting a higher priority on wan2 be enough to prevent atttempts to use wan2 as the internet link?I see other option
The MyCanal website used to work on my site, but now it doesn't. When I check on my Forti account, I see that it's blocked. So I want to understand why Forti is blocking MyCanal now and what I should do.
Previously i have 5 AP under my WLC9800, then i add some APs and some existing APs is renamed. How Fortinac can sync with the new name and add new APs to the inventory?
Dear community, I am working on a design where the customer wants 3 Fortigate units to be placed in their 3 DC’s and want them to be in HA(A/A or A/P).Is this achievable, as i see the FGCP needs less latency also even if i tweak in the HB counts and Dead timer, what other factors to be considered.Is there an alternative approach that can achieve this or a better other solution that may fit this scenario. Devices: 101 F , 400F
Please tell me.Until recently, the following KB article, which describes a workaround for automatic firmware upgrades after End of Streaming (EoES), was available.However, it now displays "Access Denied." Technical Tip: Disable auto-upgrade for unlicensed FortiGateshttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Disable-auto-upgrade-for-unlicensed-FortiGates/ta-p/414696 Please tell me why it has been made private.
Having an issue I’ve never seen before, I have a ticket open with TAC but figured I’d see if anyone has ever seen this before. As soon as I plug the modem into my Fortigate, the modem crashes constantly and will never get a lock on the ISP signal. As soon as I unplug it and connect a laptop directly to the modem, it is able to establish a lock and I get a public IP. This occurs both if I try to get a public IP using DHCP or if I try to set one of our static IPs. The ISP has tried two of their Router/Modem combo units, as well as we have tried two Arris Surfboards, one of which is known working on a different circuit. Thanks for any help!
Hi,For training purposes, I have installed FortiManager 8.0.0 on VMware and FortiGate 8.0.0, but I am encountering the following problem: I have already tried using the SSL certificate whose serial number is specified in the CN field, but the issue still persists. fgfm-allow-vm is enabled
Can we use forticasb solution as standalone without fortigate, sase, or others?
Hey everyone I have been trying to login to our FortiCloud account to register couple of new FortiGates and im unable to because they security codes aren't being sent to our email. Also I did an passwort reset already and then I received an email. But I still dont receive the security code email while trying to login. Any ideas?
Following table outline’s, a set of Dependencies and Key points to be considered and useful with planning a migration of SSL-VPN deployment to IPSEC-VPN based deployment. Below Table is an effort of consolidating the functionalities and capabilities for effective planning of a migration. Content has been extracted from official Fortinet documentations and have put into a table for quick reference. FortiClient Version Dependencies Free Version - up to client Version 7.4.3 1. User Authentication through Local user database - IKEv1 - supported with XAUTH framework* - IKEv2 - Supported with EAP 2. User Authentication through LDAP - IKEv1- supported with XAUTH framework * - IKEv2 - Limitations with the way EAP framework operates EAP-TTLS method has to be used. FortiClient Free version has limitations of changing the EAP method. ** 3. User Authentication through RADIUS - IKEv1 - Supported with XAUTH Framework * - IKEv2 - Supported with EAP-MSCHAPv2
We use 600F and hosted switches and APs in the 7.2.13 system.After testing and TAC confirmation, the 600Fwith7.2 system will discard multicast of tunnel SSIDs.Users cannot use Airplay to discover Apple TV through tunnel SSID,even though I have already configured multicast and IPv4 policies according to KB.We have two suggestions, either use 'set capwap-offload disable' or try upgrading to 7.4 or higher for testing.But we currently do not plan to upgrade to 7.4 because it is not possible to directly configure switch ports such as "loop gurad" and "stp budp guard" on the web management page, and these features are precisely the reasons why we chose Fortinet.I would like to know if Fortinet will fix this bug in FortiiOS7.2?Thanks.
Servus Community,I'm trying to add a FortiGate-VM HA cluster (A-P) running FortiOS 7.4.11 to a FortiManager VM running 7.4.11. Both FortiGate VMs and the FortiManager VM are running in evaluation/trial mode.The cluster itself is healthy and synchronized. Network connectivity is fine and TCP/541 is reachable. I have also enabled:config system global set fgfm-allow-vm enableendWhen I try to add the FortiGate to FortiManager, the device discovery fails with "Probe failed".After enabling FGFM debugging, I noticed that the TLS handshake actually completes successfully. The FortiGate then sends its authentication information including the serial number:serialno=FGVMEVO4T9J2-XXXAt that point FortiManager rejects the session and logs:serial number (FGVMEVO4T9J2-XXX) in 'get' message doesn't match the subject CN (FortiGate) in peer's certificate.I then checked the certificates on both HA members.Both nodes have the same Fortinet_Factory certificate:Subject:CN = FortiGateThe certificate fingerpr
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.