Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We migrated the FW from SonicWall to Fortigate 201G after completing all configuration it’s working fine but the SAP tunnel having issue on migrating time we resolved it, but after 1 week facing flapping issue continously . Using ikev2 and pfs disable as recommended by SAP cloud.Also we are using separate subnets in phase2. Attached VPN logs.Our device Fortigate and SAP device Cisco ASA Kindly recommend if any things need to be check on Fortigate.current version fortiOS v7.4.11 build2878 (Mature)
Hey everyone,I'm currently working on my PFE (Graduation Project) focused on deploying a Zero Trust Architecture using the Fortinet Security Fabric. I’m finalizing the deployment strategy for the FortiClient custom installer distribution, and I'd love to get some architectural feedback from the community.The Goal: Securely distribute the custom installer generated in EMS to remote endpoints during an initial onboarding period, and then tightly lock down registration afterward.The Environment: My core EMS server lives inside the secure Server LAN.For both options below, the download page is protected by a FortiWeb WAF that requires Active Directory (AD) pre-authentication before a user can access the installer. However, given the recent high-severity vulnerabilities (like the 8013 auth bypass CVEs), I am highly paranoid about zero-days and expanding the internal attack surface unnecessarily.Here are the two design paths I am debating:Option 1 (Dedicated DMZ Server + WAF + AD Auth)
Hello,I’m facing an issue with EMS endpoint alert emails. The email includes a report link for full details, but when I open it, I get the following message:“Redirect Notice – The page you were on is trying to send you to an invalid URL.”Has anyone faced this issue before or found a solution for it?
I have configured the following in a new Active-Passive setupUnit A (setup as Active 120 HA) - mgmt IP address 10.1.1.5/24 (set management ip and dedicated-management)Unit B (setup as Passive 115 HA) - Mgmt IP address 10.1.1.6/24(set management ip and dedicated-management) HA on both group ID 1tracking port2“port2” configured on both units as IP address 10.1.1.10/24 Both units are only pingable sometimes, MAC flapping messages appear every 5 seconds on both Arista switches setup as a MLAGBoth units have the same virtual MAC address (get hardware nic mgmt) other units I have setup exactly the same a-p, have different mgmt MAC’s between A and B! If I remove the group-id from Unit B, everything works, both units pingable and accessible. When I add the group-id back into Unit B, problem persists. I have even changed the group-id on both from 1 to 256, same problem. How can this be, I have checked pretty much everything but obviously there is sometime I am missing? Thanks all for any inpu
I have requirement to use one SSID for employee and guest, the employee will use EAP-TLS for authenticate and if authentication failure because the client no have certificate then the endpoint will access to guest network.This was done for wired connection (employee and guest) but on wireless connection only employee was work, if the wireless client not have certificate then the client is asked to enter the username and password. Anyone know how to achieve this?
I got a FS108D from work nothing crazy about it. I created a VLAN on it but after I did that it doesn’t show anything else on the page I inspected the browser and it says 500 Server error. It has 8 ports and I want to create some VLAN for my devices.Whats is the issue here?
HI All I need to get some guidance on how we can deploy below network Firewall HA ( 2 LAN port1 and port2 in same hardware switch), Port 1 on both FG connect to cisco switch 1 and cisco switch 2 respectively. Port 2 on both FG connect to cisco switch 1 and 2 respectively alsoCisco Switch 1 and 2 also interconnected(trunk port). Cisco runs RPVST+. Switch1 runs as STP root primary, Switch 2 runs as STP root secondaryAbove topology eventually create loop network. How should it be configured to avoid the loopFortigate hardware switch if disable STP, it eventaally create loop, and broadcast storm starts. Enable STP on FG hardware , eventually the broadcast stops. But i found some weird result. When i check Switch2 STP, it blocks the port connect to FG1, but port connect to FG2 becomes root, and forward state. Switch2 can still somehow reach FG IP, the mac-address also shows it learned from port to FG2. But FG2 runs as HA passive state. i try diagnose sniffer on FG2, nothing captured. How
I'm struggling a bit with my performance SLAs and SDWAN Rules. My typical branch office will have 2 internet connections, one is usually better than the other (i.e., Verizon FiOS plus Comcast or true DIA Fiber plus a business broadband).What's the best-practice strat for SDWAN rule? I've been mostly relying on Best Quality rule with a performance SLA that pings Google DNS (8.8.8.8), but I'm seeing more flapping than I would expect.I think my first question is: Do the Performance SLA settings under Link Status (Check Interval and Failure before inactive) affect the SLAs themselves? If I have my latency SLA set at 250ms, is the interface in violation of the SLA the first time if sees latency greater than 250ms or if my check interval is 1000ms and failure before inactive is 5, does it take 5 seconds of 250ms latency to violate the SLA?Any best-practice recommendations on these rules and Perf SLAs? I'm starting to think that Google DNS might not be the best candidate host for my probe. Do
I setup a lab environment with a FortiGate evaluation. All good… I needed to blow it all away and start again… I can see the asset in my portal, and I can download the lic file, but on a new install it does not accept it and gives me: Am I missing something here?
Hi,One of my clients have sip traffic passing through firewall. When we view forward logs firewall shows lots of logs with "0 Bytes sent/received". What does it mean?.
Hi, i have a Fortigate 200D Firewall with FortiOS 6.0.16 and a Huawei 4G Webstick Modell 3372h. I can't bring the Connection to the LTE-Network up. I searched around and found this https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-Huawei-E3372-h-modem-stick/ta-p/193600 The Problem is, that i have the AT-Command Version of this Stick and this HowTo is for the Web-Interface Version. When i try to configure the Stick as lte-modemdiagnose sys lte-modem infosays, that the Modem is not connected. So i tried to configure the Stick as "normal" Modem. The Modem itself seems to work properly: diagnose sys modem queryUSB status: Connectedmanufacturer: huaweimodel: E3372IMEI number: 868230032061123SIM state: Validservice status: Valid Servicesignal level: 3/4network name: E-Plusnetwork type: E-UTRANlocation area code:active profile(AT&V):COMMAND NOT SUPPORT^RSSI:18^HCSQ:"LTE",45,47,136,26 But in the Debug Messages a Timout occures (At
Hello FortiPeople, I’m checking if there’s a possibility to create a “recipient verification” exception for a particular source IP address. Let me explain:We have a particular client application, which sends e-mails to multiple addresses in one SMTP session.Whenever there’s a bad recipient address in the list of recipients, the application logically gets a “550 5.1.1 ... User unknown” reply from the FortiMail, via the recipient verification options set in the domain settings.However, where this SMTP client differs compared to other SMTP clients like Exchange Online, is that it quits the session after this reply and will not send the mail for ANY of the recipient, so no one receives the e-mail when only 1 address is bad.Exchange Online, for example, will continue on the same session (verified in the logs by session ID) and just continue for all the good addresses, which will then receive the mail. We tested with Thunderbird as an SMTP client, which also gives the same behaviour (SMTP se
Got a batch of forti switch 124g.Has anyone else got them?Do they also make an extremely high pitched whine like the capacitors about to blow?I've raised a ticket with support as these are brand new but wondered if this was a commonly known issue with them or I'm just unlucky?
Hi everyone,I am using 1 Hub, 2 spokes, FortiOS 7.6.3, ADVPN 2.0, BGP loopback peering without overlay IP.So, every things is good, ADVPN works right, just a problem for peering dynamic BGP between spokes.When spoke to spoke wants to speak (test by loopback addresses), auto shortucky is established, Good, but spokes cannot established BGP peering, based on my diagnose, TCP 179 will be drop due no match selector in IPsec, it seems that problem is the Tunnel between spokes but no, tunnel will established without any problem, but BGP cannot.I should note that if I use 'execute restart router' , so spokes start to establish BGP peering! it means that tunnel is not problem.The main problem is that BGP peering starts to etablish between spokes before complete establishing tunnel.So, I am looking for a way to make some delay, just a second or 2 second in BGP peering process or restart BGP peering establishing between spokes after ADVPN establishing.Can you help me how can I do it ?
Static ip update on ISP then Fortidydns is not working
I was curious if anyone was already ingesting the Malicious IP and/or Domain Lists from their MS-ISAC membership? Someone asked in another community thread if those were included in the Fortigate threat feeds somewhere, but didn't get a response. I’ve gone through the steps in several documents from support, but keep running into an Internal Error on my Fortigate when I refresh the object. I figured I would check and see if someone had already figured this out and would mind sharing the configuration settings they used to create their successful objects. I’m running a case with support but it’s slow going.
Hello everyone,I am currently experiencing an issue integrating a FortiGate VM with a FortiManager VM (version 7.6.6).When trying to authorize the FortiManager from the FortiGate GUI, I receive the following error:"Could not connect to the FortiManager to retrieve its serial number"I already followed the official Fortinet KB below without success:https://community.fortinet.com/fortigate-3/technical-tip-error-on-gui-could-not-connect-to-the-fortimanager-to-retrieve-its-serial-number-205398Additionally, the following command is not available/supported on my FortiManager:set fgfm-peercert-withoutsn enableConnectivity between both VMs is working correctly, and basic FGFM communication appears reachable.Has anyone experienced this issue on FortiManager 7.6.6 or found an alternative workaround to complete the integration successfully?Any guidance would be greatly appreciated.Thank you.
My two favourite pubs are both owned by the Greene King chain. There is no cellular signal at either of them so I like to use their free wi-fi. Everything works as expected on a public wi-fi except when I browse one particular site I get a warning that someone may be trying to intercept my communications. Only that one site (so far as I know). The site's legitimate certificate from Let's Encrypt is replaced by a fake one which claims to be issued by Fortinet. I would like to know what is going on; am I being snooped on?
What is everyone's plan for replacing SSL/RADIUS certs moving forward since certificate lifetimes are decreasing drastically over the next few years? Does FortiNAC have any plans to allow for automatic renewals? Once 2029 comes and the expiry is 45 days, it's going to be a headache to renew and upload manually.
Here is what I want to achieve with using Fortigate as a DNS server for all remote locations.For internal users, using Fortigate interface IP as a DNS server. Fortigate will forward any public domain name queries to system DNS servers while any internal domain names to HQ DNS servers. The issue I’m having is the internal DNS queries are not working. Outside DNS resolution works fine.Any suggestions? Let me know if you need more details on my configs. Thanks.
Hey everyone,We’re reviewing our outbound mail flow with FortiMail and wanted to ask if anyone here is using a Bulk email service provider alongside Fortinet infrastructure for newsletters or transactional email delivery.I’ve been testing a few services, including DigitalAka™, mainly to improve deliverability and reduce reputation issues on production mail servers. Curious to know what configurations or relay setups others are using with FortiMail.
HiWhen the USB Type A cable is connected to the Fortigate 60F USB Mng input and the other side of the USB cable Type C is connected to the LapTop then no connection takes place. Note the cable is a USB Data cable Type A to Type C. Is a UDB Driver required ? Thank you
Hello there, if anyone has experience with implementing agentless ZTNA, I would really appreciate your help if you look at this issue and help me with that. i am trying but it is not working somehow. It is also very appreciated if you can offer consultation voluntarily or you know someone who can do it, please refer to them. Here is the ticket: https://community.fortinet.com/support-forum-92/agentless-ztna-tutorial-227295?postid=228019#post228019
How do I schedule a reboot in FortiGate firewall at a certain time from remote ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.