Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I was curious if anyone was already ingesting the Malicious IP and/or Domain Lists from their MS-ISAC membership? Someone asked in another community thread if those were included in the Fortigate threat feeds somewhere, but didn't get a response. I’ve gone through the steps in several documents from support, but keep running into an Internal Error on my Fortigate when I refresh the object. I figured I would check and see if someone had already figured this out and would mind sharing the configuration settings they used to create their successful objects. I’m running a case with support but it’s slow going.
Hello everyone,I am currently experiencing an issue integrating a FortiGate VM with a FortiManager VM (version 7.6.6).When trying to authorize the FortiManager from the FortiGate GUI, I receive the following error:"Could not connect to the FortiManager to retrieve its serial number"I already followed the official Fortinet KB below without success:https://community.fortinet.com/fortigate-3/technical-tip-error-on-gui-could-not-connect-to-the-fortimanager-to-retrieve-its-serial-number-205398Additionally, the following command is not available/supported on my FortiManager:set fgfm-peercert-withoutsn enableConnectivity between both VMs is working correctly, and basic FGFM communication appears reachable.Has anyone experienced this issue on FortiManager 7.6.6 or found an alternative workaround to complete the integration successfully?Any guidance would be greatly appreciated.Thank you.
My two favourite pubs are both owned by the Greene King chain. There is no cellular signal at either of them so I like to use their free wi-fi. Everything works as expected on a public wi-fi except when I browse one particular site I get a warning that someone may be trying to intercept my communications. Only that one site (so far as I know). The site's legitimate certificate from Let's Encrypt is replaced by a fake one which claims to be issued by Fortinet. I would like to know what is going on; am I being snooped on?
What is everyone's plan for replacing SSL/RADIUS certs moving forward since certificate lifetimes are decreasing drastically over the next few years? Does FortiNAC have any plans to allow for automatic renewals? Once 2029 comes and the expiry is 45 days, it's going to be a headache to renew and upload manually.
Here is what I want to achieve with using Fortigate as a DNS server for all remote locations.For internal users, using Fortigate interface IP as a DNS server. Fortigate will forward any public domain name queries to system DNS servers while any internal domain names to HQ DNS servers. The issue I’m having is the internal DNS queries are not working. Outside DNS resolution works fine.Any suggestions? Let me know if you need more details on my configs. Thanks.
Hey everyone,We’re reviewing our outbound mail flow with FortiMail and wanted to ask if anyone here is using a Bulk email service provider alongside Fortinet infrastructure for newsletters or transactional email delivery.I’ve been testing a few services, including DigitalAka™, mainly to improve deliverability and reduce reputation issues on production mail servers. Curious to know what configurations or relay setups others are using with FortiMail.
HiWhen the USB Type A cable is connected to the Fortigate 60F USB Mng input and the other side of the USB cable Type C is connected to the LapTop then no connection takes place. Note the cable is a USB Data cable Type A to Type C. Is a UDB Driver required ? Thank you
Hello there, if anyone has experience with implementing agentless ZTNA, I would really appreciate your help if you look at this issue and help me with that. i am trying but it is not working somehow. It is also very appreciated if you can offer consultation voluntarily or you know someone who can do it, please refer to them. Here is the ticket: https://community.fortinet.com/support-forum-92/agentless-ztna-tutorial-227295?postid=228019#post228019
How do I schedule a reboot in FortiGate firewall at a certain time from remote ?
We’re currently testing BGP neighbor status changed alert, so everything is configured and after I trigger the alarm by deleting BGP neighbor from FMG by navigating to the HUB then (network>>BGP>>neighbors' range) then deleting one of the neighbors' subnets which refers to the spoke's devices range, the BGP tunnel doesn’t goes down and shows Established and the deleted subnet also appearing i the routing table on CLI.the question is does my action was correct? and it’s a BUG in the system or there is something that I should do different?
Recently we have feedback from users that they cannot get the team viewer quick support exe file TeamViewerhow do i whitelist this URL so that my users can get the file for remote support ?
Anyone know wbaout below error and how to fix this when try configure the eap-tls?failed continuing EAP TLS (13) session. EAP sub-module failed
Hello all,I tried to update my devices managed by EMS to FortiClient 7.4.6, but all users on this version are not connected to EMS anymore. When I connect to the devices, it seems the FortiClient is not running.When I start it manually directly from the install folder, the FortiClient is starting and tries to sync, but as soon as the countdown reaches 0 and the client tries to sync, the FortiClient crashes and stops running.Anyone known what happened and if there is any workaround who not involved reinstall of the FortiClient in older version ?
I have my FortAnalyzer VM where I store logs from several FortiGate firewalls in different DOMs. Until last week, I had the information available for all the firewalls, but now the logs have stopped being recorded. The devices have an active connection to FortAnalyzer. As of today, I have the logs, but from May 17th and earlier, I have no information at all.What could be happening? Why are my reports suspended? Your help would be greatly appreciated!
Hi!There is very general guide to use backup ip:https://docs.fortinet.com/document/fortinac-f/7.6.0/n-1-failover-group-and-load-balancing/433478/option-2-using-backup-ip-for-n-1-failover-groupNot so well explained in that documentation.What are the real differences of Shared and Independent mode? This functionality also seems not to be finished yet(testing 7.6.6)? For example:If i test “shared” with this simple setup:Result:When primary is “running” and secondary is “standby”Primary uses the backup address as secondary address in port1:BUT, when secondary gets active after failover, it adds the IP address to the defined VLAN: So is this expected? Why does primary use secondary address in port1, but secondary uses VLAN???----Then the “Indedpendent” mode: RESULT:When primary is active, backup IP doesn’t exist at all BUT when the secondary node becomes active, it has the backup address as secondary address in port1: This isn’t expected either? And last:If i remove shared configuration,
Hello there! I think I’m missing out something simple.I’m on FortiOS 7.4.12. This FW is filtering all traffic from workstation to the Internet via a policy with web filter enabled that allows (among others) Google map navigation.Now I need to temporary allow Chrome updates in addition to the traffic usually allowed by my webfilter.I know there is a specific application control for that but I don’t understand how to use it. I can’t put this profile in my usual rule as I do NOT want the webfilter to be modified. I can’t put a policy with the application control before my webfilter rule as this would block all non-update traffic. I can’t put a policy with application control after my webfilter policy as this would never match.How to achive this?Thank you in advance!
I’m designing a FortiAuthenticator EAP TLS setup where the user base is LDAP (Active Directory), supporting two types of endpoints: Domain-joined laptops (already managed) , certificates already present on the user device.BYOD devices (user-owned) Both need to authenticate via EAP-TLS for Wi-Fi (802.1X) using FortiGate + FortiAuthenticator. Current setup:Domain-joined devices:Certificates pushed via GPO from internal PKIEAP-TLS with certificate binding is already workingUsername is derived from the certificate CN and mapped to LDAPEAP -TLS for domain joined devices is working. And I am also able to assign dynamic vlans via radius attributes configured in the FAC user group. BYOD devices:Will be onboarded via SmartConnectAuthentication to LDAP is required firstCertificates will be issued to the device so it can use EAP-TLS Questions:For BYOD onboarding, is it better to use a local CA on FortiAuthenticator, or should I issue certificates from the LDAP/AD CA via S
Hello,I have a 3 Gbps symmetric internet connection. Topology: VM → vSwitch → backbone switch → FortiGate → IPS router → ISP.Speedtest results from two different VMs:192.168.0.0/24 segment VM: Download 2500 Mbps, Upload 1995 Mbps ✓ 10.100.10.0/24 segment VM: Download 2421 Mbps, Upload 554 Mbps ✗Both VMs run on the same hypervisor and both use vmxnet3 vNICs. Download is at full speed on both; the problem is only on the upload direction of 10.100.10.0/24There are no traffic shaping rules on the FortiGate.2 gb set srcintf "Zone_1" set dstintf "net” set action accept set srcaddr "all" set dstaddr "all" set schedule "always" set service "ALL" set utm-status enable set inspection-mode proxy set profile-protocol-options "custom-default" set ssl-ssh-profile "__upg_certificate-inspection" set logtraffic all set nat enable 500mb set srcintf "Zone_2" set dstintf "net" set action accept
Dear All,Some of the websites are getting monitored from Fortigate performance SLA, getting high latency.When I check using ping,traceroute in fortigate using CLI showing normal latency. Even I also checked from LAN machine showing normal latency. unable to find root cause of it, Could you please tell us what could be cause of showing high latency for some websites in Fortigate peformance SLA. Thanks in advanced.
Hi I want to have 1 single FortiGuard license for my 2x100F FortiGate.You have the doc if the devices are not yet registered, but i want to do this with already registerd device is this possible?FYI Doc, how to do if the devices are not registered.https://docs.fortinet.com/document/fortigate/7.4.11/administration-guide/246857
Hi- I am trying to take config backup using CLI and facing errors. Pings, Trace, Sniffer all are giving outputs FTP - Getting bellow errorConnect to ftp server <FTP server IP>Please wait...Send config file to ftp server via vdom root failed.Command fail. Return code 10 Using TFT- This is taking very long time and backup is not getting fully completed and gets timed outVersion of Firmware is v7.4.8 , , v7.4.9 , FortiOS v6.2.17 build1405 (GA) Eventually, what I am trying to do is take config backup and then upgrade the OS version using python and API commands. Guss that will also give issues
Hi I’ve been using the FortiClient app for many years on my personal Surface Pro 7 device. Not had any issues, but recently we’ve taken part in a vulnerability audit and the app is flagging a few issues. The solution is to update, but I’m struggling to do so. I had version 7.4.3 installed but need 7.4.5 for the vulnerability to be cleared. When I download the latest software file it doesn’t show any version options. Instead, it I think it pulls down the latest version it can. I’ve tried to reinstall but still only getting to 7.4.3. I’ve seen a post regarding Snapdragon processors not being compliant, with newer versions of the Surface Pro. That may explain why my colleagues Pro 12 is not working at all with the app. But my older 7 model works fine, but I just need help updating. Many thanks
Hi I’ve one Fortigate 40F with firmware version v6.4.6 build6083 (GA).What is the suggested upgrade path. The target is to reach v7.4.12(Mature) ThanksVenkat
Hello everyone. I want to enable the sandbox feature on my firewall, and my license supports it. However, how can I ensure that my files, which will be uploaded and scanned to the cloud, are secure and won't be accessed by third parties? I want to know that uploading them to the cloud is solely for scanning and then they are removed... Is there any guarantee that my data will remain safe from being accessed by any other parties, including Fortigate?
Questions, we have Fortigates in HA managed by FortiManager.If we make changes in FortiManager and install, what is the correct way to roll back changes from the FortiManager?If we make changes in FortiManager but didn't install, what is the correct way to undo the changes?If we modify the Fortigate directly, does the changes gets synced to FortiManager?Thank you.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.