Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
FortiWeb exporting and import ML learnings through API. I need to check the Fortinet Developer Network (FNDN) as to have FortiWeb in a staging environment that has ML enabled and then to export the ML learnings through API and import them on the production FortiWeb again through API will be really powerful thing. The production FortiWeb in this case does not need ML learning enabled actually enabled as maybe limiting on production the learning to fake IP as it is not needed and on Staging to the Staging Jump host or staging subnet or not limiting at all if the network is safely designed.
Hi All,I would like to ask your help about BGP with my scenario.I have FG1 connect with some FG Spoke via MPLS and VPN tunnel. I configured BGP peer for each link with the neighbor is the ip of each link.I want to prevent FG1 advertise route learned from MPLS back to FG2 via VPN tunnel and vice versa. I tried with route map out and comminity and it work for mpls because there are separate mpls for spoke but for vpn tunnel I cant because the VPN tunnel is peering with other Spoke.Could someone advise me the solution for the scenario?
Dear Fortinet Community,I am currently experiencing an issue with a FortiOS upgrade. I have unboxed two newly acquired FortiGate devices (200G and 90G), both of which are not yet license-activated.I attempted to upgrade their firmware to version 7.4.12. The FortiGate 200G was initially running 7.2.11, and I was able to upgrade it to 7.4.11, but the upgrade to 7.4.12 did not succeed. The FortiGate 90G was running 7.4.8, and I was unable to upgrade it to any other version.I am aware that from the 7.4.x branch onward, upgrades are generally limited to patch-level changes. However, in my case, this behavior is not consistent as expected.Any assistance in resolving this issue would be greatly appreciated.Best regards.
I have successfull sync my entra id group to the fortinac, however if i add someone to the group then why the user is not synced in fortinac?Example i add user1 to group IT then if i go to System-Groups-Remote Groups then the member still empty.
Hi, i tried to deploy FortiManager following this doc: https://docs.fortinet.com/document/fortimanager-private-cloud/8.0.0/microsoft-hyper-v-administration-guide/449452/creating-the-virtual-machineAdded a second Hard Disk in “IDE 0” Show me this error, i tried to create Fixed and Dynamically (in differents clear installations) but same error appears even when i have enough space.After this error i cant type in terminal. Any suggestion?
FG-80FでHA構成を構築したが、「config firewall ssh local-key」の状態がPrimaryとSecondaryで異なるのはなんで?? #Primaryconfig firewall ssh local-key edit "Fortinet_SSH_RSA2048" set password ENC AAAAELE8NqYyMBgEhQ7grTfXnpgDb0j1zQrGm/aSSQ1sqReRT3VeDXYDl6GmJTfjifhoYZqMV94zwzYt3BI8Li3/XhV3YaPXywj7lf2VBcKfDSbZbTvJO/8fw2pN25HAxq6I4/cd3ZX90abcxiEdz3oQ1adKVpy/75tzDx95iKJ04o6uTMByeivFhMvKizbm2xAEE1lmMjY3dkVA unset private-key unset public-key set source built-in next #Secondaryconfig firewall ssh local-key edit "Fortinet_SSH_RSA2048" set password ENC AAAAELE8NqYyMBgEhQ7grTfXnpgDb0j1zQrGm/aSSQ1sqReRT3VeDXYDl6GmJTfjifhoYZqMV94zwzYt3BI8Li3/XhVKqNqqBKwoZqTJvhlyp3Zj30tjCJrI4bRFjiacIgfgGLajHp73E3BtG700kjxkxzUMlTFHFg7OPISbONaK1IoYVL17IOcl6QzL6wR9NJMnLVlmMjY3dkVA set private-key "-----BEGIN OPENSSH PRIVATE KEY-----b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABCEPyKnpOC7AuAUn8wkg717AAAAEAAAAAEAAAEXAAAAB3NzaC1yc2EAAAADAQABAAABAQC37dLSRQBZoOb49bsDn/YVhLuGlHio5XLLl9Dzy
I installed FortiClient VPN 7.4.3.1736 (forticlient_vpn_7.4.3.1736_amd64.deb) on Ubuntu 24.04 using the package downloaded from the official Fortinet website.The VPN itself appears to work correctly and I can successfully connect to my VPN gateway.However, every time I start FortiClient VPN, I always receive one or more popup messages reporting conflicts or errors related to NetworkManager. The popup then asks whether I would like to upload the error report.Although the VPN is functional, these error popups appear every time the application starts, which suggests there may be a compatibility issue or a missing component.I have already tried several troubleshooting steps suggested by ChatGPT, but none of them resolved the problem.I was also told that FortiClient VPN 7.4.4 or 7.4.5 might contain fixes for Ubuntu 24.04, but I cannot find these versions on the Fortinet download site.Could anyone please advise:- Is this a known issue with FortiClient VPN 7.4.3 on Ubuntu 24.04?- Are FortiCli
Hello,According to the FortiGate Administration Guide, https://docs.fortinet.com/document/fortigate/8.0.0/administration-guide/155426web filters are applied in this order:URL filter FortiGuard Web Filtering Web content filter Web script filter Antivirus scanningI'm confused about the last step. Antivirus is a separate security profile, not a web filtering feature. Why is it included in the web filtering order? Is this order only relevant when both Web Filter and Antivirus profiles are applied to the same policy?also i see that:…...The FortiGate’s WAD daemon sends the URLs to FortiGuard in real-time for category determination.is that the webfilter process by wad even if it in flow or proxy mode?
Good day,I would like to verify that whether the local network configuration, such as static route, traffic with security files, will stop when deregister the device from Cloud managment, no not.BrgdsLiu Wei
I may have missed this and hope this is not a repost. In the screenshot, we have isolated a custom view of 10 mins and the graph is showing the Bytes in GB. Is this right?
Fortigate Automation Stich is great! If you have a security fabric configured you can automate a lot of stuff. You can automate a process restart if there is high CPU or memory :) Example: High CPU event trigger is already existing but for the memory it is called Conservative mode. You can probably use also Playbooks if FortiAnalyzer is licensed for them or FortiManager to push a CLI script to all firewalls if you have no security fabric configured. Posts from which I got the idea: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-restart-WAD-process-on-a-specific-day-and/ta-p/329282#M8818 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Execute-a-CLI-Script-based-on-High-Memory-using/ta-p/197758 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Execute-a-CLI-script-based-on-high-CPU/ta-p/195103
As someone who played with the Declarative API here are some tips and tricks. The declarative API can be used for General System settings and creating VirtualServer/RealServer/Pool objects in the default root VDOM or even in specific Vdoms for multitenant systems. You can do manual changes with GUI/CLI or REST-API and they are reflected in the Declarative API when you do GET requests. As the documentation for it is not much I am making this article. First see Does FortiADC support Declarative API for VirtualServers? | Community as I have added some useful stuff there as well. Send all specific vdom real servers and server pools in a single declaration as if not you can get an error that the declarative API is trying delete previously send realservers and pools in a previous declaration. You can send virtualserver config in the same declarations as the real server and real server pool but the declaration needs to start with the virtual servers first or you can first send all the real s
I have a printer located in one VLAN and a macOS laptop connected to another VLAN.The printer is connected via Ethernet, while the laptop connects through a FortiAP (Wi-Fi).As both devices are on different VLANs, the laptop fails to automatically discover the printer and displays a “Check Internet Connectivity” message. However, when I manually add the printer’s IP address, it connects successfully. There is a firewall policy to allow traffic between thoses two VLANs (Any services).It appears that the discovery packets (likely mDNS / AirPrint traffic) are not being forwarded between the two VLANs.Can you please help how to solve this issue ?
Probably the most bizarre IT problem I've ever come across. We are in the process of migrating from Aruba to Fortinet, wired and wireless. One building has now been completely moved to FortiAPs and since day one we've been experiencing random disconnections from our WPA2-Enterprise SSID.The initial symptoms were these: out of the blue, without moving, a device would lose internet connection, showing the 'globe' in the bottom right corner (Windows), claiming to still be connected to the network, but with no internet and with an auto-assigned APIPA address.Having done A LOT of investigation, most of the time with little to no result, I have noticed that clients are very frequently re-associating (often with the same AP), sometimes failing (hence the 'disconnections'). The signal is high, APs are generally a few feet away, it happens on both 2.4 and 5Ghz. We have done a lot of tweaking, including changes recommended by Fortinet Support, which included disabling fast roaming, PMF
how is working this rule executable_windows?? FortiMail Attachment Scan Rules (executable_windows), was catched this file 1.pdf:( detected by Content Filter, filetype application/javascript filename ABC.js in file ABC2 Integration Document - Phase 1.pdf, attachment scan rule: executable_windows). but when downloaded that file to scan by Sandbox, the file was clean result?? Any one had same this problem, and was solved?
after Upgrading From 7.4.12 to 7.6.7 on FGT70G all users with Fortitoken Cloud cannot connect IPSEC VPN IKE2 , the only way is to remove the token.
Hi All,We just opgraded a few sites to FortiOS 7.6.7 on the Gates running as Wireless Controllers (VMs), and then a few FortiAP 23JK (Inroom) to FW 7.6.5.That breaks PoE Passthrough on port3.Downgrading the AP to 7.6.4 again, brings back the PoE passthrough on port3.
Hi, I would like to filter out all the IP from network 192.168.11.0. Could you guide what is value should I input? I try type 192.168.11.* , or 192.168.11.0 or 192.168.11.1-192.168.11.100. no correct result. BrgdsLiu Wei
Hello everyone, I encountered issue where after I reload on of my core switches I lose connection to Access Switch even tho its connected redundantly to my other Core switch. This is diagram of the connection:Network diagramI am running 400F in HA cluster in Active-Passive mode. From both Fortigates I have Fortilink towards my Core switches. The switches are in MCLAG stack with Fortilink split interface disabled. We connected multiple access switches to the Core stack and they all link up correctly, they have been discovered by Switch Controller on 400F and they created the trunk interfaces towards the Core switches. (automatically)When we reload CORE1 for example we lose connection to the access switch for the time the CORE is being reloaded. We did some troubleshooting and were checking STP states on CORE2 and state of the trunks during the reload. We noticed weird thing when connected to CORE2 via CLI while CORE1 was reloading → We ran some diag commands for trunks and the trunk inf
Hello Everyone, I see that /api/declarative is desribed in fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/7a380719-1f54-11ed-9eba-fa163e15d75b/fortiadc-v7.1.0-handbook.pdf The example is for posting system configuration (Simmilar to F5 DO declarative onboarding) but what about Virtual Servers to be created declaratively ? Something like F5 AS3 way to deploy Virtual Servers. Also is there such options for the WAF?
Could you help me with a suggestion?We have a FortiGate HA setup with two ISP links. The customer wants the SSL VPN service to remain available regardless of which ISP link goes down, so that user connectivity is not impacted.One option is to configure SSL VPN access on both ISP connections. However, I have a question regarding routing behavior. If I configure two default routes for WAN1 and WAN2, with WAN1 as the preferred route, what happens when a user connects to the SSL VPN using the public IP address associated with WAN2? edit 1set dst 0.0.0.0/0set gateway <ISP1_GW>set device "wan1"set distance 10nextedit 2set dst 0.0.0.0/0set gateway <ISP2_GW>set device "wan2"set distance 20next Will the SSL VPN connection work correctly, or could there be issues due to the return traffic being routed out through the preferred WAN1 interface instead of WAN2, or it will be return via wan2 maintain symmetry.similarly., customer want to have DNAT polices for internal services to remain
I have a FortiWeb that is used for our QA environment that is not exposed to the internet. I need to be able to manage certificates on it automatically to avoid having to manually replace them every month as the lifecycle shortens. DNS-01 is completely manual so that's out. I tried HTTP-01 using an internal private ACME server, but the Fortiweb rejects the certificate when making the https request to the ACME server because it is signed by our internal CA. Does anyone have a method they are happy with for managing certificates in this situation?
Dear forti users,I would like to ask why the hb_packet_version number is different on a primary and secondary member in a ha cluster?We have 4 cluster and this is the exact same situation in every one. The devices ordered in pair for cluster, so it hardware and config is matching.One cluster a little bit different in that term I tried to add a third member (which have different bios and part-number version number, but every other parameter is also the same). Unfortunaty there very problems in syncing so I removed it from cluster. Can be the source of the hb_packet_version differences on those cluster? The support said the the version numbers must match. Really should match?fortios 7.0.17Thank you
Dear All,I had to configure Site 2 site IPsec tunnel with cisco router with using OSPF protocol so I thought, First do the lab then implement. I was doing lab to configure IPsec tunnel with cisco (CISCO CONFIG (VTI + IPsec + OSPF). but unfortunately Fortigate does not support AES encryption in config phase 1 and 2 setting. on the other side cisco router support AES encryption does not support legacy encryption like DES. Fortigate proposal setting - BR1-FW1 (phase2-interface) # edit BR12BR1BR1-FW1 (BR12BR1) # set proposalnull-md5 null-md5null-sha1 null-sha1null-sha256 null-sha256null-sha384 null-sha384null-sha512 null-sha512des-null des-nulldes-md5 des-md5des-sha1 des-sha1des-sha256 des-sha256des-sha384 des-sha384des-sha512 des-sha512BR1-FW1 (BR12BR1) # set proposalexitcisco router phase 2 proposal ( cisco router setting)BR2(config)#crypto ipsec transform-set MY_TRANSFORM_SET ? ah-md5-hmac AH-HMAC-MD5 transform ah-sha-hmac
Can you help me to find the FortiGate logs?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.