Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
This isn't as dumb as it sounds at first glance, I promise! No, I'm not trying to print to a printer that is wirelessly connected to the same SSID, which would obviously be blocked by this setting.I'm trying to set up a wireless network for guests to be able to print to one of our printers, which is wired to a "printers" VLAN. I've set up a tunnel-mode SSID with the relevant multicast firewall policies for mDNS and WSD/SSDP, unicast policies for IPP and RAW, and a Bonjour profile for printers.So far, so good. iOS, Android, and Windows devices can all discover the printer and print. Until I enable the setting to block intra-SSID traffic, at which point none of them can see the printer anymore.Is that setting simply incompatible with multicast forwarding, or what might be going on here? I really want it enabled since I don't want guest devices to be able to communicate with each other. Would an L3 firewall profile potentially work instead?
Hello, I run this VM New deployment of FortiAnalyzer for VMware FAZ_VM64-v7.6.4.F-build3579-FORTINET.out.ovf.zip (477.27 MB) on VMware but I'm getting this error not sure what might be the reason.Any help would be appreciated.
Hello,I'm deploying a trusted CA certificate to a number of Fortigates devices that are in sync with FortiManager.This is not for full SSL inspection, but for trusting SSL connections to internal servers (the ones that go into Remote CA Certificates).Right now I'm using a script since I didn't find such functionality in 7.4.11. Dynamic Local Certificate seems to be only for full SSL inspection.bDid I miss anything or scripting is the way to go?Thanks
hi, we have recently upgraded our foritmanager, this fortimanager is already present as our asset in forticloud. When we upgraded our fortimanager, we checked it was not registered. when we enter the credentials to register it, it said the serial number is already present which means communication does not have any issue, but it is not being registered, can someone please help me to check would could be the possible reason or what to check ?
Has the problem with FortiClient VPN for Android been fixed? v7.6.5 causes Error: Could not establish session on the IPsec daemon'. This was reported months ago and now we are being told we have to go to 7.6.7 to remain compliant.
Hey everyone,We use FortiClient for VPN and web filtering, managed by EMS across a few hundred endpoints. On one workstation, the FortiClient Web Filter extension shows in Edge as "Managed by your organization" and can't be removed. No other endpoint has it — our own devices don't show it at all.Same FortiClient version, same EMS group and profile as the others, and there's no GPO pushing it.What causes FortiClient to force-install that extension on its own, and where would I look to find what triggered it on just that one machine?Thank you.
I’m trying to set up a full-tunnel SSL VPN on my Fortigate 60E running 7.4.6 and for what ever reason, when connected to Forticlient if I go to a website that shows your public IP (ie- www.whatismyipaddress.com), it is showing my laptop’s local internet connection’s public IP instead of the fortigate’s WAN IP. I have tried using the ‘full-tunnel’ portal, disabling the ‘tunnel-access’ portal, changing both to ‘full tunnel’ in the SSL VPN settings and disabling both and creating a new portal which is full tunnel, but whatever I do it keeps showing up with my laptop’s local internet connection. I did some packet traces and it *seems* to be egressing the Fortigate’s WAN interface but for whatever reason it keeps showing my laptop’s internet’s public IP. I can ping devices inside the network (behind the fortigate) just fine, so I know the VPN is working. It’s a real head-scratcher. Can anyone take a look at the config (attached to this post) and tell me what is going on? Of note, I did try
Hello, I am testing dynamic MAP-E connectivity on a FortiGate-100F running FortiOS 8.0.0 build 0167. The Internet service is So-net over the NTT East FLET'S network in Japan. The VNE service appears to be JPIX “v6 Plus.” DHCPv6-PD is working. The FortiGate receives a /56 delegated prefix and the WAN interface receives an IPv6 address derived from that prefix. The relevant WAN configuration is: config system interface edit "x1" set mode dhcp set role wan config ipv6 set ip6-mode delegated set dhcp6-prefix-delegation enable set ip6-delegated-prefix-iaid 1 set ip6-upstream-interface "x1" set ip6-subnet ::1/64 config dhcp6-iapd-list edit 1 set prefix-hint ::/56 next end end nextend After applying this configuration, the VNE diagnostic correctly recognizes the delegated prefix and WAN IPv6 address: end user ipv6 prefix: 240b:10:xx
I was looking through the IPAM settings and saved a change accidentally. I lost network access to my 60F as a result. Windows Terminal isn’t working on my pc. I’m looking for a software recommendation to access the 60F from the console port and any advice on how to turn off IPAM from the command line. I’ve only used the GUI so far. Thank you in advance !!
I have 2 WAN links provided by 2 different ISPs with load balancing in HA, and as it happened one of them have been down for a couple of days and the other one is working but occasionally going down.As an emergency solution I plugged in a cellular 5G router to a free port and added the port to the SD-WAN zone.Would it affect the load balancing between the original links if I raised the cost of the cellular link and given it a lower priority? I don't want to keep the traffic going through it if either of the main links is working fine.
Hi all, I tried installing forticlient VPN onto my new computer - Surface Laptop 7. However, it shows the following error. Anyone able to support to rectify this issue?
Hi, I'm having a problem installing the VPN with Forticlient. The installation stops prematurely and displays this message. Have you experienced something similar?
Hi all, have an HA pair of 120G devices running 7.2.13 that use SDWAN to load balance internet traffic between two different fiber circuits. I recently added a cellular backup circuit, but because the cellular bandwidth is relatively low and it’s a metered connection I don’t want to add this to the same SDWAN group/rule as the 2 load-balanced fiber circuits (OutboundWAN_loadbalance). I ended up creating a new SDWAN group (5G_Failover) and all/all rule for the cellular circuit and placed it in the lowest priority position - my objective being that if both fiber circuits go down, traffic will be routed through the cellular backup automatically. Will this work the way I think it will? Hoping to get some insight from someone who has set up something similar before I test this. See screenshot for clarity.
i Download VM Forti 8 and istall it but license invalid
Hi guys, I’m writing here after few weeks of working with Fortigate support. We went into dead end. I have full admin right on Google Workspace and Fortigate 30G running 7.6.7 build 3704, I’ve configured the LDAP as follows:FortiGate-30G (G_Workspace) # showconfig user ldap edit "G_Workspace" set server "ldap.google.com" set cnid "uid" set dn "ou=users,dc=spxxxxxxx,dc=pl" set secure ldaps set port 636 set client-cert-auth enable set client-cert "G_LDAP2" nextendTest Connectivity always works (this is misleading), Test User Credentials work fine - on any user which exist on my Workspace.Problem is when I want to press Browse button, I’m getting error “Invalid LDAP server” while from Workspace logs related to LDAP I can see:Event:Search failedDescription: LDAP search with (objectClass=*) failed with INSUFFICIENT_ACCESS_RIGHTS.Similar error I’m getting when I try to configure User Group based on G_Workspace profile - “Invalid LDAP ser
Hello everyone,FortiGate devices are documented to support a maximum WAN throughput when all UTP layers are enabled.What happens if you connect a WAN with a higher throughput? Is the WAN throughput throttled? Does the firewall stop providing protection? Does the firewall slow down?Thanks
Randomly i got complain from user that they loss access to the network, and if i check on the fnac i got error belowand from endpoint o got this errorIs the error because the fnac wrong send the server certificate? If i replug the LAN cable then the connection is working back.
Hello Fortinet Community,We are currently experiencing an issue where users connecting through the FortiClient IPsec remote-access VPN do not receive their email OTP.Environment:FortiGate model: FortiGate 100F FortiOS version/build: v7.6.7 build3704 (Mature) VPN type: IPsec remote-access VPN Two-factor authentication: Email OTP Email service: fortinet-notifications.com Issue started: September 4–5, 2026 Impact: Multiple/all VPN usersThe VPN authentication process reaches the stage where the user is waiting for the email OTP, but no OTP email is received. This configuration was previously working normally.We enabled the following debug commands:diagnose debug resetdiagnose debug console timestamp enablediagnose debug application fnbamd -1diagnose debug application alertmail -1diagnose debug enableThe certificate authentication shown in the debug completes successfully with:Cert status: GOOD auth_cert_successHowever, we did not see an AuthCode being generated or an SMTP connection initia
We have a strange scenario popping up in the lab for the new EDR deployments we were consulted to explore.Everything works normally except for when a USB dock is or SD card reader as it immediately crashes the computerRebooting the with the dock plugged in will trigger a Bitlocker recovery screenReboot without the dock and the computer comes up normallyRemoving EDR and leaving EMS resolves the issue, but the computer is unprotected by compliance standardsI suspect the card readers showing up as empty unwritable disks with a mounted drive letter is part of the problem, but not sure how to tell EDR to calm down about it.The crash:Your PC has run into a problemStop code: System_Thread_Exception_Not_Handled (0x7eE)What failed: partmgr.sysHas anyone seen an issue like this before?
For those who are trying to get the VMware and setting up EVE-NG , the problems are real .I tried to deploy FortiOS v7.6.7 but the Putty on EVE-NG CE said no bootable image or device found , even though the file was there in the EVE-NG but the putty for the FortiGate couldn't find it.The Problem is the Version and EVE-NG CE itself , EVE-NG doesn't support version 7.6.x versions and beyond.it supports 7.4.x sothose who are trying to set up a lab on EVE-NG CE just get a older image. only that is supportable.
Sharing this in case others run into the same thing, and to ask whetherthere is any plan to address it on the 7.4 branch.## SummaryOn a FortiAP-231K with region code "J" (Japan) managed by a FortiGaterunning FortiOS 7.4.x, only W52 channels (36/40/44/48) are selectablein the FortiAP Profile "Set Channels" screen.All DFS channels (W53: 52-64, W56: 100-144) and UNII-3 are greyed out.The "Toggle DFS Channels" and "Toggle Weather Radar Channels" buttonsare disabled as well.In Japan, 5 GHz regulations allow 20 channels in total (W52: 4, W53: 4,W56: 12). Being limited to 4 channels makes high-density design verydifficult, since the channel reuse distance collapses.## Environment and test results- FortiAP model: FAP-231K- Region code: J (Japan)- Country/Region on FortiGate: Japan- Management: FortiGate-managed (CAPWAP)- Radio: 5 GHz, 20 MHz widthI tested every FortiAP firmware from 7.4.5 through 7.6.5.Result: as long as the FortiGate is running FortiOS 7.4.x, the behaviourdoes not change at a
I asked for an extra IP from the ISP. For that they had given me /29 IP block.They said that they will work under the old pilot IP which was already given by ISP. That IP was configured WAN1 and internet are working well. But I need to use that additional IP under firewall.Because i am going to host one web application server. For that server i need to configure public IP directly.If it comes under the server means i can able manage and control who are all want access the app server. I am using FG101E.
LS,I have 2 questions with regards to Fortimanager and normalized interfaces.1. Is it possible, or will it be possible, to map 2 (or more) interfaces in the device mapping to 1 normalized interface. Example, VOICE (SSID) and VOICE (VLAN) interfaces being mapped in the Device Mapping to the normalized interface "Voice" 2. Assume I have a normalized interface Voice-ssid with in the device mapping all the fortigates(ssid) with an Voice SSID interface. I also have a normalized interface Voice-vlan with in the device mapping all the fortigates(vlan) with an Voice VLAN interface.Note that Fortigates(ssid) is not equal to fortigates(vlan).Some fortigates have only Voice-ssid, Some have Voice-vlan and some have both.My question is, can a policy-block where "incoming interface" has both the "Voice-ssid" and "Voice-vlan" applied on all the fortigates in my estate?
Hi all, I hope you're well. I'm currently investigating some connectivity issues users are reporting on AVD displaying 'Paused Connection'. At this site, we're running FortiSwitch 448E-FPOE's and in the system events I am seeing many 'port has come up' and 'port has come down' logs. I've reviewed the spanning-tree instance and confirmed that it is stable, root bridge is correct, no recent TCN's and no high usage of system resources (CPU/Memory) noted. There are no FCS errors or any other stats on the physical ports that would suggest faulty cables. All ports connect to Cisco IP phones and from the logs it looks like the physical port flaps first which then triggered STP port status changes. I'm going to test bypassing the phone and connecting the PC directly to our FortiSwitch to rule out the phone causing the issue but wanted to know if there are any other troubleshooting steps I can take to identify the route cause. Many thanks,&n
FortiGate-VMUL support unlimited vCPUs, but the datasheet does not tell how to calculate the throughput.I need a formula to calculate the throughput by vCPU number.And does the throughput grows linear by vCPU?Thank you.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.