Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello FortiSIEM Community,I’m currently working on creating a custom parser for Aruba EdgeConnect logs in FortiSIEM, but I’m facing an issue during parser validation.Each time I create or modify the parser, the validation fails with the following error:Failed to execute node: when. Please check the usage of API and attribute name.I have double-checked the parser XML and verified that the attributes I’m using, such as hostName, procName, user, command, eventType, destName, destIpAddr, and srcIpAddr, are defined and supported in FortiSIEM.However, the error does not indicate which specific node, API, or attribute is causing the failure, which makes troubleshooting difficult.I have attached a screenshot of the parser validation error along with the current parser configuration.Would anyone with experience in FortiSIEM custom parser development be able to assist me in identifying the root cause and correcting the parser?Any guidance or example of the correct parser structure would be grea
I have some Reolink camera equipment on my network. Its all on the same VLAN (2 different switches), and it talks to each other, but the devices are showing the wrong IP. If I look in the Fortigate on the port the NVR is connected to for example, it says its IP is totally different than what shows on the NVR when I go into its settings. A different subnet even, as the FG says 10.x.x.x but on the device it says 192.x.x.x. Now I imagine this is just the device’s internal network it creates perhaps. But its the same thing for the cameras which are connected directly to a fortiswitch. And if I look at their mapping from the NVR, they all show the 192 addresses as well which is at odds with the VLAN they are on and what the FG tells me they should be. It all wouldn’t matter except for one problem. I cant connect to the NVR or cameras externally. There is a firewall rule present that allows that VLAN to go out to the internet, so I’m not sure what the problem is. If I manually change the NV
Hi , I am trying to understand what is the purpose of the configuration :EMS CA Certificate (ZTNA) under EMS Settings.Is this supposed to allow EMS administrators to install a CA certificate onto the users device CA bundle?
https://fortiguard.fortinet.com/psirt/FG-IR-26-156FG-IR-26-156 (CVE-2026-70465) advisory states the fix is available in FortiClient Windows 7.4.4 / 7.2.12 and later. However, the free VPN-only agent has not received a new release since 7.4.3 (per the community note that v7.4.4–7.4.8 include no new free VPN-only build).Could you confirm: 1. Is FortiClient Free VPN-only 7.4.3 (build 4726) vulnerable to CVE-2026-70465? 2. If yes, will a patched free VPN-only build be released, or is upgrading to a licensed version the only path to remediation? Thanks in advance.
Hello, I am wondering if it's possible to manage AP's without a fortiswitch? Company just bought a Fortigate to be used but they are sticking to the old Entrasys switch. I have it connected but it keeps using the main internet (10.1.1.x) and I am unable to find where to assign the proper VLAN tag for it. It needs to go to on the (10.1.2.x). Old switch has the proper VLANs tagged, now I just need to figure out how to get the AP to use the right VLAN.
I am automatically updating FortiClient for Windows from version 7.4.5 to 7.4.6. On about 50% of the test computers, the installation process stops at: “Stop services.” I also tried doing it manually by running the installer file, but in that case it also gets stuck at “Stop services.” How can I work around this issue?I have updated versions 7.0.x and 7.2.x many times before and never had this problem. Now I’m updating to version 7.4.x for the first time. Has anyone had a similar issue?
Hello Fortinet Community,I am currently deploying a new FortiGate and would like to clarify the recommended approach for remote access.I have read that SSL VPN tunnel mode is being deprecated/removed in newer FortiOS versions or on certain FortiGate models. Could you please help clarify the following?Is IPsec VPN now the recommended/supported option for remote-access VPN? Is there any official Fortinet documentation explaining the changes to SSL VPN tunnel mode? From which FortiOS version and/or FortiGate models does this change apply? For an existing or new deployment, should we now prioritize IPsec VPN with FortiClient instead of SSL VPN?Additionally, regarding ZTNA, I understand that it can be used to provide more granular access to specific applications/resources instead of providing traditional network-level VPN access.Does implementing Fortinet ZTNA require any additional license or FortiClient EMS subscription, or are there ZTNA capabilities already included with the FortiGate/F
Hello. I have some Ubuntu 26.04 servers configured in FortiPAM. When I set up Web-SSH access, I enable the "SSH auto-password" option so that FortiPAM can pass the password when I connect and need to run a "sudo" command. The problem is that with this version of Ubuntu, FortiPAM does not pass the password.
Hello,We are using the free FortiClient Windows VPN-only agent, version 7.4.3.Regarding Fortinet PSIRT advisory FG-IR-26-156 / CVE-2026-70465, the advisory lists FortiClient Windows 7.4.0 through 7.4.3 as affected and recommends upgrading to 7.4.4 or later. However, the FortiClient Windows release notes state that versions 7.4.4 through 7.4.7 do not include a new release of the free VPN-only agent, and that users can continue using the 7.4.3 free VPN-only agent. Could a Fortinet representative please clarify the following?Is the latest available free FortiClient Windows VPN-only 7.4.3 build affected by CVE-2026-70465? References:FG-IR-26-156: https://fortiguard.fortinet.com/psirt/FG-IR-26-156FortiClient 7.4.7 release notes: https://docs.fortinet.com/document/forticlient/7.4.7/windows-release-notes/683433/special-notices This is a request for clarification of the public PSIRT advisory’s impact and remediation path for the free VPN-only edition
Hello everyone,I need to configure a single PC to connect via SSL-VPN with MFA to my company's infrastructure, which is currently running on firmware version 7.0.Since I only need to manage 1 PC, I do not have an active FortiClient EMS contract to access the legacy downloads section in the Support Portal. I only need the free standalone VPN client (FortiClientVPNSetup_7.0.x).Could someone please provide an official or temporary download link for the FortiClient VPN version 7.0 installer for Windows 10, with 32 bits arquitecture? Thank you in advance for your help!
Hello Fortinet Community,I have a customer requirement regarding remote access VPN connectivity.My understanding is that FortiGate supports both SSL VPN and IPsec VPN for client-to-site connections. However, I have also seen recommendations to move away from SSL VPN in newer releases, and I am planning to deploy this solution on FortiOS 7.6.The customer's requirement is very specific: they want to ensure that only one concurrent VPN session is allowed per user account. For example, if a user connects through FortiClient using their username and password, a second person should not be able to use the same credentials simultaneously from another PC and establish another VPN session.Is this behavior supported natively by FortiGate/FortiClient? If so:Is there a specific setting to limit concurrent logins per user? Does it work for both IPsec and SSL VPN? Are there any best practices or recommended approaches to enforce this requirement?I would appreciate any guidance or configuration recom
I upgrade our fortigate to v7.6.7 and after upgraded then the web admin gui if use mgmt ip address can’t be accessed from advpn, only can be accessed from local site and from hub only. If i using lan ip (not mgmt) then i can access. Anyone know why?SSH to the both port (mgmt and lan) is working fine.
# Why You Can't Add DDNS to an Existing IPsec Tunnel — and What to Do Instead**Environment:** FortiGate-60F (FortiOS 7.6.x) and FortiGate-30G (FortiOS 7.4.12), site-to-site IPsec, route-based.If you built a site-to-site IPsec tunnel with a literal peer IP address and later needed to switch it to a DDNS hostname, you have probably found that FortiOS accepts every command you type and then discards all of it at commit. This article covers why that happens, the field-naming distinction that causes most of the confusion, and two ways forward depending on whether you can take an outage.---## The scenarioTwo FortiGates, site to site. One side holds a static public IP. The other is a home or branch office on a DHCP-assigned public address from the ISP.The tunnel was built with the peer's current address entered literally:```config vpn ipsec phase1-interface edit "VPN-TEST" set type static set remote-gw 203.0.113.117 ... nextend```This works. It keeps working right u
I need to move my FMG and FAZ from VMware to Hyper V. I am moving from version 7.4.11. I am assuming I can just install the template machine in Hyper V and just export/import the configuration. I will be keeping all of the same IP addresses. Am I overlooking something or will this be straight forward?
We currently have a provisioning template set for a FortiGate, however some updates were done on the actual firewall’s configuration. Mainly for connecting it to FortiClientEMS and Authenticator. Then adding a few new Policy rules. Is there a way to import the updated configuration into the FortiManager as a new provisioning template? Thanks!
What's the best way to get back in? It's a Gateway, 7 switches, and 65 APs. I've asked the client who sold them the gear it's been through the hands of 2 MSPs and no one seems to know passwords. Transitional passwords between the last 2 MSPs (not ours) are not right.I want to work veryhard to make sure we don't brick this stuff and get into a mess.It's newer gear, so unlikely the maintainer account is still in place on this firmware.How do we go about getting access back/proving ownership to Fortinet?
ENVIRONMENTFortiOS: 7.6.x (FortiGate 120G)FortiClient EMS: 7.4.x (FortiCloud SaaS)FortiClient: 7.4.7 (Windows)Authentication: IKEv2 EAP-SAML via Microsoft Entra ID---ISSUEFortiClient endpoints managed by EMS fail to complete IKEv2 IPsec VPN tunnel establishment after successful SAML authentication. The EMS-managed client sends an EAP NAK (type 08) in response to the FortiGate's EAP Identity Request, causing the FortiGate to tear down the IKE SA with 'unexpected payload type 41'.A non-EMS-managed FortiClient with an identical manually-configured tunnel connects successfully every time. The failure is specific to EMS-managed clients.---FORTIGATE IKE DEBUG (EMS-MANAGED CLIENT)The sequence on every EMS-managed connection attempt: responder received AUTH msg responder preparing EAP identity request responder received EAP msg unexpected payload type 41 schedule delete of IKE SA connection expiring due to phase1 downThe client response decodes as EAP type 08 (EAP NAK) — the client is re
On HA enviroment for FNAC with shared IP Address then we need to configure both FNAC IP to tghe switch as Radius Server and CoA? The shared IP only for FNAC mgmt only?
FortiEMS 8.0 managed FortiClient 7.4.7 using FortiTokken.after first time enter user and password details it don’t ask again user credential only fortiTokken.But as per compliance i have to configure like fortiClient ask everytime user password .i already disable the option save pasword and auto login. still same and in fortiClient (Save login) grayed.
Hello everyone, Is it possible to bypass DNSBL for certain IP ranges at FortiMail ? If we enable DNSBL using spamcop, lots of legit messages are blocked if sent from a shared SMTP clients that are temporarily blacklisted (such as *prod.protection.outlook.com and others). We get so many complains that we had to disable DNSBL.I guess we are not the only facing this problem because it seems to be an obvious problem. If a spammer sends spam using example.prod.protection.outlook which is used by thousands of legit organisations, if we discard all all messages coming from that example.prod.protection.outlook, then we are labelling legit messages as spam, and that's a problem.Can anyone recommend a workaround o a differnt approach maybe? Thanks for your help.
I forgot the password of my FGT 300C thats why I needed to reset the password via cli using the ff commands. However I got an error " User must have a profile object set operator error, -56 discard the setting Command fail. Return code -56" how to add profile for admin? Welcome ! New_FG300C~ # config system admin New_FG300C~ (admin) # edit admin new entry ' admin' added New_FG300C~ (admin) # set password password123 New_FG300C~ (admin) # end User must have a profile object set operator error, -56 discard the setting Command fail. Return code -56
We have on-prem FortiClient EMS server (7.2.x) which is an application that runs on a Windows Server. It does not appear to support SNMP. Other than just ICMP , any suggestions on the best way to monitor the EMS server?
I hve a FortiGate 60F and when I console to it I have a message that Password reset functionality is disabled. WhenI try using maintenance mode or the hard reset button it does not working. What options do I have to get in this device? If I have to reset it fully I will as long as I can get into it.
have a FG 70G 7.4.12 and a windows client with free VPN 7.4.3.4726I have followed the doc:https://docs.fortinet.com/document/fortigate/7.4.12/administration-guide/785501 but when I try to connect, the client says “Timeout while connecting” I have diagnose sniffer packet wan1 "udp and port 500" running, and see 4 packets every time I try to connect like:19.844532 1.247.132.25.1012 -> 214.153.140.239.500: udp 668The odd part (to me) is that I do not see anything in the GUI System Events > VPN Logs >Memory.I’ve made sure the proposals match on both sides.I’ve done this before multiple times on 7.2 and older, and never had these kinds of problems.Any suggestions?
After upgrading our FortiGate device from FortiOS version 7.6.6 to 7.6.7, users at the branch lost internet access when the BambiDeep SSL/SSH Inspection profile (Deep Inspection) was used in the firewall rule.Traffic is allowed by the firewall rule, and NAT is working properly. However, HTTPS connections fail when Deep Inspection is enabled.As a temporary solution, we changed the SSL/SSH Inspection profile from BambiDeep (Deep Inspection) to Certificate Inspection, and internet access was immediately restored. The first rule includes certificate inspection, and internet access works fine, but the second rule is the old one and includes “BambiDeep” SSL inspection; after the firmware upgrade, internet access is not working. Also ı tested the problem on new rule by adding BambiDeep SSL inspection ant internet acces is not working. Are they any known issue about 7.6.7 version for tihs topic ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.