Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello, I have a 200F fortigate and it's working with 7.6.4 firmware. After I upgraded, I can't see some SSID (WPA2 Personal).But WPA2 Enterprise and Open Guest SSID are working. Why might this happen?Thank you.
Hi,I have been following the KB articles and forum comments for months, but I still don’t see a workable solution for us.We are using a FG90G (FortiOS 7.4.7) with SSL VPN, around 100 LDAP users, FortiClient VPN-only, and FortiToken for MFA. This setup worked very well for many years, but due to OS-related requirements, we now need to move to a new solution.First, we configured IPSec IKEv1 with around 10 of our LDAP users. Some of them work fine, but others experience significant issues, mainly frequent disconnections — approximately 1–2 disconnects per hour. With 100 users, this is not a viable long-term solution. We then tested IKEv2 on a FG80F. It works fine with local users + FortiToken, but with LDAP + FortiToken + FortiClient VPN-only, we receive an EAP failure message. I’m not sure whether there is a proper solution via FortiClient XML configuration that could resolve this, or whether there are other limitations we are facing.A more drastic option would be to replace the FG90G wi
Hello everyone, I just encountered issue while connected Access Switches (specifically 148F and 124G) to our core switch 2048F. In our enviroment we have FGT 120G as perimeter firewall which is connected to 400F that serves as segmentation firewall and also as switch controller. 2048F is main core switch from which I have connected few access switches (148F and 124G). For some strange reason out of 9 switches only 6 came online without issue. The other 3 did not show up. Strangely I can see the ports leds blinking and if I go to FortiSwitch Ports and roll out the ports of the 2048F I can see the ports online with the missing switches serial numbers shown. The 3 missing switches would show up for authorzation I have waited approx. 30+mins. I have tried to add the FortiSwitches manually but they are still shown as “Offline”.Attaching screenshot from FortiSwtich Controler → Managed SwitchesThis is how it looks from Fortiswitch Ports menu (I circled the switches which I added manually and
Hello everybody,I hope you all doing well,I have some question for Forti web a-a setup as this is my first time updating I did my research and found that both nodes will be updated at the same time and there will be down time so is there any way like splitting the HA connection and try to update one of them then swap the traffic or am taking to much risk ? the upgrade path will be from 7.4.8->7.6.2->7.6.7what is the best way to prepare for such kind of operations I have previously worked with FortiGate's but only in Active-Passive clusters.Please advise as this is my first time trying to prepare for this Forti Web updates.Also have anyone tried 7.6.7 in production env ? it seems for me the most stable one and has no CVEs or known issues.Thank you in advance.
Hello everyone,I am preparing to deploy a brand-new FortiGate appliance for a customer and I have a couple of questions regarding the initial setup process.When I connected to the management interface for the first time, I was presented with a screen requiring FortiCare registration before proceeding.My questions are:Should the FortiCare registration be performed using the customer's FortiCare account, or is it acceptable to use our company's FortiCare account as the implementation partner? What is considered best practice? Does the FortiGate license/support contract need to be activated before performing any configuration changes, or can the firewall be fully configured first and the license activated later? What is the recommended procedure for license activation on a new appliance? Where can the license be downloaded or claimed? Is there an official Fortinet process or best-practice guide for onboarding a new FortiGate? I would appreciate any recommendations based on real-world dep
Hi all, I saw a strange issue today when i was setting up a new VPN to a site. The site has one fiber connection and one 4G connection. I set the tunnel up as usual and i see both in the list under VPN. If i check the status och the VPN i only see the “primary” (fiber) connection and no 4G. If i the edit the firewall policy the secondary (4G) connection shows green/up.If i the run diagnose vpn tunnel list i getname=******-SEC ver=2 serial=52 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.10 tun_id6=::10.0.0.10 status=down dst_mtu=0 weight=1name=******-SEC ver=2 serial=54 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.11 tun_id6=::10.0.0.11 status=down dst_mtu=0 weight=1The site is not commissioned yet, hence the primary connection down.
I have several entra group and this group imported to the fortinac, then i add some user to group called IT.When some user IT connect to the network, some of them can connect and some of them cant connect.I do debug for user who can’t connect to the network and i found this message, seem fortinac see this user is member of another group so the policy is not working. 2026-06-11 06:19:23.911 7C:B5:66:6B:D7:F3 - [Policy] HostRecordUtil.getAbstractPolicy() HostRecord DBID: 1456217792417818 Policy ID 1464353948106780 Groups not matched: Required:OR[GroupId: 1464105708654608, GroupType: 1] Provided:[GroupId: 1454135121485837, GroupType: 0, GroupId: 1456635326402562, GroupType: 0]Below is my queris:The GroupID is id from fortinac? How i can know the group name from group id? What is 0 and 1 in the group id?
Hi!Supposedly, setting executing “diagnose vpn ike log filter name” with phase1 name as argument will confine “diagnose debug application ike 255” or “diagnose debug application ike -1” debug logs to only that tunnel. However, when I do it, I see debug logs for all tunnels. How to filter out all the tunnels’ debug logs?Thanks!
Hello guys! Users on a regular IP based firewall policy with no UTM profiles applied to it, are having problems when trying to access Faceboo. On IE the page appears as text only and on Google Chrome, the pictures are blank. If there is no UTM feature applied to this rule, what can be the cause of this behaviour? Thanks in advanced guys!
Hi Everyone. today we was encountered the Fortigate Dynamic DNS issue in firmware 7.4.11 and 7.4.12. Restart the firewall few time still unable to access even ping google.com also unable to resolve but when PING 8.8.8.8 from Fortigate is reachable. In the Network → DNS → DNS server show Primary DNS and Secondary DNS server is unreachable. Even the host name unable to resolve
Dear Team, When a FortiEMS virtual machine is deployed using OVA file, it loads with one interface and the default gateway pointing to the same interface. Can we have an additional interface ? Because there is a requiremet for dedicated OOB management and Dataplane interface for Forticlient telemetry connction.https://docs.fortinet.com/document/forticlient/7.4.0/new-features/182605/deploying-ems-as-a-vm-image-7-4-1
We have multiple IPSEC VPN dial up customer sites with SAML.One of our clients sites, requires NAT to be turned OFF in the Forticlient profile to connect, and all the rest require it ON. Mostly it's the same or similar ISP, NAT in the Phase 1 policy on the Firewalls are set to the same on the two examples I tested, so I don't think it's that.FortiOS 7.2.13 on a 60F for both.Any ideas where or how I can figure out why this setting requirement differs between this site and the others?TIA
I try to add my tplink to the FNAC and in the inventory the port showing 6 from 12. Where i can see the rest of 6 ports?
I am trying to migrate a switch port from root vdom to inside. When I do that the port it does not appear in the inside VDOM and it does not accept any commands in root vdom and it gives the error:“Invalid switch portobject set operator error, -651 discard the settingCommand fail. Return code -651”I managed to bring the port back if I make the change in the config file and then upload the file to the fortigate. However, when I try to move the port again to inside I have the same issue. Also made the corrections mentione in: Fortigate 400E version 7.4.11 build2878FortiSwitch: S224DF-v7.4.6-build895,250129 (GA)
Microsoft Hyper-VAfter successfully logging in to FortiCloud, the session is automatically logged out after a short period. The logout occurs repeatedly, preventing stable access and management through FortiCloud.Troubleshooting Performed:* Verified internet connectivity* Cleared browser cache and cookies* Tried different web browsers* Confirmed correct system date and time settingsanyone manage to resolve this problem?
HelloWe are using a FortiWeb cluster as a VM for our customer. The backend servers of our customer's customers are gradually being migrated to this FortiWeb cluster from a Sophos UTM 9. We also operate the Sophos UTM 9. The first backend servers are already running on the FortiWeb VM and access is successful. The challenge now is to migrate the backend servers that use SSO login via KeyCloak with Azure to the FortiWeb cluster. We have configured a test backend server for this purpose. Our customer has configured KeyCloak (plain vanilla without any special configuartions) on his environment. We have configured the Azure parameters on our side in Azure. When accessing the test backend server via Sophos UTM 9, everything works without any problems. When accessing via FortiWeb, I can authenticate and then it's pending. After round about 20 seconds comes '404 Not Found'. What did we overlook or configure incorrectly in the FortiWeb cluster configuration?Thank you in advance for
I have an email notification set up to alert when one of our ISP’s goes down. The problem I’m having is the Minimum interval setting is not working. I have it currently set for 2 minutes and it immediately alerts me when this happens when no delay. I’m getting way more notifications than i need to for this. The model is a 60e and the firmware is 7.2.8. Does anyone have any suggestions in order for this to work properly?
HiDue to the reduction in the maximum certificate lifetime, we need to frequently upload local certificates to FortiWeb in the future.My environment uses a true transparent proxy mode, can I change it to use Let's Encrypt? If I do so, the certificates used on FortiWeb and the real server will be different. Will this cause any connection issues?Or is there a way to upload a local certificate and have it automatically applied to all server pool members?Thanks.
Do you use any AI tools for troubleshooting problems with FG's? If so, which ones work best for you and in what situations?I mean, for example, the approach in which you write: "hey, here are the logs, give me the next steps of troubleshooting to determine what is the cause and how to fix it."
One of our clients has a user he's suspicious of browsing social media consistently during work-hours. He's wanting to catch this user-out with logs/reports of the the internet traffic. How would we go about doing this? Did a quick look around, is the FortiAnalyzer the best tool for the job?
Hello,has anyone experienced issues with RADIUS authentication for IPv6 clients on a captive portal interface?Setup: FortiGate 200F, FortiOS 7.4.8, interface with security-mode captive-portal + security-mac-auth-bypass enable.IPv4 MAB works flawlessly — FortiGate sends an Access-Request with the client MAC as username, RADIUS responds with Access-Accept, and the auth entry appears in diagnose firewall auth list. No issues. config authentication rule edit "TEST Radius" set srcintf "50 Lan" set srcaddr "all" set srcaddr6 "all" nextend For IPv6, FortiGate sends no RADIUS request at all (confirmed via tcpdump). The diagnose firewall auth ipv6 list remains empty regardless of configuration.What was tested without success:1. config authentication rule with srcaddr6 "all" — CLI accepts and saves it, but the daemon never processes IPv6 sources.2. Framed-IPv6-Address (RFC 3162) in Access-Accept reply — FortiGate receives the attribute (confirmed via tcpdump, packet le
I'm trying to setup a POC to demo ZTP.....Using the Fortigate Cloud service, I was able to provision a Fortigate to it's proper On-Prem FMG. However I was unable to get the gate provisioned to the proper CLOUD FMG. (Even though it says it's supported). I then tried using FortiZTP service and was able to provision to the CLOUG FMG successfully. Has anyone else run into this ? Should we be using the FortiZTP since it's still in beta ? Tom
Anyone using FortiManager cloud with multiple FortiGates? I’m new to FortiManager Cloud and I’m having trouble streamlining FortiGate onboarding. I have about 30 firewalls to deploy.What methods are you using? We’re trying to go down the CSV upload method with several configuration variables defined in the CSV file
Hello FTNTI see in known issues of FortiOS 7.4.11 the following bug id. 1256278 Packet loss occurs when asic-offloading is enabled on FortiGate. Can anyone explain in which models and/or circumstances this can happen?
Hello,Would really appreciate it if someone can point me to the right direction or help me with the following. Using DoS policy would like to know if its possible to create 2 polices with source like soPolicy#1 IPs from specific country. The limits are set higher or set to disable.Policy#2 All other IPs . The limits are set very low The questions are Does Fortigate support anything similar to the above? If both policies are enabled Will this lead to an increase in the resource usage of the Fortigate firewall? Thank you in advance.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.