Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello there! I think I’m missing out something simple.I’m on FortiOS 7.4.12. This FW is filtering all traffic from workstation to the Internet via a policy with web filter enabled that allows (among others) Google map navigation.Now I need to temporary allow Chrome updates in addition to the traffic usually allowed by my webfilter.I know there is a specific application control for that but I don’t understand how to use it. I can’t put this profile in my usual rule as I do NOT want the webfilter to be modified. I can’t put a policy with the application control before my webfilter rule as this would block all non-update traffic. I can’t put a policy with application control after my webfilter policy as this would never match.How to achive this?Thank you in advance!
I’m designing a FortiAuthenticator EAP TLS setup where the user base is LDAP (Active Directory), supporting two types of endpoints: Domain-joined laptops (already managed) , certificates already present on the user device.BYOD devices (user-owned) Both need to authenticate via EAP-TLS for Wi-Fi (802.1X) using FortiGate + FortiAuthenticator. Current setup:Domain-joined devices:Certificates pushed via GPO from internal PKIEAP-TLS with certificate binding is already workingUsername is derived from the certificate CN and mapped to LDAPEAP -TLS for domain joined devices is working. And I am also able to assign dynamic vlans via radius attributes configured in the FAC user group. BYOD devices:Will be onboarded via SmartConnectAuthentication to LDAP is required firstCertificates will be issued to the device so it can use EAP-TLS Questions:For BYOD onboarding, is it better to use a local CA on FortiAuthenticator, or should I issue certificates from the LDAP/AD CA via S
Hello,I have a 3 Gbps symmetric internet connection. Topology: VM → vSwitch → backbone switch → FortiGate → IPS router → ISP.Speedtest results from two different VMs:192.168.0.0/24 segment VM: Download 2500 Mbps, Upload 1995 Mbps ✓ 10.100.10.0/24 segment VM: Download 2421 Mbps, Upload 554 Mbps ✗Both VMs run on the same hypervisor and both use vmxnet3 vNICs. Download is at full speed on both; the problem is only on the upload direction of 10.100.10.0/24There are no traffic shaping rules on the FortiGate.2 gb set srcintf "Zone_1" set dstintf "net” set action accept set srcaddr "all" set dstaddr "all" set schedule "always" set service "ALL" set utm-status enable set inspection-mode proxy set profile-protocol-options "custom-default" set ssl-ssh-profile "__upg_certificate-inspection" set logtraffic all set nat enable 500mb set srcintf "Zone_2" set dstintf "net" set action accept
Dear All,Some of the websites are getting monitored from Fortigate performance SLA, getting high latency.When I check using ping,traceroute in fortigate using CLI showing normal latency. Even I also checked from LAN machine showing normal latency. unable to find root cause of it, Could you please tell us what could be cause of showing high latency for some websites in Fortigate peformance SLA. Thanks in advanced.
Hi I want to have 1 single FortiGuard license for my 2x100F FortiGate.You have the doc if the devices are not yet registered, but i want to do this with already registerd device is this possible?FYI Doc, how to do if the devices are not registered.https://docs.fortinet.com/document/fortigate/7.4.11/administration-guide/246857
Hi- I am trying to take config backup using CLI and facing errors. Pings, Trace, Sniffer all are giving outputs FTP - Getting bellow errorConnect to ftp server <FTP server IP>Please wait...Send config file to ftp server via vdom root failed.Command fail. Return code 10 Using TFT- This is taking very long time and backup is not getting fully completed and gets timed outVersion of Firmware is v7.4.8 , , v7.4.9 , FortiOS v6.2.17 build1405 (GA) Eventually, what I am trying to do is take config backup and then upgrade the OS version using python and API commands. Guss that will also give issues
Hi I’ve been using the FortiClient app for many years on my personal Surface Pro 7 device. Not had any issues, but recently we’ve taken part in a vulnerability audit and the app is flagging a few issues. The solution is to update, but I’m struggling to do so. I had version 7.4.3 installed but need 7.4.5 for the vulnerability to be cleared. When I download the latest software file it doesn’t show any version options. Instead, it I think it pulls down the latest version it can. I’ve tried to reinstall but still only getting to 7.4.3. I’ve seen a post regarding Snapdragon processors not being compliant, with newer versions of the Surface Pro. That may explain why my colleagues Pro 12 is not working at all with the app. But my older 7 model works fine, but I just need help updating. Many thanks
Hi I’ve one Fortigate 40F with firmware version v6.4.6 build6083 (GA).What is the suggested upgrade path. The target is to reach v7.4.12(Mature) ThanksVenkat
Hello everyone. I want to enable the sandbox feature on my firewall, and my license supports it. However, how can I ensure that my files, which will be uploaded and scanned to the cloud, are secure and won't be accessed by third parties? I want to know that uploading them to the cloud is solely for scanning and then they are removed... Is there any guarantee that my data will remain safe from being accessed by any other parties, including Fortigate?
Questions, we have Fortigates in HA managed by FortiManager.If we make changes in FortiManager and install, what is the correct way to roll back changes from the FortiManager?If we make changes in FortiManager but didn't install, what is the correct way to undo the changes?If we modify the Fortigate directly, does the changes gets synced to FortiManager?Thank you.
Hi,I’m facing a behavior that seems counter‑intuitive regarding OSPF over inter‑VDOM links. I am in a multi‑VDOM setup:OSPF is configured between VDOMs over a VDOM link Each VDOM has its own routing instance (OSPF process) According to documentation:Inter‑VDOM routing relies on VDOM link interfaces A disabled VDOM does not process traffic (no policy lookup / no forwarding) I encountered the following situation:One of the VDOMs was administratively disabled However: OSPF adjacency was still UP Routes were still being exchanged My understanding was:A disabled VDOM should not process traffic Therefore: No OSPF Hello packets No adjacency But this does not match the observed behavior. Is this behavior expected? More specifically:Does a disabled VDOM still run routing protocols (OSPF control plane)? Is it possible that: control plane (OSPF) still runs while dataplane (forwarding) is stopped? Or:Is this a known limitation / bug / specific behavior with VDOM links? Thanks in advance BW
Hello,I have a 300E chassis, and we are going to migrate it to an 810G chassis.We need to replicate the 300E configuration on the new FAZ chassis. Do we need to update the 810G’s firmware to the same version as the 300E?Do we need to create the same number of ADOMS on the new box as on the 300E?Thanks for your feedback.
Hello Dears,I’m trying to extract content from file using the built-in connector and putting the attachment IRI to the step {{vars.input.records[0].file['@id']}} but it timeout with the following error:do you have any idea for the reason of this ?Thanks, on advance
Hello,We have a FortiSwitch connected to a Huawei core switch, and we want to manage the FortiSwitch through our FortiGate using FortiLink.We configured the FortiLink VLAN on the Huawei switch, and we also configured DHCP discovery on the FortiSwitch:config switch-controller globalset ac-discovery-type dhcpset ac-dhcp-option-code 138endWe also configured the trunk on the FortiSwitch:config switch trunkedit trunk1set static-isl enableset static-isl-auto-vlan enableset members 51 52nextendThe FortiGate discovers the FortiSwitch through FortiLink, but the switch is always displayed as Offline/Down.FLP debug logs show that the FortiGate and FortiSwitch exchange packets successfully, and the physical link is UP.Has anyone experienced this issue before when using FortiLink through a third-party core switch (Huawei)?Any advice would be appreciated.Thank you.
hi,is there a way to send a weekly or monthly report to our registered email for the FortiFlex license points usage?it’s kinda tedious and manual looking at the points usage in the portal.or are we just going to receive an email if it’s already in a low point threshold?
Hi Folks,I need an urgent solution; we have FortiGate proxy, Forti Authenticator, and FortiClient for SSO in our setup. To deploy FortiClient, we are using SCCM, not EMS. A few days back, we had an issue where FortiClient was uninstalled from many Windows systems-not all at once, but over 2-3 days-and more than 100 users complained. We engaged our SCCM and AD teams, and according to them, there was no trace in the system to identify what triggered the uninstallation. We have taken Fortinet help as well, but as it was not managed through EMS, they said it is not within Fortinet's scope either. However, later we asked the SCCM team to deploy FortiClient again on the affected users' systems and it's working, but we are left with the RCA. Can anybody please help if you have faced such an issue and how we can identify what triggedred the un-installation to prevent in the future.FortiClient version - 6.0.9
Troubleshootinghow to solve this issue? please any ideas. i have implemented the ZTNA on two devices, but still getting this error. [V][p:7134][s:8274] wad_vs_ssl_c2p_check_alpn :24835 wsp=0x7f5041e78048, alpn=h2[V][p:7134][s:8274] wad_vs_ssl_c2p_check_alpn :24844 wsp=0x7f5041e78048, vs server set alpn http2[V][p:7134][s:8274] wad_vs_proxy_match_vhost :4714 2:ZTNA-web-proxy: matching vhost by: portal.ztna.com[V][p:7134][s:8274] wad_pattern_matcher_search :1226 pattern-match succ:portal.ztna.com[I][p:7134][s:8274] wad_vs_proxy_match_vhost :4722 2:ZTNA-web-proxy: matched vhost(ztna-web-portal-fqdn 0x7f503cc31660)[E][p:7134][s:8274] wad_vs_find_cipher :10538 wsp 0x7f5041e78048 ssl no matching CipherSuite, abort[I][p:7134][s:8274] wad_ssl_app_port_fts_in_close :20148 sp=0x7f5041e78048/10 recv close request from fts close-type=0 closed=0[I][p:7134][s:8274] wad_ssl_port_task_end
Hello there,can anyone suggest any other tutorial for agentless ZTNA rather than fortinet official documentation. I don’t understand it how to implement correctly. any video, documentation, guides, articles would be appreciated.
Hi,I just want to know, when checking the maximum higher bandwidth, why is it higher when looking at it in 24 hours than in week?Example: When I’m checking the maximum higher bandwidth for a certain interface in 24 hours, the maximum is 5.11 Mbps, but when I check in week, the maximum is 2.25 Mbps.I hope someone can enlighten me. Thank you in advance.Oliver
Hi All,We have a pair of 100F’s and a pair of 600F’s , these are in HA Active/Standby mode.We have the management interface configured for well management, it has been suggested that we enable the Management Interface Reservation option within HA however there are no clear guidelines on how to do this.I understand that we cannot use the existing management interface and that we cannot use the same subnet we use for the management.So we just pick another interface , find a different subnet and patch this other interface to a switch ?. So that's two interfaces (1 for active and 1 for standby) ?.If so what purpose does that serve as you still need to patch both interfaces on the firewall - so just consuming interfaces to replicate the management interface ?So just looking for some really good configuration guidelines - not the Fortinet docos they are useless and do not explain it well enough. Regards
been wanting to ask this community specifically because i figured people here would have more practical experience than most...we are a mid sized organization in Dubai that recently went through a significant network security refresh. FortiGate firewalls, FortiSwitch, and FortiAP were all part of the deployment and the procurement process raised some questions that i could not find clear answers to through official documentation alone.the specific question is around how strictly Fortinet ties support access and FortiCare contract eligibility to authorized supply chain. we had a situation during procurement where some suppliers were offering noticeably cheaper pricing but the answers around authorization status were vague enough to make the team uncomfortable.ended up going with Tech Distributor after specifically looking for an authorized Fortinet distributor in Dubai that could confirm legitimate supply chain documentation. the pricing was not the cheapest we found but the FortiCare c
HelloCurrently the latest available versions of FAC are:6.6.16.5.56.4.9I preferred avoid 6.6.1 for my production since it is new version (I guess not mature yet).So I have few questions regarding 6.4 and 6.5.Is 6.4.x still supported? (because I noticed the last patch has been released on 28 December 2023)Should I avoid 6.5.x, since it is odd? (odd is short term support if I'm not wrong)
Hello, I need a way to install the FortiClient VPN free version that also loads a preconfigured config file. The examples I received while googling this question are not working for me. This involved having a powershell script as shown here: msiexec /i "setup.msi" /quietStart-Process "C:\Program Files\Fortinet\FortiClient\FCConfig.exe" -ArgumentList "-m vpn -f 'FortiClientConfiguration.conf' -o import -p 'connecting'" -Wait I made the Install command on Intune: powershell.exe -ExecutionPolicy Bypass -File install.ps1I created the installation script using the .intunewin file with that nifty wizard.It is not working, and I’m not getting an error or anything. Anyone else do this successfully?
I've just installed FortiClient VPN the .deb package from here https://www.fortinet.com/support/product-downloads .installed with `sudo dpkg -i ...` Setupd the configuration ( as I have on my windows pc and on my android ) when I try to connect I get the following in the journal: iul 29 14:23:43 station1 kernel: iked[283119]: segfault at 28 ip 000000000045195d sp 00007ffe2a7e6900 error 4 in iked[400000+891000] iul 29 14:23:43 station1 kernel: Code: 4c 89 e5 48 89 44 24 38 48 8d 84 24 88 00 00 00 45 89 d4 45 89 de 48 89 44 24 50 48 8b 45 00 45 89 f5 31 ff 31 db 4a 8b 0c e8 <8b> 51 28 85 d2 74 42 48 8b 71 20 8d 7a ff 31 db 48 8d 46 08 4c 8d iul 29 14:23:43 station1 fctsched[283131]: /opt/forticlient/iked: invalid option -- 'P' iul 29 14:23:43 station1 regolith.desktop[281914]: 14:23:43.573 › VpnHandler UNHANDLED {"isTrusted":true} iul 29 14:23:43 station1 fctsched[283131]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus iul 29
Hello,I’m trying to configure two different Fortigates 60F but both of these devices are unresponsive.I tried connecting via Ehternet on LAN 1 but i get no address via DHCP (no IP was released and i have APIPA address) , i tried setting up manual with IP 192.168.1.110 mask 255.255.255.0 gateway 192.168.1.99 but i can’t ping, https or ssh to 192.168.1.99 If i look at the ARP table i see that 192.168.1.99 is present but i get no response in HTTPS , SSH and PingThe weird thing is that using Wireshark i see that the Fortigate is responding to the ARP Requests but not to Layer3 traffic (HTTPS,DNS,SSH,Ping)Then i tried using the console cable connected to the Console Port of the fortigate but also that didnt work:So i tried to Reset the Fortigate but also that seems to not work, no LEDs are blinking and seems to not reset at all, i tried holding the reset button after power up for 1 min but nothing, i tried the same but when Fortigate was already booted up but nothing.The weird thing is that
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.