Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
One of our clients has a user he's suspicious of browsing social media consistently during work-hours. He's wanting to catch this user-out with logs/reports of the the internet traffic. How would we go about doing this? Did a quick look around, is the FortiAnalyzer the best tool for the job?
Hello,has anyone experienced issues with RADIUS authentication for IPv6 clients on a captive portal interface?Setup: FortiGate 200F, FortiOS 7.4.8, interface with security-mode captive-portal + security-mac-auth-bypass enable.IPv4 MAB works flawlessly — FortiGate sends an Access-Request with the client MAC as username, RADIUS responds with Access-Accept, and the auth entry appears in diagnose firewall auth list. No issues. config authentication rule edit "TEST Radius" set srcintf "50 Lan" set srcaddr "all" set srcaddr6 "all" nextend For IPv6, FortiGate sends no RADIUS request at all (confirmed via tcpdump). The diagnose firewall auth ipv6 list remains empty regardless of configuration.What was tested without success:1. config authentication rule with srcaddr6 "all" — CLI accepts and saves it, but the daemon never processes IPv6 sources.2. Framed-IPv6-Address (RFC 3162) in Access-Accept reply — FortiGate receives the attribute (confirmed via tcpdump, packet le
I'm trying to setup a POC to demo ZTP.....Using the Fortigate Cloud service, I was able to provision a Fortigate to it's proper On-Prem FMG. However I was unable to get the gate provisioned to the proper CLOUD FMG. (Even though it says it's supported). I then tried using FortiZTP service and was able to provision to the CLOUG FMG successfully. Has anyone else run into this ? Should we be using the FortiZTP since it's still in beta ? Tom
Anyone using FortiManager cloud with multiple FortiGates? I’m new to FortiManager Cloud and I’m having trouble streamlining FortiGate onboarding. I have about 30 firewalls to deploy.What methods are you using? We’re trying to go down the CSV upload method with several configuration variables defined in the CSV file
Hello FTNTI see in known issues of FortiOS 7.4.11 the following bug id. 1256278 Packet loss occurs when asic-offloading is enabled on FortiGate. Can anyone explain in which models and/or circumstances this can happen?
Hello,Would really appreciate it if someone can point me to the right direction or help me with the following. Using DoS policy would like to know if its possible to create 2 polices with source like soPolicy#1 IPs from specific country. The limits are set higher or set to disable.Policy#2 All other IPs . The limits are set very low The questions are Does Fortigate support anything similar to the above? If both policies are enabled Will this lead to an increase in the resource usage of the Fortigate firewall? Thank you in advance.
Is it possible to configure link aggregation on wan1 of the FG-80F? It was possible on the FG-80E.
Anyone experiencing this issue with FortiClient 7.4.7 and the latest macOS? I had to prep a new MacBook for one of my people and upon installing FortiClient from my EMS (Cloud) installer, it just will not register from the still good invite code bundled in the installer nor will it accept the invite code trying to manually enter and connect. It does not give me an error or anything, it just does nothing. Invite code is still good as I used it with a Windows PC afterwards and no issues. I have went through the release notes for 7.4.7 in regards to macOS and ensure disk permission access and system extension activations were good, etc… and all are on/allowed based on the release notes requirements.
Hello community. I will have to work on a deployment of a FortiADC to publish internal applications to our users. The existing (non-Fortinet) solution is publishing the internal app with the following values: App PATH: C:\red\blue\app.exeStart in folder: C:\myfolderParameters: -an entry -b entryb -c entryc.... On FortiADC I do have the fields for App Path and parameters, however im not seeing where to place the "start in folder" info on FortiADC. Any ideas here, what to do?
Hi there, due to crazy pricing in subscription models and such we're considering FortiADC as a possible replacement for our F5 BIG-IP 2-node-cluster. I have FortiADC v7.4.4 running in an eve-ng lab and some questions arose. We have BIG-IP LTM & APM but we do nothing with App Portals, we just use 1:1 mappings (almost) with a portal front with complex logic. So something I would need, and I do not know if FortiADC can do that, or if things would have to be designed differently: On BIG-IP I have an Access Profile, an equivalent I assume to HTLM Forms, where I have a form with CAPTCHA, user name and password, which then goes to AD/LDAP, then a second dialog for internal MFA authenticating over RADIUS, and then it saves the successful auth state as a user session variable, which is then used in a script for Remote Desktop Gateway clearance in the background. The BIG-IP then internally transitions to a forwardable Kerberos ticket for the user to access all the publish
Hi,FortClient for Android asks for “Overlay permissions” when starting the App during initial setup. For ZEBRA Scanners there is an option to pre-grant this permission via OEMConfig: Enabling Display Over Other Apps Permission via MDM/EMM OEMConfigTherefore, the “Package Signing Certificate Fingerprint” of FortClient App is required. Can you please provide is with this? Since the APK isn’t available for public download, it cannot be extracted via ZEBRA’s SigTools utility by customers.Thanks!
Hi,we have such problem that fortigate fortios 7.4.11 is blocking copilot.microsoft.com the error we get in the browser is:net::ERR_CERT_AUTHORITY_INVALIDSubject: Fortiguard SDNS Blocked PageIssuer: Fortiguard SDNS Blocked PageWhat we did:1.in DNS profile --> static filter we created:- wildcard name *.microsoft.com and allowed it-allowed regex .*bing\.com-allowed regex .*trafficmanager\.net2.In the deep ssl inspection profile, we created the exempts:-wildcard *.microsoft.com-wildcard *.bing.com-*.trafficmanager.netBut all the time, this site is blocked by SDNS, any help?
Hi,I'm new on Fortinet products recent I have obtained FCAI am preparing to take NSE4 exam(FCP)! Is it compassory to purchase both LAB and Instructor.led so as I can get my certificate after passing the exam?Thanks
Question: FIPS-CC is enabled. The interface is up. Why can’t I set allowaccess to permit https on port 1 for GUI access? The Background: I don’t have any FortiOS experience. I’ve been given a 71F to configure. The documentation describes enabling FIPS-CC, setting a new administrator password, and enabling the ports via config system interfaceedit internal1set status upend followed by changing the allowaccess attributes to add https via set or appendset allowaccess ping https Neither append nor set allow me to do so, and set ? doesn’t list allowaccess as an option. the internal1 (port1) was part of a virtual switch. i’ve since removed it: config system virtual-switchedit “internal”config portdelete internal1end a ‘show’ command after each ‘end’ reflects that the configurations were accepted - internal1 is up and removed from the virtual-switch. if i `show full-configuration system interface | grep -f internal1’, i get the following attributes. config system interface edit "internal1"
Good afternoonDoes anyone know what happened to the release of version 7.6.7? It was supposedly coming out on Thursday, May 21st, but it's already the 29th and there's still no news. I'm having the DNS proxy bug, so I absolutely have to stay on 7.6.4 and can't risk upgrading to 8.0.
Set up an Invitation to use (on-prem) Domain (LDAP) FortiClient Sign-in fails with this error : from EMS log :Registration attempt by Endpoint was denied due to LDAP authentication failure for user 'test-user'. Server: test.local, , Reason: Authentication error: User not found in DB with [test-user] The user is part an LDAP group that is AuthorizedAlso, The credentials work in Administration / Authentication Servers when tested Where have I gone wrong ? Thanks
Hello, is there any option to set QR Code URL Scan?we had today an incident, that e-mail was having a QR code which has leading to malicious webpage.is there any option to scan those images with QR code with fortimail?
Hello,I have configured a network share and would like any file added to the folder to be scanned automatically. I noticed that a schedule can be set, but the shortest available interval is every 15 minutes.Is there a way to configure it so that a file is scanned as soon as it is placed in the folder? Alternatively, can the scan be set to run every minute?Thanks
Hello,We have deployed EMS 7.4.7 and we need to deploy client to about 300 endpoints via Intune. But Im missing option to choose the Invitation code during installer creation. In creation is only option to “override invitation code during upgrade”. And under Invitation page when I create an invitation code it is not possible to link it to existing Forticlient installer. Is there a way how to do it? Main thing we are fighthing right now is that after installation of Client to endpoints, it is not automatically registered to EMS. I have found out this topic, where its said that we shouldnt using “enforce user verification” so I have disabled it. But still im confused about invitation codes.Thanks for help!
Hello, I’m applying to a few Inside Sales Representative roles at Fortinet and would like some insight when it comes to the interview process, culture in the sales org, how strict WFH/in office is, and anything of that mature.Context, I have just under one year of experience at a large VAR. Thank you.
Hi Everyone,I have some problem when integrating a standalone FortiSwitch (S148FFTF series) with Cisco ISE. During deployment, authentication was completely successful on Cisco ISE (Access-Accept returned), but the endpoint would fail to receive a DHCP address and drop into an "Unidentified Network" status.Environment Details Switch Model: FortiSwitch 148F (Standalone Mode) RADIUS Server: Cisco ISE Dynamic VLAN Assignement not work properly.
Hi Support, I would like to know where I can find an official UAT reference for the 2601F. The firewall has been mounted, and the customer performed the configuration themselves. Therefore, I will only perform a basic check and then submit a UAT report to the customer to close the project. Could you please provide any professional guidelines? Thank you.
Hello Fortinet Community,I would like to seek assistance regarding an issue I am currently facing with FortiClient IPSec VPN.My laptop is running Windows 11 with an Intel network adapter, using FortiClient version 7.0.14 managed by FortiEMS 7.0.13.The issue is as follows:SSL VPN connection works perfectly without any problems. However, when attempting to connect to an IPSec VPN, the connection fails with the error message: “IKE negotiation failed” / VPN connection failure.Interestingly, when I use the FortiClient free (standalone) version and import the same IPSec configuration file, the connection works successfully on both Wi-Fi and LAN.Other colleagues using the same EMS-managed FortiClient version are able to connect without any issues.Based on my initial observation, I suspected it might be related to the network adapter; however, this seems unlikely since the IPSec connection works correctly when using the free version of FortiClient.I would appreciate any insights or suggestions
I login to this portal (Fortinet Community) and the vertification code sent to the email. How i can change the vertification code from email to authenticator app?
We are working on replacing Aruba switches with FortiSwitches. We have HA firewalls and currently use a VLAN on the Aruba to pass the ISP link to the WAN ports on the firewalls. We've run into an issue at a couple of sites where the ISP device refuses to communicate with the FortiGate when passing through an unnumbered VLAN configured on the FortiLink connection. If we put the Aruba back in, the WAN links can then talk to the ISP gateway again. It's only happened at a couple of our sites, so I suspect it's specific to certain brand ISP devices. At the first site it happened at, we resolved it by moving the WAN IP to the VLAN Interface under Fortilink and eliminated the uplinks to the WAN ports. At the current site we're working on, there are hundreds of IPSec tunnels and policies tied to the WAN interfaces, so moving to a VLAN interface under FortiLink would be a time-consuming endeavor. Any idea on what may be causing this?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.