Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello,I have a 300E chassis, and we are going to migrate it to an 810G chassis.We need to replicate the 300E configuration on the new FAZ chassis. Do we need to update the 810G’s firmware to the same version as the 300E?Do we need to create the same number of ADOMS on the new box as on the 300E?Thanks for your feedback.
Hello Dears,I’m trying to extract content from file using the built-in connector and putting the attachment IRI to the step {{vars.input.records[0].file['@id']}} but it timeout with the following error:do you have any idea for the reason of this ?Thanks, on advance
Hello,We have a FortiSwitch connected to a Huawei core switch, and we want to manage the FortiSwitch through our FortiGate using FortiLink.We configured the FortiLink VLAN on the Huawei switch, and we also configured DHCP discovery on the FortiSwitch:config switch-controller globalset ac-discovery-type dhcpset ac-dhcp-option-code 138endWe also configured the trunk on the FortiSwitch:config switch trunkedit trunk1set static-isl enableset static-isl-auto-vlan enableset members 51 52nextendThe FortiGate discovers the FortiSwitch through FortiLink, but the switch is always displayed as Offline/Down.FLP debug logs show that the FortiGate and FortiSwitch exchange packets successfully, and the physical link is UP.Has anyone experienced this issue before when using FortiLink through a third-party core switch (Huawei)?Any advice would be appreciated.Thank you.
hi,is there a way to send a weekly or monthly report to our registered email for the FortiFlex license points usage?it’s kinda tedious and manual looking at the points usage in the portal.or are we just going to receive an email if it’s already in a low point threshold?
Hi Folks,I need an urgent solution; we have FortiGate proxy, Forti Authenticator, and FortiClient for SSO in our setup. To deploy FortiClient, we are using SCCM, not EMS. A few days back, we had an issue where FortiClient was uninstalled from many Windows systems-not all at once, but over 2-3 days-and more than 100 users complained. We engaged our SCCM and AD teams, and according to them, there was no trace in the system to identify what triggered the uninstallation. We have taken Fortinet help as well, but as it was not managed through EMS, they said it is not within Fortinet's scope either. However, later we asked the SCCM team to deploy FortiClient again on the affected users' systems and it's working, but we are left with the RCA. Can anybody please help if you have faced such an issue and how we can identify what triggedred the un-installation to prevent in the future.FortiClient version - 6.0.9
Troubleshootinghow to solve this issue? please any ideas. i have implemented the ZTNA on two devices, but still getting this error. [V][p:7134][s:8274] wad_vs_ssl_c2p_check_alpn :24835 wsp=0x7f5041e78048, alpn=h2[V][p:7134][s:8274] wad_vs_ssl_c2p_check_alpn :24844 wsp=0x7f5041e78048, vs server set alpn http2[V][p:7134][s:8274] wad_vs_proxy_match_vhost :4714 2:ZTNA-web-proxy: matching vhost by: portal.ztna.com[V][p:7134][s:8274] wad_pattern_matcher_search :1226 pattern-match succ:portal.ztna.com[I][p:7134][s:8274] wad_vs_proxy_match_vhost :4722 2:ZTNA-web-proxy: matched vhost(ztna-web-portal-fqdn 0x7f503cc31660)[E][p:7134][s:8274] wad_vs_find_cipher :10538 wsp 0x7f5041e78048 ssl no matching CipherSuite, abort[I][p:7134][s:8274] wad_ssl_app_port_fts_in_close :20148 sp=0x7f5041e78048/10 recv close request from fts close-type=0 closed=0[I][p:7134][s:8274] wad_ssl_port_task_end
Hello there,can anyone suggest any other tutorial for agentless ZTNA rather than fortinet official documentation. I don’t understand it how to implement correctly. any video, documentation, guides, articles would be appreciated.
Hi,I just want to know, when checking the maximum higher bandwidth, why is it higher when looking at it in 24 hours than in week?Example: When I’m checking the maximum higher bandwidth for a certain interface in 24 hours, the maximum is 5.11 Mbps, but when I check in week, the maximum is 2.25 Mbps.I hope someone can enlighten me. Thank you in advance.Oliver
Hi All,We have a pair of 100F’s and a pair of 600F’s , these are in HA Active/Standby mode.We have the management interface configured for well management, it has been suggested that we enable the Management Interface Reservation option within HA however there are no clear guidelines on how to do this.I understand that we cannot use the existing management interface and that we cannot use the same subnet we use for the management.So we just pick another interface , find a different subnet and patch this other interface to a switch ?. So that's two interfaces (1 for active and 1 for standby) ?.If so what purpose does that serve as you still need to patch both interfaces on the firewall - so just consuming interfaces to replicate the management interface ?So just looking for some really good configuration guidelines - not the Fortinet docos they are useless and do not explain it well enough. Regards
been wanting to ask this community specifically because i figured people here would have more practical experience than most...we are a mid sized organization in Dubai that recently went through a significant network security refresh. FortiGate firewalls, FortiSwitch, and FortiAP were all part of the deployment and the procurement process raised some questions that i could not find clear answers to through official documentation alone.the specific question is around how strictly Fortinet ties support access and FortiCare contract eligibility to authorized supply chain. we had a situation during procurement where some suppliers were offering noticeably cheaper pricing but the answers around authorization status were vague enough to make the team uncomfortable.ended up going with Tech Distributor after specifically looking for an authorized Fortinet distributor in Dubai that could confirm legitimate supply chain documentation. the pricing was not the cheapest we found but the FortiCare c
HelloCurrently the latest available versions of FAC are:6.6.16.5.56.4.9I preferred avoid 6.6.1 for my production since it is new version (I guess not mature yet).So I have few questions regarding 6.4 and 6.5.Is 6.4.x still supported? (because I noticed the last patch has been released on 28 December 2023)Should I avoid 6.5.x, since it is odd? (odd is short term support if I'm not wrong)
Hello, I need a way to install the FortiClient VPN free version that also loads a preconfigured config file. The examples I received while googling this question are not working for me. This involved having a powershell script as shown here: msiexec /i "setup.msi" /quietStart-Process "C:\Program Files\Fortinet\FortiClient\FCConfig.exe" -ArgumentList "-m vpn -f 'FortiClientConfiguration.conf' -o import -p 'connecting'" -Wait I made the Install command on Intune: powershell.exe -ExecutionPolicy Bypass -File install.ps1I created the installation script using the .intunewin file with that nifty wizard.It is not working, and I’m not getting an error or anything. Anyone else do this successfully?
I've just installed FortiClient VPN the .deb package from here https://www.fortinet.com/support/product-downloads .installed with `sudo dpkg -i ...` Setupd the configuration ( as I have on my windows pc and on my android ) when I try to connect I get the following in the journal: iul 29 14:23:43 station1 kernel: iked[283119]: segfault at 28 ip 000000000045195d sp 00007ffe2a7e6900 error 4 in iked[400000+891000] iul 29 14:23:43 station1 kernel: Code: 4c 89 e5 48 89 44 24 38 48 8d 84 24 88 00 00 00 45 89 d4 45 89 de 48 89 44 24 50 48 8b 45 00 45 89 f5 31 ff 31 db 4a 8b 0c e8 <8b> 51 28 85 d2 74 42 48 8b 71 20 8d 7a ff 31 db 48 8d 46 08 4c 8d iul 29 14:23:43 station1 fctsched[283131]: /opt/forticlient/iked: invalid option -- 'P' iul 29 14:23:43 station1 regolith.desktop[281914]: 14:23:43.573 › VpnHandler UNHANDLED {"isTrusted":true} iul 29 14:23:43 station1 fctsched[283131]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus iul 29
Hello,I’m trying to configure two different Fortigates 60F but both of these devices are unresponsive.I tried connecting via Ehternet on LAN 1 but i get no address via DHCP (no IP was released and i have APIPA address) , i tried setting up manual with IP 192.168.1.110 mask 255.255.255.0 gateway 192.168.1.99 but i can’t ping, https or ssh to 192.168.1.99 If i look at the ARP table i see that 192.168.1.99 is present but i get no response in HTTPS , SSH and PingThe weird thing is that using Wireshark i see that the Fortigate is responding to the ARP Requests but not to Layer3 traffic (HTTPS,DNS,SSH,Ping)Then i tried using the console cable connected to the Console Port of the fortigate but also that didnt work:So i tried to Reset the Fortigate but also that seems to not work, no LEDs are blinking and seems to not reset at all, i tried holding the reset button after power up for 1 min but nothing, i tried the same but when Fortigate was already booted up but nothing.The weird thing is that
Hi so we still havent found a solution yet. N.B. - Final Goal - is to have the same SSLVPN dialup discontinued - with new IPSEC Dialup IKEv2 - Firewall rules that control which AD User - user groups - can access which resources. This works when using local firewall users - but any sort of remote LDAP is failing. - tried AD LDAP that is working fine for logging into firewall. or the cisco duo radius server - from research and feedback from cisco staff - it should be using LDAP mode “ad_client + ldap_server_auto > this CAN send group information from AD to the FortiGate device”The thing is i dont think this is a Cisco duo problem but rather a fortigate config/compatibility problem. because if i create local firewall users - and add them into a group - attach them to the below IPSEC authentication - u can login and do the VPN connection. but as soon as u try referencing a remote LDAP - in my case a valid working AD Server or RADIUS Server - the EAP auth failed e
I have recently opened a ticket with Fortinet and shared this information so that Fortinet can fix a problem that was recently introduced in some of the newer 7.4 versions (such as 7.4.10, 7.4.11 and possibly earlier and later versions). It may affect many other versions, but I'm not sure, because I've been only having the issues with recent 7.4 versions. I have tested this on models 40F, 60F, and 61F, but I am guessing it will not be model specific.The issue: When doing a system Format of the drive, and then doing a TFTP firmware recovery, the TFTP connection will repeatedly "Timeout" when it attempts to download the firmware. On the TFTP server side, there will be a log entry when it connects, and it will result in a "Transfer Timed Out" message after it tries a number of times.I tested this using multiple TFTP servers:1) TFTPD32/TFTPD64.exe by Philippe Jounin on windows. 2) Fedora Linux's install of TFTP server3) The "Transfer" app for Mac by intuitbits4) Mac OS Native TFTP serv
Hello,Is it possible to establish a fiber link between:a FortiSwitch SFP+ port using a 10G SFP+ transceiver and a third-party switch using a 1G SFP transceiverby forcing the FortiSwitch interface speed to 1G?I would like to know if: SFP+ transceivers on FortiSwitch support 1G operation or if both sides must use the same transceiver type/speed (SFP↔SFP or SFP+↔SFP+)Has anyone tested this successfully with FortiSwitch and third-party switches?Thank you.
Why is FortiSIEM not receiving or parsing logs properly from FortiGate even though syslog forwarding is configured?
I am using FortiMail Cloud - hosted and wondering about Threat feeds. I see in the documentation it’s supposed to be a configurable option under the Security section (admin guide reports this). I have the option showing under my AntiSpam profile to choose one, but of course none exist and I cannot find it anywhere to setup/configure. Am I to assume this was just not removed from the full code as it got ported for cloud use and not allowed or is this something I need to open a TAC case and request to “open up” as it’s treated on a case by case basis?
We are currently testing the FortiClient EMS to switch from the free SSLVPN Client to IPSEC.I have some questions. Is it possible to create multiple dial-up vpn tunnels that authenticate against Azure AD via SAML?When I enabled the option “set eap enable” and “set eap-identity send-request” for a second tunnel,the connection via the first tunnel stopped working.Is it supported to add a user to multiple Azure AD groups and then assign the groups to different firewall policies in order to implement granular access control? We are using vpn split tunneling. I create a group which networks and hosts are routed through the tunnel.I then assigned that group to the VPN tunnel ( Accessible Networks ). I there a member limit for the group? Currenty it ist not supported to use a fqdn address for ipsec dialup.Are there any plans to support this?
Why is traffic still being blocked even though the firewall policy, NAT, and routing look correct on FortiGate?
We have upgraded Fortisiem cluster setup (1 Supervisor, 2 Worker, and 1 Keeper)from 7.2.6 to 7.5.0. Upgrade was successfull. we noticed that the phGenerativeAI process on the Supervisor node is restarting approximately every 3 minutes, which is generating warning alerts. Please guide@Anthony_E , @Secusaurus
Hello,Is it possible to establish a fiber link between:a FortiSwitch SFP+ port using a 10G SFP+ transceiver and a third-party switch using a 1G SFP transceiverby forcing the FortiSwitch interface speed to 1G?I would like to know if:SFP+ transceivers on FortiSwitch support 1G operation or if both sides must use the same transceiver type/speed (SFP↔SFP or SFP+↔SFP+)Has anyone tested this successfully with FortiSwitch and third-party switches?Thank you.
Hi everyone, I'm trying to set up remote access via IPSec to a FortiGate 60F. Since MS365 SSO is in use already for various services, this should be used also for VPN access. I've been able to successfully implement this and was able to connect from a Windows box with SSO and the FortiClient VPN-only version (7.4.3 hotfix 1.8758). EMS is not in use. However, I'm also looking for a solution for Linux, but each option that I see leads to a dead Open-source IPsec clients like strongswan and libreswan don't appear to support SSO authentication (yet). I tried to add a separate user using static credentials for EAP login, but I also haven't found a way to use these tools with both a PSK and additional EAP authentication.I was able to establish a connection with the regular Linux FortiClient, but it can't be used without an EMS except for a trial.The FortiClient VPN-only version for Linux (7.4.3 build 1736) appears to only support SSL VPN, but not IPSec.SSL VPN is obsolete
Hi Everyone, I want to know where is the rewards section for the Forti Defender Community? Regards Farina Ahmed
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.