Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Why is traffic still being blocked even though the firewall policy, NAT, and routing look correct on FortiGate?
We have upgraded Fortisiem cluster setup (1 Supervisor, 2 Worker, and 1 Keeper)from 7.2.6 to 7.5.0. Upgrade was successfull. we noticed that the phGenerativeAI process on the Supervisor node is restarting approximately every 3 minutes, which is generating warning alerts. Please guide@Anthony_E , @Secusaurus
Hello,Is it possible to establish a fiber link between:a FortiSwitch SFP+ port using a 10G SFP+ transceiver and a third-party switch using a 1G SFP transceiverby forcing the FortiSwitch interface speed to 1G?I would like to know if:SFP+ transceivers on FortiSwitch support 1G operation or if both sides must use the same transceiver type/speed (SFP↔SFP or SFP+↔SFP+)Has anyone tested this successfully with FortiSwitch and third-party switches?Thank you.
Hi everyone, I'm trying to set up remote access via IPSec to a FortiGate 60F. Since MS365 SSO is in use already for various services, this should be used also for VPN access. I've been able to successfully implement this and was able to connect from a Windows box with SSO and the FortiClient VPN-only version (7.4.3 hotfix 1.8758). EMS is not in use. However, I'm also looking for a solution for Linux, but each option that I see leads to a dead Open-source IPsec clients like strongswan and libreswan don't appear to support SSO authentication (yet). I tried to add a separate user using static credentials for EAP login, but I also haven't found a way to use these tools with both a PSK and additional EAP authentication.I was able to establish a connection with the regular Linux FortiClient, but it can't be used without an EMS except for a trial.The FortiClient VPN-only version for Linux (7.4.3 build 1736) appears to only support SSL VPN, but not IPSec.SSL VPN is obsolete
Hi Everyone, I want to know where is the rewards section for the Forti Defender Community? Regards Farina Ahmed
How can I troubleshoot missing event correlation between FortiGate, FortiSIEM, and FortiEDR when all devices appear connected?
What should be checked if FortiEDR detects a suspicious process but does not automatically isolate the endpoint?
Hi All, I want to ask about URL Filter in Webfilter Profile.I added a URL Filter Exempt(type:wildcard).Target url to use 8020 port, but Access block. I checked this KB: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Resolve-issue-web-filter-block-override-and/ta-p/193291?externalID=FD39997And set config: set ovrd-auth-port-warning 9020, and then the URL Filter takes effect.Does the official document mention that Fortiguard uses this port like the link below?I wonder my solution is correct. https://docs.fortinet.com/document/fortigate/6.4.0/ports-and-protocols/362392/fortiguard-open-portsMy Fortigate: 6.4.9
Hello, I have a headquarters site with a FortiGate firewall.We also have multiple secondary sites across the country. Each remote site normally uses its primary ISP connection ( through MPLS) to access the corporate network. Our goal is the following:If a remote site loses its primary ISP link,We plug in a Starlink connection at that site,The site should automatically establish an IPsec tunnel (IKEv2) to the headquarters,All traffic (0.0.0.0/0) should be routed through the tunnel to HQ (full tunnel), so the site can continue to access the corporate network and internet through HQ.The tunnel requirements:IPsec with IKEv2Full tunnelStarlink uses dynamic public IPMy question:Is it possible to configure a single Phase 1 and Phase 2 configuration on the HQ FortiGate that can accept connections from all remote sites (with dynamic IP addresses), or do I need to create one Phase1/Phase2 pair per remote site ? What I find difficult to accept from a design perspective is the idea
Hello, Is there any known reason for the FortiClient taking upwards of 30 minutes to download or sometimes failing? Today, one download started, restarted after 40% then failed. This is the VPN only client downloading. - Dan
Hello all,I tried to update my devices managed by EMS to FortiClient 7.4.6, but all users on this version are not connected to EMS anymore. When I connect to the devices, it seems the FortiClient is not running.When I start it manually directly from the install folder, the FortiClient is starting and tries to sync, but as soon as the countdown reaches 0 and the client tries to sync, the FortiClient crashes and stops running.Anyone known what happened and if there is any workaround who not involved reinstall of the FortiClient in older version ?
All Internet access must go though a proxy server in my company. Now I am testing to use FortiClient EMS for my FortiClient users. But I found that FortiClient cannot connect to FortiClient EMS for telemetry connection via a proxy. Any work around can make this work?
Hey folks. I believe FortiOS runs some modified form of the Linux kernel. I'm not sure if that's true though. (Is it?) If you haven't heard, CVE-2026-31431 was announced today and many of us are scrambling to patch Linux servers.If FortiOS is running a Linux kernel, I am wondering if this CVE will be an issue for us? Particularly if we're running FortiOS on a VM. Thoughts?
Hello everyone,I'd appreciate some guidance on a sudden FortiSwitch 108F failure we're seeing at our manufacturing site.Device information- Model: FortiSwitch 108F- Manufactured: 2023.03.22- Has been operating without any issues until this morningSymptoms observed today- Users reported a complete network outage on the segment served by this switch.- When I went on-site to check the unit, the Power LED was blinking rapidly (fast blink, not the normal steady-on state).- All port LEDs on the ports with LAN cables connected were completely off (no link/activity indication).- No traffic is passing through the switch.- I have not powered the unit off yet, in case there is any diagnostic information that should be captured first.Questions1. Does the rapid Power LED blink on the 108F indicate a specific failure mode (e.g., boot failure, firmware corruption, PoE/power fault, or hardware failure)? Is this documented somewhere I can reference?2. Is there any on-site recovery procedure I can try b
Hi,I am new to Fortinet, and we have been unable to connect to our SSIDs since I did an upgrade to v7.6.6.It takes very long and often fails. When it works the connection is very slow with high packet loss (~85%). Has anyone else experienced this? What could be the issue? Thanks
We are experiencing a critical and recurring issue with our FortiGate 401E.The device hangs once or twice daily Issue has been ongoing for ~2 years During the hang: No traffic passes through the firewall GUI and SSH become inaccessible Console is completely unresponsive Only manual reboot restores operationThis is impacting production services significantly.🔧 Troubleshooting Done:Firmware upgraded from v7.4.0 to v7.4.8 Issue persists even after upgrade No configuration changes correlate with the issue Problem occurs randomly without a clear pattern
After upgrading the firewall to FortiOS v7.4.11, I noticed inconsistencies in FortiView. For example, the information displayed in the Source column does not match what is shown in the Device column.As shown, the IP address in the Source column ends with 211.35, while in the Device column it shows 211.62. Additionally, the MAC addresses are also different.What is the problem ?
Hi everyoneWe will soon be upgrading our FAC instance from 6.6.x to (probably) 8.0.2Running a 2 node cluster, both are VMs.From what I can see, it should be a direct upgrade path without any inbetween jumps.I will read through the release notes, known issues etc, but can anyone who has performed this process comment on how it went? Any surprises or hidden 'foot-guns'?
Hello,Currently our Fortiauthenticator is on version 6.6.8, and we have an issue in which usage on the user is not matching actual usage of the firewall - resulting in the user being disconnected due to daily quota consumption. We have Daily limit profiles set on all our users. And most of the cases, the user consumed for example 700MB, and his limit is 1GB, but the Fortiauthenticator reads the usage as 1GB and disconnects him, below is more in depth and has an example.User mrw.user78x has 2GB daily limit quota enforced, below you can see his usage from firewall its self – 1GBUse monitor tab showing correct usageBut in the user profile usage showing fully wrong – 1.9GB - Only after pressing reset usage, it will refresh to the actual correct usage, but if we don’t do this, the user will be kicked out shortly due to reaching 2GB daily limit even though in reality he is not.
Have an FS108.Reset the FS108 to factory defaults using paperclip + reset button.Manually assigned my laptop Ethernet adapter IP address 192.168.1.1 mask 255.255.255.0 GW 192.168.1.99Connected Ethernet cable between my laptop and port 1 on FS108.Open browser, go to http://192.168.1.99 and nothing. Also tried https...still nothing.Console to FS108 and exec factoryreset and factoryresetfull ….still nothing. I could set this up using the console, but I’d really like to know why it is not working as advertised.I have many more FS108’s to deploy and need to figure out if the “Easy FortiSwitch Setup” is not going to be so easy.
Hi Fortinet Community Fellows!I hope all of you are having a wonderful day. I am thrilled connecting with you fox! Best Wishes,Ehtisham
Hi everyone,We are using a FortiGate 60F firewall with SSL VPN configured for remote access, and users connect via FortiClient VPN.Issue DescriptionSSL VPN connects successfully every time via FortiClient Users receive VPN IP and session remains connected without disconnecting Internal resources (servers, RDP etc.) are intermittently not reachable When the issue occurs, VPN reconnect does NOT resolve the problem Users must either wait or restart system/network stack, but behavior is inconsistentKey ObservationThe issue does NOT occur on all clients at the same time Some users continue working normally while others lose access randomly Affected clients remain “connected” but cannot reach internal network resources Once the issue occurs, re-establishing VPN session does not fix itWhat we have checked so farVPN tunnel remains up with assigned IP Issue appears random across users and sessions No clear pattern related to user group or time Has anyone faced a similar issue on FortiGate SSL
Hi everyone,I am testing **inbound SMTP STARTTLS deep inspection** on a FortiGate policy that publishes an internal mail gateway behind FortiGate.I found two Fortinet KB articles that seem directly related to this case: Technical Tip: Inbound email to mail server protected by FortiGate is not logged or inspected by Anti-Spam profileTechnical Tip: Enabling SSL/SSH inspection causes connectivity issues for STARTTLS The first article says that inbound SMTP traffic using SMTPS or STARTTLS, including STARTTLS on port `25`, needs SSL inspection if FortiGate is expected to inspect/log it with Anti-Spam, AV, DLP, etc.The second article says that SSL/SSH inspection in front of a mail security gateway can cause STARTTLS connectivity issues.My case looks very similar.Environment: Internet MTAs → FortiGate VIP → internal SMTP gatewayThe internal SMTP gateway is a Postfix / mail security gateway.The backend SMTP server supports STARTTLS on port `25`.Public side is published through VIPs:1.1.1.1:25
Hi all, I have my own Fortigate and one Fortiswitch from ebay.The switch seems under that seller account. Might I know if I still can use Forti-link to manage that switch without any issue? Thank you!
The FAC 300F in picture only has 200 user but its showing license type i belief FAC 300F only hardware limited upto 1500 user right ??
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.