Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I’m trying to configure my 100F for RingCentral, whats the best way to go about this?
I want to reset my password, but the maintener and the bcpb are not used which this version of my FGT. What should i do?
Hi team, I have recently found the neighbor roles feature in the sdwan configuration. I don't really understand the implication of primary and secondary configuration. Until now, I used parameters such as local preference to control BGP route announcements and receipts. Can I control 2 BGP sessions with both parameters? I explain myself, if one neighbor has the role secondary the BGP session is in "passive" mode until the primary BGP session fails. Thanks for teh help!
Hi All, I'm implementing SDWAN topology with Dial-Up Ipsec VPNs. I also want to implement traffic shaping for the relevant traffic. I plan to use Shaping profiles on interfaces but I'm a little bit confused about where to put the shaping profile. On the VPN interface, or on the physical WAN interface. Or Both? Never find a documentation about that. Thank you!
i have configured dialup vpn that phase2 selector i configured 0.0.0.0 both src and dst but when it push to spoke it choose only spoke’s tunnel ip only in dst instead of 0.0.0.0 and same is taking spoke src only tunnel ip and destination 0.0.0.0what should i do so it can take 0.0.0.0 is src and dst
I created an IPsec VPN tunnel on Fortinet, but after users connect, they still see their own public IP address when checking on WhatsMyIP. What could be causing this issue, and how can I fix it?
Hello, I created custom role for users in FortiPAM. I only allow to that role of users permission for secret list and secret folder (everything else is hiden). When i log with user and with that role, user see secrets and folders which is good. But the problem is because it also see secret settings (Policy,Launchers,Templates,Clasification Tags) which shouldnt see. Is there way to hide that settings from user also?Thank you.
Hello,I have a question regarding the Quarantine Release Re-scan feature in FortiMail 8.0.0.During testing, I noticed that the re-scan mechanism appears to work only for attachments/content scans, while URLs inside the email are not re-checked during message release from quarantine.Test scenario: A message containing a phishing URL was quarantined. Quarantine Release Re-scan was enabled for AntiSpam, AntiVirus, FortiSandbox, Content. After clicking Release, the email was delivered successfully. No new URL reputation lookup or antispam URL scan events appeared in the logs. It seems that the phishing URL was not re-evaluated during release. Could you please clarify whether Quarantine Release Re-scan is intended to work only for: attachments, content inspection, antivirus and not for: URL reputation checks, FortiGuard URL filtering, final URL inspection, Thank you.
Environment: Cluster (Supervisor & Workers): Residing in VDC-A using private IPs. A Public IP pool is assigned to the VDC with NAT and Firewall rules mapping to the Supervisor and Workers. Collector: Residing in VDC-B. It has a Public IP associated via NAT and is intended to communicate with the cluster over the internet. Connectivity Status: Initial connectivity (Telnet/Curl) is verified and functional between the Collector and the Supervisor's Public IP. The Problem: Although the Collector was provisioned successfully, it failed to appear in the Supervisor's Collector Health tab. Investigation of the logs revealed that during the registration handshake, the Supervisor provided its internal private IP (and the workers' private IPs) to the Collector. Consequently, the Collector attempted to establish a heartbeat using the unreachable private IP.Current Progress & Obstacles: Partial Fix: I manually updated /opt/phoenix/config/phoenix_super.txt on the Collector, replacing the
Dear Community, I have three question about changing parameters in a production environment ha cluster. This cluster has two hw fortigate on one location, which work nicely. Now I have to add a third one but in this time this should be an another location. So I have to prepare the working cluster to add a far third one. 1) I would like to make the Ha cluster more latency tolerant. Current config: hb-lost-threshold 3 hb-interval 2 hb-interval-in-milliseconds 100ms Is it enough to raise only the hb-lost-threshold, or should I change the hs-interval as well? And more importantly what should be the changeing sequence of these parameteres? Should be change one parameter at once on the primary and secondary member? 2) My dedicated hb interfaces direct connected with cable, and set up that the sync packets use this ha intercae. Now I would like to change this that every packets related to ha goes through a switch/vlan. So I have to add a new ha interface (port1 through switch) with lower pri
Hello community,I am currently configuring FSSO in FortiGate to create identity-based firewall policies using Active Directory usernames/groups, and I have a question regarding two different configuration sections that seem related to AD integration.I noticed there are two separate options in the GUI:Security Fabric > External Connectors > FSSO Agent on Windows ADUser & Authentication > LDAP ServersAt the moment, I configured only the FSSO option and it is already learning users/groups correctly from Active Directory.My question is:What is the functional difference between these two configurations? What is each option specifically used for? Is it necessary to configure both for identity-based policies? In which scenarios would LDAP configuration still be required if FSSO is already working?From my understanding so far:FSSO is mainly used for transparent user identification (User ↔ IP mapping) based on Windows logon events. LDAP seems more focused on direct authentication a
We use multiple dial up IPSec vpn's on our vm Fortigate (7.2.9) for remote support. But for windows 11 devices (forticlient 7.4.2) the split tunnel routes are not installed, only default route over the VPN. Because of this user do not receive 2fa token on the windows device as internet is not permitted. work around is to use a secondary device to receive 2fa token (mail). VPN is working for the rest, just not split tunnel. config vpn:config vpn ipsec phase1-interfaceedit "xxx"set type dynamicset interface "port5"set local-gw xxxset mode aggressiveset peertype oneset net-device disableset mode-cfg enableset ipv4-dns-server1 xxset ipv4-dns-server2 xxset proposal aes256-sha256 aes128-sha1set xauthtype autoset authusrgrp "xxx"set nattraversal forcedset peerid "xxx"set ipv4-start-ip 172.29.2.0set ipv4-end-ip 172.29.2.7set ipv4-split-include "Remote-Access-VPN-Split"set save-password enableset psksecret xxxnextendconfig vpn ipsec phase2-interfaceedit "xxx"set phase1name "xx"s
This same question was asked over a year ago, but never found resolution. I send invites to users following the Technical Tip: How to send email notification which contains FortiClient installer package that embedded with invitation code post. Forticlient is installed and connects to the fabric as expected. If a user disconnects from the fabric they are unable to reconnect without using the invite code. The invite code is supposed to be short-lived and only used to register the endpoint. I thought FCEMS Cloud sent an identity cert to the client machine upon registration. I cannot find any settings for client certs or similar. How are users supposed to reconnect after the invite code expires?
So i deployed fortiweb as a node in eve and u get unlicesed and there is no way to connect to fortiguard and get trial licesne activated so is there a solution and for the unclicensed status does it function just as a dump switch no inspection nothingI tried with transparent mode and created a vzone and nothing happens no sql injection protection nothing
I have requirement to restrict our devices to be authenticated via entra id before the devices connected to the network.Form what i know this can be fullfilled by enable the 802.1x, but also i heard this can be done even not use 802.1x. ANyonw one know what is proper way, using 802.1x or not?
There is a bug - FMG does not recognise radius server config change in the install process. How to fix this? Is it fixed in version 7.4.4 and it is 60F model
Anyone know where i can download forti vpn client for mac?I try download from https://www.fortinet.com/support/product-downloads#vpn but after i fill the data then the page only showing submitting and back to download now again.
I have an DialUp VPN with Entra ID Auth. IP Assignment via IP Range.I want to assign different ranges to different users based in their Group memberships.I found CLI Option "set assign-ip-from usrgrp".Is it possible to use this or any other option to archive this behaviour?
Hello,I need help about our issue with connectivity FG<->FAZ. We are currently troubleshooting connectivity between a FortiGate 200G and a FortiAnalyzer VM.Environment overview:FortiGate 200G running in multi-VDOM modeDedicated management interface configuredFortiAnalyzer VM reachable through data-plane routing from the root VDOMManagement and data interfaces are located in different VDOM/routing contextsObserved behavior:FortiGate is attempting to establish a connection toward the FortiAnalyzer using:TCP/514 (reliable logging / OFTP)UDP/514diagnose test application fgtlogd 1 shows:state=disconnectedoftp-state=connectingPacket sniffer on FortiGate shows:mgmt out -- 10.0.0.2 -> 192.168.0.4:514Packet sniffer on FortiAnalyzer VM does not see any packets from the FortiGate.Traceroute sourced from 10.0.0.2 toward 192.168.0.4 does not pass the first hop.FortiGate configuration notes:The management interface is configured as:set dedicated-to managementBecause of this, FAZ/FMG/DNS/NTP
Hi all, quick question for the Fortinet community:Is it possible to import an IPsec VPN configuration into FortiClient via XML including all parameters (excluding user credentials) while keeping the Pre-Shared Key encrypted?
Hello Everyone,We are planning to deploy a FortiGate 60F firewall with a 1-year Unified Threat Protection (UTP/UDP) license in our environment.Currently, we are already using the device for basic WAF-related tasks, and now we want to enable remote VPN access for our users.Our requirement is:Around 15–20 users need to connect remotely at the same time (concurrently) Users will access internal office/premises resources remotely We are considering SSL-VPN or IPsec Remote Access VPNHowever, before deployment, we want to clearly confirm the licensing situation to avoid surprises later.We have seen some firewall vendors/products where:Only 5 VPN users are allowed by default Additional concurrent VPN user licenses must be purchased separatelySo we would like confirmation specifically for FortiGate 60F:How many SSL-VPN users can connect concurrently on FortiGate 60F? Does the 1-year UTP/UDP subscription include remote VPN capability? Do we need any additional VPN user license for 15–20 concurr
Can someone from Fortinet indicate when Ubuntu 24.04 will be supported.Ubuntu 24.04 LTS was released on 25 April 2024
Hello, used products: FortiGate 80F/FortiGate 400F I have a simple Hub and Spoke Szenario, which works perfectly in 7.4.8 and less. If I upgrade my spoke to 7.4.9 I can't establish my VPN any more. Spoke says: ike V=root:0:vpn-pfi-hub: connection expiring due to mode-cfg client IPv4 error ike V=root:0:vpn-pfi-hub: going to be deleted ike V=root:0:vpn-pfi-hub: schedule auto-negotiateHub says:twin connection Spoke config: mode-cfg, but with manual assigned ip on the interfaceHub config: mode-cfg, no ip assignmentThere must have been a change in 7.4.9 - but I can't find it. If I downgrade, everything works.Kind regardsTwoSoulz
The documentation states you can define multiple certificates in an SSL profile in replace mode and it will compare the server name identification (SNI) and the common name (CN) with the certificate list in the SSL profile, and use the matched certificate as a replacement. If there is no matched server certificate in the list, then the first server certificate in the list is used as a replacement.However, this does not seem to work if you are using wildcard certificates. I have an SSL profile that has multiple separate wildcard certificates defined in the profile that is used to protect a highly available reverse proxy for several domains and subdomains.e.g. SSL Profile in replace mode has separate wildcard certificates for *.abc.net, *.abc.com, *.io.abc.com, *.abc.org, *.bbc.com, *.bbc.org. If a request comes in with an SNI of www.abc.com it will instead return the first certificate *.abc.net as the exact CN name matching does not match the wildcard.Has anyone else experienced this is
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.