Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello Everyone,We are planning to deploy a FortiGate 60F firewall with a 1-year Unified Threat Protection (UTP/UDP) license in our environment.Currently, we are already using the device for basic WAF-related tasks, and now we want to enable remote VPN access for our users.Our requirement is:Around 15–20 users need to connect remotely at the same time (concurrently) Users will access internal office/premises resources remotely We are considering SSL-VPN or IPsec Remote Access VPNHowever, before deployment, we want to clearly confirm the licensing situation to avoid surprises later.We have seen some firewall vendors/products where:Only 5 VPN users are allowed by default Additional concurrent VPN user licenses must be purchased separatelySo we would like confirmation specifically for FortiGate 60F:How many SSL-VPN users can connect concurrently on FortiGate 60F? Does the 1-year UTP/UDP subscription include remote VPN capability? Do we need any additional VPN user license for 15–20 concurr
Can someone from Fortinet indicate when Ubuntu 24.04 will be supported.Ubuntu 24.04 LTS was released on 25 April 2024
I have an DialUp VPN with Entra ID Auth. IP Assignment via IP Range.I want to assign different ranges to different users based in their Group memberships.I found CLI Option "set assign-ip-from usrgrp".Is it possible to use this or any other option to archive this behaviour?
Hello, used products: FortiGate 80F/FortiGate 400F I have a simple Hub and Spoke Szenario, which works perfectly in 7.4.8 and less. If I upgrade my spoke to 7.4.9 I can't establish my VPN any more. Spoke says: ike V=root:0:vpn-pfi-hub: connection expiring due to mode-cfg client IPv4 error ike V=root:0:vpn-pfi-hub: going to be deleted ike V=root:0:vpn-pfi-hub: schedule auto-negotiateHub says:twin connection Spoke config: mode-cfg, but with manual assigned ip on the interfaceHub config: mode-cfg, no ip assignmentThere must have been a change in 7.4.9 - but I can't find it. If I downgrade, everything works.Kind regardsTwoSoulz
The documentation states you can define multiple certificates in an SSL profile in replace mode and it will compare the server name identification (SNI) and the common name (CN) with the certificate list in the SSL profile, and use the matched certificate as a replacement. If there is no matched server certificate in the list, then the first server certificate in the list is used as a replacement.However, this does not seem to work if you are using wildcard certificates. I have an SSL profile that has multiple separate wildcard certificates defined in the profile that is used to protect a highly available reverse proxy for several domains and subdomains.e.g. SSL Profile in replace mode has separate wildcard certificates for *.abc.net, *.abc.com, *.io.abc.com, *.abc.org, *.bbc.com, *.bbc.org. If a request comes in with an SNI of www.abc.com it will instead return the first certificate *.abc.net as the exact CN name matching does not match the wildcard.Has anyone else experienced this is
Hello, I have a question regarding the “final URL inspection” improvements mentioned in recent FortiMail updates. According to the release information/documentation, FortiMail should now be able to: * resolve redirects,* analyze the final destination URL,* inspect the final URL behind redirect services. However, during my testing this behavior does not appear to work during SMTP/antispam inspection. Test scenario: * The email contains a redirect URL (Google redirect / notifications.googleapis.com).* The final destination URL is already categorized as phishing/malicious.* FortiMail rewrites the URL for URL Click Protection, but the email itself is still delivered.* In message logs and antispam logs I only see the original redirect URL. There is no information about the resolved/final URL.* URL Click Protection blocks the link only at click time, not during message inspection. Questions: 1. Is “final URL inspection” only implemented for URL Click Protection at click time?2. Is there any
How can I solve these problems?
The fw is running 7.4.11. is there true path based routing feature in a recent release?Has anyone successfully made FortiGate ZTNA path-based routing work where a single external IP + port is used to front multiple internal web servers based on URL path?Example setup I’m testing in a POC:https://10.0.3.200:50000/abc → internal Webserver A (10.88.0.3:9043)https://10.0.3.200:50000/xyz → internal Webserver B (10.88.0.11:443)What I’m seeing:FortiGate seems to pass the URI path directly to the backendSo /abc or /xyz ends up hitting the backend as-isThis results in 404s unless the backend is actually built to live under those subpaths.Below is the ztna server config. tbh I am not sure if the config itself is right.
Hi there,I have been struggling for months to replace SSL VPN with IPsec. We have a production environment with a 90G running 7.4.5 (we cannot change the OS yet because we still have not been able to migrate successfully to IPsec) and around 100 remote users connecting with LDAP and FortiToken. For the last 4 years we have had ZERO problems with SSL VPN.For about 4 months now, we have been internally testing IPsec, and we run into problems almost every week. Fortinet support recently suggested switching to IKEv2, so I decided to test this in a lab environment using an FG50G and FortiClient.Initially, I started with FortiOS 7.4.13 and FortiClient 7.0.12. With IKEv1 I was able to get the tunnel working and successfully ping the LAN. However, once I started testing IKEv2, the problems began.I then upgraded to FortiOS 7.6.6 and FortiClient 7.4.3 (which supposedly should be free of known bugs), but I still cannot get it working correctly. The VPN tunnel comes UP, but I cannot ping the LAN,
I have set up a lab following Keith over at CBT Nuggets. I followed him step by step. When I power on FW1 -FW4 when I go through the initial setup I input admin for login and leave blank for the password and keep getting Login incorrect. Is there something I am missing? I am using version 7.6.6. Fortinet FW Lab using VMware workstation
Hello everyone,I have a newly deployed FortiGate firewall with an active license.I would like to separate the internet path used by the FortiGate itself (FortiGuard updates, DNS, NTP, firmware checks, etc.) from the internet path used by LAN users accessing the internet.My setup includes a router between the FortiGate and the internet.What is the best practice to make:FortiGate local-out/update traffic go through one WAN/interface/path User LAN-to-WAN internet traffic go through another WAN/interface/pathShould this be done using:Local Out Routing Policy Based Routing SD-WAN or Static Routes?Any recommended architecture or examples would be appreciated.Thank you.
Has anyone run into this error when registering FortiClient to EMS Cloud using Google Workspace SAML?Error: 403 - app_not_configured_for_userEnvironment:FortiClient EMS Cloud Google Workspace SAML authentication FortiGate 90G HA pairAlready verified:User access set to ON for all users in Google Admin Attribute mapping is correct ACS URL and Entity ID match between EMS and Google SAML app Not in test modeStill getting the 403 on registration. Anyone else hit this and found a fix?
Can anyone explain what is the EOL date for this software version ?fortiauthenticator FAC-VM 8.0.1 build0033 (GA) end of life date
Hello everyone, After finalizing the bulk registration using the Persistent Agent, I’m wondering what’s considered the best practice to register a brand new device.The issue I’m seeing is kind of a chicken and egg problem:New devices can’t access the network because they get isolated (no Persistent Agent yet) But to deploy the Persistent Agent with GPO, the device first needs to join the domain And to join the domain, it needs network access first...How are you guys usually handling first time onboarding for new company devices after the first enrollement ?BR,
Hello Fortinet Team,I would like to confirm whether FortiClient Windows version 7.2.13.1284 is affected by the recently disclosed vulnerability related to Missing Authorization CVE-2026-44278, which may allow an authenticated local attacker to decrypt a currently logged-in user’s VPN password via an unprotected DLL function.Could you please clarify:Whether version 7.2.13.1284 is vulnerable If this issue has already been fixed in this release Whether any mitigation or upgrade is recommendedThank you in advance for your assistance.
Hi mates,I'm trying to test "SSL offloading" scenario in my lab with Fortigate v7.0.14 on kvm, as i should clear the scenario, it is simple process which we can achieve for example with nginx as a reverse proxy.There is a web-server ( 10.11.12.10) which placed in DMZ and there are WAN and MGMT interfaces as well. I'm trying to configure fortigate to act as revers-proxy to offload SSL be half of web-server. (Client from internet DST port 443 and using HTTPS in URL indeed)---> (WAN Port)-(Fortigate)-(DMZ port)--->( Web-server Port80 ) I used "virtual servers" for the solution and here's my configuration: config firewall vipedit "vweb"set uuid 3757f926-f35e-51ee-348e-fdc06559ea6eset type server-load-balanceset extip 172.29.129.190set extintf "port2"set server-type httpsset http-ip-header enableset ldb-method round-robinset persistence http-cookieset extport 443config realserversedit 1set ip 10.11.12.10set port 80nextendset http-multiplex enableset ssl-certificate
The issue:Clients connected to a vlan with Block intra-VLAN enabled can't reach the FortiGate for around 2 minutes and 30 seconds after failover. Clients connected to a vlan with no Block intra-VLAN enabled do not have this issue.All switches are managed by the Fortigate.Topology:2 X Fortigate 601F in HA A/P2 X Core switches FortiSwitch 1024E in MCLAG2 X FSR-216F-POE connected in a ring to the MCLAG switches. So, the first switch connects to the first 1024E switch and the second connects to the second 1024E switch with a link between the two FSR-216F-POE switches. (We can't change this because of the physical fibers)I have tested with two clients connected to the same switch. Client A connected to port 1 on a vlan with intra-vlan blocking enabled, and Client B connected to port 2 on a vlan with intra-vlan blocking disabled.Client A was having issues after the failover and could not reach the Fortigate for around 2 minutes and 30 seconds. Client B does not have any problems. It looses o
Hi, I am trying to migrate IKEv1 to IKEv2 Dial-UP VPN tunnels for devices that use Forticlient and that do not use Forticlient(e.g. MacOS).The configuration includes a split tunnel setup.When a Forticlient enabled client attempts an IPSec connection the client acquires a split tunnel VPN session. I can see the following few lines in the debug session that indicate routes will be installed in the routing table of the device. ike 2:QDIPS_0:10843292: processed INITIAL-CONTACTike 2:QDIPS_0:10843292: mode-cfg assigned (1) IPv4 address 172.28.12.1ike 2:QDIPS_0:10843292: mode-cfg assigned (2) IPv4 netmask 255.255.255.128ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:10.0.0.0/255.0.0.0:0ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:172.16.0.0/255.240.0.0:0ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:192.168.0.0/255.255.0.0:0ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:91.200.16.0/255.255.254.0:0ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:141.176.34.0/255.255.255.0:0ike 2:QDIPS_0:1
I’ve just rolled out 802.1x for the first time and it ~~appears~~ as if reauth causes disconnects. In the log it says the port is no longer authorised and then reauthenticates. Is that correct?I’d have expected the reauth to work similar to IPSEC, where it does it before the expiry time, so that things don’t drop? If it does then fail, then deauthorise the port.
We have a couple of internal CAs here and with a new setup of a FGT 100F on 7.6.6 and several FSW 148Fs on 7.6.6 we noticed that the CA certificates (and user peers) are not syncing to the FortiSwitches. This is with tunnel-mode compatible set already.To work around this I created several fortiswitch custom-scripts that create CAs and peers and an automation that looks for FortiSwitch Connected events and runs those scripts on the connecting switch.Is this a known issue on this release? Did I miss something in the initial setup? Is this standard behavior?
Hi all, could you tell me where I can find the link to operate queries regarding S/N to see active contracts and so on?I remember that it was something like "Find Asset" or similar but I'm not able to find it anymore... Thanks in advance
I wrote a Fortigate Administrator exam the previous week, and mid exam my pc restart and I had to login in again to continue but I was unable to continue because the Exam did not want to open again, the pearsonvue app was only showing the my video, and no chat option was available, after a while I got disconnected from the exam and I was told that I violated a policy when I contact the support team. I am reaching out because I lost my voucher and 200usd for a system that didn’t work properly. Please hep!
I’m running v7.6.6 on FortiNAC. When I issue ‘backup now’ on the system backup using the GUI, it seems to work. However, the file never shows up on FTP server. In fact, no packets are generated at all towards the FTP server, thus ruling out syntax.When I run the command from the CLI, I see the packets and the file is accepted by the FTP server.execute backup config ftp / 10.99.3.206:21 <user> <password> Any ideas why GUI not working?
We are running a Forticlient EMS Server 7.0.9 with ~350 Forticlient 7.0.9 endpoints in use. In recent weeks we have received more complaints from Windows 11 users on our network that picture files (jpg, png) become corrupt when copied or opened from the network drive. They can open them, but the pictures are "corrupted". Windows 10 users are not affected by the problem. If we disable FortiClient and copy the files again, no errors occur. We already deactivated the option "Scan Network files" in the corresponding Malware Protection Endpoint Profile, but this didn't help. Does anyone have a similar problem and a solution?
Hi ti all, Our FortiGate 50G is protecting 2 different routers from 2 different ISPs. One is plugged to Wan and the other to Lan1 (=Wan2). Domestic use network. Only ethernet. No WiFi. A few days ago, I tried to protect a TV decoder with the FortiGate. Creating the multicast policies, I have surely changed something I should not have to. The TV decoder was plugged into lan 2 which belongs to a Vlan switch (called "lan". Members: lan 2 + lan 3). This Vlan provides internet from only one of the routers Now I have the following symptoms: - When using this routers's internet and plugging the ethernet cable to my computer, my Airbook gets an auto-assigned IP first (yellow led) and, after 30 seconds, it switches to a normal IP (green led): Internet is available then. This symptom happens only with one of the routers (plugged to lan2 or lan3... Where the TV decoder was plugged to). I tried to disconnect "STP". then the symptom disappears. But comparing with the old configuration file, I notic
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.