Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi,large environment...Fortinet Firewalls and Proxy in top of the structure...I do not manage or access them, but definitely can report about problem or the solution found to my issue. The situation:1. Outlook 365 in place. Most of the users accessing e-mail through Outlook web.There are no problem when accessing e-mail using web browser. However, the users (including myself) who do use Outlook 2016 client experiencing the certificate error pop up on each Outlook opening and sometimes during the day even when it is opened.Clicking Yes or No doesn't change the ability to use Outlook 2016.Sure it is not a solution, but just to be sure I tried to install the Certificate for Current user and Local machine manually. If I had a certificate in hand, may be deploying by GPO could be a solution.But with all being said, I have a feeling that the issue could be simply fixed on Fortinet proxy. 2. The info I am getting in the message is a bit
UPDATE: I developed a solution that allows a TCL script to send an email. See article here. I have a customer that would like to run CLI/TCL scripts from FortiManager that validate the status of firewall policy and security profiles and report back the results to users. There are two ways that this might be done.1) Run the CLI/TCL script and email the script output to an email address.2) Write the results of the script output to a HTML file which is published as a custom web page and is available to users via a special URL that is hosted by FMG. (I mention this option because it is indeed possible to write to files using TCL scripts in FMG. So there is nothing to stop a TCL script from creating HTML files with script results contained therein. But there is no link to the files that makes them available to the FMG web service. So this option would need a soft link from the user space file storage area to a URL path in the FMG web server. That would be a pretty easy feature to add t
Good afternoon I upgraded the firmware of a FortiGate 60E from version 7.2.8 to 7.4.4 and once in the new version, the APs stopped working. In fact I don't see them in the "Managed FortiAPs" section, but I do see them in Dashboard -> Assets & Identities.It's a fairly old FortiAp, but up to version 7.2.8 it worked just fine. Is there any way to fix this problem? Thank you very much in advance.
Hi Team,I hope this message finds you well.I need clarification regarding the configuration of SAML authentication with a user-based policy for a customer. Here is the situation:We have successfully configured SAML authentication, and it works when users are directly connected to the LAN.However, the customer has now deployed TP-Link wireless access points (AP), and users are unable to see the authentication page.Based on my research in the community portal, it seems that to configure SSO with a user-based policy for wireless users, the Forti-AP SSID needs to have the Captive Portal enabled and mapped to the Azure portal. Could you please confirm if enabling the Captive Portal for wireless users is indeed necessary in this case? Additionally, if the customer is not using Forti-AP, what alternative solution can be provided to ensure that wireless users can successfully authenticate? I would appreciate your prompt response as we need to implement a solution as soon a
Dears, Does anyone have threat intelligence feed connector configuration with FortiEDR? Like URL: Collection ID: Authentication: BR,
Hey!I need some advice from you guys on where to look for the problem.The network diagram looks like thisWORLD -> FG30E ->2x MikroTik -> 3xESXI 1xNASTesting the link from FG -> WAN Using the command diag traffictest run -R -c 45.147.210.189 port 5200 I am getting speeds from 600 to 900 Mbits/sec so let's say its OKThen I test the connection speed between the FG30E nad Debian Server. I set up iperf3 on a debian server and connect to it from FG30E In this case I get speeds from 916Mb/s to 950Mb/s, so MikroTik switches don't slow down the linkIn the last step I make iperf3 from the Debian server to the same address as the test with FG30I have speeds between 4 and 6 Mbps....I also tested the speed from a NAS server which is not virtual, the same thing happens...Where to look for the problem because I have no idea anymore....
Dear Team,After installing FortiClient Version 7.4.0.1645, I am getting this error and couldn't connect to my Fortigate 81E with firmware v7.4.4 build2662 (Feature). It used to work fine before without any issues but I feel it was cased either by firmware upgrade or FortiClient upgrade.
I have searched high and low, but cannot get a clear answer on this, created a CSR last year for a Fortigate, got it signed by ROOT CA, installed cert and used it for SSL VPN, no problem at all. Now its renewal time, got the new cert from the signing authority GODADDY, and I cant install it? I have the ROOT CA cert on there, so I goto Certificates > import > Certificate > Local certificate, select my .cer file and I get this "Certificate file is duplicated for CA/LOCAL/REMOTE/CRL.cert" I assumed I would delete the old one and replace with this one, same issue? any help please? the troubleshooting link for this error is not helpful, I really dont understand why it doesnt work Thanks
Hi Everyone, I'm facing a strange problem, I have 2 usernames which are working fine on different machines but on some specific machines as soon i hit connect it got stuck on connecting with no progress. I'm facing this issue on windows 10 pro machines. personally i have tested it on windows11 and it's working fine on them. I'm unable to see any logs when the user is stuck on the connecting stage.
Recently I have upgraded two clients to the newest firmware released for Fortigates, 5.0.5. Both clients heavily utilize iOS in their environments and somewhere along the upgrade path to 5.0.5, iOS traffic seems be down right blocked or they start downloads but the downloads are never successful. By blocked, the user will attempt to download iOS updates, iBooks, applications, etc and either the download never starts and eventually times out or the download does start but only gets a few Mb in before it stops. One client has even reported this extends to Mac users attempting to use iTunes. Besides the firmware upgrade to 5.0.5, nothing about these clients networks have changed. Each are using different wireless setups, different switching, etc. One client has a Fortigate 100D and the other 2x300C in an Active-Active HA cluster. During testing with each client, I have disabled everything down to the web filter. With the web filter active, the problems exists but with the web
In my FortiAnalyzer, scheduled reports are no longer being generated. However, if I manually click "Generate" on a specific report, it works fine. Additionally, there is plenty of space left in the /tmp folder, so I'm unable to identify the source of the problem.
I have 2 standalone FGT200E firewalls running 6.1.15, for the last month Qualys has failed the PCI ASV scan with a detected vulnerability QID150004 Predictable Resource Location Via Forced Browsing, its finding an /image/ fileRESULT:url: https://x.x.x.x/images/Payload: https://x.x.x.x/images/comment:Original URL is: https://x.x.x.x/matched: HTTP/1.1 200 OK I have SSL VPN in tunnel only mode, web mode disabled I came across an article https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-prevent-the-SSL-VPN-web-login-portal-from/ta-p/215905 to stop the web login page from appearing, which i applied to no effect. I also changed all the portals to not allow forticlient download in case this was causing the problem. Nothing has changed on Qualys that i know of & as mentioned scans were fine until the start of July.I've searched forums, google etc but not coming across any similar issues.
Hi, We have configure new OU in Fortisase. After logged in into that OU we are unable to see the default certificate in certificate section.The same is showing properly in existing OU.Please find attached snap and guide... Regards,Ganesh
I am using fortinet firewall on AWS & also I have configured SSL vpn. I am facing an issue with the MAC user they are not able to use interenet after VPN. safari is working but google chrome is not working. I have check in the wireshark as well traffic is not hitting from google chrome after VPN connectes but same worting in safari.I have unisatll forticlient & reinstall as well but nothing helps. Please help
Spoiler (Highlight to read) Is there a way to configure a VPN connection time limit for each user or a group of users?For example: user 1 is connected to VPN for 1 houruser 2 is connected to VPN for 2 hoursAfter 1 hour, user 1 disconnects and re-authenticates. After 2 hours, user 2 disconnects and re-authenticates.
Hello. In "Advanced Settings" -> "Syslog Servers" you can set an ip address so send SSO Agent logs via syslog to a syslog server. Is there any option so select the message severity to send via syslog? At the moment the agent sending all debug and informational level logs to syslog server.
Is there a way to configure FortiGate to not reflect the DHCP server IP when the end user (guest) opens command prompt on the client machine and perform an "ipconfig /all"? If there is no direct configuration, any other ways for us to hide the IP of DHCP server? Thank you!
Greetings. For certain reason, I couldn't connect to the VPN using Fedora 40 on my system, due to a research to find out what happened, for some reason, specific dependencies were not resolved when reinstalled forticlient with the latest version (7.4.0.1636) and testing on a VM, I found that some dependencies were not installed on my system and the rpm package didn't expected to resolve, so I took the list of dependencies using dnf repoquery that matches with forticlient, using dnf install $(cat <listDependencies.txt>), and got my issue solved. If someone else is dealing with that, here's the list of dependencies that I installed:Spoiler (Highlight to read)alsa-lib-0:1.2.12-1.fc40.x86_64at-spi2-atk-0:2.52.0-1.fc40.x86_64at-spi2-core-0:2.52.0-1.fc40.x86_64atk-0:2.52.0-1.fc40.x86_64bash-0:5.2.26-3.fc40.x86_64bzip2-libs-0:1.0.8-18.fc40.x86_64cairo-0:1.18.0-3.fc40.x86_64cups-libs-1:2.4.10-3.fc40.x86_64dbus-libs-1:1.14.10-3.fc40.x86_64dnf-utils-0:4.8.0-1.fc40.noarchexpat-0:2
we'll be replacing our old Aruba APs w/ FortiAPs, each site has a fortigate connected to fortiswitch, but beyond the Fortiswitch are cisco switches. quick question; can I connect a fortiAP to a poe Cisco switch? maybe same vlan config would work (ideally)? I know when FortiAP is connected directly to Fortiswitch everything works great.
Hello Team, This is the scenario:FGT firewall offering SSL VPN serviceIs there any way to do these things?1. Autoban IP same user wrong password 5 attempts over 10 minutes2. Autoban IP different user wrong password 10 attempt over 30 minutes Thanks for the supportBR
Hello, we need to secure an IIS which servs several subdomains and different applications on one server with FortiWeb.How can it be accomplished to have different protection rules for several URL paths on the same backend server? best regardsMartin
I am having a problem running an automation to backup my computer. I want to send the backup to a sftp server of a remote branch, connected to the fortigate equipment from which I make the backup, and it is as if it did not arrive. If I do a ping it arrives, but I have to specify the source. Does anyone have any idea how I can fix it?The traffic and routes are allowed on both sides. But when I launch the "execute backup" it doesn't arrive. When pinging I have to add the source option to allow the traffic. Packet Trace #7,2024/08/06 15:59:27,"vd-root:0 received a packet(proto=6, 181.14.198.42:6817->10.1.4.121:22) tun_id=0.0.0.0 from local. flag [S], seq 4203643946, ack 0, win 65535"Packet Trace #7,2024/08/06 15:59:27,"Find an existing session, id-060b7b91, original direction"Packet Trace #7,2024/08/06 15:59:27,"enter IPSec interface VPN_IPSec1, tun_id=0.0.0.0"Packet Trace #7,2024/08/06 15:59:27,output to IPSec tunnel VPN_IPSec1 vrf 0Packet Trace #7,2024/08/06 15:59:27,"No matchi
compañeros buenos dÃas, soy nuevo en el Foro. Les comento que estamos integrando la VPN SSL con 2FA por medio de FSSO contra el directorio activo de AZURE, de momento todo conecta de manera correcta pero el cliente final me hace una consulta quiere saber si hay alguna forma de bloquear el forticlient para que el usuario final no puede editar la configuración la VPN debido que si desmarcan la opción Habilite el inicio de sesión único (SSO) para el túnel VPN puede saltarse la doble autenticación, se que quizás es mas de sistema operativo pero quisiera saber si alguno ha tenido la oportunidad de aplicar esto o alguna potra alternativa para que los usuarios no se salte el 2FA contra azure. quedo atento a sus comentarios
My policies are based on AD groups. I assume this screen is trying to authenticate me before I open a browser window but I can't make it load properly. I have the necessary certificates installed, if I try to browse a webpage I already get a username and password prompt and can authenticate and browse without problem. But this screen keeps popping up until I open a browser and authenticate. I have set the auth portal to my fw address, installed wildcard certificate that my fw uses and also the Fortigate's certificate for SSL check and I am not getting any SSL errors at all. What am I missing? This is probably a silly rookie question, I am sorry. Any help is appreciated!
Hello everyone! I'm trying to trace packets from one client. I've done it in the past successfully using the following command:diagnose debug flow filter addr x.x.x.xdiagnose debug flow trace start xdiagnose debug enable However, it seems like I am unable to trace packets from a host located on a wifi vlan, from an SSID in tunnel mode. We have a fortigate 101F. Any idea how I can make it work? Is there another CLI command I can use to track packets from such host? I read something about hardware-accelerated packets not being captured by this command, but I don't really know how to see whether these are considered hardware accelerated packets or not. Wishing you a good day!
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.