Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
FOS 7.4.3I have a client trying to use passive mode for FTP. This mode uses many ports, not just port 20/21.Is there a Service on the Fortinet that allows FTP ALG? Currently we have this open to any ports TIA :)
Located this, in the docs regardng FortiProxy."Application control uses IPS protocol decoders that can analyze network traffic to detect application traffic even if the traffic uses nonstandard ports or protocols."I am assuming that when I have an IPS sensor configured that specifies, for example, the SSH protocol, it does not care what port the traffic is using. But inspects the traffic to identify the SSH protocol.Is there somewhere in the docs this is noted, for more than FortiProxy?
Hi there, Guys I am trying to set up a firewall into a VRRP. Currently I have only configured one firewall and given a priority of 255. When I see the status of the firewall it says it is a backup. The priority is 255 so I assume is should be a master. Am i missing anything ? FortiGate-100F # get router info vrrpInterface: x2, primary IP address: 10.108.0.2UseVMAC: 1, SoftSW: 0, EmacVlan: 0 BrPortIdx: 0, PromiscCount: 0HA mode: primary (0:0:1) VRRP primary number: 0VRID: 1 verion: 2vrip: 10.108.0.1, priority: 255 (255,20), state: BACKUPadv_interval: 5, preempt: 1, ignore_dft: 0 start_time: 10primary_adv_interval: 500, accept: 1vrmac: 00:00:5e:00:01:01vrdst: 10.50.50.109vrgrp: 100 edit "x2"set vdom "root"set ip 10.108.0.2 255.255.255.248set allowaccess ping https sshset type physicalset mediatype srset alias "Uplink to Core Switch"set vrrp-virtual-mac enableconfig vrrpedit 1set vrgrp 100set vrip 10.108.0.1set priority 255set adv-interval 5set start-time 10set vrdst 10.50.
Hello, How can I change the color scheme of the interface of my FortiMail Cloud? Under Preferences, I only have the language selection option, nothing else. Thank you for your help!
Hey.I have a couple of 231F’sI use 5Ghz on my client network nearly everywhere but obviously any mesh would need to be ideally over 5Ghz and I’ve not heard great things (for obvious reasons) about broadcasting the mesh and client ssids on the same band..So - as per the title :beaming_face_with_smiling_eyes: any hacks to change radio 3 from dedicated monitor to a broadcasting AP which then could be used for mesh backhaul?=)
Hello All, We are working on a FortiGate upgrade for a customer and they have VDOMs configured on their current deployment. They are moving from a 1500D to 601F both running FortiOS 7.2.8. We have FortiConverter and have used the application to map all previous interfaces to new interfaces on the 601F. When attempting to restore the converted configuration onto the default configured 601Fs we receive the following errors in diagnose debug config-error-log read:>>> "config" "vdom" @ 12398:command parse error (error -61)>>> "config" "global" @ 12423:command parse error (error -61)>>> "config" "vdom" @ 23614:command parse error (error -61) These errors correspond to the places in the config where after multi-vdom mode is enabled, config vdom is used to initially create the vdoms, then config global is used to begin the global configurations as follows:config vdom edit rootnextedit vdom1nextedit vdom2nextend config globalconfig system globalet
Hello, does anyone have a guide to setup IPSEC tunnels to Azure while using SD-WAN?I had my tunnel to Azure working fine. Added a 2nd backup internet line and switched over to SD-WAN and now I can't get it to connect properly. I can get traffic from Azure to my site but not from my site to Azure.
Good day, I am trying to create a firewall policy on my FortiGate 7.* from the SSL-VPN interface to the LAN interface to block certain counties, I have set an Address group with the GEO locations but the source keeps saying "One User or Group is required", I have an Active Directory group set up to only allow users in this group to use the VPN can I add this? or will adding this group means these users and the GEO locations will be blocked?
I made a configuration to receive an e-mail message when my link goes down, but I would like to know which link went down, I'm using event 20099, I tried to configure event 20090 but I don't receive an e-mail.Is there any way to receive the name of the dropped link or interface?
I am trying to migrate from FortiGate 400E version 6.4.6 to FortiGate 600F version 7.2.6, but when migrating the Access Points, I see that it appears as a 'VAP switch'. Does this option change when it updates?
On a brand new deployment, I would like to start deploying web filtering. When applying the custom filter to the outbound policy, this requires SSL Inspection. Whether "Certificate-Inspection" or "deep-inspection" require browsers to have at certificate installedAs a test, I have manually installed on my browser the default "Fortinet_CA_SSL"Is the installation of the Certificate really necessary?Would it be a best practice to push this certificate to everyone or shall I create a new one? We do not have a CA server
Hi I have this scenario ,whereby some user`s are prompted to "sign-in to network "a number of times immediately they connect to the LAN. while others are not affected ,it works automatically without any user interaction.All The PC`s are windows 11 Laptop with the patch version 22H3. I have checked all the pc`s have the same certificates and also have the option of "verify server identity under Protected EAP Properties".Any ideas on how i can solve this?
Just playing around with a FAP 231F.Latest firmware 7.2 connected to a FGT running 7.2.8Currently have Orbi 6 mesh as a WiFi network - running in bridge. FGT is default gateway to the network.When on WiFi through the Orbi, comfortably get 520Mbps download with 100 up. Matches what I’m paying from my ISP.. ish.Anyway. Taking the Orbi out and replacing with the FAP - wow.It will not breach 190Mb down at all. Running in bridge - again just directly replacing the port that the Orbi plumbs into.Any tips? I cannot believe it’s that bad. My client has signal strength of -40dbm. I’m pretty much next to it.Download tests are fully comparative. Same download server tested against. Same port, same cabling, same device tested from, same distance away for each test.Put simply, everything is equal.Happy to share my wtp profile if needed but it’s fairly left to defaults. Experimented turning radios on and off, keeping radio 3 with WIDS ap scan..Power and radio are not auto - set to 100%.Cannot work t
Version: 7.4.0.0.427 Need help finding where to disable when a user is disabled in AD the host(s) that is registered to said user has all of its adapters disabled. I'm not seeing Mappings to cause this action, hoping I can be pointed in the right direction. Thank you
hello is there any way I can retrieve back user profile of super admin I accidentally change it to prof_admin thanks
Dear Community, I am facing issue that when I create a policy from LAN to WAN and my all traffic is passing without issue, but when I want to block certain countries and IP from all the port like DMZ, LAN (inside to WAN) it's not blocking at all in the Any to WAN policy, I am confused about any to wan and Lan to wan that which policy gets priority. FortiGate #policy #600e
We're going to be replacing our soon to be EOL 1048D pair, will config info be compatible with 1048E? I'm wondering if that's going to be a reasonable way (I still have more to research) to start looking at migrating to the new hardware. I'm not a network engineer so go easy on me please!
Hello everyone, We are using a Fortigate 120g. However, we can't open any website. Ping and DNS works on the client and on the fortigate and the packets are forwarded on the fortigate without dropping any packets. When we connect directly to the Fortigate 120g, we can access the Internet and open web pages without any delay. When we disconnect the Fortigate 120g and connect our old firewall, everything works fine right away. What we tried:Configuring port speed 1000Full on our Cisco CL9200 switch and on the Fortigate 120g.Do you have any idea how we can fix the problem? Thank you in advance! Best regards
Hello,I have a problem with a suspected hacking attack because someone created a user bobby tables in our webapp.We have IPS+WAF+DPI however WAF is lightly configured and only blocks exploits and trojans but everything else is monitor because otherwise we cannot create news on our webpage because WAF would block it.Can you recommend changes for fortigate in my config? I have enabled this 2 Security Profiles together with Full DPI: config ips sensor edit "IPS-LinuxServer" set comment "Test" set scan-botnet-connections block config entries edit 1 set location server set severity medium high critical set os Linux set status enable set action block next end next end And this WAF Profile: config waf profile edit "linux-waf" config signature config main-class 100000000 set action bl
Unable to add my active ISP WAN interface as SD_WAN Member to a SD_ZONE , the interface does not show up when adding it to a SD-WAN zone. This is for my home lab, I am running forti os 6.4.5. my ISP WAN 2 is down. cable is connected, because i only have 1 ISP connection, but i still assigned IP to it.
Hello,I followed this KB: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Local-user-authentication/ta-p/190084My goal was to authenticate "website-admin" users for our backend webservers so that they can do more then a normal guest visitor could do. The difference I wanted were 2 firewall policies one for guests and one for authenticated-users where for example IPS+WAF rules were more strict for guests then for authenticated users.My problem is when enabling Captive Portal I could authenticate with my backend user and traffic hit the right policy but guests who MUST NOT authenticate did also had to authenticate which is not possible for them because they should not have any credentials. How can I hide the auth page and only auth users which wanted to be authenticated? All other should be able to access all the webservers regularly.
Hello, - I opened all these ports on endpoint device 135, 139, 137, 445 TCP. - When I click "Test Workstation" button, this massage appears "failed to do workstation check through WMI" + "Unkown workstation state". - But if I open all TCP ports on endpoint, the test works normally. - What are the TCP ports should I open on endpoint device?
Good Afternoon, Some clients showed up problems to connect to the vpn(SSL-VPN), the computer is windows 10 pro 22h2 build 19045. and always stay connecting and don't show the connectiong percent before connection estabelish. I test in android and its work with client credential. i already Repair the application and also uninstalled it, and re-installed. but no success, not even with my Credentials. Any suggestion?
All, Did you experience intermittent connection when enabling IPSec FG-FG as a backup route when MPLS is also up? Remote Site:MPLS connection is the primary using static route w/ 10 AD and priority of 0While the IPSec is the secondary connection w/ 10 AD and priority of 100 when I enable the IPSec connection we always encountered slow response/intermittent traffic going to HQ.Seem the traffic flow is confuse on where to send(should be on MPLS or IPSEC). Supposedly the traffic should always go thru MPLS, since this circuit is not down. Hope to find solution on this. Thank you
hi hello there, i have questing about NAT, i have public ip x.x.x.x/28 and y.y.y.y/29. and i want some of the public ip is NAT to my private ip. for example i want to x.x.x.5 NAT to 192.168.100.50 or y.y.y.5 NAT to 192.168.100.51. and maybe add some port forwarding so service in that server can expose to internet, let say port 2222 from public ip forward to port 22 private ip. currently i have configure my fortigate with this, but still no luck and i realise that, i have /28 public ip. but only 1 ip that i can ping from internet, the one that i can ping is my public ip in interface wan1, why the rest of 13 public ip cannot ping from internet ?cus i have experience with mikrotik and i can do ping to all my 14 ip subnet /28. anyone can help me?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.