Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I just installed FortiClient EMS 7.4.0 on Ubuntu 22.0.4 according to the installation doc. All the running services check out like they're supposed to. The doc says to double-click the FortiClient Endpoint Management Server icon to fire up the gui so I can configure https access, but there is no icon to click, nor does the system have anything for forticlient in the applications menu. Anyone have a workaround for this or tell me the bin the icon is supposed to point to?
FortiGate, Firewall cannot pull users while doing SSL-VPN. It is taken in the group from all other user/groups. The user portal is actually the current users of the portal, Users/group is mapped to the port.
Hi We currently use FortiClient with FW firmware version 6.0 and are able to manage compliance profiles.I know that firmware above 6.0 does not support FortiClient and EMS server is required to manage them.Is this still the case with FortiOS 7.0? Thanks in advanceDawid
Hello team, I noticed form the log & Report -> Application Control screen that one of the machines is being used for Cryptocurrency mining. See attached screenshot. How do I block this traffic? I have P2P enabled because of the HikVision CCTV service that they provide to be able to view the cameras from outside the network. Need your help please.
Hello, I have a client running Forticlient SSL VPN over Verizon Jetpacks. We have seen intermittent connection issues with multiple users, multiple laptops and Jetpacks in different locations. The problem is the initial connection of the VPN. Sometimes it works, and then literally 2 minutes later it will fail (and vice versa). Out of 20 connection attempts, it failed on 12 and was successful on 8. Over the hour that I was investigating the issues, I was connected to the laptop via splashtop remote desktop and never once lost a connection. A continuous ping to 8.8.8.8 never dropped a packet. That being the case, I do not believe that the Cellular hotspot was in any way responsible. I verifies that VPN passthrough was enabled on the jetpack. Additionally, from a wired internet connection from the same machine, the connection attempts were 100 % successful. I am using the Static IP of the Fortigate 50E firewall in the connection s
Hi, Is there a way to map static IP for each VPN user. And can we restrict VPN users to have a single VPN session per user. This, https://kb.fortinet.com/kb/documentLink.do?externalID=FD37351, does not seem to work on version 6.0.
 Does anyone ever get a popup that just counts down and to nothing and you cannot connect to any ztna destinations. I normally get the popup once, do my SAML authentication, along with MFA against the fortiauthenticator. Then everything works and I am good. Occasionally i get this timer that just counts down until 0.
Hello team!!! I hope you are fine!!We have here, 2 kind of VPN users trying to access different resources on different VLANs (Behind the same Fortigate), we need, for example, the following:* User Group 1: Can access LAN but not DMZ* User Group 2: Can access DMZ but not LAN We have 3 WANs, the idea is create one VPN for each WAN. We choose L2TP/IPsec VPN, because this dont require to install FortiClient in each Client. All the test were done with L2TP/IPsec VPN (Using the option "Windows Native" in the wizard)What we tried in first place, is to create 2 VPNs for each WAN, one for each user group (6 VPNs), but this seems that the Fortigate, only is listenning for one VPN in each WAN.I deleted all the VPNs and references (Including addresses)I created again the VPNs for each WAN, just for "User Group 1"I could connect and access the network through the VPN, everything was fineI added the 3 VPNs for "User Group 2" (1 for each WAN)I coud NOT connect, wrong credentialsI
Using FAC for Radius/EAP-TLS, backend is Active Directory. My LDAP remote user synch rule seems to be working, except for the fact that my a user's certificate binding is not coming through. The user does have a cert issued. Any ideas - misconfiguration on FAC or my domain controller ?
I'm trying to test authentication by using Machine certs instead of User certs. When I configure the windows supplicant to use "User or Computer" OR "User" I can authenticate. If I force the setting to "Computer" it fails. Both the computer and user certs are valid and signed by same CA. I must be missing something in the Radius server config. Any ideas ?
Now that I have all my users using SSL VPN similar to how our old Cisco AnyConnect was working I would like to start learning and then implementing ZTNA to better control the users. My EMS Cloud, FortiClients and FortiGate all use ADFS for SAML. Is there anyway to setup ZTNA such that the groups the user is in controls their access to devices? For example. If I have a user in Dev group I want that user to be able to SSH to a CIDR address list. I also want them to be able to connect to HTTPS to another CIDR address list. Then I have a group like AppSupport that should only HTTPs to 2 different CIDR address groups. Then I might have a third user which has both AD groups (Dev and AppSupport) so they should be able to access the combined CIDRs. Is this at all possible???What
Hi, I want to configure a SSL VPN with a Smartcard authentication.Is this possible? Fortigate Version: 6.4.8 build1914 FortiClient version: 6.4.6.1658 RegardsChris
Hi, We have currently 20 FGT40F branches connecting via VPN IPSEC with the FGT1100E HQ.Users on the branches connect to a Cluster-RDS via RDP and uses the services/servers from the HQ network. The issue we have is that the RDP sessions are dropping randomly during the day (sometime just once or twice a day) on any branch and sometimes on random hosts. Users on HQ that connects also to the Cluster-RDS never had any complain about connection being dropped, so we assumed that the servers are OK. We performed several troubleshooting steps to try and solve this issue but the problem persists. We took 2 branches to test configurations and if they worked we'd replicate to all the others. So far we tried:- set auto-asic-offload disable- set npu-offload disable- VPN IPSEC: AES-128 and SHA-1 Lifetime:28800s (on both phases)- system session-ttl for RDP: 28800s Any help would be appreciated.Thanks
FortiGate Cluster in A-P.I noticed that there is a mismatch in vpn.ipsec.phase1-interfaces on FW02. I tried to delete the tunnel in CLI FW02 but encountered an error.FG60FFW02 (phase1-interface)# delete fg-ipsec-101Can not delete a static table entryCommand fail. Return code -61 Tried also re-calculated checksums but issue persists. Any recommendations to make this works is highly appreciated. TIA :)
Hello Team, So i have a query regarding IPSec VPN Tunnel over BGP. There is BGP on the both side i.e, Remote and Local Site. whereas, the remote site has requested to establish IPSec VPN over BGP. But the problem arise when in the Local site BGP is announced in the Cisco Router. Do we need to configure the VPN in the VPN Firewall or Cisco Router???? Please share us the solution.Thank you
Cluster Synchronization: FortiGate HA clusters rely on synchronization to ensure that all units have the same configuration, firmware version, and operational state.Out-of-Sync Symptoms: This issue may manifest as inconsistent configurations, failing failovers, or operational discrepancies between cluster members.
A while back I found a really good Technical Tip article on setting up Fortimanager for SSO with ADFS SAML with the FortiManger in SP mode. I am totally unable to find it anymore. Does anyone know of any good Tech Tip articles for this or other docs besides the standard Fortinet junk manual?
We have a production Forti100F ver 7.4.4, we bought another Forti100F, and try to set up HA in configuration mode only.The secondary Fortigate has only management ip interface set up.We issue the basic commands for setting the HA as in the admin guide, but never synched.Are there some prerequisites we are missing, or thiw mode does not work ?Thanks in advanced
Hi Guys, I hope can help me find a solution for the issue that I am having while using Fortigate email two-factor authentication in a IPSEC VPN. The problem is when a user clicks on connect in Forticlient the PC loses internet connectivity and FortClient stays waiting for the email code that was sent to the user email address, but the user can access their email because they are without internet connectivity on the PC.I am using slipt tunnelling, this does not make sense, because they need the token to connect to VPN but they don't have internet connectivity until they log into the VPN.Testing the access getting the token using my mobile phone, the VPN connection works how it should, and it does not redirect the default gateway to the VPN, only the slipt tunnelling routes are added to the PC.I hope someone can help with this inconvenient problem.Thanks for your help.
Hi,I am currently testing SSL VPN multi-factor authentication. Since we already have PKI and smart cards running in the Microsoft AD environment, I followed the steps in the guide:https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/266506/ssl-vpn-with-certificate-authenticationEverything executed smoothly, but I noticed a peculiar authentication mechanism. Fortigate's certificate multi-factor authentication matches if the account subject string on Fortigate matches part of the information in the certificate subject. I believe this is not a secure and rigorous matching method. The PKI user's subject should fully match the certificate subject. It can be observed that test3-jason was initially matched by jason's subject, leading to subsequent authentication failure.How can I avoid the following situation?Additionally, can Fortigate's certificate authentication authenticate the subject alternative name in the certificate?FortiGate The following is the ve
Hi FortiClient EMS adminsFCT EMS 7.0.13.When deploying client from EMS I get error 150 on the EMS logs.Windows events on client show 30000 ms timeout waiting for FortiClient Install Service.I checked all below prerequisites are ok.https://community.fortinet.com/t5/FortiClient/Troubleshooting-Tip-FortiClient-Deployment-Error-150-for/ta-p/260271Any idea?
I need to find a way to on mass or via policy enable the Forticlient Browser extension in Incognito mode. It is deployed by the EMS intaller, but not for Incognito mode. The user has to manually enable or can manually disable that currently. There does not seem to be a way in the EMS server or Intune to do that.
FG is the DHCP server. FG DHCP is issuing IP correctly and we can see the IP. The problem is we cant see the IP address in wiindows DNS so we cant do an nslookup or resolve the PC name to IP.I want to know if there is a config so that FG relay the DHCP info to windows DNS. This is the article I'm looking right now. https://community.fortinet.com/t5/FortiGate/Technical-TIP-Different-options-of-configuring-DNS-server-on/ta-p/278967 TIA :)
Hi All,I am new to Fortigate, when I logged in to the GUI recently, and I saw that Forticare period is about to expirebut it also shows in Hardware version: return to factory and I did not understand what that meansif I did not renew before expiration, will I be able to keep using the device?my device is 40FFortiGuard
Site to Site IPSec VPN Gateway using two Fortigates. Branch has an 80E Firmware v6.0.2, Headquarters has a 300D Firmware v5.6.6. Problem: End users reporting very slow file access from the fileservers located at headquarters.File transfer speeds between the two sites averages 425 Kbps for Data only.Should I expect better file transfer speeds between the two sites? Note: VoIP works great. Speeds out to the Internet are great.VoIP and Data are configured to use the same port on the Fortigate 80E. I'm using Windows Explorer and copying a file from the (Windows 2016 Server) fileserver to the desktop (combo of Win7 and Win10 pro) to test the file transfer speeds. Iperf between the two sites using the default settings for TCP. I didn't change the Window size. Average speed was between 2 to 3 Mbps. Ftp'ed between the two sites average speed was 1.5 to 2.0Mbps.Distance between Branch and HQ 34 miles. Branch has 30 pc's and 30 VoIP phones. 30 Employees, rarely ha
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.