Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Not an issue, but had a major decrease in firewall CPU utilization after upgrading from 7.0.14 to 7.2.8 on a Fortigate 200E Firewall. It was averaging 50 - 60% during peak hours (9AM - 8PM EST) and typically has 30,000 sessions during this time (majority short lived). After upgrading, the CPU utilization is down to 2-4% with the same number of sessions. Memory usage has stayed steady, around 40% throughout the day. I guess it's a good thing, but the dramatic decrease is a little weird. Has anyone experienced something similar? I had to double check if after the upgrade our Network Provider made the previous passive firewall the active, but that is not the case. It just seeps like a very dramatic drop, to the point where I'm concerned there may have been a misconfiguration before or misconfiguration now....
Hi sir, A simple question, after I execute a command "execute shutdown" from RJ console, the FortiGate will go into standby mode, and at this moment, the RJ console and all Ethernet ports are without function, how can I wake the FortiGate up remotely? Can the FortiGate be woken up only by AC off then on it, since it does not have a power button? Thanks,Jacky
hi,i just want to confirm if i'm doing it right when creating a new FW policy section in fortimanager.do i right-click on the specific policy, in this case in want under sequence 10, then choose "add section"?is this the same as click on the policy sequence 10 > section > + add?
Does FortiGate BGP support the use of both 16 and 32 bit AS numbers? I've been looking at the FortiGate 7.4.2 admin guide and not seeing anything definite there to answer my question. Bill
I'm using FortiAnalyzer 7.4.2 and trying to exclude logs from certain IP addresses from being processed by the Event Handler. These IP addresses in question are from our unsecure guest network and we don't need to have them reporting anything through the Analyzer. The basic firewall is still sending a ton of logs to the Analyzer, but I want to filter that out. The Event Handler system does not seem to have a method of doing this. It seems only capable of turning logs into events and cannot simply ignore the log. And I'm very hesitant to start messing with the Log Parser. Is there any method of doing this aside from the Log Parser? And if I did have to go down that route, would I need to edit the FortiAnalyzer Log Parser? Or is the FortiAnalyzer Log Parser used for forwarding logs to a SIEM after FAZ has finished with them? A side question, does FAZ use the log forwarding system to send incident details to a SIEM?&nbs
Let's say 1 user ABC has connected wireless (192.168.1.100) and wired (172.16.1.100), at this point no issue for FSSO, but once the user disconnected from wired, and use wireless to continue, then FSSO will not able detect user ABC. (it happens randomly, sometime no issue or sometime happened after 1 or 2 hour) Even i waited for 5 minutes but still nothing happen, anything that i can change to prevent this? The only method now i have to lock my laptop/pc then login again, after FSSO will immediate working...the FSSO agent installed on a joined domain server (not AD server), pull user info from AD server and the FSSO setting all default included the interval time settings.
I've got a strange problem that crops up. I think the issue is that people get a new ip address without re-logging on and the FSSO/fortigate gets confused. Situation:multiple sites, different subnet on each site. Windows laptops, Aruba wireless, Fortigate with FSSO authenticated AD groups, Fortigate policies based on AD groups. Person logs into their windows laptop at site A, successfully connects to internet through Fortigate. Closes the lid, drives to site B, opens the lid (gets a new IP address from DHCP.) After coming out of sleep, the laptop has internal network access (i.e. to local file servers) but nothing through the Fortigate. The Fortigate logs show an unauthenticated person at the new IP address trying to get through. I always have to tell them to reboot the laptop and then all is ok. I have the "IP address change verify interval (seconds)" set to 60 in the Single Sign On Agent config screen even though I doubt it is needed because the documen
How can we configure ACLs in FGT to block local traffic.
Hi, On our FortiManager (5.4.1 VM) we have an ADOM defined with several VDOM's, each with its own firewall policy package.These policy packages have already hundreds of policies. Right now we are in need to update few parameters of every single policy in all policy packages. There is no way we can do this manually in GUI policy by policy. We could grab the whole configuration of FortiManager or directly the FortiGates in a text form and do a search/replace and then re-apply it. But I don't find this to be the smartest way to change configuration. I believe the ideal approach is to use a script.CLI scripts do not make sense because there is no way to use variables, loops, if/else statements etc. in a CLI script. So I turned my attention to TCL scripts. I have enabled them for FortiManager.I am actually able to write a TCL script which should do exactly what I need the script to do. There are nice examples in the administration guide or here in the forum. M
Hi there, I recently bought a new PC and am trying to setup a VPN connection to my workplace so I can remote into my office computer. However, upon installing Forticlient as per my workplace's instructions, I am unable to connect to their server and am receiving message "Unable to establish the VPN connection. The VPN server may be unreachable. (-5053)." I have a ticket open with our IT department but they're taking a while to respond, so I figured I'd post something here to see if there's any troubleshooting I can do on my end to resolve this ahead of their investigation. For reference, I have noticed and tried the following: 1) I have tried installing the version of Forticlient on my workplace website (v. 7.2.3.0929), as well as the latest version off the website directly. My workplace produces the error message and the latest version does not do anything (it resets all the credentials and doesn't attempt to connect at all)2) Reinstalled several times using both
Guys, I need some help.I set my Firewall 60E to update yesterday and it hasn't come back. Until now, it only has the power LED on, but it doesn't start.Any tips?
Hello! I got a FortiWLC-50D running 8.6-1 build-7 with 17 Fortinet AP832 access point. No problem with that. I just jot some Meru AP832 access points that I want to add.They all are running on 6.1-3-5 When I try to update them usingupgrade ap sameThe upgrade process hangs at "Reading File". Then after 2 minutes the access point reboots but stays at 6.1-3-5. What can I do to upgrade those APs? Thank you in advance
Hi everyone, Is the above question possible? Only command I found on the CLI manual seems to apply only to the ha interface: config system haset gratuitous-arps disable I need to disable gratuitous-arps on all interfaces.
Dear Concern, There is a website that I checked in 'Web Rating Override', and its category is 'malicious website'. opening. Why? I have blocked the 'malicious website' category in the 'DNS Filter' and 'FortiGuard Category Based Filter'. Yet, the website is still opening. Why? How can I troubleshoot or check.
Good morning: I have a policy that blocks social networks, I block them in web filter and application control but I have to except developers.facebook. com but I couldn't do it. I excepted it in deep inspection and in web filter I put that address to exclude it but it still blocks me. How can I do? Thank you so much
Dipping my toes in the Fortinet world looking to replace some aging phyiscal LBs with virtualised FortiADC. I've got a pair built with aim to setup HA. But stuck at first hurdle trying to setup admin auth using LDAP for rest of the team. I've added 2 Active Directory domain controllers under User Authentication > Remote Server these are set to use Port (389), CN (sAMAccountName), Bind type (Regular), User DN (CN of the service account used to bind to LDAP), Secure connection (StartTLS) and we have Group Authentication checked Group type (WindowsAD) and the group DN with our admin team members added as CN. Test connectivity all works fine. Under User Authentication > User Group I've added a group "FortiAdmin" using Client Authentication (HTTP), Group type (Normal) and with members the 2 LDAP servers created above. Clearly Im missing something here as I keep getting Incorrect Username / Password when attempting to login with my AD account. I've been through
I can't open Forticlient console. IN GUI_1_error.log i find this message guimessenger 238 error failed to open shared memory. GLE=2 Could you help me please? Version 7.2.4
Hi, the subject explains everything. This morning I installed the newest update. Since then noone can start a vpn-connection. Me neither - and I am sure, that my logon is correct. And the others can't be all wrong also. Everything else works, and in the office I can logon as administrator - everything looks fine.The LDAP-Server is running, and hasn't been changed at all, not even rebootet. I rebootet the FortiGate again, just in case - didn't help. We use FortiTokens, but it is not asking for the token - already a problem with the logon. Any Ideas?
I'm working on gns3 and I wanted to use the Fortigate 7.0.15 .I installed it and tried to open it but nothing shows it keeps as the picture shows with no result. I used to use the 7.4.4 and it worked but the 7.0.15 and the 7.2.8 didn't
So far, in my entire experience with Fortinet, I’ve only seen API swagger being available in FNDN. But generally, with all of the other REST API’s I’ve worked with other than Fortinet, there will be a URL available on the API target system itself that allows clients to download the API swagger as one big file. And that swagger is always the applicable one for the current running version because it comes with the software release itself that is installed in the system. This is an important feature for the multitude of software packages that use API’s in highly sophisticated ways. Think Sailpoint, Apogee, ServiceNow etc. They all rely upon access to the current version of swagger for the current running software on the API target. Where can clients point their systems to when obtaining the current swagger that is running on?:FortiManager cloudFortiAnalyzer cloudFortiCloud (for Asset Management)FortiOs (bare metal and VM) It would be preferable that customers can use a URL
We have configured Wireless Authentication using SAML Credentials and Azure as IdPAfter enter the Credential the WIFI unable to connect. Please help us to resolve the issue. S Rajesh
Hello guys I am having troubles while trying to register one wokstation, it won't allow me to register the client, I am getting the following error:EMS Internal error. It is important to mention, this workstation is set up under a different domain controller, the computer does not belong to our domain because this is an specific case where a user out of the company need to connect to our systems. Do you think that could be the issue?, pls let me know if any other information is required.Hope you can give me a hand, it will be much appreciated.Thanks!!
Hello, I would like help with the following problem.As shown below, creating a URL Object (Policy & Object Address) is subject to the maximum limit. So, I am curious as to whether it is possible to expand the limit.Thank you so much!
Hello!I am trying to import secret with secret upload template but can't understood how to mention target because after importing it shows empty and I need manually convert it and choose right target. This target address is available in host field after importing.Anyone experience such issue and can point me with solution?
Hi, we have a Fortianalyzer that receives logs from Fortigates in differents countries with differents timezones.Is there a way to configure Fortianalyzer to see the logs received with the correspondent timezone of each equipment?The firmware version is 7.2.2 Thanks in advance FortiAnalyzer
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.