Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I hope this message finds you well.We have recently experienced an increase in the number of users on ournetwork. Initially, when we purchased our FortiGate 60F, we had around27 users, and the device has been performing well for our needs.However, our user base has now grown to approximately 90 users.Given this increase, could you please advise if the FortiGate 60F canhandle this number of users effectively? If the FortiGate 60F may notbe sufficient for our current user load, could you recommend anappropriate FortiGate model that would better accommodate our needs?We would appreciate any guidance or recommendations you can provide toensure our network remains secure and performs optimally.Thank you for your assistance.Best regards,Waleed FarmanNetwork & Cyber Security EngineerPH# 0966569152794Email: alamw611@gmail.com
I have an IPsec VPN tunnel that has an address range of over 200 addresses, and currently there are 60 active dial up connections. However I'm seeing all those connections are using addresses at the upper end of the range, and some users are failing to connect (debug shows "could not allocate IPv4 address"). So even though my IKE gateway list has only 60 instances, I suspect the previously used addresses aren't being put back into the pool . Does anyone know how to see available addresses for an IPsec tunnel?
Hello! I accessed it normally until this error started appearing. What should I do? Can anyone help? Thank you!
Hello, while trying to activate my fortigate VM license 7.2.3 that is running on Vmware I get the following Error:However when trying to execute a ping to Forticare domain I get a response. Thank you for the help !
Hi Community I have issues with member ports of an LACP on one of our managed FortiSwitcheThe setup is:SW1 and SW2 are configured with MCLAGThe LACP from SW1 and SW2 towards SW3 has MCLAG enabled set.I have verifyed MCLAG consistensy on SW1 and SW2 with:'diagnose switch-controller switch-info mclag peer-consistency-check 'Everything is fine from that point of view. The links towards SW3 is the ISL, and the LACP is auto configured when the switch joined.I use 1Gbps SFP fiber optic modules. My issue is, that one of the ports on SW3 is in suspended modePort 49 = upPort 50 = suspended I can't seem to fine any documents or articles on the web how to get closer to the root cause.I have used the 'get switch lldp neighbors-summary' on all 3 switches, and they are able to detect each other.I have tried changing the speed settings from (default) Auto-module, 1000full and 1000auto but this changes nothing. 'execute log display' on the switch doesn't give me anything, othe
Hi, I would like to know if there is a command to find the SSH version running on my Fortigate.
I have 40f. I want to connect 40f between switch1 for 40f (lan1) and switch2 for 40f(lan2). Because I allow some IP address to network switch1 and deny unspecific IP address. How to method ? Thank you
d
Hello everyone, when trying to create a new FortiClient Installer in FortiClient EMS 7.4 it to only get the option to "create installer config file" or to "upload packaged installers". Shouldn't there be an option to select / create new installation files?
Hi All, My boss has asked to me is it possible to accessing proxy server via public IP or FQDN which published to public?The goals is he want to use proxy from internet while out of office.I have suggest to use PAC for another option but he asked for first option possibility. Can you guys help me for the solution like this is possible or do you have alternate solution to achieve the goals?FortiProxy FortiGate
hi , can anyone please advise what is the default tcp handshake timeout value? I know the default session time out value is 3600 sec. thanks in advance!
I am setting up a Hub and Spoke ADVPN with BGP. The VPN tunnel itself work well. I can ping both way within the tunnel. However, a BGP routing cannot be not established unless I created a neighbor instead of a neighbor group in my Hub BGP settings. The Hub BGP settings even worked with a neighbor alone and without a neighbor group.Hub: FortiGate 60F FW: 7.2.8Spoke: FortiGate 40F FW: 7.2.8 Hub BGP (working):config router bgp set as 65000 set ibgp-multipath enable set additional-path enable config neighbor edit "10.0.61.4" set soft-reconfiguration enable set remote-as 65000 set route-reflector-client enable next &n
In this video, we delve into the intricacies of device profiling rules within FortiNAC, showcasing how to effectively identify, classify, and manage devices on your network. Learn how to: Set up and configure profiling rules.Ensure accurate device classification.Enhance your network security with automated device management. Fortinac Demo IV: Device Profiling rules https://youtu.be/mKXSWd2kxJk
Buenas tardes.En mi ayuntameinto tenemos contratado un servivio Fortigate, y utilizamos forticlient para conectar con la VPN corporativa. El caso es que la ultima version del ejecutable Forticlient VPN da problemas con algunos sistemas operativos windows, pues se queda intentando conectar y no hace nada, y quisiera poder acceder a otras versiones anteriores para probar aquellas que funcionen mejor con los usuarios que lo neceitan.Donde puedo obetenr esas versiones???
HelloHow can I find the general availability dates of the different FortiWeb HW models?E.g.: FWB 400F and others.
Hello Dears I am trying to add a route map on BGP out filter as below :network 1 : 100.68.0.10/32network 2 : 100.68.0.12/32network 3 : 100.65.0.144/28network 4 : 100.65.0.226/32it's allowing only /32 networks but the /28 network is not announcing to neighbor take in mind all 4 networks are static route redistributedand also I am trying to filter the out network to the neibhour but it is not working using route map and access-list Bests
helloI am trying to connect to the VPN but any user that I enter stays connected, I have already checked the users and they are functional, the network is free, it is not under any corporate domain, what can I do?the version that I installed is the one from the page, I am using Windows.
We are wondering if there is a way to display the Comments for a rule on the Firewall Policy screen?
Hello everyone, We installed Forticlient on multiple machines and I have recently been getting BSODs on some of them. They all points to Fortiproxy sending bad arguments/parameters to NETIO.sys. The machine here is using Windows 11 22H2, and the Forticlient version at the time was 7.0.11. Here's the stack from the minidump (happens in process Fortiproxy) : STACK_TEXT: Spoiler (Highlight to read)fffff904`caa2ea40 fffff807`7110992b : ffff940e`d4ba0014 fffff800`7a70a000 ffff940e`00000002 ffff940e`f4dd0320 : NETIO!StreamProcessCallout+0x273fffff904`caa2eb70 fffff807`711089dd : 00000000`00000014 ffff940e`f4dd0320 ffff940e`eb816d00 fffff904`caa2f220 : NETIO!ProcessCallout+0xa4bfffff904`caa2ecf0 fffff807`711076ee : 00000000`00000000 fffff904`caa2ef20 00000000`00000001 00000000`00000000 : NETIO!ArbitrateAndEnforce+0x59dfffff90
Hey All, Is it possible to update the Internet Service Database manually, without TFTP'ing or FTP'ing the file onto the Fortigate?I have the file downloaded locally on my Win11 PC and have local access to the FW etc? Thanks,
Hello everyone, I'm facing some security alerts in the software (here I would put the site's name) flagged on the website www.virus.total.com and would like to understand better how to distinguish between legitimate 'alerts' and 'false positives'.Could someone explain to me what criteria are used to determine if an alert is genuine or if it might be a false positive?Also, what are the best practices for handling these alerts without compromising the security of my system, and what are the direct channels for contacting for clarification, alert removal, or for engaging services related to this issue?Thank you for your help!
Hello,Can we use Azure AD as source on firewall rule, and make the log by username also rather than using source IP?
Hello, I have 2 branches that have 3 links each (this due to the instability of the ISPs). In both branches I have the same 3 ISPs. 2 of these ISPs do not offer a public IP, but rather an IP from their LAN (CGNAT), I want to connect these branches via VPN through these ISPs, I talked to the carriers and there is no way they forward a port to my branches. I read in a similar question that this can be solved using a hub-to-spoke VPN, placing the hub in some cloud or site with a fixed IP and making my 2 branches spokes. is there a tutorial on how to do this? the services i want to comunicate are: voice, BD´s, and web internal servers
We have a FortiEMS 7.4 and we want to expose RPC ports through the ZTNA.For what I have read so far there is only possibility to define single port per ZTNA destination rule.The problem is that by specification RPC uses:- TCP 135- Dynamic TCP range 49152-65535. How to make the dynamic range accessible through the ZTNA?On the FortiGate site it is OK, but on the client site when we try to create destination rule like:Server: 49152-65535The server is no longer resolved through ZTNA and no connection can be processed by it.
Hi everyone, I want to set a different time server than the one provided from Fortinet. I have run diagnose sys ntp status, and have found the synchronisation status set to "no". I have read this is a common issue and want to set a different time server for my Fortigate but I still get the synchronisation status error. The NTP server I want to use uses a hostname and has no static IP address. I have tried to use the guide posted in another thread but it has not worked for me so far (https://community.fortinet.com/t5/FortiGate/Technical-Tip-An-alternate-way-to-sync-the-NTP-server-to-avoid/ta-p/280309). Does anyone know how may I fix this issue? P. S. Why is synchronisation with Fortinet NTP server set to "no" despite time being accurate in the GUI?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.