Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi due to CVE-2022-0778, I need to keep track on latest firmware release by try subscribe firmware release but it seem not working http://pub.kb.fortinet.com/rss/firmware.xmlhttps://pub.kb.fortinet.com/rss/firmware.xml anyone success subsribe
Hello FortiGate/FortiProxy admins FortiOS 7.6.0 is now released, with many new interesting features.https://docs.fortinet.com/document/fortigate/7.6.0/fortios-release-notes/743723/new-features-or-enhancements I'm listing here some of them:974984FortiOS now preserves authentication sessions even after a Firewall reboot. This feature enhances the user experience by eliminating the need for re-authentication after a Firewall reboot. 877680Enhancement to IPsec GUI. The process of creating and editing IPsec tunnels is now more logical. The wizard supports setting the IKE version for both Hub and Spoke and Site-to-Site configurations, along with other transport-related fields for Site-to-Site tunnels. Additionally, security posture tags can be added to FortiClient Remote Access tunnels. These updates aim to make the process more intuitive and efficient. 1035775Improvements to device upgrade. This enhancement streamlines the upgrade process for all supported devices, inclu
Hello, we have two Fortigate devices in different cities. There is a connection between the two. We have a local website in city ‘X’. In city ‘Y’ there is a group that has an internet ban. How can I make the local website in city ‘X’ authorised for this group. I hope I was able to explain.
Hello,By default when I assign a FortiToken mobile license to a user they receive an activation email. The user only has 1 hour to activate the license before the license has to be reassigned. 1 hour isn't long enough... Is there a way to increase the account expiration time so the user has longer to activate it?
Hello Team, I'm configuring a profile with application-based split tunnel using this reference https://docs.fortinet.com/document/forticlient/7.2.0/ems-administration-guide/234887/configuring-a-profile-with-application-based-split-tunnel First, I applied the exclusion on MS Teams from cloud apps. I observed that MS Teams "web version" was excluded however the desktop version is not. So, I'm trying to exclude the desktop version using the path method. The desktop version is the new teams which has a path like "C:\Program Files\WindowsApps\MSTeams_24165.1414.2987.41_x64__8wekyb3d8bbwe". The problem is this path differ from version to version so it may differ from machine to another. I searched for a methods like the wildcard "C:\Program Files\WindowsApps\MSTeams_*" but this method seems to be not supported by Fortinet. How can I exclude this variable path ? Thanks,Alaa ElrayesFortiClient
I don't want to keep spamming this forum, but at the moment I can't find the documentation to help me, is there a sensible course I could do to learn how to see what our Fortis are doing? Regardless. I'm using the Built-in Threat Report to see if anything had happened and, clearly, yes it has. However, it's not clear what it has happened to. Specifically Intrusion 2, udp_flood, how do I match it up to the Victim IP and the Intrusion Source IP?   Is this the right report to be using, and how can I tune it to get better or more meaningful results? I feel I'm asking silly questions that I could easily RTFM the answer. Cheers, Simon.
Hi all, new Fortigate user here. Looking at our Fortianalyzer we have the error You have exceeded your daily logs GB/day licensing limit within the last 7 days. I've been through this forum and done some Google-Fu, so far so normal. However, and I only saw this just now, the dates are totally wrong. This is where Google-Fu fails me and I call upon the experts to assist. Any ideas? Cheers, Simon.
Hi, I find the OBM feature on FortiExtender very very useful.https://docs.fortinet.com/document/fortiextender/7.4.4/admin-guide-standalone/957071/obm-management Is similar functionality in FortiOS on Fortigate available as well ? How to use it ?If not: Any chance to get this implemented in upcoming releases ? Thanks & BRFrank
HiI tried several times reading about how NAT works in Fortigate, but it doesnt work.FortiGate 60F, firmware 7.2.8 build 1693.I found many guides using "IPv4 policy", but this is not present in my "Policy & Objects" menu, I think maybe different firmware.So I create Virtual IPs I need, then I create firewall policies from wan to virtual ip.But it doesn'n works, i presume i made something wrong o I didn't do at all something that is necessary.I am new in FortiGate, coming from other manifacturer products, any help is welcome. Edit: I add some informations may help:System is in NAT mode.Gateway is a modem/router Fritz, and Fortigate is in DMZ on it.Activating https admin on wan interface, it is reachable from internet.
Hello everyone,is it a solution to manage ldap servers integrated to a fortigate, but with an account in protected users group.It seems that once the account i use to connect my fortigate and my AD servers is put in the protected users group, the fortigate cannot contact ldap servers anymore, so all the SSL VPN authentication requests fail. Thanks for your help, if you have any solution.
Hello Please can you let me know if it is possible to create multiple remote access SSL VPN Tunnels (vrf aware). I have two LAN interfaces (subnet overlap) in separate VRFs. I want 2 ssl.root interfaces so that I can add VRF information. Is this supported ? Thanks
Dear Experts, I don't understant load-balacing mode and tie break option on service configuration of SDWAN Fortigate. I think if traffic match sdwan rule and have >= 2 paths match SLA, traffic will be load balanced base on hash mode ? And so what is purpose of tie break option ? If set it to enable, the option will override load balancing option? Or tie break just only run when all paths don't meet SLA ? Thank you in advance !
Hi Team, We would like to use SSL VPN in tunnel mode only. We have disabled the web mode on portal, but some users using Forticlient are connected in ssl-web mode. After numerous session resets clients finally connect in tunnel mode. Any ideas and help finding the reason is appreciated.
Hi All, There is an office that uses FortiGate as a router.There is a site-to-site VPN tunnel between Azure and that office.The office has a modem connected to the FortiGate router with 4G connection and when their primary connection is down the router fails over to the modem. Because Site-to-Site VPN between resources in Azure and the on-prem network is vital for business apps when the FortiGate fails over to the 4G modem there should be also a VPN tunnel over that modem. When the FortiGate fails over to 4G modem it is assigned a non-routable IP address 1.XXX.XXX.XXX and for this reason DynDNS service is used to associate 1.XXX.XXX.XXX with a DNS name. Below are the screenshot of Azure side and on-prem side VPN configuration. Both Azure and FortiGate configuration for VPN over 4G were copied from working VPN configuration over primary WAN connection. If someone has experience with Azure Site-to-Site VPN over 4G pl
Good morning!I've been told that 221B units won't work with fortigate 301E. Is this true?. Is there a compatibility chart anywhere?
Dear Expert, I am searching Fortigate SD-WAN load Balancing, and I found 2 commands:1.set load-balance-mode [source-ip-based|weight-based|...]This command is under : config system sdwanAnd: 2. set load-balance [enable|disable]This command under: config service (SD-WAN rule)I don't understand what is purpose of them , and why do FortiGate SD-WAN has these 2 commands look like same ?Because, if traffic match sdw-wan rule, the command 2 will execute, right ?, and when command 1 is executed ?Thanks !
Spoiler (Highlight to read)I am having issues with latency on internal traffic from My Fortigate 100F internal lan (hardware switch) to Fortiswitch VLAN. When I put both machines on separate Fortiswitch(148F) vlans they work fine. I have an Arube 10gb switch attached to the 100F Internal lan port.I did notice that the speed of the internal lan port is set to 1000full while the vlan interface is set to 10000full. Would this affect traffic performance?I am having issues with latency on internal traffic from My Fortigate 100F internal lan (hardware switch) to Fortiswitch VLAN. When I put both machines on separate Fortiswitch(148F) vlans they work fine. I have an Arube 10gb switch attached to the 100F Internal lan port.I did notice that the speed of the internal lan port is set to 1000full while the vlan interface is set to 10000full. Would this affect traffic performance?
I am setting up an iOS IPSec VPN and followed everything in this guidehttps://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/311726/ios-device-as-dialup-clientSo far I can access the local network but only via IPs. Hostnames does not work. Clients can ping the dns server but the client can't seem to get any resolution.Is there a problem in this guide or lacking any steps? I tried to search other KB but seem to not work either.
Hello,I recently installed FortiClient on my Debian 12 system. I tried both installing the `.deb` package directly and using the repository method. While the installation process completes successfully in both cases, I'm encountering a couple of issues:1. Keytar Error with Root Access: When I try to open FortiClient VPN with root access, I receive a "keytar error" message. However, this error does not appear when I open the application with a regular user account.2. VPN Disconnects Immediately: Regardless of the user account used to open FortiClient, the VPN connects but then immediately disconnects.Has anyone else experienced these issues? Are there any known fixes or workarounds? Any guidance would be greatly appreciated.Thank you!FortiClient#
Hi Team, We are implementing proxy policy with fsso but the issue is why we need to enable lan to wan in Firewall policy when we are defining lan to wan in Explicit proxy. Will not end system which are authenticated via fsso will reach to internet if we just mention policy in explicit only. Also when we disable traffic to Wan in normal policy internet does not work.Please suggest!
In this step-by-step tutorial, we'll walk you through the process of configuring FortiAuthenticator to act as a RADIUS server for domain users, enabling secure Wi-Fi authentication. Whether you're setting up a new network or enhancing your current infrastructure, this guide will help you integrate FortiAuthenticator with your domain environment for efficient and secure Wi-Fi access.Configure FortiAuthenticator as RADIUS server for Domain users for Wifi Radius Authentication https://youtu.be/eFwBkPgz_9A
Dear Team, We have Endpoint authenticated via FortiNAC via RADIUS Local. Endpoint has Persistent Agent installed. Our purpose is to give endpoint access when their PC is compliant but we noticed that endpoint shown OFFLINE on FortiNAC after around 30-40 minutes. This offline cause endpoint compliance being failed. During that time, FNAC also mark switchport as Link Down, Not Connected while on Actual Switch , Port is still connected, Authorized by Radius, MAC Address Table shown on the switchport. Note: Endpoint has PA installed, Switch integrated with L2 Polling SNMP, RADIUS. Thank You FortiNAC
Hey All,I am having an issue with setting up VIPs to redirect incoming traffic on a FortiGate with Central NAT enabled to a remote public IP. A few months back, I had a need to change existing VIPs that mapped from public to private, so that the new mapped IP was another public IP that is not ours. I found this article, and it all worked nice a smooth from testing to deployment in production. This was on a 200F at 7.2.8 without Central NAT. The one strange thing is that I don't get any hits on the Policy Routes. Now, I have to configure the same thing on two more FortiGates, both also at 7.2.8 - one is a 200F without Central NAT and the other is a 100E with Central NAT enabled. I'm having an issue with the 100E. There is a Central NAT policy that says any>internet / src all | dest all / NAT as outgoing interface. There are three other policies that should not be affecting my traffic as they have defined interfaces and addresses that are not involved with this. The 100E has
HelloIs there a way to quickly transfer a FortiMail VM license from an existing VM to a new one without opening a CS ticket? For example is there a way to do it from the support portal?
I am setting up an office network with a FortiGate 80F (FortiOS 7.2) and am having trouble with routing. Can anyone please tell me how to configure multiple wan routing?My scenario includes the following Vlan interfaces (LAG with switch):- wan1: 1.1.1.1- wan2: 2.2.2.2- wan3: 3.3.3.3 - lan1: 192.168.1.0/24- lan2: 192.168.2.0/24- lan3: 192.168.3.0/24- lan4: 192.168.4.0/24 Goals:1. When lans connect to the internet:- lan1 → wan1- lan2 → wan2- lan3 → wan3- lan4 → wan32. Automatically change to the following priority routing if issues occur:- lan1: wan1 → wan2 → wan3- lan2: wan2 → wan3 → wan1- lan3: wan3 → wan1 → wan2- lan4: wan3 → wan1 → wan2 My config:
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.