Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello Dears I am trying to do internet service database group but i am not seeing anything related to create group on firewall level any one can help ? Bests
Hey, Perhaps someone can assist me or guide me in the right direction. I've been trying to resolve an issue with one of my S2S VPNs for a week.I have three Fortigates: one 600F and two 400Fs. The 600F has an S2S VPN with both 400Fs, and both ends have the same configuration. All of them are still running on Firmware 6.4.15. My problem:When I ping or SSH between the 600F and one of the 400Fs through the tunnel, I experience 10-15% packet loss. This results in very slow transfer rates and even causes CLI inputs to come through in waves. When I check the packets with a ping, I see that everything is sent, and replies are sent back, but some packets are just missing on the source firewall. With SSH, I observe retransmissions, TCP duplicate acknowledgments, and TCP previous segment not captured errors.The exact same configuration with the other 400F works perfectly fine without any issues.If I ping and SSH over the WAN interfaces instead of the S2S tunnel, it also works without is
Hello guys, in the data sheet from FortiMail there is mention about attachment inspection inside of emailhttps://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiMail.pdf But in the logs from FortiMail forwarded from appliance to our logserver i do not see full smtp headers listed - there are some basic - to,from,mail-id etc. but i specifically looking for Content-type/Content-disposition headers to be able to see if the email contains attachment or not. From what i checked FM only have rules to inspect particullar behaviour based on db signatures but this simple information is slipping somewhere - is FM able to provide this simple metadata?Appreciated your support#FortiMail #FortiGa
I installed forticlient vpn on Debian 12 but i when try to connect it shows this errorError occurred in handler for 'keytar.setPassword': [Error: The connection is closed]TZ=+0400 [confighandler:EROR] websock:40 Failed to read message: Trying to work with closed connection
Hi, Can we get patch management report from EMS. Regards,Ganesh
Scan is coming back with failures on the follow, these all relate to either the Fortinet_CA or the Fortinet_Sub_CA. I've already updated my certificate for Administration as well as my SSL VPN certificate with a valid certificate. How can I go about updating the items below? Being they appear to be Root CAs I don't see them "attached" anywhere. When I look at Certificates in the unit they show up under Remote CA Certificates. Basically it doesn't like the length of these or the fact that they are showing as self-signed. I'm assuming if I remove these it will cause issues with other Fortinet Certificates, best option to proceed? SSL Certificate - Invalid Maximum Validity Date Detected 1003 / tcp over sslSSL Certificate - Signature Verification Failed Vulnerability1003 / tcp over sslSSL Certificate - Invalid Maximum Validity Date Detected1000 / tcp over sslSSL Certificate - Signature Verification Failed Vulnerability1000 / tcp over sslSSL Certific
Hi, We have a report from every single one of our Synology network attached storage (NAS) that there was an attempt to access it via SSH and the IP is coming from Fortigate itself and I wanna know exactly why? From the logs, it says a user "admin" from the IP of Fortigate (192.168.0.1) device is accessing our Synology NAS via SSH. We're using the Fortigate 100E running on FortiOS v6.0.5 build0268 (GA) additional note: Currently, some users are currently using Forticlient VPN when connected to Synology, their IP address will be marked as only one address which is 192.168.0.1 to the Synology log list, but their access is only SMB protocol, not SSH. Is there any possible that there is an infected device? although this VPN setup is already a year and a half (when the pandemic started) and that attempt was just a recent (last Saturday). Thank you and regards.
Hello every one, Kindly i have issue with fortigate 80f the connection not fully established, it shown in connected peers for 10 seconds without any traffic and the connection was dropped. the firewall is after fiber router and i'm using DMZ to forward traffic to firewall. below you can find debug log.for help please ike 0: comes 51.39.30.90:2369->192.168.100.10:500,ifindex=5....ike 0: IKEv1 exchange=Identity Protection id=1e979cdc9e8163c1/0000000000000000 len=408ike 0: in 1E979CDC9E8163C100000000000000000110020000000000000001980D0000D40000000100000001000000C801010005030000280101000080010007800E0100800200028004001480030001800B0001000C000400007080030000280201000080010007800E0080800200028004001380030001800B0001000C000400007080030000280301000080010007800E0100800200028004000E80030001800B0001000C000400007080030000240401000080010005800200028004000E80030001800B0001000C000400007080000000240501000080010005800200028004000280030001800B0001000C0004000070800D00001
Hi, is the above possible to do globally for all interfaces instead of having to go to each interface one by one to disable PING?
I have a 40F that I've configured to allow SSL VPN connections from remote computers (work from home primarily). I've got Forticlient to connect, and while connected can still connect to the internet (split tunneling) and ping the 40F at 192.168.2.99. However, I can't access our server or any other devices on the office network. I've read on other responses to similar questions that I need to set up a policy to allow the SSLVPN traffic to access that same subnet. I can't figure out for the life of me how to do that. Using ipconfig I can see the remote computer gets a correct ip pursuant to the configuration I have (192.168.2.200). However, I also notice that the subnet mask is 255.255.255.255. From what I understand, that's putting it on a different subnet than the rest of our office lan (192.168.2.0 255.255.255.0) What else do I need to do? Thank you.
I am not sure if this is normal behaviour or a problem?Our Fortiproxy cluster loses the sync approx. every 10 minutes, then it is out of sync for 1-2 minutes, then it syncs again. I can see it in GUI, on the CLI and also with SNMP.It is active-passive HA with unicast heartbeat on explicit HA-interfaces in VLAN which is only used for this.I've already rebootet both devices (VM64 v7.4.2 build0577).Switchover worked fine.It is not a network issue!When I captured the traffic I've not only seen UDP-traffic between the peers, but also TCP on ports 703 and 700.703 is mentioned in the Fortiproxy port table, but 700 is not in the list (seems to be harelay).https://docs.fortinet.com/document/fortiproxy/7.4.0/fortiproxy-ports/758533/incoming-portsAny tipps?Thanks.
Hello Expert, I config ssl vpn on my fortigate 400E firewall but would like to enable 2FA for my user account.I would to use the forticloud option for the 2FA.Could any one provide guidance most of the videos online are using fortitoken or email method for their demonstration because I suspect the presenters done not have a forticloud account. My organization has a forticloud account. Thank you.
Good morning, I was trying to use Fortinet via script on windows to connect to a client vpn. From now I have been using without License Fortinet Client to connect to VPN. I have found lots of information that I need to download Fortinet Tools to find FortiSSLVPNClient.exe, that was available on previous versions of forticlient. I'm not able to find this tools and download this file. I would be pleased if anyone can help me with that issue. Thank you in advance.
Hi sir, I have a 81F on hand, last week I tried to flash the bluetooth ptm firmware thru command: diag bluetooth program ptm It fails to set bluetooth broadcast name so when I use the FortiExplorer I got name 'FortiBlue' detected but not serial number. Even I try to flash back the firmware to original version but it still is no change. Please advise how to change back the bluetooth broadcast name to serial number. Thanks,Jacky
Does the latest FortiOS (v7.4.4) support FTM-Push for IPSEC authentication? I see a number of posts in this community on this topic that indicate this is not supported with older revisions of the FortiOS. If this is a supported method to authenticate an IPSEC remote connection, I have an issue where the IPSEC connection process does not wait for the FTM-Push to be either received or approved. As such a connection can not be established with this enabled.
Hello, I want to test a FortiGate with its security functions in my existing home environment without changing the existing internet connection or any other network configuration on the router with its WAN access. For this I place the FGT inside the local (same) subnet. I put static routes on my client so that google.com and www.google.com are going through the FGT. On the FGT there is only one static route that points to the router that has WAN connection. Actual setting is as following: Client (192.168.0.15) >> FortiGate (192.168.0.245) >> Router (192.168.0.250) >> WAN After set up the static routes on the client for Google the ping and traceroute on the clients points to the FortiGate.Also on the FortiGate there is this ICMP traffic visible in the diagnostics packet view. However, all of the test policies I created on the FortiGate do not have any hit, also the forwarding log is empty, no traffic, and so
Hello everybody I hope you are all doing well,we are facing a problem with a certain client of ours so we usually give FortiClient VPN to our customers so that they can access certain websites but the problem is with one certain client is that every week he is having a problem that his FortiClient needs to be uninstalled and set again it shows only connecting for a sec and then goes away the problem will not be solved until I uninstall the FortiClient and install it again keep in mind we are using an old version of FortiClient as our firewall is not updated to the latest version.
Hi, we have firewall with central NAT enabled. Some communications are initiated from inside network and going towards outside network. Original Source IP - 172.19.60.100Original Destination IP - 192.168.23.5Source NAT IP - 192.168.48.12 as per the central NAT rules defined this traffic is getting source NATed to the 192.168.48.12 when going through the firewall.Also, we have configured some DNAT & VIP like below for traffics which are originated from external side.External IP - 192.168.48.12Mapped IP - 172.19.60.120 When considering this 192.168.48.12 is the source NAT ip for the traffics initiated from 172.19.60.100. Also this is external IP for the traffics initiated from external and its map to the inside ip 172.19.60.120 which is different than 172.19.60.100. will this works as expected or will there be any issues ? Thanks
Hello Dears i am trying to configure policy route making the outgoing interface is SD-WAN interface , i am not seeing the SD-WAN interfaces on list interfaces any suggestion plz? Bests
Hi all,I have found two events with the same session ID and with the same URL but one had action block and the other had pass-through.So is it passed or not? In other words, is it possible for one request to have pass-through and block actions in the same time?
Question, with the new Windows Copilot+ PCs, will there be a version of Forticlient for Windows on ARM that will also support ZTNA?I have SSL VPN setup at the moment, so tried using the version of FortiClient from the Windows Store, but while it connects it will not pass traffic. The regular Forticlient on another device works just fine. I'm getting ready to work with ZTNA to learn more about it, but I have a Windows Copilot+ laptop which the native Forticlient cannot be installed to. Yes, I can go back to my other laptop, and probably will for the testing, but if this is something that's going to be coming then I can wait to do so (while working on the SSL VPN issue, or setting up an IPSec connection, instead).
We use the EMS server to configure the FortiClients on our laptops.How can I ensure in the EMS server, that only our laptops connect to the EMS and that no foreign devices ? RegardsChris
Greetings,My organization uses Gmail through the Mac Mail app. Incoming emails are working, but outgoing/sending is not. Below is a log of my co-worker trying to send a message. I am kind of a noob and hoping for someone who can help translate.OR maybe I am not even looking at the right log? Thanks!
Hello everyone, FortiOS: 7.2.4Fortigate: 200E We have two FGCP clusters and FGSP between them. FGCP clusters are georaphically spaced and RTT between them around 40-50 ms. Session sync is configured over L3 link between FGCP clusters.We have configured pickup sessions(also expectation and connectionless). 1st FGCP cluster:config system ha set group-name "cluster 01" set mode a-p set session-pickup enable set session-pickup-connectionless enable set session-pickup-expectation enable set ha-mgmt-status enable set override disable config system standalone-cluster set standalone-group-id 1 set group-member-id 1 config cluster-peer edit 1 set peerip x.x.x.xdiagnose sys ha standalone-peers Group=1, ID=1 Detected-peers=1 Kernel standalone-peers: num=1. peer0: vfid=0, peerip:port = y.y.y.y:708, standalone_id=2 sess
Greetings. 4 users are banned from the internet.But we want these users to access a local website. What should I do? Waiting for your help.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.