Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hey everyoneI’m deploying FortiSandbox for the first time and integrating it with FortiGate, F5 Load Balancer, and an internet modem.Before starting, I want to make sure the environment is ready.What are the required network prerequisites and ports that should be open?Also, are there any common mistakes or best practices I should be aware of for a first-time deploymentn?
Hello, I'm trying to do a lab with a trial version of fortianalizer (7.4.10) and fortigate (7.4.11) and I can't do the connection. When setting the IP of the analizer on the logging settings on the fortigate I get "no connection".They are on the same network, already enable the fgfm on the interface. Can ping both analizer from fortigate and vice versa. The config that I have on Fortigate:config log fortianalyzer setting set status enable set server "192.168.0.102" set certificate-verification disable set ssl-min-proto-version TLSv1end The config that I have on Analizer:config system global set adom-status enable set enc-algorithm low set global-ssl-protocol tlsv1.0 set hostname "FAZ-01" set oftp-ssl-protocol tlsv1.0 set ssl-low-encryption enable set timezone 91 set usg enableend Log from analizer
Hello, I am trying to update FortiSIEM content version from 901 to 908, but I receive a “server unreachable” error during the update.For testing, I allowed all-all access on the firewall for FortiSIEM, but the issue still persists.Has anyone experienced a similar issue? Are there any specific URLs/FQDNs, ports, or log files that should be checked for FortiSIEM content updates? Best Regards,İsmail ÜREK
Hello :)I have a question about connecting via Putty or PowerShell. How do I clear the history of entered commands that are substituted after pressing the up and down keys? Connecting via SSH to the FG900, I don't know where the history of such commands is located. Please help.
I want to make Forti Sandbox take copy of all internal mail which sent between the staff internally and scan it “URL & Attachments”How can I do this step by step on Forti Sandbox ?
Hello, Can the regulatory domain be changed on an FortiAP form -E (sweden) to -S (Philippines). Or does the sale have to be done locally in Philippines through local partner on local pricelist? BR Andreas
I was able to establish a connection for a very long time, but it then suddenly stopped working. The connection is established, but no data is received. The connection then closes after about 25 seconds.I noticed the following in the fortitray log which only appear after the time it stopped working:[2026-04-30 07:21:32.5496135 UTC+02:00] [17640:15916] [sslvpnlib 510 error] [ERROR]SslvpnAgent: Pipe is broken for writing. Error=233[2026-04-30 07:21:32.5532904 UTC+02:00] [17640:15916] [sslvpnlib 510 error] DoSendSslvpnReq() failed. Need to restart Pipe.[2026-04-30 07:21:32.5534866 UTC+02:00] [17640:15916] [sslvpnlib 510 error] Failed to connect to SslvpnDaemon, LastError=2[2026-04-30 07:21:32.5535905 UTC+02:00] [17640:15916] [sslvpnlib 510 error] CSslvpnAgent::SendSslvpnReq() 447 InitPipeHandle() failed.[2026-04-30 07:21:32.5537786 UTC+02:00] [17640:15916] [sslvpnlib 1261 error] CSslvpnBase::UpdateFortiSslvpnStatus() GetSslvpnStatus() failed.[2026-04-30 07:21:32.5538736 UTC
Hello Team, I have Fortinet firewall configure on Azure cloud as Active-passive with more than 400 Tunnels, Now i want to change mode from Active-passive to Active-Active. Any official documentation to achieve the same ?
I need help understanding an unexpected FortiEDR Manager restart.We observed the following event:Component: ManagerComponent Name: FortinetDescription: Server was restartedBefore this event, several FortiEDR components changed state to Disconnected:XX:XX:XX - Aggregator [aggregator-cloud] changed to DisconnectedXX:XX:XX - Core [core-cloud] changed to DisconnectedXX:XX:XX - Core [fortiedr-core-jumpbox-onprem] changed to DisconnectedXX:XX:XX - Warning: The following connectors will become inactive: Firewall FW (name)Then the services recovered after 20 seconds:YY:YY:YY - Manager: Server was restartedYY:YY:YY - Connection to Syslog succeeded: FAZ1YY:YY:YY - Connection to Syslog succeeded: FortiSIEMYY:YY:YY - Aggregator [aggregator-Cloud] changed to RunningYY:YY:YY - Core [core-cloud] changed to RunningYY:YY:YY - Core [core-onprem] changed to RunningWhat can cause the FortiEDR Manager to restart with the message “Server was restarted”?Any guidance on where to investigate further would be a
I am working as an intern at a startup and the website I am handling https://www.gazfull.com/ is being flagged as malicious by FortiGuard and getting blocked.There is no intentional malicious content on the site. We want to fix the root cause instead of just requesting whitelisting.What are the common reasons FortiGuard flags a website as malicious?Are there specific security loopholes, misconfigurations, headers, SSL issues, third-party scripts, or deployment patterns that typically trigger this?Also, after resolving potential issues, what is the correct process for requesting reclassification/whitelisting with FortiGuard?Any guidance on debugging this systematically would be really helpful.
Hello COMMUNITY,I am facing some problems, I would really appreciate if you can assist me with that. I have installed fortigate on vmware on ubuntu and configured it per this document (https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/545125/ztna-agentless-web-based-application-access).I added the fortigate ip (172.169.173.132) as portal.ztna.com to /etc/hosts to resolve the DNS. The issue is that web portal is not accessible. when I wrote the address to the browser, it shows with HTTP This page isn’t workingportal.ztna.com didn’t send any data.ERR_EMPTY_RESPONSE with HTTPSThis site can’t be reachedportal.ztna.com unexpectedly closed the connection.Try:Checking the connection Checking the proxy and the firewallERR_CONNECTION_CLOSED-----------------------------------------------------------THIS IS MY CONFIGURATION FGVMEVYLSWRHYA98 # show firewall vip config firewall vip edit "ZTNA-web-proxy" set uuid 65006b6c-42f6-51f1-97c1-5c559a60d09e set type
I have yet to find a working solution for what seems like a normal networking scenario. Here are the requirements:ports 1-5: port1: access vlan 5 (untagged vlan 5) should share l3 gateway with any hosts connected to trunks port2: access vlan 10 (untagged vlan 10) should share l3 gateway with any hosts connected to trunks port3: access vlan 15 (untagged vlan 15) should share l3 gateway with any hosts connected to trunks port4: trunk all vlans, native vlan 99. non-aggregate port5: trunk all vlans, native vlan 99. non-aggregatel3 interfaces of some kind. cannot be under a physical interface because two trunks must carry vlans: vlan5: 10.0.5.1/24 vlan10: 10.0.10.1/24 vlan15: 10.0.15.1/24 vlan99: 10.0.99.1/24 (native)I’ve read the documentation. I’ve asked open.ai several different times, I’ve had Claude read through multiple FortiOS version documentation. The documentation is not great in this area. So no great that claude cannot figure it out.I can make something like this work w
We are using a FortiGate-200G running FortiOS v7.6.6.We would like to know if there is a way to send alert email notifications when there is a sudden increase in the number of sessions, such as RDP sessions, passing through the FortiGate.If there is a method using FortiAnalyzer, please let us know.Alternatively, a solution using only the FortiGate would also be acceptable.
Go stdlib vulnerability detected in FortiTcs.exe (possible GO‑2026‑4865). Version Forticlient: 7.2.13.1287. Is there a fix that will release soon? Does the version 7.2.14 can fix this vulnerability?
We have deployed fortianalyzer on VM & currently it is in production.We have given 500GB of disk space first & currently we need to add 500GB size additionally.Can anybody help me on how can we add the diskspace & what all needs to be done before proceeding with the addition.
Hello everyone,I am planning a firmware upgrade for a FortiSandbox currently running 4.0.9. My target is 4.4.9.Since this is a jump across several versions, I'm looking for a validated Method of Procedure (MOP). Specifically: Upgrade Path: Based on the release notes, is a direct jump supported, or do I need to step through 4.2.x first? Cluster Impact (If applicable): If I'm in a Primary/Worker setup, should I expect significant downtime for the Rating Engine sync between these versions? Are there any known issues in the target versions that needed to consider? If anyone has a step-by-step checklist or "gotchas" for this specific path, I’d appreciate the help!
We are currently using two FortiGate-200G units in an HA configuration with the ha-direct feature enabled.After applying the following NetFlow configuration, we were unable to execute the set netflow-sampler command on the target interface.If there is any way to achieve this, we would greatly appreciate your advice.NetFlow Configurationconfig system netflow config collectors edit 1 set collector-ip "x.x.x.x" set collector-port 9996 next endendAttempted Command on the Target Interfacefw # config system interface fw (interface) # edit port1fw (port1) # set netflow-sampler bothcommand parse error before 'netflow-sampler'Command fail. Return code -61
Hi all,I built a captive portal at the fortiauthenticator and integrated it with MFA.The saml process works well when tested separately in a browser but when the user connect to the SSID it’s not getting redirected properly, an error pops up says “pretty print”.I have only basics in fortinet, can someone help ?fortiauth in Azure , EntraId in Azure, fortigate onprem.User(SSID)—-(AP)——-Fortigate ——-(IPsec)——Azure(Fortiauth+EntraID)
Hello everyone,I am facing an issue with an HA Active-Passive setup using two FortiGate 120G devices (Firmware:7.6.6).The Setup:HA Mode: Active-PassivePriority: FG1 (128) - intended Primary, FG2 (120) - intended Secondary.HA Override: enableMonitored Interfaces: ATC-LACP (802.3ad Aggregate interface connected to a core switch).The Problem: When I reboot the Primary unit (FG1), failover happens correctly, and FG2 takes over. However, when FG1 finishes booting up, it does NOT preempt back to the Primary role. Running get system ha status shows that FG1 is stuck as Secondary with the following warning: WARNING: FG120GTKXXXXXXXX has mondev down;The LACP interface on FG1 stays down. The only way to fix this and trigger preemption is to manually log into FG1 (which is currently the secondary) and flap the interface:Plaintext config system interface edit "ATC-LACP" set status down set status up nextendImmediately after this manual flap, the LACP comes up, the mondev down
I have a new Fortigate 60F that I am setting up. I upgraded the firmware to 7.2.1 and then used the web GUI to restore factory settings to give me a fresh base to work from. After the factory reset, I can see that the 60F is acting as a DHCP on the network, but I have been unable to ping it or access the web GUI to set it up. I don’t have a console cable and it may be difficult for me to get one as I am in a somewhat remote area. Does anyone have any thoughts on what could be causing this behaviour and/or how it could be resolved? Any assistance greatly appreciated.
Hi,When a non Forticlient MacOS user connects to IKEv2 IPSec they have issues with split tunnel DNS.DNS queries are only using the tunnel when using dig and implicitly querying a specific DNS server.This causes issues with other traffic.dig quanza-eun-ufg71.q @172.28.8.53 ~;; QUESTION SECTION:;quanza-eun-ufg71.q. IN A;; ANSWER SECTION:quanza-eun-ufg71.q. 86401 IN A 172.28.8.139;; SERVER: 172.28.8.53#53(172.28.8.53)With IPSec tunnelping quanza-eun-ufg71.qping: cannot resolve quanza-eun-ufg71.q: Unknown hostdig quanza-eun-ufg71.q;; QUESTION SECTION:;quanza-eun-ufg71.q. IN A;; SERVER: 172.20.10.1#53(172.20.10.1)I have checked the debug of the IPSec tunnel initiation and do not see an obvious difference.Both Forticlient and Non-Forticlient connections acquire the DNS servers in the mode-cfg.This issue does not occur with IKEv1
Hello Fortinet Community,I have a question regarding FSSO and Active Directory user visibility in FortiGate logs.Currently, the customer has LDAP/FSSO configured, and user identification works correctly for a LAN segment directly connected to the FortiGate. In those logs, we can properly see the authenticated username along with source IP, destination, and bandwidth usage.However, there are additional user segments that are not directly connected to the firewall. These networks are learned through static/dynamic routing from other network devices. For traffic coming from those routed segments, the logs only show source/destination IPs and traffic usage, but no associated username.My main question is:Can FortiGate/FSSO associate users with IP addresses regardless of whether the network is directly connected or learned through routing protocols?From my understanding, FSSO performs User ↔ IP mapping based on authentication events from Active Directory, so theoretically it should not depen
The vpn is working but the users can’t access the resources because the IP was change All the servers only approved access from the Wan address of the Forti - it's white list The IP of the server - users have to get access to it is 20.101.142.72 Anyone who connected to the VPN would receive their address, and because of that, all they had to do was put the VPN's IP in the WHITELIST and that's it. That's exactly how it works at ROCKET too. Can you help me to fix our problem?
The FortSwitch Ports view on the Fortigate shows just regular access ports where the Fortilink is. Running 7.2.12 and 7.6.4 on the switch.Talked to support and they had a look at the interfaces from the CLI and everything was as it should. This all changed after moving some VLANS around and might have caused a loop which got shut down by STP. IDK if it was related, but it happened right after.Has anyone else seen this happen? Apparently just a bug in the GUI?
Currently, we are using SSL inspection with the "certificate-inspection" profile and have Web Filter enabled.However, since the FortiGate certificate has not been manually imported into the client PCs, users see a certificate error screen when traffic is blocked.We would like to redirect users to a specific page instead of displaying the certificate error page, without importing the FortiGate certificate on the client PCs.If there is a way to achieve this, could you please advise?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.