Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I'm setting up a forticlient enterprise management server and the forticlient agents on the computer show real time protection is disabled. The correct profile is assigned to the group and the Scan Files as They Are Downloaded or Copied to My System option is enabled on the profile. Any suggestions why real time protection wont enable?
Hi, I checking on my FortiAnalyzer, seem the resource for the CPU really high. I monitored it almost 1 day and restart some of the service but still same. Based on the exe top output, some application that utilized most of the cpu are siemagentd & postgress. Its take a lot of time to generate a report when the cpu high. Anyone can assist me on this ?
Fail:(errno=131):datasrc invalid. object: system zone. detail: "Fortigate name"[root] interface:DATA How would I go about removing this object so I can upgrade the FMGs ADOM? The FMG is at 7.4.3
greetings, I created an SD-WAN rule (source = all, destination = all) for Internet access with two member interfaces. One is the underlay interface and will forward traffic to local egress (DIA), the other one is an overlay MPLS ipsec tunnel that will forward traffic to our offshore office in another country (RIA). underlay interface is the primary for internet access, overlay interface is used when underlay interface is inactive. They are judged by an SLA that uses ping as the probe to a public www server (but we are gonna change to use DNS soon). There is only one default route (0.0.0.0/0.0.0.0) pointing to the underlay interface. my concern is, when underlay interface becomes inactive, will the overlay interface be able to forward internet traffic? according to the SD-WAN routing logical, when primary interface is down, the default route via it will be updated (removed I think), then there is no route through any of the SD-WAN member interface for internet traffic.&nb
Hi, I've had an issue with a 200F v7.2.8 We have an issue where policies for VLANs attached to a port that is part of a Zone labelled DMZ are not applied when using the Zone in the firewall policy. for example Port 2 has multiple separate VLANs that are various DMZ networks.Port 2 is assigned to the DMZ ZoneOne such DMZ VLAN is a quarantine DMZ (for testing suspicious USBs etc) Port 24 is our main internet connection assigned to the WAN zone If I create a rule From DMZ Zone to WAN Zone with source set to the IP Range used on the quarantine DMZ destination all, service all I see no traffic hit that rule and logs show traffic from the IP of the device being blocked. Even if I use a DMZ Zone interface source all to WAN destination all I still get not policy hits. If I modify the rule so that the incoming interface is the Quarantine VLAN instead of the DMZ zone then the policy works. I've worked around this by using the VLANs for the
Hi everyone, Does the Frotigate come with any malware-protection software to prevent the device itself from becoming infected? Or are users exclusively dependent on security patches pushed by Forticare?
Hello. I'm working on putting together a test topology for a private Datacentre and I've run into some troubles with NAT & Routing when passing traffic over an NPU Inter-VDOM link. My design is to have an internal VDOM to handle all local policies and inter-VLAN routing, and an External VDOM to take in the WAN links and handle broad-scope security such as DDoS protection, IDPS, etc. I have multiple Public IP addresses to use and would like to be NATing from the internal VDOM using IP Pools and sending this traffic over the NPU and out to the internet, however, I have not been able to get this working with this design. The only way I've gotten this working so far is by performing the outbound SNAT from the externally facing VDOM by passing private IP traffic over the inter-VDOM link instead of Public IP traffic. I'd like to avoid this, as it would include double-handling IP address objects between VDOMs. My first hunch was to play around with the static routes /
I have a FortiGate 61F. Can I upgrade from 6.4.6 directly to 6.4.15? Has anyone done this without problems? I am managing it remotely via VPN so I would like to avoid problems that require me to be there to do any physical resets. I have asked support as well, but I'm looking for real life experiences/advice. Thank you !
Hi, I'm new with firewalls in general, and I need to do a simple set up for both DMZ and SNMP, both of which don't seem to be working, I'm using Fortigate v5.4.6 VM. For DMZ I need to add a server to a DMZ and only network clients from 1 LAN interface should be able to access it, I have managed to get client to access DMZ Server but everybody else can also access it ?! My question is particularly about the Static Route, which interface should it point to ? This gallery shows the Interface, Static Route & Policy configuration.
Hi, I wanted to ask about ZTNA. Is it mandatory to use a ZTNA server? If we don't use it, who handles user authentication and authorization? Will EMS itself or Fortigate do this?
I have a simple question about a Fortigate VM in cloud.Iam hosting multiple websites where Fortigate (mini) WAF Features are enabled like XSS, XSS Adv, SQL Injection, SQL Injections Advanced and so on.The problem is that website editing with "FCK-Editor" in the administrative webgui of the hosted sites triggers XSS basic and extended and also sql injection basic+extended. Since this is the mini waf i cannot finetune the policies.Can i do some kind of Internet-FSSO where for example a website admin can authenticate before editing a website so that I can create seperate firewall policy for authenticated admins? All the admins are workgroup Windows Computers not domain joined or something all stand alone computers.
Hola, estoy tratando de obtener las categorÃas de cada uno de los perfiles que tengo en web filter en el firewall, estoy usando esta sentencia "api/v2/cmdb/webfilter/profile/" profile parece funcionar, pero solo me muestra filtros con action block (solo me da el ID, pero no se a que objeto se refiere ni donde este el diccionario con todos los ID para saber que filtro y categoria es) y los que tienen action enable no me los muestra, hay forma de obtenerlos todos? ¿Filtros configurados para un perfil por la API de Fortigate?Gracias por tu tiempo Gracias por tu tiempo
this log MSI_CreateDB(), failed to launch appear to me when i try to install with remotely sql server with cause installation failure.any one have solution?
Good day team,Case: Caught a staff member, she enabled hotspot on their laptop because the staff wifi was temporarily down, found her pc name in the ssid list on my phone LOL. Many devices were connected in her dhcp client list. LOL, i mean, we IT staff doing so much stuff, we dont actively monitor this. Additionally, in all the major IT corporation that I have worked and managed, this feature was never really acted on or considered to be changed/disabled by the IT Bosses. Even my fellow sys engineers as myself did not pay this much mind. Something as simple as a hotpsot. Crazy world.Which is the best method?What did you do in your LAN?Which method worked for you? Is this possible with Forticlient? Would love some direct responses/suggestions/steps here.
Hi. I would like to block all App without certain users (IP/MAC adresses). Is it possible. When i go to Security -> Application Control -> select profile -> Application and filter Ovverride and add block for certain App it works. When i try to use it I'm blocked and these is ok. How can I bypass that block for certain computers? Is it possible to eg adress 192.168.1.45 have access to that app, but other are blocked? Thanks for reply and have a nice day
This is a follow up from: https://community.fortinet.com/t5/Support-Forum/AWS-IPSEC-on-BGP-routing-how-to-control-traffic-preference-for/td-p/279609 And now my issue is that I have connected the BGP with the VPCs but the routes in between are not being accepted by AWS TGW. This is my situation, from Brazil and Virginia, I need to pass on their routes to Desarrollo. I have the prefix list, the route maps, all the jazz. But for the life of me, I cannot find WHY Desarrollo does NOT show those routes.I can see the routes that set in the "Networks" section being propagated and see them also on the TGW route table.I can see the routes from BOTH, Brazil and Virginia being propagated, but they are NOT on the TGW.I thought it was the prefix list, set it to Permit ANY, still nothing.The team I work for had the idea of enabling back the static routes on the firewall and use the Redistribute: Static. And ONLY then, the routes appeared on Desarrollo. Yes, already raised a t
Hello, Our company is using an old version of FortiClient (5.6.6.1167). We want to migrate approximately 200 laptops to the latest version (7.0.7.0.345). Actually, the VPN config is set by Windows registry entries. Is it possible to keep the VPN configuration from the windows registry ?Otherwise, is it possible to deploy the latest version with a conf file ? For your information, we don't have a Forticlient EMS. Thanks for your support !
Here's my take on a basic best practices for securing corp wifi... Any feedback would be much appreciated. Client = 802.1x supplicant and certs installed on the machineAuthenticator = Wifi ControllerAuthentication Server = RADIUS serverDomain controller for user authentication Use a Machine cert to allow computer to be authenticated in order to connect to a corporate wifi for initially connectivity. Then the username / password would be used to authenticate the user against Domain Controller and grant permissions. Q1: Would there ever be a need to use the client cert in this case ?Q2: You can use any Radius server, but how could a NAC product supplement this deployment ? Thanks, Don
Dear all, Please suggest, how to create weekly monthly wan and sdwan report in Forti analyzer .Thanks Umesh
Hi Guys, I have a network made up of fortiAps connected to port 22 of the fortiswitch which in turn is connected to the fortigate 40f I wanted to configure the entire network under the 192.168.1.X class and the APs in bridge mode and assign an IP to the fortiswitch.Is all this possible? sorry but I'm new to the fortinet world I have to understand well...because the fotilink port on the fortigate is defined as dedicated to fortiswitch. Thank you very much in advance
Hi FG adminsToday on a FortiOS 7.4.4 I accidentally tried active portal and it surprisingly popped-up on my PC a very nice desktop notification (bottom-right) with a click-button and telling that an active portal is present, like FortiNAC does in isolation. Is it me or a true active portal is finally here?
My company wants to notify an employee by email or another way in Fortigate when they connect to VPN or disconnect VPNPlease help me.
Hi together, I have the following issue concerning the described network structure:Two main sites which are connected to our MPLS-Network. Other sites are also connected via MPLS. Each MPLS site has a MPLS-Router exchanging BGP-Routes with the Site-Firewall and redistributing it within the MPLS network. We want to throw out MPLS and replace it with IPSec tunnels. The goal is one connection from each remote site to each main site, routes also being exchanged via BGP and the two main sites also connected via IPSec to each other. From routing perspective this should not be a problem but if we now let the firewall things join we may break connections due to asynchronous routing when MPLS is still running:For example: packets entering via IPSec to main site 1 into MPLS to another location. Due to the BGP things within MPLS which we can't affect the answer packet maybe will be routed back through main site 2 as this is a "cheaper" way. Firewall on main site 2, of course, doesn't know ab
Hi all, Google Meet disconnects after a while, or the video call has delays, how we can configure it in fortiOS 7.4.2.is it possible to configure through traffic shaping . Thanks Umesh
Hi all, since i changed 2 internal vlan on a FortiGate 90G .... SSL is no more working. SSL VPN is connecting, but no traffic is going throw. Does anyone have an idea? the firewall policy and also paket capture are not seing any Packets.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.