Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi all, since i changed 2 internal vlan on a FortiGate 90G .... SSL is no more working. SSL VPN is connecting, but no traffic is going throw. Does anyone have an idea? the firewall policy and also paket capture are not seing any Packets.
Hi All, I have FortiAP's connected to FortiSwitches, both of which are managed by FortiGates and I am trying to figure out if it's possible for FortiNAC to identify a FortiAP when I connect to any port on the FortiSwitch and then dynamically set the VLAN on that switchport to be our AP management VLAN. If this is possible, any information about how to do it would be greatly appreciated. All of my FortiAP's appear (correctly) under the FortiGate in the Network > Inventory list in FortiNAC. I'm guessing that if the AP's were unmanaged, or classified as "Hosts", this would be possible (or easier).
Friends good day a question.I am trying to access a destination IP from the SSL VPN, however I have no response.The segment and the destination IP have been added to the policy and I still cannot access it.When I PING the destination IP from the firewall, I do get a response.Performing a debug, it was observed that it is matching the ID0 policy (denial policy) when trying to access the destination IP. msg="Denied by forward policy check (policy 0)" However, I have access to other IPs on the same segment but I do not have access to this IP.In addition, a static route for the segment has been created for a long time. What could be happening? Could you please help me.
A basic question: Would Websocket app (TCP 443) traffic be filtered by a policy with a Web Filter profile? Or do we need to match it with Application Control in a separate policy before or after the web filter policy?Thanks, Toshi
Hi, I've found the following technical tips on how route lookup is handled in FortiGatehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Routing-in-FortiGate-route-lookup-process/ta-p/194047?externalID=FD50169 But I don't think this logic applies in my case.I've an ipsec remote access VPN, the forticlient initiates the communication with the FGT (my VPN gateway), the FGT receives requests from forticlient on port1, but it sends the responses on port2 (because of an SDWAN rule I have), And I never get the response on my forticlient (I get a connection timeout on the FGT). I can't modify my SDWAN rule, so I've tried to twist this behavior by adding a PBR so that packets coming on port1 are always returned from that same port. The PBR I added never matched, that's why i want to know if Fortigate takes into consideration PBR entries when doing a route lookup for local out traffic
I have a VPN from a client when I connect it disconnects my Fortinet Single Sing On Agent Configuration user, from what I saw it changes DNS network card to the client's VPN, would there be any way to fix this?
Hi, does anyone know of a way I can restart/reboot a 201F series access point on a schedule? Like have it automatically bounce at 3 in the morning monthly?Thanks very much for any help,--mike
Hello All, I have observed port connected to Fortigate showing multiple mac on switch. What could be the reason for it.Pls note - fortigate is in High availability and I have created 2 vdom. Pfa 
@agrakov Do you have clearer pictures for this article you created?https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-Wi-Fi-configuration-with-Google-SAML/ta-p/225424 I cannot see the pictures properly for the settings. As well, do you have an updated article, that allows one to do this via the GUI since 7.XX.XX allows this to be done from the GUI? Since it's all command line I'm having trouble visualizing where some of the settings go. Any Help would be greatly appreciated. I would also need to modify it for my needs. Here are my needs:1. Instead of only SSID Interface facing users, I would like ALL Internal Interface users to be forwarded to the Google Saml iDP as the captive portal for sign in. So the captive portal would be turned on, on the internal interface2. There would be 2 Google groups, students and staff, when staff authenticate they would be assigned a specific Secuirty profile for filtering, when Student log in they would get their own mo
How can I setup HA on two fortiauthenticator appliences that are deployed in Azure ?We have no layer 2 in Azure....
Hello everybody,today I noticed something very strange. I'm working in my office, and all we employee have a public IP address that is:79.x.x.xAnyway, I'm using a free VPN client on my MacBook (ProtonVPN).This client allows to connect for free to one random location. This is the IP address assigned to me: If we double check: everything is fine. What's the problem? The problem is that FortiClient EMS shows the old IP address, the pubblic IP address of my office:   This is a problem because now I'm considered On-Fabric (because of the IP 79.x.x.x) when I should be Off-Fabric. Why is this happening? Is FortiClient capable of working with other VPN clients?  
How to enable intervlan routing on firewall with fortiswitch connected via fortilink.Different end device connected to Fortiswitch in different vlans need to communicate with each other and fortiswitch managing by fortigate. Fortigate needs to do intervlan routing.Can anyone please suggest.
Hey,I'm looking for a filter/policy to block instagram pages that contain specific hashtags. Is this possible and how to configure it ?Thx for your feedback.
Hello everyone! I am looking to leverage the Dot1x auto registration option on FortiNAC to register devices that log in to my network using WiFi. Yet, I need some way to identify that these guys became registered using this method, so I can apply scans, Net Access Policies and so on. The issue is they get assigned the NAC-Default role and I don't see any option to apply a role as we do on the portal for example, where I can give a BYOD or Guest role for example. Does anyone have any suggestions on how can I apply roles or can think of other ways to leverage this option but still have control of the way the device connected and became registered to the network? Appreciate the help! FortiNAC
Hi guys.After many years, we are about changing our organizational firewall and move to Fortigate.We are deliberating between two models: FG-400F and FG-401F.The main deference is that FG-401 has an internal storage (SSD), while the FG-400 has none.My question: How crucial is it to have internal storage,What the risk of not having one.Does it have any performance influence.Any help will be appreciated :smiling_face_with_smiling_eyes:Regards,Goldy
Hello,I've been asked to enumerate all devices on our office LANs and the Device Inventory Monitor seems to have all the information we're looking for such as MAC, IP, Hostname, OS, etc. But I can't figure out a way to export this information from the web interface. I'm surprised there isn't some kind of CSV download option or anything like that.Has anyone figured out a way to do this?
Hello, I have the following request. Which Fortinet products can perform the following tasks that I will outline? Here's what the product should do: SIEM: A local SIEM solution. Ability to separately analyze raw logs when needed, with the ability to export them in .json, .cef, and .csv formats. If the SIEM does not have this capability, the applicant must propose an alternative solution that allows retaining all security and application logs for 90 days. The solution should have User Behavior Analytics (UBA) functionality. Endpoint Security EDR/XDR: A local solution for endpoint detection and response (EDR) or extended detection and response (XDR). Privileged Access Management (PAM) Software: A local PAM solution for managing and controlling privileged access. Seven licenses required. Network Traffic Flow Recording Solution: A solution that can integrate with SIEM and firewall and/or network devices (switches, routers) to record traffic flow at the full TCP/IP packet level (in .
Hello everyone, I installed eve-ng version 5.0.1-24, and I try to upload images Fortigate, I download direct the Forticloud this images, I try to 3 versions fortinet-FGT-v7.2.8, fortinet-FGT-v7.4.4 and fortinet-FGT-v7.2.4, but not work. When I start the firewall, it's turn on, and few seconds it's turn down. I see in logs the VM (I am using virtualbox) there some problems with the network, follow below:I try to follow this page (www.eve-ng.net/index.php/documentation/howtos/howto-add-fortinet-images/ ) I did exactly the same steps, but not work too. Jul 23 13:45:14 eve-ng systemd-networkd[659]: vunl0_1_0: Gained carrierJul 23 13:45:14 eve-ng kernel: [ 2600.413920] pnet0: port 2(vunl0_1_0) entered blocking stateJul 23 13:45:14 eve-ng kernel: [ 2600.413925] pnet0: port 2(vunl0_1_0) entered forwarding stateJul 23 13:45:14 eve-ng kernel: [ 2600.417069] pnet0: port 2(vunl0_1_0) entered disabled stateJul 23 13:45:14 eve-ng systemd-networkd[659]: vunl0_1_0:
Dear supporters. Good day to you all,i have an old FortiGate firewall 60C expired license with 5.2.5v OS.i am using it for lap testing for VPN connection for remote access to specific laptop, all worked fine but i am not able to ping to any connected devices after the firewall.all policies and routing are fine.does the expiration of the licensing has anything to do with blocking these service or protocol. or it supposed to work fine. Regards
We have encountered the following issue. We need to redirect all HTTP/HTTPS requests that come to the Fortigate to a remote proxy server, while maintaining the ability to authenticate users. We followed this guide to configure the Fortigate: https://docs.fortinet.com/document/fortigate/7.0.0/new-features/23601/selectively-forward-web-requests-to-a-transparent-web-proxy.We managed to redirect all HTTP/HTTPS requests to the remote proxy server, but the problem is that Fortigate sends all requests to the remote proxy server with its own IP address. That is, all packets that were redirected had the Fortigate's IP address in the Source address field (we observed this in the proxy server logs). As a result, the proxy server cannot authenticate the user by IP address or by username. Does Fortigate have any solution to this problem?Thank you in advance
Hi all, I'm relatively inexperienced with firewalls and would value any guidance you can provide.Here's the scenario:We're connected to another company via an IPSEC VPN. The VPN was set up correctly and is operational. However, due to a recent change, we need to revise the policy.We have a label printer connected to a PC. This PC must be able to communicate with a remote server through the VPN. Currently, the PC can reach the remote server via the VPN. The problem is that the VPN's other side is receiving our public IP instead of the source PC's IP.Here are the actions I've taken:I've created two objects: one for the PC and another for the target server.I've established a new policy rule that permits traffic from the PC object (set to 'Any' during the testing phase) to pass through the VPN tunnel, with NAT disabled for this rule.I've also set up the reverse policy rule in case the target server needs to initiate contact with the PC.However, when we test the application for the pri
Hi guysI've a question about de vulnerability scan result from FortiClient.On the client in the scan results there is found an application which uses log4net. On the client I can see whats the vulnerability an in which path it's located.But on the EMS server I only see the vulnerbaility and not where it's located. Maybe I failed to see it on the EMS server... Can someone help me out??Patric
Dear All , hope you are doing great, i have FortiGate 60D, just unplugged it from the server room to hardware reset everything, put on my desk, plugged the power and all i got the power button is contiguously flashing green,it was working fine. tried to putty it with no access. your support much appreciated if anyone faced this before. RegardsGhadamsi
i recently upgraded my macbook and now need to install forticlient vpn on it.which version should i download?those that i tired download from fortinet support all comes with EMS with one month validityi just need the forticlient ssl vpn client
I have a below setup. Spoke locations: Single WAN link sites (Single Underlay) & Dual WAN link sites (2 Underlay)Hub location: Single Hub with Dual WAN link Single Underlay sites having 1 Overlay to Hub locationDual Underlay sites having 2 Overlay to Hub location I have a ADVPN with SDWAN setup, spoke-to-spoke communication is happening via shortcut tunnel. In this case some fail-over scenarios are there between spoke-to-spoke communication, Single Underlay Site - Overlay 1 is UPDual Underlay site - Overlay 1 is down (WAN 1 down) but Overlay 2 is UP (WAN 2)But communication between these sites are not happening via Criss-Cross tunnel.Question:How to achieve this communication (Criss-Cross tunnel)?Fail-over: As per TAC, Its not possibleI want to cheek anyone achieved this solution or design or not, If possible how it is done?anyone having any idea? Need your suggestion.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.