Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I have a simple question about a Fortigate VM in cloud.Iam hosting multiple websites where Fortigate (mini) WAF Features are enabled like XSS, XSS Adv, SQL Injection, SQL Injections Advanced and so on.The problem is that website editing with "FCK-Editor" in the administrative webgui of the hosted sites triggers XSS basic and extended and also sql injection basic+extended. Since this is the mini waf i cannot finetune the policies.Can i do some kind of Internet-FSSO where for example a website admin can authenticate before editing a website so that I can create seperate firewall policy for authenticated admins? All the admins are workgroup Windows Computers not domain joined or something all stand alone computers.
Hola, estoy tratando de obtener las categorÃas de cada uno de los perfiles que tengo en web filter en el firewall, estoy usando esta sentencia "api/v2/cmdb/webfilter/profile/" profile parece funcionar, pero solo me muestra filtros con action block (solo me da el ID, pero no se a que objeto se refiere ni donde este el diccionario con todos los ID para saber que filtro y categoria es) y los que tienen action enable no me los muestra, hay forma de obtenerlos todos? ¿Filtros configurados para un perfil por la API de Fortigate?Gracias por tu tiempo Gracias por tu tiempo
this log MSI_CreateDB(), failed to launch appear to me when i try to install with remotely sql server with cause installation failure.any one have solution?
Good day team,Case: Caught a staff member, she enabled hotspot on their laptop because the staff wifi was temporarily down, found her pc name in the ssid list on my phone LOL. Many devices were connected in her dhcp client list. LOL, i mean, we IT staff doing so much stuff, we dont actively monitor this. Additionally, in all the major IT corporation that I have worked and managed, this feature was never really acted on or considered to be changed/disabled by the IT Bosses. Even my fellow sys engineers as myself did not pay this much mind. Something as simple as a hotpsot. Crazy world.Which is the best method?What did you do in your LAN?Which method worked for you? Is this possible with Forticlient? Would love some direct responses/suggestions/steps here.
Hi. I would like to block all App without certain users (IP/MAC adresses). Is it possible. When i go to Security -> Application Control -> select profile -> Application and filter Ovverride and add block for certain App it works. When i try to use it I'm blocked and these is ok. How can I bypass that block for certain computers? Is it possible to eg adress 192.168.1.45 have access to that app, but other are blocked? Thanks for reply and have a nice day
This is a follow up from: https://community.fortinet.com/t5/Support-Forum/AWS-IPSEC-on-BGP-routing-how-to-control-traffic-preference-for/td-p/279609 And now my issue is that I have connected the BGP with the VPCs but the routes in between are not being accepted by AWS TGW. This is my situation, from Brazil and Virginia, I need to pass on their routes to Desarrollo. I have the prefix list, the route maps, all the jazz. But for the life of me, I cannot find WHY Desarrollo does NOT show those routes.I can see the routes that set in the "Networks" section being propagated and see them also on the TGW route table.I can see the routes from BOTH, Brazil and Virginia being propagated, but they are NOT on the TGW.I thought it was the prefix list, set it to Permit ANY, still nothing.The team I work for had the idea of enabling back the static routes on the firewall and use the Redistribute: Static. And ONLY then, the routes appeared on Desarrollo. Yes, already raised a t
Hello, Our company is using an old version of FortiClient (5.6.6.1167). We want to migrate approximately 200 laptops to the latest version (7.0.7.0.345). Actually, the VPN config is set by Windows registry entries. Is it possible to keep the VPN configuration from the windows registry ?Otherwise, is it possible to deploy the latest version with a conf file ? For your information, we don't have a Forticlient EMS. Thanks for your support !
Here's my take on a basic best practices for securing corp wifi... Any feedback would be much appreciated. Client = 802.1x supplicant and certs installed on the machineAuthenticator = Wifi ControllerAuthentication Server = RADIUS serverDomain controller for user authentication Use a Machine cert to allow computer to be authenticated in order to connect to a corporate wifi for initially connectivity. Then the username / password would be used to authenticate the user against Domain Controller and grant permissions. Q1: Would there ever be a need to use the client cert in this case ?Q2: You can use any Radius server, but how could a NAC product supplement this deployment ? Thanks, Don
Dear all, Please suggest, how to create weekly monthly wan and sdwan report in Forti analyzer .Thanks Umesh
Hi Guys, I have a network made up of fortiAps connected to port 22 of the fortiswitch which in turn is connected to the fortigate 40f I wanted to configure the entire network under the 192.168.1.X class and the APs in bridge mode and assign an IP to the fortiswitch.Is all this possible? sorry but I'm new to the fortinet world I have to understand well...because the fotilink port on the fortigate is defined as dedicated to fortiswitch. Thank you very much in advance
Hi FG adminsToday on a FortiOS 7.4.4 I accidentally tried active portal and it surprisingly popped-up on my PC a very nice desktop notification (bottom-right) with a click-button and telling that an active portal is present, like FortiNAC does in isolation. Is it me or a true active portal is finally here?
My company wants to notify an employee by email or another way in Fortigate when they connect to VPN or disconnect VPNPlease help me.
Hi together, I have the following issue concerning the described network structure:Two main sites which are connected to our MPLS-Network. Other sites are also connected via MPLS. Each MPLS site has a MPLS-Router exchanging BGP-Routes with the Site-Firewall and redistributing it within the MPLS network. We want to throw out MPLS and replace it with IPSec tunnels. The goal is one connection from each remote site to each main site, routes also being exchanged via BGP and the two main sites also connected via IPSec to each other. From routing perspective this should not be a problem but if we now let the firewall things join we may break connections due to asynchronous routing when MPLS is still running:For example: packets entering via IPSec to main site 1 into MPLS to another location. Due to the BGP things within MPLS which we can't affect the answer packet maybe will be routed back through main site 2 as this is a "cheaper" way. Firewall on main site 2, of course, doesn't know ab
Hi all, Google Meet disconnects after a while, or the video call has delays, how we can configure it in fortiOS 7.4.2.is it possible to configure through traffic shaping . Thanks Umesh
Hi all, since i changed 2 internal vlan on a FortiGate 90G .... SSL is no more working. SSL VPN is connecting, but no traffic is going throw. Does anyone have an idea? the firewall policy and also paket capture are not seing any Packets.
Hi All, I have FortiAP's connected to FortiSwitches, both of which are managed by FortiGates and I am trying to figure out if it's possible for FortiNAC to identify a FortiAP when I connect to any port on the FortiSwitch and then dynamically set the VLAN on that switchport to be our AP management VLAN. If this is possible, any information about how to do it would be greatly appreciated. All of my FortiAP's appear (correctly) under the FortiGate in the Network > Inventory list in FortiNAC. I'm guessing that if the AP's were unmanaged, or classified as "Hosts", this would be possible (or easier).
Friends good day a question.I am trying to access a destination IP from the SSL VPN, however I have no response.The segment and the destination IP have been added to the policy and I still cannot access it.When I PING the destination IP from the firewall, I do get a response.Performing a debug, it was observed that it is matching the ID0 policy (denial policy) when trying to access the destination IP. msg="Denied by forward policy check (policy 0)" However, I have access to other IPs on the same segment but I do not have access to this IP.In addition, a static route for the segment has been created for a long time. What could be happening? Could you please help me.
A basic question: Would Websocket app (TCP 443) traffic be filtered by a policy with a Web Filter profile? Or do we need to match it with Application Control in a separate policy before or after the web filter policy?Thanks, Toshi
Hi, I've found the following technical tips on how route lookup is handled in FortiGatehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Routing-in-FortiGate-route-lookup-process/ta-p/194047?externalID=FD50169 But I don't think this logic applies in my case.I've an ipsec remote access VPN, the forticlient initiates the communication with the FGT (my VPN gateway), the FGT receives requests from forticlient on port1, but it sends the responses on port2 (because of an SDWAN rule I have), And I never get the response on my forticlient (I get a connection timeout on the FGT). I can't modify my SDWAN rule, so I've tried to twist this behavior by adding a PBR so that packets coming on port1 are always returned from that same port. The PBR I added never matched, that's why i want to know if Fortigate takes into consideration PBR entries when doing a route lookup for local out traffic
I have a VPN from a client when I connect it disconnects my Fortinet Single Sing On Agent Configuration user, from what I saw it changes DNS network card to the client's VPN, would there be any way to fix this?
Hi, does anyone know of a way I can restart/reboot a 201F series access point on a schedule? Like have it automatically bounce at 3 in the morning monthly?Thanks very much for any help,--mike
Hello All, I have observed port connected to Fortigate showing multiple mac on switch. What could be the reason for it.Pls note - fortigate is in High availability and I have created 2 vdom. Pfa 
@agrakov Do you have clearer pictures for this article you created?https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-Wi-Fi-configuration-with-Google-SAML/ta-p/225424 I cannot see the pictures properly for the settings. As well, do you have an updated article, that allows one to do this via the GUI since 7.XX.XX allows this to be done from the GUI? Since it's all command line I'm having trouble visualizing where some of the settings go. Any Help would be greatly appreciated. I would also need to modify it for my needs. Here are my needs:1. Instead of only SSID Interface facing users, I would like ALL Internal Interface users to be forwarded to the Google Saml iDP as the captive portal for sign in. So the captive portal would be turned on, on the internal interface2. There would be 2 Google groups, students and staff, when staff authenticate they would be assigned a specific Secuirty profile for filtering, when Student log in they would get their own mo
How can I setup HA on two fortiauthenticator appliences that are deployed in Azure ?We have no layer 2 in Azure....
Hello everybody,today I noticed something very strange. I'm working in my office, and all we employee have a public IP address that is:79.x.x.xAnyway, I'm using a free VPN client on my MacBook (ProtonVPN).This client allows to connect for free to one random location. This is the IP address assigned to me: If we double check: everything is fine. What's the problem? The problem is that FortiClient EMS shows the old IP address, the pubblic IP address of my office:   This is a problem because now I'm considered On-Fabric (because of the IP 79.x.x.x) when I should be Off-Fabric. Why is this happening? Is FortiClient capable of working with other VPN clients?  
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.