Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
The vpn is working but the users can’t access the resources because the IP was change All the servers only approved access from the Wan address of the Forti - it's white list The IP of the server - users have to get access to it is 20.101.142.72 Anyone who connected to the VPN would receive their address, and because of that, all they had to do was put the VPN's IP in the WHITELIST and that's it. That's exactly how it works at ROCKET too. Can you help me to fix our problem?
The FortSwitch Ports view on the Fortigate shows just regular access ports where the Fortilink is. Running 7.2.12 and 7.6.4 on the switch.Talked to support and they had a look at the interfaces from the CLI and everything was as it should. This all changed after moving some VLANS around and might have caused a loop which got shut down by STP. IDK if it was related, but it happened right after.Has anyone else seen this happen? Apparently just a bug in the GUI?
Currently, we are using SSL inspection with the "certificate-inspection" profile and have Web Filter enabled.However, since the FortiGate certificate has not been manually imported into the client PCs, users see a certificate error screen when traffic is blocked.We would like to redirect users to a specific page instead of displaying the certificate error page, without importing the FortiGate certificate on the client PCs.If there is a way to achieve this, could you please advise?
Hi,I would like to ask if we can deploy SDWAN with one Internet line and MPLS?My topology:HUB and Spokes have one internet line and one MPLS. The MPLS connect directly between Hub and Spokes. The internet using for VPN between them.I dont want to config VPN via MPLS.Is it possible to deploy sdwan for both VPN and MPLS for steering or control traffic to Dc behind the HUB via both MPLS and VPN?Thank you
I have an explicit proxy test configuration with NTLM authentication;I have the groups configured in the proxy policy, but while I can authenticate on the computer, I can’t browse the web. In the debug log, it shows the error highlighted in the screenshot it’s unable to read the groups but I’ve already verified that communication between my user and the group configured in the proxy policy is working;I’m stuck; I don’t know how to fix this.FortiOS 7.4.11
I have installed FortiClient EMS version 7.4.4 (trial). I deployed this instance as a VM. I am trying to perform an automatic upgrade from the GUI to version 7.4.6. Unfortunately, it keeps showing an update error. In the logs, I see errors and warnings:Err:5 https://dl.winehq.org/wine-builds/ubuntu jammy InReleaseThe following signatures couldn't be verified because the public key is not available: NO_PUBKEY 76F1A20FF987672FWARNING: apt does not have a stable CLI interface. Use with caution in scripts.E: Conflicting values set for option Signed-By regarding source https://apt.postgresql.org/pub/repos/apt/ noble-pgdg: /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc != /usr/share/postgresql-common/pgdg/apt.postgresql.org.gpgE: The list of sources could not be read.Warning: The unit file, source configuration file or drop-ins of redis.service changed on disk. Run 'systemctl daemon-reload' to reload units.___________Please help me resolve this issue.
Hello everyone,I know that Fortinet previously removed the possibility to transfer FortiToken licenses from one FortiGate to another FortiGate.I would like to know if it is still possible to transfer FortiTokens from a FortiGate to FortiAuthenticator now. Has anyone done this recently ?Thanks in advance.BR,
Hi ! Hello everyone: Has anyone found such a situation? Is when the interface of FortiLink is generated, it can not do any firewall policy to other interface.cause FortiLink interface don't show in the firewall policy GUIDoes it mean that Fortigate does not allow any intranet data to communicate with the Fortilink interface, or is it just a bug? P.S. I have tried OS 5.4 , 5.6 , 6.0
hello allapologize in advance for my englishi'm trying to set up ltp2 vpn in my fortigate 60e 6.2, i followed this simple guide and windows connect successfully, i am assigned correct ip range and dns and i can access my internal stuff, but there's not connection to internet, even tho split tunnel is enabledi checked the policies and everything appear to be in order and i can see the user connected in fortigate ipsec monitorif i uncheck “Use default gateway on the remote network” on windows connection setting, navigation works normally but then i can't access internal stuff (what is the vpn even doing at this point?)everything works fine with regular ssl vpn connection with forticlientappreciate any help, thanks
Hi I try to configure firewall policy service select FTP_GET or FTP_PUTbut it doesn’t work
Can we set lease time for SSL VPN IP range? I don’t want same user use different IP if the user disconnect for short period.
I upgraded my FAC from 6.6.4 > 8.0.3 and something has broken EAP-TLS,Users have a cert on their devices, and a profile pushed out to the laptops, that says , connect automatically using the device cert to the SSID, before it connects seamlessly, but now they get a prompt that says “continue connecting?” if you expect to find THIS-SSID in this location, go ahead and connect” then asks you to show certificate details. This didnt happen before the upgrade, I think so far its WINDOWS 10 users only, cannot see anything in the release notes either? help appreciated.
Dear All, I am looking for help to build lab with Fortimanager & Fortigate as I am using permanent Free trail license. Have you ever been used trail license. I tried multiple times by downloading both (Fortimanager & Fortigate) to install & reinstall of Fortimanager & Fortigate permanent Free trail license but did not work any more as expected. Anybody has performed LAB using free trail license so tell me which version. So that I can also build & learn,Grow. Also want to tell you while adding with Fortigate getting error like - unable to add the device with Forti manager. Your response would be highly appreciated. Thank you.
Hello,I am looking for a NetScout Arbor parser for FortiSIEM.Could you please let me know if there is an official or community-supported parser available, or if you can provide guidance on how to obtain or develop one?Best regards,İsmail
Hello, I am using FortiAnalyzer 7.6.5. Under Log View > Logs, I can only see the Log Browse screen. Normal log categories like Forward Traffic, Event, Security Events, Web Filter, IPS, etc. are not visible. Logs are being received by the FortiAnalyzer, and under Log Browse I can see files such as tlog.log, elog.log, etc. The ADOM type looks correct, and there is no issue with admin privileges. In this case, what could be the reason for the normal log categories not being displayed? Could it be related to the Analytics/SQL database, log indexing, or any known issue with FortiAnalyzer 7.6.5? Thanks.
Hello Community, Would appreciate it if someone can point me to the right direction regarding the following. For example lets say there are 2 DoS policy with tcp_syn_flood configured like such (policy ID1 comes before policy ID2) Policy ID 1tcp_syn_flood, threshold 500, Action block Policy ID 2tcp_syn_flood, threshold 50, Action monitor The question isQ1 If policy ID 1 counter registers 400 therefore block was not triggered (below the threshold) will the packets get evaluated by policy ID 2? Regards.
I am creating a solution for a MSP where they intent to build a multi-tenant platform of Sovereign SDWAN and Unified SASE together. We have proposed a unified solution comprising the following:Unified Control and Management Plane:FortiManager, FortiAnalyzer, FortiAuthenticator, FortiNAC, FortiPAM, FortiClient EMS, FortiPortal, FortiGuard FDN (country specific mirror)!!!All the above components will be on-prem.At the Data plane apart from regular FortiGates at HUBs, PoPs and Branches, SASE specific appliances and VMs like FortiProxy, FortiSandBox, FortiDDoS, FortiADC was also considered,!!!At the same time, we are also aware and also customer got some input from Fortinet reseller SE that that Fortinet sell an SKU named FortiSASE Sovereign which is productized solution where FortiSASE Sovereign Orchestrator, FortiSASE Sovereign Web Portal resides in country specific FortiCloud SaaS and that is mandatory.So wanted some idea whether customer need to maintain split model or the original des
Hi everyone,I’m encountering a very specific and unusual issue with a web application login that only occurs within one of our corporate networks. I’m hoping someone has encountered something similar. The Problem:Users at "Site A" can load the website perfectly. However, when attempting to log in, the application returns a "Wrong Credentials" error. The Conflict:Using the exact same credentials from "Site B" (which has an identical FortiGate setup and security policies), the login is successful.Using the same credentials from home networks or mobile hotspots, the login is successful.The issue persists at "Site A" even with FortiClient disconnected. Troubleshooting Performed at Site A (Problematic Site):Security Profiles: Created a top-level "Full Access" policy with zero UTM/Security Profiles (No SSL inspection, no Web Filter, no App Control). The issue persists.SD-WAN & Routing: Forced traffic through a single ISP member using a specific SD-WAN rule to ensure no asymmetric routing
Hello, I understand that the max possible throughput supported by the FG-200G with no inspection is 39 Gbps, IPsec VPN is 36 Gbps, and max Threat protection throughput is 6 Gbps.Does that mean that when enabling the IPSec VPN would consume 36 Gbps out of the total 39 Gbps max possible throughput with no inspection? https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/pdf/fortigate-200g-series.pdf#page=7 Thanks in advance. \Best, ~sK
We have a FortiGate + FortiAuthenticator(bought and registered through a Fortigat partner). We are using the free forticlient vpn, but because it is not getting updates we are looking at fortiems. I downloaded the installer and installed it on Ubuntu. On opening EMS I get a hardware ID which I need to connect to FortiCloud and get the 3 free trial licenses. But I don't see any possibility on FortiCloud to do this.Please point me to the right place to do this.
Forticlient local logs in C:\Program Files\Fortinet\FortiClient\logs go back to installation of client. Is there anyway to set log retention in EMS that doesn’t involve uploading logs to FAZ?
So 7.4.3.8758 was a patchfix version last month. A few days ago they released 7.4.3.4726 and I applied it...and now my patch management is crying that the patchfix version is newer...but it's clearly not.Thanks forti for not knowing how numbers work.
Hello Dears,I’m facing an issue in unlocking csadmin GUI user, does anyone have any idea how to unlock it.Thanks in advance
Hello everyone, From what I understand, the recommended method to register company assets is to integrate LDAP and enable the option where endpoints with the Persistent Agent get automatically registered once users authenticate with their AD credentials.So basically, if a user has the agent installed on their laptop and logs in using AD, the device gets automatically registered, please correct me if I’m wrong here.However, I came across information suggesting this method should mainly be used during the initial onboarding phase and be disabled after. My question is:How are new company users/devices automatically registered after that initial onboarding?Is there a best practice to handle ongoing automatic registration for new assets? Thanks in advance.BR,
Hi,We have Replace firewall 80F to 70G. Afterwards Mac OS based forticlient (7.4.3) unable to connect via IPSec Client VPN. FortiGate 70G firmware: 7.4.11 Windows based forticlient (7.4.0) able to connect via IPsec Client VPN. Error on MAC OS: “connection terminated abruptly . We have logged case in TAC,After remote session they are not getting any root cause analysis Finally, concluded that we have to post this on forums to get any break-fix. As We are using Standalone Version of FortiClient Support is not available for this scenario.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.