User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We are currently using two FortiGate-200G units in an HA configuration with the ha-direct feature enabled.After applying the following NetFlow configuration, we were unable to execute the set netflow-sampler command on the target interface.If there is any way to achieve this, we would greatly appreciate your advice.NetFlow Configurationconfig system netflow config collectors edit 1 set collector-ip "x.x.x.x" set collector-port 9996 next endendAttempted Command on the Target Interfacefw # config system interface fw (interface) # edit port1fw (port1) # set netflow-sampler bothcommand parse error before 'netflow-sampler'Command fail. Return code -61
Hi all,I built a captive portal at the fortiauthenticator and integrated it with MFA.The saml process works well when tested separately in a browser but when the user connect to the SSID it’s not getting redirected properly, an error pops up says “pretty print”.I have only basics in fortinet, can someone help ?fortiauth in Azure , EntraId in Azure, fortigate onprem.User(SSID)—-(AP)——-Fortigate ——-(IPsec)——Azure(Fortiauth+EntraID)
Hello everyone,I am facing an issue with an HA Active-Passive setup using two FortiGate 120G devices (Firmware:7.6.6).The Setup:HA Mode: Active-PassivePriority: FG1 (128) - intended Primary, FG2 (120) - intended Secondary.HA Override: enableMonitored Interfaces: ATC-LACP (802.3ad Aggregate interface connected to a core switch).The Problem: When I reboot the Primary unit (FG1), failover happens correctly, and FG2 takes over. However, when FG1 finishes booting up, it does NOT preempt back to the Primary role. Running get system ha status shows that FG1 is stuck as Secondary with the following warning: WARNING: FG120GTKXXXXXXXX has mondev down;The LACP interface on FG1 stays down. The only way to fix this and trigger preemption is to manually log into FG1 (which is currently the secondary) and flap the interface:Plaintext config system interface edit "ATC-LACP" set status down set status up nextendImmediately after this manual flap, the LACP comes up, the mondev down
I have a new Fortigate 60F that I am setting up. I upgraded the firmware to 7.2.1 and then used the web GUI to restore factory settings to give me a fresh base to work from. After the factory reset, I can see that the 60F is acting as a DHCP on the network, but I have been unable to ping it or access the web GUI to set it up. I don’t have a console cable and it may be difficult for me to get one as I am in a somewhat remote area. Does anyone have any thoughts on what could be causing this behaviour and/or how it could be resolved? Any assistance greatly appreciated.
Hi,When a non Forticlient MacOS user connects to IKEv2 IPSec they have issues with split tunnel DNS.DNS queries are only using the tunnel when using dig and implicitly querying a specific DNS server.This causes issues with other traffic.dig quanza-eun-ufg71.q @172.28.8.53 ~;; QUESTION SECTION:;quanza-eun-ufg71.q. IN A;; ANSWER SECTION:quanza-eun-ufg71.q. 86401 IN A 172.28.8.139;; SERVER: 172.28.8.53#53(172.28.8.53)With IPSec tunnelping quanza-eun-ufg71.qping: cannot resolve quanza-eun-ufg71.q: Unknown hostdig quanza-eun-ufg71.q;; QUESTION SECTION:;quanza-eun-ufg71.q. IN A;; SERVER: 172.20.10.1#53(172.20.10.1)I have checked the debug of the IPSec tunnel initiation and do not see an obvious difference.Both Forticlient and Non-Forticlient connections acquire the DNS servers in the mode-cfg.This issue does not occur with IKEv1
Hello Fortinet Community,I have a question regarding FSSO and Active Directory user visibility in FortiGate logs.Currently, the customer has LDAP/FSSO configured, and user identification works correctly for a LAN segment directly connected to the FortiGate. In those logs, we can properly see the authenticated username along with source IP, destination, and bandwidth usage.However, there are additional user segments that are not directly connected to the firewall. These networks are learned through static/dynamic routing from other network devices. For traffic coming from those routed segments, the logs only show source/destination IPs and traffic usage, but no associated username.My main question is:Can FortiGate/FSSO associate users with IP addresses regardless of whether the network is directly connected or learned through routing protocols?From my understanding, FSSO performs User ↔ IP mapping based on authentication events from Active Directory, so theoretically it should not depen
The vpn is working but the users can’t access the resources because the IP was change All the servers only approved access from the Wan address of the Forti - it's white list The IP of the server - users have to get access to it is 20.101.142.72 Anyone who connected to the VPN would receive their address, and because of that, all they had to do was put the VPN's IP in the WHITELIST and that's it. That's exactly how it works at ROCKET too. Can you help me to fix our problem?
The FortSwitch Ports view on the Fortigate shows just regular access ports where the Fortilink is. Running 7.2.12 and 7.6.4 on the switch.Talked to support and they had a look at the interfaces from the CLI and everything was as it should. This all changed after moving some VLANS around and might have caused a loop which got shut down by STP. IDK if it was related, but it happened right after.Has anyone else seen this happen? Apparently just a bug in the GUI?
Currently, we are using SSL inspection with the "certificate-inspection" profile and have Web Filter enabled.However, since the FortiGate certificate has not been manually imported into the client PCs, users see a certificate error screen when traffic is blocked.We would like to redirect users to a specific page instead of displaying the certificate error page, without importing the FortiGate certificate on the client PCs.If there is a way to achieve this, could you please advise?
Hi,I would like to ask if we can deploy SDWAN with one Internet line and MPLS?My topology:HUB and Spokes have one internet line and one MPLS. The MPLS connect directly between Hub and Spokes. The internet using for VPN between them.I dont want to config VPN via MPLS.Is it possible to deploy sdwan for both VPN and MPLS for steering or control traffic to Dc behind the HUB via both MPLS and VPN?Thank you
I have an explicit proxy test configuration with NTLM authentication;I have the groups configured in the proxy policy, but while I can authenticate on the computer, I can’t browse the web. In the debug log, it shows the error highlighted in the screenshot it’s unable to read the groups but I’ve already verified that communication between my user and the group configured in the proxy policy is working;I’m stuck; I don’t know how to fix this.FortiOS 7.4.11
I have installed FortiClient EMS version 7.4.4 (trial). I deployed this instance as a VM. I am trying to perform an automatic upgrade from the GUI to version 7.4.6. Unfortunately, it keeps showing an update error. In the logs, I see errors and warnings:Err:5 https://dl.winehq.org/wine-builds/ubuntu jammy InReleaseThe following signatures couldn't be verified because the public key is not available: NO_PUBKEY 76F1A20FF987672FWARNING: apt does not have a stable CLI interface. Use with caution in scripts.E: Conflicting values set for option Signed-By regarding source https://apt.postgresql.org/pub/repos/apt/ noble-pgdg: /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc != /usr/share/postgresql-common/pgdg/apt.postgresql.org.gpgE: The list of sources could not be read.Warning: The unit file, source configuration file or drop-ins of redis.service changed on disk. Run 'systemctl daemon-reload' to reload units.___________Please help me resolve this issue.
Hello everyone,I know that Fortinet previously removed the possibility to transfer FortiToken licenses from one FortiGate to another FortiGate.I would like to know if it is still possible to transfer FortiTokens from a FortiGate to FortiAuthenticator now. Has anyone done this recently ?Thanks in advance.BR,
Hi ! Hello everyone: Has anyone found such a situation? Is when the interface of FortiLink is generated, it can not do any firewall policy to other interface.cause FortiLink interface don't show in the firewall policy GUIDoes it mean that Fortigate does not allow any intranet data to communicate with the Fortilink interface, or is it just a bug? P.S. I have tried OS 5.4 , 5.6 , 6.0
hello allapologize in advance for my englishi'm trying to set up ltp2 vpn in my fortigate 60e 6.2, i followed this simple guide and windows connect successfully, i am assigned correct ip range and dns and i can access my internal stuff, but there's not connection to internet, even tho split tunnel is enabledi checked the policies and everything appear to be in order and i can see the user connected in fortigate ipsec monitorif i uncheck “Use default gateway on the remote network” on windows connection setting, navigation works normally but then i can't access internal stuff (what is the vpn even doing at this point?)everything works fine with regular ssl vpn connection with forticlientappreciate any help, thanks
Hi I try to configure firewall policy service select FTP_GET or FTP_PUTbut it doesn’t work
Can we set lease time for SSL VPN IP range? I don’t want same user use different IP if the user disconnect for short period.
I upgraded my FAC from 6.6.4 > 8.0.3 and something has broken EAP-TLS,Users have a cert on their devices, and a profile pushed out to the laptops, that says , connect automatically using the device cert to the SSID, before it connects seamlessly, but now they get a prompt that says “continue connecting?” if you expect to find THIS-SSID in this location, go ahead and connect” then asks you to show certificate details. This didnt happen before the upgrade, I think so far its WINDOWS 10 users only, cannot see anything in the release notes either? help appreciated.
Dear All, I am looking for help to build lab with Fortimanager & Fortigate as I am using permanent Free trail license. Have you ever been used trail license. I tried multiple times by downloading both (Fortimanager & Fortigate) to install & reinstall of Fortimanager & Fortigate permanent Free trail license but did not work any more as expected. Anybody has performed LAB using free trail license so tell me which version. So that I can also build & learn,Grow. Also want to tell you while adding with Fortigate getting error like - unable to add the device with Forti manager. Your response would be highly appreciated. Thank you.
Hello,I am looking for a NetScout Arbor parser for FortiSIEM.Could you please let me know if there is an official or community-supported parser available, or if you can provide guidance on how to obtain or develop one?Best regards,İsmail
Hello, I am using FortiAnalyzer 7.6.5. Under Log View > Logs, I can only see the Log Browse screen. Normal log categories like Forward Traffic, Event, Security Events, Web Filter, IPS, etc. are not visible. Logs are being received by the FortiAnalyzer, and under Log Browse I can see files such as tlog.log, elog.log, etc. The ADOM type looks correct, and there is no issue with admin privileges. In this case, what could be the reason for the normal log categories not being displayed? Could it be related to the Analytics/SQL database, log indexing, or any known issue with FortiAnalyzer 7.6.5? Thanks.
Hello Community, Would appreciate it if someone can point me to the right direction regarding the following. For example lets say there are 2 DoS policy with tcp_syn_flood configured like such (policy ID1 comes before policy ID2) Policy ID 1tcp_syn_flood, threshold 500, Action block Policy ID 2tcp_syn_flood, threshold 50, Action monitor The question isQ1 If policy ID 1 counter registers 400 therefore block was not triggered (below the threshold) will the packets get evaluated by policy ID 2? Regards.
I am creating a solution for a MSP where they intent to build a multi-tenant platform of Sovereign SDWAN and Unified SASE together. We have proposed a unified solution comprising the following:Unified Control and Management Plane:FortiManager, FortiAnalyzer, FortiAuthenticator, FortiNAC, FortiPAM, FortiClient EMS, FortiPortal, FortiGuard FDN (country specific mirror)!!!All the above components will be on-prem.At the Data plane apart from regular FortiGates at HUBs, PoPs and Branches, SASE specific appliances and VMs like FortiProxy, FortiSandBox, FortiDDoS, FortiADC was also considered,!!!At the same time, we are also aware and also customer got some input from Fortinet reseller SE that that Fortinet sell an SKU named FortiSASE Sovereign which is productized solution where FortiSASE Sovereign Orchestrator, FortiSASE Sovereign Web Portal resides in country specific FortiCloud SaaS and that is mandatory.So wanted some idea whether customer need to maintain split model or the original des
Hi everyone,I’m encountering a very specific and unusual issue with a web application login that only occurs within one of our corporate networks. I’m hoping someone has encountered something similar. The Problem:Users at "Site A" can load the website perfectly. However, when attempting to log in, the application returns a "Wrong Credentials" error. The Conflict:Using the exact same credentials from "Site B" (which has an identical FortiGate setup and security policies), the login is successful.Using the same credentials from home networks or mobile hotspots, the login is successful.The issue persists at "Site A" even with FortiClient disconnected. Troubleshooting Performed at Site A (Problematic Site):Security Profiles: Created a top-level "Full Access" policy with zero UTM/Security Profiles (No SSL inspection, no Web Filter, no App Control). The issue persists.SD-WAN & Routing: Forced traffic through a single ISP member using a specific SD-WAN rule to ensure no asymmetric routing
Hello, I understand that the max possible throughput supported by the FG-200G with no inspection is 39 Gbps, IPsec VPN is 36 Gbps, and max Threat protection throughput is 6 Gbps.Does that mean that when enabling the IPSec VPN would consume 36 Gbps out of the total 39 Gbps max possible throughput with no inspection? https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/pdf/fortigate-200g-series.pdf#page=7 Thanks in advance. \Best, ~sK
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.