User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello Community, Would appreciate it if someone can point me to the right direction regarding the following. For example lets say there are 2 DoS policy with tcp_syn_flood configured like such (policy ID1 comes before policy ID2) Policy ID 1tcp_syn_flood, threshold 500, Action block Policy ID 2tcp_syn_flood, threshold 50, Action monitor The question isQ1 If policy ID 1 counter registers 400 therefore block was not triggered (below the threshold) will the packets get evaluated by policy ID 2? Regards.
I am creating a solution for a MSP where they intent to build a multi-tenant platform of Sovereign SDWAN and Unified SASE together. We have proposed a unified solution comprising the following:Unified Control and Management Plane:FortiManager, FortiAnalyzer, FortiAuthenticator, FortiNAC, FortiPAM, FortiClient EMS, FortiPortal, FortiGuard FDN (country specific mirror)!!!All the above components will be on-prem.At the Data plane apart from regular FortiGates at HUBs, PoPs and Branches, SASE specific appliances and VMs like FortiProxy, FortiSandBox, FortiDDoS, FortiADC was also considered,!!!At the same time, we are also aware and also customer got some input from Fortinet reseller SE that that Fortinet sell an SKU named FortiSASE Sovereign which is productized solution where FortiSASE Sovereign Orchestrator, FortiSASE Sovereign Web Portal resides in country specific FortiCloud SaaS and that is mandatory.So wanted some idea whether customer need to maintain split model or the original des
Hi everyone,I’m encountering a very specific and unusual issue with a web application login that only occurs within one of our corporate networks. I’m hoping someone has encountered something similar. The Problem:Users at "Site A" can load the website perfectly. However, when attempting to log in, the application returns a "Wrong Credentials" error. The Conflict:Using the exact same credentials from "Site B" (which has an identical FortiGate setup and security policies), the login is successful.Using the same credentials from home networks or mobile hotspots, the login is successful.The issue persists at "Site A" even with FortiClient disconnected. Troubleshooting Performed at Site A (Problematic Site):Security Profiles: Created a top-level "Full Access" policy with zero UTM/Security Profiles (No SSL inspection, no Web Filter, no App Control). The issue persists.SD-WAN & Routing: Forced traffic through a single ISP member using a specific SD-WAN rule to ensure no asymmetric routing
Hello, I understand that the max possible throughput supported by the FG-200G with no inspection is 39 Gbps, IPsec VPN is 36 Gbps, and max Threat protection throughput is 6 Gbps.Does that mean that when enabling the IPSec VPN would consume 36 Gbps out of the total 39 Gbps max possible throughput with no inspection? https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/pdf/fortigate-200g-series.pdf#page=7 Thanks in advance. \Best, ~sK
We have a FortiGate + FortiAuthenticator(bought and registered through a Fortigat partner). We are using the free forticlient vpn, but because it is not getting updates we are looking at fortiems. I downloaded the installer and installed it on Ubuntu. On opening EMS I get a hardware ID which I need to connect to FortiCloud and get the 3 free trial licenses. But I don't see any possibility on FortiCloud to do this.Please point me to the right place to do this.
Forticlient local logs in C:\Program Files\Fortinet\FortiClient\logs go back to installation of client. Is there anyway to set log retention in EMS that doesn’t involve uploading logs to FAZ?
So 7.4.3.8758 was a patchfix version last month. A few days ago they released 7.4.3.4726 and I applied it...and now my patch management is crying that the patchfix version is newer...but it's clearly not.Thanks forti for not knowing how numbers work.
Hello Dears,I’m facing an issue in unlocking csadmin GUI user, does anyone have any idea how to unlock it.Thanks in advance
Hello everyone, From what I understand, the recommended method to register company assets is to integrate LDAP and enable the option where endpoints with the Persistent Agent get automatically registered once users authenticate with their AD credentials.So basically, if a user has the agent installed on their laptop and logs in using AD, the device gets automatically registered, please correct me if I’m wrong here.However, I came across information suggesting this method should mainly be used during the initial onboarding phase and be disabled after. My question is:How are new company users/devices automatically registered after that initial onboarding?Is there a best practice to handle ongoing automatic registration for new assets? Thanks in advance.BR,
Hi,We have Replace firewall 80F to 70G. Afterwards Mac OS based forticlient (7.4.3) unable to connect via IPSec Client VPN. FortiGate 70G firmware: 7.4.11 Windows based forticlient (7.4.0) able to connect via IPsec Client VPN. Error on MAC OS: “connection terminated abruptly . We have logged case in TAC,After remote session they are not getting any root cause analysis Finally, concluded that we have to post this on forums to get any break-fix. As We are using Standalone Version of FortiClient Support is not available for this scenario.
I only have 1 non-prod switch I can use, and I upgraded from 7.2.0(?) to 7.4.7After upgrade, web GUI just showed Server Error 500, although I could still ssh into the switch.After switching boot to the secondary partition (still on 7.2.0) I was able to get back into GUI. I then upgraded incrementally, and all versions worked until 7.4.6. Trying to upgrade from 7.4.6 to 7.4.7 again gave me Server Error at the GUI.Is anyone successfully using 7.4.7 on 1048E platform?
I am attempting to access the web GUI for a standalone FortiSwitch 124E-FPOE running 7.4.7. However, I am getting a “500 Internal Server Error” from multiple machines and browsers, even after a reboot (done via SSH CLI).I attempted to follow the instructions here: to get more information, but the only thing displayed in the shell is:acces_res_check.c [ 88] : Received '/access_res_check' request from '<source_ip_redacted>’ None of my searches have found anything I can do to resolve the issue. Any support would be greatly appreciated.
Hey, I've added more than five FortiGate devices with the same firmware version to the newly deployed FortiAnalyzer (using the default certificates, without adding any custom certificate) and did not experience any issues. However, when I try to add one more FortiGate I receive an SSL error (-3). The FortiGate devices that I was able to add and the one that I can't add, all have the same remote ca certificates. There is no connection issue between them by the way, traffic is flowing both ways.
I have both 441’s and 443 in the same building. The 441’s will fire up 6GHz just fine, but the 443’s will not assign a channel.Power is OK - Two PoE+ connections - Current Power Mode: full (2) Oper Power Mode: full (2)AFC State is downCountry is set to USSupport is asserting that the 443 must have GPS location data in order for the 6GHz radio to operate, although it’s not needed on the 441. The claim is that since the 443 has detachable antennas, the FCC states it “must operate in SP mode” (Standard Power) instead of LPI (Low Power Indoor) - therefore needing GPS data “proving” its presence in a region allowing such higher power operation.Behavior on the 443’s is consistent regardless of firmware version - we’ve tested on v7.6.4 build1078, 7-1092, and 8-0022 - all the same.cw_diag -c afc status does, however, indicates an LPI power mode:AFC is configured on 6GHz radio 2 AFC State : down Cfg Country : US (841) Regdomain : 0x90000 Power Mode : None Cur Pwr Mode:
EnvironmentFortiClient VPN version: 7.0.14.0585 Windows desktop PC CPU: AMD Ryzen 9 9900X Motherboard: X870E AORUS PRO ICE RAM: 64 GB Windows 11 x64 FortiClient SSL VPNProblemThe VPN disconnects after around 20 minutes of use It is not exactly 20 minutes, just approximately After it disconnects, I cannot reconnect immediately I usually have to wait around another 20 minutes before it will connect again The problem happens only on this specific PC I installed the same FortiClient / used the same VPN profile on another computer, and it does not disconnect thereWhat I already testedReinstalled FortiClient Tried the newest available FortiClient version The issue still happens only on this machineFortiClient log behaviorThe FortiClient logs repeatedly show messages like:Broken pipe! Client is exited (3) g_hEventExit set FortiSslvpnD: PipeServerProc exitsThis makes me think the client side is breaking locally rather than the FortiGate cleanly rejecting the session.Windows events around the d
Are we able to update an extension display name or description field using API calls?
Hello everyone, I would like to know, will I have issues with the persistent agent if I use Fortinac’s Self signed certificate ? BR,
Hello,In the current version of FortiClient VPN-only, the backup and restore function is broken. Although you can select a file and enter the password, nothing happens when you click “OK.”Conversely, when restoring (a backup from before the upgrade), you can select the file, but even then nothing happens (and there's no mention of it in the logs either). Configuration Backup→ nothing happens when you klick OK (menu is closed but no file created) The version numbers don't quite add up either (to me, it just looks like it was thrown together quickly and hasn't really been quality-checked):Tray: Tray Version Info: 7.4.3.4726GUI:GUI Version Info: 7.4.3 hotfix 1.8758
HelloI have over 100 sim cards in private APN. Between my company network and t-mobile is VPN tunnel. I wonder if is any method to monitor bandwidth ussage per sim over snmp. I used Zabbix to monitor our network infrastructure and I would be happy if it was possible to monitor bandwidth consumption for particular cards in Zabbix. At the moment, only what I can monitor is all traffic through the VPN interface which is not very helpful in diagnosing problems. RegardsJN
I started the upgrade from EMS 7.4.5 to EMS 7.4.6 and am now stuck for more than 24 hours in 50% loop. And I am getting emails almost every 20 minutes, that the upgrade is scheduled. EMS is scheduled to be upgrade on 2026-March-23 06:01 (EMS server time). The current version 7.4.5.2111 will be upgrade to version 7.4.6.2170 (M). Any ideas how to exit the loop?
greetings everyonei’m trying to configure the FortiPAM custom launcher for Visual Studio Code SSH extension (Remote - SSH)i tried multiple parameters with no success so fari would really appreciate it if anyone know the correct configuration to make this happen successfullyyour support is highly appreciated
We are planning to replace our current FortiGate device, and we have found that the following configuration is enabled on the existing unit:config system settings set h323-direct-model enableendWe understand that this option is related to VoIP functionality. However, we would like to know how FortiGate's behavior changes when this setting is enabled.Could you please advise on how we can verify or confirm the behavioral differences caused by enabling this configuration?
Hi!Whilst I can see in historical logs and by real-time IKE debugging, I want to see whether existing Child SA was locally initiated (Role: initiator) or remotely (Role: Responder) using CLI command. This fundamental information - perhaps I missed it. Is there such.Thanks!
Dear All, I was trying to delete Ipsec tunnel which was earlier configured with SDWAN. The below procedure which I have used during the deleting all the reference from IPsec tunnel. 1. Tunnel was member of SDWAN Zone. I have removed the tunnel interface from SDWAN ZONE.2. Deleted static route.3. Deleted phase 2 selector.Next I was unable to delete tunnel. What I have observed during the tunnel. After all the deleting references. tunnel itself moved into default SDWAN ZONE which was created for WAN interfaces (Virtual-WAN-ZONE). My question is which tunnel moved into default virtual-wan-zone after deleting the references. Thank you.
i am using fortinet 40f . bridging has done from my isp. but while creating VIP for my yeaster s20. RTP port 10000-12000 i cant put this value on my port specifying area
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.