User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We keep losing the sync between the active and standby yesterday we get working just this morning its out of sync again
Is there any way to set/push a formulated (by a Jinja template) hostname to a secondary FGT in a-p HA from FMG WITHOUT flipping the HA?Or, simply impossible because FMG doesn’t hold the unique part of secondary devices, like host name, ha config?Toshi
Team i dont no why, but we keep on loss sync, yesterday we work with support up and get up working, just this morning the pri firewall is out-of-sync with the sec firewall any idea
Hi everyone,We are observing an issue on a FortiGate running FortiOS 7.6.7.Whenever an administrator logs into the firewall GUI, warning-level event logs are generated with the following message:"CMDB get request for sensitive information table"Immediately after these events, we observe a noticeable increase in CPU utilization on one or more CPU cores.The behavior is consistently reproducible during admin login sessions.Observations:FortiOS Version: 7.6.7 Warning log generated during GUI login activity. CPU core utilization increases shortly after the log is generated. No significant configuration changes were made prior to the issue. The behavior appears to be related to GUI access and CMDB queries.Any insights or recommendations would be greatly appreciated.
Download links for FortiClient EMS invitations are not working because the filename in the invitation are Initial Cap, while the filenames are all lower case. Running version 7.4.8. This was working up to yesterday.
Hello All,I am currently using switches from another vendor, where all default gateways for the end-user VLANs are configured on the switches. The switches have a default route pointing toward the FortiGate.I am planning to replace these existing switches with FortiSwitches. However, my concern is that when using FortiLink, the recommended Fortinet design is to place the VLAN default gateways on the FortiGate.Is it possible to use FortiLink to manage the FortiSwitches while keeping the existing design, where the default gateways for all end-user VLANs remain on the FortiSwitches, with the FortiSwitches using a default route toward the FortiGate?I would like to understand whether this design is supported and, if so, what limitations or configuration considerations I should be aware of.
We recently started investigating roaming behaviour on a customer environment using FortiAPs with WPA3-Enterprise and an external RADIUS server.The initial observation was that roaming did not appear to behave like a Fast Transition (802.11r) roam. During movement between access points, clients seemed to perform a complete authentication process again instead of using a fast handoff. This resulted in noticeable delays compared to what we would normally expect from an 802.11r-enabled deployment.To validate this, we captured both beacon frames and association traffic on the customer environment. In the captures, we noticed that clients were performing normal WPA3-Enterprise authentication exchanges after roaming. When we examined the beacon frames more closely, we found that the WPA3-Enterprise SSID advertised only the standard WPA3 Enterprise AKM. We could not find any indication of FT over IEEE 802.1X or a Mobility Domain (Tag 54) element.To rule out environmental factors, we rebuilt t
Hello Fortinet Community,I am currently configuring email-based MFA on a FortiGate running FortiOS 7.4.11 as part of a POC.I am using Brevo as the external SMTP service. SMTP authentication works, but I am having an issue with the sender/from address. The FortiGate appears to use the same email address configured as the SMTP authentication username, and I have not found a way to configure a different sender address.Has anyone encountered this behavior?Is there any workaround in FortiOS 7.4.11 to specify a different From/Sender address? Has anyone successfully implemented FortiGate email MFA using Brevo or another external SMTP relay? Would Microsoft 365 SMTP be a better alternative for this scenario? Has anyone successfully configured it for FortiGate MFA emails? Are there any recommended SMTP services or configurations for this use case?Any guidance or working configuration examples would be appreciated.Thanks in advance.
I have mac ip phone with mac addr 00:21:A0:2C:22:33 and if i test manually profiling then the rule is matchThe DPR will automatic register and move the device to role IPPHONEBut when i check on the host then i can see the role is empty, seem the DPR is not running event the rule will run ‘On Connect’ and every 5 minutes. Anyone know how to solve this?
Hi,Been digging through the EMS REST API on 7.4.8 and 8.0.0, and it looks like a wall, but better to ask before building the wrong thing.The need is simple enough: individual security events from endpoints — a malware hit, a web filter block, a vulnerability finding — each with its own timestamp, to pull into our SOC tooling.What exists is /api/v1/endpoints/index with the event_type filter (antivirus, antiransomware, webfilter, vulnerability, quarantined, pua, and the rest). Genuinely useful, but it answers "which endpoints have an antivirus event" rather than "what happened, and when". Great for a posture dashboard, less so for feeding alerts. The CSV export looks like the same view with the same filters, just asynchronous.All 15 modules in the API reference turned up nothing event-shaped. So: is there an endpoint hiding somewhere, or is this simply not what the EMS API is for? And if it isn't, is syslog out of EMS (or going through FortiAnalyzer) how everyone else solves this? One mo
Hi all,I’m troubleshooting a remote access IPsec issue on a FortiGate 200F running FortiOS 7.4.12 and wanted to see if anyone else has run into something similar.When NAT-T is enabled, remote users get noticeable packet loss / stalls over the tunnel during normal traffic — pings, file transfers, throughput tests, that kind of thing. When NAT-T is disabled, it gets a lot better.A few things I’ve already confirmed:the tunnel comes up fine the issue is reproducible when NAT-T is enabled the issue improves significantly when NAT-T is disabled I tested with NPU offload both enabled and disabled with offload enabled, tunnel error counters were higher on the problematic tunnel with offload disabled, those RX errors were much lower or zero in my captures, but the user-visible stalls still weren’t fully explained by the lower-level counters PDQ snapshots looked balanced during testing HPE dropping stayed at 0 in the snapshots I collected anomaly-drop output was empty we also contacted our ISP a
I am trying to create a FortiAnalyzer report that displays Sent and received interface bandwidth utilization over time for the Fortigates.The existing reports available in FortiAnalyzer provide data utilization using 5-minute averages, but they do not clearly identify the utilization for each individual interface.Below are multiple topics in the community:https://community.fortinet.com/support-forum-92/need-bandwidth-utilization-report-between-two-fortigate-devices-specific-interface-time-range-224155https://community.fortinet.com/fortianalyzer-6/technical-tip-how-to-generate-throughput-utilization-billing-report-98335https://community.fortinet.com/support-forum-92/fortianalyzer-how-to-generate-a-report-for-real-time-bandwidth-out-to-in-33756https://community.fortinet.com/support-forum-92/generate-bandwidth-utlization-report-for-specify-interface-in-faz-197578?tid=197578&fid=92As a possible solution, I enabled performance statistics on the FortiGate. FortiAnalyzer is now receiving
Hi everyone,We are running a FortiClient ZTNA Access Proxy deployment for our UAT environment and have run into a persistent connection loop immediately following the latest Fortinet ZTNA update. We are looking to see if anyone has hit this specific behavior or has a confirmed Bug ID/Workaround.🚨 The Symptoms Error Encountered: ZTNA Application Not Found (Error Code: 022) with the message Client certificate is not provided. Device Information: N/A. Behavior: It only affects users connecting from external networks (off-fabric). Internal corporate network connections work fine. The Loop: When we perform clean reinstalls or manual re-registrations, it works perfectly for exactly 2 hours, and then abruptly drops back into Error 022. 🛠️ Troubleshooting & Root Cause Analysis Done So FarWe have thoroughly mapped out the behavior and ruled out basic configuration errors: The 2-Hour Pattern & Compliance Discovered: * The 2-hour survival window strongly pointed to a periodic server
Hi there, I’m having issue with matching Fortigate Proxy Policies against user group membership using AD DC2. Currently I have Active Directory with 2 DC’s. I have separate ldap connections to them (because of scale of organization, and the need to granulary test the migration between them. Fortigate is configured to use Explicit Proxy and we are allowing AD groups to access specific websites in Proxy Policies.When users workstations use DC1 as primary DNS server - everything works (they can access sites allowed in polices) but after switching them to DC2 - they can’t access any website specified on Proxy Policies and fall to implicit deny. We tried switching massively - didn’t work, and we tried switching single/few groups with same result. How we perform the tests on dedicated workstation:Test workstation is joined to Domain Test workstation switches DNS server from DC1 to DC2 (currently for more than 3 weeks the station has DC2 setup as primary DNS without any other DNS servers) Tes
This is a head scratcher…..I am a network infrastructure professional services engineer. I support a few dozen customers, many of which use Fortinet products. I run VMware workstation on my laptop, and have a different VM dedicated to each of my customers with their VPN solution installed on their VM. Each VM is a clone of the same base Win11Pro system. My problem is specific to one and only one of my customers.I have no trouble connecting any of my customers except for one, Customer-X. Customer-X has two sites, each with a FortiGate and DIA. One of them is still running FortiOS 7.2 and is allowing SSLVPN (Site-A). The FortiGate at their other site (Site-B), has been upgraded to FortiOS 7.4 and has been configured to allow IPSec remote access VPN. The VM I run for this customer is a standalone Windows11 install (not domain joined). After launching the VM, I have full internet access without any detectable issues. Inside of Customer-X’s VM, the public IP reported by whatismyipa
Hello,We are experiencing an issue in our environment with FortiNAC and would like to understand the root cause.EnvironmentFortiNAC Aruba Access Switches 802.1X enabled on switch ports Printers and endpoints authenticated through FortiNAC Wired environmentIssue DescriptionWe have several devices, including network printers and some user laptops, that intermittently lose network access.Symptoms:Device works normally for a period of time. After some time (sometimes a couple of days), the device loses network connectivity. The switch port remains physically up. Reconnecting the cable does not resolve the issue. As soon as we manually perform "Register as Device" (or re-register the host/device) in FortiNAC, connectivity is immediately restored. No switch configuration changes are required for recovery.This behavior affects both:Printers Wired laptopsObservationsDuring troubleshooting, we noticed that some affected hosts show:Last Modified By: Systemshortly before or around the time the de
Hello all. We are rolling out 7.4.2 to our Mac fleet. We are seeking a way to do this via automation to auto-enable the system extensions so that when our JAMF instance touches our devices, it will install automatically. We are seeking to do this via PKG or DMG. Is this possible?
Dear All, Anybody can explain in laymon term what is under lay and over lay in SDWAN concept and how does it work. Why under lay and over lay need. Thank you in advanced for sharing the knowledge.
Hello, I recently updated FortiClient on a laptop to version 7.4.3.1790. Since then, the VPN has been unable to connect, and the Fortinet virtual adapters show as "Unknown Device" in the Windows 11 Device Manager. Every time I reboot the laptop, a FortiClient popup appears and says that FortiClient drivers have been installed that require a restart to finish. Each restart adds two more Unknown Devices in Device Manager. A reinstall or repair of FortiClient doesn't fix the issue. I've tried reinstalling Visual C++ 2015-2022, but no luck there either. The two virtual adapters are supposed to show as:- Fortinet SSL VPN Virtual Ethernet Adapter- Fortinet Virtual Ethernet Adapter (NDIS 6.30) How can I fix these two virtual adapters? Thanks,Simon
Is there anyway for RSAT tools to work with ZTNA? Users can get to domain controller via ZTNA but RSAT tools is not working.
HI all, I’m deploying a couple of 701G fortient onver an inter DCI (one fortinet on each DC) using vxlan (on a nexus 9k) and I found that when HA is enabled the same MAC are generated and for this reason this MAC’s are getting dropped from vxlan table and HA is not forming. If HA is disabled and I leave them as stand alone and put IP’s on the interfaces they can ping each other (the same for mgmt) once HA is enabled and the virtual MAC’s come in the connectivity on HA is not working and both MGMT can’t ping each other anymore and I have a duplicated messaje on my nexus logs. Does anyone know what could be wrong? Working on a 7.4.11 Regards
Hi erveryone,We use the FortiMail only as a filter.The MTA is provided by an external service provider.The FortiMail is therefore between our service provider and our internal mail server.We have deactivated the SPF check in the Antispam and in the Session Profile, because this is not needed in our construct.Nevertheless we get in the log for most mails a SPF Fail/Softfail with the message "that MTA (IP address) is/may not permitted to send email for ....".The mails are processed and sent correctly but this log entry bothers us.We are aware that the external MTA will normally trigger SPF since the mail is not sent from the original mail server to FortiMail.Is it possible to disable the entry, it is not relevant for us or is there another hidden setting somewhere that enables SPF checking?Are any of you aware of a similar problem or could it be something else? Thank you in advance!!
I have a strange case with some fortiAPs right now. 1x FAP 231G and 1x431F both on 7.6.4. I want to set a VLAN ID to have the management tagged but the variable is missing when typing cfg -s. Then i connected to the HTTPS GUI and the field is also missing. I typed in the command cfg -a AP_MGMT_VLAN_ID=200 on the CLI and I got no error. cfg -c for commit to flash. Nothing happened. Reboot and still no change, the AP won't take the VLAN ID. I have 100 more 231G on this site and also 20x431F and they all have the variable and it works fine. How is this possible? Anyone else encountering this problem?
I have a problem with FortiClient VPN 7.0.8.0427 on a few Windows PCs. When trying to connect I get:‘VPN Connection Failure - VPN connection failed. Please check your configuration, network connection and pre-shared key then retry your connection. If the problem persists, contact your network administrator for help.’The VPN does not work with any user account on the affected PC. The same users, the same VPN profile and the same FortiClient version work correctly on other computers. The problem was already present on a fresh Windows installation, so it is not caused by software installed later. Reinstalling FortiClient also did not help.Basic network connectivity looks fine. Internet connection works, the FortiGate is reachable and the client can communicate with the VPN gateway. I tested both Ethernet and Wi-Fi with the same result. Packet capture confirms that UDP/500 traffic reaches the FortiGate and the FortiGate response comes back to the affected PC.I also tested several other lap
Hi all, I have peaks of high CPU usage on the FortiSwitches FS-248E model. Theses FortiSwitch are in modo fortilink.The event is the following: How can I lower CPU usage? Currently very few customer traffic.Thanks,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.