Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I forgot the password of my FGT 300C thats why I needed to reset the password via cli using the ff commands. However I got an error " User must have a profile object set operator error, -56 discard the setting Command fail. Return code -56" how to add profile for admin? Welcome ! New_FG300C~ # config system admin New_FG300C~ (admin) # edit admin new entry ' admin' added New_FG300C~ (admin) # set password password123 New_FG300C~ (admin) # end User must have a profile object set operator error, -56 discard the setting Command fail. Return code -56
We have on-prem FortiClient EMS server (7.2.x) which is an application that runs on a Windows Server. It does not appear to support SNMP. Other than just ICMP , any suggestions on the best way to monitor the EMS server?
I hve a FortiGate 60F and when I console to it I have a message that Password reset functionality is disabled. WhenI try using maintenance mode or the hard reset button it does not working. What options do I have to get in this device? If I have to reset it fully I will as long as I can get into it.
have a FG 70G 7.4.12 and a windows client with free VPN 7.4.3.4726I have followed the doc:https://docs.fortinet.com/document/fortigate/7.4.12/administration-guide/785501 but when I try to connect, the client says “Timeout while connecting” I have diagnose sniffer packet wan1 "udp and port 500" running, and see 4 packets every time I try to connect like:19.844532 1.247.132.25.1012 -> 214.153.140.239.500: udp 668The odd part (to me) is that I do not see anything in the GUI System Events > VPN Logs >Memory.I’ve made sure the proposals match on both sides.I’ve done this before multiple times on 7.2 and older, and never had these kinds of problems.Any suggestions?
After upgrading our FortiGate device from FortiOS version 7.6.6 to 7.6.7, users at the branch lost internet access when the BambiDeep SSL/SSH Inspection profile (Deep Inspection) was used in the firewall rule.Traffic is allowed by the firewall rule, and NAT is working properly. However, HTTPS connections fail when Deep Inspection is enabled.As a temporary solution, we changed the SSL/SSH Inspection profile from BambiDeep (Deep Inspection) to Certificate Inspection, and internet access was immediately restored. The first rule includes certificate inspection, and internet access works fine, but the second rule is the old one and includes “BambiDeep” SSL inspection; after the firmware upgrade, internet access is not working. Also ı tested the problem on new rule by adding BambiDeep SSL inspection ant internet acces is not working. Are they any known issue about 7.6.7 version for tihs topic ?
Previously, with FortiClient version 7.2.13, when users initiated the VPN connection using SSO, FortiClient automatically detected the existing sign-in sessions for the customer's corporate accounts. When the authentication window was displayed, the available accounts were presented for selection, allowing users to authenticate without re-entering their credentials.However, after upgrading FortiClient to version 7.4.3, this behavior has changed. When using FortiClient's embedded browser for SSO authentication, users are always prompted to enter their username and password. The embedded browser no longer detects existing Microsoft Entra ID (Azure) sessions or displays the available signed-in accounts.On the other hand, we have verified that when FortiClient is configured to use an external browser for SSO authentication, the expected behavior is observed. The external browser correctly detects the existing Microsoft Entra ID (Azure) sessions, displays the available corporate accounts,
ScenarioEnvironment with multiple FortiGate firewalls connected to a FortiAnalyzer VM for centralized log collection and analysis.Environment VersionsFortiAnalyzer VM: 7.4.11FortiGate: 7.2.13Fabric ADOM enabledSome FortiGate devices operating in HA cluster modeAfter upgrading the FortiAnalyzer from version 7.4.6 to 7.4.11, the FortiGate devices stopped displaying FortiAnalyzer logs directly from the FortiGate GUI.SymptomsWhen accessing logs from the FortiGate GUI:Log & Report → Forward Traffic / Event Logsthe page remained completely blank.However:FortiAnalyzer continued receiving logs normallyDevices remained online in Fabric View / Device ManagerLogs were visible directly in the FortiAnalyzer GUINo explicit communication or authorization errors were displayedAdditionally, the following behaviors were observed:Analytics (actual/config days) above 100%Archive Usage above 90%diagnose dvm device list showing:conn: unknownconf: unknowndev-db: unknownThis initially suggested a possible
I have recently installed a HA pair of FG-71G (v7.6.6). The standby firewall shows the interface status changed as shown below, but there is no log at the switch / firewall the ports connected to. The interface counter seems normal for both sides. I have already replaced the physical cables but problem persists. Any idea if it is a firmware issue or the firewall is faulty? Thanks.
how to delete synced ztna application
I need to configure our environment for both single and multi-user, domain and workgroup (personal) computers.. Ideally we want absolutely no user interaction required for the shared domain pc's, at any point. These are EntraID or hybrid-joined, managed by Intune. They don't need different configuration profiles based on the user login, although we would still want to track who is logged in of course. However, auto-registration appears to only occur once during initial installation. When another user logs in, FortiClient reverts to being unregistered for that user, requiring them to enter an invite code. I would have thought it would attempt auto registration again and perform SAML user verification automatically, but it does not.We need to keep the shared devices as free from user interaction as possible, while still securing against rogue installs. Is there a different way to go about this?
We are configuring SAML authentication on our FortiGate firewall to authenticate users before applying internet access policies.Our requirement is:The first firewall policy should only trigger SAML authentication.After successful authentication, no services should be accessible through this rule.Once authenticated, subsequent policies should apply access rules for the authenticated user/group.To achieve this, we created an authentication-only policy with the following configuration:Source: allDestination: Internet ServicesInternet Services used:Microsoft-AzureMicrosoft-Azure.Front.DoorMicrosoft-Office365.PublishedAfter applying this configuration, SAML authentication works correctly when the authentication process is triggered.However, we are facing the following issue:When users open a browser and try to access Microsoft-related services (for example: office.com, outlook.com, etc.), the SAML authentication page does not appear.The browser waits for some time and eventually the webpage
We need your urgent assistance in troubleshooting an issue with our ADVPN deployment.Network Topology1 Data Center1 Head Office6 Branch Offices (Total: 8 locations)We have configured ADVPN for Hub-to-Spoke connectivity. Initially, each spoke had a single leased line, while the hub had dual leased lines. Two Hub-to-Spoke IPsec tunnels were established from the hub side, and the spoke had a single ISP. This setup worked without any issues.Recently, we added a second leased line at every spoke site for redundancy. Now, each spoke has dual ISPs, and both Hub-to-Spoke IPsec tunnels are established successfully. Routing is configured using loopback interfaces over iBGP.Issue DescriptionThe issue occurs only when the old ISP at a spoke goes down and traffic fails over to the new ISP.Although the IPsec tunnels remain UP, Hub-to-Spoke communication becomes unstable. During failover, we observe the following behavior:Sometimes the spoke loses reachability to the Data Center Hub, while the Head O
We wanted enable auto backup of Fortigate firewalls from Fortimanager to FTP server.Please guide.
We are using the free version of FortiClient VPN, and I have found that with both an older version of FortiClient, both 7.4.3.1790, and the latest version, 7.4.3.4726, I am getting the error in the attachment occasionally when fortiauth,exe loads to prompt for credentials to connect. It even does this after I removed and re-added Net 4.8 as a windows feature. Any thoughts? That I know of it is just my machine, but I work fully remote, so I really need to get this resolved.
Hi, we use Transparent Proxy Policies for destination FQDN's only, but I can't really understand why would we do it if we can just stay with the IPv4 Firewall Policy and apply all security profiles there.Can someone explain the differences in behaviors? as traffic needs to match the IPv4 Policy first anyway and I can't see any real benefit just management overhead.
Hi everyone,I'm new to the community and I'm preparing to take the NSE 4 exam soon.While reviewing the guide and testing some scenarios in the lab, I noticed what seems to be an inconsistency in the documentation.The guide states:"Administrative access options are also limited depending on the role that is set for the interface. For example, setting the interface role to 'WAN' would not display the 'Ping' option, mitigating the risk of responding to a DoS ICMP attack from the WAN."However, even when I set the interface role to WAN, the Ping option is still available.Has anyone experienced the same behavior or can explain why this happens? Is this a known behavior or perhaps a change in the latest version?Thanks in advance for any clarification!
Our cyber insurance company is running an internal pen test, and I wanted to see what others do when FortiDeceptor is running. My plan was to say nothing but add their IP to the safe list to prevent them from getting locked out mid-test. Then, when they find one, I will disclose it if they report it as a finding.On the other hand, I feel that I am lowering my security for them, so I am torn on what to do. Any pen testers or people with FortiDeceptor out there who have had a similar issue?
I have setup and enabled SSO into our FortiVoice system using Google Workspace. Everything appears to be configured correctly, and Google is returning the email address in the SAML data. However, it never actually logs on. I have tried this configured for both the admin side, as well as the user side. I type in my extension, it redirects to the Google login page, I select the email account tied to that extension, and it just returns to a login page ending in voicesso. I have exhausted my ability to locate the issue and thought it might be something simple I am overlooking. We are currently running FortiVoice version 7.2.4 if that helps any.I appreciate any ideas anyone might have.
The FortiClient VPN-only version 7.4.3.4323 has been installed onto a MacBook running macOS 26. Full disk access has been given to fctservctl2 and the network extension FortiTray has been enabled although FortiClientProxy and FortiClientPacketFilter were not present to enable. The settings for this VPN use the public IP address of the FortiGate and various DH Group and encryption levels have been tried but all to no avail. The VPN connection is IPsec VPN and tries connecting for a while then comes back with a connection timeout error. The native IKEv2 client for macOS does not work either. I read somewhere that Fortinet added macOS Tahoe 26 support in FortiClient 7.4.5 but there is no VPN-only version later than 7.4.3. I have also read that SSL-VPN support is being stopped so surely there needs to a new VPN-only version where IPsec VPN can be used. Is there ever going to be a newer VPN-only version released? Or is the option available now FortiClient Standalone? This does not seem to b
My WAN utilization is full (total 20Mbps), how we can easily which source is consume high bandwidth?I try to block the graph and click fortiview source and destination and if i compare with the Netflow from my NPM then the source is different.
Hi I am using ssl inspection on my lab.I have downloaded the certificate from fortigate and installed it on windows trusted store and on Firefox.but still have the certificate warning problem ! What do i miss?
Hi FWB adminsFortiWeb 8.0.6, I set it up as SP.When I try run SAML debug as documented in admin guide and perform SAML authentication, I get redirection to SP but I get nothing in debug output.diagnose debug application samld -1 (or 7)diagnose debug enable<output empty>Is there something else to enable in order to make SAML debug work? Any help would be appreciated.
Hello, I have network of around 7 APs. FortiAP FAP431F. I manage them through forticloud. I have an SSID that I want all APs to broadcast it, except one. How can I do that? In the availability page in the SSID configuration, I have the option of “Available to all APs” or “Available to the APs with the following AP tags”. I could not find anywhere in forticloud anything about AP tags. How can I do this? Thank you.
I am looking to set up two separate SSL-VPN access connections, that would by used by two separate groups, both groups are using the same Fortinet device in one domain. (Example:) Group One: Bill is the admin of the Marketing group and supports 10 users.Group Two: Zach is the admin of the billing group and supports 10 users. I want to make sure that both groups can access the VPN through separate IP address and separate ports. Environment FortGate 101D, Firmware 7.2.10. Thank-you
Hello Fortinet community,I am a Systems and Network Administration student working on my final-year thesis on"Implementing sandboxing technology for proactive security of incoming network flows."I need access to a FortiSandbox image for lab testing and practical research. I do not have a commercial serial number with support.Could anyone advise if there is an academic or evaluation image available, or guide me on how to obtain one for student research purposes?Thank you very much for any assistance.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.