User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi!Whilst I can see in historical logs and by real-time IKE debugging, I want to see whether existing Child SA was locally initiated (Role: initiator) or remotely (Role: Responder) using CLI command. This fundamental information - perhaps I missed it. Is there such.Thanks!
Dear All, I was trying to delete Ipsec tunnel which was earlier configured with SDWAN. The below procedure which I have used during the deleting all the reference from IPsec tunnel. 1. Tunnel was member of SDWAN Zone. I have removed the tunnel interface from SDWAN ZONE.2. Deleted static route.3. Deleted phase 2 selector.Next I was unable to delete tunnel. What I have observed during the tunnel. After all the deleting references. tunnel itself moved into default SDWAN ZONE which was created for WAN interfaces (Virtual-WAN-ZONE). My question is which tunnel moved into default virtual-wan-zone after deleting the references. Thank you.
i am using fortinet 40f . bridging has done from my isp. but while creating VIP for my yeaster s20. RTP port 10000-12000 i cant put this value on my port specifying area
Hello, thats a strange issue we have some time now after updating from FG81E to FG90G and it also only happens in one office. It is true, that there are main users (max 40) using Teams. Before with the FG81 we didnt have the problems. Now we use SD WAN for the FG90G and implicit SD WAN rule with Volume and 99% using our Internet Access A. Though we have also above a SD WAN Rule with destination Microsoft-Skype_Teams, Microsoft-Teams.Published.Worldwide.Optimize and Microsoft-Teams.Published.WorldwideOptimize.Allow for Internet Access A. We tried with dedicated Firewall Policy with ALL services and no Security Profile for these 3 destinations - with no better results. Than we tried to Bypass our DoS Policy with new policy above to only Monitor Teams UDP Ports (3478-3481 - 49152-65535) - with no better results. Only disabling the DoS Policy for out Internet Access A seems to solve the problem but since I dont want to have no DoS on this
Hello WiFi adminsIn FAP-231K datasheet, the AP supports 802.3bt (PoE++), 802.3at (PoE+) and 802.3af (standard PoE).What is the exact impact (on all aspects) if using .3at or .3af instead of .3bt?
Hello,I would like to share an issue we are currently experiencing with a FortiGate HA cluster after upgrading to FortiOS 7.6.6. I'm also interested to know if anyone else has encountered similar behavior.Environment:2× FortiGate 200FHA cluster originally running in A-A mode550 firewall policies40k sessions/s during peakUTM enabled (AV, IPS, Web Filtering, WAF)Full SSL inspection500 users20 site-to-site IPsec IKEv2 tunnels50 IPsec dial-up users (IKEv2 + SAML via Entra ID + MFA)FortiClient EMS 7.4.5FortiAnalyzer 7.6.63 Gbit internet connectivityBefore the upgrade:The cluster was running on FortiOS 7.4.11 and had been completely stable for a long time.Upgrade timeline:Upgraded from 7.4.11 to 7.6.6 on Saturday (21 Feb 2026).Everything initially appeared to be working correctly.On Monday around 11:00, when normal traffic load started, the first cluster failure occurred.Observed symptoms:The failures appear to start with HA communication issues (HA ports dropping). Shortly after that
Please how i check current fortinet version 7.2.12 when will expire and also confirm If i upgrade to new version fortinet firewall 201 will support SSL-VPN?
Hello everyone, I’ve got RADIUS set up for FortiNAC, with FortiGate managing FortiSwitch via FortiLink.What’s the easiest way to apply security policies in bulk to multiple switch ports? Thanks in advance,BR,
Dear All,How can I create an Automation alert on FortiPAM, if user launched 1 secret more than 10 times per day, to raise an alarm to delivered to my Email
Hi everyone,!I'm working on optimising my FortiSIEM reporting, and I have two specific questions for the community:1. Daily Global Report ConfigurationI want to generate a "Daily Global Report" that covers everything (incidents, config changes, and system health, etc) for the last 24 hours.What is the best way to group this into a single automated task? How can I ensure it runs at a specific hour and exports correctly every day?2. AI Integration (Inside or Outside FortiSIEM)I'm interested in using AI to analyze or summarize these reports.If you use an external AI, how do you securely connect it to FortiSIEM to pull data automatically?Thanks in advance for your insights!
I have a site to site vpn lab running in vmware workstation pro2x FortiGate Firewalls 2x Windows 10 vmsFortiGate 1 WAN Address(192.168.100.1) LAN Adress(10.1.1.1) FortiGate 1 WAN Address(192.168.100.2) LAN Adress(10.2.2.1)PC-1 (10.1.1.10) PC-2 (10.2.2.10) ip addresses of the pcs are fixedthe WAN Interfaces are on vmnet1the lan interface of fortigate 1 on vmnet 2 the lan interface of fortigate 2 on vmnet 3pc 1 can’t ping pc 2
Hi everyone!We current have a HA Setup for FG 501E. The physical HA ports are interconnected via switch in between. The switch ports are on the same vlan.The physical HA port also has an IP Address set with it. Assume 1.1.1.1 As I have checked, 100F does not have this single HA port same as 501E. It uses HA1 and HA2. Now I am thinking, to replicate our current setup to this new 100F firewall pair, can I use the same switch interconnectivity for the HA1 and assign an IP Address to the HA1 interface? Can i also leave the HA2 interfaces directly connected (w/out switch) to each firewall? The reason why I want to replicate this is because I have found out that:The communications between Fortiguard servers and our existing 501E Firewalls are using a security policy; in which the HA IP address (1.1.1.1) was being referenced. Regards,Renz
Hi everyone, somebody can help me with this error, my SSD go to 100% of use, searching; windows write and read the file push.conf forever, i erase the file and reboot and works but, later the problem start again. thanks and sorry for my bad english.
I have moved a VIP from a load balancer to an internal Fortigate as its not doing anything special, just a basic round robin.It allows a handful of public IPs to access the Virtual Server, The setup is like this:EXERNAL SOURCES > External VDOM > DNAT TO VS > Route to Internal VDOM > VS Configured on DMZ interface > Real Servers on Inside Interface.It gets as far as the VS on the DMZ Interface, I can see the hits on the VS, but that it, it does not forward anything, no denies, no blocks, it just doesn't go any further that the VS? there is no health check, does it need one? it is doing SSL offload for the external certificateThanks
Hello Group: Issue: inherited an EOL FG 30E from a business with no documentation or guides of the unit. Priority: CriticalTime to Resolution: ASAPContext:Business is a small Family Pharmacy and all critical devices/users requiring secure internet access for Pharm operations. Problem Statement: Client web access is kb/ps to websites and timing out. External clients were experiencing the same attempting to remote to site. Unsure if unit is cabled or correctly configured correctly from LAN to WAN currently. They do have internet access connecting directly to AP bypassing Fortinet 30G with fast response. This device/configuration has functioned fine in past and operation only been in existence for a year. NO configuration documentation, no 30E installation or configuration guides, and can’t locate specific due to Support expired 2019 and EOL March 2027Need:Pay for configuration troubleshooting services as required.Documentation of Installation/Configuration of device.Recommendati
I have a firewall that has a few VLANs and physical interfaces that I have turned on the Multiple interface feature and creating those subsequent policies. Working through some oddities (or maybe I just have not dug deep enough into) that seem to choosing a “catch-all” at the bottom of my list before it processes the policy above it that’s specific to the traffic. Like said, still digging some into this. Just wanted to get some feedback on how or if people like this feature, caveats I might want to watch for, etc… Thanks.
I am new to FortiGate, i am trying to setup evaluation license on a VM for training purpose, im facing a problem in accessing the GUI, i have registered the license once and it was working good and then it did not work on the next day , i have reinstalled the VM and deleted the license from my fortiCloud account, after that i always receive this message when i try to register the license “Error in downloading license : Invalid serial number “ i’ve tried to register it manually on forticloud but not worked, any advise ?
• FSSO- upgrade to 5.0.0330. whats the steps
Fairly new to Forti and deployed a range of 50G models at branch sites 5-10 users and HA pair of 70Gs at HQ which has been fine however, have an on going VOIP issue and looking for some guidance.-Telephony platform is cloud hosted-Disabled SIP ALG-No VOIP profile applied to access rulesIssues raised:-Calls dropping-Audio being lost during calls-Poor call quality
both site with redundant WAN , i got it how to do , but with singel wan on 1 side i am in doubt, please advice?
I’m using Forticlient 7.2.14 with EMS Cloud 7.4.5. All of a sudden some users are reporting that they cannon’t connect to anything (Web or corporate VPN). After investigation we found that the application firewall in our EMS profile is blocking DNS for some clients even though this same profile is working for others on the same hardware/forticlient versions. This happens off fabric and prevents even connection to EMS so users cannot then connect to the fabric (VPN). Our only path to fix was to disconnect from EMS (with password), disable the application firewall in the EMS profile and reconnect with an invitaion code. All works thereafter. What might cause this given nothing has changed in our configuration other than EMS cloud auto-updating to 7.4.5 in early April?
Using Forticlient EMS Cloud 7.4 and Forticlient 7.2.8. We using an IPSEC remote access profile but need to split-tunnel MS teams audio/video/sharing traffic but no all MS teams traffic (chat etc.). As such we have excluded the cloud application (as defined by Forticlient EMS remote access profile application based split-tunnel) Microsft-teams.Published.Worldwide.Optimized. Checking in our Foritgate ISDB view we see this object contains the IP ranges for MS teams optimize traffic listed here Microsoft 365 URLs and IP address ranges - Microsoft 365 Enterprise | Microsoft Learn: IDCategoryERAddressesPorts11OptimizeRequiredYes52.112.0.0/14, 52.122.0.0/15, 2603:1063::/38UDP: 3478, 3479, 3480, 3481 Now one some machines this generally works and on others is doesn't and this traffic is sent down our VPN. On inspection of the machine we see there is no route for the specific endpoint MS teams is using for the UDP audio stream in the ranges 52.112.0.0/1
I tried to get a copy of the macOS offline installer for the Forticlient (VPN only), but the last post leads to a dead link.
Hi,We deploy the FortiClient VPN Only app using the MSI installer, which the FortiClient Online Installer exe (7.4.3.4799) downloads into C:\ProgramData\Applications\Cache\GUID\7.4.3.4726\FortiClientVPN.msi.This MSI has the same product code {15C7B361-A0B2-4E79-93E0-868B5000BA3F} as our previously deployed install (7.4.3.1790), which prevents an in-place major upgrade, as the Windows Installer thinks it is already installed.Could you please rectify the latest MSI so it uses a unique product code? This was never a problem until now and is impacting our ability to deploy the newer client to machines running an older FortiClient version, leaving them susceptible to vulnerabilities.RegardsToji
diag sys mount listFilesystem 1M-blocks Used Available Use% Mounted on/dev/ram0 768 656 112 85% /none 1778 2 1775 0% /tmpnone 5925 9 5916 0% /dev/shm/dev/sda2 362 313 29 91% /data/dev/sda3 91 0 86 0% /home/dev/sda4 184510 666 174400 0% /var/log
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.