User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Using Forticlient EMS Cloud 7.4 and Forticlient 7.2.8. We using an IPSEC remote access profile but need to split-tunnel MS teams audio/video/sharing traffic but no all MS teams traffic (chat etc.). As such we have excluded the cloud application (as defined by Forticlient EMS remote access profile application based split-tunnel) Microsft-teams.Published.Worldwide.Optimized. Checking in our Foritgate ISDB view we see this object contains the IP ranges for MS teams optimize traffic listed here Microsoft 365 URLs and IP address ranges - Microsoft 365 Enterprise | Microsoft Learn: IDCategoryERAddressesPorts11OptimizeRequiredYes52.112.0.0/14, 52.122.0.0/15, 2603:1063::/38UDP: 3478, 3479, 3480, 3481 Now one some machines this generally works and on others is doesn't and this traffic is sent down our VPN. On inspection of the machine we see there is no route for the specific endpoint MS teams is using for the UDP audio stream in the ranges 52.112.0.0/1
I tried to get a copy of the macOS offline installer for the Forticlient (VPN only), but the last post leads to a dead link.
Hi,We deploy the FortiClient VPN Only app using the MSI installer, which the FortiClient Online Installer exe (7.4.3.4799) downloads into C:\ProgramData\Applications\Cache\GUID\7.4.3.4726\FortiClientVPN.msi.This MSI has the same product code {15C7B361-A0B2-4E79-93E0-868B5000BA3F} as our previously deployed install (7.4.3.1790), which prevents an in-place major upgrade, as the Windows Installer thinks it is already installed.Could you please rectify the latest MSI so it uses a unique product code? This was never a problem until now and is impacting our ability to deploy the newer client to machines running an older FortiClient version, leaving them susceptible to vulnerabilities.RegardsToji
diag sys mount listFilesystem 1M-blocks Used Available Use% Mounted on/dev/ram0 768 656 112 85% /none 1778 2 1775 0% /tmpnone 5925 9 5916 0% /dev/shm/dev/sda2 362 313 29 91% /data/dev/sda3 91 0 86 0% /home/dev/sda4 184510 666 174400 0% /var/log
Hello,Last week, the VPN on my personal laptop connected normally. Now, when I try to connect to the network, I get two errors:Timeout - and I don't even see an attempt to log in to Forti Auth.No errors - the GUI just freezes while connecting and disconnects after a while.System Windows 11.I will add that with version 7.4.3 hotfix (I can't check the exact version right now), but on another computer - I connect to the VPN normally (unfortunately I don't have access to it at the moment to check) IKE:1Mode: Agressive|Adress Asig.: manualIPSECOn the company's side, everything looks fine - there are other connections via VPN.
If i have ipsec tunnel for site to site connection listen on port1, then on same port i confgire ipsec tunnel for remote access then is there any miss connection?I mean is there any wrong connection when Remote Access VPN want connect then the connection will passing thru the site to site tunnel and vice versa?
I try to build VPN remote access using ipsec to preparing upgrade my fortigate production from 7.2 to 7.6 on my lab.My fortigate lab use version 7.6.4 and after i create vpn tunnel, the forti client is connected and get the ip address but the client is not able to reach to anywhere. The firewall policy and static routing was working fine.Open case to the fortigate support and they also feel strange with this issue. Someone here can help how to toubleshoot?Here my VPN config===========================config vpn ipsec phase1-interfaceedit "VPN-RA"set type dynamicset interface "port1"set ike-version 2set peertype anyset net-device disableset mode-cfg enableset proposal aes128-sha1set add-route disableset comments "VPN Remote Access"set dhgrp 5 20set wizard-type dialup-forticlientset transport autoset fortinet-esp enableset ipv4-start-ip 10.64.200.20set ipv4-end-ip 10.64.200.50set dns-mode autoset save-password enableset client-auto-negotiate enableset client-keep-alive enableset psksecret
I’m using Forticlient 7.2.14 with EMS Cloud 7.4.5. Our profile loggin settings are in debug mode as we have many issues over our time with this product. I see these debug logs are logged under %\ProgramFiles%\Fortinet\FortiClient\logs\trace. Is there any reference to what each log represents? I can’t seem to find one. Some of the log name inidcate the usage but they are verbose so I would like a reference as we are looking to build some Loki dashboards against them: Log Usage Reference Transctrl.log Sslvpnlibr.log Sslvpndaemon.log Sslvpndaemon_error.log Ftsvnic.log Fortiwf.log FortiVPNGui.log FortiVPN.log FortiVPN_Error.log fortivpn.exe_sslvpnlib.log FortiVPN.exe_FortiAuth.log
Hello FNAC admins,Is it necessary to configure the Winbind part for RADIUS authentication to work properly? Or can RADIUS function normally without integrating Winbind.Thanks in advance,BR,
Two to three months ago, we migrated to the EMS Forticlient VMware appliance 7.4.4.Today, I tested the upgrade from 7.4.4 to 7.4.5 via the GUI. I tested two times with the same result.See the log below:As you can see, I started the upgrade around 3:54 PM.The upgrade apparently finished about 30 minutes later, 4:24 PM, but I got stuck at 50% and suddenly saw a client and network error.I logged in to the EMS console via a different workstation and received the message that the EMS Ugrade completed!Only after refreshing the browser with the 50% message, did I get the message "EMS upgrade complete!"I don't see any errors in the logs, so I assume the upgrade most likely completed successfully.The (7.4.4) Forticlient on the Windows 11 workstations didn't generate any errors and could also establish an SSL VPN connection. I could also create a FortiClient installer in the EMS console1) Any idea why the upgrade dialog box is stuck at 50%?2) And I'm missing the SSLVPN option in the screenshot b
I know there are a million of these topics in here, but i dont have a support account with a product licence attached and I cant find the installer on my old laptop, I’m just moving device so i’ve lifted the config off my old laptop but it’s not working with 7.4 and I can’t access legacy downloads in support, does anyone have 7.0.8.0427 installer I can have?
I’m trying to setup a DNS service on the network interface. I followed the instructions on this link. However, it doesn’t resolve anything on the public domain. It resolves interface domain name. It looks like Fortigate doesn’t forward the query to system DNS servers. Anything I need to check? I used the following link to create DNS service. Technical Note: DNS resolution not working when DNS Server configured to 'Same as Interface IP' | CommunityBasically, I want a user to use Fortigate interface as a DNS server IP and have Fortigate to resolve internal domain relying on the local dns database but forward to system dns servers to resolve anything outside domain names.
With IPSEC being removed from the new Forticlient and SSL-VPN being removed from the Fortigates themselves, I've been migrating everyone to IKEV2 using EMS.For around 100 users I would say 80 of them are connecting fine using IKEV2, LDAP and 2FA (Fortitokens) however around 20% are consistently having issues and end up reverting back to SSL-VPN.I've created both an UDP and TCP (443) IKEV2 profile for people to try. The TCP did solve some issues but a lot of people just cannot use IKEV2. I'm pretty sure it's likely their ISP/Router blocking it but I'm just wondering if there are any other tips I could check for when setting up the client on the Fortigate?I've forced NAT Traversal and setup IKE fragmention. Any one else had issues which changing any settings helped at all?Thanks!
Hi! I tried to do an A-P 100F HA Setup where I have assigned the IP to ha1 interface. But there is no switch in between yet. Direct connection only.Everything is the same in Active and Standby firewall. But when I try to check the routing entry for the ha1 ip address, they aren’t the same. The output should show “via LAG1.16”You may refer to the images attached. The secondary firewall outputs the expected route. But on the primary, it says directly connected. It’s actually correct because I configured ha1 in primary and it just cascaded the config to secondary.One thing that confuses me is that , why different routes when they are just configured the same routing entries?
Hi, We’ve been using the On/Off Fabric feature for our FortiClient users without any issues. However, since updating the FortiClient app to version 7.2.12.1269, the app no longer correctly identifies devices that are on fabric—it now shows all devices as off fabric as. We’re using Public IP as the detection rule. Please advise if there’s a known issue with this version or if any configuration changes are required.
When sending logs to FortiSIEM using json over HTTP.if the sender can send with more than one IP, What I should use as reptIP in the API?also if I put for example one IP, if the sender send again with diff IP does the CMDB got affected?
I have 2 Fortigate 600F in a HA Cluster that needs to connect to 1 ONU. Currently, both Fortigate is connected to a L2 switch that is then connected to the ONU. However, when the ONU is rebooted, Fortigate is no longer able to obtain an ip address on the port used to connect to the ONU. If I configure link monitor, would Fortigate be able to obtain ip address after rebooting ONU?What is the recommended network configuration when using HA Cluster with ONU?
A MacOS device running FortiClient 7.2.12 is showing this in the EMS:FortiGuard Outbreak DetectionsIran-linked Cyber Attacks(compromised)The EMS is very hard to use to get any more details than that. I eventually found the "FortiGuard Outbreak Detection Rule" called "Iran-linked Cyber Attacks" and found only one MacOS CVE: https://www.cve.org/CVERecord?id=CVE-2025-13223The CVE states that the vulnerability is in "Google Chrome prior to 142.0.7444.175". The device is running 147.0.7727.138.Why is FortiClientEMS showing this false alarm?(At this point I am not trusting the EMS "FortiGuard Outbreak Detections" since it is not accurate.)
Second-hand devices - Does it actually matter if the device you are running is not registered to your forticloud account?This is assuming fortigate cloud is disabled on the unit and there’s no EMS so it cannot be remotely managed.Or should I just create a support ticket, send pictures of the labels to support and wait two weeks and hope fortinet decides to add these to my account?My plan was to test active-active HA pair so automatic updates aren’t what I want to happen.
We have setup a point to point wireless bridge using 2 FAP234's as the parent and leaf AP's. The wireless bridge is intended as a backup route to a fibre connection should it go down. A diagram below shows the setup;Network DIagramWe are however having issues in that the wireless bridge does not pass traffic when the fibre link goes down, and although I do have a TAC case open, I'm hoping a member of the community could review the setup and point out anything that could be causing the problem.One thing to highlight is that spanning tree is enabled on the switches that the AP's are connected to. Should spanning tree also be enabled on the AP's themselves, or is that managed by the switches? Any help is welcome.
Hi All, We are experiencing an issue with the forticlient VPN client on MacOS 15.5 We are currently planning our roll out of remote access via IPsec and moving away from SSL VPNs, The issue we are having is that after a device cold start/reboot, the initial attempt to connect to the remote access VPN via IPsec always fails and gives an "Connection was terminated unexpectedly" error. Trying it immediately again afterwards, it still fails. The current workaround is to connect to the same remote VPN endpoint but via SSL VPN, and then trying the IPsec once more; however, this does not always seem to work.Another workaround seems to be waiting 5-10 minutes, and trying the IPsec connection seems to work.Once successfully connected via the IPsec VPN, it continues to work until the client device is rebooted/shut down. Looking through the Forticlient debug logs, we are getting an "IPsec error -104"; however, when running an authentication debug on the FortiGate, I can
I am facing an issue where some users in the FortiGate firewall appear with an “orange” status instead of the normal connected (blue) state.When this happens, the affected users experience restricted access, and some applications or websites are blocked.Our environment is integrated with Active Directory (AD) using authentication (SSO). The issue seems to occur especially when users switch between different network connections, such as Wi-Fi, wired (LAN), or VPN. In these cases, the user’s IP address changes, and the FortiGate appears unable to properly recognize or maintain the authentication session.We have already attempted the following troubleshooting steps:Removed the user from the domain and rejoined Reinstalled the FortiGate certificateHowever, the issue persists.Interestingly, when the user connects via a wired network, the status returns to normal (blue), and access is restored.It appears that during network transitions, the user session becomes inconsistent, causing the Fort
When i use IPSEC with IKEv2 and in the forticlient I use DNS on the remote gateway then the client can connect to the VPN but can’t reach to anywhere.If i switch using IP Address for Remote gateway then the client is able to connect to the LAN.Anyone facing same issue with me or this is know issue for IKEv2?
Hi All, Anyone have any idea for Grey-noise deployment in FortiGate?And hope it is third party, so can we trust them?
Hi, I have installed Fortianalyzer-VM on my Server with 50 GB storage for trial. Then I extend my storage to 500 GB and purchased 500 GB storage license from fortinet. After the license applied my storage is not increased its showing me 50 GB only. I restarted my server several times but no result. Anyone guide me what I'm doing wrong. I attached snapshot of my storage as well as license for reference.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.