User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I have problems with a policy where I include an application control where I block access to facebook, youtube and others, one of the applications that I allow within the control is whatsapp but it has presented problems since yesterday, the attached files are not They send and the messages are sent several minutes later, the same as when receiving. I have been doing tests and by allowing the known applications the whatsapp starts working correctly, someone could help me know what the problem is if everything was working well until yesterday that I present this inconvenient. My device is a Fortigate 90D The only categories that I have blocked in the control of applications are: Botnet, Game, P2P, Social.Media, Update, Video/Audio and Unknown applications (now in monitor mode for whatsapp work) The other categories are in monitor mode
Dear All, I have question about FortiProxy Authentication Timeout. My customer need scenario like this :User group SERVER doesn’t have timeout. There is traffic or not, once authenticate the server can connect forever User group EMPLOYEE have timeout 12 hours. So, after 12 hours they must authenticate again using captive portalCould anyone suggest me what I need to configure? I don’t understand guidance from documentation clearlyThank you
Hello.We have an FG-401F firewall, divided into a few VDOMs, all in profile-based mode. Now we need to convert one of the VDOMs to policy-based mode, and as I know in this case all policies are removed. Is there any way to automatically migrate policies from profile-based mode to policy-based, so we don’t have to recreate all of them manually? Maybe some sort of tool or script?Thanks.
Hello everyone, my company is using a fully licensed FortiGate 100F firewall and I need to block Telegram. I've searched in FortiGuard and classified it as Collaboration. Now, to effectively block it and optimize my firewall's performance, should I block it via Application Control or Web Filtering? What Inspection Mode should I set? Flow or Proxy Based?Please give me your advice. Thank you!
Have the following config problem:Fortigate 1 (VLAN400) -----EPLAN LINK-----> Fortigate 2 (VLAN300) traffic works fine. Foritgate 2 (VLAN300) -----EPLAN LINK -----> Fortigate 1 (VLAN400) traffic fails. Have checked all firewall rules, static routes, etc. Can't find the problem. Looked through the docs, only finding examples of VLAN routing on the same Fortigate. I have that working just fine.
Hi guys,I'm trying to make a report in FortiAnalzer that will give me monthly report for SSLVPN login and logoutI know that there is a report for VPN login which can show you top-15 and even more. what I want is Source IP - username - even (login or logout) - timeIt is needed to be for each connection that users do i know its going to be a long report. Do you guys have any idea what dataset code can create that ? I couldn't find in the templates and tbh i dont know much about coding this.
Hello,We are experiencing a recurring issue with DHCP snooping on several firewalls running FortiOS version 7.4.x, specifically on the FortiGate 40F and 60F models.When DHCP snooping is enabled, the DHCP server appears to stop assigning IP addresses to clients. This behavior occurs consistently on these models and is resolved immediately when DHCP snooping is disabled, which indicates that the feature is not functioning as expected in this FortiOS version.We would therefore like to know whether this is a known issue or limitation in FortiOS 7.4.x, and if there are any recommended workarounds, configuration adjustments, or planned fixes in upcoming patch releases.
Looking for expert advice on Fortinet firewall security devices for enterprise environments. I’m evaluating deployment of Fortinet solutions, especially FortiGate Firewall, for high-traffic networks, zero-trust security, and centralized management.Has anyone implemented FortiGate at scale for data centers or multi-branch enterprises? I’d appreciate real-world insights on performance, licensing, VPN stability, and long-term reliability. Also open to recommendations for best configuration practices and common pitfalls during large-scale deployment.
Does FortiManager 8.0 resolve compatibility issues with FortiOS 7.4.10/7.4.11 on FortiGate 40F and 60F? Hello,After reviewing the FortiManager 8.0 compatibility chart, I understand that it is compatible with all FortiGate versions from 7.2 onward without any issues.Has anyone already upgraded to FortiManager 8.0 and can share their experience?https://docs.fortinet.com/compatibility-tool/fortimanager/fortigate
HelloChatGPT is already in FortiSIEM 7.1.I guess many of you already asked ChatGPT to help with building some FortiGate configuration or in troubleshooting issues.I dare suppose that Fortinet is working to include it directly in the next release of FortiOS and other Fortinet products.
FortiGate-100F. I am getting this warning : Conserve mode activated due to high memory usage. Internet is not working, but if i reboot the firewall, it starts working.
Hi all, have an HA pair of 120G devices running 7.2.13 that use SDWAN to load balance internet traffic between two different fiber circuits. I recently added a cellular backup circuit, but because the cellular bandwidth is relatively low and it’s a metered connection I don’t want to add this to the same SDWAN group/rule as the 2 load-balanced fiber circuits (OutboundWAN_loadbalance). I ended up creating a new SDWAN group (5G_Failover) and all/all rule for the cellular circuit and placed it in the lowest priority position - my objective being that if both fiber circuits go down, traffic will be routed through the cellular backup automatically. Will this work the way I think it will? Hoping to get some insight from someone who has set up something similar before I test this. See screenshot for clarity.
Hi,Current FortiClient v 7.4 breaks on “Connecting” status so, the way to solve this issue fast is run older version that our IT department knows that work fine: 7.2.14.1296 Where to find the installer of old versions in a easy way ? Thanks.
Hi,after the win 11 upgrade to 25h2 version more notebook/pc dont connect trough vpn ipsec .IF I disable in network adapter the Fortinet NDIS packet can connet but dont reach any devices on remote network and dont receve traffic. I tried Forticlient 7.2, 7.4 versions but nothing.Please HELP ME! Thanks in advance.
Good afternoon, Fortinet community.Today I'm reaching out to ask for your support and expertise with Fortinet. I'm having a problem with my VPN connection. My users connect to my internal network via the FortiClient VPN program to work remotely on the servers from anywhere. Lately, they've been experiencing issues, with users reporting dropped connections ("VPN outages") or weak connectivity. They might connect, but then disconnect after a while, or they might connect but with a weak signal that kicks them out of my servers.I'd appreciate your help in looking at this from a different perspective, as I don't have much experience with this technology. Thank you for your understanding and time.
The community string match ( I have done this on two firewalls already). This paticular firewall had a policy that limted SNMP, I create a new one, moved it up in priotiy and still was not getting the get - ACK. Debug flow shows this: 14:47:48 policy-88 is matched, act-accept14:47:48after iprope_captive_check(): is_captive-0, ret-matched, act-accept, idx-8814:47:48 checked gnum-10000f policy-4294967295, ret-matched, act-accept14:47:48 policy-4294967295 is matched, act-drop14:47:48 gnum-10000f check result: ret-matched, act-drop, flag-00000800, flag2-0000000014:47:48 after check: ret-matched, act-drop, flag-00000800, flag2-0000000014:47:48iprope_in_check() check failed on policy 0, dropAnyone run into this?
Hi WAF adminsSometimes my FortiWeb denies some uploaded files, just like pdf or png, and it logs an attack of type "generic attack" or "known exploit". The detected pattern can be something like this:${�ǕN�������$�Or something like that:_/I wonder if this is a real attack or just a false positive, since the signature is inside an uploaded file, while the string ${... looks like a kind of injection, and I think it should be blocked when it is in a form or in URL, not when it is in an uploaded binary data file.Or maybe I'm misunderstanding something in WAF?
Hello guys,I am trying to download FortiSIEM for the very first time, I select SUPPORT then FIRMWARE DOWNLOADS, and where I am supposed to scroll through to select FortiSIEM is greyed out and a message on the page says, I DO NOT have any registered product. Is FortiSIEM all-in-one Supervisor free or I’ll need to get a license to use it, I want to deploy it in my homelab.Thank you
Hi, we are attempting to use private 5G with a FEX 511 5G however the device is consistently flapping. It looks like the logs state that the modem is rebooting every 5 mins or so. On the P5G side we just see disconnects and reconnects. We have 2 FEX 511Gs (one outdoor and 1 indoor) with different modem hardware and are still getting the same issue. We also have a FG-50G-5G presenting no issues with the connection and every other device such as mobiles are not presenting an issue.The issue seems to be localised to the device. Is this a known issue/bug or has anyone else experienced anything similar and if they have, how was it solved?
Hello,Planning to upgrade our EMS instance to 7.4.7 (currently on 7.4.5) and one of the ‘new features’ listed for 7.4.6 is hiding the SSLVPN feature by default (https://docs.fortinet.com/document/forticlient/7.4.0/new-features/483736/ssl-vpn-feature-select-option-is-hidden-by-default-7-4-6). With one of our Remote Access profiles including an SSLVPN profile, does anyone know the expected behavior or impact this may have?IE, once the upgrade is completed, will re-connected endpoints lose their SSLVPN configuration from the remote access profile? We are planning to re-enable the SSLVPN feature post upgrade via the cli commands provided but want to plan accordingly if the upgrade may wipe out the configuration until the feature is re-enabled. I would anticipate we will have some sslvpn connections active during the upgrade and don't want active users to get booted unintentionally. Thanks!
I'm having trouble configuring Explicit Proxy with SAML authentication;Every webpage displays a certificate error: If I click “Advanced,” it opens the Microsoft authentication page and I can access the internet, but I want it to be transparent, without displaying that error.What could be causing this?
Hello,Does 10G port of F200G has backward compatibility with 1G SFP port module?
Hi,I’m having an issue with FortiClient IPsec VPN (IKEv2) using X.509 certificate authentication.I get a timeout when connecting.Setup:Windows 11Device Entra ID joined and enrolled in IntuneFortiClient VPN (free) 7.4.3.4726IPsec VPN, IKEv2, certificate (X.509)Encapsulation: AutoPorts open: UDP 500, TCP 443Issue:✅ VPN connects successfully when I sign in to Windows using a local account❌ VPN fails when I sign in using a work account (Microsoft Entra ID)No changes were made to the VPN configuration, certificates, or FortiGateThe same VPN profile works on devices not enrolled in IntuneThis strongly suggests a conflict related to Intune / Entra ID device context, not the gateway or certificate itself. I should add that there are no policies in Intune that could restrict VPN functionality.Question:Are there known issues or limitations with IPsec IKEv2 + X.509 certificates on Intune‑managed, Entra ID–joined devices?Is a device certificate required instead of a user certificate in this scenar
FortiAuthenticator Agent for Microsoft OWA questions:1. How to remove the red Secure by Fortinet label ?2. We have several domains in the forest, is it possible to choose the default domain somehow3. In some cases, we use email to change domain passwords, but after installing the 2FA agent, this will not be possible. If it is possible to change the domain password through fortiauthenticator Exchange 2019, Fortiauthenticator 6.4.2, agent 2.4
Hello How te configure auto changing password In FORTIPAM LDAP servers . BR
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.