User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
The community string match ( I have done this on two firewalls already). This paticular firewall had a policy that limted SNMP, I create a new one, moved it up in priotiy and still was not getting the get - ACK. Debug flow shows this: 14:47:48 policy-88 is matched, act-accept14:47:48after iprope_captive_check(): is_captive-0, ret-matched, act-accept, idx-8814:47:48 checked gnum-10000f policy-4294967295, ret-matched, act-accept14:47:48 policy-4294967295 is matched, act-drop14:47:48 gnum-10000f check result: ret-matched, act-drop, flag-00000800, flag2-0000000014:47:48 after check: ret-matched, act-drop, flag-00000800, flag2-0000000014:47:48iprope_in_check() check failed on policy 0, dropAnyone run into this?
Hi WAF adminsSometimes my FortiWeb denies some uploaded files, just like pdf or png, and it logs an attack of type "generic attack" or "known exploit". The detected pattern can be something like this:${�ǕN�������$�Or something like that:_/I wonder if this is a real attack or just a false positive, since the signature is inside an uploaded file, while the string ${... looks like a kind of injection, and I think it should be blocked when it is in a form or in URL, not when it is in an uploaded binary data file.Or maybe I'm misunderstanding something in WAF?
Hello guys,I am trying to download FortiSIEM for the very first time, I select SUPPORT then FIRMWARE DOWNLOADS, and where I am supposed to scroll through to select FortiSIEM is greyed out and a message on the page says, I DO NOT have any registered product. Is FortiSIEM all-in-one Supervisor free or I’ll need to get a license to use it, I want to deploy it in my homelab.Thank you
Hi, we are attempting to use private 5G with a FEX 511 5G however the device is consistently flapping. It looks like the logs state that the modem is rebooting every 5 mins or so. On the P5G side we just see disconnects and reconnects. We have 2 FEX 511Gs (one outdoor and 1 indoor) with different modem hardware and are still getting the same issue. We also have a FG-50G-5G presenting no issues with the connection and every other device such as mobiles are not presenting an issue.The issue seems to be localised to the device. Is this a known issue/bug or has anyone else experienced anything similar and if they have, how was it solved?
Hello,Planning to upgrade our EMS instance to 7.4.7 (currently on 7.4.5) and one of the ‘new features’ listed for 7.4.6 is hiding the SSLVPN feature by default (https://docs.fortinet.com/document/forticlient/7.4.0/new-features/483736/ssl-vpn-feature-select-option-is-hidden-by-default-7-4-6). With one of our Remote Access profiles including an SSLVPN profile, does anyone know the expected behavior or impact this may have?IE, once the upgrade is completed, will re-connected endpoints lose their SSLVPN configuration from the remote access profile? We are planning to re-enable the SSLVPN feature post upgrade via the cli commands provided but want to plan accordingly if the upgrade may wipe out the configuration until the feature is re-enabled. I would anticipate we will have some sslvpn connections active during the upgrade and don't want active users to get booted unintentionally. Thanks!
I'm having trouble configuring Explicit Proxy with SAML authentication;Every webpage displays a certificate error: If I click “Advanced,” it opens the Microsoft authentication page and I can access the internet, but I want it to be transparent, without displaying that error.What could be causing this?
Hello,Does 10G port of F200G has backward compatibility with 1G SFP port module?
Hi,I’m having an issue with FortiClient IPsec VPN (IKEv2) using X.509 certificate authentication.I get a timeout when connecting.Setup:Windows 11Device Entra ID joined and enrolled in IntuneFortiClient VPN (free) 7.4.3.4726IPsec VPN, IKEv2, certificate (X.509)Encapsulation: AutoPorts open: UDP 500, TCP 443Issue:✅ VPN connects successfully when I sign in to Windows using a local account❌ VPN fails when I sign in using a work account (Microsoft Entra ID)No changes were made to the VPN configuration, certificates, or FortiGateThe same VPN profile works on devices not enrolled in IntuneThis strongly suggests a conflict related to Intune / Entra ID device context, not the gateway or certificate itself. I should add that there are no policies in Intune that could restrict VPN functionality.Question:Are there known issues or limitations with IPsec IKEv2 + X.509 certificates on Intune‑managed, Entra ID–joined devices?Is a device certificate required instead of a user certificate in this scenar
FortiAuthenticator Agent for Microsoft OWA questions:1. How to remove the red Secure by Fortinet label ?2. We have several domains in the forest, is it possible to choose the default domain somehow3. In some cases, we use email to change domain passwords, but after installing the 2FA agent, this will not be possible. If it is possible to change the domain password through fortiauthenticator Exchange 2019, Fortiauthenticator 6.4.2, agent 2.4
Hello How te configure auto changing password In FORTIPAM LDAP servers . BR
Hi all, We use SAML SSO for VPN connection but recently we have had a few errors when the SSO page does not load then gives back a page not found error. Nothing has changed on the firewalls nor the VPN config.Has anyone seen this error before?
Hi,I have a fortigate filter to block the entire games categoriy but i'd like to enable to play on a minecraft java server.I've exempted *.mojang.com and *.xbox.com but the minecraft java launcher still has no connection to login to my microsoft account. I can run minecraft itself fine, and i can connect to the server but get rejected because my microsoft account is not logged in.What do i need to exempt for this to work?
Hi!This question’s context is only resolution of address objects of ‘type’ is “FQDN” referenced within firewall policies, NOT by end-users. Global:FGT (global) # show system dnsconfig system dns set primary 1.1.1.1 set secondary 8.8.8.8 set domain "x.net"end VDOM1:FGT (vdom1) # show system dns-database config system dns-database edit "x.net" set domain "x.net" set type secondary set authoritative disable set forwarder "10.1.1.2" "10.2.1.2" set ip-primary 10.1.1.2 nextend My question: if I want to Local DNS resolution (with “x.net” suffix) to preempt public DNS resolution in another VDOM, do I need to clone above “show system dns-database” into that VDOM also, or, is it sufficient to have just one, ie. in vdom1?Thanks!
I have a web application for customers to order food & beverage items through a mobile app.the web application is sitting on the DMZ segment.printing of orders is to be done through printers in the LAN print/print server. Can this work ?DMZ web appication through tablets/smartphones -> LAN printer normal printing protocols like smb, tcp/udp 137/138.or can i do wireless printing
Hello all.I am working thru the documentation about how to configure the sslvpn inspection for traffic.I have a 'default' (trusted) cert on my 91G which shows as Fortigate_CA_SSl.I also have purchased and installed a 'vpn.company.com' cert that my users utilize whenever connecting to my vpn - and that works well with mfa. The documentation states that I need to import the cert to my users' devices (computer-trusted root certificates) location but doesn't mention which I should be using. It also mentions that the certificate should be the same - in both places, meaning that the cert on the firewall and computer need to have/use the same cert in order for the process to work. I presume that this would be, should I choose to use it - the 'default' cert mentioned above. Is the correct or how do most people create/use a different cert for the ssl inspection. I plan to create, somehow, a small group of devices to utilize this process so that I can confi
Hello Community, We are currently facing an issue regarding IPSec Remote Access VPN connectivity from Linux (Ubuntu) using FortiClient VPN as the user agent. Our FortiGate is running FortiOS 7.6.6, and we want to allow remote users to connect through IPSec Remote Access VPN. However, after installing FortiClient VPN on Ubuntu, we noticed that the GUI only provides options for SSL VPN and XML configuration, and there is no option available for IPSec VPN.Since SSL VPN is not supported in our current deployment scenario on FortiOS 7.6.6, we intended to use IPSec-based Remote Access. As a workaround, we installed strongSwan on Ubuntu and configured the IPSec connection manually. The VPN tunnel was established successfully using the user created on the FortiGate, and connectivity is working properly. However, we would like to clarify the following points:Is IPSec Remote Access officially not supported in FortiClient VPN Only for Linux?If FortiClient VPN does not support
FirewallFirmware: v7.4.11 build2878 We use a dedicated alert mailbox in our Microsoft 365 tenant for all device and system alerts, and it is already functioning correctly with multiple services.I configured the FortiGate firewall to use this same mailbox, following the same SMTP settings used on our other devices. After triggering a test alert, no email was sent.I reviewed Entra ID sign‑in logs and did not see any authentication attempts from the firewall. I also checked message trace and mail flow logs, with no record of an attempted send, while the previously configured devices continue to work normally.I also set the email “From” address as recommended, but this did not change the behavior.config:config system email-server set server "smtp.office365.com" set port 587 set authenticate enable set username "alerts@ourcomanyname" set password ******************** set security smtpsend
Dear all could you please advise how can i check if fortinet product is original or gray best regards
I have a 511G in standalone mode. I have a local wifi and lan network that I have on a site to site vpn tunnel to my DC. I can send traffic to 511G, but can't get any traffic through the 511G to the devices behind the extender. Running a diag sniffer on the gate, I see the traffic from the 511G and the return, but I see 0 packets in on the site to site tunnel on the 511G. Do I have a configuration incorrect or does the 511G not support this?
Hello all. Apologies if this has been discussed before and I failed to locate it. I just received a used FG-60F and registered it without any issues. When looking at my assets section, all subscriptions appear to be expired on this device, which I was expecting. Once I reset the unit with the button on back and went to the GUI, I noticed something odd. Being new to the FortiGate, I thought I should ask if this is going to be a problem before purchasing a license. On the 60F GUI, it shows that there is FortiCare coverage to an account that isn't mine. I would have thought that my ability to register the 60F indicates that the device has been unregistered from other accounts although I could certainly be mistaken due to my ignorance on such matters. My question is: If I purchase a UTP or ATP license, is this going to create a licensing problem with FortiCare coverage or will it simply apply the new license and show it as covered with FortiCare under my account?I would very much appreciat
A client is requesting that the secondary LAN port on a FAP231G be used for a wired printer connection. I’ve never done this before, but relevant documentation has pointed me in the right direction (I hope). Before making any configurations, the printer pulled an IP from the VLAN the APs are on.Based on the documentation, I went into the “FortiAP Profiles” tab and changed the port mode to Uplink & Bridge, and the port bridge Bridge to SSID, and then selected the desired SSID, the intent being that wireless devices on said SSID will be able to print from that printer. What I expected would happen is that the printer would pull an IP from the SSID pool. It did not.Next I went into the specific AP in the “Managed FortiAPs” tab, enabled Override LAN Port, set Override Port Mode to Uplink & Link, and enabled Bridge to SSID and selected the desired SSID. This also failed to pull and IP from the SSID pool. Am I missing something/misunderstanding how this works?
We are attempting to sync MS entra devices into FortiAuthenticator 6.6.2 so that we can then complete certificate based authentication for these devices.We have on-prem AD devices syncing via LDAP and this is working fine. Has anyone managed to sync entra devices in? I am struggling to find any clear documentation for this process...Thanks in advance
Hello, I know that normaly there should be one rule allowing a connection. In my case we are experiencing with Firewall Authentication, we configured FortiAuthenticator do allow access to devices behind the Firewall based on AD Groups.Users have to sign in on Authenticator using the SAML URL: /saml-sp/CDS_SegSecServ/login/, the session is valid for 10 hours, afterwards users have to relogin. So at this time we have rules which need authentication and older rules for similar access without authentication, based on IP Adresses.The Authentication rules map users to ip’s, so at the end it is also an IP to IP rule.Now my question, what happens when the authenticated sessions runs out, since there is also the old rule which also serves the same IP, should the TCP session continue to work without interruption or does it mean that a new session is initiated and the old one get stuck.It looks like there are at least database disconnections and i am not sure if this is because the rules allowing
I’m seeing an issue in my FortiSASE v26.1.92 where an endpoint is assigned the correct profile (IT Infra), but the group is showing as “Non-AD Endpoints”, which is not expected.The device is domain-joined and should be part of the appropriate AD-synced group, but it’s not reflecting correctly in the console.Details:Endpoint status: Online & managed Correct profile applied: IT Infra Group shown: Non-AD Endpoints (incorrect) AD sync is already configuredQuestion:What could cause an endpoint to fall under “Non-AD Endpoints” even when it’s domain-joined?Any guidance would be appreciated.
We’re running FortiClient with Cloud EMS and deploying via Intune (Win32, SYSTEM).For most users we use SAML authentication, which works fine.But we also have som shared PCS with no primary users.We want the device to be registered in EMS automatically, without requiring any user to log in.What is best practice?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.