User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi!This question’s context is only resolution of address objects of ‘type’ is “FQDN” referenced within firewall policies, NOT by end-users. Global:FGT (global) # show system dnsconfig system dns set primary 1.1.1.1 set secondary 8.8.8.8 set domain "x.net"end VDOM1:FGT (vdom1) # show system dns-database config system dns-database edit "x.net" set domain "x.net" set type secondary set authoritative disable set forwarder "10.1.1.2" "10.2.1.2" set ip-primary 10.1.1.2 nextend My question: if I want to Local DNS resolution (with “x.net” suffix) to preempt public DNS resolution in another VDOM, do I need to clone above “show system dns-database” into that VDOM also, or, is it sufficient to have just one, ie. in vdom1?Thanks!
I have a web application for customers to order food & beverage items through a mobile app.the web application is sitting on the DMZ segment.printing of orders is to be done through printers in the LAN print/print server. Can this work ?DMZ web appication through tablets/smartphones -> LAN printer normal printing protocols like smb, tcp/udp 137/138.or can i do wireless printing
Hello all.I am working thru the documentation about how to configure the sslvpn inspection for traffic.I have a 'default' (trusted) cert on my 91G which shows as Fortigate_CA_SSl.I also have purchased and installed a 'vpn.company.com' cert that my users utilize whenever connecting to my vpn - and that works well with mfa. The documentation states that I need to import the cert to my users' devices (computer-trusted root certificates) location but doesn't mention which I should be using. It also mentions that the certificate should be the same - in both places, meaning that the cert on the firewall and computer need to have/use the same cert in order for the process to work. I presume that this would be, should I choose to use it - the 'default' cert mentioned above. Is the correct or how do most people create/use a different cert for the ssl inspection. I plan to create, somehow, a small group of devices to utilize this process so that I can confi
Hello Community, We are currently facing an issue regarding IPSec Remote Access VPN connectivity from Linux (Ubuntu) using FortiClient VPN as the user agent. Our FortiGate is running FortiOS 7.6.6, and we want to allow remote users to connect through IPSec Remote Access VPN. However, after installing FortiClient VPN on Ubuntu, we noticed that the GUI only provides options for SSL VPN and XML configuration, and there is no option available for IPSec VPN.Since SSL VPN is not supported in our current deployment scenario on FortiOS 7.6.6, we intended to use IPSec-based Remote Access. As a workaround, we installed strongSwan on Ubuntu and configured the IPSec connection manually. The VPN tunnel was established successfully using the user created on the FortiGate, and connectivity is working properly. However, we would like to clarify the following points:Is IPSec Remote Access officially not supported in FortiClient VPN Only for Linux?If FortiClient VPN does not support
FirewallFirmware: v7.4.11 build2878 We use a dedicated alert mailbox in our Microsoft 365 tenant for all device and system alerts, and it is already functioning correctly with multiple services.I configured the FortiGate firewall to use this same mailbox, following the same SMTP settings used on our other devices. After triggering a test alert, no email was sent.I reviewed Entra ID sign‑in logs and did not see any authentication attempts from the firewall. I also checked message trace and mail flow logs, with no record of an attempted send, while the previously configured devices continue to work normally.I also set the email “From” address as recommended, but this did not change the behavior.config:config system email-server set server "smtp.office365.com" set port 587 set authenticate enable set username "alerts@ourcomanyname" set password ******************** set security smtpsend
Dear all could you please advise how can i check if fortinet product is original or gray best regards
I have a 511G in standalone mode. I have a local wifi and lan network that I have on a site to site vpn tunnel to my DC. I can send traffic to 511G, but can't get any traffic through the 511G to the devices behind the extender. Running a diag sniffer on the gate, I see the traffic from the 511G and the return, but I see 0 packets in on the site to site tunnel on the 511G. Do I have a configuration incorrect or does the 511G not support this?
Hello all. Apologies if this has been discussed before and I failed to locate it. I just received a used FG-60F and registered it without any issues. When looking at my assets section, all subscriptions appear to be expired on this device, which I was expecting. Once I reset the unit with the button on back and went to the GUI, I noticed something odd. Being new to the FortiGate, I thought I should ask if this is going to be a problem before purchasing a license. On the 60F GUI, it shows that there is FortiCare coverage to an account that isn't mine. I would have thought that my ability to register the 60F indicates that the device has been unregistered from other accounts although I could certainly be mistaken due to my ignorance on such matters. My question is: If I purchase a UTP or ATP license, is this going to create a licensing problem with FortiCare coverage or will it simply apply the new license and show it as covered with FortiCare under my account?I would very much appreciat
A client is requesting that the secondary LAN port on a FAP231G be used for a wired printer connection. I’ve never done this before, but relevant documentation has pointed me in the right direction (I hope). Before making any configurations, the printer pulled an IP from the VLAN the APs are on.Based on the documentation, I went into the “FortiAP Profiles” tab and changed the port mode to Uplink & Bridge, and the port bridge Bridge to SSID, and then selected the desired SSID, the intent being that wireless devices on said SSID will be able to print from that printer. What I expected would happen is that the printer would pull an IP from the SSID pool. It did not.Next I went into the specific AP in the “Managed FortiAPs” tab, enabled Override LAN Port, set Override Port Mode to Uplink & Link, and enabled Bridge to SSID and selected the desired SSID. This also failed to pull and IP from the SSID pool. Am I missing something/misunderstanding how this works?
We are attempting to sync MS entra devices into FortiAuthenticator 6.6.2 so that we can then complete certificate based authentication for these devices.We have on-prem AD devices syncing via LDAP and this is working fine. Has anyone managed to sync entra devices in? I am struggling to find any clear documentation for this process...Thanks in advance
Hello, I know that normaly there should be one rule allowing a connection. In my case we are experiencing with Firewall Authentication, we configured FortiAuthenticator do allow access to devices behind the Firewall based on AD Groups.Users have to sign in on Authenticator using the SAML URL: /saml-sp/CDS_SegSecServ/login/, the session is valid for 10 hours, afterwards users have to relogin. So at this time we have rules which need authentication and older rules for similar access without authentication, based on IP Adresses.The Authentication rules map users to ip’s, so at the end it is also an IP to IP rule.Now my question, what happens when the authenticated sessions runs out, since there is also the old rule which also serves the same IP, should the TCP session continue to work without interruption or does it mean that a new session is initiated and the old one get stuck.It looks like there are at least database disconnections and i am not sure if this is because the rules allowing
I’m seeing an issue in my FortiSASE v26.1.92 where an endpoint is assigned the correct profile (IT Infra), but the group is showing as “Non-AD Endpoints”, which is not expected.The device is domain-joined and should be part of the appropriate AD-synced group, but it’s not reflecting correctly in the console.Details:Endpoint status: Online & managed Correct profile applied: IT Infra Group shown: Non-AD Endpoints (incorrect) AD sync is already configuredQuestion:What could cause an endpoint to fall under “Non-AD Endpoints” even when it’s domain-joined?Any guidance would be appreciated.
We’re running FortiClient with Cloud EMS and deploying via Intune (Win32, SYSTEM).For most users we use SAML authentication, which works fine.But we also have som shared PCS with no primary users.We want the device to be registered in EMS automatically, without requiring any user to log in.What is best practice?
Hi everyone,I’m currently using FortiManager Cloud to manage my FortiGate devices.When I was configuring static routes directly on the FortiGate, I used to rely on address objects and especially address groups as route destinations (Named Address with allow‑routing).This approach was very convenient to group multiple networks behind a single static route and keep the routing configuration clean and readable.With FortiManager (Static Route Templates), I understand that this option is not available:Destinations seem to be limited to Subnet / Internet Service / Internet Service Custom. There is no way to select an address object or an address group as a destination, unlike local FortiGate configuration.I’ve seen that meta‑fields (variables) can be used to inject subnets into route templates, but:This does not really replace the concept of address groups. It doesn’t fully meet the use case I had before.So I’m wondering how you deal with this in practice:How do you handle static routing in
Hello, i created a Test-LAB with FortiManager v7.6.6 build3654 (Mature) VM Trial licensed and FortiGate v7.4.11 build2878 (Mature) VM Trial licensed. Now ill try to Join my Gate into my Manager and got the Error. I checked with the "Compatibility Tool" and it looks good for my Case. I use Windows 11 Pro with Hypedr V and booth VM Imgaes are HyperV from Download Center. The Screenshots are attached. Thanks for help. I tried a lot of proposed solutions FortiGate = 192.168.178.241FortiManager = 192.168.178.240 Log Spoiler (Highlight to read)ConnectedFMG-VM64-HV # diagnose debug application fgfmsd 255fgfmsd debug filter: disableFMG-VM64-HV # diagnose debug timestamp enableFMG-VM64-HV # diagnose debug enableFMG-VM64-HV # 2026-02-23 05:41:29 proxy_session.c,__session_frontend_accept,833: 192.168.178.241:1156 -> 192.168.178.240:541.2026-02-23 05:41:29 __use_cert,734: start idx = 02026-02-23 05:41:29 use certificate issuer = /C=US/ST=California/L=Sunnyval
Fortigate 5.6 Fortimanager 5.6.8 Lower version but in use I've been using it well for over five years, but suddenly I can't see the policy Reboot / fmg 5.6.11 patch / db check and it only loads Have you ever seen cases like this?
Hello everyone,I would like to clarify how FortiGate handles dynamic BGP neighbors in relation to the print tablesize output.In our environment, we use a hub-and-spoke topology. On the hub, BGP peers are not configured statically one by one under config neighbor. Instead, we use:neighbor-group neighbor-rangeThis allows spoke peers to establish BGP sessions dynamically. When running print tablesize, we see:router.bgp:neighbor: 0 0 1000 My doubt is about the meaning of this value in a dynamic BGP scenario. I understand that max-neighbor-num under neighbor-range is a per-range configurable control, not necessarily the total platform limit. For example, the CLI allows: set max-neighbor-num <1-1000> or 0 and documentation mentions that 0 is the default special value. Because of that, I would like to understand the following:Does router.bgp:neighbor in print tablesize apply only to statically configured neighbors, or does it also include dynamic neighbors created through neighbor-range
Trying to set up an IKEv2 client-certificate-based IPsec connection from a FortiClient 7.4.4 to a FortiGate VPN Gateway results in the following error in the FortiGate log when evaluating the received IKE_AUTH request:ike V=root:0:IPSec-Client:176: certificate validation succeededike V=root:0:IPSec-Client:176: signature verification failedike V=root:0:IPSec-Client:176: auth verify doneike V=root:0:IPSec-Client:176: responder AUTH continuationike V=root:0:IPSec-Client:176: authentication failed Parsing the received IKE_AUTH request sent by the FortiClient, we see that the AUTH payload of type Digital Signature (14) defined by RFC 7427 is missing the one octet ASN.1 length field and the following ASN.1 OID of the Algorithm Identifier. Only the raw 64 octet ECDSA 256 Bit Signature has been added:2F Next Payload: 47 - CP00 C/Reserved0048 Length: 72 Octets = 8 + 64 Octets (2*256 Bits)0E Auth Method: 14 - Digital Signa
Hello guys, What will happen to my fortimail once licenses expire?Will it be able still to send/relay emails?What about protection, antispam, content and URL filtering? Thank you in advance.
Hi,I am looking at multiple customer scenarios where thee have more than 300 switches , or have an expansion plan in the future exceeding total of 300.If I am interested in proposing a fortilink fabric to maintain and operate them, what options do I have to increase capacity. As I understand an HA unit in A-A or A-P will not help to double switch capacity.Do we think of adding two HA pairs and then manage the whole show through Fortimanager ?
Hi, I recently started working In FortiSOAR.In playbook I am using the splunk connector with FSR: rest API call action and GET HTTP method to collect the kvstore lookup data.The kvstore lookup contains fields including Date field (which contains ephoc format of date).The Playbook is picking all the data without any issue.But I have to pick data based on condition (if date is beyond 1 month I have to pick those data)Could anyone help me how to achieve this.Thanks.
Hello,I am currently working with FortiManager Cloud (7.4) and FortiGate devices running in multi‑VDOM mode.I would like to know whether it is possible to hide or exclude specific VDOMs on FortiManager Cloud, so that:they are not visible in the Device Manager, they do not consume a device / VDOM license, while still existing on the FortiGate (i.e. without deleting the VDOM on the device itself).From what I understand so far, it looks like:all Traffic‑type VDOMs present on a FortiGate are automatically visible in FortiManager Cloud, each of them is counted as a managed device/VDOM for licensing purposes, and there is no supported way to “unmanage”, hide, or exclude a single VDOM only on the FortiManager Cloud side.Can someone please confirm whether this is indeed not possible on FortiManager Cloud today?And if so, is there any official Fortinet documentation or statement that explicitly confirms this behavior or limitation?Thanks in advance for your clarification.Best regards,B-W
Hi Team, I am looking at multiple customer scenarios where thee have more than 300 switches , or have an expansion plan in the future exceeding total of 300. If I am interested in proposing a fortilink fabric to maintain and operate them, what options do I have to increase capacity. As I understand an HA unit in A-A or A-P will not help here. Do we think of adding two HA pairs and then manage the whole show through Fortimanager ? Your views would be appreciated. Thanks !
When deploying FortiSOAR the configuration wizard reset the database password to a unique value.is there a way to know this password or reset it to a known one?
So i've recently acquired two FortiAP-221c's with POE injectors and I am having a little bit of trouble finding out what seems to be simple information. Maybe one of you can help me out. If I were to put one (or both) of these AP's in my home, what would I NEED to make them work. Is a Fortigate required because of the built in Wireless controller? I know they need to be authorized to enable the antennas, is a fortigate or VM software the only options I have?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.