User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi, I recently started working In FortiSOAR.In playbook I am using the splunk connector with FSR: rest API call action and GET HTTP method to collect the kvstore lookup data.The kvstore lookup contains fields including Date field (which contains ephoc format of date).The Playbook is picking all the data without any issue.But I have to pick data based on condition (if date is beyond 1 month I have to pick those data)Could anyone help me how to achieve this.Thanks.
Hello,I am currently working with FortiManager Cloud (7.4) and FortiGate devices running in multi‑VDOM mode.I would like to know whether it is possible to hide or exclude specific VDOMs on FortiManager Cloud, so that:they are not visible in the Device Manager, they do not consume a device / VDOM license, while still existing on the FortiGate (i.e. without deleting the VDOM on the device itself).From what I understand so far, it looks like:all Traffic‑type VDOMs present on a FortiGate are automatically visible in FortiManager Cloud, each of them is counted as a managed device/VDOM for licensing purposes, and there is no supported way to “unmanage”, hide, or exclude a single VDOM only on the FortiManager Cloud side.Can someone please confirm whether this is indeed not possible on FortiManager Cloud today?And if so, is there any official Fortinet documentation or statement that explicitly confirms this behavior or limitation?Thanks in advance for your clarification.Best regards,B-W
Hi Team, I am looking at multiple customer scenarios where thee have more than 300 switches , or have an expansion plan in the future exceeding total of 300. If I am interested in proposing a fortilink fabric to maintain and operate them, what options do I have to increase capacity. As I understand an HA unit in A-A or A-P will not help here. Do we think of adding two HA pairs and then manage the whole show through Fortimanager ? Your views would be appreciated. Thanks !
When deploying FortiSOAR the configuration wizard reset the database password to a unique value.is there a way to know this password or reset it to a known one?
So i've recently acquired two FortiAP-221c's with POE injectors and I am having a little bit of trouble finding out what seems to be simple information. Maybe one of you can help me out. If I were to put one (or both) of these AP's in my home, what would I NEED to make them work. Is a Fortigate required because of the built in Wireless controller? I know they need to be authorized to enable the antennas, is a fortigate or VM software the only options I have?
Hello, I have a 40F.Default config has a virtual hardware switch called "lan" whose member interfaces are: "lan1", "lan2" and "lan3".I would like to remove those member interfaces from the "lan" switch using Ansible. Do you know how to do that ? https://docs.ansible.com/ansible/latest/collections/fortinet/fortios/fortios_system_virtual_switch_module.html#examples I tried the tasks bellow, leaving the port empty, but no success.If I specify just one port, like lan1, it removes the others. I need to remove them all. task1- name: Remove member interfaces from "lan" virtual hardware switch fortinet.fortios.fortios_system_virtual_switch: vdom: "{{ vdom }}" state: "present" system_virtual_switch: name: "lan" port: task2- name: Remove member interfaces from "lan" virtual hardware switch fortinet.fortios.fortios_system_virtual_switch: vdom: "{{ vdo
Hi Everybody,I just installed a new Forti Client EMS 7.4.6 installation with a trial license on VMWare.EMS is nicely setup, using a signed cert etc.Now when trying to make a installer package i'm unable to do that.According to the documentation and EMS training I should be able to select between "Create installer " and "Create installer config" but don't get that option.It just let's me go through the creat installer wizard and at teh end I just can do a "download".Is it something i'm doing wrong or is it some bug/feature on a newly released version (released at 17-3-2026) as usual with FortiNet? referenced documentation was the ems 7.4 training and the EMS 7.4.6 quickstart guide: https://docs.fortinet.com/document/forticlient/7.4.6/ems-quickstart-guide/942839 Kind regardsRoger Beurskens
I have performed multiple FortiEMS upgrades over the past year,s tarting from 6.4.7, and the FortiEMS server version was always the same as the Forticlient installer package version.That is not the case with 7.4.7. The installer package version is 7.4.6.I find that confusing..Is an installer package 7.4.7 in the works?
Hello,following yesterday’s application of the EMS 7.4.6 patch on the VM (https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484), we have identified today that the majority of PCs/laptops with FortiClient versions 7.4.5 and 7.4.6 are experiencing an issue where the FortiClient Network Access Control process is utilizing 100% of the disk. Before applying the CVE patch, we did not observe this issue.A simple restart of the affected PCs did not resolve the problem. We also attempted to restart EMS, but the issue persisted. On the endpoints we are only using Telemetry, Vulnerability Scan, and VPN access.As a workaround, we tested disconnecting telemetry, generating a new invitation, and reconnecting telemetry — after which the disk utilization returned to normal.Are others experiencing similar issues?Jirka
I have a FortiExtender (FEX) connected to my Fortinet FortiGate, with no other LAN or Internet connections, and in that scenario the device connects to FortiManager Cloud without any issue.However, when I connect the MPLS links (used for LAN/Internet), the FortiGate is no longer shown as connected to FortiManager Cloud.I already created:A static route An SD-WAN/static rule forcing FortiManager Cloud traffic to use the FEXBut the issue remains.Tests PerformedOnly FEX connectedping 8.8.8.8 → Works ping fortimanager.forticloud.com → WorksMPLS connectedping using source interface = FEX → FailsQuestionHas anyone seen a similar issue where adding MPLS changes routing/return traffic behavior and breaks connectivity to FortiManager Cloud, even when policy routes/static routes are forcing traffic through the FEX? Any suggestions would be appreciated.
Hello everyone, After update FortiEDR 5.2.8 to 6.1.0.1455 in dc server , there is a problem in the collector. The collector always off and workaround is disable in console then control panel remove and restart.After restart, the EDR collector continuons. In the internet, the solution is remove this folders:!--scriptorstartfragment-->rmdir /s /q "C:\Program Files\Fortinet"rmdir /s /q "C:\ProgramData\Fortinet"!--scriptorendfragment-->But i can’t. So, there is tools to remove it, the same fcremove ( to forticlient)?
i created IPSec VPN tunnels on VDOMs that do not have a WAN connection on Site A has only one WAN connection assigned to the root VDOM, and an IPSec VPN tunnel should be configured on User and i used this configuration but it didn’t work
alfasegurosbpopular.com.co/cancelaciones/index.php# This its a phishing Please help yo report thanks
We are running into an issue where our Fortifone 380s aren't showing any personal contacts. The whole page is blank. We do have other directories which appear, however, any personal contacts do not. You can manually add one to the phone itself, and it still doesn't appear. However, when you then log into your web portal, the contact you created on the phone is there, even though it doesn't appear on the phone itself. Anyone experience this before?
How to pre-fill username field on OAuth Service portal from login_hint parameter in FortiAuthenticator 6.6.2?I have a Keycloak server with the form of user and password with OpenIdConnect service , I want only to use Fortiauthenticator for the OTP with fortitoken, but i dont want the for of user and password in the fortiauth side
Configuring FortiADC to load balance Citrix gateway servers. Access works internally but the requirement is for internet accessible. The FortiADC has no public exposure - the private vip is being nat'd at the edge firewall. Reviewed documentation posted at ==> https://docs.fortinet.com/document/fortiadc/8.0.0/fortiadc-on-citrix-vdi-deployment-guide/365130/reference-network-topology-used-in-the-examples-of-solution-2 The storefront access works as expected but the ica file is not being rewritten once you launch an application. Any assistance would be appreciated.
A user is trying to install FortiClientVPN, but after the "Downloading image" process completes, the setup wizard does not launch — nothing happens, and the process simply stops. We tested with different installers and on other devices within the same environment, and the installation worked correctly for all other users except this one. Also other apps can be installed with no problem. The Windows Event Logs show the following entry: Nombre de aplicación con errores: FortiClientVPN.exe, versión: 7.4.3.1790, marca de tiempo: 0x67db45bcNombre del módulo con errores: FortiClientVPN.exe, versión: 7.4.3.1790, marca de tiempo: 0x67db45bcCódigo de excepción: 0xc0000409Desplazamiento con errores: 0x00211f5bId. de proceso con errores: 0x3D78Tiempo de inicio de aplicación con errores: 0x1DBDAAA46008787Ruta de aplicación con errores: C:\Users\USER\AppData\Local\Temp\FortiClientVPN.exeRuta de módulo con errores: C:\Users\USER\AppData\Local\Temp\FortiClientVPN.exeId. de informe: 1d8
Hello Fortinet Community,I am currently working on configuring an IPsec Client-to-Site VPN on a FortiGate 1000D running FortiOS 7.4.11, using FortiClient for remote access. Despite multiple attempts and referencing official documentation, I am facing difficulties achieving a fully functional setup, there are ambiguities especially in the difference between remote access ans custom config, it seems like custom config is a full and manual one.I would appreciate it if someone could provide a complete, working configuration example, including both FortiGate and FortiClient configurations.Environment DetailsDevice: FortiGate 1000DFirmware: FortiOS 7.4.11VPN Type: IPsec Client-to-Site ikev2Authentication: Pre-Shared Key (PSK)Client: FortiClient 7.4.3 VPN ONLY (not EMS)Issues EncounteredTunnel may establish intermittently, but traffic does not pass correctly.I suspect there may be additional routing requirements beyond firewall policies.when i add new tunnels , even the authentification block
Hi there,I bought a used fortigate 100E. How can I deregister the previous owner?ThanksG
Hi Team,On my FortiADC, I have configured multiple virtual servers and everything is functioning correctly.However, every time I log in to the GUI, I am redirected to the “Upload License” page. After uploading the license, I can see that all configurations (including virtual servers) are intact and working as expected.This behavior repeats on every login.Has anyone encountered this issue before?Is this a known UI issue, or could there be a misconfiguration or licensing problem on my setup?Thanks in advance.
Hi I have a Fortigat 200 (v7.6.6)I have a server WAPT on vlan 10 and I want use it to wake on lan my PC in vlan 20.Unicast WOL is working wakeonlan -i <ip> <mac>But not with broadcast WOL. And WAPT use only broadcast mode for doing that.When I try to wol aPC (10.20.20.1) from wapt server (10.10.10.1) on vlan 10 :# diagnose sniffer packet v10 'dst 10.20.20.255' interfaces=[v10] filters=[dst 10.20.20.255] 3.495703 10.10.10.1.41831 -> 10.20.20.255.7: udp 102 3.495938 10.10.10.1.48121 -> 10.20.20.255.9: udp 102 # diagnose sniffer packet v20 'udp' interfaces=[v20] filters=[udp] I have taken a look herehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-route-Wake-On-Lan-WOL-magic-packet-through/ta-p/198103 but I don't understand if I need to add an entry in arp table for each PC I want to wake up (I have 2000 PC).Or if i need to enable this command config system interface edit <external_interface_name> set broadcast-forward e
Hey Fortinet Community 👋 As you may have seen in the homepage banners, we’re getting close to launching the updated Fortinet Community. If you are seeing this post on April 16th, we are currently running a 2-hour production test.Once the test is complete, we’ll switch back to the current Community. It will remain in read-only mode until we go live on April 21st.During the test: you may see brief changes as we validate the new experience in production. After the test: you’ll be redirected back to the current Community (read-only) while we finish launch preparations.Click here for details on what’s changing and how to report any issues you notice during the test window. Thanks for your patience. We appreciate it!
What are the portal addresses listed in the Sandbox tab (Type: FortiGate Cloud): "Sandbox Settings - Info - URL Threat Detection - Entries"? There are several or a dozen addresses there, but they are unknown to me.
Good day,Trying to install fortigate on ProxMox but unable to do so. I followed the install guide but when the VM is started it gets stuck on formatting disk screen. any help would be great.
Hi, do you know if ther is a fortigate config that allows creating two VPN tunnels to the same peer id but one being IKEv1 and the other tunnel IKEv2 with differents hosts in phase 2? Without showing you the error on the remote gateway "Duplicate entry found"
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.