User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
i created IPSec VPN tunnels on VDOMs that do not have a WAN connection on Site A has only one WAN connection assigned to the root VDOM, and an IPSec VPN tunnel should be configured on User and i used this configuration but it didn’t work
alfasegurosbpopular.com.co/cancelaciones/index.php# This its a phishing Please help yo report thanks
We are running into an issue where our Fortifone 380s aren't showing any personal contacts. The whole page is blank. We do have other directories which appear, however, any personal contacts do not. You can manually add one to the phone itself, and it still doesn't appear. However, when you then log into your web portal, the contact you created on the phone is there, even though it doesn't appear on the phone itself. Anyone experience this before?
How to pre-fill username field on OAuth Service portal from login_hint parameter in FortiAuthenticator 6.6.2?I have a Keycloak server with the form of user and password with OpenIdConnect service , I want only to use Fortiauthenticator for the OTP with fortitoken, but i dont want the for of user and password in the fortiauth side
Configuring FortiADC to load balance Citrix gateway servers. Access works internally but the requirement is for internet accessible. The FortiADC has no public exposure - the private vip is being nat'd at the edge firewall. Reviewed documentation posted at ==> https://docs.fortinet.com/document/fortiadc/8.0.0/fortiadc-on-citrix-vdi-deployment-guide/365130/reference-network-topology-used-in-the-examples-of-solution-2 The storefront access works as expected but the ica file is not being rewritten once you launch an application. Any assistance would be appreciated.
A user is trying to install FortiClientVPN, but after the "Downloading image" process completes, the setup wizard does not launch — nothing happens, and the process simply stops. We tested with different installers and on other devices within the same environment, and the installation worked correctly for all other users except this one. Also other apps can be installed with no problem. The Windows Event Logs show the following entry: Nombre de aplicación con errores: FortiClientVPN.exe, versión: 7.4.3.1790, marca de tiempo: 0x67db45bcNombre del módulo con errores: FortiClientVPN.exe, versión: 7.4.3.1790, marca de tiempo: 0x67db45bcCódigo de excepción: 0xc0000409Desplazamiento con errores: 0x00211f5bId. de proceso con errores: 0x3D78Tiempo de inicio de aplicación con errores: 0x1DBDAAA46008787Ruta de aplicación con errores: C:\Users\USER\AppData\Local\Temp\FortiClientVPN.exeRuta de módulo con errores: C:\Users\USER\AppData\Local\Temp\FortiClientVPN.exeId. de informe: 1d8
Hello Fortinet Community,I am currently working on configuring an IPsec Client-to-Site VPN on a FortiGate 1000D running FortiOS 7.4.11, using FortiClient for remote access. Despite multiple attempts and referencing official documentation, I am facing difficulties achieving a fully functional setup, there are ambiguities especially in the difference between remote access ans custom config, it seems like custom config is a full and manual one.I would appreciate it if someone could provide a complete, working configuration example, including both FortiGate and FortiClient configurations.Environment DetailsDevice: FortiGate 1000DFirmware: FortiOS 7.4.11VPN Type: IPsec Client-to-Site ikev2Authentication: Pre-Shared Key (PSK)Client: FortiClient 7.4.3 VPN ONLY (not EMS)Issues EncounteredTunnel may establish intermittently, but traffic does not pass correctly.I suspect there may be additional routing requirements beyond firewall policies.when i add new tunnels , even the authentification block
Hi there,I bought a used fortigate 100E. How can I deregister the previous owner?ThanksG
Hi Team,On my FortiADC, I have configured multiple virtual servers and everything is functioning correctly.However, every time I log in to the GUI, I am redirected to the “Upload License” page. After uploading the license, I can see that all configurations (including virtual servers) are intact and working as expected.This behavior repeats on every login.Has anyone encountered this issue before?Is this a known UI issue, or could there be a misconfiguration or licensing problem on my setup?Thanks in advance.
Hi I have a Fortigat 200 (v7.6.6)I have a server WAPT on vlan 10 and I want use it to wake on lan my PC in vlan 20.Unicast WOL is working wakeonlan -i <ip> <mac>But not with broadcast WOL. And WAPT use only broadcast mode for doing that.When I try to wol aPC (10.20.20.1) from wapt server (10.10.10.1) on vlan 10 :# diagnose sniffer packet v10 'dst 10.20.20.255' interfaces=[v10] filters=[dst 10.20.20.255] 3.495703 10.10.10.1.41831 -> 10.20.20.255.7: udp 102 3.495938 10.10.10.1.48121 -> 10.20.20.255.9: udp 102 # diagnose sniffer packet v20 'udp' interfaces=[v20] filters=[udp] I have taken a look herehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-route-Wake-On-Lan-WOL-magic-packet-through/ta-p/198103 but I don't understand if I need to add an entry in arp table for each PC I want to wake up (I have 2000 PC).Or if i need to enable this command config system interface edit <external_interface_name> set broadcast-forward e
Hey Fortinet Community 👋 As you may have seen in the homepage banners, we’re getting close to launching the updated Fortinet Community. If you are seeing this post on April 16th, we are currently running a 2-hour production test.Once the test is complete, we’ll switch back to the current Community. It will remain in read-only mode until we go live on April 21st.During the test: you may see brief changes as we validate the new experience in production. After the test: you’ll be redirected back to the current Community (read-only) while we finish launch preparations.Click here for details on what’s changing and how to report any issues you notice during the test window. Thanks for your patience. We appreciate it!
What are the portal addresses listed in the Sandbox tab (Type: FortiGate Cloud): "Sandbox Settings - Info - URL Threat Detection - Entries"? There are several or a dozen addresses there, but they are unknown to me.
Good day,Trying to install fortigate on ProxMox but unable to do so. I followed the install guide but when the VM is started it gets stuck on formatting disk screen. any help would be great.
Hi, do you know if ther is a fortigate config that allows creating two VPN tunnels to the same peer id but one being IKEv1 and the other tunnel IKEv2 with differents hosts in phase 2? Without showing you the error on the remote gateway "Duplicate entry found"
Hello,We are using a FortiGate device integrated with a Kubernetes Connector. The system was working properly on FortiOS 7.2.12, but after upgrading to 7.4.11, we started experiencing the following issues:SDN Connector errors The following errors are observed in the GUI: Invalid SDN filter: K8S label node.kubernetes.io/exclude-from-external-load-balancers Invalid SDN filter: K8S label node-role.kubernetes.io/control-planeWe are experiencing 504 Gateway Timeout errors on outbound traffic to servers running behind Kubernetes. Based on checks performed on the Kubernetes side: There is a noticeable latency/performance degradation in the environment However, after downgrading back to FortiOS 7.2.12, these issues are no longer observed. Therefore, we suspect that the 504 errors and performance degradation are related to FortiOS 7.4.11.Rollback result After downgrading back to 7.2.12: All issues are resolved Kubernetes services are reachable again SDN connector errors disappear.Additionally;D
Hey everyone,We’re getting ready to deploy a new site and I’m looking for some guidance on choosing the right FortiGate model.Environment details:~300 users8 FortiSwitches over FortiLinkPlanning to enable SSL Deep InspectionUsing full security profiles (IPS, AV, App Control, Web Filter, etc.)Average traffic mix: Office 365, web browsing, VPN, internal appsAverage of 25,000–30,000 concurrent sessionsI know deep inspection significantly reduces throughput, so I want to size the appliance properly to avoid bottlenecks once everything goes live.For anyone who has deployed FortiGate models in similar environments, which model would you recommend?Any real‑world performance insights or warnings are also appreciated!Thanks!
Hello, We have 3 Management IPs configured for a Fortigate device. Only one is polling on Solarwinds, 2 are failing with SNMP. MGMT-01 is .227 and MGMT-02 is .226 Here are the trace results (omitted and edited some characters): id=65308 trace_id=21 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=17, 10.x.x.88:62985->10.x.x.227:161) tun_id=10.0.0.2 from MGMT-02. "id=65308 trace_id=21 func=init_ip_session_common line=5995 msg="allocate a new session-08f7faa3"id=65308 trace_id=21 func=iprope_dnat_check line=5276 msg="in-[MGMT-02], out-[]"id=65308 trace_id=21 func=iprope_dnat_tree_check line=834 msg="len=0"id=65308 trace_id=21 func=iprope_dnat_check line=5288 msg="result: skb_flags-02000008, vid-0, ret-no-match, act-accept, flag-00000000"id=65308 trace_id=21 func=vf_ip_route_input_common line=2611 msg="find a route: flag=80000000 gw-10.x.x.227 via root"id=65308 trace_id=21 func=iprope_access_proxy_check line=439 msg="in-[MGMT-02], out-[],
I am using MDaemon as my Email host behind fortigate 100f. I am able to connect to my mdaemon server using webmail as well as outlook desktop however facing issues with outlook android. I am able to sync imap emails but unable to send email from outlook android. all recommended ports are open and accessible from outside. what could be the reason fortigate blocking outlook android traffic and how can I solve this step by step. urgent response will be appreciated. (Note: All ports are open, SSL configured and working, webmail and outlook desktop working fine even adding accounts in Gmail is working fine).Only outlook android not sending mail say "error sending mail please try again"
Hello, I am having difficulty to understanding how the captive portal works with LDAP authentication with FortiNAC, as I could not find any clear documentation for this.Could anyone help me understand the workflow and the steps involved in user authentication using LDAP?So far, I have completed the following steps, but it is not working:Configured LDAP integration — it appears to be workingChanged the standard user login method to LDAP.I am not sure if there are any additional steps required. later testing I was able to resolve the issue with help from the community.What I did:I initially added LDAP to FortiNAC and configured the standard user login type to use LDAP. However, that alone was not sufficient. Winbind is also required—without it, the setup does not function properly.Key Notes:Ensure FortiNAC is added as a computer object in Active Directory.If you are using an LDAP group for GUI administrator access, delete and recreate the LDAP user group with administrator priv
Dear Team,One of our customer upgraded the FortiClient version from 7.4.3 to 7.4.5 which is managed by EMS.After that most of the users facing to connect the VPN.By default, the FortiClient installer contains 9 VPN URLs or Gateway defined in EMS.When the user tried to connect any of the VPN gateway by clicking 'connect' button it does not react anything.For some users, the issue resolved by reinstalling the FortiClient, Re-register the zero trust telemetry with invitation code, restarting the laptop and connecting to different Wifi or network.For few users, did not helped any of the above workaround.From the user machine we collected the FortiClient log and found below logs.Could any one help with below logs to sort out the issue.sslvpndaemon_1.log[2026-04-07 08:36:49.9130356 UTC+02:00] [10616:6788] [sslvpndaemon 285 debug] TunnelInitiator::StartConnection() called.[2026-04-07 08:36:49.9134374 UTC+02:00] [10616:6788] [sslvpndaemon 287 debug] TunnelInitiator::StartConnection() tunnel: &
HiIm trying to connect two core switches to out Fortigates that running in HAThe Fortigates have been running for 3 years together with some old Alcatel Lucent switches, and now I want to upgrade to FortiSwitchThis is my setup. Best RegardsThomas
Hello, I am trying to convert incoming port 22 to 2222 with a VIP rule. However I want to keep the same external and internal IP address. The VIP will not accept this.Is there any way to only convert incoming ports with the same address ?
Hi everyone,I’m currently trying to connect to an older FortiGate device (FortiOS 5.4), so I need to use an older version of FortiClient (6.0 or 6.2).Since the device is EOL, I’m unable to download the installer from the official Fortinet support portal. I managed to get the 6.2 online installer, but it fails during installation with errors related to an invalid digital signature and MSI error code 2711.Would anyone be able to share a FortiClient VPN 6.0 or 6.2 offline installer (full package) or point me to a reliable source?I would really appreciate your help.Thanks in advance!
How do i find the status of All VPNs in FortiAnalyzer ?
Hello Fortinet Community, I would like to inquire whether it is possible to implement a VPN chaining (nested VPN) scenario using FortiClient. Use case:We have a requirement where access to a client VPN is restricted to a specific public IP address (e.g., 193.40.X.X). When connecting from our office network, we are able to access the client VPN successfully because our traffic originates from this whitelisted IP. However, we would like to achieve the following setup: Connect from a remote location (home) to our office VPN using FortiClient.Once connected, establish a second VPN connection (also via FortiClient) to the client environment.Ensure that the second VPN connection is seen as originating from the office public IP (193.40.X.X). Questions: Does FortiClient support running multiple VPN tunnels simultaneously (VPN over VPN / nested VPN)?Are there any supported configurations or best practices to achieve this setup?Are there specific requirements (e.g.,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.