User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
When using the ACME client in FortiWeb v8, does it automatically re-use the same private/public key for renewals? or does it issue a new key on each renewal?
In FortiAnalyzer, I have one ADOM with 200 firewalls and another ADOM with 5 firewalls, but on all the firewalls regardless of the ADOM, I can't see the logs in security events > WebFilter, for example, only from memory.Also, in FortiAnalyzer, in FortiView the tabs Traffic, Shadow IT, Applications and Websites, VPN, and System are grayed out, making it impossible to select them.Could this be a license issue or some configuration parameter?
I have just acquired a fg60e, i realise it's end of life but i plan on using it just for learning firewalls, vlans etc so don't need full licence for extras, i plan on doing cisco & fortinet free courses to understand more about networking & security.Tonight i have got it setup & connected to the internet & noticed it's running fw v 6.0.3, i realise it's old but in your opinions would this be adequate for learning the basics of fortinet OS or can you suggest a more up to date stable fw version.
We have just migrated to FortiClient EMS 7.4.5 LinuxVM from FortiClient 7.2.12 WindowsVM. In that process we are trying to move from Active Directory to Microsoft Entra for controlling Manage Deployments. While deployments are working fine from the Active Directory side, the issue we are seeing is that Windows devices from the Entra side are not and showing "Unsupported Operating System"All these devices are Windows and have been onboard from Intune and as this is a hybrid environment. The same device works fine on the Active Directory side.I am sure I am missing something, but I have been through it a few times and I can see nothing wrong from the setup documents.Anyone have any idea what I am missing?
Hi Everyone.I have a customer who has a FGT 80E with full UTM features. The main web policy has Web Filtering, IPS, AV and SSL inspection Security Profiles assigned. The end users are reporting that randomly they will get redirected to gstatic.com/generate_204. Looking the browser history under gstatic.com/generate_204 it references "Fortinet DNS Service" which made me wonder if it was one of the Security Profiles causing the issue. I removed all profiles from the web rule and the issue still occurred. I then came across this KB (https://kb.fortinet.com/kb/documentLink.do?externalID=FD36680) regarding QUIC (Quick UDP Internet Connections) and as the customer had reported that the issue was with Google Chrome, I asked them to implement Method 1 from the KB on a machine that was experiencing the issue. Unfortunately this did not resolve the issue. I have looked at the logs on the FGT and there is nothing there to help me. I am not convinced its a FGT issue (although the r
I have a question regarding the Web Filter Function.Currently, I have enabled the Web Filter Function by configuring "certificate-inspection" as the SSL inspection.However, because the FortiGate certificate has not been manually imported to the client PCs, a certificate error screen is displayed when communication is blocked.Therefore, I have configured the following settings to prevent the alternative message screen from being displayed:[Settings]config web-proxy explicit set https-replacement-message disableend Since the connecting client PCs are numerous and unspecified, I do not want to manually import certificates individually.I would like to display an alternative message screen instead of a certificate error when communication is blocked.If there is a way to achieve this, could you please advise me?
Hi Fortigate,My fotigate is 7.2.11 build 1740.I understand 7.2 is out of support in September. How do we upgrade from 7.2 to 7.4?regardsJohn Zen@@
Hi All, I have doubt if we can achieve below requirement. Fortigate integrate with Clearpass/ISE for ZTNA authentication , but the user identity is at Entra ID(no local AD). I knew that Fortigate can direct integrate with Entra ID using SAML, but client insist to use Clearpass/ISE as authentication server(lets not challenge client why at this moment). Flow should be ZTNA Client > Fortigate > Clearpass/ISE > Entra ID Question : Can this be done ? Or can i say this can be only done if FortiAuthenticator is used instead of Clearpass/ISE ?
Hello,I've deployed policies from my FMG to my FG, and although the deployment was successful, the changes aren't “visible” on the FortiGate.Is this normal?I'm working in a lab environment where my FMG is running version 7.41 and my FG is running version 7.2.5.Cheers :)
Can Site-to-Site VPN between HQ and a Branch be implemented with overlapping subnets? In this case, four subnets are going to be used at each site. Therefore, I would like to know if overlapping works fine for more than one single subnet. Thanks.
do the fortiswitch's support stacking ? i am speaking of traditional stacking where all switch are managed via single ip address and I can configure ports from any stack member thru a single mgmt ip . what about stacking bandwidth? do we have any dedicated stacking ports or is everything done thru the ports on the front of the switch? example if i have a 3 x 24 port 1G copper switch with no uplink ports how would i stack these 3 switches? Is daisy chain my only option?
Hello, I'm running FortiManager-VM64-KVM v7.4.10 build2278.I was wondering how to create an correlation handler event to trigger for when a specific account logs into FortiManager. I've tried getting it to work from this log entry (FortiManager > System Settings > Event Logs), but it's not triggering the event even though the account successfully logs in. 2026-03-31 08:18:00 tz="+0100" log_id=0001010018 type=event subtype=system pri=information desc="User login/logout successful" user="myuser@domain.com" userfrom="SSO(IP_address)" msg="User 'myuser@domain.com' (myuser@domain.com) with profile 'Super_User' login accepted from SSO(IP_address)." adom="root" adom_oid=0 session_id=62498 operation="login" performed_on="SSO(IP_address)" changes="'myuser@domain.com' login accepted from SSO(IP_address)" adminprof="Super_User"Does anyone have a template for this to work?
Based on this article herehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602 I know you've tried more than once to make the tunnel up with IKEv2 and with LDAP Authentication and it didn't work. First I would like to thank to my friend @Mohamedh219 for his amazing effort getting such article Here is a solution that worked out with me based on this Japanese article:https://licensecounter.jp/engineer-voice/blog/articles/20260331_fortigate_ipsec_vpnikev2_-_ldapforticlient_vpn_-.html All you have to do is enabling the transport protocol to be using TCP instead of UDP for the tunnel's configuration, and set the ike tcp port to a port that you're 100% sure it's opened by the ISPs (for example 443 which is used for web browsing) .. Check image below Also from the FortiClient perspective .. go to the VPN settings for the configured IPSEC VPN .. Go to Advanced settings under p
We're setting up ZTNA and one of the hurdles we have run in to is file shares - currently we're mapping network drives to our local domain name (eg \\contoso.lan\Share)I've been able to verify share access via a specific server FQDN but when i try to set up "contoso.lan" as a FQDN address on the firewall (verified it appears in HOSTS file), access is lost which was expected. Contoso.lan resolves to the DCs and not the file share servers.I didn't find any documentation or examples for this specific scenario and scratching my head how I could get this to work.Has anyone run in to this or have any suggestions to look in to or try?
Hello,Does anyone have the official list of FortiGate models supported by FortiOS 8.0.0?Also looking for the recommended upgrade path to reach 8.0.0 from 7.0.x and 7.2.x.Thanks in advance.
I've a question regarding the Transparent proxy policy and Proxy-based inspection policy, since the Transparent proxy policy and the proxy-based policy are doing the same thing i mean the FortiGate buffering the traffic and the client communicate with the FortiGate and the FortiGate communicate with the remote server (2 Connections - Man in the middle topology) Why we use Transparent proxy then since the proxy-based inspection mode policy has the same function?
Hello everyone,I am currently experiencing an intermittent connectivity issue affecting multiple macOS devices in our environment.The devices connect successfully to the WiFi network through FortiAP units (mostly model 231K). However, after some time, they suddenly lose network connectivity and internet access, even though they still appear as connected.From the FortiGate perspective, the affected devices are still visible under the WiFi Clients list, but they are unable to pass traffic properly.We have already performed extensive troubleshooting, including:Reviewing logs and event records on the FortiGateOpening a ticket in TACTesting different configuration adjustments on the SSIDModifying FortiAP operational profiles and performance-related settingsDespite all these efforts, the issue persists.It is also important to highlight that this behavior has been observed across different MacBook models, which suggests it is not hardware-specific.Has anyone experienced a similar issue with m
Hi Team,We would like to highlight a recurring security concern we’ve observed across multiple FortiGate deployments and incident investigations.During the initial setup of FortiGate (FortiOS), the device allows login without a predefined password and prompts the user to set one. In practice, many users end up configuring very weak passwords such as:adminadmin@123P@sswordpass@123These passwords are already available in public leaked credential lists and are commonly used in brute-force attacks.In our recent investigations, we have seen multiple FortiGate firewalls get compromised due to weak admin passwords.Attackers were able to:1.Gain admin access2.Create full-access SSL VPN configurations3.Execute ransomware inside the networkWhen these incidents happen, most customers assume:“FortiGate firewall got hacked”However, the actual root cause is weak password configuration, not a product vulnerability.This creates a reputation issue where the product is blamed instead of the misconfigurat
I've followed the instructions in https://docs.fortinet.com/document/forticlient/7.2.0/new-features/792170/entra-id-integration-7-2-1 and ended up creating 2 separate Enterprise Applications where one was used to configure the Client Secret (for the Administration > Authentication Server), and the other was used for the SAML URLs (for User Management > SAML Configuration). While this works, and I am able to register FortiClients by authenticating against Entra ID, I wonder if I did it correctly. Could this have been a single Enterprise Application? Or if not, and they had to be separate, what is the Enterprise Application with the Client Secret used for?And what is the Enterprise Application with the SAML URLs used for? Also what is this?To configure the Azure tenant app for initiating passthrough (domain):Is this an alternative to registering an Entra ID user's endpoint to EMS using SAML (which is my goal)?
What is difference in kvm image
Hi everybody, Since a few days ago, when scanning with nmap, 2 ports appear as open:PORT STATE SERVICE53/tcp open domain dnsmasq 2.90113/tcp closed ident853/tcp open domain-s I run scanning regularly. I do not understand how this could happen. I am trying to close them but no success. I do not use Override authentication. If somebody could help, I would appreciate.Thank you @AEK@mpapisetty
Hi, I have an issue regarding a Forti 60F on which i tried doing a quick install that wasn't working. I deleted the task but later on, after trying a full Install Wizard, i realized it was blocked due to that one task i deleted (Blocked by session id(xxxx), task(xxxx)).Now that i have deleted the task, i can no longer do any install wizard as long as it is running.I looked up all of fortinet documentation and ran the commands on command line, but all the commands that could delete the task are no longer supported by Fortimanager 7.6.6Is there any other solution to stop the task completely, or recover it ?
Hi all,I currently have the following setup:FortiManager Cloud → FortiGate → FortiLink → FortiSwitchAll configuration is pushed via FortiManager templates.What would be the best practice to safely remove a FortiSwitch from the FortiGate in this scenario? Thanks.
HiI upgraded the 60F from version 7.0.5 to 7.2 three days ago. The system looks very promising but has a problem with a new feature in Log & Report. The "Summary" page in "System Events" and "Security Events" is blank - no data exists (it is not grayed out, only all tables are empty). When I go to the "Details" tab, all logs of individual modules are in place, regardless of whether I choose "FortigateCloud" or "Memory". I have a licensed version of "Standalone FortiGate Cloud account" - 1 year log retention.Can anyone, are there any specific requirements to run this function (maybe Fortianalizer?).Or is it an early version of the system bug?Does it work for someone?Thanx
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.