User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I have are two Fortigate firewall between model 50G and 50G-WIFI. Also use SD-WAN to created dual internet and its through SD-SLA mark the auto fail-over. In my case has an interesting problem occurred:***also use the same as police & static route Model 50G-WIFI:SD-WAN member: VPN_01, VPN_02 => enableWan, A=>enable that are two VPN tunnel & internet service also work as well.===============================Model 50G:SD-WAN member:VPN_01, VPN_02 =>enableWan, A=>enableVPN with Phase1 =>lost====SD-WAN member:VPN_01, VPN_02 =>enableWan, A=>disableVPN service work as normal====SD-WAN member:VPN_01, VPN_02 =>enableVPN service work as normal, internet service not workingas above case problem, how can to resolve it?
在 Fortinet 的 SASE 解决方案中,我看到主组件 FortiSASE 拥有自己的控制平台,也称为 FortiSASE,可用于管理 FortiGate、SD-WAN 等设备。我还注意到 FortiManager 也包含在 Fortinet SASE 解决方案中。FortiManager 是否也提供自己的控制台界面?它和 FortiSASE 控制台有什么区别?FortiSASE是否提供对设备本身(例如交换机)的配置控制?据我所知,FortiSASE可以配置和管理FortiGate设备。您的客户目前在部署 Fortinet SASE 解决方案时,主要使用 FortiSASE 控制台还是 FortiManager?
I'm unable to activate my trial license with my email address jmujica@outlook.com, I have an trial license assigned but unable to reuse the license
Hi everyone! We have an existing FG 501E which we'll be decommissioning in a few weeks. We plan on replacing it with FG 100F. In order to lessen the risk and errors, I plan on backing up the old firewall config and just restore it to a newly factory-reset FG100F.However, our existing 501E has Global, and 2 vdoms(including root). On the 100F, we plan on NOT using a vdom. Just put everything in global configuration. Question:1. Is it possible to backup and restore this properly?2. Is it possible to not use a VDOM and just put everything in global config?
This is the most frustrating experience that I ever had with a 30day eval license registration. My customer wants to evaluate Fortigate against another solution and I can't create a PoC without using 1vCPU and a 2GB ram?I have registered the license and the instance still requires a licenseDescriptionPartnerProduct ModelFortiGate VM TrialRegistration Date2026-04-03Lost more than 2 hours as the documentation is not clear (does not even have a link on what is the portal to create a user on how to get a 30 day license - I actually need it for a week)
How can I avoid issues with security profiles after the license expires?Web filter, IPS, DNS filter Is there a way for them to work offline without updating?
I'm using clearpass accounting with rsso to a fortigate 200g using aruba wifi. also have intrium updates enabled on clearpass.Athentications are working and RSSO is picked up correctly on the firewall however when roaming between access points I am prompted for captive portal. The connection doesnt drop and im using fast roaming on the wifi which would say its a firewall issue any settings to tweak on the firewall so it doesnt distrupt roaming.?
I installed FortiClient EPP/APT Edition for testing purposes, but I am now unable to uninstall it from my system.When I try to uninstall it from Control Panel → Programs and Features, the uninstaller only shows a Repair option and does not provide an option to uninstall.I also attempted to resolve this by downloading the FortiClient removal tool from the Fortinet Support Portal. However, I am facing issues there as well.When I navigate to:Support → Firmware Download → Product SelectionI encounter the following message:"Sorry, you don't have any product covered by a Fortinet support contract."Additionally, the product selection button is not working, so I am unable to select any firmware image or proceed further.For context:I downloaded FortiClient EPP/APT Edition(windows) online for testingI do not have a serial number or active support contractThe uninstall option is not available (only repair is shown)FortiClient #Windows #Uninstall #EPP/APT
Hello,I would like to understand the behavior of the network when FortiNAC becomes unreachable or stops (service down).In this scenario:What happens to the access ports on the switches?Do they fall back to the default VLAN automatically?Are already authenticated endpoints still allowed to communicate, or are they impacted?Also:What are the best practices or recommendations to handle this situation?Is there a way to ensure continuity (fail-open vs fail-close behavior)?Any feedback or real-world experience would be appreciated.Thank you.
Hello everyone,I am working on implementing FortiClient 7.2.4 trial.I did import a web filter profile from our FortiGate and enabled ssl deep inspection. Now it does not seem that FortiClient EMS imports the SSL inspection certificate which is used from FortiGate (and trusted by the clients). I did not find any setting to let me control the certificate used for ssl deep inspection in FortiClient EMS... Anyone knowing where to set the certificate used for deep inspection in FortiClient EMS? Edit: Ok seems like forcing to install the FortiClient extension gets rid of invalid ssl certificate warnings. Is this the way to go then?But I still get certificate warnings when starting Outlook... So how do I set this up correctly?
Hi, we want to create a site-to-site VPN via Fortimanager, but don't want to enable VPN community. Is the following procedure correct? our Fortimanager os version is 7.4.x. 1. login to Fortimanager Device Group2. choose the firewall 3. click VPN and choose interface mode4. create phase 1 5. create phase 26. install the config via installation wizardCan anyone please help to advise? Thanks in advance!
I am testing the IPSEC tunnel with the ztna client (unfortunately there is no forticlient vpn under linux that supports IPSEC), and had trouble with https sites, so I want to add some info for other victims.Somehow my ethernet interface picked a MTU of 1280 instead of the 1500 default for ethernet. This caused that the MTU for the sites behind the VPN was 1170, so I could do a telnet to check that the port was open but couldn't open any site. Forcing the MTU on the ethernet to 1500 fixed the issue and now I can browse all the sites without issue.
Just curious, would it be too much to ask that we be given materials that we can actually highlight and make notes on when studying for the NSE Exams? I have a PDF for the self-paced NS4, but I can't modify this document with personal notes or annotate sections that I need to call out to myself.
Details:Could you kindly explain fml cloud working with an on-prem exchange server?
Working on a FortiManager–FortiGate integration scenario and observed an interesting behavior — looking for insights from the community.I configured the following directly on FortiGate:Firewall policiesAddress objects & groupsStatic routesPrefix listsRoute mapsEverything works perfectly on the firewall.However, when I perform “Import Configuration” into FortiManager:Policies, objects, and static routes are imported correctlyPrefix list and route map names appear, but their entries/content are missingOn the other hand, when I perform a “Retrieve Configuration”, I can see the full configuration including prefix list and route map entries.So the questions:Why does FortiManager import process not fully bring in prefix list / route map configurations?Is this expected behavior (device-level vs policy-level separation), or a limitation/bug?What is the recommended production approach to manage routing objects like prefix lists via FortiManager?Would appreciate insights from anyone who has
Hello There,1- I have been facing an issue with IPsec and need your opinions plz.i have sdwan zone with 5 wan links for internet, site-to-site is configured binding wan1 and works fine, once i confure ipsec-remote vpn on wan1 it works fine too but site-to-site goes down after some time and does not come up unless i completely delete the remote vpn.2- I decided to setup remote vpn on another wan link to avoid any possible conflict having at wan1, but remote vpn does not work at all at WAN2 or WAN3, even though the sdwan rule also created for port 500 4500 via wan2-wan3.
Dear all, I was reading fortigate article related to active-passive mode for primary unite selection criteria. 1. Monitored interfaces - unite with fewest failed monitored interface.2. uptime - unite with highest HA uptime becomes primary3. priority - highest4. serial no - highest If override is disabled.Now the question is that - based on the highest as attached snapshot device will become primary if cluster uptime is higher. but if cluster uptime is less than 300 seconds will not become primary. Thanks in adavnced.
Our ISP recentlly upgraded our internet speeds to 4GB, Is it possible to use a 10gb tranciver in one of the open ports and use that as my WAN port? So I get better speeds (I know i wont get better speeds from desktops etc but I do have 4GB to 4GB site to site vpn tunnels that I do some backups over so it would help speed and time. Thanks in advance.
Hi all,I'm trying to get RADIUS accounting packets from a Windows Server NPS (RADIUS) to be forwarded to a Fortinet FSSO Collector, but I'm stuck.Here's my setup:NPS is authenticating 802.1X Wi-Fi logins using PEAP/EAP-MSCHAPv2.Accounting forwarding is enabled in the Connection Request Policy (CRP) – the option “Forward accounting requests to this remote RADIUS server group” is checked.The Remote RADIUS Server Group points to the FSSO Collector (IP: 10.81.0.36, port: 1813, shared secret OK).In the FSSO collector itself, RADIUS accounting is enabled, listens on 1813, and matches the shared secret.Wireshark confirms that UDP packets on port 1813 are never sent.Every time a user authenticates, NPS logs this in Event Viewer with:pgsqlKopírovaťUpraviťLogging Results: Accounting information was written to the local log file.What I’ve tried so far:Recreated the CRP from scratch with minimal conditions (NAS port type only).Made sure CRP is at the top of
I need to update the firmware on it because the credentials are lost. but now I cant get a new download, or register the product past end of life. Is there anything I can do?*I was able to make an informed decision. Thank you everyone
Hi, I use the FortiClient Single Sign-On Mobility Agent and I am facing an issue: FAC registers all user IP addresses.Let’s consider two users: one connected remotely through VPN and one connected from the corporate LAN. The home network IP address of the remote user overlaps with the IP address of the user in the corporate LAN. As a result, one of the users is removed from FortiGate/FAC with the following error:Internally logoff and removing FortiClient item 11024-HR.xxx.xxx:192.168.12.26 [xxx.xxx/jshith] (all IPs conflicting).I believe that during the initial FAC/EMS configuration I chose the option to register all IP addresses, but now I cannot find this setting. I am not sure whether I am simply overlooking it or whether it disappeared after an update.How should this be handled? Regards, Lukasz
Hi everyone,I’ve deployed an IPsec dial-up VPN to allow users to connect via FortiClient.The VPN uses IKEv2 and a RADIUS server, and all users belong to the emergency group.After configuring FortiClient with all the correct phase 1 and phase 2 parameters, I consistently get the following error when trying to connect:"WRONG CREDENTIAL EAP FAILED CONNECTING TO 8.x.x.x"Below I’ve included the phase 1 and 2 configuration, along with the log captured from the FortiGate.The log clearly shows that the user is correctly identified, as well as their group membership.However, shortly before the error, this message appears:ike V=Vpn:1:Emergency:1804 EAP 14757603831873 result FNBAM_DENIED ike V=Vpn:1:Emergency: EAP failed for user "jjonh"Phase1 configuration:edit "Emergency"set type dynamicset interface "WAN"set ike-version 2set peertype anyset net-device disableset mode-cfg enableset ipv4-dns-server1 8.8.4.4set proposal aes256-sha256set dpd on-idleset dhgrp 14set eap enableset eap-identity s
Hi everyone, I've got the guest flow working — guests get isolated, hit the captive portal, self-register, and get moved to the guest VLAN. SNMP, MAC learning, and L2 traps are all configured and working on the switch side.Now I'm trying to set up the employee flow and I'm not sure what the best practice is. For employees I want them to authenticate against Active Directory and then get placed into the employee VLAN automatically. My question:For AD-authenticated employees, is the captive portal still the recommended approach or should I be looking at dot1x instead? (It is a wired network, no wireless).Any advice or example configs would be greatly appreciated. Thanks!
Hello everyone, I have a question regarding guest self-registration accounts in FortiNAC. Guest accounts are configured with a validity period of 24 hours. Once the account expires, I’m trying to locate the history or record of that account. The only place where I can still see some trace of them is under the Account Requests section. Could anyone please clarify where expired guest accounts are stored, or how we can access their history after expiration? Is there a specific log, report, or database section that retains this information? BR,
Hi All, I am quite new to FortiNAC and would appreciate some guidance. A recent vulnerability assessment identified TLS-related issues on a FortiNAC 500 running version 8.7. Based on our checks, the device is already EOL/EOS. However, immediate replacement is not currently possible, so we are exploring mitigation options. The vulnerability recommendation is to disable TLS 1.0 and TLS 1.1 and allow only TLS 1.2 or higher. May I know whether this EOL FortiNAC system supports disabling TLS 1.0/1.1 through configuration without upgrading the firmware? Any advice or recommended workaround would be greatly appreciated. Thank you very much.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.