User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
We are configuring SAML authentication on our FortiGate firewall to authenticate users before applying internet access policies.Our requirement is:The first firewall policy should only trigger SAML authentication.After successful authentication, no services should be accessible through this rule.Once authenticated, subsequent policies should apply access rules for the authenticated user/group.To achieve this, we created an authentication-only policy with the following configuration:Source: allDestination: Internet ServicesInternet Services used:Microsoft-AzureMicrosoft-Azure.Front.DoorMicrosoft-Office365.PublishedAfter applying this configuration, SAML authentication works correctly when the authentication process is triggered.However, we are facing the following issue:When users open a browser and try to access Microsoft-related services (for example: office.com, outlook.com, etc.), the SAML authentication page does not appear.The browser waits for some time and eventually the webpage
We need your urgent assistance in troubleshooting an issue with our ADVPN deployment.Network Topology1 Data Center1 Head Office6 Branch Offices (Total: 8 locations)We have configured ADVPN for Hub-to-Spoke connectivity. Initially, each spoke had a single leased line, while the hub had dual leased lines. Two Hub-to-Spoke IPsec tunnels were established from the hub side, and the spoke had a single ISP. This setup worked without any issues.Recently, we added a second leased line at every spoke site for redundancy. Now, each spoke has dual ISPs, and both Hub-to-Spoke IPsec tunnels are established successfully. Routing is configured using loopback interfaces over iBGP.Issue DescriptionThe issue occurs only when the old ISP at a spoke goes down and traffic fails over to the new ISP.Although the IPsec tunnels remain UP, Hub-to-Spoke communication becomes unstable. During failover, we observe the following behavior:Sometimes the spoke loses reachability to the Data Center Hub, while the Head O
We wanted enable auto backup of Fortigate firewalls from Fortimanager to FTP server.Please guide.
We are using the free version of FortiClient VPN, and I have found that with both an older version of FortiClient, both 7.4.3.1790, and the latest version, 7.4.3.4726, I am getting the error in the attachment occasionally when fortiauth,exe loads to prompt for credentials to connect. It even does this after I removed and re-added Net 4.8 as a windows feature. Any thoughts? That I know of it is just my machine, but I work fully remote, so I really need to get this resolved.
Hi, we use Transparent Proxy Policies for destination FQDN's only, but I can't really understand why would we do it if we can just stay with the IPv4 Firewall Policy and apply all security profiles there.Can someone explain the differences in behaviors? as traffic needs to match the IPv4 Policy first anyway and I can't see any real benefit just management overhead.
Hi everyone,I'm new to the community and I'm preparing to take the NSE 4 exam soon.While reviewing the guide and testing some scenarios in the lab, I noticed what seems to be an inconsistency in the documentation.The guide states:"Administrative access options are also limited depending on the role that is set for the interface. For example, setting the interface role to 'WAN' would not display the 'Ping' option, mitigating the risk of responding to a DoS ICMP attack from the WAN."However, even when I set the interface role to WAN, the Ping option is still available.Has anyone experienced the same behavior or can explain why this happens? Is this a known behavior or perhaps a change in the latest version?Thanks in advance for any clarification!
Our cyber insurance company is running an internal pen test, and I wanted to see what others do when FortiDeceptor is running. My plan was to say nothing but add their IP to the safe list to prevent them from getting locked out mid-test. Then, when they find one, I will disclose it if they report it as a finding.On the other hand, I feel that I am lowering my security for them, so I am torn on what to do. Any pen testers or people with FortiDeceptor out there who have had a similar issue?
I have setup and enabled SSO into our FortiVoice system using Google Workspace. Everything appears to be configured correctly, and Google is returning the email address in the SAML data. However, it never actually logs on. I have tried this configured for both the admin side, as well as the user side. I type in my extension, it redirects to the Google login page, I select the email account tied to that extension, and it just returns to a login page ending in voicesso. I have exhausted my ability to locate the issue and thought it might be something simple I am overlooking. We are currently running FortiVoice version 7.2.4 if that helps any.I appreciate any ideas anyone might have.
The FortiClient VPN-only version 7.4.3.4323 has been installed onto a MacBook running macOS 26. Full disk access has been given to fctservctl2 and the network extension FortiTray has been enabled although FortiClientProxy and FortiClientPacketFilter were not present to enable. The settings for this VPN use the public IP address of the FortiGate and various DH Group and encryption levels have been tried but all to no avail. The VPN connection is IPsec VPN and tries connecting for a while then comes back with a connection timeout error. The native IKEv2 client for macOS does not work either. I read somewhere that Fortinet added macOS Tahoe 26 support in FortiClient 7.4.5 but there is no VPN-only version later than 7.4.3. I have also read that SSL-VPN support is being stopped so surely there needs to a new VPN-only version where IPsec VPN can be used. Is there ever going to be a newer VPN-only version released? Or is the option available now FortiClient Standalone? This does not seem to b
My WAN utilization is full (total 20Mbps), how we can easily which source is consume high bandwidth?I try to block the graph and click fortiview source and destination and if i compare with the Netflow from my NPM then the source is different.
Hi I am using ssl inspection on my lab.I have downloaded the certificate from fortigate and installed it on windows trusted store and on Firefox.but still have the certificate warning problem ! What do i miss?
Hi FWB adminsFortiWeb 8.0.6, I set it up as SP.When I try run SAML debug as documented in admin guide and perform SAML authentication, I get redirection to SP but I get nothing in debug output.diagnose debug application samld -1 (or 7)diagnose debug enable<output empty>Is there something else to enable in order to make SAML debug work? Any help would be appreciated.
Hello, I have network of around 7 APs. FortiAP FAP431F. I manage them through forticloud. I have an SSID that I want all APs to broadcast it, except one. How can I do that? In the availability page in the SSID configuration, I have the option of “Available to all APs” or “Available to the APs with the following AP tags”. I could not find anywhere in forticloud anything about AP tags. How can I do this? Thank you.
I am looking to set up two separate SSL-VPN access connections, that would by used by two separate groups, both groups are using the same Fortinet device in one domain. (Example:) Group One: Bill is the admin of the Marketing group and supports 10 users.Group Two: Zach is the admin of the billing group and supports 10 users. I want to make sure that both groups can access the VPN through separate IP address and separate ports. Environment FortGate 101D, Firmware 7.2.10. Thank-you
Hello Fortinet community,I am a Systems and Network Administration student working on my final-year thesis on"Implementing sandboxing technology for proactive security of incoming network flows."I need access to a FortiSandbox image for lab testing and practical research. I do not have a commercial serial number with support.Could anyone advise if there is an academic or evaluation image available, or guide me on how to obtain one for student research purposes?Thank you very much for any assistance.
HelloI completed the NSE 2 course successfully, but my NSE 2 certificate/badge is still not showing in my account.More than 48 hours have passed since I completed the course.Thank you.
Hello buddies,I’m new to the Fortinet community and would like to start learning how to properly configure and manage FortiGate.My goal is to set up a small hands-on lab where I can learn about firewall policies, VLANs, VPNs, web filtering, and basic network security without affecting the production environment.Could you recommend a learning path, course, documentation, or lab setup suitable for beginners? Would FortiGate-VM be suitable for this purpose? What networking knowledge should I have before getting started?Thanks for any guidance or recommendations here.
I have configured a FortiSwitch Dynamic Port Policy (DPP) to allow only 3 specific MAC addresses on a switch port. When one of the legitimate MAC addresses is connected, the DPP identifies the device and assigns the configured dynamic VLAN successfully.However, I am experiencing an issue when the legitimate device is disconnected and an unauthorized device is connected to the same port shortly afterward.My test scenario is:Connect legitimate device (Test_MAC1). DPP identifies Test_MAC1 and assigns the dynamic VLAN. Test_MAC1 is disconnected from the switch port. Within a few seconds, connect an unauthorized device (Test_MAC4). Test_MAC4 is not included in the DPP allowed MAC list. However, Test_MAC4 still receives an IP address from the previously assigned dynamic VLAN and can access the network.It appears that the dynamic VLAN assignment/state is not being flushed immediately when the legitimate device is removed from the port.Is there any way to Fix this?Dynamic port policy Configura
Some users need to access Tor, so I created a rule and set the destination to the Fortinet Internet Service Database (ISDB) associated with Tor. We tested it and saw that they could access Tor pages via the web. However, when the user tries to access the "tor.browser" application, it doesn't load. These users have internet access, but only through HTTP and HTTPS ports. Wasn't the TOR.BROWSER application part of the Fortinet Internet Service Database (ISDB)? Or is it necessary to add the ports used by TOR.BROWSER to the internet access policy? Do you know which ports that application uses, tor.browser?
Hi I'm trying to collect Palo Alto logs into FAZ.If I want to view the normalized logs, do I have to use the log parser?cause I use Log View --> Log Browse, it only showing raw log.
I would like to understand whether the following design is possible and, if so, how it can be configured on a FortiGate 200F or 600F.Current Topology:FortiSwitch 124F ── FLINK_INET_1 ────┐ FortiGate 200FFortiSwitch 548D ── fortilink ───────┘FortiSwitch 124F-POEVLAN 700 configured with IP address 11.11.11.1/30Connected to FortiGate 200F via a FortiLink-enabled interface i.e FLINK_INET_1.FortiGate 200FConnected to both FortiSwitches using separate FortiLink-enabled interfaces.Requirement is to configure VLAN 700 as a Layer 2 bridge only, without Layer 3 routing on the FortiGate.FortiSwitch 548D-FPOEVLAN 700 configured with IP address 11.11.11.2/30Connected to FortiGate 200F via another FortiLink-enabled interface i.e fortilink.RequirementI need VLAN 700 traffic to pass transparently through the FortiGate 200F, effectively allowing the two FortiSwitches to communicate as if they were on the same Layer 2 VLAN.QuestionHow can VLA
Hello,is there any way to get prepared for NSE1 other then Fortinet Learning Center ? Thanks
Dear Security Review Team, I am writing on behalf of IASC Ltd. (Indian Applied Science Corporation) regarding the security classification and/or blocking of our institutional domain: https://newiasc.com IASC Ltd. is an independent institution operating in the maritime security, competency, technology, research and engineering domain. Our website provides institutional information, professional publications, maritime research, technical material and related professional services. We have been informed that newiasc.com is currently subject to an adverse security or reputation classification within external security and website reputation systems. We respectfully dispute any such classification and request an immediate formal false-positive review of our domain. The domain is operated and controlled by IASC Ltd. and is not operated for phishing, fraud, malware distribution, scams, spam, gambling, adult content or other malicious activity. We have conducted server-side verification of our
Hi,I’m using fortimanager provisionning template to manager my IPSec VPN.I’m create a template.In this template I create a IPSec tunnel (Phase 1 and phase 2) with a name like myipsec_model.To create a second Ipsec tunnel, I’m click on clone option. A new tunnel it created with this name : clone_myipsec_model.I can’t rename the new IPSec configuration. I cleck on rename button change the name but this one is not change.I’m use fortimanager 7.6.7.Thanks you for your helpRegardsStéphane
Hi,For one of our customer, I have got the FortiGate 200G firewall as rented device as we are yet to receive our own new firewalls due to lead time. Meanwhile after changing the device password, firewall is asking for Forti care registration which I don't have as this been rental device, is there any way forward for this, I tried skipping the registration from bios but firewall does not boot further with error - Failed to boot the system.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.