User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi everyone,I am experiencing a very strange display behavior on my FortiLink topology after adding a new device.Context and Versions:FortiGate: FGT-200F running v7.2.13 build 1762 (Mature)FortiSwitches: 8x FSW-148F running v7.6.6 build 1137Topology managed via FortiLink.Issue Description: Up until yesterday, I had 7 switches deployed and everything was working perfectly. The physical inter-switch links (ISL) appeared correctly in the "FortiSwitch Ports" section as "dedicated to connect to peer FortiSwitch".Then, I added an 8th switch ("03" on image 1) using our standard procedure, daisy-chaining it behind another FortiLink-managed switch ("02"). Right after connecting it, ALL our switches lost the "dedicated to connect to peer FortiSwitch" status on their uplinks/downlinks.Now, the physical ports connecting the switches together appear as shown in screenshot #2:They are tagged as simple "Edge Ports".Their Native VLAN is _default.Forti_Link (_default) and Allowed VLAN is quaranti
I'm trying to install the FortiClient package on Fedora Workstation 43, which doesn't seem to be properly tested for this distro. I am using the official guide mentioned here. The reason for posting the issue here in the community is to gain the attention of FortiClient developers so they can resolve the issue promptly. ~ sudo dnf install forticlientUpdating and loading repositories:Repositories loaded.Package Arch Version Repository SizeInstalling:forticlient x86_64 7.4.6.1867-1.el7 repo.fortinet.com 611.7 MiBTransaction Summary:Installing: 1 packageTotal size of inbound packages is 186 MiB. Need to download 186 MiB.After this operation, 612 MiB extra will be used (install 612 MiB, remove 0 B).Is this ok [y/N]: y[1/1] forticlient-0:7.4.6.1867-1.el7.x86_64 100% | 4.0 MiB/s | 186.5 MiB | 00m47s-------------------------------------------------------------------------------------------------------------------------------------------------[1/1] Total 100% | 4.0 MiB/s | 186
Hello everyone,we would like to distribute an IPSec tunnel configuration to other users, including external contractors, using the export/import of an XML file.However, I’ve noticed that when a user imports such an XML file, it overwrites all previously configured tunnels.Is there any way to create an XML file that allows users to import only one or several tunnels in a simple and user-friendly way, without replacing all existing ones?Thank you very much in advance for your help!
Hi all,Has anyone experienced an issue where, after a FortiManager upgrade, routing entries were unexpectedly removed from a routing template?In our case, four static routes (including the default route) disappeared from the routing template itself — not directly from the FortiGate configuration, but from the template in FortiManager. As a result, when templates were pushed, the routes were also removed from the managed devices, causing connectivity issues.Additionally:The routes were no longer present in the template database after the upgradeRe-adding them led to conflicts during install (likely due to ordering or object inconsistencies)I’m trying to determine whether this behavior is:A known issue related to template migration during upgradeA change in how routing templates are handledOr a one-off corruption/inconsistencyHas anyone seen similar behavior or has insight into this?Thanks!
Upon opening Forticlient VPN a bunch of users seem to get this error, the only work around so far was uninstalling and re-installing. However noticing that this problem comes back again after a while. System is Windows 11 25h2 with latest updates. Visual C++ latest redistributables installed. What other
Hello Community: any idea of strategy for the migration of FortiManager and FortiAnalyzer managing an SDWAN architecture of concentrator in HA and spokes from a VM of a Service Provider to my Data Center with physical appliances. Best regardsCC
I'm a home lab user, and as such I don't have a full EMS configuration setup. However, I do have a couple of linux boxes out in the wild (my kid, and myself each have a couple). When we were running SSL VPN on my 60F, there was no issue. However, with it having been depricated and my possibly moving to a 90G in the near future, I'm looking for the next best option. After doing some research, it appears that the FortiClient VPN (Free) version no longer supports IPSec on Linux. In the past, if I wanted to connect Linux to a SonicWall, WatchGuard, or pfSense box, I would use OpenVPN. So, I'm asking the community if they have used it to access their home lab remotely without having to rely on a secondary server sitting behind their gate.
Hello there,We have a couple of challenges in deploying FortiGate and FortiWeb on EVE-NG Community in the Lab. As you know, the current exam version is based on FortiOS 7.6 and this renewing is probably going to continue, which means we have to get ready for next versions. The problem is:1. When we download FortiGate 7.6.4 & 7.6.3, both version looks incompatible with EVE-NG on VMWare workstation (25H2 and 17.5) and Hyper-V. The former hangs in "Formating shared partition and the later hangs in a stage ahead (somewhere logging about IPS..... ). Some folks advised using V7.2.x or... . But, this is not the answer I'm looking for. Same problem with last to versions of Fortiweb. 2. As you all may knows, Fortinet has made changes in licensing policies. Reports says V7.6 needs a valid license even for lab setup. This makes the case a little complicated, because we could use a 2-months Eval license before. If your recommend is to raise a ticket and asking for Evaluation license,
Hello community , If I use certificate inspection in an SSL/SSH inspection policy, users don’t need to have the certificate installed on their machines for basic URL filtering. However, for blocked pages, will users see the block banner? I assume they won’t. In that case, I would need to install the certificate on their devices, right? If so, does that mean there’s no real benefit to using certificate inspection if you don’t want to install certificates on guest machines? please suggest. basically customer want filtering but with no certifcate install.
Hi,I use the FortiClient Single Sign-On Mobility Agent and I am facing an issue: FAC registers all user IP addresses.Let’s consider two users: one connected remotely through VPN and one connected from the corporate LAN. The home network IP address of the remote user overlaps with the IP address of the user in the corporate LAN. As a result, one of the users is removed from FortiGate/FAC with the following error:Internally logoff and removing FortiClient item 11024-HR.xxx.xxx:192.168.12.26 [xxx.xxx/j**bleep**h] (all IPs conflicting).I believe that during the initial FAC/EMS configuration I chose the option to register all IP addresses, but now I cannot find this setting. I am not sure whether I am simply overlooking it or whether it disappeared after an update.How should this be handled?Regards,Lukasz
Hello everyone,We are currently in the design phase of an ingress security architecture in AWS and have not implemented anything yet. We are seeking guidance, reference architectures, and best practices to help us design this correctly.Proposed Architecture (Under Consideration)Internet → External NLB (TLS pass-through) → FortiGate-VM instances (inspection layer) → Internal ALB → Web applicationsThe external NLB would be internet-facing and handle TCP/TLS pass-through (no SSL termination).Traffic would be forwarded to FortiGate-VM (NGFW) instances for inspection.After inspection, traffic would be sent to an internal ALB, which would perform:HTTPS terminationHost-based routing (e.g., app1.example.com, app2.example.com, etc.)The internal ALB would route traffic to backend targets (EKS / ECS / EC2).GoalsAt the FortiGate layer, we aim to:Apply web filtering policiesPerform deep SSL inspection (if feasible)Allow only clean/validated traffic to reach the internal ALBAllow specific domains, U
We have enabled the explicit proxy feature to forward traffic to an upstream proxy saas provider.Is it possible to also enable the Inline CASB to work as well to help direct traffic? As an example, I want to bypass the upstream proxy for all Azure/M365 traffic and go direct rather than to our upstream proxy provider.
i have been trying to get demo account for fortisoar i have not recieved any email It has been 4 days since when i applied for demo account .I tried multiple work Emails and multiple times still no response
Dear Fortinet Team,Thank you for considering my suggestion. I would like to request that Fortinet develop a software solution similar to (Cisco Packet Tracer), designed for network simulation and training purposes. Such a tool would be highly valuable for learners and professionals who want to practice and strengthen their networking skills in a safe, virtual environment.I appreciate your attention to this idea and hope it may contribute to future developments. Best regards, Spoiler (Highlight to read)How CanI Learning Forti Product ?How CanI Learning Forti Product ?
Hi,We recently released two Linux VMs (Ubuntu 24.04 LTS) to configure the EMS server and external DB Postgres. The architecture is EMS with standalone remote DB without Docker (as reported on the Fortinet official document).With this introduction, I'll explain that the problem we encountered occurred 10 days after completing the configuration.Suddenly, the EMS GUI was no longer usable, displaying an error 500 (see image below). Both VMs, the one hosting the EMS and the one hosting the external DB, were correctly reachable via SSH. As additional information, I'd like to point out that the EMS server and external DB are on the same network and there are no network devices in between them. Furthermore, the hardware resources of both VMs are oversized compared to Fortinet's minimum requirements, and during the error, we didn't detect any problems or resource spikes on the VMs (e.g., disk full or resource spikes).Since the error persisted, we first attempted to restart the systems in t
We are experiencing a problem on an endpoint managed through FortiClient EMS. The PC is running Windows 11 updated to the latest available build, and the latest FortiClient version compatible with EMS is installed. The malfunction concerns the Web Filter extension on Google Chrome: • Randomly, the FortiClient extension disappears from Chrome. • When the extension is missing, the user is no longer able to browse (traffic blocked). • After one or more reboots, the extension reappears automatically and browsing works again normally. Issue to Resolve: The FortiClient Web Filter extension on Chrome is being removed randomly, preventing browsing. After a reboot, the endpoint restores the extension by itself. We request support to identify the cause and provide a definitive solution.
hi there,need advice, and some helps for best setup to my needs.I just bought Fortigate FG-71G.this fortigate will manage:- 4 ISP: ISP_1, ISP_2, ISP_3, ISP_4. only ISP_1 and ISP_2 have public IP.- this fortigate will connect to another fortigate use VPN IPSEC via ISP_1 (backup with ISP_2) if ISP_1 down.- also will use VPN SSL use connection ISP_1, backup with ISP_2 if ISP_1 down. - 5 unit floor (each floor can't communicate each others, unless require different, (unit_A to Unit_E) with:1. unit_A- don't have access internet- can communicate with unit_B, with limited services.2. unit_B- will have access internet via ISP_4.- can communicate with unit_A, with limited services.- if some case ISP_4 down, it may use ISP_3 (configure/ switch manually)3. unit_C- will have access internet via ISP_4- need divide into 3 groups, but can access 1 shared printer.- each groups can't communicate each other (except to shared printer). shared printer will be connect to Active directory in same netwo
Hi, I'm looking to update the firewall to remediate vulnerabilities currently on FGT60F-FW-7.00
Hello TAC,We are replacing 2 × FS-424D core switches (FortiLink-managed, configured as an MC-LAG pair with ICL) with 2 × FS-424E.When we attempted to replace the first switch, all downstream switches and APs went offline.Can you confirm the correct replacement sequence for this scenario, and whether the new 424E switches must be pre-configured before connection or if they will automatically inherit configuration from FortiLink after joining the fabric?Thanks.
Hello,I have an issue which I cannot find a solution to. I installed FortiClient VPN, created connection, imported certificate, and allowed disk access. After entering credentials for VPN I get prompt "Fortitray application ask to use keychain type "System"" - there I need to enter admin credetials. If I enter admin creds 5+times it will connect.How to allow it permanently?Certificate is trusted, Fortitray is allowed everywhere I could find.Macbook Air 2020macOS Tahoe 26.1Forticlient VPN 7.4.3.6667Thank you for your help
fortinet 60f no internet issue. need reboot fortinet some time unble to get login page
After Adding Acces spoints to FortiNAC (by discovery using SNMP strings), i can't see the virtualized devices tab , why ??
When I go to connect to my VPN and type in my password, a dialog opens for me to put in a token from my fortitoken app on my phone. The box does not focus the input box for text though, so I have to manually click in. It is not apparent, as the password dialog focuses the password field immediatly. I have had to input another token multiple times because it keeps not typing when I want to type. Please fix this.
I’ve got a couple servers at different sites that need to synchronize data between them on a set schedule over an HTTP/2 connection across a VPN tunnel.I’m having an issue where it appears that the FortiGates are marking the sessions as timed out (evidenced by action in logs) despite traffic actively flowing across the tunnel.I tried increasing the TCP timers on rhe service object, changing the policy to proxy mode, and disabling asic offload, but it still appears to be having issues.I also tried a diag debug session list but never saw anything about what’s causing the timeout.Any ideas?
Hi Everyone, I would like to setup Dual WAN ports with a single IPSec tunnel for redundancy on FortiGate Firewall. To configure dual WAN ports with a single IPSec tunnel for redundancy on FortiGate, create two separate IPSec tunnels (one for each WAN) and use SD-WAN to manage failover. Set up identical phase 1 and 2 parameters for both, but configure the remote gateway IP, and ensure static routes or BGP routes are managed via the SD-WAN interface, allowing the tunnel to fail over seamlessly if one ISP fails. Key Configuration Steps:SD-WAN Setup: Add both WAN ports (e.g., WAN1, WAN2) to an SD-WAN zone.Create Two Tunnels: Create "Tunnel_to_ISP1" (interface: WAN1) and "Tunnel_to_ISP2" (interface: WAN2).Routing: Create static routes for the VPN traffic, setting the SD-WAN interface as the gateway.Redundancy: Configure Dead Peer Detection (DPD) to detect tunnel failures.Policies: Create firewall policies to all
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.