User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
After Adding Acces spoints to FortiNAC (by discovery using SNMP strings), i can't see the virtualized devices tab , why ??
When I go to connect to my VPN and type in my password, a dialog opens for me to put in a token from my fortitoken app on my phone. The box does not focus the input box for text though, so I have to manually click in. It is not apparent, as the password dialog focuses the password field immediatly. I have had to input another token multiple times because it keeps not typing when I want to type. Please fix this.
I’ve got a couple servers at different sites that need to synchronize data between them on a set schedule over an HTTP/2 connection across a VPN tunnel.I’m having an issue where it appears that the FortiGates are marking the sessions as timed out (evidenced by action in logs) despite traffic actively flowing across the tunnel.I tried increasing the TCP timers on rhe service object, changing the policy to proxy mode, and disabling asic offload, but it still appears to be having issues.I also tried a diag debug session list but never saw anything about what’s causing the timeout.Any ideas?
Hi Everyone, I would like to setup Dual WAN ports with a single IPSec tunnel for redundancy on FortiGate Firewall. To configure dual WAN ports with a single IPSec tunnel for redundancy on FortiGate, create two separate IPSec tunnels (one for each WAN) and use SD-WAN to manage failover. Set up identical phase 1 and 2 parameters for both, but configure the remote gateway IP, and ensure static routes or BGP routes are managed via the SD-WAN interface, allowing the tunnel to fail over seamlessly if one ISP fails. Key Configuration Steps:SD-WAN Setup: Add both WAN ports (e.g., WAN1, WAN2) to an SD-WAN zone.Create Two Tunnels: Create "Tunnel_to_ISP1" (interface: WAN1) and "Tunnel_to_ISP2" (interface: WAN2).Routing: Create static routes for the VPN traffic, setting the SD-WAN interface as the gateway.Redundancy: Configure Dead Peer Detection (DPD) to detect tunnel failures.Policies: Create firewall policies to all
Dear All, I have a site in hk with subnet 192.168.1.0/24 this site using fortigate 60E, and in hk sitei have a openvpn appliance access server running , and also one openvpn access server with ip 192.168.1.72, and also I have another site in china with subnet 192.168.12.0/24 and also using fortigate as a internet firewall, a site to site vpn built between hk and china, openvpn appliance access server created an user account and exported .ovpn and import to a window server as openvpn client and the window server with ip 192.168.12.90 also running rras with lan routing enabled, and in hk fortigate having static route 192.168.12.0/255.255.255.0 with gateway address 192.168.1.72, whenever traffic toward 192.168.12.0/24 its will route via 192.168.1.72 (the openvpn appliance access server), and in china, there is a esxi with ip 192.168.12.103 and fortigate 192.168.12.99, I found that I can ping and telnet 443 with esxi and for
Please help me block logs saved to the SSD. I'm referring to "Local Traffic" and entries that appear even 2-3 times per second. For now, I've disabled "Local Traffic" logging on the SSD, but I'd like to see traffic from Fortigate (e.g., to globalguardservice, NTP, etc.). The FG61E is in transparent mode, connected to the internet via the Local Interface.This large number of entries concerns local network connections from some devices. These entries include:Source=192.168.3.XX (LAN addresses)Destination=255.255.255.255 or 192.168.3.255Application Name="DHCP/DHCP Relay" or "udp/15600"Destination Interface=[object Object]Source Interface=internalHow can I block this, but still allow other connections, such as those to Fortigate servers and other services, to be visible?
Hi everyone, I need your help.I have a Fortinac device with 200 licenses. However, I've purchased an additional 100 licenses, which should total 300. However, this total isn't displayed in the Fortinet GUI; only 200 licenses are shown. The additional 100 licenses are visible in the Fortinet support section, where the device is registered. How can I make them appear in the GUI? I understand that the additional licenses should be displayed automatically.
In Administration - Deployment - Collector, there are two available options: “Update Collectors” and “Request Collector Installer.”For Collector (Agent) deployment, the correct option to use is “Request Collector Installer.” Through the Update Collectors section, you can update the agent version for the relevant operating system by selecting either a single collector group or multiple collector groups. When deploying a Collector, after selecting the operating system, you can choose either the current version (n) or the previous version (n-1).For server systems, using the n-1 version is generally the safer option.Parameter descriptionsAggregator Address = Refers to the main server in the data collection and transmission layer that centrally processes telemetry collected from endpoints and forwards it to the FortiEDR management console.Organization = Represents the tenant identity and indicates w
Good morning, team,I have been experiencing a recurring issue within my infrastructure for some time.I have already opened a case with TAC; however, no definitive solution has been provided so far.Currently, I manage an environment consisting of approximately seven FortiAnalyzers, each with an associated FortiAnalyzer Collector.Until September 2025, there were no issues within this topology. However, at a certain point, the environment began to exhibit unexpected behavior.FortiGates started losing log visibility across multiple features, including Traffic Forward, FortiView, and any other functionality that relies on logs sourced from the FortiAnalyzer.The issue initially affected several FortiGates connected to FortiAnalyzer 01. After several hours of troubleshooting, we identified that restarting the FortiAnalyzer Collector linked to FortiAnalyzer 01 would temporarily restore functionality, allowing logs to be displayed again on the FortiGates. However, this proved to be only a tempo
FortiManager 7.4.9 Free Trial managing FortiGate 100F on 7.4.9 Config status: Synchronized On FortiManager I've created a new IP reservation under IP Assignment Rules, device global DB status changes to modified, yet when I use the install wizard I'm unable to push the reservation to the FortiGate 100F. The install preview is empty and it doesn't recognize the reservation. Either new one or deleting an old reservation.I have tried to modify a firewall policy along with the reservation but it only recognizes changed policy not the reservation.
I created a LETS ENCRYPT Cert on my FortiAuthenticator and Fortigate that has the SSID for Guests, always had an issue with GODADDY on Apple devices, so we moved to LE. creating the cert via ACME was ll good, cert is valid , matches the FQDN etc, but now annoyingly the problem is worse, Apple and Android dont trust the cert! when they connect to the GUEST SSID, the phones browser says "Security Warning SSL_UNTRUSTED""This certificate isn't from a trusted authority" but the common name "myfortiauthenticator.mydomain.net" is signed by Lets Encrypt: Issued by:Common name:R13Organisation:Lets Encrypt and the cert is 100% valid. Fortinet support Lets Encrypt and ACME, and is a perfect solution, but whats the point if Apple and Android dont trust it? or am I missing something?
Hi, Can somebody please shed any light on this for me. I have configured Application Control to 'Block' the 'Proxy' category and I have 'Deep SSL Inspection' enabled on my firewall policy. When the firewall policy is set to 'Flow-mode' the NordVPN client on the PC is blocked, however when the exact same policy is set to 'Proxy-mode' NordVPN can connect successfully. I can see logged Security Events for Wireguard being blocked when in 'Proxy-mode' but eventually the NordVPN client passes through the UTM and connects. Can somebody please explain why this is the case? I thought 'Proxy-mode' was a more thorough inspection and would expect to see the opposite behaviour. Interestingly just to add to this, I see a lot more granularity in the Applications listed in the Security Event logs when using 'Flow-based' opposed to 'Proxy-based' inspection. Regards, Jonathan.
Hello Fortinet CommunityWe're facing a connection problem with an Fortigate60, on which no connection to any rusdesk Relay is possible. On the Firewall of the Target there is no traffic at all from the source, which means somehow the connection is still blocked. Does anyone know what could cause this?
Hi, We are investigating a strange failover issue with managed FortiSwitches by a HA pair of Fortigates 601F. We are having strange issues with traffic loss if we failover to the passive Fortigate. The issues are only on vlan's were we have intra vlan blocking enabled. If we disable this feature everything is working fine. The problem is that we have traffic loss from the clients to the gateway/fortigate for 2 minutes and 30 seconds after failover. Support found out that the mac adress for that Fortigate vlan is learned on the wrong trunks. We have switches in a ring connected to a pair of 1024E MCLAG core switches. I'm analyzing this issue and in the core switches logging I see the following messages during the failover/issue: 10: 2026-01-08 10:14:49 log_id=0103030700 tz=+0100 type=event subtype=system pri=information vd=root action="daemon-startup" user="init" ui="None" daemon="l2dbg" pid="2589" msg="Daemon l2dbg started"11: 2026-
I have a load of Proxy rules, and have placed them in a specific order, So that all the "UNAUTH" Rules are at the top and then the AUTH rules, Problem I have, I need an UNAUTH rule to catch the rest of the traffic using a webfilter, to block things, but if I place this rule at the end of the UNAUTH rules, the people who need to AUTH to certain sites will now hit this rule first, which i dont want, its for Apple IPHONE users, that cant AUTH but need to be allowed out. The Auth Rules are important to allow certain groups to certain sites, but as they will be below this UNAUTH catch all policy, they will hit that? I cant figure out how to arrange the rules! any advice appreciated.
Hardware: FortiGate 101F paired with FortiAP.Account: I have created a local user on the firewall.Goal: I want an Android tablet to connect to the Wi-Fi using TLS authentication.How do I generate the necessary client certificate for the Android tablet to authenticate and connect to the Wi-Fi? I've already asked Gemini and ChatGPT, but neither provided the correct procedure. Both of them just gave me AI hallucinations.
Hello,I am currently using FortiClient EMS version 7.2.4, while our field users are running version 7.2.5. Occasionally, some users encounter the 'Endpoint blocked by EMS' error.There are no issues regarding the device license status. I can resolve the issue temporarily by manually unblocking the user from the console, but this is not a permanent solution as the problem recurs. What could be the underlying causes of this issue?
Hi Community,Can anyone share me the configuration guide to configure Hub and spoke dialup VPN with BGP with Fortimanager.I wanted to configure this on Fortimanager.Issue is my Spokes are not getting a IP from Hub during Negotiation.I found the guide to do this via Firewall but not able to find any documentation to do this via fortimanager.
hi there,I need help please.I use FG60F with firmware 7.2.x I've created firewall policy with webfilter and ssh inspection. suddenly, some computers can't access certain https website, but the other PC still can access the web without issue. if the -problem computers- use direct internet (not via fortinet), they can access the website. where is the issue? anyone has same experience? thank you
I'm trying to allow CoPilot in office.outlook.com sessions, but block copilot.microsoft.com in general browser sessions, as well as all other LLMs My web filter has Artificial Intelligence Technology blocked in the Fortiguard category based filter, and a URL filter: *.google.com/*udm=50**.google.com/*udm=14*m365.cloud.microsoftbing.com/chatcopilot.microsoft.com*.bing.comcopilot.microsoft I also have an application control profile on the proxy policy, with the GenAI category blocked. The only way I can get it working is to have the AI blocking web filter in both the the firewall and proxy policies. Having the web filter in just the proxy policy works for most LLMs via browser, except CoPilot. It works, but I'd like to know why, as this goes against the admin guide on transparent proxies. https://docs.fortinet.com/document/fortigate/7.6.6/administration-guide/15908/transparent-proxy I don't like not understanding my firewall's config :(  
Hi Folks, This new thread is created to clarify if it possible to use the functionality Fortiguard DDNS to implement a domain name once that name is configured, that be use in a remote access VPN. As example:I configure and activate the DDNS domain XYZcompany.fortiddns.com in the fortiguard ddns. (Image Attached)Later, I want to use that DNS XYZCompany in our FortiClient. (Image Attached) Thanks for your answer. Best Regards,Joel
Fortigate firewall FG90G HA what are the must keep requirements to be kept ready before HA config including Licenses do I require single or two licenses
As part of investigation by checking sample of 100 Fortigate sites from 800+ sites. The data showed that 48 Fortigate sites out of 100 sites having memory conserve mode based on crashlogs. It appears that it took a second when entering and then existing memory conserve mode. Some nodes showed multiple conserve mode instances. Example:29: 2026-03-09 17:47:57 green="1572 MB" msg="Kernel enters memory conserve mode"63: 2026-03-09 17:47:58 service=kernel conserve=exit total="1918 MB" used="1541 MB" red="1687 MB" The customer has 800+ Fortigate sites. I'd like to be sure that no impact to the customer given their large deployment. I was told that the configuration below will help to resolve the conserve mode. Two questions are:Can someone help to explain what the configuration below does and how it will help? Is it the best solution to resolve or eliminate conserve mode? Are there any impacts and drawbacks?#----------------------------------------
Hi guys,I have a question about FCSS after july 15 2026.I was planning on FCSS Secure Networking.I passed NSE 7 - Enterprise Firewall Administrator 7.6 and was planning on NSE 6 - Network Security Support Engineer 7.6.After July 15 both of these exams being canceled.I couldn't figure out what will happen according to their new mappinghttps://www.fortinet.com/nse-training-updateWill it count for something ? am I gonna receive NSE 6 ? or I will need to do NSE 4 to get NSE 7?
Just a simple inquiry. We have a setup for Active-Passive (HA) in our remote site. Since fortiguard services are shared from Master, does it really necessary to avail full license to both primary and secondary firewall?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.