User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
As part of investigation by checking sample of 100 Fortigate sites from 800+ sites. The data showed that 48 Fortigate sites out of 100 sites having memory conserve mode based on crashlogs. It appears that it took a second when entering and then existing memory conserve mode. Some nodes showed multiple conserve mode instances. Example:29: 2026-03-09 17:47:57 green="1572 MB" msg="Kernel enters memory conserve mode"63: 2026-03-09 17:47:58 service=kernel conserve=exit total="1918 MB" used="1541 MB" red="1687 MB" The customer has 800+ Fortigate sites. I'd like to be sure that no impact to the customer given their large deployment. I was told that the configuration below will help to resolve the conserve mode. Two questions are:Can someone help to explain what the configuration below does and how it will help? Is it the best solution to resolve or eliminate conserve mode? Are there any impacts and drawbacks?#----------------------------------------
Hi guys,I have a question about FCSS after july 15 2026.I was planning on FCSS Secure Networking.I passed NSE 7 - Enterprise Firewall Administrator 7.6 and was planning on NSE 6 - Network Security Support Engineer 7.6.After July 15 both of these exams being canceled.I couldn't figure out what will happen according to their new mappinghttps://www.fortinet.com/nse-training-updateWill it count for something ? am I gonna receive NSE 6 ? or I will need to do NSE 4 to get NSE 7?
Just a simple inquiry. We have a setup for Active-Passive (HA) in our remote site. Since fortiguard services are shared from Master, does it really necessary to avail full license to both primary and secondary firewall?
Hello, I'd like to move the WAN connection from WAN2 to WAN1 on some FortiGates managed by a FortiManager, just so the physical installation is the same on all gates. While I am aware that this will bring an outage, and that's OK as long as it is planned, I want to make sure that when the cable is connect to WAN1, internet traffic goes out as it should.So, ideally, I would prepare the following configuration on FortiManager:deconfigure IP of WAN2 (which is actually used as internet connection)reconfigure IP of WAN1 with the old IP of WAN2modify the gateway in SD-WAN BUT, logically, if you do step 1 above, connectivity of the FortiGate is lost, so, my question:Will the above configurations be fully loaded on the FortiGate, before getting fully applied, or will the each step be done one by one by the FortiManager, connectivity lost after step 1 and my install fail, requiring an on-site intervention of a FortiGate administrator? If it would be the first situation (conf
Hi,I am writing to request a review and whitelisting of my domain. Previously, my website had some security issues; however, I have completely rebuilt the website from scratch (+ better host, + new PHP version + FTP fix) and ensured that all malware and vulnerabilities have been fully removed.All necessary precautions have been taken to ensure that the website is now clean, secure, and compliant with best practices.URL: https://lesbateauxagathois.comI kindly request you to review my domain again and whitelist it at your earliest convenience.Please let me know if any further information or verification is required from my side.Thank you for your time and support.
I am working on relaxing our SSL VPN with IPSEC. currently running 7.2.12 on the FG (azure vm) and using the free FTC 7.4.3.IPSEC is configured with split tunneling, accessible networks is using an address group and all members are subnets. Connection on all FTC apps was imported from a config file.ISSUE: some devices are getting a 0.0.0.0 route pointing to the ipsec tunnel. other devices are getting the correct routes when connecting.any ideas what would cause some devices to not get the correct routes?
We have a Fortigate 200E, running firmware 7.6. IP address of 10.10.0.1 (Internal Software Switch).I deployed a Freeradius Server, IP 10.10.0.11, for RADIUS based 802.1x WPA-Enterprise authentication for Wifi. The Radius Server is up and running, I can run a radtest from my local machine on the network behind the Fortigate and get successful connections.This issue is when I go to add the FreeRadius information to the Radius Server section on the Fortigate, I am constantly hit with "Can't contact RADIUS server". My secret and IP are correct. I have tried to make a firewall allow rule from internal to internal, source all, and destination 10.10.0.11 with Radius services, but it didn't make any difference.I've gone through all the Googling I can, tried setting the Source-ip to the Fortigate, nothing I do is letting the Fortigate connect to the Radius Server.Any help would be appreciated.Thanks.
Hi all, I am calling the API of local users, license , interfaces etc . Getting response status - 429 with message "Too many requests" . How can it solve this.
Hey thereHow do you handle port security?Currently i use NAC Policies with Switches. Earlier i did also MAC Whitelist for dhcp Reservation, but it consumes to much time.Also in the automation we have if a switch port changes MAC it send an Alert mail to us.The nice thing is, if we replace the switch, user can just plug all cables random in it and the NACs kicks in.
Hi all,I’m running into an issue with FortiClient SAML authentication when working with multiple Entra ID tenants and wanted to ask if anyone has faced something similar.Environment:FortiClient 7.4.5 with SAML authentication (Azure / Entra ID)FortiClient EMS 7.4.5Authentication is handled via embedded WebView (not external browser)Endpoint is Azure AD joined (Entra ID) with user signed in as `user@tenantA.com`Scenario:When connecting to VPN using SAML against tenant A → everything works fineWhen connecting to VPN using SAML against tenant B → authentication failsObserved behavior:FortiClient does NOT display a login prompt or account selection, instead, it automatically tries to authenticate using the currently logged-in Windows account (`user@tenantA.com`)Since this user is not present (or not assigned) in tenant B, authentication fails with:AADSTS50105 (user not assigned / not found)Key point:It seems that FortiClient (WebView) is using Windows SSO (WAM) and silently reusing the exis
Hello everyone, Is there a way to export the FortiNAC config file on my local pc ?As well, is there a way to upload the config file on FortiNAC's GUI, or it's only via FTP/TFTP ? BR,
Hi everyone,I'm facing a persistent login loop with a Blazor Server (.NET Core) application hosted on IIS 10, sitting behind a FortiWeb appliance. The setup: External Traffic: HTTPS (SSL handled by FortiWeb).Internal Traffic: HTTP (between FortiWeb and IIS).Server Side: I have configured IIS URL Rewrite to force HTTPS=on server variable and enabled X-Forwarded-Proto support. The Problem:When users try to log in, the authentication cookie (.AspNetCore.Cookies or .AspNetCore.Identity.Application) is never stored in the browser, although other cookies like .AspNetCore.Session and FortiWeb's persistence cookies are present. This causes an infinite redirect loop back to the login page.Locally (bypassing FortiWeb), the application works perfectly and the authentication cookie is generated correctly. What I've tried so far: Enabled "Add X-Forwarded-Proto" and "Add X-Forwarded-For" in the FortiWeb X-Forwarded-For Rule.Verified that "Cookie Security" is disabled in the
I’m fairly new in 3D animation, but the way I’ve always done a character modeling is:Either I get or I make a 2D character turnaround, import it into maya using the front, side and back cameras, and start modeling as if I was “tracing” the drawing (Idk if I’m making sense).I thought this was standard practice, and it’s the most comfortable way for me to model. But one of my professors always scolds me for importing the reference to maya, he says I should “understand the shapes and not copy them” and also “in a pipeline, the concept artist won’t always give you a turnaround” (isn’t that their job?)He’s also very against recording yourself or taking pictures of yourself to have a reference when animating.I get what he’s saying, but I thought the standard practice was to use as many references as possible. But then again, I’m a beginner. Can anyone weigh in on this?
Hello Team,I have already purchased the IPS license with the following details:Date: March 09, 2026Purchase Order #: POS 260XXXContract Registration Code: 1385TXXXQuote ID: 695XXXHowever, on my device dashboard, the IPS license is still not active.Could you please assist me in checking and activating the IPS license on my device? Thank you.Best regards,Aang
I have this policy to assign vlan 17 for devices which not managed by MDM.But the result why devices managed by MDM also hit this rule?
Hello everyone,I have a FortiGate 60F with a FortiSwitch 108E-POE running FortiOS 7.4.11.I changed the FortiLink management VLAN from the default (4094) to our university VLAN 1363 using the following commands:text config system interface edit fortilink set switch-controller-mgmt-vlan 1363 next end After applying the change, I can no longer access the FortiGate WebUI (neither HTTPS nor HTTP) from VLAN 1363. Interestingly, ping to the FortiGate IP on the 1363.fortilink sub-interface works fine.The only workaround I’ve found so far is to create an additional VLAN (1364) on top of fortilink exclusively for FortiGate management, assign the IP address there, and enable allowaccess.My question: Is there a way to access the FortiGate WebUI using only VLAN 1363 (the same VLAN used for FortiLink management) without having to create a second VLAN?I also tried disabling the client certificate requirement with:text config system global set admin-https-clien
I recently purchase some FortiAP-433G. I connected them to a Cisco 9200L PoE switch. The AP and switch negociate PoE succesfully at 802.3at, and the switch supplies 30W.This AP, according to the spec sheets can operate at 802.3at (30W) or 802.3bt (60W) When creating more than 2 SSIDs on the AP, ir begins to constantly reboot it self. Has anyone experience this issue as well?
Maybe I'm just being clueless...I want to explicitly allow a specific URL on the Fortigate,I want to allow certain URLs for the entire network (Source: all) – but only those specific ones, so that:Other domains that happen to be on the same IP address aren’t automatically allowed but are still checked by subsequent policies and can therefore be treated differently.How do I do that? I tried setting up a rule at the top that accesses a web filter which has stored these URLs as static addresses.But that just allows all URLs to be accessed. I want to ensure that this policy is effectively bypassed for other URLs and that the subsequent policies are applied.
Hi, I am looking for help.I am trying to add FortiGate 7.6.4 KVM to FortiManager 7.6.4 KVM, but it doesn't work. From FMG, I am getting the "Probe failed" error message for both OAuth Login (after successful login) and Legacy Login. From FG, I am getting the following errors:From GUI From CLI Connectivity test is OK:FG can ping FMG and vice versaFMG-Access is enabled on the FG interface connected to FMGTelnet to FMG IP 541 from FG is successful Other information:fgfm-allow-vm is enabled on FMGFAZ 7.6.4 KVM is successfully added to FMGexecute central-mgmt register-device on FG does nothingI am not using a custom certificate
Anything behind the firewall usually needs a refresh or two to get past the TLS handshake. Otherwise, Firefox sits there. Sometimes it goes through fine. Anything not behind the firewall doesn't have problems.Any suggestions? Thank you.
Hi,What model is a replacement for the FortiGate cluster HA A-P 300E devices?- 3k hosts- Partially Deep Inspection deploy , we want to implement extend even more DPI rules- routing beetwen vlans/ subnets on L3 not on FortiGate- 500 firewall policy flow mode, 300 firewall policy proxy mode, we want to switch policies with flow mode to proxy mode- 5 VPN IPsec S2S - a database application was running through tunnel- 10 IPsec dialup peak connection- 3 ISP connections that give a total summary speed of 3900 Mbps- FAZ, FCT, FML, FortiWeb Integration Stack
Hello,Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9Our authentication is direct from the fortigate to Active Directory (ldaps)It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602 BUT, it is not working when we add a FortiToken on the account I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/ta-p/420733The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Windows/ta-p/407272https://docs.fortinet
Hi everyone ! I'm facing a very strange issue. I'm running FortiOS 7.0.8. On some of my FortiGate, I can't access to web gui trough LAN interface. On my browser, I can see the certificate warning and after I accept it, the donut is running indefinitely.If a do a packet capture during this, I can see paquet transiting trough my FortiGate to web interface port. If i go trough wan interface, I can access to the login page without any problem and suddenly, I can access to web gui trough lan for a while... Very very strange no ? Someone can help me to understand what appends ? Thanks
Hello all,an administration team need access to Fortigate firewalls. In general, they only need read-only access, but they should be able to disable and enable interfaces. I configured a new accprofile, where all options are set to read only, but the access control for network is set to read-write. When the user logs in, he gets prompted to choose between "Login Read-Only" and "Log Out", The user does not get any write access with the custom profile. Implemented on a FG 101F, version 7.4.5. Any ideas, what is wrong? The relevant configuration:config system accprofileedit "net_admin"set scope globalset commentsset secfabgrp readset ftviewgrp readset authgrp readset sysgrp readset netgrp read-writeset loggrp readset fwgrp readset vpngrp readset utmgrp readset wanoptgrp readset wifi readset cli-get enableset cli-show enablenextend config system adminedit "net-admin"set accprofile "net_admin"set vdom "DATA" "root"set password ***nextend Kind regards, Hakan
Hi All, Does anyone know how to connect with the vpn from an iOS device using the fortitoken? Regards, Omar
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.