User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello,Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9Our authentication is direct from the fortigate to Active Directory (ldaps)It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602 BUT, it is not working when we add a FortiToken on the account I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/ta-p/420733The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Windows/ta-p/407272https://docs.fortinet
Hi everyone ! I'm facing a very strange issue. I'm running FortiOS 7.0.8. On some of my FortiGate, I can't access to web gui trough LAN interface. On my browser, I can see the certificate warning and after I accept it, the donut is running indefinitely.If a do a packet capture during this, I can see paquet transiting trough my FortiGate to web interface port. If i go trough wan interface, I can access to the login page without any problem and suddenly, I can access to web gui trough lan for a while... Very very strange no ? Someone can help me to understand what appends ? Thanks
Hello all,an administration team need access to Fortigate firewalls. In general, they only need read-only access, but they should be able to disable and enable interfaces. I configured a new accprofile, where all options are set to read only, but the access control for network is set to read-write. When the user logs in, he gets prompted to choose between "Login Read-Only" and "Log Out", The user does not get any write access with the custom profile. Implemented on a FG 101F, version 7.4.5. Any ideas, what is wrong? The relevant configuration:config system accprofileedit "net_admin"set scope globalset commentsset secfabgrp readset ftviewgrp readset authgrp readset sysgrp readset netgrp read-writeset loggrp readset fwgrp readset vpngrp readset utmgrp readset wanoptgrp readset wifi readset cli-get enableset cli-show enablenextend config system adminedit "net-admin"set accprofile "net_admin"set vdom "DATA" "root"set password ***nextend Kind regards, Hakan
Hi All, Does anyone know how to connect with the vpn from an iOS device using the fortitoken? Regards, Omar
Anyone experienced issues with FortiClient VPN not working on Windows 11 24H2? I have no issues on Windows 11 23H2. I've tried various versions with no luck connecting with stability. There is a lag once reaching 95-98%, hangs, then connects but disconnects immediately after. So far rolling back windows 11 23h2 is only fix so far. PS. Foritnet support has denied of any issues with windows 11 24h2. Current FortiClient 7.2.4 Any suggestions?
Hi,I am looking for older version of FortiClient VPN version 7.0.8.0427.Can someone please help me with the information about where I can get the software.Thanks,
Hope you are doing great , So my customer have fortigate NAC running version 7.2, customer wants to login the switches using a single LDAP group. LDAP is integrated with the NAC. can any one share me any tutorial or any step by step configuration link ?
Good Afternoon ColleaguesI hope you are doing well . When moving from a network with HQ (Datacenter) and many remote branches that using MPLS to Fortinet SD-WAN , Does HQ (Datacenter) & remote branches need to have static IP addresses ? Best Regards
We use LDAPS to check users belong to an AD group in our explicit proxy policies. Ever since we replaced our domain controllers with Server 2025, users receive a pop-up saying proxy authentication is required. We use regular bind type, with our AD CA's certificate. This test OK, and diagnose debug application fnbamd -1 shows the certificate working.The CNI is cn, but I've tried using sAMAccountName and uid. Looking in Event Viewer on the DCs, I see lots of event id 1216 and 15351535Internal event: The LDAP server returned an error.Additional DataError value:00000003: LdapErr: DSID-0C060666, comment: Error decrypting ldap message, data 0, v65f41216Internal event: An LDAP client connection was closed because of an error.Client IP: <ip of firewall>:17943Additional DataError value:3 The system cannot find the path specified.Internal ID:c06065f I briefly tried disabling ldapserverintegrity and LdapEnforceChannelBinding on the DCs to see if that was the cause, but no cha
Hello all,i'm trying to limit how much bandwidth my user can have for downloading. i have setup a per-ip-shaper at 30mb but it seems that the limitation randomly apply at 10-15mb instead. from what i can find online this seems to be the proper way to use it? i have set the web facing interface max bandwidth properly and can't think of why it wouldn't match the speed i set, any idea?
I’m facing an issue with connecting to the VPN using FortiClient.When I click on “Connect”, it does not show the username/password (or SSO) login prompt and nothing happens — the button stays in blue color.
Probably an easy question and after reading it seems Fortigate can do what I want.I have a couple secure networks that per our device onboarding process, I want to whitelist those MACs to have connectivity on their respective network (plug in device to wall, get internet. Plug any device not on address list that hits that network/vlan, no network). We have UniFi layer 2/layer3 switching and running into issues with wireless and downstream of allowed MAC lists.I can give more info if needed, just curious if my assumption on Fortigate functionality is accurate. Happy to read another linked thread if I missed it.
Hi, I need to create a launcher for the ASDM.Any suggestions? Thanks
Do I need an Advanced Bot Protection (ABP) license to enable biometric-based bot protection on FortiWeb?
Users have experienced high latency when connecting to FortiClient IPSec (EMS) over Starlink. We have observed that users on Starlink connections encounter noticeable latency when establishing IPSec sessions through FortiClient.
Hi All, Is possible to disable the dynamic mapping object feature on Fortimanager? I have a customer that often change object configuration directly on Fortigate and after "import policy" in Fortimager and then "re-install pollicy". The problem is that after "import policy" it change the type of object from "address" to "dynamic address" and just that Fortigate that was changed is actualized on Fortimager. Regards,Claudio Rezende
Looking at buying some Fortinet kit, has anyone experienced failure within a year or two?Is the quality good, or does it improvement in terms of things failing?Whats your experience?
Hello, Apologies if this isn't the right place for this question, and I will say upfront I am somewhat of a novice with Fortigate. I am running a Fortigate 60D, I have two vlans, a private network for my PCs and an IoT VLAN where all my Google speakers connect to. I'd like to me able to manage/cast to my Google devices from the private network. I've tried adding a policy to allow MDNS traffic between the two networks, but I'm not sure I set it up right. Can someone please help with a step-by-step guide on how to set this up? Thanks!!
Hey thereHow do you handle port security?Currently i use NAC Policies with Switches. Earlier i did also MAC Whitelist for dhcp Reservation, but it consumes to much time.Also in the automation we have if a switch port changes MAC it send an Alert mail to us.The nice thing is, if we replace the switch, user can just plug all cables random in it and the NACs kicks in.
Hello, I downloaded FGT_VM64_KVM-v7.4.11.M-build2878-FORTINET.out.kvm from the Fortinet site but only thing in the extracted folder is the fortios.qcow2 file (103mb). Why doesn't admin or maintainer login work? I can't activate the free license or activation via web on VPC in Eve-ng . I dont know the ip of the firewall to even try. Could that be why I am not getting login info because wrapper.txt.is missing? I am unable to login to get to the web gui to activate license. Any help will be appreciated.
What could be causing the icons before to application names not to display?They disappear after a while.They don't show up in the "Application Signatures" or "Application Name" logs.Only a restart helps. Fortigate 61E firmware 7.2.13The signature databases are up to date.
Hello! There is a migration scenario where I am not sure 100% about the port-naming\mapping order.I have 2 FortiGate VM in a public cloud (some local Open-Stack\KVM based vendor). My case is moving VMs between AZs and it can be done only manually. So for now I have 5 interfaces\ports on each VM and whey were configured in an adding order (I added one by one and got "port1, port2, port3" etc). In the migration process I'll have to stop the VM, save the image and redeploy in another AZ (like moving an HDD) and attach the image. I will create the same networks with the same IP parameters , but my concern is that when I power on the VM ports can be1) the same 5, but mixed between each other2)First 5 ports got "empty" and new start from 6 to 10Both options are bad. Does anyone know anything about port naming\mapping and the correct order and how can I impact within KVM environment. I couldn't find anything except several reddit's posts 7ish years old.The ver is 7.4.11Thanks!
Hello everyone, Previously, Fortinet allowed customers to purchase a FortiGate-VM separately and renew only the license. However, this option has now been replaced with the FortiGate-VM subscription model, where both the VM and its licenses must be renewed together.My question is, when the VM subscription (including the license) expires, what exactly happens? Will the entire VM and its configuration be lost, or is there a way to retain the configuration (probably through snapshot) Kind regards,
I stepped away from Fortinet for a while and am coming back to find that there still seems to be no real solution to connecting the internal switch ports and external (FortiSwitch) switch ports on the same VLAN. You'd think that once you setup FortiLink, attach a FortiSwitch, and start making FortiSwitch VLANs that those VLAN interfaces would be available to add to either a software switch or hardware (vlan) switch. It doesn't seem that is the case though... Instead, it seems the only way to share traffic between internal ports and external ports is to PHYSICALLY connect between them? Is this really the best (only?) solution:Create virtual VLAN switch with VLAN ID of zero on Fortigate.Add all the ports you are going to use as membersCreate sub-interfaces for each VLAN ID that you are using on the networkDesignate a physical port on the firewall as the trunkCreate a trunk port on the switch controller for the FortiSwitchesPhysically connect the internal (fw) switch trunk
Hi,my network has a fortinet fortigate 200F firewall and active directory with windows server 2019 (DHCP and DNS) and is connected to the Internet via two different ISPs (A and B) with their respective routers/modems configured for load balancing. There is also an external web server connected to ISP A with a static IP. The ISP A router/modem is a netgate pfsense configured so that the web server uses public IP 1 for external connections (from the Internet) and private IP 2 for internal connections (LAN). Connections to the web server work fine from the external network, but from the internal network I am experiencing a potential DNS Rebind attack issue. After some research, I think this is due to the fact that sometimes internal connections use ISP B, which is the one that does not manage the web server.So I wonder what is the best way to force the firewall to route all internal connections to the web server URL to ISP A (excluding ISP2). Where can I find a guide?Thank you.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.