User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hey,we have FortiClient EMS (Linux) running at version 7.4.5 build2111 (Mature)And recently we installed a small independent elasticsearch cluster that's only supposed to get the FortiClient Endpoint Events. The FortiClient EMS Administrator Guide is not helpful at all at explaining how to get EMS to connect to that elasticsearch cluster. It keeps complaining about the CA certificate:2026-03-18T15:07:43.445Z ERROR service/event.go:103 create indices: create all indices: check if index forticlientems_alerts_745-write exists: an error happened during the Exists query execution: tls: failed to verify certificate: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA") I used the emscli to give it the proper parameters including a path to the certificate, imported it to the ubuntu trust store and tried every possible way I can t
Probably since thursday when our VPN (Forticlient 7.0.7.0245) is connected we have assigned local DNS but when trying to access or ping some internal services/servers it doesnt resolve. Tried using command below and got our local DNS serverscutil --dns | grep 'nameserver\[[0-9]*\]'when I use nslookup with hostname it also does resolve to IP. Any ideas what could be wrong? Thanks,
Hi everyone! I am posting this again because for some reasons, my previous post was tagged as spam. I cannot push my installation on my fortigate firewall via fortimanager. It is giving me this error. No one among my team is aware who did the last config but they are certain that no one did this type of change. Most of the error is thiscommand_cli_unset:6496 clear MEMBER table oper error. ret=-56 For further logs, please refer to the attached image fileThe logs read from left to rightIf the image is un-readable, let me know for anyone interested and i will forward the actual logs text file Regards,Renz
What is best practice for TACACS+ Policies in the FortiAuthenticator regarding whether to have a single policy for all TACACS+ Clients or have separate policies for various groups of TACACS+ Clients?Would you only separate into multiple policies if you plan to segregate access by group? In other words, if we have routers, firewalls, and switches, then would you create a Router Group, Firewall Group, and Switch Group, and have the corresponding Group "assigned" to separate policies for each of these? Then a super user who needs access to all devices would have to be assigned to all groups?
Does anyone have the SNMP MIB for Fortiap that they could share with me, please?
Hello,I’m currently working with SD-WAN over IPsec, using a FortiExtender (FEX) with LTE connectivity.Since LTE does not provide a static default gateway, I’m unsure how to properly configure the “Local Gateway” setting.What should be defined in the Local Gateway field in this scenario?Thanks in advance.
Working on a unit running 7.4.4 with FIPS-CC enabled. Trying to get this integrated with Azure using SAML. I had seen this document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Unable-to-import-remote-certificate-to-FIPS-CC/ta-p/253435 so followed it as best I was able. Created a csr/key via OpenSSL, got a certificate from a local Windows server (used Webserver template) that is the CA for the domain. Created a PKCS12, imported that into Azure. Downloaded the certificate per the document. When I tried imported it into the FGT initially the firewall complained that it didn't trust the issuing CA. So I imported the root certificate from the CA. When I go back in to import the certificate now as a remote certificate, the GUI says it's importing, but it doesn't show up and isn't available in the cli or when trying to create a new SSO connection. I noticed that the certificate that was created doe
I installed the ESXi version of the FortiGate VM and added the FortiSwitch under FortiLink. However, the logs keep showing the following error. how can I resolve it??FortiLink: ISL timing-out for trunk(XXX) member port(24) did not receive ISL pkt for(10) sec
Good day. We have two FortiGate 40Fs and an IPSec tunnel between them. No issues accessing files across the tunnel. Tunnel Policies are set to allow ALL services. The customer has a VoIP system and they utilize the paging functionality. Paging is working locally per site but will not work over the tunnel, meaning, if Site A initiates a page, all phones in Site A can hear the page but none in Site B - and vice versa. We have multicast policies between the tunnel and can see byte counts. Has anyone done this setup successfully? Appreciate any guidance. Thank you.OD
hi,i took FGT administrator 7.4 last 2025 and plan to take FMG to complete my FCP network security cert.do i go for the FMG 7.4 version or FMG 7.6?can FGT admin 7.4 compliment FMG 7.6 to complete the FCP network security cert requirement?can someone provide the latest links for training/certificate to achieve FCP network secrity?
I have the OT Applications add-on for Fortigate FG-70F firewall. I can create a profile, activate the OT signatures and use them to create a modbus specific profile. The issue is that when the firewall is power cycled, the OT application signatures disappear, meaning my rule isn't working. I then need to manually turn off and on OT signatures in the profile to make the profile work. These firewalls are going to be isolated with only local access, so this is going to cause issues in the event we advise the customer to reboot the devices or another technician unaware of this issue performs a reboot during maintenance. Is there any fix for this issue?
I have switched ISP from cable to fiber, which means I need to switch my 80F WAN connection from a cable modem to a Eero Max 7 router wired connection. I cannot get the 80F <-> Eero configuration to work (i.e., get internet connectivity), even though the Eero recognizes the 80F wired connection to its 2.5Gb port.Is anyone successfully using a 80F <-> Eero configuration?Any help on the setup, please?FortiGate
We ran and update on the 100 box last night.Out internal interface has two subnets, the primary is an old legacy one that three or four mission critical serves run on and the secondary is the new one that includes all work stations etc. After the update the secondary was fine but he primary lost all traffic. We rolled back to 7.49 and all is fine. Annoying bug that we have no way of testing as we have no test environment. We had held off till the mature release as we've been burned before.Just an FYI.
Hello,I would like to confirm the latest stable FortiOS version for the 101F, along with compatibility for FortiSwitches. unfortunately the compatibility matrix indicates 7.6, it has been experiencing several issues. so what is best stable version in 7.4.x series.thank you
I've connected all of my cameras to FortiRecorder but it shows 0/200 cameras that are not cloud managed. What do I need to do get them cloud ready and accessible?
Hello, Recently, within one week of one another, had a FGT60F and a FortiWiFi-60F boot with incorrect time and date after an unexpected and more than one hour power loss. Year was 1999 once and 2000 on the other device. Both devices are running firmware v7.4.11 build 2878 and connected to FortiGate cloud with valid subscriptions. After the power loss, local traffic is not able to communication with Fortiguard DNS due to the time issue. Therefore:Updating time via Fortiguard NTP servers fails.Fortilink devices show as offline.Fortigate Cloud MGMT down. Having to update devices to use 8.8.8.8, 8.8.4.4 for system DNS. NTP then updates using FortiGuard and after some time, FortiGuard DNS will allow communication again. One device is 3 years old and the other is around 5. Checked for a way to check the internal battery status but came up empty. Any help or thoughts are appreciated.
dash board is not opening after the log in on the web browser
Hello, is it possible to disable remotely LDAP global sensitivity? https://kb.fortinet.com/kb/documentLink.do?externalID=FD50400 we have a lot of user and for every user disable via cli is really crazy.... thanks in advance
Hi I want to connect Android to FortiSASE. I used the Default Invitation code to link EMS.When linked, one certificate is downloaded to my phone.If I go to the FortiClient's VPN and try to connect, it will be asked for a certificate.If I select the certificate that was downloaded a while ago, it will be asked to enter the password.How do I know what the password is?Is FortiSASE setting it up separately? If this situation is a structural problem with Android, is there any other solution? Thank you
So in my lab I have a hub and 3 spokes. Each have 2 WAN ports. I am testing testing failover senarios, and that seems to be working. The issue is kind of weird though. I have a computer connected to a spoke firewall and I set the computer it to ping the other 2 spokes (10.0.200.2 and 10.0.200.3(both are /32 subnets on a LoopBack interface). What I am seeing is when the computer is pinging only one of the spokes, everything is fine, but when I set the computer to ping both spokes at the same time, then I see shortcuts being created for one spoke, then delete and new shortcut created for the other spoke. It's like only one shortcut can be alive at one time. It just keeps flopping like this. So I am not sure if this is an IPSec issue or routing issue. Any help understanding this would be appreciated. Thank you.
Hi!Issuing "execute fmpolicy print-adom-package ..." does not present an option to see "CLI Template". Is it possible using CLI?Thanks!
Hello,Can the EOS (End of Support) date for Fortinet products change after it is published?If yes, is the change usually only a few days? For example:I noticed the EOS date for FortiFone 380B changed from 4/3/2032 to 15/3/2032 Is this expected? Thanks.
Hello, I am wondering what the best practice is for hub to hub communication in an ADVPN 2.0 Dual Hub set up. The hubs are geographically separated and will be advertising their own IP space into the overlay. We're doing BGP per loopback. Normally with route reflectors, I just do an iBGP peering as non route-reflector clients. My thought was to create separate IPSEC tunnels, place them in a different SD-WAN Zone and peer via iBGP. There will absolutely be traffic between these two sites.
Hi,I noticed something strange in the built-in 360 Security Report in FortiAnalyzer.Between two weekly reports the number of detected devices increased from 2690 to 3707. Most of the increase is detected as Windows devices (from about 1398 to 2144).This does not match reality, because no large number of new Windows machines were added to the network.Another strange thing is that the report shows 561 devices detected on port6, but port6 is not used at all on my FortiGate.Versions:FortiAnalyzer: 7.4.10FortiGate / FortiOS: 7.4.11 Screenshots from both reports are attached.Thanks.
Is there a way to seach for conserve mode history in the past months in the large customer sites over 800 FortiGate devices? Trying to find if conserve mode might have happened on any sites. Thank you
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.