User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello,Can the EOS (End of Support) date for Fortinet products change after it is published?If yes, is the change usually only a few days? For example:I noticed the EOS date for FortiFone 380B changed from 4/3/2032 to 15/3/2032 Is this expected? Thanks.
Hello, I am wondering what the best practice is for hub to hub communication in an ADVPN 2.0 Dual Hub set up. The hubs are geographically separated and will be advertising their own IP space into the overlay. We're doing BGP per loopback. Normally with route reflectors, I just do an iBGP peering as non route-reflector clients. My thought was to create separate IPSEC tunnels, place them in a different SD-WAN Zone and peer via iBGP. There will absolutely be traffic between these two sites.
Hi,I noticed something strange in the built-in 360 Security Report in FortiAnalyzer.Between two weekly reports the number of detected devices increased from 2690 to 3707. Most of the increase is detected as Windows devices (from about 1398 to 2144).This does not match reality, because no large number of new Windows machines were added to the network.Another strange thing is that the report shows 561 devices detected on port6, but port6 is not used at all on my FortiGate.Versions:FortiAnalyzer: 7.4.10FortiGate / FortiOS: 7.4.11 Screenshots from both reports are attached.Thanks.
Is there a way to seach for conserve mode history in the past months in the large customer sites over 800 FortiGate devices? Trying to find if conserve mode might have happened on any sites. Thank you
Hi,We've been experiencing a significant number of security incidents involving websites categorized as "unrated" that are hosting malicious content and scripts.I'm curious how the community approaches web filtering policies specifically for unrated websites. I don't want to block the entire unrated category globally, as I suspect there will be impact on legitimate websites that fall into this classification. Ive noticed some MS IPs unrated, which Im concerned might impact O365, or other potential unknowns.Also, see below, if a website is categorized as unrated but has a risk level of "suspicious," how would I go about blocking those suspicious URLs specifically? Any guidance or best practices would be greatly appreciated.Example here:
I have ZTNA setup on a Fortigate, devices that connect through the ZTNA setup can reach everything they are suppose to on that Fortigate, where proxy policies use the EMS tags. I have an ipsec tunnel to another site and can route the proxy traffic to it. The EMS server is sharing all clients to all connected devices, but i can't use the tags on Site Bs firewall policies, because it only sees the clients external IP if i have transparent mode on or my WAN IP on site A if i don't. But neither of those are an ip the client has a tag for. I want to maintain a single fw rule, so that when clients are on site A, the same tags give them access as when they connect through ZTNA server on site A. The on site A works, because the IP matches what the client has. Is there anyway for the FW rule on site B to see this traffic is coming from a client from site A that matches the tag in the firewall rule?
I am trying to figure out how to add a web server certificate to Fortiems 7.4.5. to be used as the web server cert and the forticlient certificate. There are 3 options, Lets Encrypt, PKCS12 and PEM. I would like to use PKCS12. I use an outside vendor for this purpose. There does not appear to be a way to create a CSR on the FortiEMS server. There is not access to the Ubuntu server running on the backend. (using fortinet image). Its fully locked down. I thought we had to create the CSR on the server being used for Fortiems. So I tried creating the CSR using Openssl running on Windows 11. I was able to upload the CSR to the CA and then was able to download the certificates. 1. Do you need root, intermediate and server cert to create a single .pfx file for upload as PKCS12? Or do I only need the intermediate and server cert.? 2. IN what order should the certs appear in the PFX file? 3. For creating the CSR, what are the mandatory items required, common name. city,
Hi everyone, I am relatively new to the Fortinet world and I’m currently working on my first SD-WAN deployment exercise. I’m at the stage where I need to select the right FortiGate model to act as the Hub, but I want to make sure I don't under-provision the hardware or over-spend unnecessarily.Could you help me identify the critical variables I should consider for the correct sizing of the Hub? From my initial research, I’m looking into: Total Number of Spokes, Tunnel Count, Routing Table Size. Beyond these, what else am I missing? For example, how do I calculate the impact of security profiles (IPS, Antivirus, Application Control) when they are applied at the Hub level in an SD-WAN architecture? If there are any specific FortiGate Sizing Guides or "rules of thumb" you use when designing the Hub capacity, I would love to hear them.Thanks in advance for your patience and help!
Hello, I have HTTP (80) and HTTPS (443) open on the firewall. VIP made that points to the internal IP. Subdomain made that points to the VIP. A record works and I can navigate to the WebGUI. I can also view the /.well-known/acme-challenge/ directory. HTTP to HTTPS redirection is enabled in EMS. FQDN set in EMS.When I attempt a LE cert creation, I receive the error:A.C.M.E. Certificate request has failed. CA Authority is unable to make a connection with EMS. Check the logs for more details (/var/log/forticlientems/fcm). I can see multiple LE servers GET the challenge file from tcp dump, and multiple 200 OK responses from EMS. netstat -tulnp | grep :443 returns:tcp6 0 0 :::443 :::* LISTEN 3450/apache2 Any idea why this would be happening?
Hello Fortinet Community,I would like to share a scenario we are facing with a customer's FortiGate 40F (v7.2.13) and seek your advice on the best security strategy to implement.The Situation: We are seeing persistent and constant "Admin login failed" events in our logs. These are brute-force attempts targeting the WebGUI from various IP ranges and multiple countries.Current Approach: So far, my mitigation strategy has been:Creating Address Objects (Type: Subnet) for each attacking IP range.Grouping them into an Address Group.Applying a Local-In Policy to drop traffic from that group:This has turned into a "cat and mouse" game. As soon as I block one range, new ones appear. I considered Geographical Blocking, but it feels too aggressive since many attacking IPs originate from the USA, and I am concerned about inadvertently blocking essential services or legitimate traffic. I also researched this Technical Tip: Technical Tip: Block FortiGate Administrator Login with an automated sc
Looking at the utilization reports for our FortiGate we have decided to downgrade the license from 4vCPU to 2vCPU .. currently license gets synced from Portal via FortiGuard. Once the license is updated in the portal do i need to redownload and apply the license file again ? or will it auto synchronize.
I try to follow guide from 1. Generate TLS certificate for Microsoft Entra ID to do authentication | FortiNAC-F 7.6.5 | Fortinet Document Library to generate EAP-TLS from intune.In Method 2 Step 2 why i got error when Subject Name Format i fill to CN={{UserPrincipleName}} and the other attribut also have same error.Also whay i must fill in certification authority and certification authority name?
Hi everyone, I'm having an issue where I'm going over my daily limit for FortiAnalyzer logs and I'm looking into ways to minimize them without impacting visibility too much. I've already enabled reliable logging and I really don't want to entirely stop taking in interim logs for ongoing sessions. My thinking is that I can increase the interval from the default 2 minutes to make some impact on the amount of logs taken in daily while still providing visibilty If this is not possible, my next strategy would be to set the compression of logs to happen immediately instead of after the default 7 days with this command: config system sql set compress-table-min-age <days>endHowever, I would like to know if there would be any impact besides a small delay on alerts or reports, or higher use of VM resources. Thanks in advance for any assistance.
Hi,I couldn’t find any additional information or discussion about the bug mentioned in the 7.4.5 release notes.I’m currently doing a new EMS deployment connected to Microsoft Entra ID and I’m having issues with Invitation Code registration. The Invitation Code gets accepted, but the client never completes registration (it just keeps loading). EMS logs don’t show much.I tested disabling MFA for one user. After some time, I was able to successfully register one device using an Invitation Code, but I still could not register a second device with the same user (same tenant, same EMS settings, devices provisioned the same way via Intune).Because EMS can resolve and display the Entra ID domain user correctly for the device that registered, I assume the Entra connection/setup itself is basically working.Could this behavior be caused by the following known issue?1208862Entra ID user verification fails if MFA is made compulsory on Entra ID side.If yes: is there any ETA for an update or hotfix t
I know you need to be running v26.1.x in your SASE instance, and all your FortiClients running on 7.4.5, to set your clients VPNs to run connect IPsec over TCP. But in the SASE console I can find only one setting that affects encapsulation: under Endpoint Profiles/Global connection settings. There is one toggle next to FortiSASE Cloud Security Tunnel encapsulation and it's either Auto or UDP. UDP appears to be set as the default. The description of Auto is that the client will try UDP first and then falls back to TCP encapsulation. If you select Auto there is no apparent way to set the TCP port you want to use, and there appears to be no way to just force your clients to use TCP from the start. We want to force clients to always use IPsec over TCP and to force port 443. Does anyone know if this is currently possible given the versions l listed?
I have an issue where the FortiClient endpoint disconnects from EMS when a different user logs into the PC. I am using 7.4.3 build 1926 When installing FortiClient to the endpoint after entering the invitation code, it prompts for a username and password to complete the install. I have LDAP setup so I can use the credentials of the user of the PC or I can enter the domain admin and the install will complete and the endpoint connects to the EMS. The problem I have is that if I later come back to that PC and need to login as a different user or a domain admin; maintenance, troubleshooting, etc.., the endpoint will disconnect from the EMS. No prompt or warning, I just notice it the next time I go look at the EMS for whatever reason and see the endpoint is not connected. I opened a case with Fortinet and was told this is expected behavior if I RDP to the PC, but it doesn't matter if I RDP or login local, logging in as a different user will make the endpoint di
I'm working with a very simple network, comprised of a Fortinet Switch, Router, and some endpoints. The Fortinet switch is a FS-148F-POE (48-port), and the router is a FortiGate 70G. Both were purchased recently through BlueAlley via Amazon. The router is on firmware v7.4.11 build2878 (Mature). Initially, the switch was connected to the router through the router's port #5, a FortiLink port was not used. Everything was working fine but I thought it better to connect the switch to the router via a FortiLink port. So I moved the cable connecting the switch from the router's Port #5 to Port A. At this point, the router recognized the switch and I was able to Authorize and Register the switch. I was also able to upgrade the switch to the suggested latest firmware (v7.6.6 build1137). But after the firmware upgrade, the switch rebooted and then vanished under "Managed FortiSwitches," though it still appeared under System/Firmware &
Hi, One of my customers want to replace his Cisco Router, configured as DMVPN Hub, with a fortigate 1000D firewall.The cisco Router is used to create VPNs with other cisco router, in the spoc sites. Do Fortigate support DMVPN and is there a way to make this configuration running without replacing the cisco routers on the spoc sites. Best regards
Hello everyone,I’m working on a FortiNAC 7.2 deployment and I’m trying to enforce a restriction specifically for guest users.GoalAllow each guest user to authenticate and access the network from only one device, preventing the same credentials from being used simultaneously on multiple devices.Current contextWe are using:Guest Registration / Guest Self-RegistrationCaptive Portal authenticationStandard FortiNAC host registrationIn Settings → User/Host Management there is a global parameter called “Allowed Hosts”, which defines how many devices a user can register.Additionally, the same parameter exists at the individual user level, where it can be manually overridden per user account.ProblemThe global setting applies to all users, which is not ideal in our scenario.What we would like to achieve instead is:Allowed Hosts = 1 only for users created through Guest or Guest Self-RegistrationInternal or managed users should not be affected by this limitation.QuestionsIs there a way in FortiNAC
What dot1x method can be used for seamless login?Currently i'm on PoC with Fortinet vendor to implement dot1x and when testing the user is prompted to signin and must enter credential when plugged to the wired.We want if the user login using company device which already joined to the Azure Active Directory then when the LAN plugged to the switch then the user can directly access to the netowrk without prompting to login.
Hello is it possible to use this feature on FortiGate 90G? which ports can be used for this purpose? I try to set port3 and got command parse error before 'dedicated-to'Command fail. Return code -61
I'm trying to automate FortiGate configuration backups by pulling them via SSH using a script. For security reasons, I want to use an account that has strictly read-only privileges (no write access).I created a custom Admin Profile with "Read" access to all modules and assigned it to my backup user. However, when the script runs show full-configuration, the output is incomplete. I noticed that FortiOS hides higher-privileged users (like super_admin accounts) from read-only users, presumably to prevent privilege escalation.Because of this limitation, the backup I pull via SSH is not a 100% complete configuration.I am already aware of alternative methods, such as using Automation Stitches to push the backup to an FTP/SFTP server, or using the REST API with a token. However, my current infrastructure heavily relies on a centralized server pulling configs via SSH.My question is: Is there any CLI trick, hidden setting, or specific configuration in FortiOS that allows a strictly read-only us
In the SDWAN rule what different if we put :Single Performance SLA but contain 2 serversDual Performance SLA but every SLA contain 1 server only?
Hey Guys, I have been struggling to push changes in User & Authentication (i.e creating new local users) from the FortiManager to the FG. Whenever i try to use the installWizard it says there are no changes to push?!I checked ADOM setting and all but im stuck. Policies etc. are being pushed just fine just the users are not Fortios: 7.4.8 Build2795 (mature)FortiManager: 7.47 mature
What is the best way to do RCA on memory conserve mode on FortiGate? The conserve mode happened on Feb 9, 2026 as shown in the output below. 215: 2026-02-09 19:00:05 service=kernel conserve=on total="1918 MB" used="1688 MB" red="1687 MB"216: 2026-02-09 19:00:05 green="1572 MB" msg="Kernel enters memory conserve mode"217: 2026-02-09 19:00:06 MemTotal: 1964180 kB218: 2026-02-09 19:00:06 MemFree: 30232 kB Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.