Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello everyone,I’m working on a FortiNAC 7.2 deployment and I’m trying to enforce a restriction specifically for guest users.GoalAllow each guest user to authenticate and access the network from only one device, preventing the same credentials from being used simultaneously on multiple devices.Current contextWe are using:Guest Registration / Guest Self-RegistrationCaptive Portal authenticationStandard FortiNAC host registrationIn Settings → User/Host Management there is a global parameter called “Allowed Hosts”, which defines how many devices a user can register.Additionally, the same parameter exists at the individual user level, where it can be manually overridden per user account.ProblemThe global setting applies to all users, which is not ideal in our scenario.What we would like to achieve instead is:Allowed Hosts = 1 only for users created through Guest or Guest Self-RegistrationInternal or managed users should not be affected by this limitation.QuestionsIs there a way in FortiNAC
What dot1x method can be used for seamless login?Currently i'm on PoC with Fortinet vendor to implement dot1x and when testing the user is prompted to signin and must enter credential when plugged to the wired.We want if the user login using company device which already joined to the Azure Active Directory then when the LAN plugged to the switch then the user can directly access to the netowrk without prompting to login.
Hello is it possible to use this feature on FortiGate 90G? which ports can be used for this purpose? I try to set port3 and got command parse error before 'dedicated-to'Command fail. Return code -61
I'm trying to automate FortiGate configuration backups by pulling them via SSH using a script. For security reasons, I want to use an account that has strictly read-only privileges (no write access).I created a custom Admin Profile with "Read" access to all modules and assigned it to my backup user. However, when the script runs show full-configuration, the output is incomplete. I noticed that FortiOS hides higher-privileged users (like super_admin accounts) from read-only users, presumably to prevent privilege escalation.Because of this limitation, the backup I pull via SSH is not a 100% complete configuration.I am already aware of alternative methods, such as using Automation Stitches to push the backup to an FTP/SFTP server, or using the REST API with a token. However, my current infrastructure heavily relies on a centralized server pulling configs via SSH.My question is: Is there any CLI trick, hidden setting, or specific configuration in FortiOS that allows a strictly read-only us
In the SDWAN rule what different if we put :Single Performance SLA but contain 2 serversDual Performance SLA but every SLA contain 1 server only?
Hey Guys, I have been struggling to push changes in User & Authentication (i.e creating new local users) from the FortiManager to the FG. Whenever i try to use the installWizard it says there are no changes to push?!I checked ADOM setting and all but im stuck. Policies etc. are being pushed just fine just the users are not Fortios: 7.4.8 Build2795 (mature)FortiManager: 7.47 mature
What is the best way to do RCA on memory conserve mode on FortiGate? The conserve mode happened on Feb 9, 2026 as shown in the output below. 215: 2026-02-09 19:00:05 service=kernel conserve=on total="1918 MB" used="1688 MB" red="1687 MB"216: 2026-02-09 19:00:05 green="1572 MB" msg="Kernel enters memory conserve mode"217: 2026-02-09 19:00:06 MemTotal: 1964180 kB218: 2026-02-09 19:00:06 MemFree: 30232 kB Thanks
I would like to have some informations to move reperedestempliers.fortiddns.com dyndns domain actualy on a fgt30e ) to other FGT60e can you help me ?
I built a FortiGate VM04 6.4.6 in Azure and ran into this nifty little bug that I wanted to document because I couldn't find anything on it. The configuration was all set in place and ready to go and we had just finished adding the last additional interfaces for HA and Management when I updated the static route for the LAN and lost connectivity to the device. I connected in through Azure's Console and saw that the configuration had took but I couldn't ping anything and the device said all interfaces were down. A reboot let me back in and the config had stuck. I assumed it was a bad VM and rebuilt it, pushed the old config and then added an address object. The VM went down again. Rebuilt the VM, added another address object, VM went down. After rebuilding the device another time using 6.4.5 and going into the events and debugging with Fortinet, we identified that DHCP was enabled on the HA and Management ports, which was not recommended. The technician then noticed that the route c
Hi, It seems that the FortiClient only performs automatic registration under the user under which the software is installed. We deploy the initial installation with Intune, which use the system user.When the user starts the client, no registration has taken place. How can I solve the problem?
Hi everyone,I am configuring a Dial-up IPsec VPN on FortiGate (FortiOS 7.6.6) and I want to restrict access based on the user group.RequirementI have two local user groups configured on the FortiGate RA-ADMIN-USER RA-CCTV-USERBoth groups should be able to connect to the same Dial-up IPsec VPN tunnel, but with different access permissions RA-CCTV-USER → should be able to access only the CCTV subnet RA-ADMIN-USER → should be able to access all internal subnets What is the recommended way to allow multiple user groups to authenticate to the same IPsec Dial-up VPN? If anyone has implemented a similar setup, I would appreciate guidance or example configuration.Thanks in advance.
Hi I'd like to know how to restrict encryption to TLS 1.2 / TLS 1.3 only when accessing the FortiADC WebUI.On FortiGate, this can be done by using the global setting set strong-crypto enable.However, on FortiADC (version 7.6.x), this command does not appear. Does anyone knows this ?
Hello,I’m currently staging a pair of FortiGate 90G firewalls and noticed the factory default configuration assigns the x1 and x2 interfaces as a FortiLink aggregate, while the A and B ports appear intended for WAN connectivity.From the default configuration I observed:x1 + x2 configured as an aggregate interface with FortiLink enabledA and B presented as standalone physical interfaces that can be used for WANport1/port2 included in the internal hardware switchMy questions are:Is the intended design on the FortiGate 90G that A/B are the preferred WAN interfaces, while x1/x2 are reserved primarily for FortiLink or high-speed LAN uplinks?If FortiSwitch is not being used, is it recommended to remove FortiLink from x1/x2 and repurpose those interfaces as normal 10G LAN or WAN ports?Is there any Fortinet best-practice guidance on which interfaces should be used for WAN vs LAN when FortiLink is not required on this model?This unit ships with FortiLink preconfigured on x1/x2, so I want to con
Dear expert,i am seeking your guidance and assistance to fix the routing problem. Recently we got direct-connect ( MPLS) link to connect AWS EC2 from on-prem data center. not configured yet. apart from that site-to-site IPsec VPN tunnel also established with AWS and working fine. All BGP handling is taken care by ISP with regards to direct-connect. The issue isoutgoing data from local lan ( port 9) is not going to AWS through port 4 (10.18.152.4/24). working From port4 to gateway of ISP router gateway 10.18.152.1 is reachable.From port4 to AWS EC2 subnet 10.18.144.0/24 is reachable. AWS EC2 subnet to ISP Router GW 10.18.152.1 is reachable.From port 9 to port 4 / 10.18.152.4 is reachable not workingLAN port 9 to port 4's gateway 10.18.152.1 is not reachable.AWS EC2 to port 4 (10.18.152.4) is not reachable. FW polices areport 9 to port 4 > all traffic allowedPort 4 t port 9 > all traffic allowed static route are configured in
So I finally upgraded to 7.6.6 on my FWF60F and initially things were running fine. But now that is has been up for a few days, the GUI loading has gotten really slow. Doing a diag sys top, I am seeing the httpsd process as zombie and on each update, the process id is incrementing.Anyone else seeing issues like this on the smaller units?
Hello Everyone: We need to reset an FAP-234F-A to factory defaults because we don't have the admin password. Here are the details: 1. We have the unit connected to a FortiGate 40F, which has the default IP address of 192.168.1.99 for now while we set things up. The FAP-234F-A is set to 192.168.1.2 and we can ping it and browse to the GUI. 2. The QuickStart Guide for this unit says that it comes with a special POE injector that has a reset button on it because the AP doesn't. Probably because it's a ruggedized outdoor unit and having a reset button would compromise the ruggedness. The model number of the PO injector that shows in the QSG is EPA5006GPR-4P. It's made by EnGenius, but the only one they have is the EPA5006GR, so we bought that one. It has a reset button on it but pressing it for more than 10 seconds doesn't reset the AP to factory defaults. It does nothing. Probably because it's slightly different than the EPA5006GPR-4P and the pinout
Been troubleshooting intermittent FortiClient VPN user issue for MONTHS. Finally caught it in the act with a TAC and MS Support. Still no answer so I'm sharing the oddity here. VPN Clients have traffic stop until DPD times them out. This happens to any user, on any ISP, at any time of day. Client is on Port 61020 to port 4500 on the Firewall... Typical NAT-T session.They were fully connected and working, then... Traffic stops. Here's the output of the sniffer 4 0 1 capture from the Client side FW:2026-03-09 14:47:24.661204 port3 out HQ-IP.61020 -> AZ-IP.4500: udp 3442026-03-09 14:47:24.688854 port3 in AZ-IP.4500 -> HQ-IP.61020: udp 5362026-03-09 14:47:24.733526 port3 out HQ-IP.61020 -> AZ-IP.4500: udp 882026-03-09 14:47:25.441206 port3 in AZ-IP.4500 -> HQ-IP.61020: udp 1042026-03-09 14:47:25.441821 port3 out HQ-IP.61020 -> AZ-IP.4500: udp 1042026-03-09 14:47:26.451448 port3 in AZ-IP.57802 -> HQ-IP.61020: udp 104 WTF?2026-03-09 14:47:27.963936 port3 out
Hi, I recieve this error when I'm trying connecting "Notification: Backup DNS failed" when I'm trying to connect. What's the problem? I installed the last version of Forticlient, I'm using Ubuntu 22.04
Since Fortinet is transitioning from SSL VPN to IPSec VPN, we would like to request your guidance regarding this scenario. Our client currently uses SSL VPN for their remote users. These users access the network from phones and tablets without FortiClient, simply by entering an IP address and port in their browser. Configuring a VPN client on these devices would be cumbersome for them. However, IPSec VPN does not natively support browser-only access in the same way. Could you advise on the best approach to implement IPSec VPN for this use case while keeping remote access simple for users on mobile devices? Thank you for your support.
Hello All, As i have done Geo-Fencing for CHINA on SSL-VPN. But in case any of my colleague goes to china & needs to access vpn he wont be able to get any. is there any way in fortigate to implement an exception where the geo-fencing for China remains in place globally, but SSL-VPN access is allowed for a specific VPN user group (for example, a temporary travel group) when connecting from China? pls guide. Regards
Hello everyone, I’ve been reading a few articles about FortiNAC configuration and got a bit confused. Some sources mention that it’s not recommended to configure RADIUS, L2 MAC traps, and syslogs together, and that the preferred option is just L2 MAC traps. But in another article, I read that configuring syslog is recommended. https://community.fortinet.com/t5/FortiNAC/Technical-Tip-An-example-of-a-simple-network-deployment-of/ta-p/266446 BR,
Hello everyone, So I know when a guest (rogue) first connects to a switch port, they are isolated and need to register/auth with the captive portal based of the group membership/enforcement group configured on that port. I get this part. My question is for corporate devices, do they need to authenticate via the captive portal each time they connect ? BR,
Hey all, I've got a location with fortigate/ipsec site to site VPN; i.e. branch to HQ. There is a user on wifi at branch, where wifi only has internet access. Internet access from wifi leaves the local fortigate via the same interface the site to site vpn traffic uses, and that user would like to VPN to HQ. Is there some combination of IPSec settings that will allow the site to site VPN and "dialup" users to connect to the same target Fortigate from the same source WAN IP? I've attempted aggressive mode IKEv1 with a variety of combinations of peertype any vs one, unspecified, and then either phase 1 local id set or not set, etc. but have not arrived at a combo that allows both to exist in harmony.
We are currently evaluating the integration capability of FortiNAC with the existing network devices in our environment, including FortiGate, devices from Cisco, and Extreme Networks. According to the reference documentation, we understand that FortiNAC supports FortiGate starting from FortiOS version 6.0+ and later. Therefore, we would like to clarify whether FortiNAC can still integrate with or manage FortiGate devices running older FortiOS versions (for example 5.x) in case the firmware cannot be upgraded. If supported, what level of integration or functionality would be available? Additionally, for network devices from Cisco and Extreme Networks, we would like to clarify whether there are any minimum firmware version requirements for integration with FortiNAC. Specifically, do these devices require a firmware upgrade to be supported, or can the integration be achieved using standard protocols such as SNMP, SSH, or RADIUS without upgrading the existing firmware?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.