Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
When launching an RDP session using a stored Secret through FortiPAM (via Proxy mode and NLA mode), the connection does not automatically inject the stored password.Instead:The RDP client pre-populates the username field with the currently logged-in Windows user from the client machine.The session then prompts for a password.The stored Secret credentials in FortiPAM are not injected.Authentication must be completed manually.
Hi,We are looking into a solution for machine to machine traffic with FortiProxy. We saw that there is an option for oidc in recent versions of FortiProxy and were wondering if that is something we can use. The IdP we would like to use is Entra ID. As said, this is machine to machine, so no browser popup or user interaction should be required. Is this setup possible with FortiProxy?
In the VPN we can select Peer Option to 'Peer ID from dialup group'. How we can create the dialup group?When we create the group then which type should i select (Firewall, FSSO, RSSO, or Guest)?Also we must have the user and this user should be as member for above group. When create the user which user type should i select (Local User Remote Radius, Remote TACACS, Remote LDAP, FSSO or FortiNAC user)?
I have to deploy the Overlay Orch, the default ASN is 65000. The ASN should be private, or it can be public, this is because the customer is using the 65000. Thanks.
Hello,I wanted to replace our existing Aruba Core Switch with a FortiSwitch 148F.Currently the Aruba is connected to my Fortigate 100F via an LACP with different VLANS , the VLAN 1 is currently used by the network. Here's the screenshot of the existing conf with the Aruba switch connected to port1 and port2 I've tried to create a software switch with the Fortilink interface and the LACP but i can't use the LACP for the hd switch.So i attached the Fortiswitch to the Fortilink in order to preconfigure it but i can't create the same VLANS/Subnet on the Fortilink and the fortigate says that they are already used in the LACP.So i would like to know how to migrate this, i can't attach the fortiswitch directly to the LACP becouse it is a production environment and i have to minimize downtimes so i wanted to attach the Fortiswitch to the Fortlink, then preconfigure the Switch AND the Fortilink with the existing VLANS (but i can't create those networks...
Hello, Ive got this situation with a fortilink lacp already working but only 1 physical connection. I wan to add a new connection but I want to confirm if I can add the cable while hot-swapping without any disruption, and the business doesn't allow for a maintenance window, I'd like to know if adding a cable between the firewall and the switch would cause any problems. Additionally, I'd like to know if any further configuration is necessary, given that the firewall is already configured with the FortiLink LACP to use this new physical connection. Any suggestions or link would be really appreciated.
Hey guys, Is it correct to say that when I disable the password policy on my FortiGate, the IPSEC tunnels with PSK configured in it will remain up and no network impact? Background:I have an existing IPSEC tunnel configured with PSK, also password policy is enabled.I wanted to disable password policy. Thank you!
Hello, As a continuation of a previous thread that was marked as Solved by the person that opened it, the issue appears to be present on 7.4.3.6667 but on 7.4.1.1716 it was not present/affected by whatever is causing it. It happens when the lock screen is either manually initiated or the computer reaches the timer that is set to start it.The disconnect is almost instant as soon as the lock screen is being trigger with the laptop being connected to a power outlet so not on battery. At the previous version 7.4.1 it never disconnected even if the laptop was in lock screen for hours, it remained connected to the VPN. These are the only logs that I could find and maybe someone could help remediate this issue because it's quite annoying to be fair.We are aware that it's a free version of FortiClient w/o support but considering some vulnerabilities are fixed within the latest version and a downgrade to a previous one isn't a real option and neither deactivating lock screen
i cannot acces the FortiNAC UI, i executed this command:- execute service status nacthe output is:- Master Process is Down!
I have been trying to get Dialup VPN users connect via IPSec on a fortigate 80F firewall device but the vpn client cannot reach any internal network. Ping to 192.168.4.x shows request timed out. I have double checked the configurations thoroughly but could not find any issues on the ipsec tunnel setup or firewall policy. show vpn ipsec phase1-interface Dialup_VPN//config vpn ipsec phase1-interfaceedit "Dialup_VPN"set type dynamicset interface "wan1"set mode aggressiveset peertype anyset net-device disableset mode-cfg enableset ipv4-dns-server1 192.168.4.3set ipv4-dns-server2 10.61.50.3set proposal aes256-sha256set dpd on-idleset dhgrp 14set xauthtype autoset authusrgrp "vpngroup"set ipv4-start-ip 172.16.2.10set ipv4-end-ip 172.16.2.50set ipv4-netmask 255.255.255.0set ipv4-split-include "MAF_Servers"set psksecret ENC 1KvTP2fJpmTD24X4AvgNLfMByHhIF5Ajxnr4iofvNF0iXUQt0lxHgModqbtzPRg3Pw1W45otRTxZpRzpqh7pgGQ68CkUucW1pZMv82xUtwXxGqyyQEJqPXRh/QpUDf8OrOozkcpNE43+8ZhMMjUU187
Dear FortiGuard Support & Web Filtering Team,I am writing to urgently appeal the recent categorization of my website, thecupcut.com, which was mistakenly updated to the "Phishing" category by your automated system.This is a massive False Positive. I request a manual review by a security analyst based on the following facts:1. No Phishing Elements Exist: My website is a simple software informational blog. There are absolutely NO login forms, NO password fields, and NO credential-harvesting mechanisms anywhere on the site. It is physically impossible for this domain to be used for phishing.2. Cleared by Global Authorities:Google Safe Browsing has thoroughly scanned the domain and officially cleared it (Current Status: "No unsafe content found").Out of 94 global security vendors on VirusTotal, over 90 top-tier companies (including Kaspersky and McAfee) list the site as 100% Clean.Your automated scanner may have misinterpreted a standard layout, text, or an advertisement as a threat. C
I looking a way to fix the CVE-2025-31514 then i got this article PSIRT | FortiGuard Labs.Can i know what mean of 'Migrate to a fixed release'? My FGT running on version 7.4.11
Hi, I got and issue with my fortinet account, my third party authenticator not work and when i want to reset it, i received correctly the OTP code but when i add it on fortinet to reset, i got this ERROR Either your email or sms or password is incorrect. Please try again.
Been looking into conserve mode (on current versions, 5.6+, so only memory conserve mode) and to understand it better made the image above. Threshold values are based on the defaults. Some things I'm pretty sure about from documentation. But there are some things not clear to me, they either aren't described or at least I can't find that documentation. So primary question. Are the things shown in the image above how you believe conserve mode works? Anything which is wrong? Secondary question does anyone have any insight (preferably with links to documentation) on the question marks?* Are there other actions taken after entering conserve mode?* Does something change when dropped out of "extreme" conserve mode, or does that also have to return to green threshold before new sessions are allowed again? sources:changes (since 5.6...) : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Conserve-mode-changes-in-FortiGate-5-6-and-above/ta-p/198502tri
Is there a way to recover the deleted FortiToken, my colleague use Google authenticator (he's authenticator is already sync to cloud) and he accidentally deleted it. And he hold the master account on our Fortinet Support portal. He tried to use the Lost FortiToken in thrid party-app but no good, event the supplied information are all correct.
Hello,We have encountered an issue where FortiClient VPN Only clients are unable to connect, and the debug log shows the error "gw validation failed", whereas the full FortiClient EMS client works as expected. At the moment, the following setup is working correctly only with the paid FortiClient EMS:Remote Access VPN (IPsec)Certificate-based authenticationSAML authentication via Microsoft Entra ID (Azure AD)phase1-interface:config vpn ipsec phase1-interfaceedit "RA-VPN-IPSEC"set type dynamicset interface "wan2"set ike-version 2set authmethod signatureset net-device disableset mode-cfg enableset ipv4-dns-server1 10.102.xxx.xxxset ipv4-dns-server2 10.102.xxx.xxxset ipv4-dns-server3 10.100.xxx.xxxset proposal aes256-sha256set dhgrp 14set eap enableset eap-identity send-requestset eap-cert-auth enableset certificate "<our-worldwide-trusted-certificate>"set peer "RA-IPSEC-VPN-CLIENT"set ipv4-start-ip 10.102.251.10set ipv4-end-ip 10.102.251.200set ipv4-split-include "10.100.0.0-14
Hello,This is my current topology:FortiGate → FortiSwitch (FortiLink) with the following VLANs:DataVoiceThe FortiGate is also configured with SD-WAN using two MPLS interfaces.The issue I'm seeing is the following:When I connect a notebook to a port on the FortiSwitch, I can access all LAN devices without any problem. However, when I try to access the internet, for example by doing a ping, the traffic does not go beyond the Data VLAN gateway IP.Important detail:Both LAN and internet traffic should exit through the same MPLS path.To validate the issue, I reverted the MPLS interfaces back to the Huawei device, and in that scenario the customer has both LAN and internet connectivity working correctly.The configuration on the FortiGate is fairly straightforward, mainly BGP with SD-WAN, nothing unusual.Has anyone seen a similar behavior or have any ideas on what could be causing this?Thanks in advance.Si querés, también te puedo armar una
I have trouble connecting using FortiClient VPN version 7.4.3 hotfix 1.8758 and the latest Windows 11 25H2 update. After entering my login and password, I don't get any connection status feedback – I only get a "disconnect" button, which, when pressed, freezes the program and shows "disconnecting" all the time. I also have FortiClient VPN with an earlier hotfix version on other devices and have no connection issues but installing older version is not a solution, so I will be thankful for any advice.
RAM activationCPU(00:000106ca bfebfbff): MP initializationCPU(01:000106ca bfebfbff): MP initializationCPU(02:000106ca bfebfbff): MP initializationCPU(03:000106ca bfebfbff): MP initializationTotal RAM: 4096MBEnabling cache...Done.Scanning PCI bus...Done.Allocating PCI resources...Done.Enabling PCI resources...Done.Zeroing IRQ settings...Done.Verifying PIRQ tables...Done.Boot up, Initialize boot device failed. Changed Different Hard drives and still same error I cannot even get to the tftp configuration to install the latest OS Anyone have any insight about this error?
Hi,I'm new to Fortipam and I want to understand if there is a desktop application of Fortipam for the IT personal that connects to the fortipam and where you can create and use your secrets. Thanks in advance
HiI need to migrate all IPSec Tunnel to one zone to create a single policy.Now i can't migrate tunnel because "Integrate Interface" is gray and it can't select it.
Here is a cleaner and more professional version for your post:Hello everyone,I’m currently working with a FortiExtender (FEX) using LTE connectivity, and I’m facing an issue related to public IP changes.Every time the LTE provider assigns a new IP address, the connection drops completely. The only way to restore connectivity is by rebooting the FortiExtender.Has anyone experienced a similar behavior?I would like to understand:Is this expected behavior with LTE dynamic IP?Is there any configuration (keepalive, DPD, monitoring, etc.) that can prevent losing connectivity after an IP change?Would enabling specific SD-WAN or tunnel monitoring settings help in this case?Any recommendations or best practices would be greatly appreciated.Thanks in advance!
I would like to know if anyone has experience implementing guest authentication using QR codes or guest access codes through the FortiGate captive portal at the interface level.Currently, I am configuring a captive portal for guest WiFi access, and I would like to provide a more user-friendly authentication method for visitors. Ideally, I would like to implement one of the following options:Access through QR codes that redirect users directly to the captive portal login page.Guest access codes or vouchers that users can enter in the captive portal to gain temporary access
Hi,I tested a FortiExtender LAN Extension on an FGVM-02. After removing the Extender configuration, only the tunnel interface remains, which cannot be deleted. The error message is: (phase2-interface) # delete fext-ipsec-***Can not delete a static table entryCommand fail. Return code -61 Does anyone have an idea how I can remove it? Thanks.
Hello, We have FortiSwitch user ports configured with 802.1X authentication, using a Microsoft NPS server as the RADIUS server. We now need to ensure that IP phone ports and access point (AP) ports are also protected with 802.1X, so that if a device other than an AP or IP phone is connected, it must authenticate. I tried creating a dynamic port policy with the following logic: * The first three rules match APs based on vendor and device type, and assign them a VLAN policy without 802.1X.* The last rule assigns our 802.1X policy to any device that does not match the previous rules. However, when I connect a PC to these switch ports, it somehow receives the native VLAN configured in the VLAN policy used for the AP rules. This happens even though the PC does not appear as a matched device for those AP rules. Does anyone know why this might be happening? Or can you suggest another way to bypass 802.1X only for IP phones and APs without using MAB(without h
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.