Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
RAM activationCPU(00:000106ca bfebfbff): MP initializationCPU(01:000106ca bfebfbff): MP initializationCPU(02:000106ca bfebfbff): MP initializationCPU(03:000106ca bfebfbff): MP initializationTotal RAM: 4096MBEnabling cache...Done.Scanning PCI bus...Done.Allocating PCI resources...Done.Enabling PCI resources...Done.Zeroing IRQ settings...Done.Verifying PIRQ tables...Done.Boot up, Initialize boot device failed. Changed Different Hard drives and still same error I cannot even get to the tftp configuration to install the latest OS Anyone have any insight about this error?
Hi,I'm new to Fortipam and I want to understand if there is a desktop application of Fortipam for the IT personal that connects to the fortipam and where you can create and use your secrets. Thanks in advance
HiI need to migrate all IPSec Tunnel to one zone to create a single policy.Now i can't migrate tunnel because "Integrate Interface" is gray and it can't select it.
Here is a cleaner and more professional version for your post:Hello everyone,I’m currently working with a FortiExtender (FEX) using LTE connectivity, and I’m facing an issue related to public IP changes.Every time the LTE provider assigns a new IP address, the connection drops completely. The only way to restore connectivity is by rebooting the FortiExtender.Has anyone experienced a similar behavior?I would like to understand:Is this expected behavior with LTE dynamic IP?Is there any configuration (keepalive, DPD, monitoring, etc.) that can prevent losing connectivity after an IP change?Would enabling specific SD-WAN or tunnel monitoring settings help in this case?Any recommendations or best practices would be greatly appreciated.Thanks in advance!
I would like to know if anyone has experience implementing guest authentication using QR codes or guest access codes through the FortiGate captive portal at the interface level.Currently, I am configuring a captive portal for guest WiFi access, and I would like to provide a more user-friendly authentication method for visitors. Ideally, I would like to implement one of the following options:Access through QR codes that redirect users directly to the captive portal login page.Guest access codes or vouchers that users can enter in the captive portal to gain temporary access
Hi,I tested a FortiExtender LAN Extension on an FGVM-02. After removing the Extender configuration, only the tunnel interface remains, which cannot be deleted. The error message is: (phase2-interface) # delete fext-ipsec-***Can not delete a static table entryCommand fail. Return code -61 Does anyone have an idea how I can remove it? Thanks.
Hello, We have FortiSwitch user ports configured with 802.1X authentication, using a Microsoft NPS server as the RADIUS server. We now need to ensure that IP phone ports and access point (AP) ports are also protected with 802.1X, so that if a device other than an AP or IP phone is connected, it must authenticate. I tried creating a dynamic port policy with the following logic: * The first three rules match APs based on vendor and device type, and assign them a VLAN policy without 802.1X.* The last rule assigns our 802.1X policy to any device that does not match the previous rules. However, when I connect a PC to these switch ports, it somehow receives the native VLAN configured in the VLAN policy used for the AP rules. This happens even though the PC does not appear as a matched device for those AP rules. Does anyone know why this might be happening? Or can you suggest another way to bypass 802.1X only for IP phones and APs without using MAB(without h
Last year we closed a location in the Eastern time zone and put the recovered AP's in storage. When a site in the Central time zone had an urgent need, we shipped them 5 AP's from this inventory, and now the site is complaining all their computers are defaulting to the Eastern Time Zone. Now the finger pointing is going on between the Windows desktop team and the Networking team. I discovered a portal MS provides where you can request your BSSIDs to not be tracked in their geo database, but it's an input only form that leaves you wondering if anything is really going to happen. It also provides no way to determine if BSSID is what is causing the incorrect time zone detection. The FortiGate is set to the correct time zone, has the correct time, and DHCP points clients to the internal NTP servers for centralized time. I am curious if anyone else has come across this and have any advice on resolving it? Denny
Hey guysI already know that we can update IPS Engine manually.https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-manually-upgrade-the-IPS-Engine/ta-p/194513https://community.fortinet.com/t5/FortiGate/Technical-Tip-Upgrading-IPS-Engine-on-the-primary-FortiGate-will/ta-p/202345But can we update IPS Engine automatically ? Are there any related document ?
Lab Setup:Host Machine:Connected to internet.Default gateway: 192.168.1.1/24Running VMware WorkstationVM Configurations:FortiWeb VM:Port1 (LAN segment: WAN): 10.10.10.10/24Port2 (LAN segment: Lan): 192.168.2.101/24Port3 (Management - Bridged): 192.168.1.121/24Windows Client VM:LAN segment: WANIP: 10.10.10.2/24Default gateway: 10.10.10.10Firewall disabledWindows Server_1 VM (IIS):LAN segment: LanIP: 192.168.2.250/24Default gateway: 192.168.2.101Windows Server_2 VM (IIS):LAN segment: LanIP: 192.168.2.240/24Default gateway: 192.168.2.101FortiWeb Configuration:Created VIP: 10.10.10.50/24 on Port1Created Virtual Server using this VIPCreated Server Pool:Type: Reverse ProxyServer Balance: enabledHealth Check: HTTPLoad Balancing: Round RobinAdded both servers (192.168.2.250 and 192.168.2.240)Port: 80Health check: InheritCreated Policy:Linked to Virtual ServerLinked to Server PoolProtocol: HTTPLog traffic: enabledIIS Configuration:IIS installed on both Windows ServersDefault website works when
Hi,I download the latest Fortinet VPN file.Trying to install it ion Windows 11 25H2The process seems working but at the end, application is not installed. no error message.I'm trying to supress microsoft visual C++ distirbution, then retry to install but same result.How to fix it & install the VPN client ?
these 2 microsoft team network are injected into mac route table to be sent over vpn tunnel and when it does this, user fails to join the meeting (see attached screenshot). Our vpn set up is ssl vpn and with split tunnel based on firewall policy destination with FQDN route injectionBelow are those network:Below are microsoft team network on netstat -nr above52.112.127.222Query name (QNAME):api.flightproxy.teams.microsoft.comAnswer (A record) name (RRNAME):epx-enterpriseproxy.d03-058.ic3-calling-enterpriseproxy.01-eastus-prod.cosmic.office.netReturned IP52.112.127.222 52.112.23.78Query name (QNAME):epx.usea-03.ic3-calling-enterpriseproxy.eastus-prod.cosmic.office.netAnswer (A record) name (RRNAME):epx-enterpriseproxy-1.d03-058.ic3-calling-enterpriseproxy.01-eastus-prod.cosmic.office.netReturned IP:52.112.23.78It appears so far only mac user having this issue . The issue is reproducible easily. We run through diagnose firewall fqdn list-all and the injec
Hello,I made a support ticket for this issue (=11577363) The combination we use :Forticlient-EMS with IKEv2(with EAP-TTLS) IPSEC dialup vpn with authentication via AD LDAP(S) , Fortigate v7.4.x does not seem to support the following : change the password when expired or change for the first time at login when checked.I've been asked to make a new feature request to allow this in future releases.I hope this can be done via this way.
Anyone seen a problem using FMG from Safari on MacOS where you occasionally (every few minutes) get a message saying connection to FMG was lost, usually counts down for a few seconds then reconnects. It's likely related to a tcp keep alive because it doesn't happen when I'm interacting, only when I'm idle for a few minutes. I'm just not sure if I should adjust Mac or FMG side. I only see this in FMG but it never happens on Windows machines, even using Safari.
Hello together, we are currently using free FortiClient VPN in our environment and have started experiencing a serious issue affecting multiple users.When users click “Connect” in the FortiClient VPN client, the connection progress does not start — no percentage counter appears and the login process does not proceed at all. In addition, the FortiClient icon is no longer visible in the system tray.We have already: Restarted all related servicesPerformed complete uninstallations and reinstallationsRebooted the affected machines multiple times None of these steps resolved the issue. The only thing that has worked so far is a full reinstallation of the operating system, which is obviously not a sustainable solution. The issue has already occurred on 6 machines and the number is increasing.We need assistance in identifying the root cause and a proper fix. Thanks for the Help. Ist an German Client.There is no percentage progress bar displayed during the connecti
Hi,When a user logs in to FortiSASE for the first time, the device is automatically placed in the Default Endpoint Group.Is there a way to make the device join a specific endpoint group immediately instead of going to the Default group first?I would like to avoid moving devices manually after first login.
Hello,I’m facing an issue with FSSO on FortiGate.Scenario:FSSO is configured and connected correctly.When I run: diagnose debug authd fsso listI can see all logged-in users that FSSO knows about.However:The firewall does not recognize these users in policies.The users are not usable for authentication-based rules.They only become available after I manually refresh/pull users from the GUI.this photo how i pulled into firewall My Question:Is there a way to pull/import FSSO users into FortiGate via CLI or API instead of using the GUI?Specifically:Is there a CLI command to force FortiGate to sync FSSO users?Can this be done via REST API?Is there a debug command that forces the firewall to populate the user table? Any guidance would be appreciated.Thank you.FortiGate #FSSO
Hi all,I need one clarity about captive portal option we have under user and authentication.i wanted to know the use case of this and by default it is disable still captive portal works in my environment.
Hi everyone! I am currently doing a clean-up on our FG501-E. Part of cleanup is to check whether the tunnels are still passing traffic. Where could I efficiently check this type of log? I did the 3 and no results came back1. diag vpn ike gateway list2. Went to the GUI > Dashboard > Network > IPSEC3. Went to FortiAnalyzer > Events > VPN It feels like I am doing wrong on checking. Could you kindly suggest other ways to check this? Regards!
Hi, I am currently migrating multiple Cisco ASA firewall to a single FortiGate (HA setup). I extracted multiple NTP server and DNS server, and all of them are requirement of the client for auditing. How can I configure this servers on the FortiGate?
Hi All,I need some expert opinion for my issue that is being caused by the FortiEMS Client. CPU behaviour:When downloading a test file, the CPU would remain at 100% consistently.Testing with another laptop performing the same download showed CPU around 45%, indicating normal behaviour.FortiClient observation:When FortiClient Fabric Agent (EMS) was enabled and the machine was on fabric, CPU usage during downloads would spike to ~100%.When FortiClient was disabled / off fabric, CPU usage dropped to ~40–50% during the same download test.This also causes network drop, teams issue and many more other problems that is related to network. The on-fabric feature currently has all modules disabled except for the system module, yet the CPU spike still occurs when the endpoint is connected to the fabric. The issue has been confirmed to be caused by the FortiEMS Client. My version is 7.2.8. Case has already been raised but I am not nearing or anywhere close to the solution. 
I have a setup where the Fortigate has Microsoft Entra Single Sign-On as an authentication scheme and a ZTNA setup that uses groups from that. The devices are Entra joined Intune managed, and synced and verified to the Forticlient EMS server. Everything works when using Windows devices. It automatically knows who the user is, matches the groups he is in and allows access to whatever is setup on the proxy policy. But when i do it for macOS devices, it doesn't work. I am having issues understanding what this means from the documentation FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.For the integration to work macOS endpoints must be managed by Intune and enrolled to the company portal using Entra ID. My mac device is managed by Intune and enrolled to the company portal using Entra ID (tho
We're running FortiClient 7.4.5. All of our Windows 11 computers contain thousands of events like this in the Windows Security log. There are close to 100 every minute and they're all the same. Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.File Name: \Device\HarddiskVolume3\Program Files\Fortinet\FortiClient\FortiAmsi.dll I don't know when the issue started, but it has been going on for at least a year and through multiple FortiClient versions. I opened a Fortinet support ticket and they told me it was a Microsoft issue. I'm skeptical that attempting to contact Microsoft would be helpful. Do others notice these events in the security log. The events occur so often that it's hard to find other important events.
my forticlient has been working fine now i cant get in always saying credential or sslvpn configuration is wrong -7200 even tho my password and everything is correct
When I tried to connect to my IPSEC VPN, an error " time out connecting to its wan"what should I do?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.