Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi, I am currently migrating multiple Cisco ASA firewall to a single FortiGate (HA setup). I extracted multiple NTP server and DNS server, and all of them are requirement of the client for auditing. How can I configure this servers on the FortiGate?
Hi All,I need some expert opinion for my issue that is being caused by the FortiEMS Client. CPU behaviour:When downloading a test file, the CPU would remain at 100% consistently.Testing with another laptop performing the same download showed CPU around 45%, indicating normal behaviour.FortiClient observation:When FortiClient Fabric Agent (EMS) was enabled and the machine was on fabric, CPU usage during downloads would spike to ~100%.When FortiClient was disabled / off fabric, CPU usage dropped to ~40–50% during the same download test.This also causes network drop, teams issue and many more other problems that is related to network. The on-fabric feature currently has all modules disabled except for the system module, yet the CPU spike still occurs when the endpoint is connected to the fabric. The issue has been confirmed to be caused by the FortiEMS Client. My version is 7.2.8. Case has already been raised but I am not nearing or anywhere close to the solution. 
I have a setup where the Fortigate has Microsoft Entra Single Sign-On as an authentication scheme and a ZTNA setup that uses groups from that. The devices are Entra joined Intune managed, and synced and verified to the Forticlient EMS server. Everything works when using Windows devices. It automatically knows who the user is, matches the groups he is in and allows access to whatever is setup on the proxy policy. But when i do it for macOS devices, it doesn't work. I am having issues understanding what this means from the documentation FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.For the integration to work macOS endpoints must be managed by Intune and enrolled to the company portal using Entra ID. My mac device is managed by Intune and enrolled to the company portal using Entra ID (tho
We're running FortiClient 7.4.5. All of our Windows 11 computers contain thousands of events like this in the Windows Security log. There are close to 100 every minute and they're all the same. Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.File Name: \Device\HarddiskVolume3\Program Files\Fortinet\FortiClient\FortiAmsi.dll I don't know when the issue started, but it has been going on for at least a year and through multiple FortiClient versions. I opened a Fortinet support ticket and they told me it was a Microsoft issue. I'm skeptical that attempting to contact Microsoft would be helpful. Do others notice these events in the security log. The events occur so often that it's hard to find other important events.
my forticlient has been working fine now i cant get in always saying credential or sslvpn configuration is wrong -7200 even tho my password and everything is correct
When I tried to connect to my IPSEC VPN, an error " time out connecting to its wan"what should I do?
Hi!The FortiClient IPsec connection takes too long when using the FortiClient EMS-managed client.Clients that are not managed by EMS (VPN‑only client) take about 6 seconds to establish the IPsec connection.Example log:06:09:02.585 → VPN connection starts06:09:02.834 → IKE_SA_INIT sent06:09:02.851 → IKE_SA_INIT received (16ms)06:09:02.914 → EAP-MSCHAPv2 started06:09:02.936 → EAP-MSCHAPV2: Authentication succeeded (22ms!)06:09:03.657 → negotiation success (~1s total IKE)+4.29s GAP – NO IKE activity06:09:07.947 → first ike_sa_alive checks(only keepalives, no real traffic)06:09:24.777 → Ready to read packets06:09:24.787 → tunnel_name = dummyThe IKE negotiation itself takes ~1 second.Technically, the tunnel is up at 06:09:03.657.But FortiClient only reports the tunnel as "Ready" 21 seconds later — from 06:09:03 to 06:09:24.Attempts so far: config user settingset auth-on-demand always set client-auto-negotiate enableset client-keep-alive enableCreated VIP and policy to allow traffi
found several KB articles state the dev_down value in diagnose sys session stat or diagnose sys session full-stat is related to the time firewall sessions are deleted because an (IPsec) interface goes down, although one says IPsec admin down and the other general interface down ... planning to do some tests on that soonish. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Session-counter-information/ta-p/197839 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Meaning-of-the-counter-fields-in-diagnose-sys/ta-p/192305 But how does it relate to two values? what is the first and the second value, a recent and total value perhaps? Can't find the exact answer in the KBs.
Hello, I just ran into this: on a FGT I have two policies: One has a VIP as destination to rewrite an ip into a different subnetThe other matches all traffic between the involved subets and interfaces.the policies have exactly this order. In FortiAnalyzer I can see:- it does the VIP because it shows me the destinatin nat ip- it didn't match the first policy though because source intf and -address were wrong in itBut- it also didn't match the 2nd one even though everything in there matches and the traffic got denied (Policy #0 implicit deny). I understand why it didn't match the first policy but I don't get why it didn't match the other policy then. Policy #1: Source Interface: zone2destination Interface: zone1source address is in subnet of member of zone2destination: vip1action: allowservices: ping,https vip1:external IP: ip the traffic originates tomapped IP: destination ip (which is also on a meber of zone1) Didn't match because traffic or
Forticlient VPN 7.4.3.1790 (free)Fortigate 100F 7.4.11We are doing cert based IKEv1 with xauth and Fortitoken, works fine.Now im migrating, so i started setting up SAML and IKEv2 with PSK, it worked. From there I wanted to make it certificate base, some EAP config are already in there:
Hello everyone, I'm used to upgrade Fortinet products from the GUI, the usual steps, download the image from support.fortinet.com then upload it on the GUI.Apparently FortiNAC is a different story, I would appreciate any guidance on this.I'm trying to upgrade from version 7.2.7 to 7.6.4. BR,
Hi, I accidentally deleted one of the free FortiToken Mobile tokens that came with my FortiGate 80F.Now the token is no longer visible in User & Authentication → FortiTokens.Is there any way to re-import or restore the deleted free FortiToken Thank you.
From FortiMail documentation, one can read:Sensitive data can be any of the following types:Predefined: For your convenience, FortiMail comes with a list of predefined information types, such as credit card numbers and SIN numbers. To view the predefined sensitive data, go to Data Loss Prevention > Sensitive Data > Standard Compliance. Indeed, I can find the list of pre-defined sensitive data and their names made clear what they match most of the time. However, I was wondering if it was possible to get details on how these default predefined sensitive data are actually configured. For instance, would "Illegal_Drugs" match drug names in any language? The same question applies to "Offensive_Words". If not, knowing the structure of these would help configure our own fingerprint. Regarding fingerprint, the documentation states:DLP document fingerprintingOne of the DLP techniques to detect sensitive data is fingerprinting (also called document fingerprinting).
Hi, Can someone advise , I have a fortinet router that have 2 sim card install, but the failover for the sim card does not work as when sim 1 is down sim 2 does not take over and the internet is down. 1)How can I check if is configure to failover between 2 sim card2)If not can advise how to configure the failover for the sim card Regardsvinowg
Hi all,I’m looking for guidance on designing a scalable hub-and-spoke architecture on a FortiGate.Design OverviewI have AWS connected to a FortiGate via Direct Connect (DX) and advertising routes via BGP.The FortiGate acts as a hub.Multiple vendors (customers) connect to the same FortiGate.Each vendor has a dedicated BGP peering session.RequirementI need strict separation between vendors:Customer A must NOT be able to communicate with Customer B.Each customer should be isolated at the routing level.Only the VRF associated with the AWS DX connection should have visibility of all customer prefixes.Traffic flow should be:Customer → FortiGate → AWSAWS → FortiGate → Specific CustomerBut never:Customer A → FortiGate → Customer BConstraintsThe solution must be scalable (10+ customers, potentially more).I do NOT want:One VDOM per customer.VDOM links between customers.I’m looking to use VRFs instead of VDOMs for segmentation.What I’m Trying to AchieveConceptually:Each customer has its own
Hi,Hoping you all are doing great today. I want to share as well as get expert thoughts on an issue i am facing. I have a ForitGate 401E, which is out of support btw, is booting directly into SMC mode. It is getting manual LAN ip and is pingable from my laptop. And the firewall is rebooting itself nearly after every 5 minutes (possibly a bootloop). There is no option of TFTP in the SMC mode. And the logs that i have been able to fetch are as follow:comlog print--- COMLOG ENABLED: 2026-02-27 02:05:30 ------ COMLOG SYSTEM BOOT: 2026-02-27 02:07:43 ---FortiGate-401E (22:10-08.16.2019)Ver:05000013Serial number:FG4H1ETBXXXXXXXRAM activationCPU(00:000906ea bfebfbff): MP initializationCPU(02:000906ea bfebfbff): MP initializationCPU(04:000906ea bfebfbff): MP initializationCPU(06:000906ea bfebfbff): MP initializationCPU(08:000906ea bfebfbff): MP initializationCPU(0a:000906ea bfebfbff): MP initializationTotal RAM: 8176MBEnabling cache...Done.Scanning PCI bus...Done.Allocating PCI resources...Don
I’m trying to configure the fortigate/fortiswitch to replace my old Cisco equipment.However I cannot get the switch to recognise the two devices on different vlans.I’ve set native 200 (pc) allowed 100,200 (voice,pc).Created a lldp profile and assigned it to vlan voice interfaceAre there any other steps I need to take or is this just not possible ?
Hello support-team,recently we've updated our 600F to 7.4.11M release.Now I'm wondering why the ability to edit the set of services that are used within more than one policy is gone. That feature improved administration and is necessary in my opinion.I found article 330663 for bulk editing a few items of a policy but services are missing. Is there an option to enable editing the services in bulk?Best regardsSebastian
Hi; I have the same problem as:https://community.fortinet.com/t5/Support-Forum/FSSO-cannot-read-Windows-NPS-user-logins/m-p/63413/thread-id/63323/highlight/true I have an Windows AD Environment with two DCs (Server 2016). and and Windows Radius Server NPS (Server 2019).Fortigate 100F 7.4.3 The Radius is for Wireless Authentication with my Aruba Instant APs. Working fine.FSSO with the Agents installed works also finde, and i applied and testet some User-based Policies, also working fine. But how do i get the FSSO Agent Collector to collect the data from my Radius? Best regardsLukas
Hi all. A dump question.Can we install the AD connector within the AD server?Cause in the article didn't mention about the connector is not allowed to install with the AD server.It only mention install in the host that can connect to both EMS and AD server but the host spec also not given.
Hi to all,I would like to disable VPN on my Fortigate. It was configured by the company who installed the firewall but I will not use it. Which command do I have to run because I have asked to the Forticare and they told me to run the following which does not seem to correspond to unable the VPN but the opposite: config vpn ipsec phase1-interface edit "VPN_Forticlient" set type dynamic set interface "wan" set peertype any set net-device disable set mode-cfg enable set proposal aes128-sha256 aes256-sha256 aes128-sha1 aes256-sha1 set comments "VPN: VPN_Forticlient (Created by VPN wizard)" set wizard-type dialup-forticlient set xauthtype auto set authusrgrp "VPN_Group" set i
I am using forticlient.forticloud.com/ems Version 7.4.3 build1926. I have deployed FortiClient 7.4.3.1790 to my endpoints. Initially, when I did a vulnerability scan, I found many. I tried different ways to patch them and most of them got patched. My vulnerability scans still show new vulnerabilities. When I try to patch them they show Patch Scheduled. How do I determine or specify when a Scheduled Patch will be applied?
We have several user groups mapped to separate, corresponding SSL-VPN Portals. Each of these portals has Split Tunnel Enabled Based on Policy Destination. Each of these portals also has Routing Address Override with network addresses that match the same "allowed destination" addresses in their corresponding policies. Is Routing Address Override even needed?According to Split Tunnel Enabled Based on Policy Destination, "Only client traffic in which the destination matches the destination of the configured firewall policies will be directed over the SSL-VPN tunnel."So in an example where the Accounting network is 192.168.0.0/24 and a user is in the Accounting Group, which is assigned to the Accounting Policy (that allows access to the 192.168.0.0/24 network); Would I even need any address in the Routing Address Override for the Accounting SSL-VPN Portal?From what I understand, any traffic to 192.168.0.0/24 would go over the SSL-VPN with Split Tunnel Enabled Based on Policy Destinati
Hi everyone,is there a way to use a separate interface for management purpose different from the service interface used by endpoints for telemetry ? I'm using the Forticlient EMS VM version. Thank you in advance
Good day, I'm trying to install a Fortigate 7.6.6 VM for a lab and have this issue After that I only get a white screen, and enter the trial license window or the device or anything. This is my configuration FortiGate-VM64-KVM (port1) # showconfig system interfaceedit "port1"set vdom "root"set mode dhcpset distance 1set allowaccess ping https ssh httpset type physicalset snmp-index 1nextend FortiGate-VM64-KVM (dns) # showconfig system dnsset primary 8.8.8.8set secondary 8.8.4.4end FortiGate-VM64-KVM (1) # getseq-num : 1status : enabledst : 0.0.0.0 0.0.0.0gateway : 10.16.13.20preferred-source : 0.0.0.0distance : 1weight : 0priority : 1device : port1 This is what I get when I do the diagnose debug enable diagnose debug application update -1 execute update-now FortiGate-VM64-KVM # execute update-nowupd_daemon[1981]-Received update request from pid=2518FortiGate-VM64-KVM # do_setup[349]-Starting SETUPupd_
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.