Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi,Hoping you all are doing great today. I want to share as well as get expert thoughts on an issue i am facing. I have a ForitGate 401E, which is out of support btw, is booting directly into SMC mode. It is getting manual LAN ip and is pingable from my laptop. And the firewall is rebooting itself nearly after every 5 minutes (possibly a bootloop). There is no option of TFTP in the SMC mode. And the logs that i have been able to fetch are as follow:comlog print--- COMLOG ENABLED: 2026-02-27 02:05:30 ------ COMLOG SYSTEM BOOT: 2026-02-27 02:07:43 ---FortiGate-401E (22:10-08.16.2019)Ver:05000013Serial number:FG4H1ETBXXXXXXXRAM activationCPU(00:000906ea bfebfbff): MP initializationCPU(02:000906ea bfebfbff): MP initializationCPU(04:000906ea bfebfbff): MP initializationCPU(06:000906ea bfebfbff): MP initializationCPU(08:000906ea bfebfbff): MP initializationCPU(0a:000906ea bfebfbff): MP initializationTotal RAM: 8176MBEnabling cache...Done.Scanning PCI bus...Done.Allocating PCI resources...Don
I’m trying to configure the fortigate/fortiswitch to replace my old Cisco equipment.However I cannot get the switch to recognise the two devices on different vlans.I’ve set native 200 (pc) allowed 100,200 (voice,pc).Created a lldp profile and assigned it to vlan voice interfaceAre there any other steps I need to take or is this just not possible ?
Hello support-team,recently we've updated our 600F to 7.4.11M release.Now I'm wondering why the ability to edit the set of services that are used within more than one policy is gone. That feature improved administration and is necessary in my opinion.I found article 330663 for bulk editing a few items of a policy but services are missing. Is there an option to enable editing the services in bulk?Best regardsSebastian
Hi; I have the same problem as:https://community.fortinet.com/t5/Support-Forum/FSSO-cannot-read-Windows-NPS-user-logins/m-p/63413/thread-id/63323/highlight/true I have an Windows AD Environment with two DCs (Server 2016). and and Windows Radius Server NPS (Server 2019).Fortigate 100F 7.4.3 The Radius is for Wireless Authentication with my Aruba Instant APs. Working fine.FSSO with the Agents installed works also finde, and i applied and testet some User-based Policies, also working fine. But how do i get the FSSO Agent Collector to collect the data from my Radius? Best regardsLukas
Hi all. A dump question.Can we install the AD connector within the AD server?Cause in the article didn't mention about the connector is not allowed to install with the AD server.It only mention install in the host that can connect to both EMS and AD server but the host spec also not given.
Hi to all,I would like to disable VPN on my Fortigate. It was configured by the company who installed the firewall but I will not use it. Which command do I have to run because I have asked to the Forticare and they told me to run the following which does not seem to correspond to unable the VPN but the opposite: config vpn ipsec phase1-interface edit "VPN_Forticlient" set type dynamic set interface "wan" set peertype any set net-device disable set mode-cfg enable set proposal aes128-sha256 aes256-sha256 aes128-sha1 aes256-sha1 set comments "VPN: VPN_Forticlient (Created by VPN wizard)" set wizard-type dialup-forticlient set xauthtype auto set authusrgrp "VPN_Group" set i
I am using forticlient.forticloud.com/ems Version 7.4.3 build1926. I have deployed FortiClient 7.4.3.1790 to my endpoints. Initially, when I did a vulnerability scan, I found many. I tried different ways to patch them and most of them got patched. My vulnerability scans still show new vulnerabilities. When I try to patch them they show Patch Scheduled. How do I determine or specify when a Scheduled Patch will be applied?
We have several user groups mapped to separate, corresponding SSL-VPN Portals. Each of these portals has Split Tunnel Enabled Based on Policy Destination. Each of these portals also has Routing Address Override with network addresses that match the same "allowed destination" addresses in their corresponding policies. Is Routing Address Override even needed?According to Split Tunnel Enabled Based on Policy Destination, "Only client traffic in which the destination matches the destination of the configured firewall policies will be directed over the SSL-VPN tunnel."So in an example where the Accounting network is 192.168.0.0/24 and a user is in the Accounting Group, which is assigned to the Accounting Policy (that allows access to the 192.168.0.0/24 network); Would I even need any address in the Routing Address Override for the Accounting SSL-VPN Portal?From what I understand, any traffic to 192.168.0.0/24 would go over the SSL-VPN with Split Tunnel Enabled Based on Policy Destinati
Hi everyone,is there a way to use a separate interface for management purpose different from the service interface used by endpoints for telemetry ? I'm using the Forticlient EMS VM version. Thank you in advance
Good day, I'm trying to install a Fortigate 7.6.6 VM for a lab and have this issue After that I only get a white screen, and enter the trial license window or the device or anything. This is my configuration FortiGate-VM64-KVM (port1) # showconfig system interfaceedit "port1"set vdom "root"set mode dhcpset distance 1set allowaccess ping https ssh httpset type physicalset snmp-index 1nextend FortiGate-VM64-KVM (dns) # showconfig system dnsset primary 8.8.8.8set secondary 8.8.4.4end FortiGate-VM64-KVM (1) # getseq-num : 1status : enabledst : 0.0.0.0 0.0.0.0gateway : 10.16.13.20preferred-source : 0.0.0.0distance : 1weight : 0priority : 1device : port1 This is what I get when I do the diagnose debug enable diagnose debug application update -1 execute update-now FortiGate-VM64-KVM # execute update-nowupd_daemon[1981]-Received update request from pid=2518FortiGate-VM64-KVM # do_setup[349]-Starting SETUPupd_
Our district has started an esports program and we're having difficulties with Nintendo Switches on our network. NAT Type is B. UDP ports are not blocked. When hosting a game on a switch on our network, those outside the network cannot connect. They get a NAT Transversal error. What settings do I need to have on the FortiGate to allow esports traffic for the Nintendo Switches?
Hello, Fairly new to Fortinet and I am looking to get some guidance. I currently have 2x FortiSwitch 148F and I am looking to get setup in my enviroment. What is the best route to get support with this?
We're an MSSP hosting our own on prem multi-tenant Fortimanager and a few thousand FortiGates out in the field and VMs in our datacenters / public cloud.Prior to CVE-2024-47575 we had our FMG exposed to the internet. Upon the news breaking we ACL'ed off the FMG to known FGT IPs. The problem with this is that we offer SD-WAN with LTE (behind CG-NAT) so static IP based ACLs (via threatfeed) which is creating massive operational headaches.I have some designs I've been considering on how to work around this, but I'd like to hear from you guys on how you've chosen to handle this.
Any strategies or advice you can give on adding the FortiSwitch to an existing FortiGate? I'm trying to avoid the removal of firewall policies, addresses, DHCP server, SNAT, essentially anything that ties back to where the switch will be plugged in at and converted to a FortiLink connection.
When we use IPSec for remote access with Split tunnel enabled, can we make the fortiget to not set dns in the client?Now when the forticlient connected to the VPN then the client can't access the local domain.
Hi everyone, Quick question: today we installed on an existing firewall a FortiGate FGT101F running firmware v7.4.8 build2795 (Mature), in NAT mode. The issue is that it always stays “Out of sync” — it looks like synchronization never actually starts. It’s odd because I followed the guide step by step, and I also performed a factory reset, but nothing changed: it still remains Out of sync. What’s even stranger is that with another customer, on a similar setup, the sync started immediately. Any ideas on what this could depend on, or has anyone run into this before? Thanks!
I recently bought a FortiGate 300D from Facebook Marketplace for really cheap. I’m planning to use it for my homelab while studying for CCNA and general networking practice.The problem is I don’t have access to firmware downloads since I’m not the original owner and don’t have a support contract tied to my account.Does anyone have experience with getting firmware access for second‑hand devices and registering older / EOL FortiGate units?
Hello Recently, we've been assigned for a PoC for one of our customers which is i financial institution. We've setup a hub & spoke topology with 2 Fortinet VMs in Active-Active scenario and External & Internal Load Balancers.Our main concern and issue is when for example vm01 on spoke01 vnet communicates with vm01 on spoke02 via fgt-1 and i perform a reboot on this specific firewall the RDP or SSH session is lost. Is there any solution or workaround where in situations like these the TCP sessions are smoothly transferred on the next fortinet ?Regards
I have a query about a FAC for a customer, it acts as a Captive Portal for Guest WIFI, and it works fine except for Apple Devices, there is an issue with GoDaddy and trust on IOS, which neither of the vendors seem to care about, so I need to move from GoDaddy, The reason I am using it is so that Guests don't get a secure warning when accessing the FAC portal page, The company has a domain, that I created a cert for and used DNS to point that FQDN internally to the FAC, this to me is very clumpy, but that's the way its done! The customer doesn't want to use the existing domain and will purchase a new one, "companyxyz.com" for example. How would this work? the FAC is on an internal IP, and if I create a CSR for "fac.companyxyz.com" and get it signed by lets encrypt. How will this resolve to an internal IP? would the DNS for the domain allow a Private IP? Has anyone ever done Lets Encrypt on a FAC? Ill be using this same domain to create certificates on th
Hello Supoort, I have a 80f fortigate that is connect to external customer (BOH) they a use Palto altoWe configured two VPN ( from my Fortigate to customer (1) using a private lease name NDMA as primary link and the other is an internet connectionBecause we are using policy base vpn am unable to configure SDWAN on the Fortigate.My challenge if the primary link (NDMA) drops how do I fail over seamlessly to the other secondary link.Thank you
Hi all,I’m looking for best practice advice.Topology:20 hubs2 branchesEach hub has:2x MPLS links (already in SD-WAN)1x FortiExtender (Internet link)My idea is to use Overlay Orchestration only over the Internet (FEX) link, since it will be used for Internet access and backup.Would it be better to:Use Overlay only on the Internet link and keep MPLS as regular SD-WAN transportorInclude MPLS + Internet in the Overlay?What would be the recommended design at this scale?Thanks.
Good Morning Community,I'm comparing solutions that can work as a mail server for an organization (previously had exchange server)so I would like to ask does anyone has a use-case of running FortiMail in server mode, and feed me back on his experience concerning the below points:Effectiveness of server mode, and does it provide a real dependable mail server solution for organization levelCons of the this solution, especially concerning user experience and administrator experienceApps (like outlook or others) that can be used on desktop and mobile devices to access this mail server, and support calendar and address book synchronization, and the user experience concerning those featuresAdministrator experience with LDAP authentication (if applicable)I would be glad to find a successful use-case using this solutionFortiMail
For these past two firmware releases, it looks like emails won't be sent out for 2FA and for Automation Stitching? I've tried our postfix relay and fortinet's email server and neither work. Sending a test email via diagnose log alertmail test shows nothing incoming on our postfix relay and no relevant logs. I know the release notes list 2FA emails not working for both versions but is it affecting all emails in general?Is there anyway to remediate this, or will I just need to wait for 7.6.7?
Voicemail audio is very low. When playing voicemail you have to turn volume control all the way up to hear audio
Does anyone here know what causes this error and how to fix it.I check the certificate for SSL VPN, and it still shows as valid. So, I'm sure where the error is from.Also note a few weeks ago I upgraded from 7.2.11 to 7.4.11
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.