Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello,I have two FortiGates (Site 1 & Site 3) connected via two GRE overlays:GRE_DC1_S3_AS20 – latency: 0.39ms, packet loss: 0%, jitter: 0.05msGRE_DC1_S3_SP5 – latency: 35.15ms, packet loss: 0%, jitter: 2.79msI configured SD-WAN between the two sites.Test scenario:Site 1: 172.16.213.2Site 3: 172.16.233.31. Best-effort / untagged trafficSD-WAN rule: Best Quality, latency criterionTraffic correctly uses AS20When AS20 degrades, traffic fails over to SP5 → works as expectedAfter this test, I modified the SD-WAN rule for untagged traffic:Strategy: ManualPreferred interface: SP5Observed behavior:Untagged traffic correctly goes via SP5 (as intended)2. Classified traffic (CS6) SD-WAN ruleNetwork Control for CS6 class trafficStrategy: Best QualityCriteria: LatencyProtocol specification:Protocol number: 0Type of Service (TOS): 0xc0Bit mask: 0xffTest ping from 172.16.233.2 :ping -s 600 -c 100 -D -Q 0xc0 172.16.213.2Expected behavior:Traffic should use AS20 because latency (0.39ms) is well bel
Hi All, So have some MacBooks with sometimes this message, but wifi is still running, no ip change or whatever. 1 - Why this messages? (How can I find out why this is happening)2 - How to disable them? Any ideas?ThanksFortinac Persistant Agent v10.7.2.13Connected with FortiAP
My team has been deploying a lot of SDWan lately with DIA and Broadband circuits. We have a couple of sites that have frequently been reporting session disconnects from cloud hosted applications and SIP phones that suddenly lose audio. I asked the sites to start reporting the exact times so I could correlate their issues to events in the logs. So far, each reported event seems to correlate to SDWan changes. Digging in deeper, neither of the circuits seem to be dropping, just falling outside the defined SLA values. Each time it was reported, I checked the active sessions on the firewall for the impacted phones and saw the destination interface being used didn't match the interface SDWan was preferring at the time. This leads me to believe the SDWan decisions are impacting existing connections. If I have the "Update Static Route" slider enabled, and a circuit doesn't meet the defined SLA requirement, will it break existing connections by removing the rout
My security team has this compliance requirement."Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters." How would this be configured in FortiGate?
Hi all, So I am trying to setup Azure Saml for the first time and I am hitting an issue that I cannot seem to find an answer to. So when using the forticlient I can get to show the microsoft login page but after I enter the user/password I get this. AADSTS700016: Application with identifier '' was not found in the directory ''. This can happen if the application has not been installed by the administrator of the tenant or consented to by any user in the tenant. You may have sent your authentication request to the wrong tenant. Everything I can find seems to point to the making sure the Azure Application Identifier (Entity ID) and the fortigate Entity-ID match but I have verified it and they do match so not sure what else to look at. Eddie
Dear all, i wanted to improve my multicast traffic enabling IGMP snooping and multicast routing. I am using a Fortigate 40F (7.2.10) together with a Fortiswitch 108F and FortiAP 231G. Before, multicast between my VLANS (ports are on NAC mode) worked perfectly, but now I am lost and I do not know what I am doing wrong... Here some information out of my CLI: FortiGate40F (settings) # showconfig system settingsset multicast-ttl-notchange enableset gui-multicast-policy enableset gui-dos-policy enableset gui-local-in-policy enableset gui-dynamic-routing enableset gui-advanced-wireless-features enableset gui-email-collection enableset gui-multiple-interface-policy enableFortiGate40F # get switch-controller igmp-snoopingaging-time : 300flood-unknown-multicast: disablequery-interval : 125FortiGate40F # diag switch-controller switch-info igmp-snooping groupS108F***********:IGMP-SNOOPING learned mcast-groups:port VLAN GROUP Age-timeout IGMP-VersionGT40F*** 20 querier 120 V2GT40F*
Hi all, We have a Fortigate 81F. Also have a Cradlepoint R920 router. I am trying to get the two connected via an ipsec tunnel. The Fortigate has a static public IP, R920 is on a mobile network with CGNAT. R920 is configured to initiate the connection. I see there is meant to be an option to set the Fortigate side to passive-mode but that command is not on our Fortigate (FortiOS 7.4) We have other site-to-site vpn connections to this Fortigate, using EdgeRouters but they have static public IPs. The Fortigate reports Phase 1 successful, but then both sides seem to be waiting for the other to respond. Here is an extract from the Fortigate debug log (I've replaced the IP addresses with place-holder names in bold):responder received AUTH msgprocessing notify type INITIAL_CONTACTprocessing notify type EAP_ONLY_AUTHENTICATIONprocessing notify type MESSAGE_ID_SYNC_SUPPORTEDpeer identifier IPV4_ADDR R920PUBLICIPre-validate gw IDgw validation OKauth ve
Currently, I am blacklisting IPs that trigger more than three unauthorized login attempts daily via the local access policy. This is causing issues where valid users are getting locked out and complaining about connectivity. Since switching to IPsec VPN would likely present the same challenge, I am considering whether we need to refine our filtering criteria or policy logic.
Hi Fortinet Community, Claude AI app is installed on a laptop and when it is launched I see this in the FortiGate logs. How can I check what block it and what should be allowed. Thanks in advance.
I am running FAZ 7.6.6 and have been scouring the internet looking to see if anybody has a solution for setting up an output profile to take and html or maybe even CSV report and putting it in the BODY of the email vs a file attachment.
what can I do? I'm just on the LAN that is connected to the Fortigate 40F.
Hello Everyone: We need to reset an FAP-234F-A to factory defaults because we don't have the admin password. Here are the details: 1. We have the unit connected to a FortiGate 40F, which has the default IP address of 192.168.1.99 for now while we set things up. The FAP-234F-A is set to 192.168.1.2 and we can ping it and browse to the GUI. 2. The QuickStart Guide for this unit says that it comes with a special POE injector that has a reset button on it because the AP doesn't. Probably because it's a ruggedized outdoor unit and having a reset button would compromise the ruggedness. The model number of the PO injector that shows in the QSG is EPA5006GPR-4P. It's made by EnGenius, but the only one they have is the EPA5006GR, so we bought that one. It has a reset button on it but pressing it for more than 10 seconds doesn't reset the AP to factory defaults. It does nothing. Probably because it's slightly different than the EPA5006GPR-4P and the pinout
We are attempting to install Forticlient 7.4.5 for our users. We are making the switch from SSLVPN LDAP authentication to IPSec using SAML authentication with Office 365. We are running into many issues using the Full EMS client listed below:Frequent Memory Leaks transitioning into a BSODWindows lock screen being a blank blue screen not allowing any user input and only able to be resolved via a restart.VPN Connection configuration completely dropping off of workstations while off the network. EMS claims remote access to be OK for these machines but only reinstalling or plugging the machine on our private network brings it back. I've had limited success trying to run a version of the client only utilizing the remote access but long term we are wanting to enable other components of EMS. My main question is whether anyone else has seen these issues now or in the past? If you have resolved them, what did you do? Happy to provide more detail
We have an existing Fortigate 7.4.11 firewall configuration with 100+ firewall policies and 10 VPN, IPSec connections and 2 WAN connections. We are wanting to now configure SDWAN to handle the 2 WAN Connections. Has anyone retrospectively added SDWAN to your existing config? We are looking for options.Current options seem like1. configure SDWAN and remove all references to the WAN interfaces (ie assigning those references to some other interface), then building SDWAN and reassigning to the zones. Pros: point and click Cons: take the network down for a bit while this configuration is being done and then troubleshoot issues2. dump the config, and integrate the changes, then try to import that new config into the fortigate Pros: seems quick, little downtime cons: seems like it will fail. 3. script the changes and dump those into the CLE Pros: seems quick, prone to errors cons: troubleshooting after it fails4. Building another
Hello, We are starting to patch our Fortinet devices. Several of them are configured in HA (FortiGate, FortiAuthenticator, FortiWeb, FortiADC, and FortiMail). In a critical scenario, we may need to restore the OS via TFTP on each node. In this case, should we take a separate backup from each HA member, or would restoring the HA backup on both devices be sufficient to fully recover the cluster configuration?
Hi All, new to the fortigate/FortiAP world so needing some help on a few issues We Have recently installed a new Wifi network into a school using the fortigate being used as a wireless lan controller and the APs are the FortiAP241k models. We are trying to connect a device which is a large touchscreen television to the network and it does not authenticate and can not connect to the wifi. The device is a promethean Active 9 device. We have tested the screen by connecting them to a personal hotspot and these work fine so it is just the fortigate Wifi it can not connect to. We have also tested plugging the devices directly into a switch port and these work fine this way also. Is there anything we need to do on the fortigate to make these connect to the wifi and is there anything that would be stopping these devices connecting. We have also tried to screen share from a laptop and an iPad to the screen when they are on the same network and this also does not w
Hi everyone,I am looking for some guidance on an issue I'm having with my Web Filter configuration. A specific betting/gambling website is still accessible to users, even though I have explicitly blocked it.Here is what I have configured so far:Blocked the Gambling category in the applied Web Filter profile.Added the specific website to the Static URL Filter with the action set to "Block". Any help or troubleshooting tips would be greatly appreciated!Thanks in advance.
In a custom dial-up VPN configurationWith ike v2 and mschap2 enabledI need to match users who connect to the VPN with their respective groups via radius attributes passed by Forti Authenticator.Currently, if I configure the IPSec tunnel with ike v1Xauth within the policies, it works.However, if I enable IKE v2, I connect to the VPN, and authentication works even with 2FA.Nevertheless, the user is not matched on Fortigate because I do not see them in the list:diagnose firewall auth listTherefore, the user is not associated with the remote radius group membership in Forti Authenticator.Is it possible to emulate the behavior of xauth while maintaining the relevant remote groups of Forti Authenticator within the policies, even with IKE v2?I would like to avoid creating x pahse1 interfaces for x groups on my Fauth that belong to two different LDAP servers.
Hi. Does anybody have an opinion about FortiGate appliances setup in a design where all routing is between sub-interfaces on the Fortilink interface? I call this a "FortiGate-on-a-Stick" design.I am considering the ISP connections for a new install consisting of three FS448E switches in a FortiLink design with two FG121G appliances in HA mode. I will use Vlan sub-interfaces on the FortiLink interface for two ISP DIA circuits as well as Vlans in my LAN.FortiGates-on-a-Stick design Is this a bad idea? Is FortiLink stable enough for this design to be reliable? Does FortiOS prefer to separate Inside and Outside on different physical interfaces for NAT and SDWAN features?
Maybe other users can take advantage of it, i've created a FortiWeb API Package, downloadable via PyPi "pip install fortiweb-api". Doc/Code on Github: https://github.com/thom-gyger/fortiweb_api.git. I also created an Fortiweb API Agent (MCP server ) to be used with an LLM. Github: https://github.com/thom-gyger/fortiweb_api_agent.git have fun, Thom#api #automation #ai FortiWeb
HelloIs it normal that FAC 6.6.9 has more known issues that 6.6.8, which in turn has more known issues thank 6.6.7, which in turn has more known issues than 6.6.6?From what I understand, normally each new patch should fix known issued from the previous version, right?
is there way to create script for Windows machines that would make the station to connect to cloud based EMS?There are articles about on prem EMS script that uses the IP of the EMS but in our case we have the EMS in Fortinet cloud and we use invitation code to connect. Sometimes it happens that the station disconnects from EMS and we would like to run the script from GPO to autoconnect to the station. https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-create-a-script-to-connect-Windows/ta-p/271163Any help appreciated.
Hello, we have two FS-424E-Fiber as core switches and two FG-90G as active/passive. As we don't have enough 10G ports, we can only connect each Forti with 1x10G + 1x1G to the two core switches via MCLAG. The problem is that the traffic should of course primarily run over the 10G connection, the 1G only as a passive backup. If I add both interfaces to the Fortilink and deactivate the FortiLink split interface, it is not guaranteed that the 10G connection is actively used.If I activate the FortiLink split interface, both are actively used. Is there a possibility that I have overlooked? Thanks and regardsBjörnar
Background: we've run out of 10gb ports on our switches and need to use on one the Fortigates.Was wondering if it's possible to bridge an existing Fortiswitch VLAN to one of the physical ports on the Fortigate.That way we can take advantage of the extra ports on the Fortigate.
Hello,The Per-Device pane in SSID(AP Manager) have very limited options on what you can set per Mapped Device.The case is that there is multiple location using same SSID name, call it "ABC", on location 1 this does not use IGMP Snooping, Multicast Enhancement and Fast BSS Transition, but on Location 2 these are enabled.Is this possible to do in FortiManager somehow without changing SSID Name? The reason this is wanted is to get multiple location in sync, but they don't necessary have the same settings.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.