User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello guys, I would like to understand whether anyone has experienced a similar issue and, if possible, identify the root cause.I recently performed a migration from a pair of FortiGate 501E devices to a pair of FortiGate 401F devices. Both the FortiGates and FortiManager were running version 7.4.11.The firewalls being migrated were the central hub of our entire infrastructure.They were managed by FortiManager and used SD-WAN Templates extensively.In addition, they were acting as the VPN hub through VPN Manager, with approximately 100 remote FortiGate devices connected to them.To prepare for the migration, I brought the new 401F devices online and initially configured only the primary unit.At that stage, the two new firewalls were not yet configured in an HA cluster.I imported the complete configuration from the old 501E and assigned the new device to the existing SD-WAN template in FortiManager.The only step I intentionally postponed until the migration day was adding the new firewall
I have a Fortigate FGT200F running 7.4.11.It has a large number of physical connections that I’d like to rationalize down to VLAN interfaces on a trunk of multiple 10G lines. As such, the “names” of many of my networks are going to change from “portx” to “some-name-I-pick”. This has follow-on consequences for firewall objects and policies. Naturally, I don’t really want to delete all my policies and objects to get this done.Many of the objects are tied to associated-interfaces. To ease the migration, I tried as a first step to reconfigure the objects by removing the “set associated-interface” command from each object in a backup of the config, then restoring the altered backup.The firewall accepted the altered configuration and booted, however it permitted no traffic to traverse any policies while in this state. During this time it logged errors such asaction="connect" status="failure" reason="SSL accept failed" msg="40B84138E57F0000:error:0A000416:SSL routines:ssl3_read_bytes:ssl/tls
Hello everyone! I'm looking for a way to make FortiClient (the free one, VPN only) save user password. When I fresh install FortiClient VPN (7.4.3 hotfix 1.8758), this checkbox is not present at all. I've read some manuals on XML configs and found configuration parameters that make this checkbox visible. I craft a .conf file with the parameters, import it, the checkbox I wanted is present, but once my connection is establishsed, the utility goes to tray, and then I untray it back (a lock sign in the top right corner is present even if I turned it off before), I break the connection I've just established, and all the checkboxes are gone from GUI.What am I doing wrong and how to fix it? It's just really frustrating to re-enter my password everytime. Any help is appreciated. Thanks in advance!
So i m doing a demo for a project i m doing for a client and i activated the free trial doe 200f series fortigate that work as HAtransfered the assets into another forticlould account but the ems free trial is still on the older accountCan anyome help me with this please an is the free trial can be activated just once even if i move the fortigateCan i remove the trial from the old account and activate on the new oneAny help is apperciated because i m stuck now and been ike this for 2 days
Hello everyone,I am currently working on a production firewall migration from a FortiGate 500D (FortiOS 5.6.x) to a FortiGate 1000F (FortiOS 7.6.x).After migrating the configuration, we are facing an issue where public traffic reaches the FortiGate 1000F but does not reach the internal server. If we reconnect the old FortiGate 500D with the same network topology, everything works normally.EnvironmentSource firewall: FortiGate 500D (FortiOS 5.6.4) Target firewall: FortiGate 1000F (FortiOS 7.6.6) Same public IP addresses Same ISPs Same internal servers BGP is used for routing VIPs are used for inbound servicesWhat has already been verifiedWe have carefully compared the configurations of both firewalls and checked the following:VIP configuration Firewall policies Address objects and address groups Static routes BGP routing Interface mapping Central NAT and Policy NAT Security policies Traffic logs diagnose debug flow Routing tableWe also disabled Central NAT and tested Policy NAT, but the
So for whatever reason on new devices that we have set up the past couple of months we cannot seem to connect to our VPN at all on these new devices. However, the older devices seemingly have no issue. We have tried reinstalling the C++ libraries, reinstalling FortiClient, and updating the NIC driver but have had no luck. All of these new devices are running Windows 11 Pro 24H2 and its a mix of 2 Dell Latitude laptops and one Microsoft Surface Pro 9 if that helps with anything. Also tried looking for some of the older versions on the support page but we don't have the firewall tied to our account so it doesn't let us search through the download page. I have tried version 5.4.3.0870 of FortiClient that we had saved but that didn't work either although I am not sure if that version is Windows 11 compatible or not. Not sure where to go from here any help is appreciated!
Hi everyone,I’m trying to understand whether there is a way to log some TLS/SSL handshake information when using an SSL/SSH profile configured with Certificate Inspection, rather than Full/Deep Inspection.I tested the following settings:set ssl-handshake-log enableset ssl-server-cert-log enableset ssl-negotiation-log enablebut, from my tests, these logs seem to be generated only when the SSL/SSH profile is configured for Full/Deep Inspection.What I would specifically like to retrieve, even when using Certificate Inspection, is information such as:the SNI (Server Name Indication) sent by the client; the negotiated TLS version; ideally, other basic TLS handshake metadata that FortiGate can observe without decrypting the session.Since SNI and TLS version are available during the handshake and do not necessarily require payload decryption, it would be very useful to have them available in the traffic/SSL logs also with Certificate Inspection.Thanks in advance for any suggestions or clarifi
Hi, I need to ask regarding default configuration for FortiClient EMS. In FortiClient EMS 7.2.12 did the “Let EMS schedule automatic upgrade” option under menu System Settings > EMS Settings is enabled by default?I don’t think that I explicitly enabled this option, but I received notification EMS upgrade is available and the scheduled upgrade also has been set.From the following documentation, there is no information that automatic upgrade option is enabled by default.https://docs.fortinet.com/document/forticlient/7.2.13/ems-administration-guide/371397
Hello,I have a FortiGate with two WAN connections, and I am trying to establish two separate site-to-site IPsec tunnels to the same 3rd-party firewall.The design as below;Currently, I have the following issue:IPsec Tunnel 1 over WAN-A → Established IPsec Tunnel 2 over WAN-B → Not Established The same remote peer IP is used for both tunnels.My questions are:Is this design supported without any conflict when using two different WAN interfaces? Is there anything specific I need to configure on FortiGate when both tunnels use the same remote peer IP? Since Tunnel 1 is working but Tunnel 2 is not, what should I check first? Could this be caused by the ISP blocking IPsec/IKE traffic, especially UDP/500 or UDP/4500? What is the best way to verify whether the WAN-B ISP is blocking the IPsec traffic?I have already checked the FortiGate side and would appreciate any advice on what else I should investigate.Thank you.
What is the latest version of FSSO agent for Microsoft Server 2025 AD?We are planning to upgrade our AD to Server 2025 as the existing on is on Server 2016.what are the things we need to take note of
Hi all, We don't have EMS and I've managed to push out a new IPSEC connection to the machines via group policy but obviously as the pre-shared key is encrypted it then creates a random one on each machine so has anyone found a way to do this using group policy at all. We are using the free VPN from Fortinet and not the Windows native one.Thanks
Fortinet TAC has also reviewed the case and confirmed that they cannot see any SMTP traffic leaving the FortiGate.At this point, it appears that the email notification process is never invoked even though authentication reaches the "Token is needed" stage.Hi everyone,I am facing a very strange issue on a FortiGate 601E running FortiOS 7.4.12 (build 2902).Environment- FortiGate 601E- FortiOS v7.4.12 GA build 2902- Multi-VDOM enabled- Root VDOM hosts the SSL VPN- SSL VPN authentication uses Local User + Email-based Two-Factor AuthenticationSymptomsThe SSL VPN login works normally.After entering the username and password, the SSL VPN client displays:"An email message containing a Token Code will be sent..."The System Event log also records:"Send two-factor authentication token code"However, the user never receives the email.What makes this strange is that FortiGate never attempts to establish any SMTP connection.Troubleshooting performed✓ Local user configured with:set two-factor email✓ E
Hello everyone,We’re currently preparing to deploy a larger FortiSwitch environment and are discussing the best way to get started with Dynamic Port Policies.The environment consists of two FortiSwitch 2048F switches as the core and about 20 access switches. The access switches will connect primarily standard clients, printers, Swyx DECT base stations, Raspberry Pi systems, a total of about 40 FortiAPs, and other IoT Devices. However, the APs are distributed very unevenly across the access switches—some have no APs, while others have five, for example.Currently, network segmentation is still very straightforward. The majority of the servers, clients, printers, etc., are still all located within the same network 172.16.0.0/16. Although there is already an organizational address allocation within this network—for example, servers are primarily in 172.16.0.x and clients starting at 172.16.100.x—technically, it is still the same network.A few true VLANs already exist, for example, for Wi-F
so i just got a free ems cloud license using my fortigate cloud and it gave me 3 endpoint i was asking if i transfere the fgt to another account do i lose the trial license or not or could i just activate it again i hope someone have a clear answer i m doing a demo for a client any help is appreciat
Greetings,Looking for advice on best way to migrate from current Palo Alto in Azure to FortiGate.Can it be deployed into the same subnets, or does it need to be in new subnets same vnet?Thanks!-Greg
So how are we all doing SSO user authentication on InTune/Entra joined clients going through an on-prem Fortigate?For many years we've been using the DC SSO agent to authenticate users on domain-joined devices, but now with clients moving away from local AD and so no longer domain-joined so not authenticating on the on-prem DC, this obviously makes the DC agent redundant.I'd rather avoid a captive portal if possible since that's a bit of a step backwards from the nice slick SSO solution we're used to, so what's the most elegant way to do SSO authentication to an Entra 365 account?
Hi,Has anyone else experienced traffic issues with FortiOS 7.6.6 on hardware models other than the 201G?On our 201G, we experienced delays and random disconnections, and Support recommended setting no-acceleration on the specific policies where the issue occurred.We are planning to deploy the 701G soon, so I would like to understand whether similar issues have been reported on other hardware models as well, especially the 700G/701G.
We're building a cryptographic-discovery capability that ingests firewall SSL/TLS-inspection logs. The device is a FortiGate 90G (we don't have the exact FortiOS version yet, so please note any version dependencies).Could you confirm:With SSL/SSH inspection enabled, what cryptographic detail do the UTM/SSL logs contain — TLS version, negotiated cipher, key-exchange protocol/curve, auth/signature algorithm, and server-certificate details (subject, issuer, validity, fingerprint, key alg/size)? Which FortiOS version is required for the full SSL certificate/handshake/negotiation logging (the ssl-server-cert-log / ssl-handshake-log / ssl-negotiation-log options)? Do the logged fields differ between certificate inspection (no decryption) and deep inspection, and what is logged for TLS 1.3? Export options for these logs — syslog (JSON/CEF), FortiAnalyzer, and any REST API for pulling logs — plus the field names/format so we can parse them.A sample log line or a link to the field reference wou
I add Fortigate to the Fortinac and why i get below event? Actually the Fortinac connect to the Fortigate using SSH and not telnet.
I've noticed an extremely strange thing upon upgrading some test FortiGates to the new version 7.6.7: the upgrade goes fine, and the FortiGate is happily online and is routing/firewalling-just fine. However, when trying to load the GUI it is just a blank page.I can see the little favicon loading for the FortiGate login page, but its just blank otherwise. I can SSH in just fine, so that is good. I do not see any settings reset in global settings, and strangely going to the http login instead of https sometimes works (I have https redirect turned on).As the FortiGate seems to be perfectly fine otherwise, I thought I'd see if anyone else has experienced this?Also I have tried multiple browsers with privacy/incognito mode on, so I don't think it is a cache issue.
Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.Am I missing something in t
Hi All, VersionFortiGate-81F v7.4.8,build9191,260511 (FIPS-CC-74-8)FIPS-CC mode: enableFortiSwitch-148F-FPOE v7.4.8,build0929,250909 (GA)Security mode: none In our environment, Federal Information Processing Standards (FIPS) is required due to the contract we have. I have been running into the following issues while testing FIPS mode on our equipment.The FortiSwitches appear under Managed FortiSwitches. I can see the firmware version, status, and join time, but I cannot SSH into the switches from the GUI. It also does not show the Connecting From status or the switch IP address.Under FortiSwitch Ports, the port connecting the FortiGate and the FortiSwitch shows as down. When I assign a VLAN to a FortiSwitch port, the VLAN assignment is accepted, but it does not actually take effect on the connected device.However, from the FortiGate CLI, I can SSH into the switch without any issues. The switch status is visible, but it appears that the configuration is not being fully synchronized to t
I believe when we add the switch to the fnac for 1st time then fnac inventory will collect below data such as Name, Default Vlan, Current Vlan from the switch. When we have changes on the switch, example i make port description and change the default vlan then why in the fnac is not updated? Resync the interface is not helping
Hello, I would like to clarify the expected FortiGate behavior when a FortiGuard/UTM license expires. Our FortiGate 81F had a UTM contract that expired on August 6, 2026. A new license contract was purchased/renewed on Friday, but the new contract has not yet been activated. After the previous contract expired, Internet traffic through one of our existing firewall policies was blocked. Basic websites could not be accessed. The affected firewall policy had the following security profiles enabled: - AntiVirus - Web Filter - DNS Filter - Application Control - IPS - File Filter When we disabled these security profiles, Internet connectivity immediately returned to normal. Fortinet Customer Service stated in the support ticket: “internet connectivity will not be affected due to the absence of a license.” They also stated that basic firewall policies that do not rely on subscription-based security services should continue to function. Therefore, I would like to understand the technical behav
Hello, I am able to configure OSPF over IPSec tunnel, but: - I have another OSPF interface (through a physical interface) with lower cost that is Up and routes in the routing table are using this preferred link with correct cost.- When the IPSec tunnel comes Up, the routing table is modified; routes are now using the IPSec interface although I have defined a higher cost for the VPN interface... looks like something is forced. Has anyone come across a similar situation? Thanks, Monty.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.