Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi all, We have a Fortigate 81F. Also have a Cradlepoint R920 router. I am trying to get the two connected via an ipsec tunnel. The Fortigate has a static public IP, R920 is on a mobile network with CGNAT. R920 is configured to initiate the connection. I see there is meant to be an option to set the Fortigate side to passive-mode but that command is not on our Fortigate (FortiOS 7.4) We have other site-to-site vpn connections to this Fortigate, using EdgeRouters but they have static public IPs. The Fortigate reports Phase 1 successful, but then both sides seem to be waiting for the other to respond. Here is an extract from the Fortigate debug log (I've replaced the IP addresses with place-holder names in bold):responder received AUTH msgprocessing notify type INITIAL_CONTACTprocessing notify type EAP_ONLY_AUTHENTICATIONprocessing notify type MESSAGE_ID_SYNC_SUPPORTEDpeer identifier IPV4_ADDR R920PUBLICIPre-validate gw IDgw validation OKauth ve
Currently, I am blacklisting IPs that trigger more than three unauthorized login attempts daily via the local access policy. This is causing issues where valid users are getting locked out and complaining about connectivity. Since switching to IPsec VPN would likely present the same challenge, I am considering whether we need to refine our filtering criteria or policy logic.
Hi Fortinet Community, Claude AI app is installed on a laptop and when it is launched I see this in the FortiGate logs. How can I check what block it and what should be allowed. Thanks in advance.
I am running FAZ 7.6.6 and have been scouring the internet looking to see if anybody has a solution for setting up an output profile to take and html or maybe even CSV report and putting it in the BODY of the email vs a file attachment.
what can I do? I'm just on the LAN that is connected to the Fortigate 40F.
Hello Everyone: We need to reset an FAP-234F-A to factory defaults because we don't have the admin password. Here are the details: 1. We have the unit connected to a FortiGate 40F, which has the default IP address of 192.168.1.99 for now while we set things up. The FAP-234F-A is set to 192.168.1.2 and we can ping it and browse to the GUI. 2. The QuickStart Guide for this unit says that it comes with a special POE injector that has a reset button on it because the AP doesn't. Probably because it's a ruggedized outdoor unit and having a reset button would compromise the ruggedness. The model number of the PO injector that shows in the QSG is EPA5006GPR-4P. It's made by EnGenius, but the only one they have is the EPA5006GR, so we bought that one. It has a reset button on it but pressing it for more than 10 seconds doesn't reset the AP to factory defaults. It does nothing. Probably because it's slightly different than the EPA5006GPR-4P and the pinout
We are attempting to install Forticlient 7.4.5 for our users. We are making the switch from SSLVPN LDAP authentication to IPSec using SAML authentication with Office 365. We are running into many issues using the Full EMS client listed below:Frequent Memory Leaks transitioning into a BSODWindows lock screen being a blank blue screen not allowing any user input and only able to be resolved via a restart.VPN Connection configuration completely dropping off of workstations while off the network. EMS claims remote access to be OK for these machines but only reinstalling or plugging the machine on our private network brings it back. I've had limited success trying to run a version of the client only utilizing the remote access but long term we are wanting to enable other components of EMS. My main question is whether anyone else has seen these issues now or in the past? If you have resolved them, what did you do? Happy to provide more detail
We have an existing Fortigate 7.4.11 firewall configuration with 100+ firewall policies and 10 VPN, IPSec connections and 2 WAN connections. We are wanting to now configure SDWAN to handle the 2 WAN Connections. Has anyone retrospectively added SDWAN to your existing config? We are looking for options.Current options seem like1. configure SDWAN and remove all references to the WAN interfaces (ie assigning those references to some other interface), then building SDWAN and reassigning to the zones. Pros: point and click Cons: take the network down for a bit while this configuration is being done and then troubleshoot issues2. dump the config, and integrate the changes, then try to import that new config into the fortigate Pros: seems quick, little downtime cons: seems like it will fail. 3. script the changes and dump those into the CLE Pros: seems quick, prone to errors cons: troubleshooting after it fails4. Building another
Hello, We are starting to patch our Fortinet devices. Several of them are configured in HA (FortiGate, FortiAuthenticator, FortiWeb, FortiADC, and FortiMail). In a critical scenario, we may need to restore the OS via TFTP on each node. In this case, should we take a separate backup from each HA member, or would restoring the HA backup on both devices be sufficient to fully recover the cluster configuration?
Hi All, new to the fortigate/FortiAP world so needing some help on a few issues We Have recently installed a new Wifi network into a school using the fortigate being used as a wireless lan controller and the APs are the FortiAP241k models. We are trying to connect a device which is a large touchscreen television to the network and it does not authenticate and can not connect to the wifi. The device is a promethean Active 9 device. We have tested the screen by connecting them to a personal hotspot and these work fine so it is just the fortigate Wifi it can not connect to. We have also tested plugging the devices directly into a switch port and these work fine this way also. Is there anything we need to do on the fortigate to make these connect to the wifi and is there anything that would be stopping these devices connecting. We have also tried to screen share from a laptop and an iPad to the screen when they are on the same network and this also does not w
Hi everyone,I am looking for some guidance on an issue I'm having with my Web Filter configuration. A specific betting/gambling website is still accessible to users, even though I have explicitly blocked it.Here is what I have configured so far:Blocked the Gambling category in the applied Web Filter profile.Added the specific website to the Static URL Filter with the action set to "Block". Any help or troubleshooting tips would be greatly appreciated!Thanks in advance.
In a custom dial-up VPN configurationWith ike v2 and mschap2 enabledI need to match users who connect to the VPN with their respective groups via radius attributes passed by Forti Authenticator.Currently, if I configure the IPSec tunnel with ike v1Xauth within the policies, it works.However, if I enable IKE v2, I connect to the VPN, and authentication works even with 2FA.Nevertheless, the user is not matched on Fortigate because I do not see them in the list:diagnose firewall auth listTherefore, the user is not associated with the remote radius group membership in Forti Authenticator.Is it possible to emulate the behavior of xauth while maintaining the relevant remote groups of Forti Authenticator within the policies, even with IKE v2?I would like to avoid creating x pahse1 interfaces for x groups on my Fauth that belong to two different LDAP servers.
Hi. Does anybody have an opinion about FortiGate appliances setup in a design where all routing is between sub-interfaces on the Fortilink interface? I call this a "FortiGate-on-a-Stick" design.I am considering the ISP connections for a new install consisting of three FS448E switches in a FortiLink design with two FG121G appliances in HA mode. I will use Vlan sub-interfaces on the FortiLink interface for two ISP DIA circuits as well as Vlans in my LAN.FortiGates-on-a-Stick design Is this a bad idea? Is FortiLink stable enough for this design to be reliable? Does FortiOS prefer to separate Inside and Outside on different physical interfaces for NAT and SDWAN features?
Maybe other users can take advantage of it, i've created a FortiWeb API Package, downloadable via PyPi "pip install fortiweb-api". Doc/Code on Github: https://github.com/thom-gyger/fortiweb_api.git. I also created an Fortiweb API Agent (MCP server ) to be used with an LLM. Github: https://github.com/thom-gyger/fortiweb_api_agent.git have fun, Thom#api #automation #ai FortiWeb
HelloIs it normal that FAC 6.6.9 has more known issues that 6.6.8, which in turn has more known issues thank 6.6.7, which in turn has more known issues than 6.6.6?From what I understand, normally each new patch should fix known issued from the previous version, right?
is there way to create script for Windows machines that would make the station to connect to cloud based EMS?There are articles about on prem EMS script that uses the IP of the EMS but in our case we have the EMS in Fortinet cloud and we use invitation code to connect. Sometimes it happens that the station disconnects from EMS and we would like to run the script from GPO to autoconnect to the station. https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-create-a-script-to-connect-Windows/ta-p/271163Any help appreciated.
Hello, we have two FS-424E-Fiber as core switches and two FG-90G as active/passive. As we don't have enough 10G ports, we can only connect each Forti with 1x10G + 1x1G to the two core switches via MCLAG. The problem is that the traffic should of course primarily run over the 10G connection, the 1G only as a passive backup. If I add both interfaces to the Fortilink and deactivate the FortiLink split interface, it is not guaranteed that the 10G connection is actively used.If I activate the FortiLink split interface, both are actively used. Is there a possibility that I have overlooked? Thanks and regardsBjörnar
Background: we've run out of 10gb ports on our switches and need to use on one the Fortigates.Was wondering if it's possible to bridge an existing Fortiswitch VLAN to one of the physical ports on the Fortigate.That way we can take advantage of the extra ports on the Fortigate.
Hello,The Per-Device pane in SSID(AP Manager) have very limited options on what you can set per Mapped Device.The case is that there is multiple location using same SSID name, call it "ABC", on location 1 this does not use IGMP Snooping, Multicast Enhancement and Fast BSS Transition, but on Location 2 these are enabled.Is this possible to do in FortiManager somehow without changing SSID Name? The reason this is wanted is to get multiple location in sync, but they don't necessary have the same settings.
Hi,We are moving to a new ISP, and they have provided us with WAN and LAN network blocks. Normally when we order a new circuit, we get one block with however many available IPs we need.From what I can tell, the WAN block gets configured in our WAN interface(tested this, verified working), and we pick out a LAN IP from our LAN block to use for our VIPs.Is this correct? It sounds like the ISP routes the LAN block to our WAN block if i am understanding this correctly.
Hello everyone,Have you ever used Forticonverter Free?https://docs.fortinet.com/document/forticonverter-service/25.1.0/online-help/724941/get-free-license-for-fortigate-conversionIs it reliable?Are there any account limitations?
Recently we noticed the particular firewall traffic received a huge receive date. Is it possible for a single traffic to send around 30 GB of data?
Hello, after my last Fortimanager Upgrade Source and Destination in Firewall Policy rules only show a few entries, to show all i have to mouseover a "+" character/symbol.This is good for a better first overview, but from time to time a need a screenshot of some definitions, in this case it is anoying since i have no possibility to capture all Hosts/Services/...Is there a way to make it work like in older Fortimanager versions??
When migrating configurations from one firewall to another, do the certificates have to be signed again?
When i try to use the latest version on my Windows 11 Machine or macOS Tahoe machine The FortiClient returns SSL VPN Connection is down, or login failed, access denied I changed the password many times, but the same issue persists.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.