Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Dears, I am currently facing an issue while attempting to add a FortiGate VM to FortiManager in my lab environment (EVE-NG).During the probe process, I receive the following error:"FGFMs(probing...): serial number (FGVMEVRAKOOY7JB3) in 'get' message doesn't match the subject CN (FortiGate) in peer's certificate."Based on initial troubleshooting, this appears to be a mismatch between the FortiGate serial number and the certificate CN presented during FGFM communication.Could you please advise on the recommended approach to resolve this issue in FortiManager 7.4.10, particularly in a virtual lab environment?Your support is highly appreciated.
Hi Everyone.I have been blocking malicious domain and ip using firewall policy. Recently I configured external threatfeed for ip but couldn't figure out how to do it for domains. My requirement is to call domains in source and destination of the policy for blocking.Is there any way I can do it??
Hi,we have problems to register the trial license for the FortiAnalyzer VM.The device is registered in our assets. But when I try to registered it in FortiCare during initial setup it fails with the error "The product serial number has already been registered". I found out, the the FortiAnalyzer has problem with the connection to server usfds1.fortinet.com.We must use a web-proxy within the company network. Our Fortigates working fine with it but not the FortiAnalyzer. DNS is working correctly.Web-Proxy is set up and the VM is permit in the firewall to communicate with it.The date/time is correct.I also uploaded the license manual.And any other connection seems to be working. Any Idea to solve the problem.
Hi Fortinet Community,We manage FortiGate firewalls for one of our customers with a multi-site setup consisting of one Main Plant and four Branch Plants. In the Main Plant and two of the Branch Plants, there is an additional isolated/internal FortiGate used only for internal communications.RequirementWe need to generate a historical bandwidth utilization report for traffic from one specific Branch Plant to the Main Plant, passing through a VRF interface, for the below specific date/time windows.Required Time Ranges27 January 2026: 9:15 AM – 9:45 AM28 January 2026: 9:20 AM – 9:40 AMTraffic DetailsTraffic Path: Branch Plant → Main PlantConnectivity: Site-to-site IPsec tunnel, running over a VRF interface (specific interface)Reporting Scope: Bandwidth utilization for the specific VRF/interface and IPsec tunnel traffic between these two sitesTools Available: FortiGate + FortiAnalyzer (logs are available in FortiAnalyzer)Output ExpectedWe are looking for a report that includes:Inbound and o
I have my first user trying to connect with her brand new Macbook (home machine) to our Fortigate SSL-VPN. I have a couple dozen Windows users (home machine) connecting in successfully. She gets through I think to the 98% level, then gets an error: Connection error. Can not connect to VPN server. When I look on the Fortigate VPN log, I don't see anything referencing this user. Any help would be greatly appreciated.
Hi everyone, Does anyone already encountered this error "Incorrect certificate file format for CA/LOCAL/CRL/REMOTE cert." when uploading CA root certificate to fortigate? Certificate is from may lab setup Win Svr 2019 as AD/DNS with enterprise root security authority service installed.I'm running 6.2.7 fortigate version. What I'm trying to achieve is to authenticate thru LDAP server my ssl vpn users thru a secure connection. I'm just wondering since I already achieved it on latest fortigate version 7.0 smoothly without errors. Am I missing something or any compatibility issues with 6.2.7 versions? Appreciated much your advises and feedback, what causing the error, I'm kinda stock to it. Thank you.
Hello Fortinet team,Could you please help me with my question? I need to configure SD-WAN on a FortiGate, as we have two active WAN links. The goal is for one to function as the primary link and the other as a backup, so that if the primary link goes down, the secondary link automatically assumes internet connectivity. Currently, we have the following configured on the firewall: SSL VPNSite-to-Site VPN (IPsec) Both configurations are associated with the primary WAN. My questions are as follows: SSL VPN: What configuration should be implemented so that, in case of a WAN1 failure, the SSL VPN service automatically switches to WAN2?Considering that the clients have configured their agents with the remote gateway corresponding to the public IP address of the primary WAN. Site-to-Site VPN (IPsec): In this case, the remote devices are pointing to the public IP address of the primary WAN1.What would be the best practice to ensure automatic failover to WAN2 i
Hi Guys, I´m looking for a solution for IPv4 and IPv6 traffic via IPSec that only allows certain clients. (Interfaces are WLAN, LAN or LTE) The prefered soulution is that I can filter the clients with there MAC addresses. I tried it once with this guide: https://docs.fortinet.com/document/fortigate/6.2.0/new-features/485133/mac-address-based-policies But here I cant get a simple ping through the tunnel if I have address group with the mac. (i dont blacklist or something like that) What do I have to do to get this working? (for IPv4 and IPv6)
Hi team,I'm working directly on my Serveur. On this serveur, we deployed a web solution for others users in my office. Sometimes, I need to access to customers's serveurs and I'm using FortiClient 5.4.3.0870 for that.During the remote connection, my Serveur is inacessible for others users in my office ; that means they can't working.This situation didn't exist before we changed the Server's position. (We moved it from building A to building B). I'm not pretty sure this is cause by Forticlient.Do you have some idea? Any helps is welcome.Thanks in advance.Regards**************Bonjour l'équipe, Je travaille directement sur mon Serveur. Sur ce serveur, nous avons déployé une solution web pour les autres utilisateurs de mon bureau. Parfois, j'ai besoin d'accéder aux serveurs des clients et j'utilise FortiClient 5.4.3.0870 pour cela. Lors de la connexion à distance, mon Serveur est inaccessible pour les autres utilisateurs de mon bureau ; cela signifie qu'ils ne peuvent p
When configuring remote_sites.txt for Azure Virtual WAN, the sample file format doesn't seem to make sense.I was wondering where can I get additional info?
Hello. I am trying to figure out how fortinet stuff works, and it seems like it's tied up to the cloud. It looks like I have to get my fortigate unclaimed before I can use it. Is that correct? I haven't found anywhere to put the serial number into, to check warranty status and if it's claimed. When I enter the SN into the forticloud I get this:Invalid input data:Please double-check the Fortinet appliance registration number you typed in. If your input is correct and the problem persists, please submit a customer service ticket. It is the 100% correct SN I am using. Could this mean my 101F has been claimed and is unusable? Thanks!
Hi, I'm new and this is my first post.I'm currently configuring ZTNA, but I have problems I'm not able to solve. I want to connect to a SQL DB via TOAD GUI.Therefore I changed the SQL instance port from dynamic to fixed (Port 6434). Is there any other port next to may be 1433 and 1434 I need to enable in my ZTNA Server on the Fortigate?
Hi all,just wanted to check about flow-based vs proxy-based web-filter options.Is it similar to flow based vs proxy based inspection modes or something different.
I'm wanting to know the actually future replacements for the E & F series FG if possible, please. From some research the 100E for example can be replaced by the F series (80F & 100F), however some of the F series are also listed as EOL, whats to say these aren't any time soon. My question is: What is the long-term replacement please? Thanks in advance. CD
Hi there, I have configured Remote access Ipsec vpn with forticlient (IPsec Wizard) and I want to implement following best practice. 1. Client must get static IP address (not clients get the IP address from DHCP Pool)OrCan I bind static IP address to Users statically . 2. If Client is not performing any activity within 5 min or 10 min or more, Connection automatically should be disconnected. ( When Client is idle condition) 3. At a time only one user can login the VPN with his/her username. for example - test user only can login from one machine, not multiple machine. 4. Can I bind static mac address of the Client machine with user name or IP address. 5. MFA - I have checked it is working fine for me. 6. Can I create two/more separate group and assign different subnet. Thank you for support.
Until last week, our firewall indicated 7.4.11 as the mature release; however, as of today, I've observed it displaying 7.4.9 as the mature release. Furthermore, I am unable to locate these specific versions within the upgrade path. I am inquiring if anyone else is experiencing a similar issue. I have already initiated a TAC case to gather additional information regarding this matter.
Hi everyone I’m experiencing very high latency when FortiClient connects to EMS Cloud over a dial-up IPsec tunnel. The latency is noticeable even with basic tests, for both internal and external traffic.So far, I have disabled UTM/inspection on the related firewall policies and verified MTU settings on both EMS and the FortiGate. EMS is using the default MTU (1280), and there are no custom MTU settings configured on the FortiGate.
Hello all,I wanted to know if any debug commands to check traffic is getting dropped from which security profile. I know the debug command to check traffic is hitting which policy. I wanted to know the debug command for security profile and any cli commands to check security profile logs.
Hi dear community, I am deploying fortiwaf 600F, traffic logs enabled in waf through this command , but logs are not showing, i need to check traffic and create policies. In Firewall Policies option its dont have log session check available like fortigate firewalls. Hard disk is available and space is also free. I previously only upgraded firmware to FortiWeb-600F 8.0.2 build 0060 (GA.F),250304 firmware version config log traffic-log set status enableend .Furthermore packet log also enabled. Needs your complete guide line to resolve this issue. WAF is deployed in Reverse Proxy mode.
We recently moved to 7.4.X, and one complaint we have gotten multiple times now, is that there's no longer any indication next to the VPN connection of what user is being used. These VPN tunnels make use of SSO and has such it is not always immediately obvious what user is currently being used. Is this something that's gone for good on 7.4 or are we just missing a configuration?
Hello All, Just need some clarity on VPN connectivity between countries. I face random issue with SSL VPN while connecting from India to Italy. initially while connecting we get not reachable or not connecting and get stuck at 10% or 40%. After 2 to 3 attempts it works fine. As i understand there is no issue in VPN configs. Have you guys faced any such issues when trying to connect VPN. How do you troubleshoot this issues.
Hi Community, I would clearify, when enable "UEBA" feature, does it require install other FortiSIEM agent? as we already installed "FortiSIEM Log Agent" on servers (Window), our current version 7.4.x.x.Thanks for your respoonds.
StrongSwan IKEv2 VPN tunnel with X509 Authentication - helpI am doing a proof of concept, trying to get a router with StrongSwan embedded in it, for a Site-to-Site IKEv2 VPN tunnel back to HQ, using certificate authentication. The remote side (router) has a dynamic IP address. At the HQ side, the tunnel is configured as a dynamic/dialup tunnel. If we can make it work, there will be about 200 more just like it later. If I use PSK, the tunnel comes up and stays up, so connectivity between the remote site and HQ appear to be good. If I use X509, the tunnel comes up for about 10 seconds, I see the phase 2 up in the IPSec monitor and the route gets installed on the Fortinet/HQ side, and then there is a failure (on the StrongSWAN side) with the logs with error message "certificate status is not available" and something about not being able to reach the CRL or OCSP servers, with a timeout of 10000ms (which lines up with the tunnel coming up for 10 seconds). The
Hi, we have FG200F with new OS and SD WAN Rule for our Sharepoint sites. This worked fine until maybe last year october when we got the first users with saving problems, access problems, etc. Users are not allowed to use OneDrive, they download Word files from our xxx.sharepoint.com and work with OFC. Since we know that MS made some changes we are looking for internet access problems with the FG200F. First we created a SD WAN rule with destination Micrsosoft all services using ourt best internet access interface A. Also we deleted all UTM features on the policy but we still have problems. I checked and all sessions to the sharepoint sites use interface A. I am not so sure, that we get a solution on the FG and that it more a client problem but any ideas what else we can try?Thanks!
Hi there, I'm having issue in a lab (build by me) that i've created with trial version of FortiGate VMs (x2), FortiManager (x1) and FortiAnalyzer (x1).I've added two FortiGates to the FortiManager, and everything was working without issues, untill the first device installation.The FortiManager keeps showing error in the installation of device configuration, after digging around, i found out that the issue occurs because of the "set banned-cipher" command. This command seems to be not available in the trial fortivm, and in the FortiManager I wasn't able to remove the setting from the CLI configuration (because it requires at least 1 cipher that has to be banned).The running versions of the devices are;FortiGate VMs KVM 7.4.4 build 2662 (Feature)FortiManager v7.4.3-build2487 240514 (GA)FortiAnalyzer (while it doesn't have to do with the issue) v7.4.3-build2487 240514 (GA) When i deselect the banned-cipher and click apply (in the CLI configuration of the device) the ci
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.