Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello, I am currently trying to troubleshoot an issue where an external client cannot connect to an internal server. i have follow this documentation guide but I do not understand 100% the output of the #diagnose sys session list command: https://kb.fortinet.com/kb/documentLink.do?externalID=FD30042 FW (FW_VDOM_1) # diagnose sys session listsession info: proto=6 proto_state=01 duration=83 expire=3576 timeout=3600 flags=00000000 sockflag=00000000 sockport=0 av_idx=0 use=4 origin-shaper= reply-shaper= per_ip_shaper= class_id=0 ha_id=1 policy_dir=0 tunnel=/ vlan_cos=0/7 state=log may_dirty f00 statistic(bytes/packets/allow_err): org=3969/32/1 reply=16481/45/1 tuples=2 tx speed(Bps/kbps): 0/0 rx speed(Bps/kbps): 1/0 orgin->sink: org pre->post, reply pre->post dev=37->41/41->37 gwy=172.16.40.19/0.0.0.0 hook=pre dir=org act=dnat 81.63.141.211:53466->191.2.16.148:443(172.16.40.19:443) hook=post dir=reply act=snat 172.16.40.19:443->81.63.141.211
Has anyone else had this issue?
Hello All,I have 3 buildings, all in the same metro area, with a Fortigate pair managing 2 other building's Fortiswitch network over L2. With the following subset of my topology:Building1 FGT Pair > FSW PairBuilding1 FSW Pair > Building2 FSW Pair over an ISP wavelength fiber pairBuilding1 FSW Pair > Building3 FSW Pair over an ISP wavelength fiber pairBuilding2 FSW < UBNT P2P Radios > Building3 FSW (redundant link) I have a Ubiquiti P2P Wireless system in Buildings 2 and 3. I have the radios configured and setup between Buildings 2 and 3, with a strong link between the two. They tag their management traffic (GUI/setup of the radios) with a VLAN that does not interfere with anything fortilink-related, but they should pass any other L2 traffic across them transparently. Each Building's FSW Pair is a 1024E with an MCLAG-ICL between the two. Spanning Tree is the default Fortiswitch factory configuration (MST, 0 and 15 instances). Ideally, I'd like to get these
I have Windows domain environment, session helper is enabled. For normal active directory domain services it works fine. I also have CA server for auto enrollment, this does not work. I had to allow dynamic port range from clients to CA server for certificate auto enrolment. How can I enable this on Firewall to work over a single port?
Hi, i downloaded "FMG_VM64_HV-v7.6.6.M-build3654-FORTINET.out.hyperv", create a new VM in Hyper, create a Disk Drive and bind the extracted "fmg.vhd". Then i started the VM, open Browser and set my Login Details from FortiCloud Account. It looks "licensed" but the VM is noch listed in my Assets? can anybody tell me why? I see only my Trial FortiGate
Admin I need help to generate report on the demo link, I've been searching for some time now on how to generate report in FortiMail, but none of the documentation helps. I haven't configured any single thing, because I saw there's already a data on the demo, please guide me on how to generate a report in this FortiMail Demo, thanks.
Have set everything up as described in this article:https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-explicit-proxy-authentication-with/ta-p/206219 Have even tried it 3 times! everything is set up but, when I use a browser with the proxy address, (In Firefox) I get "the proxy server is refusing connections" if I change the Auth method and rules to simple LDAP, it works fine, I can log in and then browse, testing web filters etc. klist on the box im testing from:#5> Client: myusername@mydomain.netServer: LDAP/*****************KerbTicket Encryption Type: AETicket Flags 0x40a50000 -> forate name_canonicalizeStart Time: 2/2/2026 10:08:19End Time: 2/2/2026 20:08:19Renew Time: 2/9/2026 10:08:19Session Key Type: AES-256-CTS-Cache Flags: 0Kdc Called: ***************** have also recreated the keytab succesfully twice, I really thought this would be simple! LDAP connection is fine.. and tested. Any pointers please?
Hello,I bought an FGT 60E with firmware version 7.4.7. It is still registered with a reseller that I can’t contact, so I’m unable to register it on my account. It’s for testing purposes, but I would really like to update it to the latest firmware. Would anyone be able to provide it to me? Thank you very much, and sorry if I have broken a forum rule. Have a nice day.Julien
Hi everyoneIm using FAC as radius server for dot1x network access and with Unifi Access points as authenticator.the issue I'm having is that radius accounting messages I receive don't contain Supplicant IP address and all radius accounting messages are followed by this message : FortiAuthenticator rad_accounting [13775] [WARN]: [RX] Packet decode had attributes which it couldnt handle and skipped in packet from *.*.*.*:35947 Any guidance would be greatly appreciated
Hi. I really want to take NSE4 Exam but I really don’t know where to start. On my current role, we handle fortigates, like fw policy reviews, setting up NATs, IPSec VPN, SSL SVPN, etc. So basically my experience is more on the common needs of a enterprise network. I have this gut feeling that my knowledge is not enough. So can anyone advice me how should ai prepare?
We have a FortiWiFi-30G running FortiOS 7.4.8 managed by FortiManager 7.4.8.During configuration installation, FortiManager tries to push the following commands:config vpn ssl settings set banned-cipher SHA1 SHA256 SHA384 set servercert '' endAs a result, the installation fails with:install and save finished status=FAILEDThe command config vpn ssl settings does not exist on this model (only config vpn ssl client is available).FortiWiFi # config vpn ssl client Client. FortiWiFi # config vpn ssl setting command parse error before 'setting' Command fail. Return code 1Although the error doesn’t affect the running configuration, the device always stays in Conflict state, and automatic updates do not work.How can we remove or exclude this part (config vpn ssl settings) from the configuration template so that FortiManager stops trying to apply it?Verification report excerpt:---> generating verification report (vdom root: vpn ssl settings:banned-cipher) remote original: to
LS, I'm having the issue that login in to a switch using https give the following error messages in the Analyzer. "Administrator admin login failed from https(x.x.x.x) because of wrong time schedule."If I do this using ssh i will get the following error message. "Administrator admin login failed from https(x.x.x.x) because of invalid user name"I have reset the passwords using the fortimanager without errors and I'm able to login to 2 other switches attached to the same fortigate.ssh from on switch to the other does not work either.Fortigate is a 40F with 7.4.9 FortiOS.Fortiswitches are 124E and 124F with version 7.4.8 software. While writing this I just realize the 2 working units are the 124F and the failing one is the 124E unit.Failing means the login failing. otherwise the unit is fully operational and can be managed from the Fortimanager. Any ideas?Willem
Hi guys, Earlier I was able to connect to VPN but since past few days can't connect to the VPN and everything seems to be stuck. I have re-installed the app several times facing the same issue. My OS is Windows 11. I got the following error in GUI error log file-[2026-02-23 00:39:28.6618173 UTC+05:30] [8344:6856] [guimessenger 238 error] failed to open shared memory. GLE=2[2026-02-23 00:39:39.0909282 UTC+05:30] [8344:6856] [guimessenger 238 error] failed to open shared memory. GLE=2
SSL VPN was replaced to IPSEC on FGT version 7.6. I already configure IPSEC IKEv2 with EAP enabled.But why in forticlient android when select IKEv2 there is no field to enter the credentials?
Dear All, Unable to setup radius server with Windows server. Can you please confirm Is there any limitation for Fortigate permanent evolution license . I have put all my effort make reachablity with windows Server for Radius configuration . nothing worked. Please suggest me what should I do further. Make reachability with Server .
Good Afternoon ColleaguesI hope you are doing well . When trying to validated the license for FortiNet on FortiGuard , It takes long time and give message in snapshot 2. However when log to FortiCloud , The license has 56 days to expire. So kindly advice whether it has been activated/validated or not ? If not , What should be done to activate/validate it? Best Regards
I configured my FG (latest 7.2.x) to authenticate SSL-VPN users via SAML to Entra ID then map the security groups received via SAML "group" attribute to groups in the FG (remote SAML server, then using the object ID of the group). The groups were added into SSL-VPN settings to map to SSL-VPN portals. I configured 2 security groups in Entra ID (group 1 and group 2). 2 corresponding FG groups (group 1 and group 2). 2 corresponding SSL-VPN portals, and 2 corresponding firewall policies. The intention is if a user is a member of group 1, he will get policy 1 applied (e.g. allow SSH to 1.1.1.1). If a user is a member of group 2, he will get policy 2 applied (e.g. allow SSH to 1.1.1.2). If a user is a member of both groups, he should get both policies applied. However it seems for a member who is in both groups, FG is only receiving group membership for one of the groups (group 1 for 1.1.1.1). I checked the VPN logs and VPN user dashboard widget and saw group 1. Unfortuna
Hi,I'm officially losing after days of research and studies. The guide doesn't seem clear to me (or maybe I'm stupid enough to not get it).I'm designing 2 DCs following Fortinet's recommended design, the 1st has 2 EMS nodes, 2DBs and 1 witness. The other DC has 1 DB and 1 witness.what I learned so far: I need kind of load balancers, at the outside level (for requests coming from the outside) point on 2 different VIPs (DC1 and DC2), VIP of DC1 is pointing as well on both EMS servers there, DC 2 has only a single node but i'll use a VIP there as well for design purposes.in the inside, each fortigate (of each DC) has a VIP that includes its respective EMS nodes (LAN side)For local DNS, i'll need a load balancer here as well, so I can track the active EMS across both DCs (single FQDN, 2 IPs = 2 VIPs defined in the Fortigates; 1st VIP has both EMS nodes of DC1, and VIP of DC2 has EMS IP of DC2.is this understanding correct? do I still need the custom hostname though (i don't see how to use
Hi all,I’m running into a weird issue with our FortiGate 60F and could use some guidance. Here’s the context:We’re planning to shut down our on-prem DNS server and move some devices to use public DNS at one of our sites. The problem is that, even though all affected devices are on the same subnet/interface and show similar IP config, some are hitting the implicit deny policy while others are hitting my LAN-to-WAN policy.Here’s what I’ve observed. Devices that can’t reach public DNS can still browse the web using our on-prem DNS server. This server has conditional forwarders pointing to 8.8.8.8and 8.8.4.4. I have a firewall policy list as follows:LAN-to-Netsweeper – forwards all HTTP/HTTPS traffic to our web filtering provider.LAN-to-WAN – should catch everything else, including traffic from our internal interface 172.24.XX.XX/22.The problem is that, for devices on the same subnet:Some hit the LAN-to-WAN policy as expected.Some hit the implicit deny instead.I’ve also attached a screensh
Hi All,I have not done this setup but I need to configure it so I'm trying to understand what needs to be done.I have the below setup where a BBU is suppose to reach the Target IP but it doesn't.. I performed packet capture and sniffer to find out the below, 10.2.186.30 needs to reach Target over the 2 IPSec Tunnels.. 2026-02-18 14:05:59.077617 CORE in 10.2.186.30 -> 10.136.137.34: ip-proto-132 16 2026-02-18 14:05:59.077620 CORE in 10.2.186.30 -> 10.136.137.33: ip-proto-132 16 2026-02-18 14:05:59.077624 VDOMA-VDOMB0 out 10.2.186.30 -> 10.136.137.34: ip-proto-132 16 2026-02-18 14:05:59.077626 VDOMA-VDOMB0 out 10.2.186.30 -> 10.136.137.33: ip-proto-132 16 2026-02-18 14:05:59.077627 CORE in 10.2.186.30 -> 10.136.137.34: ip-proto-132 48 2026-02-18 14:05:59.077629 VDOMA-VDOMB1 in 10.2.186.30 -> 10.136.137.33: ip-proto-132 16 2026-02-18 14:05:59.077644 VDOMA-VDOMB0 out 10.2.186.30 -> 10.136.137.34: ip-proto-132 48 2026-02-18 14:05:59.0776
Dial Up IP Sec VPN using SAML authentication and Entra ID as IdP.External clients can connect to the VPN just fine.Internal clients cannot connect to the VPN. has anyone successfully setup IPSec VPN for internal clients?
Hi!Is it true, that when using winbind and PEAP, the only way to login to network is format DOMAIN\username.And username@domain.com doesn't work? Another related question: Is there a way to enforce plain username login to specific windbind domain?So client enters only username and password withoun domain info... BR, A
The vFSA appliance is deployed in IBM Cloud Classic (Dallas) in an active–passive configuration with only one public subnet IP currently assigned, and no additional public IPs available in the subnet. We have five web servers hosting different websites that must be externally accessible. In the absence of spare public IP addresses, we would like guidance on how to expose these services behind the firewall with separate public IPs. Please advise on the recommended architecture or configuration for this setup. If possible please share some links if there are any. Thanks
What are the Windows AD Service Account minimum privileges for the Fortinet SSO user account I must assign in the Windows Active Directory Domain Controller? Granting the overly privileged Domain Admins group to a service account is not permitted due to best practices and the security policies enforced by the security team.
Hello all , I’m a bit confused about the certificate-probe-failed error and would like to better understand why it happens and how to identify its root cause.We experienced denied traffic on the FortiGate firewall to smart.3CX.be:5001 due to a certificate probe failed error, with the following message:"SSL connection is blocked due to unable to retrieve server’s certificate.”(certificate-probe-failed) As the default behavior for CERT probe failed is block so the traffic is blocked.It's strange for me as the issue occurred yesterday, where the traffic was consistently blocked by the firewall. However, today the traffic started passing successfully, and the service is working as expected without any changes made on the firewall side. does anyone have any idea about that ?note : I use default Certificate inspection profile with flow mode .
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.