Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
When configuring remote_sites.txt for Azure Virtual WAN, the sample file format doesn't seem to make sense.I was wondering where can I get additional info?
Hello. I am trying to figure out how fortinet stuff works, and it seems like it's tied up to the cloud. It looks like I have to get my fortigate unclaimed before I can use it. Is that correct? I haven't found anywhere to put the serial number into, to check warranty status and if it's claimed. When I enter the SN into the forticloud I get this:Invalid input data:Please double-check the Fortinet appliance registration number you typed in. If your input is correct and the problem persists, please submit a customer service ticket. It is the 100% correct SN I am using. Could this mean my 101F has been claimed and is unusable? Thanks!
Hi, I'm new and this is my first post.I'm currently configuring ZTNA, but I have problems I'm not able to solve. I want to connect to a SQL DB via TOAD GUI.Therefore I changed the SQL instance port from dynamic to fixed (Port 6434). Is there any other port next to may be 1433 and 1434 I need to enable in my ZTNA Server on the Fortigate?
Hi all,just wanted to check about flow-based vs proxy-based web-filter options.Is it similar to flow based vs proxy based inspection modes or something different.
I'm wanting to know the actually future replacements for the E & F series FG if possible, please. From some research the 100E for example can be replaced by the F series (80F & 100F), however some of the F series are also listed as EOL, whats to say these aren't any time soon. My question is: What is the long-term replacement please? Thanks in advance. CD
Hi there, I have configured Remote access Ipsec vpn with forticlient (IPsec Wizard) and I want to implement following best practice. 1. Client must get static IP address (not clients get the IP address from DHCP Pool)OrCan I bind static IP address to Users statically . 2. If Client is not performing any activity within 5 min or 10 min or more, Connection automatically should be disconnected. ( When Client is idle condition) 3. At a time only one user can login the VPN with his/her username. for example - test user only can login from one machine, not multiple machine. 4. Can I bind static mac address of the Client machine with user name or IP address. 5. MFA - I have checked it is working fine for me. 6. Can I create two/more separate group and assign different subnet. Thank you for support.
Until last week, our firewall indicated 7.4.11 as the mature release; however, as of today, I've observed it displaying 7.4.9 as the mature release. Furthermore, I am unable to locate these specific versions within the upgrade path. I am inquiring if anyone else is experiencing a similar issue. I have already initiated a TAC case to gather additional information regarding this matter.
Hi everyone I’m experiencing very high latency when FortiClient connects to EMS Cloud over a dial-up IPsec tunnel. The latency is noticeable even with basic tests, for both internal and external traffic.So far, I have disabled UTM/inspection on the related firewall policies and verified MTU settings on both EMS and the FortiGate. EMS is using the default MTU (1280), and there are no custom MTU settings configured on the FortiGate.
Hello all,I wanted to know if any debug commands to check traffic is getting dropped from which security profile. I know the debug command to check traffic is hitting which policy. I wanted to know the debug command for security profile and any cli commands to check security profile logs.
Hi dear community, I am deploying fortiwaf 600F, traffic logs enabled in waf through this command , but logs are not showing, i need to check traffic and create policies. In Firewall Policies option its dont have log session check available like fortigate firewalls. Hard disk is available and space is also free. I previously only upgraded firmware to FortiWeb-600F 8.0.2 build 0060 (GA.F),250304 firmware version config log traffic-log set status enableend .Furthermore packet log also enabled. Needs your complete guide line to resolve this issue. WAF is deployed in Reverse Proxy mode.
We recently moved to 7.4.X, and one complaint we have gotten multiple times now, is that there's no longer any indication next to the VPN connection of what user is being used. These VPN tunnels make use of SSO and has such it is not always immediately obvious what user is currently being used. Is this something that's gone for good on 7.4 or are we just missing a configuration?
Hello All, Just need some clarity on VPN connectivity between countries. I face random issue with SSL VPN while connecting from India to Italy. initially while connecting we get not reachable or not connecting and get stuck at 10% or 40%. After 2 to 3 attempts it works fine. As i understand there is no issue in VPN configs. Have you guys faced any such issues when trying to connect VPN. How do you troubleshoot this issues.
Hi Community, I would clearify, when enable "UEBA" feature, does it require install other FortiSIEM agent? as we already installed "FortiSIEM Log Agent" on servers (Window), our current version 7.4.x.x.Thanks for your respoonds.
StrongSwan IKEv2 VPN tunnel with X509 Authentication - helpI am doing a proof of concept, trying to get a router with StrongSwan embedded in it, for a Site-to-Site IKEv2 VPN tunnel back to HQ, using certificate authentication. The remote side (router) has a dynamic IP address. At the HQ side, the tunnel is configured as a dynamic/dialup tunnel. If we can make it work, there will be about 200 more just like it later. If I use PSK, the tunnel comes up and stays up, so connectivity between the remote site and HQ appear to be good. If I use X509, the tunnel comes up for about 10 seconds, I see the phase 2 up in the IPSec monitor and the route gets installed on the Fortinet/HQ side, and then there is a failure (on the StrongSWAN side) with the logs with error message "certificate status is not available" and something about not being able to reach the CRL or OCSP servers, with a timeout of 10000ms (which lines up with the tunnel coming up for 10 seconds). The
Hi, we have FG200F with new OS and SD WAN Rule for our Sharepoint sites. This worked fine until maybe last year october when we got the first users with saving problems, access problems, etc. Users are not allowed to use OneDrive, they download Word files from our xxx.sharepoint.com and work with OFC. Since we know that MS made some changes we are looking for internet access problems with the FG200F. First we created a SD WAN rule with destination Micrsosoft all services using ourt best internet access interface A. Also we deleted all UTM features on the policy but we still have problems. I checked and all sessions to the sharepoint sites use interface A. I am not so sure, that we get a solution on the FG and that it more a client problem but any ideas what else we can try?Thanks!
Hi there, I'm having issue in a lab (build by me) that i've created with trial version of FortiGate VMs (x2), FortiManager (x1) and FortiAnalyzer (x1).I've added two FortiGates to the FortiManager, and everything was working without issues, untill the first device installation.The FortiManager keeps showing error in the installation of device configuration, after digging around, i found out that the issue occurs because of the "set banned-cipher" command. This command seems to be not available in the trial fortivm, and in the FortiManager I wasn't able to remove the setting from the CLI configuration (because it requires at least 1 cipher that has to be banned).The running versions of the devices are;FortiGate VMs KVM 7.4.4 build 2662 (Feature)FortiManager v7.4.3-build2487 240514 (GA)FortiAnalyzer (while it doesn't have to do with the issue) v7.4.3-build2487 240514 (GA) When i deselect the banned-cipher and click apply (in the CLI configuration of the device) the ci
Hello, I am currently trying to troubleshoot an issue where an external client cannot connect to an internal server. i have follow this documentation guide but I do not understand 100% the output of the #diagnose sys session list command: https://kb.fortinet.com/kb/documentLink.do?externalID=FD30042 FW (FW_VDOM_1) # diagnose sys session listsession info: proto=6 proto_state=01 duration=83 expire=3576 timeout=3600 flags=00000000 sockflag=00000000 sockport=0 av_idx=0 use=4 origin-shaper= reply-shaper= per_ip_shaper= class_id=0 ha_id=1 policy_dir=0 tunnel=/ vlan_cos=0/7 state=log may_dirty f00 statistic(bytes/packets/allow_err): org=3969/32/1 reply=16481/45/1 tuples=2 tx speed(Bps/kbps): 0/0 rx speed(Bps/kbps): 1/0 orgin->sink: org pre->post, reply pre->post dev=37->41/41->37 gwy=172.16.40.19/0.0.0.0 hook=pre dir=org act=dnat 81.63.141.211:53466->191.2.16.148:443(172.16.40.19:443) hook=post dir=reply act=snat 172.16.40.19:443->81.63.141.211
Has anyone else had this issue?
Hello All,I have 3 buildings, all in the same metro area, with a Fortigate pair managing 2 other building's Fortiswitch network over L2. With the following subset of my topology:Building1 FGT Pair > FSW PairBuilding1 FSW Pair > Building2 FSW Pair over an ISP wavelength fiber pairBuilding1 FSW Pair > Building3 FSW Pair over an ISP wavelength fiber pairBuilding2 FSW < UBNT P2P Radios > Building3 FSW (redundant link) I have a Ubiquiti P2P Wireless system in Buildings 2 and 3. I have the radios configured and setup between Buildings 2 and 3, with a strong link between the two. They tag their management traffic (GUI/setup of the radios) with a VLAN that does not interfere with anything fortilink-related, but they should pass any other L2 traffic across them transparently. Each Building's FSW Pair is a 1024E with an MCLAG-ICL between the two. Spanning Tree is the default Fortiswitch factory configuration (MST, 0 and 15 instances). Ideally, I'd like to get these
I have Windows domain environment, session helper is enabled. For normal active directory domain services it works fine. I also have CA server for auto enrollment, this does not work. I had to allow dynamic port range from clients to CA server for certificate auto enrolment. How can I enable this on Firewall to work over a single port?
Hi, i downloaded "FMG_VM64_HV-v7.6.6.M-build3654-FORTINET.out.hyperv", create a new VM in Hyper, create a Disk Drive and bind the extracted "fmg.vhd". Then i started the VM, open Browser and set my Login Details from FortiCloud Account. It looks "licensed" but the VM is noch listed in my Assets? can anybody tell me why? I see only my Trial FortiGate
Admin I need help to generate report on the demo link, I've been searching for some time now on how to generate report in FortiMail, but none of the documentation helps. I haven't configured any single thing, because I saw there's already a data on the demo, please guide me on how to generate a report in this FortiMail Demo, thanks.
Have set everything up as described in this article:https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-explicit-proxy-authentication-with/ta-p/206219 Have even tried it 3 times! everything is set up but, when I use a browser with the proxy address, (In Firefox) I get "the proxy server is refusing connections" if I change the Auth method and rules to simple LDAP, it works fine, I can log in and then browse, testing web filters etc. klist on the box im testing from:#5> Client: myusername@mydomain.netServer: LDAP/*****************KerbTicket Encryption Type: AETicket Flags 0x40a50000 -> forate name_canonicalizeStart Time: 2/2/2026 10:08:19End Time: 2/2/2026 20:08:19Renew Time: 2/9/2026 10:08:19Session Key Type: AES-256-CTS-Cache Flags: 0Kdc Called: ***************** have also recreated the keytab succesfully twice, I really thought this would be simple! LDAP connection is fine.. and tested. Any pointers please?
Hello,I bought an FGT 60E with firmware version 7.4.7. It is still registered with a reseller that I can’t contact, so I’m unable to register it on my account. It’s for testing purposes, but I would really like to update it to the latest firmware. Would anyone be able to provide it to me? Thank you very much, and sorry if I have broken a forum rule. Have a nice day.Julien
Hi everyoneIm using FAC as radius server for dot1x network access and with Unifi Access points as authenticator.the issue I'm having is that radius accounting messages I receive don't contain Supplicant IP address and all radius accounting messages are followed by this message : FortiAuthenticator rad_accounting [13775] [WARN]: [RX] Packet decode had attributes which it couldnt handle and skipped in packet from *.*.*.*:35947 Any guidance would be greatly appreciated
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.