User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I've noticed an extremely strange thing upon upgrading some test FortiGates to the new version 7.6.7: the upgrade goes fine, and the FortiGate is happily online and is routing/firewalling-just fine. However, when trying to load the GUI it is just a blank page.I can see the little favicon loading for the FortiGate login page, but its just blank otherwise. I can SSH in just fine, so that is good. I do not see any settings reset in global settings, and strangely going to the http login instead of https sometimes works (I have https redirect turned on).As the FortiGate seems to be perfectly fine otherwise, I thought I'd see if anyone else has experienced this?Also I have tried multiple browsers with privacy/incognito mode on, so I don't think it is a cache issue.
Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.Am I missing something in t
Hi All, VersionFortiGate-81F v7.4.8,build9191,260511 (FIPS-CC-74-8)FIPS-CC mode: enableFortiSwitch-148F-FPOE v7.4.8,build0929,250909 (GA)Security mode: none In our environment, Federal Information Processing Standards (FIPS) is required due to the contract we have. I have been running into the following issues while testing FIPS mode on our equipment.The FortiSwitches appear under Managed FortiSwitches. I can see the firmware version, status, and join time, but I cannot SSH into the switches from the GUI. It also does not show the Connecting From status or the switch IP address.Under FortiSwitch Ports, the port connecting the FortiGate and the FortiSwitch shows as down. When I assign a VLAN to a FortiSwitch port, the VLAN assignment is accepted, but it does not actually take effect on the connected device.However, from the FortiGate CLI, I can SSH into the switch without any issues. The switch status is visible, but it appears that the configuration is not being fully synchronized to t
I believe when we add the switch to the fnac for 1st time then fnac inventory will collect below data such as Name, Default Vlan, Current Vlan from the switch. When we have changes on the switch, example i make port description and change the default vlan then why in the fnac is not updated? Resync the interface is not helping
Hello, I would like to clarify the expected FortiGate behavior when a FortiGuard/UTM license expires. Our FortiGate 81F had a UTM contract that expired on August 6, 2026. A new license contract was purchased/renewed on Friday, but the new contract has not yet been activated. After the previous contract expired, Internet traffic through one of our existing firewall policies was blocked. Basic websites could not be accessed. The affected firewall policy had the following security profiles enabled: - AntiVirus - Web Filter - DNS Filter - Application Control - IPS - File Filter When we disabled these security profiles, Internet connectivity immediately returned to normal. Fortinet Customer Service stated in the support ticket: “internet connectivity will not be affected due to the absence of a license.” They also stated that basic firewall policies that do not rely on subscription-based security services should continue to function. Therefore, I would like to understand the technical behav
Hello, I am able to configure OSPF over IPSec tunnel, but: - I have another OSPF interface (through a physical interface) with lower cost that is Up and routes in the routing table are using this preferred link with correct cost.- When the IPSec tunnel comes Up, the routing table is modified; routes are now using the IPSec interface although I have defined a higher cost for the VPN interface... looks like something is forced. Has anyone come across a similar situation? Thanks, Monty.
Good morning teams 😊;For FortiClient EMS Trial, I created an IPsec VPN tunnel.However, I cannot export the XML configuration file with the VPN password included.Is there a way to export the VPN XML configuration with a password?What I would like is that when the user imports the XML configuration file (with forticlient) , they are required to enter a password before they can access the VPN.thanks for you support 😊
Hello PAM adminsFortiPAM 1.4.1.I'm very new in FortiPAM and I have questions regarding Web launcher.When I'm in company's local network all works fine, Web launcher, RDP launcher and SSH launcher.However when I'm outside and connect from public IP and try run Web launcher it doesn't work, while SSH launcher and RDP launcher still work fine.I noticed that for both RDP and SSH launcher, PAM opens the browser tab with address bar contains a public address like https://pam.mycompany.com/someaddress.While for Web launcher it opens the private IP of the target, which naturally can't work from WAN without some proxy on the client.If I'm not wrong I think it needs FortiClient in order to work, right?So my question:Does it work with FortiClient for Windows, Linux & MacOS?Does it require EMS?Is there a plan to make it work in future release without FortiClient? (other PAM products can do it without agent)
We encountered some issues accessing some URLs after upgrading from 7.2.12M to 7.4.12M using FGT401E on HA.applications like MS Teams get disconnected suddenly and users reported that access to some external portal become very laggy.upon checking the traffic log, we noticed that the Application name was classify as 2x which is a service group in our firewall.under this group, there is HTTP, HTTPs, TDP, 2X publishing agent port and 2X terminal server agent port.due to the many issues encountered, we have rollback to 7.2.12M
We have identified duplicate endpoint entries in our EMS console and, to manage them, we created two separate groups: one group in Domain and another group in Workgroup.We are able to delete the endpoints that are listed under the Workgroup group without any issues. However, for the endpoints that are present in the Domain group, we do not see an option to delete them. Additionally, we are unable to move these endpoints from the Domain group to the Workgroup group.Could you please let us know:Is there a way to delete the endpoints that are currently listed under the Domain group in the EMS console? What is the recommended process for moving endpoints from the Domain group to the Workgroup group?Any guidance or best practices to resolve these duplicate entries would be greatly appreciated.Thank you.
When i have a new ipphone connected to the network then fnac will move this ipphone to registration vlan before device profiling is running. After device profilling run then i can see the ipphone move to host role ‘IP Phone’ and registered’But after the devices was profiled then how the vlan can be changed automatically to voice vlan? The only way the ip phone get the voice vlan after the ip phone registered by profiling is reboot the ip phone.
Hi everyone,I am attempting to set up a new IPsec VPN connection using the standalone FortiClient VPN only v7.2.1.0779 app, but several configuration options appear to be missing from the user interface: Missing Single Sign-On (SSO): When creating an IPsec VPN profile, there is no option or toggle for Single Sign-On (SSO / SAML) anywhere in the GUI. Missing Mode Config Parameters: Under Address Assignment, selecting Mode Config does not reveal options for Encapsulation, IKE UDP port, or IKE TCP port. Any insights or guidance would be greatly appreciated. Thanks!Missing option in my appSSO setting i expectedMode configuration setting i expected
My Fnac license 106 is in use, how we can know detail which endpoint is consume the license?
hello everyone,i am setting up a home lab and recently acquired a fortigate 60d rugged.i tried to reset it using coolterm on my mac and after the proccess it just got stuck on system halted, now its “bricked”i am trying to find a way to get it back up and running and i am fully aware that this product is an end of life model. tried also customer service and dident help. any help will be great!
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
Hi, we were an on-prem only company. Earlier this year we went hybrid with 365.For VPN earlier we had our clients connecting through forticlient with AD credentials leveraging RADIUS. No MFA.We then configured a parallel setup using IPSec ike v2 and authentication with EntraID, adding the MFA feature then.My question is: is this the natural approach that most of the former on-premise companies adopt once moved to Cloud or are there other suggested setups, maybe leveraging already existent on-premise RADIUS infrastructure?
We can select 802.1x authentication set to user or computer if we use wired. How about for wifi? There is no option to select that option on the wireless card properties.
Hello Community,We are currently encountering a known limitation with the standalone (unlicensed) FortiClient app on Android. When attempting to connect to an IPsec IKEv2 VPN using a Pre-Shared Key (PSK) alongside EAP user authentication, the client fails to render the username and password prompt during the connection sequence.This behavior aligns with the issue documented in the following Fortinet Knowledge Base article:Troubleshooting Tip: FortiClient VPN without license on Android has missing username and password promptDeploying FortiClient EMS or reverting to deprecated IKEv1 for a single mobile endpoint is not feasible for our environment. As a result, we are looking for advice on the following: Alternative Client Apps: Are there recommended third-party IPsec IKEv2 clients for Android (e.g., strongSwan, native Android VPN setup) that can successfully handle PSK + EAP/XAuth user authentication against a FortiGate without modifying the core gateway configuration? Configuration W
Hi AllI would like to know if there is a method to export FGT Policies into Excel (csv) format.Please advise any available options. Am using FortiOS v7.4.12 Many thanks
I have DPR to set host role new ip phone to role IPPHONE then after the device profiled why the vlan is not changed? The ipphone still sit on isolated network except i replug the phone. Isn't when the host role changed then the policy will be evaluated automatically?
Hi everyone,I'm currently setting up FortiXDR and I'm a bit confused about the required FortiAnalyzer configuration.Our environment consists of:FortiClient EMS Cloud FortiXDR license Local FortiAnalyzer VM (no FortiAnalyzer Cloud license)We do not have a FortiAnalyzer Cloud license, only a local FortiAnalyzer VM.My question is:For FortiXDR, where should the FortiClient logs (configured in the System Settings Profile) be sent?Should the FortiClients send their logs to a FortiAnalyzer Cloud instance, even though we don't have a FortiAnalyzer Cloud license? Or is it supported to send the logs directly to our local FortiAnalyzer VM while still using FortiXDR?Most of the users work from home, so we are currently using a DNAT with TLS configuration.Has anyone successfully deployed FortiXDR with EMS Cloud + local FortiAnalyzer?Kind regards,MG4
can we get a proper captive portal instead of showing the default page.https://<controller-ip>/vpn/auth_web_ok.htmlwe tried changing the auth_web_ok.html inside custom captive portal under maintenance. but still its loading the default fortinet page as shown below.
If we use computer authentication then can service connector get record grom device group? I want to make dynamic vlan assigment based on entra id with computer authentication.
Hi Everyone,We have a fortigate firewall with HA and FortiOS is 7.4. also laid few client based FortiGate SSL-VPNs accounts.Now we have to upgrade either 7.6 or 8.0, where as not support the client based FortiGate SSL-VPNs accounts. So, what is the best practice for moving to 7.6 or 8.0 version?.Before upgradation can we use any migration tool only for SSL-VPN accounts to IPsec or any other?.MY SSL-VPN purpose is providing the RDP access & Web based internal urls. Anyone guide me for best practice for without any production impact?.Thanks in advance.
Our internal tools use FMG API to manage it and we were looking to create a Threat Weight Template using API.I have checked:https://fndn.fortinet.net/index.php?/documents/file/521-fortimanager-76-json-api-full-reference/https://how-to-fortimanager-api.readthedocs.io But did not find the API endpoints.If someone has done it before or has any API collection they can share ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.