User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Our internal tools use FMG API to manage it and we were looking to create a Threat Weight Template using API.I have checked:https://fndn.fortinet.net/index.php?/documents/file/521-fortimanager-76-json-api-full-reference/https://how-to-fortimanager-api.readthedocs.io But did not find the API endpoints.If someone has done it before or has any API collection they can share ?
When we use DHCP fingerprint for device profiling then we need to add ip helper on L3 interface. How if the L3 using fortigate, there is no ip helper command?
Can anyone help me with the issue where LAN failover is not occurring between the FortiGate HA pair and the Cisco VSS switches?[ Cisco VSS Logical Switch ](Switch 01 + Switch 02)/ \[Po101] [Po101]/ \ / \(Eth1/3) (Eth2/3) (Eth1/4) (Eth2/4)| | | |[ x1 ] [ x2 ] [ x1 ] [ x2 ][FortiGate-01] [FortiGate-02](ACTIVE) (PASSIVE)| |TRAFFIC <----------- NO TRAFFICThe Cisco switch is configured with an EtherChannel (Port‑Channel 101) that bundles four interfaces—Eth1/3, Eth2/3, Eth1/4, and Eth2/4—operating in active mode, as shown in the diagram.The FortiGate firewalls are deployed as an HA pair, with ports X1 and X2 connected to the Cisco VSS switches. Port X5 is connected to the Internet link (Cisco Wan Router) and is also configured as an HA‑monitored interface.Additionally, the X5 port is part of the WAN_Aggregate interface, which is assigned to VLAN 50. VLAN 50 serves as the Internet_VLAN SVI, and the default gateway for the Internet_VLAN resides on the Cisco router.When the X5 interfa
Hi everyone,I operate a small autonomous system. There is not much throughput, maybe 200Mbit/s peak.I'm wondering if a 80E has enough RAM for peering at 2 IXPs+receiving a full table from a transit provider.Anyone with experience in that regard?
Hello, apologies if this has been posted before, but I could not find anything in the forums.We are a K-12 that recently switched to a FortiStack (Gate (100F), switches (148FPOE), WAPs (231G and K series). We are coming from Cisco Meraki and missing a big feature (or cannot find said feature) that I’m hoping to duplicate with FAZ. Being K-12, we have students lose devices on campus. We were able to log into the Meraki portal., look up a device hostname/mac and see what access point that endpoint last connected to. This helped students track their lost device.I cannot find anything simliar in the FortiWorld. I've piecemealed a dataset in FAZ from the Gate Event logs that gives me the client mac, last connected AP, and the last_seen time. I’ve parsed that along with a query based off Gate > Application Control > aware-New-Endpoint-Devices dataset. It looks like it would be what I need but I think the last_seen time is when it was FIRST connected to a particular access point. I real
Hello, My ISP delegates an IPv6 prefix but, unfortunately, it's dynamic and changes weekly. It works though and two LAN interfaces successfully have prefixes. Great!I would now like to add a ULA to an interface but cannot see a way to add a second IPv6 address if the interface is set dynamically. For testing (please excuse the short ULA), I switched from the interface itself having a prefix delegated to having a ULA: config ipv6 set ip6-address fdfc:c::40/64 set ip6-allowaccess ping https set ip6-send-adv enable set ip6-other-flag enable config ip6-prefix-list edit fdfc:c::/64 next end config ip6-delegated-prefix-list edit 1 set upstream-interface "wan1" set delegated-prefix-iaid 1 set subnet 0:0:0:1::/64 set rdnss-service default next end end I have (accidentally) stumbled upon a solution. It seems to work but is this actually valid configuration?Many thanks for reading
Just ran into this issue and I cannot find the reason: I connect a dialup ipsec vpn using FortiClient VPN successfully.I then have internet via the vpn (no split tunneling enabled).Which is wanted behaviour.Now I tried to download a zip file from github.com and I got blocked.The Firewall Policy that allows internet from out of this VPN does have UTM Filters on but none is set to block .zip.In FortiAnalyzer I see my traffic but I see no UTM block here. The session details in FAZ only show 2-3 security event that are all of type “pass”. This is because APP Control is set to monitore quite a lot here.So no block here but in Chrome via that VPN I still do get some Fortinet blocking page saying this is blocket because of the filetye. I have no clue what causes this. Do you have any thints or tipps on this?
Hello,I would like to share some information I found: FortiMail VM no longer has a memory limitation. I tested versions 7.4.2 and 7.6.5 in the lab, and neither has the memory limitation (this likely applies to other earlier versions as well). This can be confirmed using the `get system status` command:FortiMail VM01 with more than 4GB RAMRegards,Vitor Luz
I am having an issue with the FortiClient IPsec IKEv2 VPN connection on Android. I entered all the required information correctly and tried many configuration changes, but the issue still persists. When I attempt to connect, I receive a “Null” error message.At the same time, I tested the same VPN configuration on my iPhone, and the connection works perfectly without any issues. Iphone Settings Android Phase2 Settings Andorid VPN Settings
Hello, I have a frustrating case where a H-A cluster successfully authenticates against an external LDAP server using port 636, but is not able to browse the users in it.Testing a user is successful as well. Look at the attached screenshots.I changed the “cnid” field several times, including “sAMAccountName”.The version we are using is 7.4.12.
Hi everyone,I’d like to clarify something regarding the Intune deployment using the official bash script as it seems to be a bit problematic.I was following during configuration → Deploying FortiClient using a shell script | FortiClient 7.4.0 | Fortinet Document Library We are updating from 7.4.2 to a higher version. Issue I encountered are the following: *If the EMS is connected, the service does not run at all. No errors are show shown in the Intune portal. Which leaves me with the impression that the devices are not being reached. *Some newer OS versions -> macOS 26.5.2, assigned to the same group are not added to the list of “pending” (invisible, not in the list). And I don’t understand why. I am unsure if the script is even reaching them. The person in question had the older version, we removed it manually, and then we were waiting for the script to be executed. The person’s device was synced a few times (and restarted once) - no changes. *In some occasions, the script does n
Hi everyone,I have configured DNSBL under Profile > AntiSpam > AntiSpam on my FortiMail.I'd like to verify whether the DNSBL configuration is actually working as expected. Is there a way to confirm this from the FortiMail side?Specifically, I'm looking for answers to the following:Are there any logs or event logs that indicate DNSBL lookups are being performed? Is there a CLI command or diagnostic command that can be used to verify DNSBL functionality? What's the best practice for testing whether DNSBL is functioning correctly?If anyone has experience with this or can share the recommended verification steps, I would really appreciate it.Thank you in advance!
Hello everyone,Equipment:Model: FortiSwitch 124F-FPOE Firmware: 7.4.3 (Build 830) GAIssue:A CMK15 intercom/communicator device connected to a PoE port on the switch is not receiving any power. The device does not power on.Already checked:The Ethernet cable has been tested and is working correctly. A Wi-Fi access point connected to another port on the same switch receives PoE power correctly and works normally. The same phone device (CMK15), when connected to a different Fortinet-brand switch running the same firmware version, works correctly. It also works correctly when connected to a switch from a different brand.Could this be a hardware issue, or is there a missing configuration on the FortiSwitch? If not, what should my next step be?Thank you.
Could you please let me know whether you have encountered a similar issue or are aware of any possible solutions? We are currently migrating from SSL-VPN to IPsec-VPN. Since the migration, some users have been experiencing significantly slower download speeds when connected via IPsec-VPN. Observed speeds:Download: approximately 50 MbpsUpload: approximately 200 Mbps The speed tests were conducted using the following website:https://speedtest.gate02.ne.jp/ When the affected users switch back to SSL-VPN, the download speed returns to normal and the issue does not occur. Additionally, split tunneling is not enabled in our environment. We would appreciate any insights or recommendations you may have regarding this issue.
Hi everyone,I'm looking for the FortiAnalyzer 7.2.11 JSON-RPC API documentation. Does anyone have a copy or know where I can find the complete documentation?I'm currently integrating FortiAnalyzer with an external system and need information on the available JSON-RPC methods and objects.Any documentation, examples, or links would be greatly appreciated.Thanks in advance!
Hi, Please, can you change my Fortinet Community Username to "FortiEng_345"?Bests,
Hello guys,I tried to research the info but I can't find it. Hope you have the answer.Context : I have one policy package per Fortigate. For exemple, 10 fortigate so 10 policy package. In each policy package, I have some blacklist policies with the same group objects. If I update the group, it will change the policy package state of all devices, which is the normal behaviour. My issue is that I have to install one by one each policy package and I can't find a way to push every thing at the same time.So my question : is it possible to do it or is there an option to enable ?
Running FortiWeb KVM_PAYG on Proxmox (standalone, not a cloud marketplace deployment). Reproduced this identically on two separate fresh installs — 8.0.6 build0116 and 7.6.9 build1133. Running FortiWeb KVM_PAYG on Proxmox (standalone, not a cloud marketplace deployment). Reproduced this identically on two separate fresh installs — 8.0.6 build0116 and 7.6.9 build1133.Setup:Operation Mode: Reverse Proxy, standalone (no HA) port1 (external): static/DHCP IP, allowaccess includes http/https/ssh/ping port2 (internal): static IP, reaches backend fine Server Pool → backend IP:80, enabled Virtual Server → Use Interface IP enabled, bound to port1 Server Policy → links VS + Pool + HTTP Service (port 80) + a Web Protection Profile, status shows Running admin-port moved to 8080 beforehand, confirmed no port-in-use conflict when creating the policy License page: all green (VM License, Support Contract, etc.)Symptom:Client (Kali, same L2 segment) connects to the Virtual Server IP on port 80: curl -v
My port switch config isinterface GigabitEthernet1/0/1switchport access vlan 100switchport mode accessswitchport voice vlan 200authentication order dot1x mabauthentication port-control autoauthentication periodicmabsnmp trap mac-notification change addedsnmp trap mac-notification change removeddot1x pae authenticatorspanning-tree portfastend I think i no need to add two bold command above since the radius will be used and not snmp. Am i right?
Hello,Can someone clarify/confirm if the deployment/install of FortiClient via EMS still works in EMS 7.4.7 running on top of Ubuntu 24.04 w/ local DB, when AD is used as Authentication Server with LDAPS to connect and the user in question is part of Domain Admins and the prerequisites for remote installation in regards to ports / services ( https://docs.fortinet.com/document/forticlient/7.0.6/ems-administration-guide/12424/preparing-windows-endpoints-for-forticlient-deployment ) on the Windows computers are configured.Last time I used it was in EMS 7.2.X and it worked and since version 7.4 I’ve done only manual installations of FCT on workstations so far, so this is the first time hitting this and not working.The deployment policy is done properly, but no installation starts and also I cannot find any logs or I am not looking where I should.
Hi community,I am setting up a KMS (Key Management Service) host on a Windows Server 2025 VM in an on-premises environment behind a FortiGate firewall. The KMS host VM sits on the internal network and needs outbound internet access only for the initial KMS host key activation against Microsoft.Our environment:- FortiGate firewall managing outbound internet access- KMS host: Windows Server 2025 VM (static IP on internal network)- KMS clients: 3 other Windows Server VMs on the same internal network - We want to restrict internet access to the minimum required — only the KMS host VM should be allowed out, and only to the specific Microsoft endpoints neededMy questions:1. What specific FQDNs / IP addresses need to be whitelisted in the FortiGate policy for KMS host activation? I understand port 1688 TCP is involved — is kms.core.microsoft.com the only endpoint, or are there others ?2. Should this be a one-time firewall rule, or does the KMS host need periodic outbound access (e.g. for the
Hello,We are experiencing an issue with RADIUS authentication on FortiNAC after upgrading the appliance.The problem only affects newly added switches. Any switch that is added to the FortiNAC inventory after the upgrade is unable to authenticate via RADIUS.Existing switches that were already present in the inventory before the upgrade continue to work correctly, including switches on which I have recently enabled RADIUS. However, as soon as a new switch is added to the inventory and RADIUS is configured, all RADIUS authentication requests are rejected.The RADIUS server is reachable and RADIUS tracking is configured correctly. On the Aruba switch, the RADIUS server status is healthy and there are no connectivity or shared secret issues.The following message is logged on the FortiNAC RADIUS server: Mon Aug 3 16:02:03 2026 : Auth: (24) Invalid user (RADIUS not enabled on device): [ArubaTstRadius] (from client 10.11.49.12 port 0)Mon Aug 3 16:02:03 2026 : Auth: (24) Login incorrect (RADIU
Hello everyone,I am facing an issue with a FortiLink deployment over a RADWIN 5000 Point-to-Multipoint (PtMP) wireless network and would like to know if anyone has experienced something similar.TopologyFortiGate |FortiLink |RADWIN 5000 HBS / \ SU-1 SU-2 | |FortiSwitch1 FortiSwitch2The RADWIN network is operating in Layer 2 Bridge mode. No routing or NAT is configured between the FortiGate and the remote FortiSwitches. The wireless network transports the required VLANs correctly.Current behavior If only one remote site is powered on, the FortiSwitch is discovered and managed successfully through FortiLink. If I power on the second remote site, both remote FortiSwitches appear as Offline in the FortiGate. Despite this, all end-user devices connected to both FortiSwitches continue to pass traffic normally on their VLANs. Data connectivity is not affected. In other words: FortiLink management fails. User traffic continues to work without issues. Additio
When we use user authentication then we can enable dynamic vlan assigment based on the user group, example user group IT will get vlan IT and user HR will get vlan HR.Now when we switch from user authentiction to computer authentication the primary authentication will use certificate stored in computer and this make dynamic vlan based on user group is not working.Anyone here ever try to combine computer authentication but enabled dynamic vlan based on the user group?
When we disable host on Fnac then are we expected the host will be disconnect (move to deadend or isolation network) from the network realtime? I try disable a host but the host still connected to the network.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.