Skip to main content
matheusbpedro
New Member
June 6, 2023
Solved

NGFW mode unavailable to change

  • June 6, 2023
  • 10 replies
  • 4938 views

I`m trying to get the certificate NSE4, but in the training (CBT Nuggets) have a NGFW option in the last version 7.0.10 I made this change without problems
System > Settings > NGFW Mode 
Now, in version 7.0.11 I didnt find this options in the same section, print attached Version 7.0.11Version 7.0.11Version 7.0.10Version 7.0.10
 Someone can help me?

 

Best answer by Yurisk

You got the wrong VM image - you installed FortiFirewall, but you need FortiGate. 

Output of free licensed VM Fortigate, see the name after Version:

 

FGT-7-2-2 # get sys stat Version: FortiGate-VM64 v7.2.2,build1255,220930 (GA.F) Virus-DB: 1.00000(2018-04-09 18:07) Extended DB: 1.00000(2018-04-09 18:07) Extreme DB: 1.00000(2018-04-09 18:07) AV AI/ML Model: 0.00000(2001-01-01 00:00) IPS-DB: 6.00741(2015-12-01 02:30) IPS-ETDB: 6.00741(2015-12-01 02:30) APP-DB: 6.00741(2015-12-01 02:30) INDUSTRIAL-DB: 6.00741(2015-12-01 02:30) IPS Malicious URL Database: 1.00001(2015-01-01 01:01) IoT-Detect: 0.00000(2001-01-01 00:00) Serial-Number: FGVMEV_ATFDMNL66 License Status: Valid VM Resources: 1 CPU/1 allowed, 2007 MB RAM/2048 MB allowed

 

 

More on difference https://community.fortinet.com/t5/Support-Forum/What-is-FortiFirewall/td-p/222567

10 replies

srajeswaran
Staff
Staff
June 7, 2023

Do you have VDOMs enabled? Can you check from the CLI?

 

To enable policy-based NGFW mode without VDOMs in the CLI:
config system settings     set ngfw-mode policy-based end
To enable policy-based NGFW mode with VDOMs in the CLI:
config vdom     edit <vdom>         config system settings             set ngfw-mode policy-based         end     next end

 

matheusbpedro
New Member
June 7, 2023

Hi Suraj,

I try your comment in my VM, but it looks like all commands that you sent in this version didnt work, see below:

versao 7.0.10.PNG6d5d7c38-765d-41d5-a2f7-8f9f6b230b2b.PNG

srajeswaran
Staff
Staff
June 7, 2023

Can you share below outputs?

get system status

get system settings | grep ngfw

 

Yurisk
SuperUser
SuperUser
June 7, 2023

Try changing on CLI as @srajeswaran  mentioned above, or try to delete all cookies/enter in Incognito mode of the browser. This setting is for there and didn't move, seems like a browser thing. 

yurisk.info - all things Fortinet blog, no ads
Faiza_Emam_Delhi
Visitor III
June 7, 2023

It seems that in version 7.0.11 of Fortinet, the NGFW mode option has been removed from the System Settings section. However, this does not mean that the NGFW mode is unavailable.

To change the NGFW mode in version 7.0.11, you will need to use the CLI (Command Line Interface) instead of the GUI (Graphical User Interface). You can access the CLI by connecting to the Fortinet device via SSH or Telnet.

Once you are connected to the device, you can use the following command to change the NGFW mode:

config system global
set ngfw-mode <mode>
end

Replace <mode> with the desired mode, which can be one of the following:

- proxy
- flow
- proxy-based-flow

After entering the command, be sure to save the changes with the following command:

end
write memory

I hope this helps you in your pursuit of the NSE4 certification....

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!