User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I completed the NSE 2 a few years ago. I just checked my profile and I don’t see it in there anymore. Where did it go?
Hello, everyone. We currently have an HA cluster in Active-Active mode in Azure that is load-balanced by Azure Load Balancers.We need to change the HA type to Active-Passive mode and remove the load balancers from the architecture. Is this possible?Does making this type of change require evaluating any additional configuration?I understand that an SDN Connector could be used, but is this specific to Azure or Fortinet? Could this result in an additional “cost” that needs to be paid? Thanks for your comments.
We have a primary Fortigate that is used to control Internet access for several retirement communities across several campuses. We have traffic from all sites Hide-NAT’d to different IPs based on the type of traffic. Guest/public access from all sites get NAT’d to this IP, internal residents get NAT’d to that IP. Internal systems get NAT’d to a different public IP still. This helps when someone on the internal network has a system which has been compromised and is causing one of our public IPs to get blacklisted.However it is still a problem when one of our public IPs gets blacklisted because a system is doing something it shouldn’t. What is the best way on the Fortigate to identify problematic internal systems (particularly spam sources), and block their IP from being allowed public access?
Is it possible to modify the landing page when you open the client to be the Remote Access Tab with it defaulting to a specific connection? The policy calls a profile that has both IPsec and SSL vpn. Wanted to push users to start using the IPSec connection and would be simpler if they just opened the client to that section rather than having to explicitly select the IPsec vpn connection.
This is a long shot, but I just wanted to check on here to be sure. I’m trying to troubleshoot some devices that are offline in difficult-to-access locations. I tried asking Fortinet tech support, and they said that no such database exists. Just wanted to check here just in case.
HelloOn FortiGate 30E with FortiOS v6.2.3 build 1066 (GA), the administrator user name and password have been changed.Unfortunatly the credentials have been lost.The default admin account is disabled or deleted.There is no other account.is there a way to recover the administrator access, without losing the configuration?Thanks for your help.Philippe
In DoS Policy » tcp_src_session option.if i set Threshold = 30Is it mean 30 session per 60 seconds ?
We host a Norwegian sports club website that FortiGuard classifies as Malicious Websites, High Risk, "strong confidence of malicious intent". We have submitted it three times through the Web Filter rating request form and each time received the same automated reply keeping the rating, with no evidence given. Hoping someone from FortiGuard Labs can take a look. Domains: kveldeil.no and www.kveldeil.no - both have identical rating history. Rating history, from your own Web Filter Lookup:07 Dec 2016 - added as Malicious Websites29 Mar 2017 - updated as Sports23 Jan 2019 - removed as Sports So the site was flagged in 2016, corrected to Sports in 2017, and in January 2019 the Sports rating was removed, which reverted it to the 2016 entry. There is no detection newer than December 2016 in the history. That suggests the current rating is inherited from old data rather than from anything recently observed. What the site is: Kvelde Idrettslag, an amateur sports club. It runs on our CMS platform
I asked for an extra IP from the ISP. For that they had given me /29 IP block.They said that they will work under the old pilot IP which was already given by ISP. That IP was configured WAN1 and internet are working well. But I need to use that additional IP under firewall.Because i am going to host one web application server. For that server i need to configure public IP directly.If it comes under the server means i can able manage and control who are all want access the app server. I am using FG101E.
In an Active-Active FGCP cluster, only the primary unit answers ARP requests using the HA virtual MAC address, while subordinate units retain their own physical/real MAC addresses.When the primary load-balances a session to a subordinate unit, could you confirm:Is the packet handed off to the subordinate over the same data/LAN interface (addressed to the subordinate's real MAC), or over the dedicated HA heartbeat link? Since the subordinate never responds to ARP requests, how does the upstream switch learn/populate its MAC table entry for the subordinate's physical MAC — is this purely through standard source-MAC learning when the subordinate transmits traffic (e.g., forwarding the processed packet to its next hop), or is there an additional FortiGate-specific mechanism (e.g., periodic announcement frames) to keep the switch's table populated? Does the subordinate's return/outbound traffic exit directly through its own interface to the destination, or does it always route back through
i Download VM Forti 8 and istall it but license invalid
We currently have a FortiGate firewall running FortiOS version 7.2.11, and we are planning to upgrade the firmware to a recommended and supported version.Could you please share the recommended FortiOS version for our firewall model, along with the correct and supported upgrade path from FortiOS 7.2.11?
Hi,I am experiencing a FortiToken Mobile activation failure on Android 16 with FortiToken Mobile 6.5.0.0030.The error shown during activation is: "Invalid server certificate - FortiToken Mobile cannot validate the server certificate."I found an older Fortinet Community discussion describing a very similar problem after upgrading to Android 13:FortiToken Mobile cert error on Android 13https://community.fortinet.com/support-forum-92/fortitoken-mobile-cert-error-on-android-13-115185In that thread, the original poster later reported: "Fortinet support said this is bug 765700."Fortinet also documented bug 765700 in the FortiToken Mobile Android 5.2.3 release notes:FTM Android 5.2.3 Known issueshttps://docs.fortinet.com/document/fortitoken/5.2.3/ftm-android-5-2-3-release-notes/999611/known-issuesBug 765700 is described there as: "'Untrusted Certificate' popup throws when activating/completing token transferring or approving/denying Login Requests"Fortinet later listed bug 765700 in the FTM A
I have many event like this for cisco ipphone. Are this event say that we can enable device profile using CDP?
This is a head scratcher…..I am a network infrastructure professional services engineer. I support a few dozen customers, many of which use Fortinet products. I run VMware workstation on my laptop, and have a different VM dedicated to each of my customers with their VPN solution installed on their VM. Each VM is a clone of the same base Win11Pro system. My problem is specific to one and only one of my customers.I have no trouble connecting any of my customers except for one, Customer-X. Customer-X has two sites, each with a FortiGate and DIA. One of them is still running FortiOS 7.2 and is allowing SSLVPN (Site-A). The FortiGate at their other site (Site-B), has been upgraded to FortiOS 7.4 and has been configured to allow IPSec remote access VPN. The VM I run for this customer is a standalone Windows11 install (not domain joined). After launching the VM, I have full internet access without any detectable issues. Inside of Customer-X’s VM, the public IP reported by whatismyipa
Hi Guys, Has anyone sat the NSE4 exam so far? I’m taking this exam next month and feeling a bit nervous.Please share your experience how tough was it, which topics came up the most, and what helped you pass?Any tips would be appreciated for all the people like me preparing right now
Hello!I just recently downloaded the Hyper-V image for FortiGate-VM, version 8.The VM boots fine, no issues, the CLI is accessible through SSH.When comes time to apply the evaluation license, it seems to fail (using the “exec vm-license-options” command).On the Web GUI, the evaluation license seems to apply (by logging in with my Fortinet account) but after a reboot, it says “No License” in the system status.Then, in the Web GUI, I login, briefly see the “what’s new” video pop up and then it pops back to the login screen.Any ideas?Thanks!EDIT: I forgot to add that when running “exec vm-license” it requires a token, which I do not have.
Hello,In our company we have an EMS instance currently deployed in Azure and we need to move it out to another cloud service. Due to the security requirements given to us, each EMS client must be authenticated with SAML to connect to EMS for management. In the past we have migrated EMS 7.2 to 7.4 Windows → Linux deployment and this caused all of our 2000+ connected users to be thrown out of EMS and needed to be onboarded again. Perhaps someone has already successfully tried EMS migration to another instance (keeping the same FQDN) with SAML authentication enforced? Looking for ways to execute a seamless migration so that endpoints would not need to be onboarded to EMS again. Note that our SAML authentication goes through FortiAuthenticator. Endpoints are ~99% on MacOS. Support has recommended restoring the database/configuration on the new instance but could not definitively say if SAML re-authentication would kick in.Thanks
We have become aware of the following security advisories regarding a vulnerability in FortiClient:https://fortiguard.fortinet.com/psirt/FG-IR-26-156https://advisories.ncsc.nl/2026/ncsc-2026-0296.htmlWithin our organization, we exclusively use FortiClient VPN-only for Windows. We do not use the full FortiClient client or FortiClient EMS.Therefore, we would like to know whether the vulnerability described in FG-IR-26-156 also affects the FortiClient VPN-only client.Additionally, we would appreciate clarification on the following:* Is FortiClient VPN-only affected by this vulnerability?* If so, which versions are affected?* Which version does Fortinet recommend installing to address the vulnerability?* Is an updated version of FortiClient VPN-only currently available?* Does the VPN-only client update automatically, or do we need to manually deploy the updated version to all our laptops?We would appreciate your clarification so that we can take the appropriate measures if necessary.Kind r
Hi everyone,We are currently using ExtremeCloud IQ Connect Cloud to centrally manage our Access Points.Our current environment has the following characteristics:We are using ExtremeCloud IQ Connect Cloud for centralized AP management. The cloud platform centrally manages the Access Points. SSIDs and VLANs are configured and managed through the cloud platform. There is no on-premises Wireless Controller deployed in the environment. ExtremeCloud IQ Connect Cloud does not provide a dedicated Management IP that can be directly added to FortiNAC as a network device. We have tested adding an individual AP to FortiNAC using the AP's Management IP. FortiNAC was able to connect to the AP and retrieve information such as the SSID.We would like to clarify the following points:Can ExtremeCloud IQ Connect Cloud be directly integrated with FortiNAC, or is it necessary to add/manage each individual AP in FortiNAC? If individual APs need to be added to FortiNAC, can FortiNAC control client access base
dear im going to deployed FortiAuthenticator as external captive portal , guest user will connect to Aruba WLC please guide me to achieve this
I am using FortiNAC-CA / FortiNAC-OS v7.6.5.0815 (GA) together with a FortiGate and I would like to implement a daily Internet usage limit for self-registered guest users.My requirement is:Guest connects to the Guest Wi-Fi. Guest self-registers through the FortiNAC captive portal. After successful authentication, the guest receives Internet access. The guest is allowed a maximum of 1 hour of Internet access per day. After the 1 hour is consumed, Internet access should be blocked automatically. The guest should not be able to regain access by disconnecting/reconnecting or registering again. After the daily 24-hour reset, the same user/device should receive another 1 hour of access. Ideally, the limitation should be based on the user or device/MAC address, so creating another self-registration session does not bypass the limit.I understand that FortiNAC has Account Duration and Reauth Period, but from the documentation it appears that Account Duration is not a recurring daily quota. For
mailfilterd stuck at ~100% CPU, FortiMail 8.0.0 build 183 — cause unclearFortiMail 8.0.0 build 183. mailfilterd sits at ~99.8% CPU continuously (not a spike), RSS grown to ~1.5GB (baseline is usually ~100MB). All other processes idle. Session count (24–50) and bandwidth are normal, so it's not a traffic flood.Enabled diagnose debug application mailfilterd level 8 + duration 30 and pulled the Trace Log. The only thing logged for 10 minutes was:FmailAIClient.cpp:931:ping():entryrepeating once a minute, on a single thread, with no other activity captured — looks like a routine heartbeat, not the actual hot path.I can't figure out what's actually causing the 100% CPU. Any help would be appreciated.
I struggle to understand why this dataset query shows no result on my FortiAnalyzer instance:SELECT dstport, srcip, dstipFROM $logWHERE $filter AND ipstr(dstip) IN ('172.31.11.80', '172.31.11.83')GROUP BY srcip, dstip, dstportORDER BY dstport, srcipTo be sure, I am getting results if in the Log View I search for: dstip=172.31.11.80 or dstip=172.31.11.83Any hint?
Hello Fortinet Community,We are currently experiencing an issue where users connecting through the FortiClient IPsec remote-access VPN do not receive their email OTP.Environment:FortiGate model: FortiGate 100F FortiOS version/build: v7.6.7 build3704 (Mature) VPN type: IPsec remote-access VPN Two-factor authentication: Email OTP Email service: fortinet-notifications.com Issue started: September 4–5, 2026 Impact: Multiple/all VPN usersThe VPN authentication process reaches the stage where the user is waiting for the email OTP, but no OTP email is received. This configuration was previously working normally.We enabled the following debug commands:diagnose debug resetdiagnose debug console timestamp enablediagnose debug application fnbamd -1diagnose debug application alertmail -1diagnose debug enableThe certificate authentication shown in the debug completes successfully with:Cert status: GOOD auth_cert_successHowever, we did not see an AuthCode being generated or an SMTP connection initia
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.