Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Unable to connect to SSL VPN after firmware upgrade to v7.6.7. The connection goes to 10% then I get the following error message: "Unable to establish the VPN connection. The VPN server may be unreachable."
q
Hi Team,I configured IPsec Remote Access (Dialup) for FortiClient users (Windows, macOS, Android) on FortiGate 201G – FortiOS 7.4.12. How can I restrict VPN access based on Geo-IP, so users can connect only from a specific country?Thanks.
Due to the lack of support of the SSL VPN, I am migrating the FortiClients VPN to IPSec. Created a new IPSec Dialup config and the tunnel worked fine for a local user. However when I enable the Fortitoken for the user (I receive the token in the email) but the tunnel never goes up and FortiClient show “time out” msg. Sniffing the traffic is possible to see my local peer trying to connect on port 500/4500 but get no answer back from the firewall. Once I try the user without the token it goes completely fine. Any ideas? Cheers
Hello,I’m creating this Topic because I’m facing an issue that neither me, Dell or our Forticlient provider faced before and we both have no idea what exactly is going on. We ordered a batch of Dell Computer Pro 3 14260. Those computers are facing kernel boot trap double fault with fortishield.sys. It occurs most of the time when the computer is booting with Forticlient 7.2.15.1309, but also very often when connecting or disconnecting of Forticlient. We also tried with 7.2.14 and 7.2.13 with same issueOur EMS is in 7.2 so we can’t try 7.4 for now it’s ongoing we have to build a linux machine for the upgrade.We don’t have this problem with any other dell computer model Of course if I don’t have Forticlient installed I don’t have any issueI’m trying to compare the components for those computers and see what could be conflicting but extremely difficult I just know it’s something with fortishield.sys as it is mentioned in the minidumps If anyone faces this (no result on forum search) or h
Hi all,I've made a free firewall migration tool, now available on GitHub: https://github.com/gateshift/gateshiftIt's still in beta, and feedback from people who actually do this work would be welcome.If you run firewall migrations or optimizations, give it a try and let me know where it falls short.
Recently upgraded my Fortigates to 7.4.5 - tested VPN - all fine.Gone to work from home and can no longer connect - stops at 10%I have tried absolutely everything I have seen online for example DIsabling IPV6 on both my network adapters and on my router.lowering MTUchecking all policieschanging DNS settingsloads of other things. The only thing I found that lets me connect is first connecting to Cloudflare one Traffic + DNS (UDP)I have checked and there no IP’s blocked on my Fortigates. No other user has reported a problem.I am on Youfibre. I cannot access many websites i need when connected to Cloudflare so this isn’t a permanent solution. Any ideas? The logs don’t seem to show many any errors of the time i’m trying to connect either. TIA
I upgraded my E-series FortiGate from version 7.6.3 to version 7.6.6. After the upgrade to 7.6.6, I lost connectivity to several networks that had been working without issues on version 7.6.3.I checked the configuration, and the static routes and policies remained unchanged; however, we had no connectivity. We had to downgrade back to version 7.6.3. Connectivity was restored after reverting to the previous version.Has anyone else encountered this scenario? I’ve reviewed the release notes and found nothing regarding configuration loss or any changes that might explain this behavior.Has anyone else experienced something similar?NOTE: My FortiGate has FortiLink configured with a FortiSwitch. I am not sure if this could be a compatibility issue. However, upon reviewing the release notes, I haven't found anything related to this type of behavior.
HiI have reviewed the FortiClient website and available documentation, but I was unable to find any clear resources explaining how to deploy FortiClient together with the required configuration VPN profile via Intune for Windows users.deployment with a preconfigured setup is supported? If so, please provide the relevant deployment guide, configuration documentation, or recommended deployment method.
Our company is transitioning from SSL-VPN to ZTNA. We have been testing ZTNA on 2 devices. It seems Windows built-in applications are extremely slow to open. For an example, when ZTNA is enabled, task manager took 17 seconds to open, command prompt took 39 seconds, recyle bin took 1 minute to open.When ZTNA was disabled, task manager took 1.81 seconds, command prompt took 1.18 seconds. and recycle bin took 1.81 seconds. This is a big difference. For a basic configuration, we are using ZTNA destinations and tags in EMS and ZTNA servers and firewall policies on the Fortigate. To resolve internal FQDN’s, I have configured DNS servers on Fortigate forwarding DNS request to internal DNS servers. We have also setup a KDC proxy which may have helped slightly. Has anyone experience this before and is there a configuration fix for this? In my testing everything works pretty well except for group policy. The only big issue is slowness opening these types of applications.
Hello community,Product: FortiGate-90GThe device is currently running FortiOS 7.4.7 build 2731.Its FMWR/support contract expired on 11 July 2025.FortiCloud SSO access is currently being blocked with Attack ID 20000021 because the installed FortiOS version is affected by CVE-2026-24858. I would therefore like to update the device to a security-fixed FortiOS release. However, due to the expired support contract, the FortiGate does not permit the upgrade through FortiGuard and the FortiCare portal does not allow me to download the firmware image manually. I am not requesting access to a newer major/minor FortiOS branch. I would like to remain within the existing FortiOS 7.4.x branch and upgrade only to the current security-fixed patch release, preferably FortiOS 7.4.12.Is it possible for the the official FortiOS 7.4.12 firmware image for this FortiGate-90G to be provided, or can someone from this community enable another supported method of upgrading this device to 7.4.12 for security rem
Currently testing FAP241K with Fortiswitch 148F-FPOE, Currently Auto transmit power is set to 17 to 20 dBm with target dBm at -70. Not using any DFS channel. Poe mode is high.why is it even with just a single AP, transmit power never goes above 17?To go higher requires setting it to percentage. 100% can go up to 28 dbm, changing it back to auto and it get stuck at 28 dbm. Any ideas?
Hello Fortinet community,We are trying to connect our Fortigate 100F (7.6.7) to our RADIUS server (Windows NPS) but the NAS-IP of the Fortigate is designed to only accept IPv4 addresses. In our case, the NAS-IP needs to be the gateway of one of the interfaces on the Fortigate (configured as aaaa:bbbb:cccc:dddd::1) which is autorised in the NPS server According to the CLI reference, the field is hardcoded to use legacy IPv4 which I do not want to enable on my network :set nas-ip {ipv4-address}Are there any plans to add IPv6 support to this field ? Thanks
I haven’t been able to connect to my company network with Forticlient for the past two weeks. The latest versionof Forticlient vpn installed is 7.4.3 hotfix 1.8758. I keep getting a “connection timeout” error. I tried running it as an administrator, but that didn’t fix it. I uninstalled and reinstalled it, but that didn’t work either. I tried installing older versions, but that didn’t solve the problem either. The strange thing is that I can connect from some computers but not others. My Windows updates are also up to date. For example exact same windows uptade version and same forticlient vpn config but one computer can connect but other cannot.
Hello all,we have an Exchange Hybrid setup with all our mailboxes on-prem. We need to let graph send emails via Exchange Online but we would need to relay these emails via our Fortimail appliance. So the Exchange Online environment does not send these itself without going through the Fortimail first. We found this in the cookbook:How to integrate FortiMail into Microsoft 365 | FortiMail Appliance and VM 7.4.0 | Fortinet Document LibraryAnd this technical guideline:Technical Tip: Office365 Secure Relay via FortiMail to avoid unauthorized email relay | CommunityAnd it seems like we can’t let graph talk directly to our on-prem Exchange servers:https://learn.microsoft.com/en-us/graph/hybrid-rest-support So we wondered how does the Technical Tip from fortinet make sure that we are not risking the relaying of unwanted emails. The authenticated part in the technical guideline does not apply here, no? Because our user mailboxes are all on-prem? And regarding the cookbook: our concern is that w
I was doing some troubleshooting today and I kept getting errors when trying to save my DoS policies. Turns out that 7.4 uses the individual interfaces, despite the interfaces being in an SD-WAN zone. In 7.6, all of the DoS policies use SD-WAN zones and NOT the interface. I somehow missed this in any of the release notes, but wanted to mention it hear in case it's giving anyone else problems.
Failed to perform SNMP connect. Please verify that the device can be contacted via ICMP (ping), and that the SNMP credentials are correct.Ping worked, SNMP was enabled on the FortiGate interface, and the SNMPv3 settings matched on both sides. A packet capture on the FortiGate showed UDP 161 requests arriving from FortiNAC, but the FortiGate did not respond.The cause in my case was FortiGate administrator Trusted Hosts. The FortiNAC source IP was not included in the permitted hosts for an administrator account with Trusted Hosts configured. This prevented the SNMP request from being processed, even though it reached the FortiGate.To resolve it:Identify the source IP FortiNAC uses to reach the FortiGate.In System > Administrators, review the accounts with Restrict login to trusted hosts enabled.Add the FortiNAC source IP as an allowed trusted host in all the administartors.Save the change and run Validate Credentials again in FortiNAC.The FortiGate was added successfully after the Tru
Hi guys,I have FortiGate VM 7.6.6 on windows 10 with Hyper V & FortiSwitch 124F 7.6.6I configured Software switch with Fortilink and following this KBi have enabled MAC spoofing on the Hyper V VM networkso when I connect the Fortiswitch to my computer its receiving DHCP, then I authorize it on the FortiGateat first it seems that Fortilink is up and after a few seconds its down and I also no longer have ping to the Fortiswitch this is my interface settings config system switch-interface edit "FortiLink2" set vdom "root" set member "port2" nextendconfig system interface edit "FortiLink2" set vdom "root" set fortilink enable set ip 10.200.0.1 255.255.255.0 set allowaccess ping fabric set type switch set lldp-reception enable set lldp-transmission enable set snmp-index 15 set switch-controller-nac "FortiLink2" set switch-controller-dynamic "FortiLink2" nextendI would appreciate it if someo
I have multiple IPsec site to site VPNs and remote access VPNs but all the tunnel shows in same table and there is not any option to see this is site to site and this is Remote access VPN tunnel.To verify that I need to open every VPN every time and check this is site to site and this is remote VPN.Like there are option in sophos firewall that we can differentiate this is remote and this is site to site.I faces issue multiple time during troubleshooting and every time need to open tunnel and verify that is remote access or site to site
HelloI've been tasked with migrating from a 60E to a 70G.7.4.12 to 7.4.12A backup and a read-only user in the 60E was given to me.I've participated in this procces before but now i'm alone.Any usefull advice?
Hi everyone,Since a few days FW can’t access the servers and we’ve lost our access for a few users (with quota, app and YT supervision). Licenses are up to early 2027.I noted the firmware was coming to EOS on 10/01. I followed the troubleshooting tip on the community and got this result in the cmd prompt:FGD_DNS_SERVICE_LICENSE:server=139.138.105.53:853, expiry=0000-00-00, expired=1, type=0server=173.243.140.53:853, expiry=0000-00-00, expired=1, type=0Thanks for any help.Sylvain
Hi everyone,We are currently facing a weird issue on our network and I'm hoping someone here might be able to point me in the right direction.A few of our employees in the finance and HR department need to access an online UK tax and salary calculation portal for payroll verification.However, whenever they try to open it from their office machines connected behind our FortiGate firewall, the page either fails to load or shows a block/timeout error. Interestingly, it works completely fine on their mobile data or home networks, which confirms the issue is strictly related to our corporate network setup.Here is a quick overview of our current setup:FortiGate Model: FortiGate 100FFirmware Version: FortiOS 7.2Features Active: Web Filtering, SSL Inspection (Deep Inspection), and FortiGuard Categories.I checked the FortiGate Log & Report section under Forward Traffic and Web Filter, but nothing obvious stands out immediately blocking it—though it might be falling under a strict category o
Hello,Our client used to be able to connect to our website but is now blocked since the end of July.The error:Fortinet" wasn't installed properly on your computer or the network. Ask your IT administrator to resolve this issue.NET::ERR_CERT_AUTHORITY_INVALIDPlease install a root certificate for "Fortinet". We recommend your IT administrator read the configuration instructions for "Fortinet" to resolve this issue. Antivirus, firewall, and web filtering or proxy software are among the applications that can cause this issue. What could be the reason? How can we debug it with our client? Thanks
What would cause apple devices running ARD to disappear in network list when there are more devices connected and reappears when there are less devices? This is a FortiAPs/FortiSwitches environment.
I have been running FortiClient 7.4.8 on my endpoints, all of which are Windows 11 devices fully compatible with the FortiClient agent.Recently, I have been experiencing an issue with Google Chrome. Whenever FortiClient requires an update and prompts for a system reboot, after the endpoint restarts, the Chrome configuration appears to be partially reset. It seems as though the browser's local data or cache has been cleared, causing some settings to be lost.The behavior is almost as if Chrome had been reinstalled or its user profile had been recreated after the reboot. The most noticeable impact is that browser extensions lose their configuration and must be set up again.Has anyone else experienced a similar issue with Chrome following a FortiClient update? Does anyone know what could be causing this behavior?I suspect it may be related to the Anti-Exploit feature or possibly the Web Filter browser extension, but I have not been able to confirm the root cause yet.Any insights or recomme
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.