Mark a Best Answer
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Je demande à tous votre support afin de m’aider à corriger ce problème
I have multiple devices with varying levels of active support, and the inability to unlock the geoIP database is quite inconvenient. There is no method for manual updates, and using external filtering can consume significant memory resources when attempting to restrict access from a large geographical region.I understand the rationale behind conditioning support and updates to the greatest extent possible. Even "evil" major manufacturers like HP, Dell, and Lenovo provide publicly accessible BIOS and firmware updates for older hardware in response to critical security vulnerabilities, while placing non-critical updates behind a paywall. Their objective is to prevent the proliferation of insecure devices under their brand.
Bonjour je n’arrive pas à importer le certificat CA sur fortigate 7.6.7. J’ai généré un certificat par AD CS, que j’essaye d’importer sur fortigate mais je reçois une erreur qui me dit que le format du certificat est incorrect. Je précise que cette CA a servi a signé le certificat SSL de forticlient EMS. C’est dans le cadre d’un lab ZTNA, je veux intégrer forticlient EMS 7.4.8 sur Fortigate. J’utilise des licences d’évaluations.
Hi, When trying to renew the server certificate (or create a new one) using the automated option. I get this error: "EMS Invalid certificate and private key: argument 'data' Cannot convert "<class 'str'>" instance to a buffer. Did you mean to pass a bytestring instead?" EMS 7.4.5 build2111 (Mature) Any ideas on what could be causing this? thanks
I replaced the secondary unit of a FortiMail (3000F) configured in a primary-secondary setup and rebuilt it using the old secondary unit's configuration.Before connecting it to the primary unit, the following entries appeared in the "Mail Event" logs:/var/spool/etc/mail/submit.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail_ec.cf: WARNING: dangerous write permissions/var/spool/etc/mail/sendmail.cf: WARNING: dangerous write permissionsDoes FortiMail use sendmail for email transmission and reception?For the time being, I have connected it to the primary unit, and data synchronization is complete.If the primary unit were to fail in this state, causing the secondary unit (which generated these error logs) to take over as the primary,would email transmission and reception function correctly?I am concerned about this point. Do you have any information regarding these logs?When I tested sending an email via Webmail from this secondary unit,the following entry appeared in
Hii, I am thinking to Write NSE 4 in the upcoming week. So now my doubt is to attend NSE4 exam is it mandatory to complete NSE1, NSE2 and NSE3 Certifications ?? Actually i have Completed my NSE1, NSE2 and NSE3 certifications on 12/Aug/2019. And i heard that NSE1, NSE2 and NSE3 certifications is valid till 2 years. In that case my NSE1,NSE2 and NSE3 certifications got expired. So now is it mandatory to recertify all NSE1, NSE2 and NSE3 certifications and then should attend NSE4 or i can attend the NSE4 exam directly.Kindly please someone update on this .
Hello, I have a specific deployement scenerio in my hand. My customer has a closed circuit production plant. There are handfull of PCs and a lot of cameras, industrial devices, industrial printers...etc. I have no problems with enviromental devices. The problem is this plant has limited internet connection and does not use LDAP. PCs are joined to a domain and configured in HQ. Then send to this plant. My question is: Can I use agent without LDAP integration for doing basic scans for applications and viruswall? Since there are no LDAP, I am thinking of using self signed certificates and trust them manually from client agents. But I still need to login to the agents, which I won't be able to match to an LDAP. I did some researchs, I have some ideas but I was not able to come up with a viable solution. If you guys can steer me to a right direction I will be glad. thanks in advance.#fortinac
I currently block the advertising categories in our DNS and URL Filtering Profiles. We are starting to get a small but increasing number of websites that are blocking access unless we allow access to the Ad network they are using (Screenshot attached below). I am hesitant to allow access to the ad network, however I am getting pressure to do so. What are others thoughts on this. Is it truly a security risk? Is there away to continue to block the ads and allow the website?
Currently testing FAP241K with Fortiswitch 148F-FPOE, Currently Auto transmit power is set to 17 to 20 dBm with target dBm at -70. Not using any DFS channel. Poe mode is high.why is it even with just a single AP, transmit power never goes above 17?To go higher requires setting it to percentage. 100% can go up to 28 dbm, changing it back to auto and it get stuck at 28 dbm. Any ideas?
Hi Fellas,I'm deploying FortiClient EMS 8.0 using Microsoft Intune (Win32 app) and have run into an issue.Environment FortiClient EMS 8.0.x Microsoft Intune (Win32 app) Deployment package generated from EMS with MSI Installer Files enabled EMS generated: forticlient.msi forticlient.mst PackagingBoth files were placed in the same source folder and packaged into a single .intunewin using IntuneWinAppUtil.exe.The install command in Intune is:msiexec.exe /i "forticlient.msi" TRANSFORMS="forticlient.mst" /qn /norestart /L*v "%ProgramData%\Microsoft\IntuneManagementExtension\Logs\FortiClientInstall.log"IssueThe installation completes successfully, but when FortiClient launches, it still displays the "Enter Invitation Code or IP Address" screen.Even when I manually enter the Invitation Code or the EMS IP address, the client does not register with EMS.Additionally, the folder:C:\Windows\FortiEMSInstaller_logsis not created, so there are no EMS installer logs to review.Expected B
Hello community,Product: FortiGate-90GThe device is currently running FortiOS 7.4.7 build 2731.Its FMWR/support contract expired on 11 July 2025.FortiCloud SSO access is currently being blocked with Attack ID 20000021 because the installed FortiOS version is affected by CVE-2026-24858. I would therefore like to update the device to a security-fixed FortiOS release. However, due to the expired support contract, the FortiGate does not permit the upgrade through FortiGuard and the FortiCare portal does not allow me to download the firmware image manually. I am not requesting access to a newer major/minor FortiOS branch. I would like to remain within the existing FortiOS 7.4.x branch and upgrade only to the current security-fixed patch release, preferably FortiOS 7.4.12.Is it possible for the the official FortiOS 7.4.12 firmware image for this FortiGate-90G to be provided, or can someone from this community enable another supported method of upgrading this device to 7.4.12 for security rem
Hi Team,I have completed NSE1 and NSE2, currently completing NSE3.I need to achieve FCF and FCA certificates but unable to find it anywhere.Can you please advise where/how to find FCF and FCA enrolment, exam, and certificates?
Hi everyone, I'm Sarah, just joined this community. We've been running a site-to-site VPN on FortiGate and occasionally notice intermittent drops, especially during peak traffic hours. Has anyone tuned specific settings (dead peer detection, keepalive intervals) to make tunnels more stable? Would appreciate any troubleshooting tips before opening a support ticket.
FortiGate-VM64-HV Trial Issue on Hyper-VPlatform:- Hyper-V (Server 2019) Gen 1 virtual machine- FortiGate-VM64-HV v8.0.1 build0245 (GA.F)- Trial LicenseIssue:The trial license activation completed successfully and the CLI shows "License Status: Valid". However, after logging into the web GUI, I logged out immediately.CLI access works normally.Network Connectivity:- Can ping 8.8.8.8 successfully- Default route configured via 192.168.1.254 on port1Relevant Output:FGT-VM64-HV-NZVQOU # get system statusVersion: FortiGate-VM64-HV v8.0.1 build0245 (GA.F)First GA patch build date: 260421Current Security Level: HighFirmware Signature: certifiedLicense Status: ValidVM Resources: 1 CPU/1 allowed, 1694 MB RAM/2048 MB allowedHostname: FGT-VM64-HV-NZVQOUOperation Mode: NATCurrent virtual domain: rootMax number of virtual domains: 10Virtual domains status: 1 in NAT mode, 0 in TP modeCurrent HA mode: standaloneBranch point: 0245Release Version Information: GAFortiOS x86-64: YesRouting Table:S* 0.0.0.
Hello Fortinet Community,I have installed FortiGate-VM64 FortiOS 8.0.0 in my EVE-NG lab environment.The FortiGate VM boots normally, and I am able to access the GUI login page.Current IssueI can successfully enter my credentials and the GUI appears to authenticate successfully. However, immediately after login, I am logged out and redirected back to the login page.In other words:Open FortiGate GUI. Enter username and password. Authentication appears successful. GUI starts to load. Immediately after that, the session is terminated and I am returned to the login screen.EnvironmentPlatform: EVE-NG Device: FortiGate-VM64 FortiOS: 8.0.0 Build: 0167 Image: FGT_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvm.zip Deployment: KVM/EVE-NGLicense StatusThe FortiGate license is showing Up to Date / Active, so there does not appear to be an obvious licensing issue.What I have checkedFortiGate VM is booting normally. GUI is reachable. Username/password are accepted. License status shows up to date. The
Hi,What issues could there be in a split-brain scenario? I realize the raw logs sync wouldn't be a problem, but what about configs? For instance, an admin adds some devices to one node while another admin adds new devices to the other node. How can the Geo-redundant HA reconcile those changes? Can that damage Analyzers and Collectors?
I am experiencing an issue when connecting to the IPsec Dial-Up VPN from a Linux virtual machine using strongSwan.Once the VPN connection is established successfully, the Linux VM loses its Internet connectivity. However, the same IPsec Dial-Up VPN connection works correctly on Windows machines, where Internet access remains available after the VPN is connected.
Customer has a 60E - i have config backup from 60E - don’t have access to 60E registered account ( ????@datec.com.fj ); have a new 70G ( registered by me to ????@nivismotors.com.fj who is the owner/customer ) - why is it so difficult to get support to assist to convert my 60E config, and import “new” config into 70G via forticonverter. I sent time today with both customer & technical support via chat, and neither is able to assist to resolution. Going forward why should i advise customers to stay with FG
Hi all,Due to SSL VPN no longer being supported in newer FortiOS versions, we’re migrating our FortiClient remote-access VPNs from SSL VPN to IPsec Dial-Up.Our SSL VPN setup is used by our team, partners, etc., and authentication is done via Azure SSO. I created an IPsec Dial-Up tunnel using local FortiGate authentication and it works fine. However, when I switch to SSO authentication, it fails. (go to the online login page but fails in the end). Before I lose too much hair on this migration 😅, I’m trying to understand whether IPsec Dial-Up can really reproduce our current SSL VPN setup.Main questions:Azure SSO: Is SSO supported for IPsec Dial-Up in the same/similar way as SSL VPN? Different IP pools per group: Can each user group get its own client IP range? No RADIUS: The “Assign IP from User Group” option seems to require RADIUS. Is there another way without deploying a RADIUS server? Split tunneling: With SSL VPN, access is mainly controlled by firewall policies. With IPsec, it l
We have become aware of the following security advisories regarding a vulnerability in FortiClient:https://fortiguard.fortinet.com/psirt/FG-IR-26-156https://advisories.ncsc.nl/2026/ncsc-2026-0296.htmlWithin our organization, we exclusively use FortiClient VPN-only for Windows. We do not use the full FortiClient client or FortiClient EMS.Therefore, we would like to know whether the vulnerability described in FG-IR-26-156 also affects the FortiClient VPN-only client.Additionally, we would appreciate clarification on the following:* Is FortiClient VPN-only affected by this vulnerability?* If so, which versions are affected?* Which version does Fortinet recommend installing to address the vulnerability?* Is an updated version of FortiClient VPN-only currently available?* Does the VPN-only client update automatically, or do we need to manually deploy the updated version to all our laptops?We would appreciate your clarification so that we can take the appropriate measures if necessary.Kind r
I’m currently preparing for NSE 4 on FortiOS 7.6, and one thing I’ve noticed is that going through the study material and actually being able to troubleshoot a FortiGate scenario are two very different things.So I wanted to hear from people who have recently prepared for or passed the exam.What helped you the most?Hands-on FortiGate labs Fortinet Training Institute material Fortinet documentation and KB articles Practice questions CLI troubleshooting Real-world troubleshooting scenariosPersonally, I’ve found that combining the official material with hands-on practice makes it much easier to understand where the gaps are.For those who have already taken NSE 4, how did you balance theory and hands-on practice, and what would you recommend spending more or less time on?
Hello everyone,Since this morning, multiple clients across our network have simultaneously started receiving virus warnings from FortiClient. The legitimate Windows printer component splwow64.exe is being flagged.Here are the exact details of the alert: Process/Object: C:\Windows\splwow64.exe Virus Name: FSA/RISK_HIGH//2000002004 Status: Files could not be quarantined To rule out an actual file-based infection, we verified the system file on the affected endpoints: The Microsoft signature is intact (Get-AuthenticodeSignature returns the status Valid). A local SFC scan (sfc /verifyfile=C:\Windows\splwow64.exe) reports no integrity violations. The file on disk is undamaged. The SHA256 hash of the file is BC7412A5EF6D1B32F7032E1008A324006B19C5A5CE4D27BC8D26DFD6BD7EDB0E. Checking this hash on VirusTotal currently shows 0/71 detections. Since the file itself is cryptographically clean and unmodified on the disk level, we strongly suspect this is a false positive caused by a recent p
Does anyone know if the new exam is using Enteroruse Firewall Admin questions?NSE library has enterprise firewall admin and sdwan modules but nothing that lines up with name Network security architect or is it a whole new exam with both modules combined?
We are a new customer running FC 7.4.8 on 400+ Tahoe 26.6 Macs. We need to verify if Macs can be auto-updated from our EMS (Example: When 7.4.9 drops, can our Macs get updated silently/automatically like other popular VPN/Security solutions)? I'm unable to find any official documents on this.
Has anyone run into this error when registering FortiClient to EMS Cloud using Google Workspace SAML?Error: 403 - app_not_configured_for_userEnvironment:FortiClient EMS Cloud Google Workspace SAML authentication FortiGate 90G HA pairAlready verified:User access set to ON for all users in Google Admin Attribute mapping is correct ACS URL and Entity ID match between EMS and Google SAML app Not in test modeStill getting the 403 on registration. Anyone else hit this and found a fix?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.