User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
HelloOn FortiGate 30E with FortiOS v6.2.3 build 1066 (GA), the administrator user name and password have been changed.Unfortunatly the credentials have been lost.The default admin account is disabled or deleted.There is no other account.is there a way to recover the administrator access, without losing the configuration?Thanks for your help.Philippe
I am using FortiNAC-CA / FortiNAC-OS v7.6.5.0815 (GA) together with a FortiGate and I would like to implement a daily Internet usage limit for self-registered guest users.My requirement is:Guest connects to the Guest Wi-Fi. Guest self-registers through the FortiNAC captive portal. After successful authentication, the guest receives Internet access. The guest is allowed a maximum of 1 hour of Internet access per day. After the 1 hour is consumed, Internet access should be blocked automatically. The guest should not be able to regain access by disconnecting/reconnecting or registering again. After the daily 24-hour reset, the same user/device should receive another 1 hour of access. Ideally, the limitation should be based on the user or device/MAC address, so creating another self-registration session does not bypass the limit.I understand that FortiNAC has Account Duration and Reauth Period, but from the documentation it appears that Account Duration is not a recurring daily quota. For
dear im going to deployed FortiAuthenticator as external captive portal , guest user will connect to Aruba WLC please guide me to achieve this
Hi AllI would like to know if there is a method to export FGT Policies into Excel (csv) format.Please advise any available options. Am using FortiOS v7.4.12 Many thanks
mailfilterd stuck at ~100% CPU, FortiMail 8.0.0 build 183 — cause unclearFortiMail 8.0.0 build 183. mailfilterd sits at ~99.8% CPU continuously (not a spike), RSS grown to ~1.5GB (baseline is usually ~100MB). All other processes idle. Session count (24–50) and bandwidth are normal, so it's not a traffic flood.Enabled diagnose debug application mailfilterd level 8 + duration 30 and pulled the Trace Log. The only thing logged for 10 minutes was:FmailAIClient.cpp:931:ping():entryrepeating once a minute, on a single thread, with no other activity captured — looks like a routine heartbeat, not the actual hot path.I can't figure out what's actually causing the 100% CPU. Any help would be appreciated.
Hi,I am experiencing a FortiToken Mobile activation failure on Android 16 with FortiToken Mobile 6.5.0.0030.The error shown during activation is: "Invalid server certificate - FortiToken Mobile cannot validate the server certificate."I found an older Fortinet Community discussion describing a very similar problem after upgrading to Android 13:FortiToken Mobile cert error on Android 13https://community.fortinet.com/support-forum-92/fortitoken-mobile-cert-error-on-android-13-115185In that thread, the original poster later reported: "Fortinet support said this is bug 765700."Fortinet also documented bug 765700 in the FortiToken Mobile Android 5.2.3 release notes:FTM Android 5.2.3 Known issueshttps://docs.fortinet.com/document/fortitoken/5.2.3/ftm-android-5-2-3-release-notes/999611/known-issuesBug 765700 is described there as: "'Untrusted Certificate' popup throws when activating/completing token transferring or approving/denying Login Requests"Fortinet later listed bug 765700 in the FTM A
I struggle to understand why this dataset query shows no result on my FortiAnalyzer instance:SELECT dstport, srcip, dstipFROM $logWHERE $filter AND ipstr(dstip) IN ('172.31.11.80', '172.31.11.83')GROUP BY srcip, dstip, dstportORDER BY dstport, srcipTo be sure, I am getting results if in the Log View I search for: dstip=172.31.11.80 or dstip=172.31.11.83Any hint?
i Download VM Forti 8 and istall it but license invalid
Hi everyone,We are currently using ExtremeCloud IQ Connect Cloud to centrally manage our Access Points.Our current environment has the following characteristics:We are using ExtremeCloud IQ Connect Cloud for centralized AP management. The cloud platform centrally manages the Access Points. SSIDs and VLANs are configured and managed through the cloud platform. There is no on-premises Wireless Controller deployed in the environment. ExtremeCloud IQ Connect Cloud does not provide a dedicated Management IP that can be directly added to FortiNAC as a network device. We have tested adding an individual AP to FortiNAC using the AP's Management IP. FortiNAC was able to connect to the AP and retrieve information such as the SSID.We would like to clarify the following points:Can ExtremeCloud IQ Connect Cloud be directly integrated with FortiNAC, or is it necessary to add/manage each individual AP in FortiNAC? If individual APs need to be added to FortiNAC, can FortiNAC control client access base
In an Active-Active FGCP cluster, only the primary unit answers ARP requests using the HA virtual MAC address, while subordinate units retain their own physical/real MAC addresses.When the primary load-balances a session to a subordinate unit, could you confirm:Is the packet handed off to the subordinate over the same data/LAN interface (addressed to the subordinate's real MAC), or over the dedicated HA heartbeat link? Since the subordinate never responds to ARP requests, how does the upstream switch learn/populate its MAC table entry for the subordinate's physical MAC — is this purely through standard source-MAC learning when the subordinate transmits traffic (e.g., forwarding the processed packet to its next hop), or is there an additional FortiGate-specific mechanism (e.g., periodic announcement frames) to keep the switch's table populated? Does the subordinate's return/outbound traffic exit directly through its own interface to the destination, or does it always route back through
We currently have a FortiGate firewall running FortiOS version 7.2.11, and we are planning to upgrade the firmware to a recommended and supported version.Could you please share the recommended FortiOS version for our firewall model, along with the correct and supported upgrade path from FortiOS 7.2.11?
Hello Fortinet Community,We are currently experiencing an issue where users connecting through the FortiClient IPsec remote-access VPN do not receive their email OTP.Environment:FortiGate model: FortiGate 100F FortiOS version/build: v7.6.7 build3704 (Mature) VPN type: IPsec remote-access VPN Two-factor authentication: Email OTP Email service: fortinet-notifications.com Issue started: September 4–5, 2026 Impact: Multiple/all VPN usersThe VPN authentication process reaches the stage where the user is waiting for the email OTP, but no OTP email is received. This configuration was previously working normally.We enabled the following debug commands:diagnose debug resetdiagnose debug console timestamp enablediagnose debug application fnbamd -1diagnose debug application alertmail -1diagnose debug enableThe certificate authentication shown in the debug completes successfully with:Cert status: GOOD auth_cert_successHowever, we did not see an AuthCode being generated or an SMTP connection initia
Hi Team,I am facing an issue with my FortiGate VM running in my lab environment and would appreciate any guidance.Environment:FortiGate VM Image: FortiGate-VM64-KVM v6.2.3 EVE-NG installed on VMware Workstation License: Evaluation (Evolution) license installed via GUIIssue:The FortiGate VM was working normally before installing the evaluation license. After uploading and applying the license through the GUI, the VM initiated a reboot.Since then, the VM has been unable to boot successfully. Instead, it continuously crashes with a kernel panic (double fault) during startup and enters a reboot loop.Below is the console output:FortiGate-VM64-KVM #FortiGate-VM64-KVM # Requesting FortiCare Trial license, proxy:(null)The system is going down NOW !!Please stand by while rebooting the system.Restarting systemPANIC: double fault, error_code: 0x0Kernel panic - not syncing: Machine halted.CPU: 0 PID: 1 Comm: initXXXXXXXXXXX Tainted: P 4.19.13 #1Hardware name: Bochs Bochs, BIOS Boc
We host a Norwegian sports club website that FortiGuard classifies as Malicious Websites, High Risk, "strong confidence of malicious intent". We have submitted it three times through the Web Filter rating request form and each time received the same automated reply keeping the rating, with no evidence given. Hoping someone from FortiGuard Labs can take a look. Domains: kveldeil.no and www.kveldeil.no - both have identical rating history. Rating history, from your own Web Filter Lookup:07 Dec 2016 - added as Malicious Websites29 Mar 2017 - updated as Sports23 Jan 2019 - removed as Sports So the site was flagged in 2016, corrected to Sports in 2017, and in January 2019 the Sports rating was removed, which reverted it to the 2016 entry. There is no detection newer than December 2016 in the history. That suggests the current rating is inherited from old data rather than from anything recently observed. What the site is: Kvelde Idrettslag, an amateur sports club. It runs on our CMS platform
In DoS Policy » tcp_src_session option.if i set Threshold = 30Is it mean 30 session per 60 seconds ?
Hello, I am testing dynamic MAP-E connectivity on a FortiGate-100F running FortiOS 8.0.0 build 0167. The Internet service is So-net over the NTT East FLET'S network in Japan. The VNE service appears to be JPIX “v6 Plus.” DHCPv6-PD is working. The FortiGate receives a /56 delegated prefix and the WAN interface receives an IPv6 address derived from that prefix. The relevant WAN configuration is: config system interface edit "x1" set mode dhcp set role wan config ipv6 set ip6-mode delegated set dhcp6-prefix-delegation enable set ip6-delegated-prefix-iaid 1 set ip6-upstream-interface "x1" set ip6-subnet ::1/64 config dhcp6-iapd-list edit 1 set prefix-hint ::/56 next end end nextend After applying this configuration, the VNE diagnostic correctly recognizes the delegated prefix and WAN IPv6 address: end user ipv6 prefix: 240b:10:xx
Hey everyone, i'm sure the answer always depends but wondering who uses DARRP vs manual channel configuration. I've been using DARRP for a few years now and it works 'fine', but I have noticed sometimes it will over saturate a channel instead of using different ones. We typically reboot the AP and it will pick a different channel and things are fine. I've considered moving to a manual config. The only reason I don't is the obvious, it's manual and would love for DARRP to just work. For a scope we a few campuses and about 250APs.
https://fortiguard.fortinet.com/psirt/FG-IR-26-156FG-IR-26-156 (CVE-2026-70465) advisory states the fix is available in FortiClient Windows 7.4.4 / 7.2.12 and later. However, the free VPN-only agent has not received a new release since 7.4.3 (per the community note that v7.4.4–7.4.8 include no new free VPN-only build).Could you confirm: 1. Is FortiClient Free VPN-only 7.4.3 (build 4726) vulnerable to CVE-2026-70465? 2. If yes, will a patched free VPN-only build be released, or is upgrading to a licensed version the only path to remediation? Thanks in advance.
Hello,We are using the free FortiClient Windows VPN-only agent, version 7.4.3.Regarding Fortinet PSIRT advisory FG-IR-26-156 / CVE-2026-70465, the advisory lists FortiClient Windows 7.4.0 through 7.4.3 as affected and recommends upgrading to 7.4.4 or later. However, the FortiClient Windows release notes state that versions 7.4.4 through 7.4.7 do not include a new release of the free VPN-only agent, and that users can continue using the 7.4.3 free VPN-only agent. Could a Fortinet representative please clarify the following?Is the latest available free FortiClient Windows VPN-only 7.4.3 build affected by CVE-2026-70465? References:FG-IR-26-156: https://fortiguard.fortinet.com/psirt/FG-IR-26-156FortiClient 7.4.7 release notes: https://docs.fortinet.com/document/forticlient/7.4.7/windows-release-notes/683433/special-notices This is a request for clarification of the public PSIRT advisory’s impact and remediation path for the free VPN-only edition
I mean, they are easily powerful enough and fit out usecase. No technical problem at all but they were released in 2019 and go eol September 2031. It does not sound clever to me to lose more than half of its lifespan.
We are testing FortiClient WebFilters and we are trying to test incognito mode extensions. It works on Windows browsers, but not macOS. Windows users get a pop-up asking to approve the new extension. (see example).None of my browsers have any FC extensions. Does this work on macOS?Bonus question: Can this pop-up be suppressed?
The FortiClient VPN-only version 7.4.3.4323 has been installed onto a MacBook running macOS 26. Full disk access has been given to fctservctl2 and the network extension FortiTray has been enabled although FortiClientProxy and FortiClientPacketFilter were not present to enable. The settings for this VPN use the public IP address of the FortiGate and various DH Group and encryption levels have been tried but all to no avail. The VPN connection is IPsec VPN and tries connecting for a while then comes back with a connection timeout error. The native IKEv2 client for macOS does not work either. I read somewhere that Fortinet added macOS Tahoe 26 support in FortiClient 7.4.5 but there is no VPN-only version later than 7.4.3. I have also read that SSL-VPN support is being stopped so surely there needs to a new VPN-only version where IPsec VPN can be used. Is there ever going to be a newer VPN-only version released? Or is the option available now FortiClient Standalone? This does not seem to b
We received a notification last Friday regarding the need to upgrade our FortiEMS system. As per the schedule, we initiated the upgrade on Saturday at 1:00 AM.However, since Monday, we have been unable to access FortiEMS. The system continuously displays an "upgrade in progress" status, and refreshing the browser every 10 minutes has not resolved the issue.
We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document LibraryThat last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registrat
Hi everyone,We would like to ask for assistance regarding CVE-2024-21762 on a FortiGate FG-100F currently running FortiOS 7.2.8.Our customer is requesting us to remediate this security vulnerability.Could anyone please confirm whether FortiOS 7.2.8 has already addressed CVE-2024-21762?If not, what is the recommended action and remediation procedure to fix this vulnerability?This is an important security issue and needs to be addressed as soon as possible. Any official guidance or recommendations would be greatly appreciated.Thank you for your support.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.