User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hello everyone,I’m looking for the best way to review configurations and rules on FortiGate Firewall and FortiWeb. Are there any tools available for this, or benchmarks to follow?Any suggestions would be greatly appreciated!Thank you!
Our company is transitioning from SSL-VPN to ZTNA. We currently have Microsoft conditional acess policies allowing certain public IP addresses configured for SSL VPN allowing the public IP of the VPN firewall. Is there anyway for this to work with ZTNA? Currently, the microsoft logs are showing the public IP of individual users instead of the firewall.
I’ve been straining my brain for weeks on this. It seems like it should be so simple. Is anyone aware of any bugs with Remote IPSEC VPN and 8.0? I have followed this documentation but i’m obviously missing something. I’m attempting to use the Forticlient cert (i was doing my internal pki, but found to check EMS tags i needed to present the EMS cert) and i keep getting hung up here:[1742] fnbamd_auth_session_done-Session done, id=84988985766011[1209] __fnbamd_cert_auth_run-Exit, req_id=84988985766011[1785] create_auth_cert_session-fnbamd_cert_auth_init returns 0, id=84988985766011[1698] auth_cert_success-id=84988985766011[1321] fnbamd_cert_auth_copy_cert_status-req_id=84988985766011[1329] fnbamd_cert_auth_copy_cert_status-Matched peer user 'Remote-Employee_peer'[1458] fnbamd_cert_auth_copy_cert_status-Cert st 210, req_id=84988985766011[356] fnbamd_comm_send_result-Sending result 0 (nid 672) for req 84988985766011, len=2776[360] fnbamd_comm_send_result-Failed send reply (2788, errno 101)
Bonjour,Impossible de charger une licence d’essai dans GNS 3 au dessus de la version 7.0.12, apparemment Forti ne laisse plus faire.Est-ce que quelqu’un aurait cette image FGT_VM64_KVM-v7.0.12.M-build0523-FORTINET.out.kvm.qcow2 ou une version inférieure ?Merci de votre réponseMike.
We currently have a FortiGate firewall running FortiOS version 7.2.11, and we are planning to upgrade the firmware to a recommended and supported version.Could you please share the recommended FortiOS version for our firewall model, along with the correct and supported upgrade path from FortiOS 7.2.11?
In environments where Layer‑2 connectivity extends between remote sites (bridges, wireless links, Metro‑Ethernet, VLAN trunks, etc.), a standalone FortiSwitch may be automatically discovered and adopted by a remote FortiGate acting as a Switch Controller.This can lead to: Unexpected FortiLink activation Automatic VLAN deletion Port configuration changes Hostname changes Loss of local switch configuration This behavior occurs because the FortiSwitch sends CAPWAP discovery packets by default, and any reachable FortiGate may respond and adopt the switch.ScopeFortiSwitchOS 7.6.x and above Standalone FortiSwitch (not intended to be managed by FortiGate)ProblemEven with the following settings: config switch global set auto-fortilink-discovery disable set auto-isl disableendconfig switch physical-port edit <port> set lldp-profile default nextendThe FortiSwitch may still be adopted by a remote FortiGate. This happens because CAPWAP discovery remains enabled. So
Hi AllI would like to know if there is a method to export FGT Policies into Excel (csv) format.Please advise any available options. Am using FortiOS v7.4.12 Many thanks
HI FNAC adminsFortiNAC-F 7.2.9.I have this scenario:A new AD users (not added to FNAC yet) connects to SSID managed by FNAC from a client having NAC agent FNAC adds it automatically to user DB (created from RADIUS connection) , and it adds it not as “Loaded from Directory”, but just like local user, and remains the same even after AD sync As it didn’t add it as “Loaded from Directory” it doesn’t match my UHP neither my access policy, so it is dropped in isolation So I have to remove the user manually and let it created by LDAP automatically after sometimeMy question:Is there a way to force AD user override existing user created from RADIUS connection Otherwise is there a way just to preload all ad users to FNAC user DB even before any user connects Or any other flexible/automatic solution
mailfilterd stuck at ~100% CPU, FortiMail 8.0.0 build 183 — cause unclearFortiMail 8.0.0 build 183. mailfilterd sits at ~99.8% CPU continuously (not a spike), RSS grown to ~1.5GB (baseline is usually ~100MB). All other processes idle. Session count (24–50) and bandwidth are normal, so it's not a traffic flood.Enabled diagnose debug application mailfilterd level 8 + duration 30 and pulled the Trace Log. The only thing logged for 10 minutes was:FmailAIClient.cpp:931:ping():entryrepeating once a minute, on a single thread, with no other activity captured — looks like a routine heartbeat, not the actual hot path.I can't figure out what's actually causing the 100% CPU. Any help would be appreciated.
Hello i want to know the correlation latency for fortiSIEM 2200G because i cant seem to find it anywhere mentioned in the documentatios
We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document LibraryThat last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registrat
Hi Team,We currently restrict our FortiGate SSL VPN access to users connecting from the UAE region using GeoIP restrictions.However, some vendors are based in Egypt and may RDP into their office PC located in the UAE, and then establish the FortiClient VPN connection from that UAE PC.Is there a way to configure FortiClient EMS to restrict VPN access based on the client’s public IP or location, so that if the actual client is connecting from outside the UAE, the VPN connection is denied?Any recommended configuration or best practice would be appreciated.
Hi Community,I’m experiencing performance issues with FortiAP FAP-231G and would appreciate some advice from anyone who has deployed this model in a high-density environment.When the AP has more than approximately 30 clients connected, especially during Microsoft Teams meetings, I experience the following: Some clients are unexpectedly disconnected from the FAP-231G. Clients are sometimes forced to roam/reconnect to a much farther AP, even though the FAP-231G appears to have good signal strength. The issue is more noticeable during Teams meetings and other traffic-intensive activities. With fewer clients, the AP appears to perform normally.I would like to understand whether this could be related to FAP-231G capacity, radio configuration, client load balancing, roaming thresholds, airtime utilization, or FortiAP/FortiGate configuration.My environment is using FortiGate-managed FortiAPs.Has anyone experienced similar behavior with the FAP-231G? If so:1. What is the recommended number of
I am using FortiNAC-CA / FortiNAC-OS v7.6.5.0815 (GA) together with a FortiGate and I would like to implement a daily Internet usage limit for self-registered guest users.My requirement is:Guest connects to the Guest Wi-Fi. Guest self-registers through the FortiNAC captive portal. After successful authentication, the guest receives Internet access. The guest is allowed a maximum of 1 hour of Internet access per day. After the 1 hour is consumed, Internet access should be blocked automatically. The guest should not be able to regain access by disconnecting/reconnecting or registering again. After the daily 24-hour reset, the same user/device should receive another 1 hour of access. Ideally, the limitation should be based on the user or device/MAC address, so creating another self-registration session does not bypass the limit.I understand that FortiNAC has Account Duration and Reauth Period, but from the documentation it appears that Account Duration is not a recurring daily quota. For
Hi,I am experiencing a FortiToken Mobile activation failure on Android 16 with FortiToken Mobile 6.5.0.0030.The error shown during activation is: "Invalid server certificate - FortiToken Mobile cannot validate the server certificate."I found an older Fortinet Community discussion describing a very similar problem after upgrading to Android 13:FortiToken Mobile cert error on Android 13https://community.fortinet.com/support-forum-92/fortitoken-mobile-cert-error-on-android-13-115185In that thread, the original poster later reported: "Fortinet support said this is bug 765700."Fortinet also documented bug 765700 in the FortiToken Mobile Android 5.2.3 release notes:FTM Android 5.2.3 Known issueshttps://docs.fortinet.com/document/fortitoken/5.2.3/ftm-android-5-2-3-release-notes/999611/known-issuesBug 765700 is described there as: "'Untrusted Certificate' popup throws when activating/completing token transferring or approving/denying Login Requests"Fortinet later listed bug 765700 in the FTM A
Currently, the FortiGate 60F is experiencing an inconvenience when there is an electrical power outage and the equipment starts operating using the UPS.When the power change is produced, the FortiGate apparently falls down and stops allowing network traffic, both incoming and outgoing.The way it has been used to restore the service is to physically disconnect the FortiGate and reconnect it to electrical power. After carrying out this procedure, the equipment normally starts correctly and allows network traffic again.However, on one occasion the FortiGate did not start correctly even after disconnecting and connecting it again, which increases concern about the cause of the problem.
Hi, Has anyone had any luck getting FortiClient vpn working on Tahoe? so far iv had 0 success .All windows based clients work fine however
nslookup v4-aws.api.intuit.com 96.45.45.45Server: dns1.fortiguard.netAddress: 96.45.45.45*** dns1.fortiguard.net can't find v4-aws.api.intuit.com: Server failednslookup v4-aws.api.intuit.com 96.45.46.46Server: dns2.fortiguard.netAddress: 96.45.46.46*** dns2.fortiguard.net can't find v4-aws.api.intuit.com: Server failed
Hello everyone! Recently we upgraded our Fortigate (120G HA Active-Passive cluster) from 7.2.11 to 7.4.11, and different problems started to occur.Some users spontaneously lose access to the Internet with ERR_TUNNEL_CONNECTION_FAILED (we use explicit proxy with Kerberos authentication and deep ssl inspection). It happens at random times and with random users, lasts usually up to 2-3 minutes, then works as usual.FortiGates started to randomly reboot with the message "Fortigate had experienced an unexpected power off!", there's no CPU/RAM issue, usually mem is around 40%, and proc is around 10-12%. Due to fast HA failover users don't feel the interruption, but it's definitely not a good sign. Before the update both NGFW had worked for 367 days.Anyone experienced similar issues? Any workarounds? Or should I just be rolling back to 7.2.11?Any advice and help will be appreciated. Thank you in advance!
ScenarioEnvironment with multiple FortiGate firewalls connected to a FortiAnalyzer VM for centralized log collection and analysis.Environment VersionsFortiAnalyzer VM: 7.4.11FortiGate: 7.2.13Fabric ADOM enabledSome FortiGate devices operating in HA cluster modeAfter upgrading the FortiAnalyzer from version 7.4.6 to 7.4.11, the FortiGate devices stopped displaying FortiAnalyzer logs directly from the FortiGate GUI.SymptomsWhen accessing logs from the FortiGate GUI:Log & Report → Forward Traffic / Event Logsthe page remained completely blank.However:FortiAnalyzer continued receiving logs normallyDevices remained online in Fabric View / Device ManagerLogs were visible directly in the FortiAnalyzer GUINo explicit communication or authorization errors were displayedAdditionally, the following behaviors were observed:Analytics (actual/config days) above 100%Archive Usage above 90%diagnose dvm device list showing:conn: unknownconf: unknowndev-db: unknownThis initially suggested a possible
Hi everyone,I’m planning to migrate from SSL VPN to IPsec VPN. Here’s the situation:The FortiClient app is already installed on users’ devices, and I need a way to deploy the IPsec VPN profile to those devices via Intune (all devices are managed by Intune).I’m currently using the VPN-only version of FortiClient, and as far as I know, deploying VPN profiles centrally requires an EMS license.Could you please advise if there’s any alternative solution in this case?Thanks
i have newly created VIP rule to publish local microsoft dynamic test server to the internet to access anywhere, but the vip rule not hit any packets.attached the rule screenshot and policy, any help from the community team would be appreciated
I have a VIP IP address defined on my Fortigate Firewall, and I'm using Cloudflare with a proxy enabled. When I log the source on the firewall, I only see the Cloudflare IP address. Is it possible to see the incoming VIP traffic as if it were the real IP address?
Hi,I would like to know if anyone else is experiencing similar issues with FortiEndpoint EMS Cloud and the integrated FortiEDR feature.Our environment is currently running:FortiClient EMS Cloud: 7.4.7 build 2194 (Mature) FortiClient: 7.4.7 Windows 11 25H2: Build 26200.8875 FortiEDR Engine assigned by EMS: 5.2.8.0044Originally, we noticed that some endpoints using the same EMS policies and profiles had FortiEDR working and connected, while others showed FortiEDR Disabled in FortiClient and Disconnected in FortiEDR Cloud.Both working and affected endpoints are operating in the same environment and network, which makes the different behavior seem questionable. We are also seeing the same issue on endpoints in customer environments, so it does not appear to be limited to a single device or network.We also tested multiple FortiClient versions, including 7.4.4, 7.4.5, and 7.4.6, but the behavior remained the same.On affected endpoints, the Collector reported:FortiEDR Detected incompatible ma
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.