User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I have set up a site to site VPN on the fortigate 90G with 4 selectors. On the other end is a Cisco ASA device. After all configurations are done and I try to bring up the VPN, the tunnel is coming up but only one selector out of the 4 phase 2 are coming up. I have 2 servers on the local side and there are two servers on the remote side. Each device on my local network is supposed to talk to the each device on the remote side. I have tried to use named addresses, grouped addresses, and the actual IP addresses for the selectors but I’m still getting the same result. I also tried to set the initiator-ts to enabled but this also seems to not help. What seems to be happening is that tunnel is only bringing up the first match of the selector and ignoring the rest leaving them in a down state. I would really appreciate any assistance. It’s been giving a headache for a few days now and I can’t get it to work as it should. I would also like to point out that I do not have access to the cisco d
Hi, I want to make ipip and gre tunnel to mikrotik. on mikrotik side mtu 1420 is set for ipip and 1400 for gre.I have fortios 7.6.7 and can not set mtu on ipip and gre interface directly. how can i do that?
Environment2x FortiGate-VM64-KVM, v8.0.0, build0167 (GA.F) License Status: Invalid (permanent-trial / unlicensed mode — not a normal 15-day FortiCloud eval) Lab topology: two sites connected via two independent ISP paths, each carrying one IPsec VTI tunnel (VTI-A over path 1, VTI-B over path 2), both VTI interfaces as members of a single SD-WAN zonegw-site-01 (192.168.1.2/24) — fw-site-01 (port4: 192.168.1.1/24) — [ISP1/ISP2] — fw-site-02 (port4: 192.168.2.1/24) — gw-site-02 (192.168.2.2/24)VTI-A: 172.16.1.1 (fw-site-01) ↔ 172.16.1.2 (fw-site-02) VTI-B: 172.16.2.1 (fw-site-01) ↔ 172.16.2.2 (fw-site-02)IKEv2, proposal des-sha512 (forced by the eval-mode low-encryption restriction), dhgrp 29, net-device enable. Both tunnels status=up with active SAs (diagnose vpn tunnel list), real traffic counters climbing.GoalSimple: execute ping 192.168.1.1 from fw-site-02, reaching fw-site-01's LAN-facing interface (port4) through the tunnel. Not even LAN-to-LAN — just firewall-to-firewall, locally-
Hello everyone. I am finalizing a FortiSIEM HA migration and am facing significant difficulties in completing the process stably. The goal is to completely decommission Environment 1—currently acting as the primary environment—and promote Environment 2 to take over as the new primary FortiSIEM environment. During the process, I encountered inconsistencies involving Patroni, etcd, PostgreSQL, and node synchronization. Even after reconfiguration, references and records from the previous environment can persist in the cluster, hindering the establishment of Environment 2 as the new Leader and the formation of a stable HA setup. I would like to know if anyone has performed this type of transition and could share their experience—specifically regarding the permanent removal of Environment 1, the promotion of Environment 2 as the new primary environment, the cleanup of old references in Patroni and etcd, HA reconfiguration, and validation steps to preserve the CMDB, database, events, and ser
Hi,I would like to understand whether FortiClientVPNInstaller 7.4.3.4726 requires version 7.4.3.8758 to be installed in order to fix vulnerabilities.I’m using ManageEngine Patch Manager, and it says that I need to upgrade to version 7.4.3.8758. However, I cannot find this version anywhere.
This is a long shot, but I just wanted to check on here to be sure. I’m trying to troubleshoot some devices that are offline in difficult-to-access locations. I tried asking Fortinet tech support, and they said that no such database exists. Just wanted to check here just in case.
Hi!Command "diagnose vpn ipsec status" shows “NP6_0”, “NP6_1”, .., “NPU Host Offloading”, “CP9” and “SOFTWARE” counters.Two questions:Question 1: what are the units of these counters - bytes, packets, traffic sessions, SAs?Question 2: what is “NPU Host Offloading:” and what kind of traffic causes this counter to increment compared to “NP6_0”, “NP6_1”, .., “CP9” and “SOFTWARE”?Thanks!
Hello!I just recently downloaded the Hyper-V image for FortiGate-VM, version 8.The VM boots fine, no issues, the CLI is accessible through SSH.When comes time to apply the evaluation license, it seems to fail (using the “exec vm-license-options” command).On the Web GUI, the evaluation license seems to apply (by logging in with my Fortinet account) but after a reboot, it says “No License” in the system status.Then, in the Web GUI, I login, briefly see the “what’s new” video pop up and then it pops back to the login screen.Any ideas?Thanks!EDIT: I forgot to add that when running “exec vm-license” it requires a token, which I do not have.
Hi everyone,Is it possible to register the FortiClient to EMS Cloud without needing the invitation code. We have more than 300 PCs to install the client and we dont want to enter the invitation to each of them. Bests,FortiEng
This just screwed the complete ip interface config on some of our managed FGT: with FMG 7.4 FOrtinet have changed the behaviour of resolving meta data variables!In 7.2. it primary uses vdom level in provisioning templates and global level in scripts.In 7.4. it primary uses global level everywhere! So be sure to change your per-device-mappings in variables to the global object before you first time deploy the config after you upgraded FMG to 7.4. To me this is a bit strange since Fortinet themselves in the FMG 7.4 release notes say FMG 7.4 is downwards compatible from 7.0 on.In case of variables used in scripts/templates its obviously not.
I have many event like this for cisco ipphone. Are this event say that we can enable device profile using CDP?
Hello everyone,FortiGate devices are documented to support a maximum WAN throughput when all UTP layers are enabled.What happens if you connect a WAN with a higher throughput? Is the WAN throughput throttled? Does the firewall stop providing protection? Does the firewall slow down?Thanks
Is it possible to modify the landing page when you open the client to be the Remote Access Tab with it defaulting to a specific connection? The policy calls a profile that has both IPsec and SSL vpn. Wanted to push users to start using the IPSec connection and would be simpler if they just opened the client to that section rather than having to explicitly select the IPsec vpn connection.
Hi all, I have an intervlan issue with fortinet firmware after upgraded from 7.4.9 to 7.4.11 , Kindly anyone has face issue please support for that
Hi,I am experiencing a FortiToken Mobile activation failure on Android 16 with FortiToken Mobile 6.5.0.0030.The error shown during activation is: "Invalid server certificate - FortiToken Mobile cannot validate the server certificate."I found an older Fortinet Community discussion describing a very similar problem after upgrading to Android 13:FortiToken Mobile cert error on Android 13https://community.fortinet.com/support-forum-92/fortitoken-mobile-cert-error-on-android-13-115185In that thread, the original poster later reported: "Fortinet support said this is bug 765700."Fortinet also documented bug 765700 in the FortiToken Mobile Android 5.2.3 release notes:FTM Android 5.2.3 Known issueshttps://docs.fortinet.com/document/fortitoken/5.2.3/ftm-android-5-2-3-release-notes/999611/known-issuesBug 765700 is described there as: "'Untrusted Certificate' popup throws when activating/completing token transferring or approving/denying Login Requests"Fortinet later listed bug 765700 in the FTM A
I asked for an extra IP from the ISP. For that they had given me /29 IP block.They said that they will work under the old pilot IP which was already given by ISP. That IP was configured WAN1 and internet are working well. But I need to use that additional IP under firewall.Because i am going to host one web application server. For that server i need to configure public IP directly.If it comes under the server means i can able manage and control who are all want access the app server. I am using FG101E.
Hi Guys, My firewall did an update recently from 7.4.9 to 7.4.10 and since then my static routes have stopped working. I have a couple of internal routers that route between different subnets. They were configured a number of years ago, and since then I haven't had any issue with them until now. The routes are very straight forward - Destination (192.168.50.0/24** subnet at other side of router) Gateway (192.168.10.10 router IPt) Interface (LAN) (enabled). Clients gateways are set to the Fortigate device and everything was fine until the update. All clients could reach 192.168.50.x without issue. That's now stopped working. If I add a static route on the clients direct it works fine. So issue is definetly at Fortigate. Also all monitoring of the subnet stop at exact time of update. Tried removing and re-entering/rebooting, just doesn;t want to work. Anyone got a similar issue/fix? Many thanks &n
The FortiClient VPN-only version 7.4.3.4323 has been installed onto a MacBook running macOS 26. Full disk access has been given to fctservctl2 and the network extension FortiTray has been enabled although FortiClientProxy and FortiClientPacketFilter were not present to enable. The settings for this VPN use the public IP address of the FortiGate and various DH Group and encryption levels have been tried but all to no avail. The VPN connection is IPsec VPN and tries connecting for a while then comes back with a connection timeout error. The native IKEv2 client for macOS does not work either. I read somewhere that Fortinet added macOS Tahoe 26 support in FortiClient 7.4.5 but there is no VPN-only version later than 7.4.3. I have also read that SSL-VPN support is being stopped so surely there needs to a new VPN-only version where IPsec VPN can be used. Is there ever going to be a newer VPN-only version released? Or is the option available now FortiClient Standalone? This does not seem to b
I completed the NSE 2 a few years ago. I just checked my profile and I don’t see it in there anymore. Where did it go?
Hello, everyone. We currently have an HA cluster in Active-Active mode in Azure that is load-balanced by Azure Load Balancers.We need to change the HA type to Active-Passive mode and remove the load balancers from the architecture. Is this possible?Does making this type of change require evaluating any additional configuration?I understand that an SDN Connector could be used, but is this specific to Azure or Fortinet? Could this result in an additional “cost” that needs to be paid? Thanks for your comments.
We have a primary Fortigate that is used to control Internet access for several retirement communities across several campuses. We have traffic from all sites Hide-NAT’d to different IPs based on the type of traffic. Guest/public access from all sites get NAT’d to this IP, internal residents get NAT’d to that IP. Internal systems get NAT’d to a different public IP still. This helps when someone on the internal network has a system which has been compromised and is causing one of our public IPs to get blacklisted.However it is still a problem when one of our public IPs gets blacklisted because a system is doing something it shouldn’t. What is the best way on the Fortigate to identify problematic internal systems (particularly spam sources), and block their IP from being allowed public access?
HelloOn FortiGate 30E with FortiOS v6.2.3 build 1066 (GA), the administrator user name and password have been changed.Unfortunatly the credentials have been lost.The default admin account is disabled or deleted.There is no other account.is there a way to recover the administrator access, without losing the configuration?Thanks for your help.Philippe
In DoS Policy » tcp_src_session option.if i set Threshold = 30Is it mean 30 session per 60 seconds ?
We host a Norwegian sports club website that FortiGuard classifies as Malicious Websites, High Risk, "strong confidence of malicious intent". We have submitted it three times through the Web Filter rating request form and each time received the same automated reply keeping the rating, with no evidence given. Hoping someone from FortiGuard Labs can take a look. Domains: kveldeil.no and www.kveldeil.no - both have identical rating history. Rating history, from your own Web Filter Lookup:07 Dec 2016 - added as Malicious Websites29 Mar 2017 - updated as Sports23 Jan 2019 - removed as Sports So the site was flagged in 2016, corrected to Sports in 2017, and in January 2019 the Sports rating was removed, which reverted it to the 2016 entry. There is no detection newer than December 2016 in the history. That suggests the current rating is inherited from old data rather than from anything recently observed. What the site is: Kvelde Idrettslag, an amateur sports club. It runs on our CMS platform
In an Active-Active FGCP cluster, only the primary unit answers ARP requests using the HA virtual MAC address, while subordinate units retain their own physical/real MAC addresses.When the primary load-balances a session to a subordinate unit, could you confirm:Is the packet handed off to the subordinate over the same data/LAN interface (addressed to the subordinate's real MAC), or over the dedicated HA heartbeat link? Since the subordinate never responds to ARP requests, how does the upstream switch learn/populate its MAC table entry for the subordinate's physical MAC — is this purely through standard source-MAC learning when the subordinate transmits traffic (e.g., forwarding the processed packet to its next hop), or is there an additional FortiGate-specific mechanism (e.g., periodic announcement frames) to keep the switch's table populated? Does the subordinate's return/outbound traffic exit directly through its own interface to the destination, or does it always route back through
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.