Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fsyong
New Contributor

very bad experience with Fortigate

Just joined a company, the vpn is fortigate 60, os 2.5. after changed some settings can not access the web interface anymore. execute factoryrest, no web access to the interface. reset many times, occasionally use static DHCP setting, the VPN can get ip address for dhcp server and access by web!! after updated the os to MR7. A client complained about the SSL VPN client to Germany. he just used our internet to VPN to Germany. Failed. Can somebody post some pictures out tell how to configure the VPN. Another user complain his voip mobile phone software ( similar to skype) always can not online or maybe just 10mins. Really bad service. No more Fortigate.
14 REPLIES 14
fsyong

Honestly, the device can not be accessed by web after reboot. The ex-tech has the same problem once before, after that he never wants to touch it. I backuped the working configuration before the change. After reset, as I mentioned I can access the web control occasionally, when I changed something like just the ip address even restored backup, after reboot.... no access. After updated the firmware, I have no problem to access the device any more. My concern is the device is defected? Need RMA? I dont want the whole office stop working some day. Since updated the firmware, everybody ignored this issure I had before, just doubt the configurations I created for the new issues like sip or ssl vpn. Till now nobody can explain this to me. So bad. One user using a softphone software from T-system, the software using RTP(30000-3100) SIP 5070 Another user has no admin rights in his computer, I can not check the setting of the SSL-VPN. I have add the port 10443 in custom service, doesnt work. Right now no way to go back, I explained already at that time I just want to make the VPN working ,so everybody can connect to the internet,update firmare was my only chance. So I updated to MR7. some guys recommended MR6, I downgraded. Right now I am using MR6P3. kind new to Fortigate. I have problem to upload images. So I just post out the texts. Status ID Source Destination Schedule Service Profile Action internal(fortigate) -> wan1(AT&T T1) (2) 1 all all always ANY ACCEPT 7 all all always Germany voip ssl-vpn ACCEPT internal(fortigate) -> wan2 (1) 6 all all always ANY unfiltered ACCEPT wan1(AT&T T1) -> internal(fortigate) (2) all all always ANY web ACCEPT all all always Germany voip ssl-vpn ACCEPT custom service group Germany voip ssl-vpn Members: SIP, SSL-VPN to bonn, voip for Erico, Https, Sip-Msnmessenger custom service SSL-VPN to Bonn TCP/1-65535:10443 voip for ERICO TCP/1-65535:30000-31000 UDP/1-65535:5070 Everything was working before the web access problem. Thanks.
Not applicable

This is a common problem man,, i had also the same situation..this is because the firmware corrupted, so even if u reset to factory default, there is no use..so u need to upload the firmware again using the console cable with the help of any tftp.
Not applicable

I had a very similar problem. A Fortigate 60 with V2.5 firmware, that worked for years without problems. Then one day, it stopped working and wouldn' t respond on any of the ports. I contacted fortinet and the first thing they said was ' please upgrade the firmware' At first, I thought ' Hold on a minute, this unit is malfunctioning, you should be helping me, not fobbing me off' . But I did what they said, and the unit is now on the latest firmware, which was quite a long process of gradual upgrades, erasing and restoring of the config several times, but now the unit is working perfectly, even though no specific problem was highlighted. Obviously I can' t explain what caused the problem, in the first place, but the important thing is that it' s working properly now! Andy
FortiRack_Eric
New Contributor III

Firmware version is about 5 years old.... that' s about the stone age in human years.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
abelio

I had a very similar problem. A Fortigate 60 with V2.5 firmware, that worked for years without problems.
Andy, every networking device or software has its lifecycle; if you have not taken measures yet about this and forthcoming issues, maybe this 2006' s note could convince you:
" Fortinet End of Life Announcement 30 April 2006 Fortinet is announcing the end of life of FortiOS 2.5.x. • Fortinet is announcing the end of life of FortiOS 2.5.x on 30 April 2006. • Platforms affected: FortiGate 50A, 60, 60M, 100, 100A, 200, 200A, 300, 300A, 400, 400A, 500, 500A, 800, 1000, 3000, 3600, 5001; FortiWifi 60. • The final date to purchase a new maintenance contract is 30 July 2006. • The final date to extend an existing maintenance contract is 30 July 2008. • The last day of the EOL support period is 30 July 2009. Per terms of the Fortinet EOL policy, software support includes investigating and troubleshooting issues in an attempt to provide solutions and workarounds and may include, at Fortinet’s discretion, bug fixes, new features, or enhancements. If a particular bug fix, new feature, or enhancement is available in a new release, Fortinet will not provide additional software releases as the customer should upgrade to the then most current software release. (Please note that software upgrades may be required to correct certain problems.) Fortinet will provide ongoing subscription services updates for active (non-EOL) software releases and EOL software releases throughout the EOL support period. "
So, would be you comfortable with for example an winNT4 server for instance? regards,

regards




/ Abel

regards / Abel
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors