Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fsyong
New Contributor

very bad experience with Fortigate

Just joined a company, the vpn is fortigate 60, os 2.5. after changed some settings can not access the web interface anymore. execute factoryrest, no web access to the interface. reset many times, occasionally use static DHCP setting, the VPN can get ip address for dhcp server and access by web!! after updated the os to MR7. A client complained about the SSL VPN client to Germany. he just used our internet to VPN to Germany. Failed. Can somebody post some pictures out tell how to configure the VPN. Another user complain his voip mobile phone software ( similar to skype) always can not online or maybe just 10mins. Really bad service. No more Fortigate.
14 REPLIES 14
FortiRack_Eric
New Contributor III

You the kind of guy that buys a car takes the engine apart and rebuild it and if it' s not working blames the car manufacturer?

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
fsyong
New Contributor

What? We purchased service contract with Fortigate since 2004. The tech replied emails after 1-2days, called them, they said you need go website get a ticket, then the tech will response!! Remember: Reset to default should let you access to 192.168.1.99 anytime. Remember: Since we bought the item since 2004, kind of old but we paid money for the warranty!!! Do you have such experience like whole company users have internet problem and vendor no response?
Not applicable

it seems i have been met such problems
fsyong
New Contributor

Thanks for your reply. I can not remember what kind of setting I made, maybe just add new account, definetly no firewall rules applied. when you use the console to execute a factory reset, you know what I mean, Factory reset means nothing applied, you should connect to the 192.168.99. nothing to do with my configurations, just factory default!! dont suspect my experince in setting IP MASK,cabling. But infact you can not ping from console to outside, you can not ping from outside to the interface. you also can switch to dhcp mode ,and get ip address from dhcp server but same message: network unreachable.... Everybody told me use TFTP, network unreachable how can you connect to TFTP server. Strange things : I used mode dhcp, the fortigate can get the ip address from my dhcp server, but still can not ping in/out. 1 time I can get in the interface, when I move back to server room, power on/off, no access again. when I tried to access interface, no any rules applied,no any special setting except ip address, netmask. Again, I tried reset to default more than 30 times. suddenly I can access the interface, then I updated the firmware to MR7. now some user compain about the SSL-VPN, one user complain about his voip logon/off every 20 mins, I applied a ticket but 3 days no tech responsed. We paid $800 for 2 year contract include hardware,firmware,antivirus...... Honestly Fortinet service really sucks. I am thinking about switching to different company when 2 weeks later old contracts expire.
FortiRack_Eric
New Contributor III

You should be aware that Fortinet Maintenance & Support is meant for cases where a unit doesn' t do what the manual says, it' s not a backup consultant to tell you ' how to configure' a device. What do you expect here? The forum is to get pointer from peers, not to bitch about Fortinet. What made you decide to upgrade a unit with 2.5 (which is over 4 years old) to go to MR7, why not MR6? That' s when you could have posted a message here. There' s a lot of functionally of the FG unit that quite differs from 2.5 to 3.0 mr7. Sounds like you have to tweak sip-helper and/or session ttl. Point is again the analogy with a car don' t fiddle with the cam timing if you don' t know the specifics of the engine and have the proper experience/training. A FG is a proper security device and not some kind of toy

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
fsyong

I totally understand this forum belongs to fortinet, nobody will like dumping xxx in their own backyard. Let' s calm down a little bit. I got a ticket from fortinet last sunday, I have explained my situation to the technical support, the only solution they gave to me was update firmware. please, please read my ticket. No way to update the firmware, till the midnight 1day later when I used remote console and found that I can access the interface. I backed to my office, the only things I can/want to do was updating firmware, that is my only help. at that time I have no time to tell which version, so I thought the highest will be the best. I am afraid to upgrade or downgrade the fortigate firmware, I do believe there have some problems inside the devices, but unfortunately I dont want whole office can not remote access or connect to the internet. So I posted,and want some experts can post some easy1-2-3 pictures let me know. cause My problem is not the ssl vpn setting inside my fortigate, is a user from germany who has his own SSL VPN client software back to germany. My setting is very simple, only wan1-internal web profile. another user is using a mobile phone software like skype, sorry I can not read german. but both users have no problem when I gave then connection bypass the fortigate. Honestly Eric, if you are expert, you should know what the execute to factoryreset means. please dont blame me for complaining the car vendor, as an end user, reset means we trust the vendor, and should connect to 192.168.1.99. I am here for help, but also I want other users know the service I have, hope fortinet can realize this and improve their service not just blaming end user ruined their reputation. have a nice weekend
FortiRack_Eric
New Contributor III

couple of words of advise: factoryreset is resetting a FG60 internally to clean config, internal is 192.168.1.99 if possible always do firmware upgrades, factoryreset with console cable connected ssl-vpn is clientless to a FG unit, except for some new features in MR7. MR6p3 is most stable with ssl-vpn functinality. It' s not guaranteed but I' ve seen downgrades from Mr7 to Mr6 without loss of config. I would advise to backup Mr7, do a downgrade, then again do a backup. take the backup config and remove not readable parts between, config and end. Then restore config and work from there

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
fsyong

Thanks for the advise. Few questions which version is better? MR5 P6 or MR6P3 Fortinet website recommend MR5 P6 for fortigate 60B. I suspected the interface problem was caused by the flash memory, as I mentioned the virus lists are junk characters( os2.5), unreadable. At that time, console is my only way to access the VPN. I downgraded to MR5 SP6, the setting still there, thanks. I will try to figure out the ssl-vpn problem. cause the user complained many days already.
UkWizard
New Contributor

Wow, this is the first ' hostile' thread i have seen on the forums and version 2.5? thats very old and unsupported. If you lost access to the GUI originally whilst adding a user, then you probably set the " trusted hosts" section of all the users? If set incorrectly, this would stop you getting to the GUI altogether. So this might have been your original problem. Thought i would let you know, just in case you set it accidentally again.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors