Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi Community, As per title “How to get Fortinet higher up to review related TAC Manager ticket”In ticket (11996986), we had factually proven the issue and the TAC Manager do acknowledge on it.Suddenly the TAC Manager (Jonathan) twist the fact on what discussed.Luckily we had video call recorded. How can we further submit to Fortinet higher up to review this TAC Manager whether these action is being approved? Thank You Best Regards,YK
When i have a new ipphone connected to the network then fnac will move this ipphone to registration vlan before device profiling is running. After device profilling run then i can see the ipphone move to host role ‘IP Phone’ and registered’But after the devices was profiled then how the vlan can be changed automatically to voice vlan? The only way the ip phone get the voice vlan after the ip phone registered by profiling is reboot the ip phone.
I try to send CoA to the endpoint but we can see from below picture the CoA is failed, and from tcpdump there is no traffic to port 1700. Also in the cisco switch i already enable CoA debug but not receive any message. This mean the fortinac not send the CoA message?
Had multiple issues when adding a FortiGate using discover device. It always said device serial number does not match Only once I updated to 7.4.11 did it finally add First post here and its the end of my day so I’ll add more later, just don’t want someone to lose an entire day to this like I did.
After correct configuration ddns for DynDNS (not Forti-DDNS) is there any CLI-command to check the status for this service ? My firmware version = 5.0.1.
Dear All, Anybody can explain in laymon term what is under lay and over lay in SDWAN concept and how does it work. Why under lay and over lay need. Thank you in advanced for sharing the knowledge.
For FortiEdge Cloud, how do you assign different user accounts to have access to different networks?I believe this used to be accomplished using the Multi Tenancy license and sub accounts, correct?Since this can’t be ordered anymore and is going away, how do you do it using the new organization method?
Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.Am I missing something in t
Previously, with FortiClient version 7.2.13, when users initiated the VPN connection using SSO, FortiClient automatically detected the existing sign-in sessions for the customer's corporate accounts. When the authentication window was displayed, the available accounts were presented for selection, allowing users to authenticate without re-entering their credentials.However, after upgrading FortiClient to version 7.4.3, this behavior has changed. When using FortiClient's embedded browser for SSO authentication, users are always prompted to enter their username and password. The embedded browser no longer detects existing Microsoft Entra ID (Azure) sessions or displays the available signed-in accounts.On the other hand, we have verified that when FortiClient is configured to use an external browser for SSO authentication, the expected behavior is observed. The external browser correctly detects the existing Microsoft Entra ID (Azure) sessions, displays the available corporate accounts,
Dear Community, We have this case where we want to configure two different IP Addresses as destination for our fortigate to be monitored as part of our link health monitoring. Our Cariteria is like this:First Destination is the next hop ISP IP AddressSecond Destination is our Server on the Internet Now we want the link to monitor both IP Addresses and if any of these two IP Addresses are not reachable then the link should be detected as down. Can anyone help me how to do this one.I have also read this on the internet can you all confirm if this is true?Someone suggested using the OR logic and configure two separate SDWAN performance SLA one for each Destination Server and if an interface participates in multiple Performance SLA (health-check) probes, it's only considered "up" if it passes ALL of them. So failing even one the interface marked down = SD-WAN swings traffic to the Backup. This is exactly the OR-failure logic you want. Best Regards,Shah.
We recently started investigating roaming behaviour on a customer environment using FortiAPs with WPA3-Enterprise and an external RADIUS server.The initial observation was that roaming did not appear to behave like a Fast Transition (802.11r) roam. During movement between access points, clients seemed to perform a complete authentication process again instead of using a fast handoff. This resulted in noticeable delays compared to what we would normally expect from an 802.11r-enabled deployment.To validate this, we captured both beacon frames and association traffic on the customer environment. In the captures, we noticed that clients were performing normal WPA3-Enterprise authentication exchanges after roaming. When we examined the beacon frames more closely, we found that the WPA3-Enterprise SSID advertised only the standard WPA3 Enterprise AKM. We could not find any indication of FT over IEEE 802.1X or a Mobility Domain (Tag 54) element.To rule out environmental factors, we rebuilt t
Hello, Trying to understand what happened and how to prevent it in the future: - Running FortiGate-VM in an Azure VM.- This FG has a custom site-to-site IPSec tunnel to on-prem. This effectively connects the virtual data centre to the on-premises data centre. Tunnel is initiated from Azure.- Suddenly, the tunnel no longer works. Phase 2 will not go up.- The first sign of trouble is this: Unavailable : Live Migration (Unplanned)At Thursday, October 13, 2022 at 7:29:19 PM EDT, the Azure monitoring system received the following information regarding your Virtual machine:This virtual machine was paused for 0.675000 seconds due to a memory-preserving Live Migration operation. No additional action is required from you at this time. Recommended StepsNo action is required - A couple of minutes after this, alerts start going off that connectivity has been lost.- After some trouble shooting, pinging, checking routes, connectivity, rebooting, firmware upgrade,
Hello, installation of FortiClient VPN ends in an error "FortiClient VPN Wizard ended prematurely because of an error." I am running Windows 11 home on my new surface 11 pro. I executed Installation .exe as Administrator, i disabled Windows Defender temporarily. Any further ideas?
I setup 1VM (FMG V8.0.0) and FW(V8.0.0) and trying to onboard fortigate firewall to manager but getting below error , is there any bug or do i need to make further changes in the configuration considering both VM Mgt subnet are in same subnet. Error “The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager.Could not connect to the FortiManager to retrieve its serial number.”
Hello team, I have interesting situation. there are 4xFg900G in cluster. there is FTP server in vlan 100.L3 DG address for that vlan 100 is on Fortigate.When secondary 900G FGs from cluster want to reach ftp they can not.We also have cluster of 4xFG 400F for additional services, and they can all reach ftp server , no matter primary or one of 3 secondary FGs How to solve this situation?My final aim is to upgrade one of secondary FGs regarding MVC (Multi-version cluster) option, set upgrade-mode local-only, and upgrade one of secondaries and then reset ha uptime so that upgraded one become primary. Reason for that is because we must not have any downtime, and we want to take test after upgrade if all services are ok
Hello everyone,I am facing an issue with a FortiLink deployment over a RADWIN 5000 Point-to-Multipoint (PtMP) wireless network and would like to know if anyone has experienced something similar.TopologyFortiGate |FortiLink |RADWIN 5000 HBS / \ SU-1 SU-2 | |FortiSwitch1 FortiSwitch2The RADWIN network is operating in Layer 2 Bridge mode. No routing or NAT is configured between the FortiGate and the remote FortiSwitches. The wireless network transports the required VLANs correctly.Current behavior If only one remote site is powered on, the FortiSwitch is discovered and managed successfully through FortiLink. If I power on the second remote site, both remote FortiSwitches appear as Offline in the FortiGate. Despite this, all end-user devices connected to both FortiSwitches continue to pass traffic normally on their VLANs. Data connectivity is not affected. In other words: FortiLink management fails. User traffic continues to work without issues. Additio
Good day, i have block instagram from application Control. it works in laptop or pc that connected through this network. but for user who using mobile phone with Wifi access, still able to access Instagram application smoothly. my question is, how to block instagram for user access from mobile phone Iphone or Android. Thank you for Help
Hi everyone,I'm trying to integrate FortiWLC 8.6-5 build-8 (FortiWLC-500D) with Aruba ClearPass Guest (ClearPass Policy Manager 6.12.7.308288 on C3010 platform) as an external captive portal.Current setupFortiWLC 8.6-5 build-8 External captive portal: Aruba ClearPass Guest Authentication type: RADIUS Captive Portal External Server Type: Fortinet-Presence External URL: https://<clearpass fqdn>/guest/guest_register_3.phpThe captive portal profile is configured as:Authentication Type: radiusCaptive Portal External Server Type: Fortinet-PresenceSuccess Redirect URL: https://<default redirect url>Login flowClient connects to SSID.FortiWLC redirects the client to the ClearPass Guest portal.The login page receives all FortiWLC parameters correctly, including:magicusermacuseripserveripapmacapidapnodeidssidpost=https://<controllerip>:8081/vpn/loginUser? User enters username/password.ClearPass successfully authenticates the user against the authentication source.After successf
Why link status for each port is different between the device and fortinac? On the device port g1/0/27 - 31 is up but in the NAC is different
EnvironmentPlatform: FortiGate (hardware appliance)HA mode: Active / PassiveFortiOS current version: 7.4.8Target version: 7.4.10HA priorities:Unit A (Master): priority 200Unit B (Slave): priority 100Expected upgrade behavior (normal case)Based on Fortinet documentation and past experience, the expected HA upgrade sequence is:Firmware upgrade starts on the slave unit (B).Slave reboots and temporarily disconnects from HA.Cluster fails over to the upgraded slave.Firmware upgrade is then applied to the former master (A) in background.Final failback occurs according to HA priority (unit A becomes master again).Observed behavior / Issue descriptionDuring the upgrade from 7.4.8 to 7.4.10 (firmware uploaded via GUI using .out file downloaded from fortinet official source):The upgrade process took more than 20 minutes, significantly longer than usual.HA became disconnected, and unit B (slave) was no longer visible from the cluster GUI.Accessing unit B directly via Console & Management
Hi!I’ve been testing Fortinac 7.6.7 in lab. It seems, that they did major changes to the RADIUS configurations. Changes are welcome, if you have not implemented Fortinac yet, but for existing installation, it might cause some work.I have been told, that nothing changes when I’m using Fortinet only devices (Fortigate, Fortiswitches and FortiAPs).That’s not true, if you are using RADIUS (in practise 802.1x)Or we can say, that nothing changes in 7.6.7 for existing devices, but if you are going to add new devices, you have to use the new selector based method. And later you have to migrate all existing devices.(https://docs.fortinet.com/document/fortinac-f/7.6.7/support-for-radius-only-devices/276659/overview)You have to migrate all existing devices to the new method before future release, because the support for the legacy method will be removed. There is a great migration tool, but it creates individual configurations for every device. It works, yes, but is quite a big mess.Missing best
I have many event like below picture, can we troubleshoot from where the mac address is come? On my L3 switch i can’t see this mac.
If we use computer authentication then can service connector get record grom device group? I want to make dynamic vlan assigment based on entra id with computer authentication.
Hi Fortinet Support,We're looking for guidance on deploying and configuring the FortiClient VPN application on Apple iOS devices managed through SOTI MobiControl.Our Android devices are working as expected, where the VPN configuration and authentication are deployed through SOTI. However, the process appears to differ on iOS, and we're looking for the recommended approach.Specifically, we'd like to know:Whether the FortiClient VPN configuration can be deployed automatically through SOTI MDM on iOS. Whether VPN profiles and authentication settings can be pre-configured using Managed App Configuration or another supported method. If there are any limitations on iOS compared with Android regarding deployment or user interaction. Whether there is any official Fortinet documentation or best practice guidance for deploying FortiClient VPN on iOS using SOTI MobiControl.Our environment:MDM: SOTI MobiControl Devices: Apple iPhone and iPad (iOS/iPadOS) VPN Client: FortiClient Android deployment
It seems IPSEC MFA via FortiToken requires FortiClient 7.4.4 when using LDAP, so no free FortiClient version then.Are there any other options for MFA with FortiClient VPN Only 7.4.3? Does it still work with SAML, or Radius via Windows NPS perhaps?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.