Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
I believe when we add the switch to the fnac for 1st time then fnac inventory will collect below data such as Name, Default Vlan, Current Vlan from the switch. When we have changes on the switch, example i make port description and change the default vlan then why in the fnac is not updated? Resync the interface is not helping
We encountered some issues accessing some URLs after upgrading from 7.2.12M to 7.4.12M using FGT401E on HA.applications like MS Teams get disconnected suddenly and users reported that access to some external portal become very laggy.upon checking the traffic log, we noticed that the Application name was classify as 2x which is a service group in our firewall.under this group, there is HTTP, HTTPs, TDP, 2X publishing agent port and 2X terminal server agent port.due to the many issues encountered, we have rollback to 7.2.12M
Hello,I followed this technical tip:Fortinet Technical Tip – Quickly isolate hosts that have disabled or uninstalled the Persistent AgentIt works very well when I stop and restart the Persistent Agent. The host is correctly detected as At-Risk, and I can see the VLAN change from the remediation VLAN back to the production VLAN as expected.However, when I completely uninstall the Persistent Agent and then reinstall it, the host remains in "Agent Not Communicating" status. The status does not change after the agent has been reinstalled.After reinstalling the agent, I have to delete the host from FortiNAC and restart the workstation before it is detected correctly again.Is this expected behavior?I also have a question regarding the following statement from the technical tip:"An Event Mapping can be created that immediately changes the host status to 'At-Risk' as soon as an event 'Persistent Agent Not Communicating' is created."Does this Event Mapping apply to all hosts, regardless of thei
Hi everyone,I am attempting to set up a new IPsec VPN connection using the standalone FortiClient VPN only v7.2.1.0779 app, but several configuration options appear to be missing from the user interface: Missing Single Sign-On (SSO): When creating an IPsec VPN profile, there is no option or toggle for Single Sign-On (SSO / SAML) anywhere in the GUI. Missing Mode Config Parameters: Under Address Assignment, selecting Mode Config does not reveal options for Encapsulation, IKE UDP port, or IKE TCP port. Any insights or guidance would be greatly appreciated. Thanks!Missing option in my appSSO setting i expectedMode configuration setting i expected
My Fnac license 106 is in use, how we can know detail which endpoint is consume the license?
hello everyone,i am setting up a home lab and recently acquired a fortigate 60d rugged.i tried to reset it using coolterm on my mac and after the proccess it just got stuck on system halted, now its “bricked”i am trying to find a way to get it back up and running and i am fully aware that this product is an end of life model. tried also customer service and dident help. any help will be great!
So i m doing a demo for a project i m doing for a client and i activated the free trial doe 200f series fortigate that work as HAtransfered the assets into another forticlould account but the ems free trial is still on the older accountCan anyome help me with this please an is the free trial can be activated just once even if i move the fortigateCan i remove the trial from the old account and activate on the new oneAny help is apperciated because i m stuck now and been ike this for 2 days
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
I upgrade our fortigate to v7.6.7 and after upgraded then the web admin gui if use mgmt ip address can’t be accessed from advpn, only can be accessed from local site and from hub only. If i using lan ip (not mgmt) then i can access. Anyone know why?SSH to the both port (mgmt and lan) is working fine.
Hi, we were an on-prem only company. Earlier this year we went hybrid with 365.For VPN earlier we had our clients connecting through forticlient with AD credentials leveraging RADIUS. No MFA.We then configured a parallel setup using IPSec ike v2 and authentication with EntraID, adding the MFA feature then.My question is: is this the natural approach that most of the former on-premise companies adopt once moved to Cloud or are there other suggested setups, maybe leveraging already existent on-premise RADIUS infrastructure?
We can select 802.1x authentication set to user or computer if we use wired. How about for wifi? There is no option to select that option on the wireless card properties.
Hello Community,We are currently encountering a known limitation with the standalone (unlicensed) FortiClient app on Android. When attempting to connect to an IPsec IKEv2 VPN using a Pre-Shared Key (PSK) alongside EAP user authentication, the client fails to render the username and password prompt during the connection sequence.This behavior aligns with the issue documented in the following Fortinet Knowledge Base article:Troubleshooting Tip: FortiClient VPN without license on Android has missing username and password promptDeploying FortiClient EMS or reverting to deprecated IKEv1 for a single mobile endpoint is not feasible for our environment. As a result, we are looking for advice on the following: Alternative Client Apps: Are there recommended third-party IPsec IKEv2 clients for Android (e.g., strongSwan, native Android VPN setup) that can successfully handle PSK + EAP/XAuth user authentication against a FortiGate without modifying the core gateway configuration? Configuration W
Hi AllI would like to know if there is a method to export FGT Policies into Excel (csv) format.Please advise any available options. Am using FortiOS v7.4.12 Many thanks
I'm facing a strange issue with a new FortiGate VM instance running on Proxmox.EnvironmentHypervisor: Proxmox VE FortiGate: FortiGate VM Disk image: fortios.qcow2 Access: Web GUI over HTTPS Version: FortiGate-VM64-KVM v8.0.0.build0167.260420 (GA.F)IssueI created a new FortiGate VM using the fortios.qcow2 image.The VM boots successfully, and I can access the FortiGate GUI login page. I can also enter the admin credentials and authentication is successful.However, immediately after successful login, I am logged out and redirected back to the login page.So the behavior is:FortiGate GUI Login ↓Enter credentials ↓Authentication successful ↓GUI starts loading ↓Immediately logged out ↓Redirected back to Login pageThere is no normal session timeout involved because the logout happens immediately after login.Troubleshooting already attemptedI also tried increasing the administrator timeout:config system global set admintimeout 30endHowever, this did not res
I have configured a FortiSwitch Dynamic Port Policy (DPP) to allow only 3 specific MAC addresses on a switch port. When one of the legitimate MAC addresses is connected, the DPP identifies the device and assigns the configured dynamic VLAN successfully.However, I am experiencing an issue when the legitimate device is disconnected and an unauthorized device is connected to the same port shortly afterward.My test scenario is:Connect legitimate device (Test_MAC1). DPP identifies Test_MAC1 and assigns the dynamic VLAN. Test_MAC1 is disconnected from the switch port. Within a few seconds, connect an unauthorized device (Test_MAC4). Test_MAC4 is not included in the DPP allowed MAC list. However, Test_MAC4 still receives an IP address from the previously assigned dynamic VLAN and can access the network.It appears that the dynamic VLAN assignment/state is not being flushed immediately when the legitimate device is removed from the port.Is there any way to Fix this?Dynamic port policy Configura
Hi,I would like to know if anyone else is experiencing similar issues with FortiEndpoint EMS Cloud and the integrated FortiEDR feature.Our environment is currently running:FortiClient EMS Cloud: 7.4.7 build 2194 (Mature) FortiClient: 7.4.7 Windows 11 25H2: Build 26200.8875 FortiEDR Engine assigned by EMS: 5.2.8.0044Originally, we noticed that some endpoints using the same EMS policies and profiles had FortiEDR working and connected, while others showed FortiEDR Disabled in FortiClient and Disconnected in FortiEDR Cloud.Both working and affected endpoints are operating in the same environment and network, which makes the different behavior seem questionable. We are also seeing the same issue on endpoints in customer environments, so it does not appear to be limited to a single device or network.We also tested multiple FortiClient versions, including 7.4.4, 7.4.5, and 7.4.6, but the behavior remained the same.On affected endpoints, the Collector reported:FortiEDR Detected incompatible ma
Hi everyone,Is it possible to register the FortiClient to EMS Cloud without needing the invitation code. We have more than 300 PCs to install the client and we dont want to enter the invitation to each of them. Bests,FortiEng
I have DPR to set host role new ip phone to role IPPHONE then after the device profiled why the vlan is not changed? The ipphone still sit on isolated network except i replug the phone. Isn't when the host role changed then the policy will be evaluated automatically?
Hi everyone,I'm currently setting up FortiXDR and I'm a bit confused about the required FortiAnalyzer configuration.Our environment consists of:FortiClient EMS Cloud FortiXDR license Local FortiAnalyzer VM (no FortiAnalyzer Cloud license)We do not have a FortiAnalyzer Cloud license, only a local FortiAnalyzer VM.My question is:For FortiXDR, where should the FortiClient logs (configured in the System Settings Profile) be sent?Should the FortiClients send their logs to a FortiAnalyzer Cloud instance, even though we don't have a FortiAnalyzer Cloud license? Or is it supported to send the logs directly to our local FortiAnalyzer VM while still using FortiXDR?Most of the users work from home, so we are currently using a DNAT with TLS configuration.Has anyone successfully deployed FortiXDR with EMS Cloud + local FortiAnalyzer?Kind regards,MG4
can we get a proper captive portal instead of showing the default page.https://<controller-ip>/vpn/auth_web_ok.htmlwe tried changing the auth_web_ok.html inside custom captive portal under maintenance. but still its loading the default fortinet page as shown below.
If we use computer authentication then can service connector get record grom device group? I want to make dynamic vlan assigment based on entra id with computer authentication.
Hello everyone,We’re currently preparing to deploy a larger FortiSwitch environment and are discussing the best way to get started with Dynamic Port Policies.The environment consists of two FortiSwitch 2048F switches as the core and about 20 access switches. The access switches will connect primarily standard clients, printers, Swyx DECT base stations, Raspberry Pi systems, a total of about 40 FortiAPs, and other IoT Devices. However, the APs are distributed very unevenly across the access switches—some have no APs, while others have five, for example.Currently, network segmentation is still very straightforward. The majority of the servers, clients, printers, etc., are still all located within the same network 172.16.0.0/16. Although there is already an organizational address allocation within this network—for example, servers are primarily in 172.16.0.x and clients starting at 172.16.100.x—technically, it is still the same network.A few true VLANs already exist, for example, for Wi-F
Hi Everyone,We have a fortigate firewall with HA and FortiOS is 7.4. also laid few client based FortiGate SSL-VPNs accounts.Now we have to upgrade either 7.6 or 8.0, where as not support the client based FortiGate SSL-VPNs accounts. So, what is the best practice for moving to 7.6 or 8.0 version?.Before upgradation can we use any migration tool only for SSL-VPN accounts to IPsec or any other?.MY SSL-VPN purpose is providing the RDP access & Web based internal urls. Anyone guide me for best practice for without any production impact?.Thanks in advance.
Our internal tools use FMG API to manage it and we were looking to create a Threat Weight Template using API.I have checked:https://fndn.fortinet.net/index.php?/documents/file/521-fortimanager-76-json-api-full-reference/https://how-to-fortimanager-api.readthedocs.io But did not find the API endpoints.If someone has done it before or has any API collection they can share ?
Fortinet TAC has also reviewed the case and confirmed that they cannot see any SMTP traffic leaving the FortiGate.At this point, it appears that the email notification process is never invoked even though authentication reaches the "Token is needed" stage.Hi everyone,I am facing a very strange issue on a FortiGate 601E running FortiOS 7.4.12 (build 2902).Environment- FortiGate 601E- FortiOS v7.4.12 GA build 2902- Multi-VDOM enabled- Root VDOM hosts the SSL VPN- SSL VPN authentication uses Local User + Email-based Two-Factor AuthenticationSymptomsThe SSL VPN login works normally.After entering the username and password, the SSL VPN client displays:"An email message containing a Token Code will be sent..."The System Event log also records:"Send two-factor authentication token code"However, the user never receives the email.What makes this strange is that FortiGate never attempts to establish any SMTP connection.Troubleshooting performed✓ Local user configured with:set two-factor email✓ E
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.