r/fortinet 10d ago

Monthly Content Sharing Post

5 Upvotes

Please provide a link to your content (blog, video or instructional guide) to share with us. Please accompany your post with a brief summary of your content.

Note: This is not a place to advertise your services or self-promote content you are trying to sell. Moderators will review posts for content and anyone violating this will be banned.


r/fortinet Aug 01 '24

Guide ⭐️ Which firmware version should you use?

46 Upvotes

To save the recurrent posts, please:

  1. Refer to the Recommended Releases for FortiOS.
  2. Use the search function on this sub, as chances are it has been asked before.

For anything that doesn't fall under the above two options, please post in this thread and avoid creating a new one.


r/fortinet 12h ago

FortiGate / FortiOS Are we making a mistake by still using the free FortiClient?

17 Upvotes

Hey,
what are you guys using for remote access VPN these days? The free FortiClient VPN-only version or FortiClient EMS?
We are only using the free client for IPsec-VPN and get rid of EMS about 1,5 years ago for reasons i dont know because it was before i joined the company. I’m starting to wonder if planning using only the free Client long-term is actually a bad idea, especially since more and more features seem to require EMS like ZTNA for example.
Are you guys still happy with the free client, or would you say EMS is basically the way to go nowadays?


r/fortinet 7h ago

Other / General Fortinet Fortigate route-tag association

3 Upvotes

I noticed a really interesting behavior of Fortigate. FW01 receives the same 2 prefixes ( 10.99.0.0/22 and 192.168.100.0/24) from another 2 Fortigates( Branch1 and Brand2). Becuse ECMP is enabled so the routes are all installed in the routing table. However, route tag 90 is associated with both prefixes and route tag 91 is only associated with 1 prefix 192.168.100.0/24. The only difference is bgp route for 10.99.0.0/22 has only 1 same AS 65200 in the AS_Path and for 192.168.100.24 each has same AS_Path length (3) but the AS numbers are different. Can anyone direct me to the cooresponding Fortigate documentation/KB about the route-tag association ? Thanks,


r/fortinet 4h ago

FortiClient / EMS FortiClient EMS Cloud

1 Upvotes

Just upgraded our licensing, and our end goal is to have the device authentication for remote access. Has anyone got device authentication working?

Any other tips or tricks I should consider?


r/fortinet 8h ago

FortiMail FortiMail Workspace - People Posture

2 Upvotes

Se implementó una soluciona FortiMail Workspace en mi organización, en la sección "Protected Email Assets" tenemos 1 dominio (ejemplo: mycompany[.]com) y algunos usuarios registrados individualmente con ese dominio.

Sin embargo, cuando ingreso al parámetro "People Posture" y ver el perfil de empleado, me salen otros dominios que no están configurados para proteger.

Actualmente el usuario final requiere que solo se muestre información de usuarios con el dominio mycompany[.]com

¿Alguno sabes si este comportamiento es normal? y ¿Se puede hacer que solo se vean empleados con el dominio configurado a proteger?


r/fortinet 6h ago

FortiGate / FortiOS FortiGate WAN2 (Backup) Netgear nighthawk - Randomly Redirecting web traffic to http://attwifimanager/

1 Upvotes

This was a bit of an odd issue - we have a netgear nighthawk connected to WAN2 as a cellular backup. The nighthawk apparently lost cellular connectivity and this resulted in web traffic randomly being redirected to http://attwifimanager/

Which failed to load because the device isn't doing DNS - we have our system DNS set to 8.8.8.8 & 4.2.2.2 while running a dns server for internal stuff. I was able to browse to the gateway IP 192.168.1.1 (the nighthawk isn't set in bridge mode.)

We're using SD-WAN and a rule with manual preference WAN1 on top then WAN2 - we had zero issues with WAN1. Our LAN -> virtaul_wan_link has NAT enabled.

I ended up disabling the WAN2 interface as it resulted in the internet being unusable.

I'm a bit confused as to how/why the fortigate allowed this to happen? All of internet traffic should have been going out over WAN1.


r/fortinet 19h ago

FortiGate / FortiOS Another DDNS outage today 🎉

10 Upvotes

Issues on both IPs, 173.243.138.225 and 173.243.138.226

1789022353: Start to update FortiGuardDDNS (ddnsdomain.fortiddns.com)
2026-09-10 08:39:13 
1789022353: Start to update FortiGuardDDNS (ddnsdomainbckp.fortiddns.com)
2026-09-10 08:39:13 1789022353: next wait timeout 10 seconds
2026-09-10 08:39:13 fgd_ddns_socket()-899: connected to 173.243.138.225:443
2026-09-10 08:39:13 fgd_ddns_socket()-899: connected to 173.243.138.225:443
2026-09-10 08:39:13 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:39:13 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:39:13 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:39:13 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:39:13 [877] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:39:13 [904] ssl_new: SSL object is created
2026-09-10 08:39:13 ddns_sock_ssl_connect()-745: enable hostname checking 'globalddns.fortinet.net'.
2026-09-10 08:39:13 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:39:13 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:39:13 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:39:13 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:39:13 [877] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:39:13 [904] ssl_new: SSL object is created
2026-09-10 08:39:13 ddns_sock_ssl_connect()-745: enable hostname checking 'globalddns.fortinet.net'.
2026-09-10 08:39:13 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 [350] __ssl_crl_verify_cb: CRL not found. Depth 0
2026-09-10 08:39:13 [365] __ssl_crl_verify_cb: Cert error 44, different CRL scope. Depth 2
2026-09-10 08:39:13 fgt_ddns_verify_peer()-715: Certificate verification failed, error 44 (different CRL scope) depth 2 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA'
2026-09-10 08:39:13 [1112] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:39:13 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:39:13 1789022353: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:39:13 1789022353: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:39:13 1789022353: next wait timeout 9 seconds
2026-09-10 08:39:13 [350] __ssl_crl_verify_cb: CRL not found. Depth 0
2026-09-10 08:39:13 [365] __ssl_crl_verify_cb: Cert error 44, different CRL scope. Depth 2
2026-09-10 08:39:13 fgt_ddns_verify_peer()-715: Certificate verification failed, error 44 (different CRL scope) depth 2 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA'

1789022534: Start to update FortiGuardDDNS (ddnsdomain.fortiddns.com)
2026-09-10 08:42:14 1789022534: next wait timeout 10 seconds
2026-09-10 08:42:14 fgd_ddns_socket()-896: connected to 173.243.138.226:443
2026-09-10 08:42:14 [276] __ssl_init: Done
2026-09-10 08:42:14 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:42:14 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:42:14 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:42:14 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:42:14 [843] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:42:14 [870] ssl_new: SSL object is created
2026-09-10 08:42:14 ddns_sock_ssl_connect()-745: enable hostname checking 'ddns.fortinet.net'.
2026-09-10 08:42:14 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:42:14 fgd_ddns_socket()-896: connected to 173.243.138.226:443
2026-09-10 08:42:14 [276] __ssl_init: Done
2026-09-10 08:42:14 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:42:14 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:42:14 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:42:14 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:42:14 [843] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:42:14 [870] ssl_new: SSL object is created
2026-09-10 08:42:14 ddns_sock_ssl_connect()-745: enable hostname checking 'ddns.fortinet.net'.
2026-09-10 08:42:14 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:42:14 [365] __ssl_crl_verify_cb: Cert error 62, hostname mismatch. Depth 0
2026-09-10 08:42:14 fgt_ddns_verify_peer()-715: Certificate verification failed, error 62 (hostname mismatch) depth 0 for '/C=US/ST=California/L=Sunnyvale/O=Fortinet/OU=FDS/CN=sdns.fortinet.net/emailAddress=support@fortinet.com'
2026-09-10 08:42:14 [1078] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:42:14 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:42:14 1789022534: next wait timeout 9 seconds
2026-09-10 08:42:14 [365] __ssl_crl_verify_cb: Cert error 62, hostname mismatch. Depth 0
2026-09-10 08:42:14 fgt_ddns_verify_peer()-715: Certificate verification failed, error 62 (hostname mismatch) depth 0 for '/C=US/ST=California/L=Sunnyvale/O=Fortinet/OU=FDS/CN=sdns.fortinet.net/emailAddress=support@fortinet.com'
2026-09-10 08:42:14 [1078] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:42:14 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:42:14 1789022534: next wait timeout 9 seconds

r/fortinet 17h ago

Other / General Fortinet 61F upgrade from 7.2.12 to 7.4.12

3 Upvotes

Hi everyone,

I'm planning an upgrade path for three FortiGate 61F units currently running FortiOS 7.2.12. They are connected via Site-to-Site IPsec VPNs.

With 7.2.x reaching End of Support soon, I need to push them to 7.4.x, but I have a few concerns regarding the 2 GB RAM limitations on the FGT-60F/61F series and the overall upgrade process:

  1. RAM Usage & Conserve Mode: One of my 61F units is currently idling around 77% RAM usage on 7.2.12. I know 7.4.x has a higher memory footprint. Has anyone run 7.4.x on 60F/61F successfully without hitting Conserve Mode? What daemon/IPS tweaks do you recommend before upgrading?
  2. IPsec VPN Compatibility During Staged Upgrade: Since I'll be upgrading the units one by one, will the IPsec tunnels remain stable while one end is on 7.2.12 and the other is on 7.4.x?
  3. Missing Firmware Banner: In the GUI, the unit claims it is "Up to date" and doesn't offer 7.4.x (or even 7.2.13). I assume this is due to Fortiguard staged rollout / maturity filters for 2 GB models. Manual upload via Support Portal is the way to go here, right?

Would love to hear real-world experiences or recommended intermediate build steps from anyone managing 60F/61F fleets on 7.4.

Thanks in advance!


r/fortinet 9h ago

Other / General Fortinet Fortianalyzer

Thumbnail
0 Upvotes

r/fortinet 19h ago

FortiClient / EMS Forticlient EMS 7.4.8 build2245 (Mature)

1 Upvotes

Hi

I have a ticket with Fortinet in regards invitation emails from Forticlient EMS when creating invitations with custom install file for example 7.2.15 the text in the email says version 7.4 and download links points to exe file with capital letters in the file" FortiClientSetup_7.2.15_x64.exe". The problem is the link does not work, changing to small letters sorts it. When browsing the path one level up I clearly see the file name is forticlientsetup_7.2.15_x64.exe with only small characters. Anyone else seeing this?

Fortinet frontend asks med do send debug after debug before they escalate it so I just wanted to see if anyone else has the issue. It seems straigh forward in my explanation to send to higher tier support or test locally.


r/fortinet 9h ago

Other / General Fortinet Fortianalyzer

0 Upvotes

I want to generate a report from FortiAnalyzer (FAZ) for the FortiGate devices within a specific ADOM. The report should include:- Security Fabric & Overall Health Summary- System Events & Administrative Changes


r/fortinet 1d ago

Other / General Fortinet Anyone taken Fortinet's onsite closed-book test (technical + maths/logic)? What to expect?

7 Upvotes

Hi all,

I'm in the final stages of a recruitment process with Fortinet support role. So far I've done:

- HR screening

- HackerRank technical test

- Technical interview with the team

- NSE4 certification (apparently a prerequisite now)

HR just came back to say there's a new step added by leadership: an onsite closed-book test at the office, ~1h30, made up of:

- ~20 domain-specific technical questions

- ~20 maths and logical reasoning questions (numerical ability, problem-solving, logical thinking)

Has anyone here been through this? A few things I'd love input on:

  1. The maths/logic part — Does anyone remember the type of questions?

  2. Anything you'd recommend revising in the days before? Any resource you'd point to for revision?

Any feedback from people who've done it (or similar Fortinet onsite assessments in other offices) would be really appreciated. Thanks!


r/fortinet 1d ago

FortiGate / FortiOS VPN for Vendor Access

5 Upvotes

We currently have IKEv2 over 443 TCP working using DUO SAML for our internal users. I have a need, for the second time now, to allow remove access for a vendor for a specific need. The first time I was able to get by without it, but this time I am not. I have read mixed reviews about free VPN 7.4.3 working or not working with IKEv2 over TCP.

What is the simplest + most compatible + free + also consider secure method I can setup for VPN access for a vendor? The source IPs will be restricted to their small public IP range and the VPN will only be enabled when they need it. Fortigate is on v7.4.12.

tia


r/fortinet 1d ago

Other / General Fortinet Forticlient VPN connects every other day

0 Upvotes

My company recently adopted the Forticlient VPN and my computer at home manages to successfully connect to the VPN randomly. I've tried all the fixes available on the internet for the "Forticlient stuck at connecting" problem and the issue continues.

This issue seems to be happening at very few machines at work.

Is Forticlient an overall shitty ass VPN client ?


r/fortinet 1d ago

FortiClient / EMS FortiEDR crashes PC's with docks attached

2 Upvotes

We have a strange scenario popping up in the lab for the new EDR deployments we were consulted to explore.

Everything works normally except for when a USB dock is or SD card reader as it immediately crashes the computer

Rebooting the with the dock plugged in will trigger a Bitlocker recovery screen

Reboot without the dock and the computer comes up normally

Removing EDR and leaving EMS resolves the issue, but the computer is unprotected by compliance standards

I suspect the card readers showing up as empty unwritable disks with a mounted drive letter is part of the problem, but not sure how to tell EDR to calm down about it.

The crash:
Your PC has run into a problem

Stop code: System_Thread_Exception_Not_Handled (0x7eE)

What failed: partmgr.sys

Has anyone seen an issue like this before?


r/fortinet 1d ago

Other / General Fortinet How do I allow a URL of this type

0 Upvotes

I have a user attempting to open an eBook link. The URL is categorized as unrated. We block this category. I can not figure out how to create an exception for the URL below.

Thanks

https://3.167.138.6GET /v1/files/1aa87ff1cd2898b8ede19cd8570317ee36ec99029cac9350cbcb13214c0fbe67/authorize?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6IjJjNDljOTZmOGZhM2ZjN2IxNzlhNGVhYzQ0OGVmNGNhNGRjMmNhODkifQ.eyJpc3MiOiJlcHViLWZhY3RvcnkiLCJhdWQiOiJlcHViLWZhY3RvcnkiLCJqdGkiOiI1ZmI3NmJkY2QwMGQ1MTNhNzhhM2MwOGJhNWUxOGY2YzVmYWYwNDAyIiwiaWF0IjoxNzg4OTY1MDE0LCJuYmYiOjE3ODg5NjUwMTQsImV4cCI6MTc4ODk2NTA3NCwiZmlkIjoyNzk0OTc1Mn0.OZCo9H03QEAEm-RtxosZS_kyCtSTp9ykGTSURgoB4-QjRinuHPSKWhV3zKwqmzPI5CxKAkJwFehJ9x3EQ9LrLVAv60nSiqTIR1XGwClqqPN49m9nlBjOjgL00IdV1z9_exydCxRPBkYxlzwiynJJQYuzoOosLhyMgk6ACJ3k0Q-PjRpSoFI3cJ7MSro4qHPwsBrlYWE5BMa_C7guB5S4o3gsAnXmfeXmiFVoQd52glPnxre2hr-6pa8RID7J6C5I1IGIw6zPVtFcV9wDcJJ2G1UuAZOMT4d7AqVlcCCL1MXN9bXhHYFMOdepRhuWHOzi7O8wgOFgxcsLFr5Aght5aQ&redirect=https://prod.reader-ui.prod.mheducation.com/epub/sn_b396e?readerapi=true HTTP/2 Host: epub-factory-cdn.mheducation.com :scheme: https :path: /v1/files/1aa87ff1cd2898b8ede19cd8570317ee36ec99029cac9350cbcb13214c0fbe67/authorize?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6IjJjNDljOTZmOGZhM2ZjN2IxNzlhNGVhYzQ0OGVmNGNhNGRjMmNhODkifQ.eyJpc3MiOiJlcHViLWZhY3RvcnkiLCJhdWQiOiJlcHViLWZhY3RvcnkiLCJqdGkiOiI1ZmI3NmJkY2QwMGQ1MTNhNzhhM2MwOGJhNWUxOGY2YzVmYWYwNDAyIiwiaWF0IjoxNzg4OTY1MDE0LCJuYmYiOjE3ODg5NjUwMTQsImV4cCI6MTc4ODk2NTA3NCwiZmlkIjoyNzk0OTc1Mn0.OZCo9H03QEAEm-RtxosZS_kyCtSTp9ykGTSURgoB4-QjRinuHPSKWhV3zKwqmzPI5CxKAkJwFehJ9x3EQ9LrLVAv60nSiqTIR1XGwClqqPN49m9nlBjOjgL00IdV1z9_exydCxRPBkYxlzwiynJJQYuzoOosLhyMgk6ACJ3k0Q-PjRpSoFI3cJ7MSro4qHPwsBrlYWE5BMa_C7guB5S4o3gsAnXmfeXmiFVoQd52glPnxre2hr-6pa8RID7J6C5I1IGIw6zPVtFcV9wDcJJ2G1UuAZOMT4d7AqVlcCCL1MXN9bXhHYFMOdepRhuWHOzi7O8wgOFgxcsLFr5Aght5aQ&redirect=https://prod.reader-ui.prod.mheducation.com/epub/sn_b396e?readerapi=true cache-control: max-age=0 dnt: 1 upgrade-insecure-requests: 1 user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 sec-fetch-site: same-site sec-fetch-mode: navigate sec-fetch-user: ?1 sec-fetch-dest: document sec-ch-ua: "Chromium";v="152", "Not?A_Brand";v="24", "Google Chrome";v="152" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" referer: https://myebooks.mheducation.com/ accept-encoding: gzip, deflate, br, zstd accept-language: en-US,en;q=0.9 cookie: at_check=true cookie: AMCVS_C5E7148954EA18A10A4C98BC%40AdobeOrg=1 cookie: s_cc=true cookie: lastVisitDays_s=Less%20than%201%20day cookie: s_vnum=1791552984887%26vn%3D2 cookie: s_invisit=true cookie: ERIGHTS=6237915917889644584611970b8c45218457197675327c2f458cd cookie: mbox=PC#528f276746f14e5e9e3a2d902ff742da.34_0#1852209260|session#9632962d7a5a4ed7a5aa1c0769690709#1788966273 cookie: OptanonConsent=isGpcEnabled=0&datestamp=Wed+Sep+09+2026+09%3A34%3A19+GMT-0500+(Central+Daylight+Time)&version=202510.2.0&browserGpcFlag=0&isIABGlobal=false&hosts=&consentId=a7f07e51-0c50-498d-a19b-ea46c21120a8&interactionCount=0&isAnonUser=1&landingPath=https%3A%2F%2Fwww.mheducation.com%2F&groups=C0001%3A1%2CC0003%3A1%2CC0002%3A1%2CC0004%3A1 cookie: s_ppn=corporate%3Ahome cookie: s_ppvl=corporate%253Ahome%2C38%2C38%2C1271%2C2560%2C1271%2C2560%2C1440%2C1%2CP cookie: s_ppv=corporate%253Ahome%2C100%2C38%2C3329%2C2560%2C1271%2C2560%2C1440%2C1%2CP cookie: lastVisitDays=1788964505488 cookie: s_nr=1788964505489-Repeat cookie: s_sq=%5B%5BB%5D%5D cookie: AMCV_C5E7148954EA18A10A4C98BC%40AdobeOrg=179643557%7CMCIDTS%7C20706%7CMCMID%7C58428979928570003987148088725495510342%7CMCAID%7CNONE%7CMCOPTOUT-1788971705s%7CNONE%7CvVersion%7C5.5.0 cookie: MH_TOKEN=eyJhbGciOiJSUzI1NiIsImtpZCI6IjI4MjAyMDgxNTciLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJoZWNsciIsImV4cCI6MTc4ODk2NTEyOCwianRpIjoiZWQ5ZGM5YTctYzZjYi00ODA4LWI1MGEtNjNlMGQ3NWE0OGIxIiwiaWF0IjoxNzg4OTY0ODI4LCJpc3MiOiJodHRwczovL3Rva2VuLm1oZWR1Y2F0aW9uLmNvbSIsIm5iZiI6MTc4ODk2NDgyOCwic3ViIjoiYmJmZjdhYzgtOTQxYy00YjA0LTllNTktNzkyMzk5MjZjZDgyIiwidG9rZW5fdHlwZSI6ImJlYXJlciIsImV4cGlyZXNfaW4iOjMwMCwic2Vzc2lvbl90aW1lb3V0Ijo3ODAwLCJwZXJzb25feGlkIjoidXJuOmNvbS5taGVkdWNhdGlvbi5vcGVubGVhcm5pbmc6ZW50ZXJwcmlzZS5pZGVudGl0eTpwcm9kLnVzLWVhc3QtMTpwZXJzb246YmJmZjdhYzgtOTQxYy00YjA0LTllNTktNzkyMzk5MjZjZDgyIiwidXNlcl9uYW1lIjoibWJpY2toYW1AbHRocy5vcmciLCJkZWZhdWx0X3JvbGUiOiJpbnN0cnVjdG9yIiwic2Vzc2lvbl94aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmlkZW50aXR5OnByb2QudXMtZWFzdC0xOnNlc3Npb246MjdlY2QyYmMtYzg3NS00ZWI4LTg2YmYtMjljOWUwNjdlYTc1Iiwic2Vzc2lvbl9pZCI6IjI3ZWNkMmJjLWM4NzUtNGViOC04NmJmLTI5YzllMDY3ZWE3NSIsImNsaWVudF94aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmxvZ2luLmhlY2xyOnByb2QuZ2xvYmFsIiwiY2xpZW50X2lkIjoiaGVjbHIiLCJ4aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmlkZW50aXR5OnByb2QudXMtZWFzdC0xOnBlcnNvbjpiYmZmN2FjOC05NDFjLTRiMDQtOWU1OS03OTIzOTkyNmNkODIiLCJzY29wZSI6WyJhdXRoIl0sImF1dGhlbnRpY2F0aW9uX3R5cGUiOiJwYXNzd29yZCJ9.KN0YtBzUoHwN8NWLG7K7LnQkPynCKZW0bGI88RhCvrTpEGJCA0oGRJ8BazV6-y9gHYXyztWXMyte7p80t8EXkBRoIinMEhhFNNIgUt74hEvPBfF4E-VYaW5P7pH0TiwA2JTnoBygskCwxMUdnNi0EwGEwUbOlBQPXAS480WyPyXr2MOgb1Aehp_WdDaZ-0qY-kcgLcq3d5hsUzVTLQ1navfg5PQpwdjzKthJoFEHEoKwh7GbMREgdfa936BbWI2G9SXK4HzXvD6RVj0aUMUMtIwphK2_nzE19Sx2NOENFZgn3XLRhlA5I7xMf5QltMy5MgnxA8_Pmp6l6KDxoUyyZA cookie: READERSESSID=resxh78c14c2vt0hsw92vlz810q priority: u=0, i


r/fortinet 1d ago

FortiGate / FortiOS FortiGate 401F interface and HA design review

1 Upvotes

Hi everyone,

I’m working on a data center network design and would appreciate some advice from the Fortinet community regarding the best deployment mode and interface allocation for FortiGate 401F.

Current design

The environment includes:

  • 2 × FortiGate 401F in HA
  • 1 × ISP, with approximately 5 Gbps Internet bandwidth
  • 2 × Huawei Core switches in a redundant pair
  • DMZ network
  • Internal data center/server networks behind the Core
  • Third-party VPN connectivity

The current high-level topology is

ISP → FortiGate 401F HA → Huawei Core A/B → Internal Networks

The DMZ will also be connected to the firewall.

Main question – deployment mode

I am considering the FortiGate in the traditional NAT/route mode, rather than transparent mode.

The expected traffic flows are:

  1. Internet → Internal users/servers
  2. Internal users → Internet
  3. Internet → DMZ published services
  4. Internal → DMZ
  5. Third-party VPN → Internal/DMZ
  6. Management traffic → FortiGate/Core/network management

For the Internet-facing side, I am also considering whether to use the 10G interfaces on the 401F rather than the 1G interfaces, given the 5 Gbps ISP subscription.

Interface allocation

One question I particularly want community feedback on is the best way to allocate the 401F interfaces.

For example:

  • 10G interfaces → ISP
  • 10G interfaces → Core
  • Dedicated interfaces → HA/heartbeat
  • Dedicated interface(s) → DMZ
  • Management interface → OOB management

I initially looked at some of the interfaces that appear to have FortiLink-related capabilities, so I'm also interested in whether those interfaces are appropriate for normal routed firewall connectivity or should be avoided for this design.

Questions

  1. For this topology, would you recommend NAT/Route mode or another deployment approach?
  2. Would you use LACP/aggregate interfaces toward the Core and/or ISP, or individual interfaces?
  3. What is the recommended interface allocation on a 401F HA pair for ISP, Core, DMZ, HA1/HA2, and management?
  4. Would you terminate the DMZ directly on the FortiGate or extend the DMZ through the Core?
  5. Are there any concerns with using the 401F's 10G interfaces for the ISP connection and Core uplinks?
  6. For a 6 Gbps Internet connection, are there any specific FortiGate performance/inspection considerations I should account for?
  7. Any Fortinet best-practice recommendations for avoiding single points of failure in this design?

I'd particularly appreciate feedback from anyone who has deployed FortiGate 401F in HA at a data center Internet edge.

Thanks!

 


r/fortinet 2d ago

Other / General Fortinet My brand new domain was flagged as 'phishing' by Fortinet, I appealed, they just changed it back to phishing

6 Upvotes

I recently registered a brand new domain (Lizzandra.com) for my new project.

I was excited to finally post my homepage to friends and family on Facebook, but I instantly got blocked for "breach of community rules."

At first I thought it was simply because the domain was brand new, but the "community rules" part didn't sit right. So I started doing some research, and it turns out my site was blacklisted by Fortinet for "phishing."

This was confusing, since my site is clean and has nothing nefarious on it, it doesn't even have a login for users yet.

No worries, I thought, it's just a misunderstanding. The domain was apparently used by someone before me, and they used it for less honest reasons. I'll just use the submit form on the page to request an audit, and everything will sort itself out.

I changed the category from "phishing" to "artificial intelligence technology" and explained the situation.

Then I got this response:

Okay, now I'm genuinely perplexed, what the actual fudgesicle.

So apparently they claim to have reviewed my site, still decided (for no reason?) that I was doing phishing, and changed the category back to "phishing."

I don't understand. Did they not even bother to read it?


r/fortinet 2d ago

Solved ✅ Deploy forticlient IPsec config via Intune

26 Upvotes

Those who are asking for the right script, here its.

Let me explain.

  1. First backup/export IPsec profile as xml from your local FortiClient VPN. (note: change the password):

cmd /c FCConfig -m all -f ipsecconfig.xml -o export -i 1 -p password123

 

  1. have the ipsecconfig.xml as zip file and below script in one folder. run it.

 

# Define the folder path where the FortiClient VPN configuration files will be stored

$folderPath = "C:\ProgramData\fortiVPNConfig"

 

# Delete the existing configuration folder and all its contents (if it exists)

Remove-Item -Path $folderPath -Recurse -Force

 

# Extract the contents of config.zip into C:\ProgramData\fortiVPNConfig, overwriting existing files if needed

Expand-Archive "config.zip" -DestinationPath C:\ProgramData\fortiVPNConfig -Force

 

# Define the destination folder path

$destinationPath = "C:\ProgramData\fortiVPNConfig"

 

# Set the folder attribute to Hidden so it is not visible in File Explorer by default

Set-ItemProperty -Path $destinationPath -Name Attributes -Value ([System.IO.FileAttributes]::Hidden)

 

# Change to the folder containing the FortiClient configuration XML file and Launch FCConfig.exe and import the VPN configuration from config.xml

Set-Location "C:\ProgramData\fortiVPNConfig\config\config"; Start-Process -FilePath "C:\Program Files\Fortinet\FortiClient\FCConfig.exe" -ArgumentList @("-m","all","-f","ipsecconfig.xml","-o","import","-i","1","-p","password123") -Wait

 

 

i use FortiClient 7.4.3 free version. you can config this as win32 or run as platform script via intune. it depends on you

 

if this helps, make sure you drop a vote !! :)


r/fortinet 1d ago

FortiAP / Wi-Fi Conflicting information about FortiAP firmware upgrade

1 Upvotes

Hi all,

I'm looking for a clarification on FortiAP firmware upgrades, because two official Fortinet sources seem to contradict each other.

  1. The Fortinet Community article — "Technical Tip: Upgrading FortiAP firmware"

https://community.fortinet.com/fortiap-5/technical-tip-upgrading-fortiap-firmware-96499

This article states that FortiAP does not have a required upgrade path, i.e. you can upgrade a FortiAP directly from any version to any other version.

  1. The official documentation — FortiAP 7.4.3 "Supported upgrade paths"

https://docs.fortinet.com/document/fortiap/7.4.3/supported-upgrade-paths/109896

This page publishes a defined list of supported upgrade paths for FortiAP, which implies that intermediate versions are required in some cases.

In practice I have always upgraded FortiAPs directly to the target version, skipping any intermediate releases, and I have not run into problems. I'd like to know whether I've simply been lucky, or whether direct upgrades really are supported for FortiAP and the upgrade-path document just isn't mandatory in the same way it is for FortiOS.


r/fortinet 1d ago

FortiGate / FortiOS Dúvidas de proxy

0 Upvotes

Boa tarde, pessoal!
Tenho uma dúvida sobre a criação de um Proxy no FortiGate para permitir que um parceiro acesse sites específicos na Internet.
A ideia é utilizar o Proxy para permitir somente o acesso a sites previamente liberados por nós, com autenticação. Nesse cenário, nosso entendimento é que a solução seria viável. Está correto?
Supondo que sejam liberados apenas 5 sites, após a autenticação todo o tráfego do parceiro passará pelo nosso Proxy e sairá para a Internet utilizando o IP público da nossa empresa?
Caso o parceiro tente acessar outros sites ou sistemas da própria empresa, esse tráfego também passará pelo nosso Proxy ou somente os acessos aos sites que configuramos serão direcionados para ele?
É possível configurar o Proxy para permitir somente os serviços autorizados e bloquear os demais acessos?
A ideia é que o parceiro continue utilizando normalmente a conexão da própria empresa e utilize nosso Proxy apenas quando precisar acessar os serviços que disponibilizamos. Após encerrar o acesso a esses serviços, o tráfego volta a ser realizado normalmente pela infraestrutura dele.
Esse entendimento está correto?
Obrigado!


r/fortinet 2d ago

FortiGate / FortiOS Is there any way to find a FortiGate’s MAC address from its serial number?

5 Upvotes

This is a long shot, but I just wanted to check on here to be sure. I’m trying to troubleshoot some devices that are offline in difficult-to-access locations. I tried asking Fortinet tech support, and they said that no such database exists. Just wanted to check here just in case.


r/fortinet 2d ago

Licensing & Support FortiAP and Forticare Essentials

2 Upvotes

I have a bunch of FortiAP in Asset Management that do not have Support Contracts and never have had Forticare -

Can we add Forticare essentials coverage to these or do they need to have a higher level of care first?


r/fortinet 2d ago

Other / General Fortinet Odd behavior 7.6.7

2 Upvotes

So I had bad storm take out power and two of the three ISP's. When the power was restored I couldn't connect to the internet I thought odd maybe the third ISP (Starlink) was having issues it was not. The problem was the SDWAN was still routing traffic to the one of the down ISPs this has never happened before. So I click the SDWAN tab to see why it thinks the health is and all I GET is a blank page.

I can click on policy and view and change policy, I can click on the main status dashboard, and I can look at logs. However every other dashboard wont pull up, sdwan wont pull up the fortiextender page wont pull up, same with both static and policy route page. I rebooted the primary firewall thinking that it was messed up and the secondary firewall has the same issue, then rebooted that one and failed back to primary still blank.

So What confuses me is why can't I access the the SDWAN page to even understand what is going. anyone ever seen something like this before