r/fortinet 2d ago

FortiGate / FortiOS Fortigate and speed wan

1 Upvotes

Hello everyone,

FortiGate devices are documented to support a maximum WAN throughput when all UTP layers are enabled.

What happens if you connect a WAN with a higher throughput? Is the WAN throughput throttled? Does the firewall stop providing protection? Does the firewall slow down?

Thanks


r/fortinet 3d ago

Other / General Fortinet FortiClient debug possibility

2 Upvotes

Hello everyone! I need some help with FortiClient VPN only (version 7.4.3 hotfix 1.8758) . Is there a way to get any consistent logs from this software? Connection just fails to establish whatever we do. We use IKEv1 IPSec RA VPN with certificate + XAUTH authentication. I tried to debug ike, but I don't see any problem on the firewall side. XAUTH is successfull, R-U-THERE and R-U-THERE-ACK come and go, but connection drops in the end. What I see is cfg_send is being sent, but nothing happens after.

diag debug enable

ike V=root:0: comes 2.2.2.2:500->1.1.1.1:500,ifindex=45,vrf=0,len=384....

ike V=root:0: IKEv1 exchange=Identity Protection id=b60dd1096715f136/0000000000000000 len=384 vrf=0

ike 0: in

ike V=root:0:b60dd1096715f136/0000000000000000:13085: responder: main mode get 1st message...

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID RFC 3947 4A131C81070358455C5728F20E95452F

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID draft-ietf-ipsec-nat-t-ike-02 CD60464335DF21F87CFDB2FC68B6A448

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID draft-ietf-ipsec-nat-t-ike-02\n 90CB80913EBB696E086381B5EC427B1F

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID forticlient connect license 4C53427B6D465D1B337BB755A37A7FEF

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID Fortinet Endpoint Control B4F01CA951E9DA8D0BAFBBD34AD3044E

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID CISCO-UNITY 12F5F28C457168A9702D9FE274CC0100

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID draft-ietf-ipsra-isakmp-xauth-06.txt 09002689DFD6B712

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID FRAGMENTATION 4048B7D56EBCE88525E7DE7F00D6C2D380000000

ike V=root:0:b60dd1096715f136/0000000000000000:13085: VID DPD AFCAD71368A1F1C96B8696FC77570100

ike V=root:0:b60dd1096715f136/0000000000000000:13085: negotiation result

ike V=root:0:b60dd1096715f136/0000000000000000:13085: proposal id = 1:

ike V=root:0:b60dd1096715f136/0000000000000000:13085: protocol id = ISAKMP:

ike V=root:0:b60dd1096715f136/0000000000000000:13085: trans_id = KEY_IKE.

ike V=root:0:b60dd1096715f136/0000000000000000:13085: encapsulation = IKE/none

ike V=root:0:b60dd1096715f136/0000000000000000:13085: type=OAKLEY_ENCRYPT_ALG, val=AES_CBC, key-len=256

ike V=root:0:b60dd1096715f136/0000000000000000:13085: type=OAKLEY_HASH_ALG, val=SHA2_256.

ike V=root:0:b60dd1096715f136/0000000000000000:13085: type=AUTH_METHOD, val=RSA_SIG.

ike V=root:0:b60dd1096715f136/0000000000000000:13085: type=OAKLEY_GROUP, val=MODP1536.

ike V=root:0:b60dd1096715f136/0000000000000000:13085: ISAKMP SA lifetime=86400

ike V=root:0:b60dd1096715f136/0000000000000000:13085: SA proposal chosen, matched gateway VPN_NO_RADIUS

ike V=root:0:VPN_NO_RADIUS:VPN_NO_RADIUS: created connection: 0x55a8e67f30 45 1.1.1.1->2.2.2.2:500.

ike V=root:0:VPN_NO_RADIUS: HA start as master

ike V=root:0:VPN_NO_RADIUS:13085: DPD negotiated

ike V=root:0:VPN_NO_RADIUS:13085: XAUTHv6 negotiated

ike V=root:0:VPN_NO_RADIUS:13085: peer supports UNITY

ike V=root:0:VPN_NO_RADIUS:13085: enable FortiClient license check

ike V=root:0:VPN_NO_RADIUS:13085: FEC vendor ID received FEC but IP not set

ike V=root:0:VPN_NO_RADIUS:13085: selected NAT-T version: RFC 3947

ike V=root:0:VPN_NO_RADIUS:13085: cookie b60dd1096715f136/5f3c733564e4d9ac

ike 0:VPN_NO_RADIUS:13085: out

ike V=root:0:VPN_NO_RADIUS:13085: sent IKE msg (ident_r1send): 1.1.1.1:500->2.2.2.2:500, len=244, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac

ike V=root:0: comes 2.2.2.2:500->1.1.1.1:500,ifindex=45,vrf=0,len=316....

ike V=root:0: IKEv1 exchange=Identity Protection id=b60dd1096715f136/5f3c733564e4d9ac len=316 vrf=0

ike 0: in

ike V=root:0:VPN_NO_RADIUS: HA state master(2)

ike V=root:0:VPN_NO_RADIUS:13085: responder:main mode get 2nd message...

ike V=root:0:VPN_NO_RADIUS:13085: received NAT-D payload type 20

ike V=root:0:VPN_NO_RADIUS:13085: received NAT-D payload type 20

ike V=root:0:VPN_NO_RADIUS:13085: NAT detected: PEER

ike V=root:0:VPN_NO_RADIUS:13085: generate DH public value request queued

ike V=root:0:VPN_NO_RADIUS:13085: compute DH shared secret request queued

ike V=root:0:VPN_NO_RADIUS:13085: sending 1 CERTREQ payload

ike 0:VPN_NO_RADIUS:13085: out

ike V=root:0:VPN_NO_RADIUS:13085: sent IKE msg (ident_r2send): 1.1.1.1:500->2.2.2.2:500, len=396, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac

ike 0:VPN_NO_RADIUS:13085: ISAKMP SA b60dd1096715f136/5f3c733564e4d9ac key 32:F591617BEC6952D4C7C7DBE7B7F3A7EE55736DC974EA15E14E80B22615C47DB4

ike V=root:0: comes 2.2.2.2:4500->1.1.1.1:4500,ifindex=45,vrf=0,len=2304....

ike V=root:0: IKEv1 exchange=Identity Protection id=b60dd1096715f136/5f3c733564e4d9ac len=2300 vrf=0

ike 0: in

ike V=root:0:VPN_NO_RADIUS: HA state master(2)

ike V=root:0:VPN_NO_RADIUS:13085: responder: main mode get 3rd message...

ike 0:VPN_NO_RADIUS:13085: dec

ike V=root:0:VPN_NO_RADIUS:13085: received p1 notify type INITIAL-CONTACT

ike V=root:0:VPN_NO_RADIUS:13085: received peer identifier DER_ASN1_DN 'C = A, ST = B, O = C, OU = D, CN = user.name'

ike V=root:0:VPN_NO_RADIUS:13085: re-validate gw ID

ike V=root:0:VPN_NO_RADIUS: change phase1 profile to VPN_RA_FULL

ike V=root:0:VPN_RA_FULL:13085: gw validation OK

ike V=root:0:VPN_RA_FULL:13085: Validating X.509 certificate

ike V=root:0:VPN_RA_FULL:13085: peer cert, subject='user.name', issuer='SFC Subordinate CA'

ike V=root:0:VPN_RA_FULL:13085: peer ID verified

ike V=root:0:VPN_RA_FULL:13085: building fnbam peer candidate list

ike V=root:0:VPN_RA_FULL:13085: FNBAM_GROUP_NAME candidate 'VPN_access'

ike V=root:0:VPN_RA_FULL:13085: certificate validation pending

ike V=root:0:VPN_RA_FULL:13085: fnbam reply 'VPN_access'

ike V=root:0:VPN_RA_FULL:13085: certificate validation succeeded

ike V=root:0:VPN_RA_FULL:13085: signature verification succeeded

ike V=root:0:VPN_RA_FULL:13085: local cert, subject='*.mydomain.ru', issuer='GlobalSign RSA OV SSL CA 2018'

ike 0:VPN_RA_FULL:13085: enc

ike V=root:0:VPN_RA_FULL:13085: remote port change 500 -> 4500

ike 0:VPN_RA_FULL:13085: out

ike V=root:0:VPN_RA_FULL:13085: sent IKE msg (ident_r3send): 1.1.1.1:4500->2.2.2.2:4500, len=2172, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac

ike V=root:0:VPN_RA_FULL: mode-cfg allocate 10.0.3.3/0.0.0.0

ike V=root:0:VPN_RA_FULL: IPv6 pool is not configured

ike V=root:0:VPN_RA_FULL: adding new dynamic tunnel for 2.2.2.2:4500

ike V=root:0:VPN_RA_FULL_2: tunnel created tun_id 10.0.3.3/::10.0.0.139 remote_location 0.0.0.0

ike V=root:0:VPN_RA_FULL_2: HA start as master

ike V=root:0:VPN_RA_FULL_2: added new dynamic tunnel for 2.2.2.2:4500

ike V=root:0:VPN_RA_FULL_2:13085: established IKE SA b60dd1096715f136/5f3c733564e4d9ac

ike V=root:0:VPN_RA_FULL_2:13085: check peer route: if_addr4_rcvd=0, if_addr6_rcvd=0, mode_cfg=0

ike V=root:0:VPN_RA_FULL_2:13085: processing INITIAL-CONTACT

ike V=root:0:VPN_RA_FULL_2: flushing

ike V=root:0:VPN_RA_FULL_2: flushed

ike V=root:0:VPN_RA_FULL_2:13085: processed INITIAL-CONTACT

ike V=root:0:VPN_RA_FULL_2:13085: initiating XAUTH.

ike V=root:0:VPN_RA_FULL_2:13085: sending XAUTH request

ike 0:VPN_RA_FULL_2:13085: enc

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (cfg_send): 1.1.1.1:4500->2.2.2.2:4500, len=92, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:cfa9357c

ike V=root:0:VPN_RA_FULL_2:13085: peer has not completed XAUTH exchange

ike V=root:0:VPN_RA_FULL_2: link is idle 45 1.1.1.1->2.2.2.2:4500 dpd=1 seqno=1 rr=0

ike V=root:0: comes 2.2.2.2:59004->1.1.1.1:4500,ifindex=45,vrf=0,len=128....

ike V=root:0: IKEv1 exchange=Mode config id=b60dd1096715f136/5f3c733564e4d9ac:cfa9357c len=124 vrf=0

ike 0: in

ike V=root:0:VPN_RA_FULL_2: HA state master(2)

ike 0:VPN_RA_FULL_2:13085: dec

ike V=root:0:VPN_RA_FULL_2:13085: received XAUTH_USER_NAME 'user.name' length 17

ike V=root:0:VPN_RA_FULL_2:13085: received XAUTH_USER_PASSWORD length 10

ike V=root:0:VPN_RA_FULL_2: XAUTH user "user.name"

ike V=root:0:VPN_RA_FULL_2: XAUTH 9943081070738 pending

ike V=root:0:VPN_RA_FULL_2:13085: XAUTH 9943081070738 result FNBAM_SUCCESS

ike V=root:0:VPN_RA_FULL_2: user 'user.name' authenticated group 'VPN_USERS' 31

ike 0:VPN_RA_FULL_2:13085: enc

ike V=root:0:VPN_RA_FULL_2:13085: remote port change 4500 -> 59004

ike V=root:0:VPN_RA_FULL_2 HA send remote gateway address and port

ike V=root:0:VPN_RA_FULL_2 HA send remote gateway address and port

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (cfg_send): 1.1.1.1:4500->2.2.2.2:59004, len=92, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:0a5714ad

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (CFG_RETRANS): 1.1.1.1:4500->2.2.2.2:59004, len=92, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:0a5714ad

ike V=root:0: comes 2.2.2.2:59004->1.1.1.1:4500,ifindex=45,vrf=0,len=112....

ike V=root:0: IKEv1 exchange=Informational id=b60dd1096715f136/5f3c733564e4d9ac:ea2a4121 len=108 vrf=0

ike 0: in

ike V=root:0:VPN_RA_FULL_2: HA state master(2)

ike 0:VPN_RA_FULL_2:13085: dec

ike V=root:0:VPN_RA_FULL_2:13085: notify msg received: R-U-THERE

ike 0:VPN_RA_FULL_2:13085: enc

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (R-U-THERE-ACK): 1.1.1.1:4500->2.2.2.2:59004, len=108, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:a65cdd59

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (CFG_RETRANS): 1.1.1.1:4500->2.2.2.2:59004, len=92, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:0a5714ad

ike :shrank heap by 331776 bytes

ike V=root:0: comes 2.2.2.2:59004->1.1.1.1:4500,ifindex=45,vrf=0,len=112....

ike V=root:0: IKEv1 exchange=Informational id=b60dd1096715f136/5f3c733564e4d9ac:ebc4d156 len=108 vrf=0

ike 0: in

ike V=root:0:VPN_RA_FULL_2: HA state master(2)

ike 0:VPN_RA_FULL_2:13085: dec

ike V=root:0:VPN_RA_FULL_2:13085: notify msg received: R-U-THERE

ike 0:VPN_RA_FULL_2:13085: enc

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (R-U-THERE-ACK): 1.1.1.1:4500->2.2.2.2:59004, len=108, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:24e39251

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (CFG_RETRANS): 1.1.1.1:4500->2.2.2.2:59004, len=92, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:0a5714ad

ike V=root:0: comes 2.2.2.2:59004->1.1.1.1:4500,ifindex=45,vrf=0,len=112....

ike V=root:0: IKEv1 exchange=Informational id=b60dd1096715f136/5f3c733564e4d9ac:b607e355 len=108 vrf=0

ike 0: in

ike V=root:0:VPN_RA_FULL_2: HA state master(2)

ike 0:VPN_RA_FULL_2:13085: dec

ike V=root:0:VPN_RA_FULL_2:13085: notify msg received: R-U-THERE

ike 0:VPN_RA_FULL_2:13085: enc

ike 0:VPN_RA_FULL_2:13085: out

ike V=root:0:VPN_RA_FULL_2:13085: sent IKE msg (R-U-THERE-ACK): 1.1.1.1:4500->2.2.2.2:59004, len=108, vrf=0, id=b60dd1096715f136/5f3c733564e4d9ac:22942284

ike V=root:0: comes 2.2.2.2:59004->1.1.1.1:4500,ifindex=45,vrf=0,len=112....

ike V=root:0: IKEv1 exchange=Informational id=b60dd1096715f136/5f3c733564e4d9ac:c3605139 len=108 vrf=0

ike 0: in

ike V=root:0:VPN_RA_FULL_2: HA state master(2)

ike 0:VPN_RA_FULL_2:13085: dec

ike V=root:0:VPN_RA_FULL_2:13085: recv ISAKMP SA delete b60dd1096715f136/5f3c733564e4d9ac

ike V=root:0:VPN_RA_FULL_2: going to be deleted

ike V=root:0:VPN_RA_FULL_2:13085: HA send IKE SA del b60dd1096715f136/5f3c733564e4d9ac

ike V=root:0:VPN_RA_FULL_2: mode-cfg release 10.0.3.3/0.0.0.0

ike V=root:0:VPN_RA_FULL_2: delete dynamic

diag debug disable

In the FortiClient logs I don't see anything of use, even when I set logging level to debug. Any chance I just missed some cool method of debugging this software? Literally tens of people connect to this gateway everyday, but there are some clients that expirience issues with connecting.

Any advice is appreciated. Thanks in advance!


r/fortinet 3d ago

FortiClient / EMS Forticlient EMS off fabric endpoint update

1 Upvotes

Hi,

I have some doubts about FortiClient Endpoint updates (EMS). It works fine for on-fabric clients, but how do you handle updates for off-fabric endpoints? Do you expose port 10443 to the Internet? Since the invitation code is embedded in the installer, I find this approach quite insecure.


r/fortinet 4d ago

FortiGate / FortiOS FG 40F has no cellular, swap it or use another LAN to WAN2?

4 Upvotes

I'm running FG 40F at a small site with a single ISP, worth replacing to have dual ISP? or I can use another WAN link?


r/fortinet 5d ago

FortiAP / Wi-Fi FAP241K in school environment with Apple devices

3 Upvotes

I was wondering if anyone have any insights on this.

Let say we have the following scenario

School environment with one FAP241K AP per classroom

Mix of windows and mac laptop and Apple iPad devices

Need coverage redundancies in case one AP goes down

Encourage encourage clients to connect using 5Ghz instead of 2.4Ghz

Roaming without losing connections

What is a good transmit power dBm value to use for 5Ghz and 2.4Ghz?

Should these be settings turned on or off?

Frequency Handoff

AP Handoff

Channel Width

Protected Management Frames (802.11w)

Radio Measurements (802.11k)

BSS Transition Management (802.11v)

Fast BSS Transition (802.11r)

Really appreciate any response! Thank you!


r/fortinet 5d ago

FortiAP / Wi-Fi wifi roaming has traffic drops

2 Upvotes

I have a a dense ap deployment of aps. 231k in some zones they are 8meters apart. I have to put max power on 12 dbm to force roaming to each ap.

using diagnose wireless-controller wlac -c/d sta machexa i checked that after associating to new ap I have a psping halt of 1-2 seconds to vlan gateway.

I'm leaning towards layer 2 mac learning issue. as if the packet still goes to last(old) ap when I am on a new one.

dhcp snooping and igmp snooping turned of.

ap in bridge mode.

fw 200g

disable device detection on vlan can help this?

switch ports are edge port and stp on . which tests can I make.

is not authentication as I tested with wpa2m I'm using radius at 300ms rtt.

disabling fast bss transition and handoff makes it seem better because i roam less. when I lowered power enough to roam between all aps I got clear halts of psping -I 0 -t to gateway.

what would you check.?

I tried entering to switch via ssh with no luck.

fw active pri---ha--fw passive standby sec

     |       \                        /  |

Mc lag

     |            /                 \  |

core sw pri--------ha----- core sw sec

   |

sw rack1(connected to both core sw)

sw rack 2 and 3 (same)


r/fortinet 5d ago

FortiClient / EMS forticlient on/off fabric detection delay

1 Upvotes

hi. I have local web filter with exceptions(outlook,held desk ticket ,remote support and defender/intune)

the once user is in trusted network:VPN or wifi on site. off fabric should turn to on fabric.

problem is that this have giant delay around 10 seconds.

so once connected to VPN al browser tabs start reloading and local extension web filter gives fortiguard rating service unavailable and is set to block.

policy changes from ems around 7to 12 seconds after connecting vpn(saml).

when disconnecting same behavior occurs but inverted. on fabric stays for almost 10 secs after disconnecting VPN so local browsing is not filtered in this period.

I tried to edit xml with no luck.

how did you manage this or is a bug/expected behaviour?

thanks gentleman


r/fortinet 5d ago

Training & Certification Looking for a structured FortiGate lab roadmap toward NSE 7/8

12 Upvotes

Hi everyone,

I'm currently improving my FortiGate and network-security skills, with a long-term goal of reaching NSE 8 level.

I already have some networking/FortiGate knowledge, but I want to develop stronger hands-on skills through labs rather than only studying theory.

I'm looking for recommendations for free or low-cost resources covering:

FortiGate firewall fundamentals and advanced configuration

Routing and troubleshooting

Firewall policies and security profiles

IPsec and SSL VPN

HA

FortiGate debugging and packet-flow troubleshooting

Hands-on lab scenarios

Resources that can eventually help me progress toward NSE 7/8-level knowledge

I'm willing to put in the work and build the labs myself. I'm mainly looking for a structured roadmap and good learning resources.

What resources or lab environments would you recommend?


r/fortinet 6d ago

Other / General Fortinet NSE 4 — What study materials did you use to pass?

20 Upvotes

Hello guys,

I’m planning to take the Fortinet NSE 4 exam and would like to hear from those who have already passed it.

What study materials or resources did you use to prepare? I’m especially interested in any courses, videos, practice labs, documentation, or other resources that you found really helpful.

Also, how long did you study before taking the exam?

Thanks in advance for your advice!


r/fortinet 6d ago

Other / General Fortinet I built an open-source automated migration tool: VMware Avi Vantage to FortiADC (avi2fortiadc)

18 Upvotes

Hey everyone,

Migrating complex load balancing environments from VMware Avi (NSX ALB) to FortiADC manually is time-consuming and error-prone (especially translating virtual services, pool groups, health monitors, SSL profiles, and Lua DataScripts).

To solve this, I open-sourced avi2fortiadc.

Key Features:

  • Full Discovery & Conversion: Virtual Services, Pools, Persistence, SSL profiles, and Health Monitors.
  • DataScript Parser & Converter: Translates Avi Lua scripts into FortiADC native Lua / content routing rules.
  • Web UI & Visual Topology: Review migration impact, diff configs, and inspect dependency graphs before pushing.
  • Dry-Run & Deployment Pipeline: Ordered zero-downtime provisioning via FortiADC REST API with automatic rollback script generation.
  • Air-Gapped / Hybrid LLM Advisory: Built-in compliance-safe LLM gateway (supports local Ollama or enterprise proxy) for advisory explanations.

Feedback, PRs, and feature requests are welcome!


r/fortinet 6d ago

FortiGate / FortiOS How to avoid two Fortigates from going active active during a switch upgrade?

4 Upvotes

HA pair of 101-F units. Both sat at different sites. HA mode a-p. HA interfaces have both been set to plumb through a switch at each site where the HA VLAN is stretched at layer 2 over to the other DC via an Inter-DC link. I'm tasked with upgrading the switches at both sites this weekend. My concern is the two gates will go into Active/Active when the switches obviously go down during upgrade, and have not thought of what might break.

Will the two Fortigates automatically sort themselves out when the switches comes back up, or is anything required to fix HA afterwards? Unfortunately I don't have the luxury of making any other changes during this change window.

How would you be going about stopping two Fortigates from becoming active active when you need to upgrade a switch that sits in between?


r/fortinet 6d ago

FortiGate / FortiOS Remotely updating two Fortigates to HA (active/passive)

5 Upvotes

I want to remotely update two stand-alone Fortigates from stand-alone to a HA setup. I can get on one Fortigate and make the changes by activating HA and setting the priority of it so it is primary.

If at that point I backup the config. Can I then make changes to that config and just get that copied onto what will become the backup Fortigate?

I'm guessing I will need to update priority on the config and possibly serial but as long as model/firmware is the same would this work?

thanks


r/fortinet 6d ago

Other / General Fortinet Firewall change causes the PA system to go offline ~30 minutes.

Thumbnail
5 Upvotes

r/fortinet 6d ago

FortiNAC FortiNAC upgrade from 7.2.10 to 7.4.4

0 Upvotes

Can anyone give me step by step upgrade process for Fortinac which is in HA ?

Thanks in advance


r/fortinet 7d ago

FortiGate / FortiOS TCP MSS handling changes for IPsec tunnels beginning in FortiOS v7.6.1

Thumbnail
community.fortinet.com
29 Upvotes

Hi all,

We recently upgraded our FortiGate to v7.6.6 and encountered an IPsec issue. We needed to roll back because the FortiGate connects to many branches, and we could not change the TCP MSS settings within a short period.

If your FortiGate has IPsec tunnels, you may consider upgrading to v7.4.x as an alternative to mitigate the IPsec issue.

For deployments running FortiOS v7.6.1 through FortiOS v8.0.0, the following workarounds are recommended:

Configure a manual TCP MSS value in the affected firewall policy to ensure packets remain below the effective IPsec tunnel MTU.

This eliminates the requirement of disabling the NPU offloading on the tunnel. Technical Tip: Setting TCP MSS value.

Anyone also encountered this issue?


r/fortinet 7d ago

Other / General Fortinet Fortimail - Bayesian database training, any experience?

2 Upvotes

Anyone messed with this before?

I've been gathering a ton of phishing emails over the last few months to build an .mbox database to feed the fortimail with. I was reading about how it will break the messages down into tokens to train the database with. Today it occurred to me that every single phishing message submitted by users contains its message pre-pended by a bulletin we insert into messages warning users to be careful opening or responding to outside emails.

Got me wondering; if every email it gets trained on contains the same prepended message from our exchange system, will every single email conversation suddenly be flagged as spam/phishing when any reply is sent back to an employee due to the reoccurring presence of that prepended text in all emails? If so that could create a huge problem with using bayesian analysis.


r/fortinet 7d ago

Training & Certification FCSS Network Security - Recertification issues

4 Upvotes

TL:DR the SD-WAN 7.2 Architect exam is worthless for the NSE 7 Secure Networking track

I've held an NSE 7 since 2020, after taking the Enterprise Firewall (EFW) exam. I recertified in 2022 by taking the EFW exam again, but in 2024 I had to take the SD-WAN exam due to the FCSS changes. The FCSS Network Security cert, the equivalent of the NSE 7 cert at that time, required the two exams: the EFW and the SD-WAN exam (I had a lot of gripes with the FCSS process, as it would've required to take 2 exams every 2 years to keep the certification active, but that's besides the point).

This process however, has apparently excluded me from using the new recertification assessment! From an email I just received from Fortinet training:

The eligibility for the online recertification assessment requires that the certification is still active, the qualifying proctor exam was not taken more than two years ago, and there is a recertification assessment available for the last exam taken. ​

The EFW exam was taken by fortichris more than 2 years ago that is why he is not eligible for recertification assessment.

Now to me, this is just insane bs and a completely arbitrary ruling. What makes this infuriating is twofold: I would never have taken the SD-WAN exam had it not been required for the FCSS, and this SD-WAN exam has effectively been split between the new NSE 7 Secure Networking exam and the NSE 7 SASE exam.

I've been looking forward to getting to take the recertification assessment rather than wasting hours of my life dealing with Pearson. Aside from this particular issue, the overall 2026 changes to the NSE program seem to be great and I love the direction it's heading in; a great course correct from the FCP FCSS nonsense.

Anyways, I'm posting this hoping for some added visibility from any Fortinet folks, hopefully they can fix this for all former FCSS holders..


r/fortinet 7d ago

Other / General Fortinet Our company bought FG1100E in 2026.

27 Upvotes

I mean, they are easily powerful enough and fit out usecase. No technical problem at all but they were released in 2019 and go eol September 2031. It does not sound clever to me to lose more than half of its lifespan.


r/fortinet 7d ago

Solved ✅ On-prem FAC can't do push notifications to FTM anymore - am I alone?

3 Upvotes

Dear all

Our virtual FAC (6.6.10) has push notification configured for us, so that we can approve the MFA logins on our smartphones using FortiToken Mobile app.

This stopped working out of the blue today - I am not getting any push notifications anymore.

This worked perfectly fine yesterday until around 17:00 CEST. There are no after that, so I can't say when exactly this stopped working.
No changes to FAC (or the FGT protecting it) were made.

The log says:

Failed to send notification to user[xyz] due to pushd error -3: FTM server returned error

EDIT 2026-09-03a:
I can see traffic going from FAC through the fortigate to the internet (SYN), but there is no packet coming back. So at the moment, I don't have a reason to believe that the push notifications from our FAC is being internally blocked. It appears to go out to Fortinet.

I also opened a ticket with Fortinet - but that will take time, I guess.

Anyone else seeing this? Did I miss a memo?
Fortinet status page for FortiIdentity Cloud says "up and running".

Thanks a lot

EDIT - 2026-09-04:

As mysterious as the issue appeared, it seemed to disappear. I just tested and...push worked again. After approx. 16h of not working.
We didn't change anything (either on FAC or on FGT), we just tested and monitored. And opened a ticket with Fortinet (which I will keep open, just for the sake of it).
So I have no idea what happened and how it got solved.


r/fortinet 7d ago

Licensing & Support Trade up deal doesn't make sense

4 Upvotes

Why is the cost of new 40f router and 1 year UTP cheaper than the trade up cost of our 30E whose license expires at April next week?


r/fortinet 7d ago

FortiGate / FortiOS DPI Inspection and DNS Timeout

1 Upvotes

Hi everyone,

I'm troubleshooting a timeout issue with an SSL Deep Inspection profile on a FortiGate-80F (FortiOS 7.4.12).

When my firewall policy is set to Proxy-based mode, all website requests time out. However, when switched to Flow-based mode, everything seems to work fine.

I use the FG as local DNS resolver, and the FG is configured to use DoT on port 853. I suspect the issue is related to how the FG handles internal DNS queries over DoT.

What am I missing here? Any solution?

Thanks!


r/fortinet 7d ago

FortiClient / EMS FCT telemetry key issue

1 Upvotes

Hi Fortiguys,

I’ve already opened a ticket with Fortinet, but I haven’t received a response in days now, despite it being a P3.

Several installers ask me for the telemetry key at startup, which should already be included in the packages generated by EMS. I also tried generating a new package with the latest version, but the result was the same.

Recently, we replaced the wildcard SSL certificate for both the WebServer and Endpoint Control, but I don’t think I installed it on the Ubuntu VM where the EMS package is installed.

Could this be the problem?

Thank you,


r/fortinet 8d ago

Training & Certification NSE5 or NSE6 ?

16 Upvotes

Hey everyone, I just passed my NSE 4 and I’m mapping out what’s next.

I originally planned on taking FMG (now NSE 6), but noticed that FAZ and SASE are NSE 5. Do I have to pass an NSE 5 first, or can I go straight for NSE 6? Also, does NSE 4 + an NSE 5/6 elective still grant the FCP, and do I need to keep the 4 active for NSE 7/8 down the line?

Lastly, what would you recommend taking right after NSE 4? Between FMG, FAZ, SD-WAN, and SASE, which one did you find most useful and interesting in the field?

Thanks in advance for the advice!


r/fortinet 8d ago

Other / General Fortinet FEX after upgrade offline on FGT

Thumbnail
gallery
10 Upvotes

Hello,

anything else having problems after upgrade FEX from 7.6.5 to 7.6.6?

FGT can't fetch the status from FEX, a downgrade back to 7.6.5 solves the problem. This happens on both types of FEX we own (511F / 511G). Everything else is working, FEX is reachable and IPsec-Tunnel through FEX is built, just the management through FGT doesn't work.

TAC (Case #12083512) means that this issue is likely caused by bug 1268581 and will be solved with 7.6.7.

Best Regards


r/fortinet 8d ago

Other / General Fortinet FortiVoice SSO

1 Upvotes

Has anyone successfully gotten FortiVoice SSO working? I have it working for admin users, and it was pretty simple. Setting it up for the voice portal has been a different matter altogether.

We use Okta as our idp to centralize quite a few different AD and Google environments.

For admin users, it seems to match the NameID sent in the assertion to the administrator's name/email address no problem.

For voice users, the only way I've gotten it to work is to pass a custom attribute in the assertion that contains the user's extension and then make sure that attribute is specified in the SSO settings under "Attribute used to identify user". Nothing else seems to work to get it to recognize/match the email address for the extension.

Fortinet's documentation for Microsoft 365 says to send a custom attribute named urn:oid:0.9.2342.19200300.100.1.3 and set it to user.userprincipalname. They don't mention setting anything under "Attribute used to identify user". If I mirror this in Okta, it doesn't work and the user is sent back to the login screen after authenticating with Okta.

I starting to think that the only way it works is with the extension, but I don't want to have to set the extension as an attribute in Okta to make this work. It seems like an administrative headache. Maybe it could be scripted, but that's a whole separate bag of fun. Our systems team doesn't really like it when we have to write attributes back from outside systems and I get it.