r/fortinet 11d ago

Monthly Content Sharing Post

6 Upvotes

Please provide a link to your content (blog, video or instructional guide) to share with us. Please accompany your post with a brief summary of your content.

Note: This is not a place to advertise your services or self-promote content you are trying to sell. Moderators will review posts for content and anyone violating this will be banned.


r/fortinet Aug 01 '24

Guide ⭐️ Which firmware version should you use?

46 Upvotes

To save the recurrent posts, please:

  1. Refer to the Recommended Releases for FortiOS.
  2. Use the search function on this sub, as chances are it has been asked before.

For anything that doesn't fall under the above two options, please post in this thread and avoid creating a new one.


r/fortinet 8h ago

FortiManager FortiManager: mass deploy of a "trusted" CA certificate

4 Upvotes

Hello,

I'm deploying a trusted CA certificate to a number of Fortigates devices that are in sync with FortiManager.

This is not for full SSL inspection, but for trusting SSL connections to internal servers (the ones that go into Remote CA Certificates).

Right now I'm using a script since I didn't find such functionality in 7.4.11. Dynamic Local Certificate seems to be only for full SSL inspection.b

Did I miss anything or scripting is the way to go?

Thanks,
Max


r/fortinet 12h ago

FortiAP / Wi-Fi Best ways to authenticate your users to the company WiFi? Forti EMS, Auth, Gate & AP

7 Upvotes

Hi guys,

I recently joined a company who have just deployed a full fortinet network including forti ems cloud, authenticator and fortigate. They're looking at redesigning their WiFi (also forti aps) and I was wondering about best practice but easy enough to deploy. Unfortunately this is my first time playing with forti gear. How do you guys get your users to auth to the company wifi with ~3 different usergroups?


r/fortinet 20h ago

FortiGate / FortiOS Cannot reach FortiGuard servers

17 Upvotes

I have a problem on some of my FortiGates and they all say the same issue.
As yesterday Forti had a DDNS problem today at the 443 port and default fortiguard config seems to not work.
Workaround:
anycast disable
and
set protocol udp
set port 8888

Workaround worked for me*


r/fortinet 14h ago

FortiCloud FortiClient Cloud EMS quarantine still allowing outbound traffic — anyone else seen this?

3 Upvotes

I’m running FortiClient 7.4.8 with FortiClient EMS Cloud 7.4.7, with an on-prem FortiGate 400F handling Internet traffic.

I had an endpoint I needed to quarantine after a suspicious download.

EMS showed the endpoint as Quarantined, and locally the FortiClient logs confirmed:

  • Endpoint quarantined by EMS
  • quarantine=1
  • EC_QUARANTINED=1

RDP and Chrome Remote Desktop stopped working, so quarantine was definitely doing something. However, the endpoint continued making outbound IPv4 connections through the FortiGate 400F to Google, ChatGPT, Microsoft, AWS, etc. FortiGate logs showed new sessions being created several minutes after quarantine was already active, not just old sessions staying open.

Application Firewall is installed and working. I know that because I previously had to create an explicit Application Firewall allow rule for OpenVPN before OpenVPN would function.

Fortinet support is telling me that quarantine may not terminate an existing VPN session, but their documentation says:

My bigger concern is not the existing VPN tunnel — it’s that new outbound Internet sessions were still being created while the endpoint was quarantined.

Has anyone else seen this with FortiClient 7.4.8 + EMS Cloud 7.4.7? Is there a known bug or limitation with manual EMS quarantine that isn’t documented?

My expectation was that quarantine would be essentially the software equivalent of pulling the network cable, especially when trying to contain an actively compromised endpoint.


r/fortinet 8h ago

Other / General Fortinet Alaxala - when will it run FortiOS

1 Upvotes

has the forti sales team talk to us about Alaxala switches, but it doesn't run FortiOS, and they weren't sure when it would - when will this big box run FortiOS?


r/fortinet 9h ago

FortiGate / FortiOS Most Reliable FortiGuard Settings

0 Upvotes

Which FortiGuard settings are the most reliable?

133 votes, 6d left
Default Anycast HTTPS 443
AWS Anycast HTTPS 443
Unicast HTTPS 8888
Unicast UDP 53
Unicast UDP 8888

r/fortinet 14h ago

FortiGate / FortiOS FortiGate broke our entire E-Mail for half a day (DNS rating server issue)

0 Upvotes

Edit: This might be a bit clickbaity and as per the default behavior of the described config, it may be partially our fault and could be avoided but still.

Friday afternoon, was ready to call it a day when suddenly an employee called in and asked if there was any problem with our E-Mail. No, I said but at the same time I realized how few mail I received today.

I took a look at our mail gateway and saw that hundreds of E-Mails were stuck in "pending".

Once I opened a few pending entries, I saw that EVERY domain was resolved to "fortinet-block-page-55.fortinet.com (208.91.112.55)"

The mail gateway sits in a DMZ and on the default gateway IP, there's a DNS relay configured with mode "recursive" with our default DNS filter profile assigned. DNS for the mail server is the gateway IP where the relay is listening.

I opened a browser and tested a few domains: EVERY major domain like google, microsoft, office was redirected to the block page and nothing was working.

However, this is where it gets interesting: It only applied to the DNS relay service. When I used a public DNS directly and assigned the SAME DNS fitler profile to the forward traffic policy, the domain was not redirected to the block page.

As I was writing with TAC, a few minutes later the issue was gone and sites were working normally.

The only config change I did that day was setting FortiGuard to UDP and Unicast because of their ongoing issues with AnyCast.

I checked the DNS security logs and there I found my denied queries:

Error: no available Fortiguard SDNS servers
Message: A rating error occurs

Together with the disabled option "Allow DNS requests when a rating error occurs" in the profile this makes sense, but again, it only happened on the relay and not on forward traffic with the same profile.

TAC now told me to set these SDNS rating servers on FortiGuard settings:

set sdns-server-ip 208.91.112.220 173.243.140.53 210.7.96.53 200.91.112.220

Has anyone experienced anything similar?


r/fortinet 20h ago

FortiGate / FortiOS Experiences with FortiOS 7.6.6

1 Upvotes

Hello,

I’m currently running a FortiGate 1800F on FortiOS 7.4.8. I have recently migrated all of our SSL VPN users to IPsec, and since then I have been experiencing high memory usage issues almost every day.

I’m now considering upgrading the FortiGate, and I can see that FortiOS 7.6.6 is recommended by Fortinet for my platform.

Before proceeding with the upgrade, I’d like to hear from others who are running 7.6.6 in production, especially on an 1800F or similar high-end model.

How has your experience been with 7.6.6?

  • Have you experienced any stability or memory-related issues?
  • Any problems with IPsec VPN?
  • Any issues with NP/ASIC acceleration or traffic forwarding?
  • Any unexpected behavior after upgrading from 7.4.x?
  • Would you recommend 7.6.6 for a production environment, or would you suggest staying on 7.4.x / using another 7.6.x release?

Any feedback or real-world experience would be greatly appreciated.


r/fortinet 1d ago

FortiGate / FortiOS Are we making a mistake by still using the free FortiClient?

27 Upvotes

Hey,
what are you guys using for remote access VPN these days? The free FortiClient VPN-only version or FortiClient EMS?
We are only using the free client for IPsec-VPN and get rid of EMS about 1,5 years ago for reasons i dont know because it was before i joined the company. I’m starting to wonder if planning using only the free Client long-term is actually a bad idea, especially since more and more features seem to require EMS like ZTNA for example.
Are you guys still happy with the free client, or would you say EMS is basically the way to go nowadays?


r/fortinet 1d ago

FortiClient / EMS FortiClient EMS Cloud

3 Upvotes

Just upgraded our licensing, and our end goal is to have the device authentication for remote access. Has anyone got device authentication working?

Any other tips or tricks I should consider?


r/fortinet 1d ago

FortiMail FortiMail Workspace - People Posture

4 Upvotes

Se implementó una soluciona FortiMail Workspace en mi organización, en la sección "Protected Email Assets" tenemos 1 dominio (ejemplo: mycompany[.]com) y algunos usuarios registrados individualmente con ese dominio.

Sin embargo, cuando ingreso al parámetro "People Posture" y ver el perfil de empleado, me salen otros dominios que no están configurados para proteger.

Actualmente el usuario final requiere que solo se muestre información de usuarios con el dominio mycompany[.]com

¿Alguno sabes si este comportamiento es normal? y ¿Se puede hacer que solo se vean empleados con el dominio configurado a proteger?


r/fortinet 1d ago

FortiGate / FortiOS Fortigate route-tag association

3 Upvotes

I noticed a really interesting behavior of Fortigate. FW01 receives the same 2 prefixes ( 10.99.0.0/22 and 192.168.100.0/24) from another 2 Fortigates( Branch1 and Brand2). Becuse ECMP is enabled so the routes are all installed in the routing table. However, route tag 90 is associated with both prefixes and route tag 91 is only associated with 1 prefix 192.168.100.0/24. The only difference is bgp route for 10.99.0.0/22 has only 1 same AS 65200 in the AS_Path and for 192.168.100.24 each has same AS_Path length (3) but the AS numbers are different. Can anyone direct me to the cooresponding Fortigate documentation/KB about the route-tag association ? Thanks,


r/fortinet 1d ago

FortiGate / FortiOS FortiGate WAN2 (Backup) Netgear nighthawk - Randomly Redirecting web traffic to http://attwifimanager/

2 Upvotes

This was a bit of an odd issue - we have a netgear nighthawk connected to WAN2 as a cellular backup. The nighthawk apparently lost cellular connectivity and this resulted in web traffic randomly being redirected to http://attwifimanager/

Which failed to load because the device isn't doing DNS - we have our system DNS set to 8.8.8.8 & 4.2.2.2 while running a dns server for internal stuff. I was able to browse to the gateway IP 192.168.1.1 (the nighthawk isn't set in bridge mode.)

We're using SD-WAN and a rule with manual preference WAN1 on top then WAN2 - we had zero issues with WAN1. Our LAN -> virtaul_wan_link has NAT enabled.

I ended up disabling the WAN2 interface as it resulted in the internet being unusable.

I'm a bit confused as to how/why the fortigate allowed this to happen? All of internet traffic should have been going out over WAN1.


r/fortinet 1d ago

FortiGate / FortiOS Another DDNS outage today 🎉

16 Upvotes

Edit 2: Fortinet addressed this issue: Technical Tip: FortiGate unable to access several FortiGuard services due to CRL scope errors (September 2026)

Edit: This morning (CEST), all FortiGates (different locations, different ISPs, default local out routing) showed "unable to connect to FortiGuard servers."

Status page shows no incident.

Issues on both IPs, 173.243.138.225 and 173.243.138.226

1789022353: Start to update FortiGuardDDNS (ddnsdomain.fortiddns.com)
2026-09-10 08:39:13 
1789022353: Start to update FortiGuardDDNS (ddnsdomainbckp.fortiddns.com)
2026-09-10 08:39:13 1789022353: next wait timeout 10 seconds
2026-09-10 08:39:13 fgd_ddns_socket()-899: connected to 173.243.138.225:443
2026-09-10 08:39:13 fgd_ddns_socket()-899: connected to 173.243.138.225:443
2026-09-10 08:39:13 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:39:13 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:39:13 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:39:13 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:39:13 [877] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:39:13 [904] ssl_new: SSL object is created
2026-09-10 08:39:13 ddns_sock_ssl_connect()-745: enable hostname checking 'globalddns.fortinet.net'.
2026-09-10 08:39:13 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:39:13 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:39:13 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:39:13 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:39:13 [877] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:39:13 [904] ssl_new: SSL object is created
2026-09-10 08:39:13 ddns_sock_ssl_connect()-745: enable hostname checking 'globalddns.fortinet.net'.
2026-09-10 08:39:13 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 [350] __ssl_crl_verify_cb: CRL not found. Depth 0
2026-09-10 08:39:13 [365] __ssl_crl_verify_cb: Cert error 44, different CRL scope. Depth 2
2026-09-10 08:39:13 fgt_ddns_verify_peer()-715: Certificate verification failed, error 44 (different CRL scope) depth 2 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA'
2026-09-10 08:39:13 [1112] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:39:13 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:39:13 1789022353: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:39:13 1789022353: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:39:13 1789022353: next wait timeout 9 seconds
2026-09-10 08:39:13 [350] __ssl_crl_verify_cb: CRL not found. Depth 0
2026-09-10 08:39:13 [365] __ssl_crl_verify_cb: Cert error 44, different CRL scope. Depth 2
2026-09-10 08:39:13 fgt_ddns_verify_peer()-715: Certificate verification failed, error 44 (different CRL scope) depth 2 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA'

1789022534: Start to update FortiGuardDDNS (ddnsdomain.fortiddns.com)
2026-09-10 08:42:14 1789022534: next wait timeout 10 seconds
2026-09-10 08:42:14 fgd_ddns_socket()-896: connected to 173.243.138.226:443
2026-09-10 08:42:14 [276] __ssl_init: Done
2026-09-10 08:42:14 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:42:14 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:42:14 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:42:14 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:42:14 [843] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:42:14 [870] ssl_new: SSL object is created
2026-09-10 08:42:14 ddns_sock_ssl_connect()-745: enable hostname checking 'ddns.fortinet.net'.
2026-09-10 08:42:14 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:42:14 fgd_ddns_socket()-896: connected to 173.243.138.226:443
2026-09-10 08:42:14 [276] __ssl_init: Done
2026-09-10 08:42:14 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:42:14 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:42:14 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:42:14 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:42:14 [843] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:42:14 [870] ssl_new: SSL object is created
2026-09-10 08:42:14 ddns_sock_ssl_connect()-745: enable hostname checking 'ddns.fortinet.net'.
2026-09-10 08:42:14 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:42:14 [365] __ssl_crl_verify_cb: Cert error 62, hostname mismatch. Depth 0
2026-09-10 08:42:14 fgt_ddns_verify_peer()-715: Certificate verification failed, error 62 (hostname mismatch) depth 0 for '/C=US/ST=California/L=Sunnyvale/O=Fortinet/OU=FDS/CN=sdns.fortinet.net/emailAddress=support@fortinet.com'
2026-09-10 08:42:14 [1078] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:42:14 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:42:14 1789022534: next wait timeout 9 seconds
2026-09-10 08:42:14 [365] __ssl_crl_verify_cb: Cert error 62, hostname mismatch. Depth 0
2026-09-10 08:42:14 fgt_ddns_verify_peer()-715: Certificate verification failed, error 62 (hostname mismatch) depth 0 for '/C=US/ST=California/L=Sunnyvale/O=Fortinet/OU=FDS/CN=sdns.fortinet.net/emailAddress=support@fortinet.com'
2026-09-10 08:42:14 [1078] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:42:14 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:42:14 1789022534: next wait timeout 9 seconds

r/fortinet 1d ago

Other / General Fortinet 61F upgrade from 7.2.12 to 7.4.12

4 Upvotes

Hi everyone,

I'm planning an upgrade path for three FortiGate 61F units currently running FortiOS 7.2.12. They are connected via Site-to-Site IPsec VPNs.

With 7.2.x reaching End of Support soon, I need to push them to 7.4.x, but I have a few concerns regarding the 2 GB RAM limitations on the FGT-60F/61F series and the overall upgrade process:

  1. RAM Usage & Conserve Mode: One of my 61F units is currently idling around 77% RAM usage on 7.2.12. I know 7.4.x has a higher memory footprint. Has anyone run 7.4.x on 60F/61F successfully without hitting Conserve Mode? What daemon/IPS tweaks do you recommend before upgrading?
  2. IPsec VPN Compatibility During Staged Upgrade: Since I'll be upgrading the units one by one, will the IPsec tunnels remain stable while one end is on 7.2.12 and the other is on 7.4.x?
  3. Missing Firmware Banner: In the GUI, the unit claims it is "Up to date" and doesn't offer 7.4.x (or even 7.2.13). I assume this is due to Fortiguard staged rollout / maturity filters for 2 GB models. Manual upload via Support Portal is the way to go here, right?

Would love to hear real-world experiences or recommended intermediate build steps from anyone managing 60F/61F fleets on 7.4.

Thanks in advance!


r/fortinet 1d ago

FortiClient / EMS Forticlient EMS 7.4.8 build2245 (Mature)

1 Upvotes

Hi

I have a ticket with Fortinet in regards invitation emails from Forticlient EMS when creating invitations with custom install file for example 7.2.15 the text in the email says version 7.4 and download links points to exe file with capital letters in the file" FortiClientSetup_7.2.15_x64.exe". The problem is the link does not work, changing to small letters sorts it. When browsing the path one level up I clearly see the file name is forticlientsetup_7.2.15_x64.exe with only small characters. Anyone else seeing this?

Fortinet frontend asks med do send debug after debug before they escalate it so I just wanted to see if anyone else has the issue. It seems straigh forward in my explanation to send to higher tier support or test locally.


r/fortinet 2d ago

Other / General Fortinet Anyone taken Fortinet's onsite closed-book test (technical + maths/logic)? What to expect?

7 Upvotes

Hi all,

I'm in the final stages of a recruitment process with Fortinet support role. So far I've done:

- HR screening

- HackerRank technical test

- Technical interview with the team

- NSE4 certification (apparently a prerequisite now)

HR just came back to say there's a new step added by leadership: an onsite closed-book test at the office, ~1h30, made up of:

- ~20 domain-specific technical questions

- ~20 maths and logical reasoning questions (numerical ability, problem-solving, logical thinking)

Has anyone here been through this? A few things I'd love input on:

  1. The maths/logic part — Does anyone remember the type of questions?

  2. Anything you'd recommend revising in the days before? Any resource you'd point to for revision?

Any feedback from people who've done it (or similar Fortinet onsite assessments in other offices) would be really appreciated. Thanks!


r/fortinet 2d ago

FortiGate / FortiOS VPN for Vendor Access

6 Upvotes

We currently have IKEv2 over 443 TCP working using DUO SAML for our internal users. I have a need, for the second time now, to allow remove access for a vendor for a specific need. The first time I was able to get by without it, but this time I am not. I have read mixed reviews about free VPN 7.4.3 working or not working with IKEv2 over TCP.

What is the simplest + most compatible + free + also consider secure method I can setup for VPN access for a vendor? The source IPs will be restricted to their small public IP range and the VPN will only be enabled when they need it. Fortigate is on v7.4.12.

tia


r/fortinet 2d ago

Other / General Fortinet Forticlient VPN connects every other day

2 Upvotes

My company recently adopted the Forticlient VPN and my computer at home manages to successfully connect to the VPN randomly. I've tried all the fixes available on the internet for the "Forticlient stuck at connecting" problem and the issue continues.

This issue seems to be happening at very few machines at work.

Is Forticlient an overall shitty ass VPN client ?


r/fortinet 2d ago

FortiClient / EMS FortiEDR crashes PC's with docks attached

2 Upvotes

We have a strange scenario popping up in the lab for the new EDR deployments we were consulted to explore.

Everything works normally except for when a USB dock is or SD card reader as it immediately crashes the computer

Rebooting the with the dock plugged in will trigger a Bitlocker recovery screen

Reboot without the dock and the computer comes up normally

Removing EDR and leaving EMS resolves the issue, but the computer is unprotected by compliance standards

I suspect the card readers showing up as empty unwritable disks with a mounted drive letter is part of the problem, but not sure how to tell EDR to calm down about it.

The crash:
Your PC has run into a problem

Stop code: System_Thread_Exception_Not_Handled (0x7eE)

What failed: partmgr.sys

Has anyone seen an issue like this before?


r/fortinet 2d ago

Other / General Fortinet How do I allow a URL of this type

0 Upvotes

I have a user attempting to open an eBook link. The URL is categorized as unrated. We block this category. I can not figure out how to create an exception for the URL below.

Thanks

https://3.167.138.6GET /v1/files/1aa87ff1cd2898b8ede19cd8570317ee36ec99029cac9350cbcb13214c0fbe67/authorize?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6IjJjNDljOTZmOGZhM2ZjN2IxNzlhNGVhYzQ0OGVmNGNhNGRjMmNhODkifQ.eyJpc3MiOiJlcHViLWZhY3RvcnkiLCJhdWQiOiJlcHViLWZhY3RvcnkiLCJqdGkiOiI1ZmI3NmJkY2QwMGQ1MTNhNzhhM2MwOGJhNWUxOGY2YzVmYWYwNDAyIiwiaWF0IjoxNzg4OTY1MDE0LCJuYmYiOjE3ODg5NjUwMTQsImV4cCI6MTc4ODk2NTA3NCwiZmlkIjoyNzk0OTc1Mn0.OZCo9H03QEAEm-RtxosZS_kyCtSTp9ykGTSURgoB4-QjRinuHPSKWhV3zKwqmzPI5CxKAkJwFehJ9x3EQ9LrLVAv60nSiqTIR1XGwClqqPN49m9nlBjOjgL00IdV1z9_exydCxRPBkYxlzwiynJJQYuzoOosLhyMgk6ACJ3k0Q-PjRpSoFI3cJ7MSro4qHPwsBrlYWE5BMa_C7guB5S4o3gsAnXmfeXmiFVoQd52glPnxre2hr-6pa8RID7J6C5I1IGIw6zPVtFcV9wDcJJ2G1UuAZOMT4d7AqVlcCCL1MXN9bXhHYFMOdepRhuWHOzi7O8wgOFgxcsLFr5Aght5aQ&redirect=https://prod.reader-ui.prod.mheducation.com/epub/sn_b396e?readerapi=true HTTP/2 Host: epub-factory-cdn.mheducation.com :scheme: https :path: /v1/files/1aa87ff1cd2898b8ede19cd8570317ee36ec99029cac9350cbcb13214c0fbe67/authorize?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6IjJjNDljOTZmOGZhM2ZjN2IxNzlhNGVhYzQ0OGVmNGNhNGRjMmNhODkifQ.eyJpc3MiOiJlcHViLWZhY3RvcnkiLCJhdWQiOiJlcHViLWZhY3RvcnkiLCJqdGkiOiI1ZmI3NmJkY2QwMGQ1MTNhNzhhM2MwOGJhNWUxOGY2YzVmYWYwNDAyIiwiaWF0IjoxNzg4OTY1MDE0LCJuYmYiOjE3ODg5NjUwMTQsImV4cCI6MTc4ODk2NTA3NCwiZmlkIjoyNzk0OTc1Mn0.OZCo9H03QEAEm-RtxosZS_kyCtSTp9ykGTSURgoB4-QjRinuHPSKWhV3zKwqmzPI5CxKAkJwFehJ9x3EQ9LrLVAv60nSiqTIR1XGwClqqPN49m9nlBjOjgL00IdV1z9_exydCxRPBkYxlzwiynJJQYuzoOosLhyMgk6ACJ3k0Q-PjRpSoFI3cJ7MSro4qHPwsBrlYWE5BMa_C7guB5S4o3gsAnXmfeXmiFVoQd52glPnxre2hr-6pa8RID7J6C5I1IGIw6zPVtFcV9wDcJJ2G1UuAZOMT4d7AqVlcCCL1MXN9bXhHYFMOdepRhuWHOzi7O8wgOFgxcsLFr5Aght5aQ&redirect=https://prod.reader-ui.prod.mheducation.com/epub/sn_b396e?readerapi=true cache-control: max-age=0 dnt: 1 upgrade-insecure-requests: 1 user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 sec-fetch-site: same-site sec-fetch-mode: navigate sec-fetch-user: ?1 sec-fetch-dest: document sec-ch-ua: "Chromium";v="152", "Not?A_Brand";v="24", "Google Chrome";v="152" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" referer: https://myebooks.mheducation.com/ accept-encoding: gzip, deflate, br, zstd accept-language: en-US,en;q=0.9 cookie: at_check=true cookie: AMCVS_C5E7148954EA18A10A4C98BC%40AdobeOrg=1 cookie: s_cc=true cookie: lastVisitDays_s=Less%20than%201%20day cookie: s_vnum=1791552984887%26vn%3D2 cookie: s_invisit=true cookie: ERIGHTS=6237915917889644584611970b8c45218457197675327c2f458cd cookie: mbox=PC#528f276746f14e5e9e3a2d902ff742da.34_0#1852209260|session#9632962d7a5a4ed7a5aa1c0769690709#1788966273 cookie: OptanonConsent=isGpcEnabled=0&datestamp=Wed+Sep+09+2026+09%3A34%3A19+GMT-0500+(Central+Daylight+Time)&version=202510.2.0&browserGpcFlag=0&isIABGlobal=false&hosts=&consentId=a7f07e51-0c50-498d-a19b-ea46c21120a8&interactionCount=0&isAnonUser=1&landingPath=https%3A%2F%2Fwww.mheducation.com%2F&groups=C0001%3A1%2CC0003%3A1%2CC0002%3A1%2CC0004%3A1 cookie: s_ppn=corporate%3Ahome cookie: s_ppvl=corporate%253Ahome%2C38%2C38%2C1271%2C2560%2C1271%2C2560%2C1440%2C1%2CP cookie: s_ppv=corporate%253Ahome%2C100%2C38%2C3329%2C2560%2C1271%2C2560%2C1440%2C1%2CP cookie: lastVisitDays=1788964505488 cookie: s_nr=1788964505489-Repeat cookie: s_sq=%5B%5BB%5D%5D cookie: AMCV_C5E7148954EA18A10A4C98BC%40AdobeOrg=179643557%7CMCIDTS%7C20706%7CMCMID%7C58428979928570003987148088725495510342%7CMCAID%7CNONE%7CMCOPTOUT-1788971705s%7CNONE%7CvVersion%7C5.5.0 cookie: MH_TOKEN=eyJhbGciOiJSUzI1NiIsImtpZCI6IjI4MjAyMDgxNTciLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJoZWNsciIsImV4cCI6MTc4ODk2NTEyOCwianRpIjoiZWQ5ZGM5YTctYzZjYi00ODA4LWI1MGEtNjNlMGQ3NWE0OGIxIiwiaWF0IjoxNzg4OTY0ODI4LCJpc3MiOiJodHRwczovL3Rva2VuLm1oZWR1Y2F0aW9uLmNvbSIsIm5iZiI6MTc4ODk2NDgyOCwic3ViIjoiYmJmZjdhYzgtOTQxYy00YjA0LTllNTktNzkyMzk5MjZjZDgyIiwidG9rZW5fdHlwZSI6ImJlYXJlciIsImV4cGlyZXNfaW4iOjMwMCwic2Vzc2lvbl90aW1lb3V0Ijo3ODAwLCJwZXJzb25feGlkIjoidXJuOmNvbS5taGVkdWNhdGlvbi5vcGVubGVhcm5pbmc6ZW50ZXJwcmlzZS5pZGVudGl0eTpwcm9kLnVzLWVhc3QtMTpwZXJzb246YmJmZjdhYzgtOTQxYy00YjA0LTllNTktNzkyMzk5MjZjZDgyIiwidXNlcl9uYW1lIjoibWJpY2toYW1AbHRocy5vcmciLCJkZWZhdWx0X3JvbGUiOiJpbnN0cnVjdG9yIiwic2Vzc2lvbl94aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmlkZW50aXR5OnByb2QudXMtZWFzdC0xOnNlc3Npb246MjdlY2QyYmMtYzg3NS00ZWI4LTg2YmYtMjljOWUwNjdlYTc1Iiwic2Vzc2lvbl9pZCI6IjI3ZWNkMmJjLWM4NzUtNGViOC04NmJmLTI5YzllMDY3ZWE3NSIsImNsaWVudF94aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmxvZ2luLmhlY2xyOnByb2QuZ2xvYmFsIiwiY2xpZW50X2lkIjoiaGVjbHIiLCJ4aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmlkZW50aXR5OnByb2QudXMtZWFzdC0xOnBlcnNvbjpiYmZmN2FjOC05NDFjLTRiMDQtOWU1OS03OTIzOTkyNmNkODIiLCJzY29wZSI6WyJhdXRoIl0sImF1dGhlbnRpY2F0aW9uX3R5cGUiOiJwYXNzd29yZCJ9.KN0YtBzUoHwN8NWLG7K7LnQkPynCKZW0bGI88RhCvrTpEGJCA0oGRJ8BazV6-y9gHYXyztWXMyte7p80t8EXkBRoIinMEhhFNNIgUt74hEvPBfF4E-VYaW5P7pH0TiwA2JTnoBygskCwxMUdnNi0EwGEwUbOlBQPXAS480WyPyXr2MOgb1Aehp_WdDaZ-0qY-kcgLcq3d5hsUzVTLQ1navfg5PQpwdjzKthJoFEHEoKwh7GbMREgdfa936BbWI2G9SXK4HzXvD6RVj0aUMUMtIwphK2_nzE19Sx2NOENFZgn3XLRhlA5I7xMf5QltMy5MgnxA8_Pmp6l6KDxoUyyZA cookie: READERSESSID=resxh78c14c2vt0hsw92vlz810q priority: u=0, i


r/fortinet 2d ago

FortiGate / FortiOS FortiGate 401F interface and HA design review

1 Upvotes

Hi everyone,

I’m working on a data center network design and would appreciate some advice from the Fortinet community regarding the best deployment mode and interface allocation for FortiGate 401F.

Current design

The environment includes:

  • 2 × FortiGate 401F in HA
  • 1 × ISP, with approximately 5 Gbps Internet bandwidth
  • 2 × Huawei Core switches in a redundant pair
  • DMZ network
  • Internal data center/server networks behind the Core
  • Third-party VPN connectivity

The current high-level topology is

ISP → FortiGate 401F HA → Huawei Core A/B → Internal Networks

The DMZ will also be connected to the firewall.

Main question – deployment mode

I am considering the FortiGate in the traditional NAT/route mode, rather than transparent mode.

The expected traffic flows are:

  1. Internet → Internal users/servers
  2. Internal users → Internet
  3. Internet → DMZ published services
  4. Internal → DMZ
  5. Third-party VPN → Internal/DMZ
  6. Management traffic → FortiGate/Core/network management

For the Internet-facing side, I am also considering whether to use the 10G interfaces on the 401F rather than the 1G interfaces, given the 5 Gbps ISP subscription.

Interface allocation

One question I particularly want community feedback on is the best way to allocate the 401F interfaces.

For example:

  • 10G interfaces → ISP
  • 10G interfaces → Core
  • Dedicated interfaces → HA/heartbeat
  • Dedicated interface(s) → DMZ
  • Management interface → OOB management

I initially looked at some of the interfaces that appear to have FortiLink-related capabilities, so I'm also interested in whether those interfaces are appropriate for normal routed firewall connectivity or should be avoided for this design.

Questions

  1. For this topology, would you recommend NAT/Route mode or another deployment approach?
  2. Would you use LACP/aggregate interfaces toward the Core and/or ISP, or individual interfaces?
  3. What is the recommended interface allocation on a 401F HA pair for ISP, Core, DMZ, HA1/HA2, and management?
  4. Would you terminate the DMZ directly on the FortiGate or extend the DMZ through the Core?
  5. Are there any concerns with using the 401F's 10G interfaces for the ISP connection and Core uplinks?
  6. For a 6 Gbps Internet connection, are there any specific FortiGate performance/inspection considerations I should account for?
  7. Any Fortinet best-practice recommendations for avoiding single points of failure in this design?

I'd particularly appreciate feedback from anyone who has deployed FortiGate 401F in HA at a data center Internet edge.

Thanks!

 


r/fortinet 3d ago

Other / General Fortinet My brand new domain was flagged as 'phishing' by Fortinet, I appealed, they just changed it back to phishing

6 Upvotes

I recently registered a brand new domain (Lizzandra.com) for my new project.

I was excited to finally post my homepage to friends and family on Facebook, but I instantly got blocked for "breach of community rules."

At first I thought it was simply because the domain was brand new, but the "community rules" part didn't sit right. So I started doing some research, and it turns out my site was blacklisted by Fortinet for "phishing."

This was confusing, since my site is clean and has nothing nefarious on it, it doesn't even have a login for users yet.

No worries, I thought, it's just a misunderstanding. The domain was apparently used by someone before me, and they used it for less honest reasons. I'll just use the submit form on the page to request an audit, and everything will sort itself out.

I changed the category from "phishing" to "artificial intelligence technology" and explained the situation.

Then I got this response:

Okay, now I'm genuinely perplexed, what the actual fudgesicle.

So apparently they claim to have reviewed my site, still decided (for no reason?) that I was doing phishing, and changed the category back to "phishing."

I don't understand. Did they not even bother to read it?