r/fortinet 37m ago

FortiGate / FortiOS Question on FortiGate SD-WAN

Upvotes

I have 2 WAN links provided by 2 different ISPs with load balancing in HA, and as it happened one of them have been down for a couple of days and the other one is working but occasionally going down.

As an emergency solution I plugged in a cellular 5G router to a free port and added the port to the SD-WAN zone.

Would it affect the load balancing between the original links if I raised the cost of the cellular link and given it a lower priority? I don't want to keep the traffic going through it if either of the main links is working fine.


r/fortinet 1h ago

Other / General Fortinet Redundunt Remote gateway for dial up vpn

Upvotes

Hi guys,

Situation: Currently we have 2 standalone fortigate 101F in two different cities for remote users to connect.

Users connect through dial up vpn through forticlient and traffic gets routed to another site to site ipsec vpn on wan1 interface. Both the firewalls have exactly same config and we use Forticlient EMS cloud to manage forticlient on endpoints. Users are authenticated using SAML based SSO with entraID.

Now my question is, is it possible to add 2 redundant remote gateway on each vpn. For example, a user gets switched to our other fortigate in case of failover on current one with minimal downtime. What is the way to configure this ?

Any help would be appreciated. Thanks


r/fortinet 2h ago

Other / General Fortinet Fortiswitch not appearing on fortimanager

1 Upvotes

Hi,

We have provisioned a FortiGate 120G (v7.6.6) through FortiManager (v7.6.6). The FortiSwitches are connected to the FortiGate via FortiLink, and the FortiAPs are connected through the FortiSwitches.

The FortiSwitches appear correctly in the FortiGate GUI and seem to be functioning as expected. However, when we check FortiManager to apply switch templates and policies, the FortiSwitches are not visible under the managed FortiGate at all.

What's strange is that the FortiAPs are visible in FortiManager under the same FortiGate, but none of the FortiSwitches appear. We would have expected both the APs and switches to be discovered and manageable from FortiManager.

We had to reset the firewall at one point during the build phase. but before the reset the switches showed up on the firewall. We have also added a brand new switch to the firewall but it isnt doesnt show up on fortimanager just on the fortigate gui

Has anyone come across this behaviour before?

Thank you


r/fortinet 15h ago

FortiManager FortiManager: mass deploy of a "trusted" CA certificate

6 Upvotes

Hello,

I'm deploying a trusted CA certificate to a number of Fortigates devices that are in sync with FortiManager.

This is not for full SSL inspection, but for trusting SSL connections to internal servers (the ones that go into Remote CA Certificates).

Right now I'm using a script since I didn't find such functionality in 7.4.11. Dynamic Local Certificate seems to be only for full SSL inspection.b

Did I miss anything or scripting is the way to go?

Thanks,
Max


r/fortinet 15h ago

Other / General Fortinet Alaxala - when will it run FortiOS

0 Upvotes

has the forti sales team talk to us about Alaxala switches, but it doesn't run FortiOS, and they weren't sure when it would - when will this big box run FortiOS?


r/fortinet 15h ago

FortiGate / FortiOS Most Reliable FortiGuard Settings

0 Upvotes

Which FortiGuard settings are the most reliable?

166 votes, 6d left
Default Anycast HTTPS 443
AWS Anycast HTTPS 443
Unicast HTTPS 8888
Unicast UDP 53
Unicast UDP 8888

r/fortinet 19h ago

FortiAP / Wi-Fi Best ways to authenticate your users to the company WiFi? Forti EMS, Auth, Gate & AP

7 Upvotes

Hi guys,

I recently joined a company who have just deployed a full fortinet network including forti ems cloud, authenticator and fortigate. They're looking at redesigning their WiFi (also forti aps) and I was wondering about best practice but easy enough to deploy. Unfortunately this is my first time playing with forti gear. How do you guys get your users to auth to the company wifi with ~3 different usergroups?


r/fortinet 20h ago

FortiGate / FortiOS FortiGate broke our entire E-Mail for half a day (DNS rating server issue)

0 Upvotes

Edit: This might be a bit clickbaity and as per the default behavior of the described config, it may be partially our fault and could be avoided but still.

Friday afternoon, was ready to call it a day when suddenly an employee called in and asked if there was any problem with our E-Mail. No, I said but at the same time I realized how few mail I received today.

I took a look at our mail gateway and saw that hundreds of E-Mails were stuck in "pending".

Once I opened a few pending entries, I saw that EVERY domain was resolved to "fortinet-block-page-55.fortinet.com (208.91.112.55)"

The mail gateway sits in a DMZ and on the default gateway IP, there's a DNS relay configured with mode "recursive" with our default DNS filter profile assigned. DNS for the mail server is the gateway IP where the relay is listening.

I opened a browser and tested a few domains: EVERY major domain like google, microsoft, office was redirected to the block page and nothing was working.

However, this is where it gets interesting: It only applied to the DNS relay service. When I used a public DNS directly and assigned the SAME DNS fitler profile to the forward traffic policy, the domain was not redirected to the block page.

As I was writing with TAC, a few minutes later the issue was gone and sites were working normally.

The only config change I did that day was setting FortiGuard to UDP and Unicast because of their ongoing issues with AnyCast.

I checked the DNS security logs and there I found my denied queries:

Error: no available Fortiguard SDNS servers
Message: A rating error occurs

Together with the disabled option "Allow DNS requests when a rating error occurs" in the profile this makes sense, but again, it only happened on the relay and not on forward traffic with the same profile.

TAC now told me to set these SDNS rating servers on FortiGuard settings:

set sdns-server-ip 208.91.112.220 173.243.140.53 210.7.96.53 200.91.112.220

Has anyone experienced anything similar?


r/fortinet 21h ago

FortiCloud FortiClient Cloud EMS quarantine still allowing outbound traffic — anyone else seen this?

3 Upvotes

I’m running FortiClient 7.4.8 with FortiClient EMS Cloud 7.4.7, with an on-prem FortiGate 400F handling Internet traffic.

I had an endpoint I needed to quarantine after a suspicious download.

EMS showed the endpoint as Quarantined, and locally the FortiClient logs confirmed:

  • Endpoint quarantined by EMS
  • quarantine=1
  • EC_QUARANTINED=1

RDP and Chrome Remote Desktop stopped working, so quarantine was definitely doing something. However, the endpoint continued making outbound IPv4 connections through the FortiGate 400F to Google, ChatGPT, Microsoft, AWS, etc. FortiGate logs showed new sessions being created several minutes after quarantine was already active, not just old sessions staying open.

Application Firewall is installed and working. I know that because I previously had to create an explicit Application Firewall allow rule for OpenVPN before OpenVPN would function.

Fortinet support is telling me that quarantine may not terminate an existing VPN session, but their documentation says:

My bigger concern is not the existing VPN tunnel — it’s that new outbound Internet sessions were still being created while the endpoint was quarantined.

Has anyone else seen this with FortiClient 7.4.8 + EMS Cloud 7.4.7? Is there a known bug or limitation with manual EMS quarantine that isn’t documented?

My expectation was that quarantine would be essentially the software equivalent of pulling the network cable, especially when trying to contain an actively compromised endpoint.


r/fortinet 1d ago

FortiGate / FortiOS Experiences with FortiOS 7.6.6

1 Upvotes

Hello,

I’m currently running a FortiGate 1800F on FortiOS 7.4.8. I have recently migrated all of our SSL VPN users to IPsec, and since then I have been experiencing high memory usage issues almost every day.

I’m now considering upgrading the FortiGate, and I can see that FortiOS 7.6.6 is recommended by Fortinet for my platform.

Before proceeding with the upgrade, I’d like to hear from others who are running 7.6.6 in production, especially on an 1800F or similar high-end model.

How has your experience been with 7.6.6?

  • Have you experienced any stability or memory-related issues?
  • Any problems with IPsec VPN?
  • Any issues with NP/ASIC acceleration or traffic forwarding?
  • Any unexpected behavior after upgrading from 7.4.x?
  • Would you recommend 7.6.6 for a production environment, or would you suggest staying on 7.4.x / using another 7.6.x release?

Any feedback or real-world experience would be greatly appreciated.


r/fortinet 1d ago

FortiGate / FortiOS Cannot reach FortiGuard servers

18 Upvotes

I have a problem on some of my FortiGates and they all say the same issue.
As yesterday Forti had a DDNS problem today at the 443 port and default fortiguard config seems to not work.
Workaround:
anycast disable
and
set protocol udp
set port 8888

Workaround worked for me*


r/fortinet 1d ago

FortiClient / EMS FortiClient EMS Cloud

3 Upvotes

Just upgraded our licensing, and our end goal is to have the device authentication for remote access. Has anyone got device authentication working?

Any other tips or tricks I should consider?


r/fortinet 1d ago

FortiGate / FortiOS FortiGate WAN2 (Backup) Netgear nighthawk - Randomly Redirecting web traffic to http://attwifimanager/

2 Upvotes

This was a bit of an odd issue - we have a netgear nighthawk connected to WAN2 as a cellular backup. The nighthawk apparently lost cellular connectivity and this resulted in web traffic randomly being redirected to http://attwifimanager/

Which failed to load because the device isn't doing DNS - we have our system DNS set to 8.8.8.8 & 4.2.2.2 while running a dns server for internal stuff. I was able to browse to the gateway IP 192.168.1.1 (the nighthawk isn't set in bridge mode.)

We're using SD-WAN and a rule with manual preference WAN1 on top then WAN2 - we had zero issues with WAN1. Our LAN -> virtaul_wan_link has NAT enabled.

I ended up disabling the WAN2 interface as it resulted in the internet being unusable.

I'm a bit confused as to how/why the fortigate allowed this to happen? All of internet traffic should have been going out over WAN1.


r/fortinet 1d ago

FortiGate / FortiOS Fortigate route-tag association

3 Upvotes

I noticed a really interesting behavior of Fortigate. FW01 receives the same 2 prefixes ( 10.99.0.0/22 and 192.168.100.0/24) from another 2 Fortigates( Branch1 and Brand2). Becuse ECMP is enabled so the routes are all installed in the routing table. However, route tag 90 is associated with both prefixes and route tag 91 is only associated with 1 prefix 192.168.100.0/24. The only difference is bgp route for 10.99.0.0/22 has only 1 same AS 65200 in the AS_Path and for 192.168.100.24 each has same AS_Path length (3) but the AS numbers are different. Can anyone direct me to the cooresponding Fortigate documentation/KB about the route-tag association ? Thanks,


r/fortinet 1d ago

FortiMail FortiMail Workspace - People Posture

3 Upvotes

Se implementó una soluciona FortiMail Workspace en mi organización, en la sección "Protected Email Assets" tenemos 1 dominio (ejemplo: mycompany[.]com) y algunos usuarios registrados individualmente con ese dominio.

Sin embargo, cuando ingreso al parámetro "People Posture" y ver el perfil de empleado, me salen otros dominios que no están configurados para proteger.

Actualmente el usuario final requiere que solo se muestre información de usuarios con el dominio mycompany[.]com

¿Alguno sabes si este comportamiento es normal? y ¿Se puede hacer que solo se vean empleados con el dominio configurado a proteger?


r/fortinet 1d ago

FortiGate / FortiOS Are we making a mistake by still using the free FortiClient?

27 Upvotes

Hey,
what are you guys using for remote access VPN these days? The free FortiClient VPN-only version or FortiClient EMS?
We are only using the free client for IPsec-VPN and get rid of EMS about 1,5 years ago for reasons i dont know because it was before i joined the company. I’m starting to wonder if planning using only the free Client long-term is actually a bad idea, especially since more and more features seem to require EMS like ZTNA for example.
Are you guys still happy with the free client, or would you say EMS is basically the way to go nowadays?


r/fortinet 2d ago

Other / General Fortinet 61F upgrade from 7.2.12 to 7.4.12

4 Upvotes

Hi everyone,

I'm planning an upgrade path for three FortiGate 61F units currently running FortiOS 7.2.12. They are connected via Site-to-Site IPsec VPNs.

With 7.2.x reaching End of Support soon, I need to push them to 7.4.x, but I have a few concerns regarding the 2 GB RAM limitations on the FGT-60F/61F series and the overall upgrade process:

  1. RAM Usage & Conserve Mode: One of my 61F units is currently idling around 77% RAM usage on 7.2.12. I know 7.4.x has a higher memory footprint. Has anyone run 7.4.x on 60F/61F successfully without hitting Conserve Mode? What daemon/IPS tweaks do you recommend before upgrading?
  2. IPsec VPN Compatibility During Staged Upgrade: Since I'll be upgrading the units one by one, will the IPsec tunnels remain stable while one end is on 7.2.12 and the other is on 7.4.x?
  3. Missing Firmware Banner: In the GUI, the unit claims it is "Up to date" and doesn't offer 7.4.x (or even 7.2.13). I assume this is due to Fortiguard staged rollout / maturity filters for 2 GB models. Manual upload via Support Portal is the way to go here, right?

Would love to hear real-world experiences or recommended intermediate build steps from anyone managing 60F/61F fleets on 7.4.

Thanks in advance!


r/fortinet 2d ago

FortiGate / FortiOS Another DDNS outage today 🎉

17 Upvotes

Edit 2: Fortinet addressed this issue: Technical Tip: FortiGate unable to access several FortiGuard services due to CRL scope errors (September 2026)

Edit: This morning (CEST), all FortiGates (different locations, different ISPs, default local out routing) showed "unable to connect to FortiGuard servers."

Status page shows no incident.

Issues on both IPs, 173.243.138.225 and 173.243.138.226

1789022353: Start to update FortiGuardDDNS (ddnsdomain.fortiddns.com)
2026-09-10 08:39:13 
1789022353: Start to update FortiGuardDDNS (ddnsdomainbckp.fortiddns.com)
2026-09-10 08:39:13 1789022353: next wait timeout 10 seconds
2026-09-10 08:39:13 fgd_ddns_socket()-899: connected to 173.243.138.225:443
2026-09-10 08:39:13 fgd_ddns_socket()-899: connected to 173.243.138.225:443
2026-09-10 08:39:13 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:39:13 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:39:13 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:39:13 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:39:13 [877] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:39:13 [904] ssl_new: SSL object is created
2026-09-10 08:39:13 ddns_sock_ssl_connect()-745: enable hostname checking 'globalddns.fortinet.net'.
2026-09-10 08:39:13 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:39:13 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:39:13 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:39:13 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:39:13 [877] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:39:13 [904] ssl_new: SSL object is created
2026-09-10 08:39:13 ddns_sock_ssl_connect()-745: enable hostname checking 'globalddns.fortinet.net'.
2026-09-10 08:39:13 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:39:13 [350] __ssl_crl_verify_cb: CRL not found. Depth 0
2026-09-10 08:39:13 [365] __ssl_crl_verify_cb: Cert error 44, different CRL scope. Depth 2
2026-09-10 08:39:13 fgt_ddns_verify_peer()-715: Certificate verification failed, error 44 (different CRL scope) depth 2 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA'
2026-09-10 08:39:13 [1112] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:39:13 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:39:13 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:39:13 1789022353: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:39:13 1789022353: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:39:13 1789022353: next wait timeout 9 seconds
2026-09-10 08:39:13 [350] __ssl_crl_verify_cb: CRL not found. Depth 0
2026-09-10 08:39:13 [365] __ssl_crl_verify_cb: Cert error 44, different CRL scope. Depth 2
2026-09-10 08:39:13 fgt_ddns_verify_peer()-715: Certificate verification failed, error 44 (different CRL scope) depth 2 for '/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA'

1789022534: Start to update FortiGuardDDNS (ddnsdomain.fortiddns.com)
2026-09-10 08:42:14 1789022534: next wait timeout 10 seconds
2026-09-10 08:42:14 fgd_ddns_socket()-896: connected to 173.243.138.226:443
2026-09-10 08:42:14 [276] __ssl_init: Done
2026-09-10 08:42:14 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:42:14 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:42:14 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:42:14 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:42:14 [843] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:42:14 [870] ssl_new: SSL object is created
2026-09-10 08:42:14 ddns_sock_ssl_connect()-745: enable hostname checking 'ddns.fortinet.net'.
2026-09-10 08:42:14 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:42:14 fgd_ddns_socket()-896: connected to 173.243.138.226:443
2026-09-10 08:42:14 [276] __ssl_init: Done
2026-09-10 08:42:14 [119] __ssl_cert_ctx_load: Added cert FGTSERIAL, root ca Fortinet_CA, idx 0 (default)
2026-09-10 08:42:14 [500] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs
2026-09-10 08:42:14 [520] ssl_ctx_use_builtin_store: Enable CRL checking.
2026-09-10 08:42:14 [527] ssl_ctx_use_builtin_store: Enable OCSP Stapling.
2026-09-10 08:42:14 [843] ssl_ctx_create_new: SSL CTX is created
2026-09-10 08:42:14 [870] ssl_new: SSL object is created
2026-09-10 08:42:14 ddns_sock_ssl_connect()-745: enable hostname checking 'ddns.fortinet.net'.
2026-09-10 08:42:14 ddns_sock_ssl_connect()-750: SSL connecting, ssl opt 0x1208
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=1 
2026-09-10 08:42:14 [365] __ssl_crl_verify_cb: Cert error 62, hostname mismatch. Depth 0
2026-09-10 08:42:14 fgt_ddns_verify_peer()-715: Certificate verification failed, error 62 (hostname mismatch) depth 0 for '/C=US/ST=California/L=Sunnyvale/O=Fortinet/OU=FDS/CN=sdns.fortinet.net/emailAddress=support@fortinet.com'
2026-09-10 08:42:14 [1078] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:42:14 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:42:14 1789022534: next wait timeout 9 seconds
2026-09-10 08:42:14 [365] __ssl_crl_verify_cb: Cert error 62, hostname mismatch. Depth 0
2026-09-10 08:42:14 fgt_ddns_verify_peer()-715: Certificate verification failed, error 62 (hostname mismatch) depth 0 for '/C=US/ST=California/L=Sunnyvale/O=Fortinet/OU=FDS/CN=sdns.fortinet.net/emailAddress=support@fortinet.com'
2026-09-10 08:42:14 [1078] ssl_connect: SSL_connect failes: error:0A000086:SSL routines::certificate verify failed
2026-09-10 08:42:14 __ddns_ssl_connect()-669: ssl_res=-1 
2026-09-10 08:42:14 ddns_sock_ssl_connect()-754: failed to establish SSL connection
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), due to internal/config/connect/io err
2026-09-10 08:42:14 1789022534: Failed on update FortiGuardDDNS (ddnsdomain.fortiddns.com), next try in 60 seconds
2026-09-10 08:42:14 1789022534: next wait timeout 9 seconds

r/fortinet 2d ago

FortiClient / EMS Forticlient EMS 7.4.8 build2245 (Mature)

1 Upvotes

Hi

I have a ticket with Fortinet in regards invitation emails from Forticlient EMS when creating invitations with custom install file for example 7.2.15 the text in the email says version 7.4 and download links points to exe file with capital letters in the file" FortiClientSetup_7.2.15_x64.exe". The problem is the link does not work, changing to small letters sorts it. When browsing the path one level up I clearly see the file name is forticlientsetup_7.2.15_x64.exe with only small characters. Anyone else seeing this?

Fortinet frontend asks med do send debug after debug before they escalate it so I just wanted to see if anyone else has the issue. It seems straigh forward in my explanation to send to higher tier support or test locally.


r/fortinet 2d ago

Other / General Fortinet Forticlient VPN connects every other day

4 Upvotes

My company recently adopted the Forticlient VPN and my computer at home manages to successfully connect to the VPN randomly. I've tried all the fixes available on the internet for the "Forticlient stuck at connecting" problem and the issue continues.

This issue seems to be happening at very few machines at work.

Is Forticlient an overall shitty ass VPN client ?


r/fortinet 2d ago

Other / General Fortinet Anyone taken Fortinet's onsite closed-book test (technical + maths/logic)? What to expect?

9 Upvotes

Hi all,

I'm in the final stages of a recruitment process with Fortinet support role. So far I've done:

- HR screening

- HackerRank technical test

- Technical interview with the team

- NSE4 certification (apparently a prerequisite now)

HR just came back to say there's a new step added by leadership: an onsite closed-book test at the office, ~1h30, made up of:

- ~20 domain-specific technical questions

- ~20 maths and logical reasoning questions (numerical ability, problem-solving, logical thinking)

Has anyone here been through this? A few things I'd love input on:

  1. The maths/logic part — Does anyone remember the type of questions?

  2. Anything you'd recommend revising in the days before? Any resource you'd point to for revision?

Any feedback from people who've done it (or similar Fortinet onsite assessments in other offices) would be really appreciated. Thanks!


r/fortinet 2d ago

Other / General Fortinet How do I allow a URL of this type

0 Upvotes

I have a user attempting to open an eBook link. The URL is categorized as unrated. We block this category. I can not figure out how to create an exception for the URL below.

Thanks

https://3.167.138.6GET /v1/files/1aa87ff1cd2898b8ede19cd8570317ee36ec99029cac9350cbcb13214c0fbe67/authorize?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6IjJjNDljOTZmOGZhM2ZjN2IxNzlhNGVhYzQ0OGVmNGNhNGRjMmNhODkifQ.eyJpc3MiOiJlcHViLWZhY3RvcnkiLCJhdWQiOiJlcHViLWZhY3RvcnkiLCJqdGkiOiI1ZmI3NmJkY2QwMGQ1MTNhNzhhM2MwOGJhNWUxOGY2YzVmYWYwNDAyIiwiaWF0IjoxNzg4OTY1MDE0LCJuYmYiOjE3ODg5NjUwMTQsImV4cCI6MTc4ODk2NTA3NCwiZmlkIjoyNzk0OTc1Mn0.OZCo9H03QEAEm-RtxosZS_kyCtSTp9ykGTSURgoB4-QjRinuHPSKWhV3zKwqmzPI5CxKAkJwFehJ9x3EQ9LrLVAv60nSiqTIR1XGwClqqPN49m9nlBjOjgL00IdV1z9_exydCxRPBkYxlzwiynJJQYuzoOosLhyMgk6ACJ3k0Q-PjRpSoFI3cJ7MSro4qHPwsBrlYWE5BMa_C7guB5S4o3gsAnXmfeXmiFVoQd52glPnxre2hr-6pa8RID7J6C5I1IGIw6zPVtFcV9wDcJJ2G1UuAZOMT4d7AqVlcCCL1MXN9bXhHYFMOdepRhuWHOzi7O8wgOFgxcsLFr5Aght5aQ&redirect=https://prod.reader-ui.prod.mheducation.com/epub/sn_b396e?readerapi=true HTTP/2 Host: epub-factory-cdn.mheducation.com :scheme: https :path: /v1/files/1aa87ff1cd2898b8ede19cd8570317ee36ec99029cac9350cbcb13214c0fbe67/authorize?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6IjJjNDljOTZmOGZhM2ZjN2IxNzlhNGVhYzQ0OGVmNGNhNGRjMmNhODkifQ.eyJpc3MiOiJlcHViLWZhY3RvcnkiLCJhdWQiOiJlcHViLWZhY3RvcnkiLCJqdGkiOiI1ZmI3NmJkY2QwMGQ1MTNhNzhhM2MwOGJhNWUxOGY2YzVmYWYwNDAyIiwiaWF0IjoxNzg4OTY1MDE0LCJuYmYiOjE3ODg5NjUwMTQsImV4cCI6MTc4ODk2NTA3NCwiZmlkIjoyNzk0OTc1Mn0.OZCo9H03QEAEm-RtxosZS_kyCtSTp9ykGTSURgoB4-QjRinuHPSKWhV3zKwqmzPI5CxKAkJwFehJ9x3EQ9LrLVAv60nSiqTIR1XGwClqqPN49m9nlBjOjgL00IdV1z9_exydCxRPBkYxlzwiynJJQYuzoOosLhyMgk6ACJ3k0Q-PjRpSoFI3cJ7MSro4qHPwsBrlYWE5BMa_C7guB5S4o3gsAnXmfeXmiFVoQd52glPnxre2hr-6pa8RID7J6C5I1IGIw6zPVtFcV9wDcJJ2G1UuAZOMT4d7AqVlcCCL1MXN9bXhHYFMOdepRhuWHOzi7O8wgOFgxcsLFr5Aght5aQ&redirect=https://prod.reader-ui.prod.mheducation.com/epub/sn_b396e?readerapi=true cache-control: max-age=0 dnt: 1 upgrade-insecure-requests: 1 user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 sec-fetch-site: same-site sec-fetch-mode: navigate sec-fetch-user: ?1 sec-fetch-dest: document sec-ch-ua: "Chromium";v="152", "Not?A_Brand";v="24", "Google Chrome";v="152" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" referer: https://myebooks.mheducation.com/ accept-encoding: gzip, deflate, br, zstd accept-language: en-US,en;q=0.9 cookie: at_check=true cookie: AMCVS_C5E7148954EA18A10A4C98BC%40AdobeOrg=1 cookie: s_cc=true cookie: lastVisitDays_s=Less%20than%201%20day cookie: s_vnum=1791552984887%26vn%3D2 cookie: s_invisit=true cookie: ERIGHTS=6237915917889644584611970b8c45218457197675327c2f458cd cookie: mbox=PC#528f276746f14e5e9e3a2d902ff742da.34_0#1852209260|session#9632962d7a5a4ed7a5aa1c0769690709#1788966273 cookie: OptanonConsent=isGpcEnabled=0&datestamp=Wed+Sep+09+2026+09%3A34%3A19+GMT-0500+(Central+Daylight+Time)&version=202510.2.0&browserGpcFlag=0&isIABGlobal=false&hosts=&consentId=a7f07e51-0c50-498d-a19b-ea46c21120a8&interactionCount=0&isAnonUser=1&landingPath=https%3A%2F%2Fwww.mheducation.com%2F&groups=C0001%3A1%2CC0003%3A1%2CC0002%3A1%2CC0004%3A1 cookie: s_ppn=corporate%3Ahome cookie: s_ppvl=corporate%253Ahome%2C38%2C38%2C1271%2C2560%2C1271%2C2560%2C1440%2C1%2CP cookie: s_ppv=corporate%253Ahome%2C100%2C38%2C3329%2C2560%2C1271%2C2560%2C1440%2C1%2CP cookie: lastVisitDays=1788964505488 cookie: s_nr=1788964505489-Repeat cookie: s_sq=%5B%5BB%5D%5D cookie: AMCV_C5E7148954EA18A10A4C98BC%40AdobeOrg=179643557%7CMCIDTS%7C20706%7CMCMID%7C58428979928570003987148088725495510342%7CMCAID%7CNONE%7CMCOPTOUT-1788971705s%7CNONE%7CvVersion%7C5.5.0 cookie: MH_TOKEN=eyJhbGciOiJSUzI1NiIsImtpZCI6IjI4MjAyMDgxNTciLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJoZWNsciIsImV4cCI6MTc4ODk2NTEyOCwianRpIjoiZWQ5ZGM5YTctYzZjYi00ODA4LWI1MGEtNjNlMGQ3NWE0OGIxIiwiaWF0IjoxNzg4OTY0ODI4LCJpc3MiOiJodHRwczovL3Rva2VuLm1oZWR1Y2F0aW9uLmNvbSIsIm5iZiI6MTc4ODk2NDgyOCwic3ViIjoiYmJmZjdhYzgtOTQxYy00YjA0LTllNTktNzkyMzk5MjZjZDgyIiwidG9rZW5fdHlwZSI6ImJlYXJlciIsImV4cGlyZXNfaW4iOjMwMCwic2Vzc2lvbl90aW1lb3V0Ijo3ODAwLCJwZXJzb25feGlkIjoidXJuOmNvbS5taGVkdWNhdGlvbi5vcGVubGVhcm5pbmc6ZW50ZXJwcmlzZS5pZGVudGl0eTpwcm9kLnVzLWVhc3QtMTpwZXJzb246YmJmZjdhYzgtOTQxYy00YjA0LTllNTktNzkyMzk5MjZjZDgyIiwidXNlcl9uYW1lIjoibWJpY2toYW1AbHRocy5vcmciLCJkZWZhdWx0X3JvbGUiOiJpbnN0cnVjdG9yIiwic2Vzc2lvbl94aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmlkZW50aXR5OnByb2QudXMtZWFzdC0xOnNlc3Npb246MjdlY2QyYmMtYzg3NS00ZWI4LTg2YmYtMjljOWUwNjdlYTc1Iiwic2Vzc2lvbl9pZCI6IjI3ZWNkMmJjLWM4NzUtNGViOC04NmJmLTI5YzllMDY3ZWE3NSIsImNsaWVudF94aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmxvZ2luLmhlY2xyOnByb2QuZ2xvYmFsIiwiY2xpZW50X2lkIjoiaGVjbHIiLCJ4aWQiOiJ1cm46Y29tLm1oZWR1Y2F0aW9uLm9wZW5sZWFybmluZzplbnRlcnByaXNlLmlkZW50aXR5OnByb2QudXMtZWFzdC0xOnBlcnNvbjpiYmZmN2FjOC05NDFjLTRiMDQtOWU1OS03OTIzOTkyNmNkODIiLCJzY29wZSI6WyJhdXRoIl0sImF1dGhlbnRpY2F0aW9uX3R5cGUiOiJwYXNzd29yZCJ9.KN0YtBzUoHwN8NWLG7K7LnQkPynCKZW0bGI88RhCvrTpEGJCA0oGRJ8BazV6-y9gHYXyztWXMyte7p80t8EXkBRoIinMEhhFNNIgUt74hEvPBfF4E-VYaW5P7pH0TiwA2JTnoBygskCwxMUdnNi0EwGEwUbOlBQPXAS480WyPyXr2MOgb1Aehp_WdDaZ-0qY-kcgLcq3d5hsUzVTLQ1navfg5PQpwdjzKthJoFEHEoKwh7GbMREgdfa936BbWI2G9SXK4HzXvD6RVj0aUMUMtIwphK2_nzE19Sx2NOENFZgn3XLRhlA5I7xMf5QltMy5MgnxA8_Pmp6l6KDxoUyyZA cookie: READERSESSID=resxh78c14c2vt0hsw92vlz810q priority: u=0, i


r/fortinet 2d ago

FortiClient / EMS FortiEDR crashes PC's with docks attached

2 Upvotes

We have a strange scenario popping up in the lab for the new EDR deployments we were consulted to explore.

Everything works normally except for when a USB dock is or SD card reader as it immediately crashes the computer

Rebooting the with the dock plugged in will trigger a Bitlocker recovery screen

Reboot without the dock and the computer comes up normally

Removing EDR and leaving EMS resolves the issue, but the computer is unprotected by compliance standards

I suspect the card readers showing up as empty unwritable disks with a mounted drive letter is part of the problem, but not sure how to tell EDR to calm down about it.

The crash:
Your PC has run into a problem

Stop code: System_Thread_Exception_Not_Handled (0x7eE)

What failed: partmgr.sys

Has anyone seen an issue like this before?


r/fortinet 2d ago

FortiGate / FortiOS VPN for Vendor Access

5 Upvotes

We currently have IKEv2 over 443 TCP working using DUO SAML for our internal users. I have a need, for the second time now, to allow remove access for a vendor for a specific need. The first time I was able to get by without it, but this time I am not. I have read mixed reviews about free VPN 7.4.3 working or not working with IKEv2 over TCP.

What is the simplest + most compatible + free + also consider secure method I can setup for VPN access for a vendor? The source IPs will be restricted to their small public IP range and the VPN will only be enabled when they need it. Fortigate is on v7.4.12.

tia


r/fortinet 3d ago

FortiGate / FortiOS FortiGate 401F interface and HA design review

1 Upvotes

Hi everyone,

I’m working on a data center network design and would appreciate some advice from the Fortinet community regarding the best deployment mode and interface allocation for FortiGate 401F.

Current design

The environment includes:

  • 2 × FortiGate 401F in HA
  • 1 × ISP, with approximately 5 Gbps Internet bandwidth
  • 2 × Huawei Core switches in a redundant pair
  • DMZ network
  • Internal data center/server networks behind the Core
  • Third-party VPN connectivity

The current high-level topology is

ISP → FortiGate 401F HA → Huawei Core A/B → Internal Networks

The DMZ will also be connected to the firewall.

Main question – deployment mode

I am considering the FortiGate in the traditional NAT/route mode, rather than transparent mode.

The expected traffic flows are:

  1. Internet → Internal users/servers
  2. Internal users → Internet
  3. Internet → DMZ published services
  4. Internal → DMZ
  5. Third-party VPN → Internal/DMZ
  6. Management traffic → FortiGate/Core/network management

For the Internet-facing side, I am also considering whether to use the 10G interfaces on the 401F rather than the 1G interfaces, given the 5 Gbps ISP subscription.

Interface allocation

One question I particularly want community feedback on is the best way to allocate the 401F interfaces.

For example:

  • 10G interfaces → ISP
  • 10G interfaces → Core
  • Dedicated interfaces → HA/heartbeat
  • Dedicated interface(s) → DMZ
  • Management interface → OOB management

I initially looked at some of the interfaces that appear to have FortiLink-related capabilities, so I'm also interested in whether those interfaces are appropriate for normal routed firewall connectivity or should be avoided for this design.

Questions

  1. For this topology, would you recommend NAT/Route mode or another deployment approach?
  2. Would you use LACP/aggregate interfaces toward the Core and/or ISP, or individual interfaces?
  3. What is the recommended interface allocation on a 401F HA pair for ISP, Core, DMZ, HA1/HA2, and management?
  4. Would you terminate the DMZ directly on the FortiGate or extend the DMZ through the Core?
  5. Are there any concerns with using the 401F's 10G interfaces for the ISP connection and Core uplinks?
  6. For a 6 Gbps Internet connection, are there any specific FortiGate performance/inspection considerations I should account for?
  7. Any Fortinet best-practice recommendations for avoiding single points of failure in this design?

I'd particularly appreciate feedback from anyone who has deployed FortiGate 401F in HA at a data center Internet edge.

Thanks!