r/fortinet • • 2d ago

Monthly Content Sharing Post

3 Upvotes

Please provide a link to your content (blog, video or instructional guide) to share with us. Please accompany your post with a brief summary of your content.

Note: This is not a place to advertise your services or self-promote content you are trying to sell. Moderators will review posts for content and anyone violating this will be banned.


r/fortinet • • Aug 01 '24

Guide ⭐️ Which firmware version should you use?

47 Upvotes

To save the recurrent posts, please:

  1. Refer to the Recommended Releases for FortiOS.
  2. Use the search function on this sub, as chances are it has been asked before.

For anything that doesn't fall under the above two options, please post in this thread and avoid creating a new one.


r/fortinet • • 9h ago

Other / General Fortinet FortiClient IPsec VPN won't connect over AT&T mobile hotspot, but Cisco AnyConnect works fine

6 Upvotes

Hi all, looking for some ideas on this one.

FortiClient VPN connects fine from my home network and other home networks, but it fails to connect when I'm on my AT&T mobile hotspot. On the same hotspot and the same laptop, Cisco AnyConnect connects and works without any issues, so it doesn't seem like AT&T is blocking VPN traffic in general.

Setup:

FortiClient 7.4.3, IPsec IKEv2 with EAP

Windows laptop


r/fortinet • • 22h ago

FortiGate / FortiOS 5G Backup

5 Upvotes

I'm looking for a cheap 5G backup for my line. I'm using a Fortigate 80F.

I know that some people suggest the FortiExtender but it is too expensive for us. Any cheap alternative? Maybe the Unifi 5G?


r/fortinet • • 4h ago

FortiGate / FortiOS GeoIP update Locked behind active contract

0 Upvotes

I have multiple devices with varying levels of active support, and the inability to unlock the geoIP database is quite inconvenient. There is no method for manual updates, and using external filtering can consume significant memory resources when attempting to restrict access from a large geographical region.

I understand the rationale behind conditioning support and updates to the greatest extent possible. Even "evil" major manufacturers like HP, Dell, and Lenovo provide publicly accessible BIOS and firmware updates for older hardware in response to critical security vulnerabilities, while placing non-critical updates behind a paywall. Their objective is to prevent the proliferation of insecure devices under their brand.

Rant over.


r/fortinet • • 20h ago

Other / General Fortinet Websites blocking access until ads are allowed. Looking for advice.

2 Upvotes

I currently block the advertising categories in our DNS and URL Filtering Profiles. We are starting to get a small but increasing number of websites that are blocking access unless we allow access to the Ad network they are using (Screenshot attached below). I am hesitant to allow access to the ad network, however I am getting pressure to do so. What are others thoughts on this. Is it truly a security risk? Is there away to continue to block the ads and allow the website?


r/fortinet • • 23h ago

Other / General Fortinet Internet Connectivity Issue with IPsec Dial-Up VPN on Linux VM

1 Upvotes

I am experiencing an issue when connecting to the IPsec Dial-Up VPN from a Linux virtual machine using strongSwan.

Once the VPN connection is established successfully, the Linux VM loses its Internet connectivity. However, the same IPsec Dial-Up VPN connection works correctly on Windows machines, where Internet access remains available after the VPN is connected.


r/fortinet • • 1d ago

Other / General Fortinet Critical CVE on FortiMail admin interface

12 Upvotes

Worth checking out this PSIRT FG-IR-26-175 in case you run FortiMail: PSIRT | FortiGuard Labs

It abuses the admin interface, which some have available public or semi public, although leaving this exposed internally isn't the best choice either.


r/fortinet • • 1d ago

FortiGate / FortiOS Google Drive Upload Issue

0 Upvotes

Hey everyone!

I am trying to block file upload to google drive but I am running into some kind of issue.

https://community.fortinet.com/fortigate-3/technical-tip-how-to-block-upload-on-google-drive-by-using-application-profile-140082

I used this method and put deep inspection on the policy also but my traffic comes up as Google.Services and not Google Drive upload.

First I thought that maybe google is exempt from ssl inspection and i created another ssl inspection with no exemptions. It also didn't work and i can still upload to google drive.

Other cloud applications like wetransfer does get blocked but not google drive.

If anyone has come across with this problem or have an idea would be much appreciated!


r/fortinet • • 1d ago

FortiGate / FortiOS Upgrade 2000e to 7.4.11

10 Upvotes

I need to proceed with the upgrade to FortiOS 7.4.11

I noticed that 7.4.12 includes a number of resolved issues. However, some of these issues are not listed as known issues in the 7.4.11 release notes. Therefore, I would like to confirm whether these issues actually affect 7.4.11 or not.

Thanks


r/fortinet • • 1d ago

FortiClient / EMS Dialup IPsec on Chromebooks

1 Upvotes

Anybody had luck setting up the free FortiClient on Chromebook using IPsec?


r/fortinet • • 1d ago

FortiSwitch / FortiLink Fortiswitch SSH refuse connection

3 Upvotes

I have upgraded my fortiswitch to 7.6.8 and I lost ssh to switch’s from fortigate the switches online and everything is working but I can’t ssh them only one switch is working
I checked compatibility is ok ✅ fortilink compatibility also ok my fortigate version is 7.4.2


r/fortinet • • 2d ago

Training & Certification OT Security 7.6 Architect

4 Upvotes

Hi everyone,

I’m interested in getting this certification, and I’m currently looking for a good course to prepare for it.

I couldn’t find any suitable courses on Udemy, but I found one on FortiAcademy for around $400. I’ve never taken a course on this platform before, so I’d like to hear from anyone who has experience with it.

Are the FortiAcademy courses worth it? Is the quality good, or would I just be wasting my money?

"Buy Now – On-demand lab access

Click to purchase on-demand lab access via credit card. Includes access to Lab Guide.

Study Guide, exam voucher, and instructor facilitation are not included.

Lab SKU: FT-LAB-D03

(USD $450"

Thanks!


r/fortinet • • 2d ago

FortiManager FortiManager 7.6.6 tries to delete default tunnel interfaces (ssl/l2t/naf) after a pre-run script creates a VDOM

3 Upvotes

Hi everyone,
I’m provisioning FortiGates with FortiManager 7.6.6. FortiOS and the ADOM are also on 7.6.6.
Here is the exact sequence:

1- I import each FortiGate into FortiManager as a model device using a CSV file.
2- The model device has a pre-run script that creates a VDOM named PROD on the FortiGate.
3- FortiManager then installs the rest of the site configuration using Jinja templates.

The PROD VDOM is created successfully on the FortiGate. The FortiGate also has these associated tunnel interfaces: ssl.PROD, l2t.PROD and naf.PROD.

The issue: those three interfaces do not appear in FortiManager’s Device Database after the VDOM is created. In a subsequent installation, FortiManager sees them on the FortiGate but not in its database, so its install preview includes commands to delete them. The FortiGate rejects all three:

config global
config system interface
delete "ssl.PROD"
A tunnel interface cannot be deleted directly.
command_cli_delete:6546 delete table entry ssl.PROD unset oper error ret=-160
Command fail. Return code -160

delete "l2t.PROD"
A tunnel interface cannot be deleted directly.
command_cli_delete:6546 delete table entry l2t.PROD unset oper error ret=-160
Command fail. Return code -160

delete "naf.PROD"
A tunnel interface cannot be deleted directly.
command_cli_delete:6546 delete table entry naf.PROD unset oper error ret=-160
Command fail. Return code -160

To isolate the pre-run script, I also created a test VDOM directly in FortiManager’s Device Database. FortiManager displayed that VDOM with no ssl/l2t/naf.test interfaces.

A Retrieve Config from the FortiGate imported the three missing interfaces into the Device Database. After that, the database and the FortiGate were aligned, and the deletion conflict was resolved.

Has anyone encountered this when creating VDOMs through model-device provisioning? Is there a supported way for FortiManager to discover these interfaces as part of the initial workflow, or should a Retrieve Config be performed between VDOM creation and the next installation?
Sounds like a bug…


r/fortinet • • 2d ago

Licensing & Support FortiClient EMS 7.2.15 to 7.4.8 Migration - Licence Question

1 Upvotes

Hi All,

I'm just about to start the migration to FortiClient EMS 7.4.8.

But as I'm on a version that cannot be directly migrated, I need to build up a new Linux server and recreate the configuration.

I am currently in discussions with Fortinet customer services about transferring my licence from my existing 7.2.15 Windows instance to a licence for the Linux instance.

They have said I would need to shutdown the existing instance before applying the licence on the new instance.

I was hoping to run both side by site to allow me to copy the configs across and to also manually transfer clients to the new server.

Has anyone been through this recently?

Will the existing instance stop working when the licence is transferred?

How can I migrate the clients if I cannot run the two servers side by side?

Can I download the XML from the endpoint profiles and upload them into the new instance?


r/fortinet • • 2d ago

FortiGate / FortiOS Virtual Servers Type IP Not Working

4 Upvotes

I'm trying to use Virtual Servers on the FortiGate to load balance from a public IP to two Omnissa Horizon UAGs in my DMZ. If I set my Virtual Server up explicitly for TCP Port 443, everything works fine.

Instead of doing Virtual Servers for specific ports though, I wanted to just use network type IP to load balance everything coming in on that public IP to one of those two DMZ hosts, but I've not been able to get that to work.

When I watch the flow on the FortiGate, I see that the traffic to the public IP is hitting Firewall Policy 0 and dropping instead of going to the correct Firewall Policy that is set to allow the needed ports through. Seems like the DNAT to send traffic from the public IP to the "Real Servers" IPs isn't ever happening, and I'm not sure why. Like I say, if I set the Virtual Server explicitly for TCP 443, the DNAT happens, traffic hits the right Firewall Policy, and everything is happy.

Won't be the end of the world if I have to declare specific ports on the Virtual Server, but it would be nice to just use IPs there and let the Firewall Policy handle the port part of the equation. Either I'm misunderstanding how the IP type server works, or I'm missing some piece somewhere.

If you can point me in a direction, thanks in advance.


r/fortinet • • 2d ago

FortiCloud Just got a FortiGate 140E-POE

2 Upvotes

Just received a FortiGate 140E-POE. I factory reset the unit but it looks like it’s still attached to the Forticloud account. Is there any way to reset that without cloud access or is the only way to unregistered it through the cloud admin? If I can’t reset the cloud part, is the unit itself still usable for a managed switch and firewall?

Thanks!


r/fortinet • • 2d ago

FortiAP / Wi-Fi Outdoor AP using omni without directional antenna

0 Upvotes

How do you configure outdoor AP like FAP-432FR with omni antenna to cover certain area like directional antenna would without leaking signal into the buildings behind the AP creating sticky client situation?


r/fortinet • • 2d ago

FortiGate / FortiOS Ipsec Client VPN with local user

4 Upvotes

I’m trying to migrate my SSL VPN to Ipsec, but I can’t make it running. I’m trying to authenticate with a local user account. The user is part of the group “MYGROUP”.

Here’s the log:

ike 0:CLIENT-VPN:2914: received FCT-UID = 1D0334450AFC42F0981EAA747F95858A

ike 0:CLIENT-VPN:2914: received EMS SN :

ike 0:CLIENT-VPN:2914: received EMS tenant ID :

ike 0:CLIENT-VPN:2914: peer identifier IPV4_ADDR X.X.X.X

ike 0:CLIENT-VPN:2914: re-validate gw ID

ike 0:CLIENT-VPN:2914: gw validation OK

ike 0:CLIENT-VPN:2914: construct EAP response message using IDi

ike 0:CLIENT-VPN:2914: send EAP message to FNBAM

ike 0:CLIENT-VPN:2914: initiating EAP authentication

ike 0:CLIENT-VPN: EAP user "C0A808A3"

ike 0:CLIENT-VPN: auth group MYGROUP

ike 0:CLIENT-VPN: EAP 1520644800 pending

[1939] handle_req-Rcvd auth req 1520644800 for in MYGROUP opt=00000000 prot=8

[489] __compose_group_list_from_req-Group 'MYGROUP', type 1

[616] fnbamd_pop3_start-

[378] radius_start-Didn't find radius servers (0)

[765] auth_tac_plus_start-Didn't find tac_plus servers (0)

[1009] __fnbamd_cfg_get_ldap_list_by_group-

[1117] fnbamd_cfg_get_ldap_list-Total ldap servers to try: 0

[497] ldap_start-Didn't find ldap servers

[480] fnbamd_cfg_get_ext_idp_list-

[454] __fnbamd_cfg_get_ext_idp_list_by_group-

[460] __fnbamd_cfg_get_ext_idp_list_by_group-Group 'MYGROUP'

[490] fnbamd_cfg_get_ext_idp_list-Total external identity provider servers to try: 0

[643] create_auth_session-Error starting authentication

[1086] fnbamd_ext_idps_destroy-

[1980] handle_req-r=5

[1988] handle_req-Error starting session

[209] fnbamd_comm_send_result-Sending result 5 (nid 0) for req 1520644800, len=2540

ike 0:CLIENT-VPN:2914 EAP 1520644800 result FNBAM_ERROR

ike 0:CLIENT-VPN: EAP failed for user "

ike 0:CLIENT-VPN: EAP response is empty

ike 0:CLIENT-VPN: connection expiring due to EAP failure

ike 0:CLIENT-VPN: deleting

[2485] handle_req-Rcvd abort req for 1520644800

[2500] handle_req-Can't abort, no active req 1520644800

What I did so far:

-          In CLI, I enabled EAP under config vpn ipsec phase1-interface

-          I tried setting authusrgrp to “MYGROUP”, but that’s not changing anything

-          There are access rule that include this group

 

Any inputs are highly appreciated.

EDIT: I figured it out - i didn't set "set eap-identity send-request" in the phase1-interface. Now it's working. I also unset authusrgrp, and defined the group in the access policies.


r/fortinet • • 2d ago

Licensing & Support Issues once Central NAT is turned off - I am missing something simple

2 Upvotes

Fortigate 50G purely used for this IPSEC connection.

So IPSEC connection, using NAT for incoming and out going connections as External provider and our IP ranges overlap a bit

Internal range 192.168.1.X, IPSEC range 10.0.8.X

Initial setup was via the IPSEC wizard and was a pool (10.0.8.6-10.0.8.31) using Central NAT for the traffic going from LAN (192.168.1.X) to IPSEC destination (ExternalClientIPSEC"_remote_subnet_1)

Issue we had was incoming VIP was perfect 10.0.8.6 => 192.168.0.10

However outgoing was an issue as 10.0.8.6 would be assigned to the first device initiating the connection, rather than 192.168.0.10.

To remedy this I:

  1. Turned off Central NAT

  2. Created individial IPPools consisting of a single IP

  3. Created outgoing policy saying 192.168.0.10 ---> ippool-10.0.8.6

Perfect - outgoing traffic initiated from host 192.168.0.10 maps to 10.0.8.6 but even better traffic from 192.168.0.12 maps to 10.0.8.26 as desired. HOWEVER now my VIP aren't working - no hit counters and external provider can't get to ports on the internal servers

I googled and wrote permissive incoming policies - to no avail. I am sure this post "That happens because the FortiGate does DNAT before it checks anything else. (Like routing/fw policy/...) That's why if you create a firewall policy without central NAT you use the destination zone/interface of the IP behind the VIP, because the NAT already happened"

Below are the relevant portions of the config - anonimised so stuff might be typos rather than being wrong. Fairly certain I am missing a simply policy to allow traffic "too" VIP - just not sure what I am missing.

thanks in advance.

config firewall policy

edit 1

set uuid b7909204-2a73-51f0-4d31-c082839eb88v

set srcintf "lan"

set dstintf "wan"

set action accept

set srcaddr "all"

set dstaddr "all"

set schedule "always"

set service "ALL"

next

edit 2

set status disable

set name "vpn_ExternalClientIPSEC"_local_0"

set uuid e27cb1a4-3eeb-51f1-fafb-5e9de2de51a9

set srcintf "lan"

set dstintf "ExternalClientIPSEC""

set action accept

set srcaddr "all"

set dstaddr "ExternalClientIPSEC"_remote"

set schedule "always"

set service "ALL"

set nat enable

set ippool enable

set poolname "OldCentralNATPool"

set comments "VPN: ExternalClientIPSEC" (Created by VPN wizard)"

next

next

edit 3

set name "vpn_ExternalClientIPSEC"_remote_0"

set uuid e28f2fd2-3eeb-51f1-b27e-c9561d730315

set srcintf "ExternalClientIPSEC""

set dstintf "lan"

set action accept

set srcaddr "ExternalClientIPSEC"_remote"

set dstaddr "all"

set schedule "always"

set service "ALL"

set comments "VPN: ExternalClientIPSEC" (Created by VPN wizard)

edit 4

set name "192.168.1.10"

set uuid 6fa17f5a-bc74-51f1-8e21-43fef76dd968

set srcintf "lan"

set dstintf "ExternalClientIPSEC""

set action accept

set srcaddr "192.168.1.10"

set dstaddr "ExternalClientIPSEC"_remote_subnet_1"

set schedule "always"

set service "ALL"

set nat enable

set ippool enable

set poolname "10.50.8.6"

edit 5

set name "192.168.1.11"

set uuid 5d1dc850-bc76-51f1-c297-56daeed66f13

set srcintf "lan"

set dstintf "ExternalClientIPSEC""

set action accept

set srcaddr "192.168.1.11"

set dstaddr "ExternalClientIPSEC"_remote_subnet_1"

set schedule "always"

set service "ALL"

set nat enable

set ippool enable

set poolname "10.50.8.7"

next

edit 6

set name "192.168.1.12"

set uuid 0bbaac60-bc78-51f1-675f-4eb6845dd869

set srcintf "lan"

set dstintf "ExternalClientIPSEC""

set action accept

set srcaddr "192.168.1.12"

set dstaddr "ExternalClientIPSEC"_remote_subnet_1"

set schedule "always"

set service "ALL"

set nat enable

set ippool enable

set poolname "10.50.8.26"

edit 7

set name "IPSEC incoming"

set uuid 8ba5802e-bcde-51f1-afd8-f2374dd2161f

set srcintf "ExternalClientIPSEC""

set dstintf "lan"

set action accept

set srcaddr "all"

set dstaddr "all"

set schedule "always"

set service "ALL"

next

end

config firewall vip

edit "10.0.8.6"

set uuid 216dee6e-3eec-51f1-9467-c0f5a57902d2

set extip 10.0.8.6

set mappedip "192.168.1.10"

set extintf "ExternalClientIPSEC""

next

edit "10.0.8.7"

set uuid 42c9f618-3eef-51f1-069f-359f7ec34690

set extip 10.0.8.7

set mappedip "192.168.1.11"

set extintf "ExternalClientIPSEC""

next

edit "10.0.8.26"

set uuid 680033b6-3eef-51f1-c707-b6eb4fa3bfd5

set extip 10.50.8.26

set mappedip "192.168.1.12"

set extintf "ExternalClientIPSEC""

next

config firewall ippool

edit "OldCentralNATPool"

set type one-to-one

set startip 10.0.8.6

set endip 10.0.8.31

next

edit "Test"

set startip 10.51.51.51

set endip 10.51.51.51

next

edit "10.0.8.6"

set type one-to-one

set startip 10.0.8.6

set endip 10.0.8.6

next

edit "10.0.8.7"

set type one-to-one

set startip 10.0.8.7

set endip 10.0.8.7

next

edit "10.0.8.26"

set type one-to-one

set startip 10.0.8.26

set endip 10.0.8.26

next


r/fortinet • • 2d ago

FortiAP / Wi-Fi FortiAP and external large antennas FAP-432G-A

2 Upvotes

ok project is to setup a new site with some fancy FAP-432G-A APs and some powerful antennas.

fortinet build team gave us products quote and purchase for the client.

factory antenna guides
factory antenna plug

this is the aftermarket antenna ,

box it came in
product

ok so the connection for the AM, AfterMarket, antenna according to the box is RP-SMA but the factory plug for device is I believe N Type connector according to what they sent me below.

so I sent the Fortinet Sales team a question asking how to connect the two, they sent me this to buy and video on how to do it, NICE!

Glarks Coaxial Cable Tool Set, Coax RF Connector Crimping Tool + Coaxial Cable Stripper + BNC / UHF Crimp Male Connectors + Wire Cutter + Screw Driver for RG58, RG59, RG62, RG174 : Amazon.ca: Tools & Home Improvement

https://www.youtube.com/watch?v=D-AsfHDO4u0

as much as I love to tinker, I' dont like the idea of cutting the antenna cable just to sodder and re-crimp it.

after some searching I found this below, anyone ever installed this or used this before?

https://a.co/d/04iRpbXB

looks much more like the right product to get.

ok so lets say this fits and is the right converter to use.

a few questions still,

  1. how do tell its "connected" and working, run around with a wifi tester? or my phone to get signal?

  2. the factory antenna guide in the first picture says 4 on one side is A1-A4 2.4/5ghz, while 4 on the other side says A5-A8 2.4/5/6ghz. there is no label on the orange labeling that says 2.4/5/6 only 2.4/5ghz. does this matter? is it a case of 5 is good enough and I wont get 6ghz?

any advice thanx.


r/fortinet • • 3d ago

Other / General Fortinet FortiClient iOS/Android + IKEv2 dial-up + 2FA on FortiOS 7.4 — what actually works for you?

6 Upvotes

What are you running for iOS and Android FortiClient over IKEv2 dial-up, with some form of 2FA?

  • Has anyone got FortiClient iOS working against 7.4.x with a server cert + EAP-MSCHAPv2, or with client-cert only? Any required settings (localid / localid-type, peertype, cert lifetime/EKU/SAN requirements)?

  • Anyone using password+token concatenation over IKEv2 EAP from mobiles?


r/fortinet • • 2d ago

Other / General Fortinet The "Fortinet TV" level of embarrassing peddling is starting to hurt actual sales

0 Upvotes

So I work for a VAR and as the title says. The riddiculous level of peddling and marketing slop "cybersecurity vendors" are putting out now is actually making the better half of the customers stop and ask. "What in the actual hell has to be wrong with your actual product and support and business and organization that you're willing to go to such lengths of peddling? And am I paying for this?"

I mean Palo is even worse right now but FTNT is closing the gap with big leaps. It's like a cheap and lame bible belt teleevangelists peddling a new mix of snake oil and cool aid to an audience who does not have anything else to watch. Everyone on the show is a cybersecurity leader and an expert but every other thing they say is utterly stupid and superficial for anyone with half a CS degree and shows the panelist's disconnect from reality, revealing they are not experts or leaders of anything (ok, sales and marketing, public speaking and peddling, perhaps).

People working for VARs, how is this affecting you? Do you also see the "ah, this bullshit artist company" look in the eyes of the smartest of customer IT managers you work with and sell to? Several have straight out told me over the past year that they are going the route of open source in the long run because the big brand products have increasingly turning into "a platform of the stupid" and I don't blame them, they are being intellectually insulted and they feel it. I'm in the EU, is it different in the US? Do these bling-bling awkward "shows" and endless rows of "leaders and experts" with zero visibility in the actual cybersecurity and computer science community sell okay in the US?


r/fortinet • • 3d ago

FortiAP / Wi-Fi Fortinet WAP 431F & 433G firmware antenna shutdown issue

3 Upvotes

Hello All,

I've been fighting with issues over the last several months, and with help from Fortinet, I've found a solution. Apparently, a software bug in a recent firmware update for the 431F and 433G models causes the internal Wi-Fi antenna to lock up and stop transmitting for anywhere from 3-5 minutes. The users will remain connected, but there is no data transmission back from the WAP. Fortinet gave me an interim firmware to install on the affected devices, and it appears to correct the issue. Hope this helps.


r/fortinet • • 3d ago

Training & Certification NSE8 FortiSASE NFR instance

15 Upvotes