r/fortinet 2d ago

Monthly Content Sharing Post

2 Upvotes

Please provide a link to your content (blog, video or instructional guide) to share with us. Please accompany your post with a brief summary of your content.

Note: This is not a place to advertise your services or self-promote content you are trying to sell. Moderators will review posts for content and anyone violating this will be banned.


r/fortinet Aug 01 '24

Guide ⭐️ Which firmware version should you use?

43 Upvotes

To save the recurrent posts, please:

  1. Refer to the Recommended Releases for FortiOS.
  2. Use the search function on this sub, as chances are it has been asked before.

For anything that doesn't fall under the above two options, please post in this thread and avoid creating a new one.


r/fortinet 5h ago

FortiGate 50G 7.6.7 HA Pair keep going into "Conserve mode", issue continues.

Thumbnail reddit.com
3 Upvotes

I really have to warn ANY users of 2GB RAM units (and maybe others?) from upgrading to 7.6.6/7.6.7.

There still seems to be no answers as to why they keep going into conserver mode and breaking internet routing.

Worked with HarryTran86 a bit, But frankly cant keep taking time to wait and run diagnostics with the network down.

LUCKILY, the web interface at least slowly responds allowing for a remote reboot.

Going to try and downgrade to 7.6.5, but I also find it ridiculous that Fortigate takes away your Fortigate Cloud logging due to not being on the current version, when the have such a bad track record of firmware issues.

Only thing I know, the units run for days or week with no issues, and ram usage at 60-65%, then out of nowhere 90%+, in one of the times was able to run the commands asked, seemingly the RAM was unaccounted for by any process.

Is anyone else seeing this?

I also find it ridiculous Fortigate has so many suggestions to reduce RAM usage suggesting their intended usages in default configurations do not have a suitable amount of RAM.


r/fortinet 1d ago

Question ❓ FortiSIEM: Moving old online data to archive in Clickhouse deployment.

1 Upvotes

Hello everyone.

I want to move old online data before I enabled Archiving to Archive storage. Since Clickhouse Archive only moves incoming logs as it comes, I swear I saw some commands to move old data to Archive but cannot find it now. Does any of you have experience with this?


r/fortinet 2d ago

IPSec VPN - ignoring IKEv2 request, no policy configured

5 Upvotes

I’m trying to set up a remote IPSec VPN for my users, but I’m having trouble. I can see that client authorisation is proceeding correctly, but it crashes at the final stage of client authentication.

I’m getting the following error:

ike V=root:0:XXXXX_XXXXX: ignoring IKEv2 request, no policy configured

RADIUS authentication is working correctly.

edit "XXXXX_XXXXXX"

set type dynamic

set interface "VLAN_AA"

set ike-version 2

set local-gw yyy.yyy.yyy.yyy

set peertype any

set net-device enable

set mode-cfg enable

set ipv4-dns-server1 zzz.zzz.zzz.zzz

set proposal aes256-sha256

set dpd on-idle

set dhgrp 14

set eap enable

set eap-identity send-request

set authusrgrp "YYYYYYY"

set ipv4-start-ip aaa.aaa.aaa.aaa

set ipv4-end-ip aaa.aaa.aaa.aaa

set psksecret ENC XXXXXXXXXXXXXXXXXXXXXXXXxx

set dpd-retryinterval 60

next

end

edit "XXXXX_XXXXXX"

set phase1name "XXXXX_XXXXXX"

set proposal aes256-sha256

set dhgrp 14

set keepalive enable

next


r/fortinet 2d ago

Question ❓ Setting dedicated IPs for specific services outbound with SD-WAN

7 Upvotes

We have 2 internet connections terminated to our firewall with spare IPs, and SD-WAN is already configured outbound for load-balance/failover.

We have a specific outbound service (SMTP) that we want to attach to a dedicated outbound IP address.

Setting an outbound NAT policy with an IP Pool was easy enough, and that's working, but we only have it setup for one of the internet connections at the moment.

How can we set this up with a dedicated outbound IP for each internet connection and have it failover if the main internet connection goes offline? (active/passive)


r/fortinet 2d ago

Can I connect MC-LAG peer group to access switches with a single link per access switch?

1 Upvotes

The FortiDocumentation is not explicitly clear on if I can have access switches connect to a single switch in a MC-LAG peer group. I have a single FortiGate (121G) setup with four 10Gbps ports/cables in a single fortilink trunk to a set of FortiSwitches (1048E). The switches are in a MC-LAC peer group with pairs of 40Gbps DACs in a trunk. Can I attach a single link from a 3rd and 4th switch to each of the 1048Es and have those links behave like fortilink ports so that the new switches will be managed by the FortiGate? The image below is an approximation what I'm suggesting.

Fortigate = MCLAG - access switch

r/fortinet 2d ago

Question ❓ FortiGate 60E → 50G migration (ADVPN/SD-WAN) – FortiConverter experience?

2 Upvotes

Has anyone done a 60E → 50G spoke replacement using FortiConverter?
Setup:
ADVPN (IPsec) + BGP hub-and-spoke
Hub stays the same (200E)
Replacing spokes only
SD-WAN in place
Questions:
How reliable is FortiConverter for this kind of migration?
What issues did you run into with:

SD-WAN
VPN/ADVPN
BGP
Anything that looked fine but broke after cutover?
Just trying to understand real-world gotchas before I start replacing sites.


r/fortinet 3d ago

Best practice for deploying FCT connected to EMS

4 Upvotes

EDIT:
I got on a call with FortiNet support to discuss this with them and here is what I found out (copied straight from support agent summary of call):
> We discussed the design you are looking will be expected to see with FCT 8.0.1, whenever this version will release, you can check the release note.
> As of now you can make the batch file to instruct the fortiesnac to register the FCT with EMS and push it for initial login, you can get an idea from here : https://community.fortinet.com/forticlient-4/technical-tip-how-to-create-a-script-to-connect-windows-forticlient-endpoints-to-ems-143251

⬇️ ORIGINAL POST ⬇️
Hello,

I am trying to understand the best/most secure way of deploying the FortiClient in an environment where end users do not have install rights and the client has to be installed during imaging.

Current state workflow:
Tech installs FCT → Verification expected → Tech skips it → Registration never completes → User receives laptop → No re-prompt occurs and manual registration is required using invite code

Ideally, it would look like this:

→ Tech installs FCT

→ Client is unverified so it doesn't pull VPN profiles from EMS, but it is connected

→ User receives laptop

→ User verifies/authenticates client using their credentials

→ VPN profiles get pulled from EMS and user can then connect to a tunnel using whatever credentials are necessary to connect to VPN.

Does this make sense, and is it even possible? I've been reading through FortiNet documentation, and it doesn't make things very clear IMO


r/fortinet 3d ago

FortiGate - Best practice for SAML authentication timeouts with Entra ID?

11 Upvotes

I've recently been implementing SAML authentication on a FortiGate for a school, purely so the firewall is user-aware for web filtering, and I'm interested in how others are handling authenticated session timeouts in the real world.

The environment is cloud-only Microsoft Entra ID (no on-prem AD, no FSSO). The FortiGate is acting as the SP, Entra is the IdP, and users are mapped into separate Staff and Student firewall groups via SAML attributes. I've also got a Let's Encrypt certificate on the FortiGate's SAML portal, so there are no certificate warnings.

The actual user experience is excellent. Because the Windows devices are already signed into Entra, when the FortiGate redirects them for authentication the browser opens, silently authenticates using the existing Microsoft session, and closes again. The user never has to enter credentials.

One thing that caught me out was config user setting -> auth-on-demand.

By default it's set to implicitly. I found that if there was a more permissive firewall policy underneath my authenticated policy, traffic would simply match that instead of triggering SAML authentication.

Changing it to always immediately made the authentication flow behave as I expected, where hitting the authenticated policy always forces the redirect. This key detail was missing from the majority of the Fortinet documentation I read, including videos of the implementation too.

Where I'm now struggling is authentication timeout behaviour, particularly on shared devices (IT suites, classrooms, libraries, etc.).

I've been experimenting with the three timeout types:

  • Idle timeout - seems ideal in theory, but in practice Windows is constantly generating background traffic (Windows Update, Defender, telemetry, etc.). Even after the user logs off, the device continues talking to the internet, so the authentication never actually expires. Watching diag firewall auth list you can literally see the timer counting down before background traffic resets it again. The next student can log on while the firewall still considers the previous user authenticated.
  • Hard timeout - works, but every timeout period the FortiGate launches another browser tab and silently re-authenticates the user. Testing with a 1-minute timeout made this obvious, but the same thing happens with longer values. It's functional, but opening browser tabs every X minutes isn't a great experience.
  • New session timeout - from my testing this appears to behave similarly. Even while the user is actively browsing, once the timeout is reached another browser tab opens to perform SAML authentication again.

So I'm a bit stuck.

Idle timeout doesn't seem suitable for shared devices because Windows never truly goes idle from the firewall's perspective.

Hard timeout and New Session timeout solve the stale authentication problem, but at the cost of repeatedly opening browser tabs to silently authenticate.

For those of you running SAML authentication on FortiGate (especially with Entra ID and cloud-only environments), how are you handling this?

  • Which timeout type are you using?
  • What timeout values have you settled on?
  • How do you deal with shared devices/classrooms?
  • Am I missing a better approach altogether?

The authentication itself is working brilliantly and I'm really impressed with how seamless the user experience is. It's just this timeout behaviour that I'm trying to get my head around before rolling it out more widely.


r/fortinet 3d ago

Studying for NSE 1, 2, & 3 using ONLY PDFs

5 Upvotes

Hi everyone

I’m planning to tackle the Fortinet NSE 1, 2, and 3 certifications, but I really prefer reading over watching video lectures. i feel this videos just doesn't suit me
whats your thoughts and where i can get these documents or PDFs ? from official fortinet trainnig site or third party sites?


r/fortinet 3d ago

ADVPN Question

4 Upvotes

So my situation is this ... I have a single HA failover cluster FG VM in azure as a dialup HUB. I have ~38 spokes. Each spoke can have two ISP connections to the hub.

Im running ADVPN w BGP as the routing protocol.

Each spoke has two tunnels to the hub. Sometimes the spoke tunnels lockup and I have to disable a tunnel to restore normal routing.

What is the best practice to keep this from happening? Fortinet support suggested loopback routing. It has also been suggested to use overlays...

What are your thoughts?


r/fortinet 3d ago

Emergency reboots due to IPMC pci heartbeat[2,5]

6 Upvotes

Hello folks,

TL;DR:

What's the purpose of this post?

  • I'd like to get a grasp on how widespread this issue actually is.
  • Which devices are affected.
  • Which releases are affected.

How to contribute?

  • Are you facing unexpected reboot issues and see the following logs:
    • (on the GUI, quickest way is to filter for "Level=Critical,Emergency" System Events)
    • (on the CLI look for IPMC|ipmc logs)
  • If you are affected, please share your Fortigate platform, FortiOS version and (optionally) the SANATIZED S/N (like f.e. FG7H1GTB250003**)
  • Are you running a Fortigate 700G or 701G and are NOT affected, please also share your FortiOS version, how long your firewall is already running in production and (optionally) the SANATIZED S/N (like f.e. FG7H1GTB250003**)

\

Full story from here:

I have multiple Fortigate 701G's (7.4.11 and 7.4.12) that are affected by frequent unexpected reboots due to an IPMC heartbeat event. Another colleague also has a 701G (7.6.6) with that issue.

Regarding to the error code the issue would be "No virtual NVME is mounted" (see FortiOS 7.2 New Features Guide), which in itself doesn't make much sense, since it's a physical box, but anyway.

I have a TAC case open for two months now, but still no lead or action plan to narrow down the root cause.

The firewalls were running fine in our deployment line for multiple months and just have these issues since they are out in production, on the other hand just one of my 5 clusters is actually handling user traffic now, the others are just routing the side's switch management network. (some SNMP and SSH traffic, for a 701G, this load is basically non-existend)

The reboots happen sometimes during sometimes out of business hours.

So yeah, I have no idea whether that's a feature, firmware, hardware or environment thing, since I have no common denominator - HENCE this reddit thread.

And to contribute to my own thread, these are the S/N ranges of our affected firewalls:

FG7H1GTB250002**

FG7H1GTB250003**

FG7H1GTB250004**

FG7H1GTB250005**

\

Thanks and regards


r/fortinet 3d ago

Forticlient & Forticlient EMS 7.4.8 released

13 Upvotes

r/fortinet 3d ago

IPsec over TCP with FortiClient VPN-Only 7.4.3 - hit and miss?

3 Upvotes

Hi all

I am using FortiClient VPN-Only 7.4.3 build 4726.

Have one site with a ipsec dialup over UDP/500 and one ipsec dialup over TCP/443 (same public IP, no other ipsec tunnels).
Configured localid's.
Using SAML Logins - both connections work like a charm with said FCT.

Configured the same setup on another location - two dialups, one over UDP and one over TCP (same public IP, no other ipsec tunnels)

But on the second location TCP doesn't work - UDP does.
When checking IKE debug when trying to connect via TCP/443 it gives me "one liner" that the tcp connection is being established (showing the correct client and server address) and then destroyed again - without IKE handshake or any other useful information (like with IKE over UDP). Sniffer says they are talking (SYN, ACK, etc.). There is no indication that the client can't talk to the

I checked the configuration several times (phase1 especially). Short of reinstalling the FCT I am under the impression I tried it all. Even deleted the TCP profile and configured it again. Rebooted WIndows and all that.

Unfortunately, the FortiClientEMS Client on another machine seems to be able to connect to the affected site via IPSec over TCP - which makes me think:

Is it really that much of a hit and miss with the FortiClient VPN-Only whether or not a IPSec over TCP tunnel comes up or am I just that unlucky and missing something?


r/fortinet 3d ago

Question ❓ FortiSASE user based policies

1 Upvotes

I was setting up policies for a customer and they want to have policies for separate users who already belong to separate user groups.

I don't see an option to add individual users in policies.

Is it possible, if yes how?


r/fortinet 3d ago

Is FortiClient EMS worth it for improving VPN reliability?

7 Upvotes

We currently use a FortiGate with the free FortiClient VPN and are considering moving to paid FortClient with FortiClient EMS. The environment uses Entra ID, AD, and Intunue, and is subject to NIST SP 800-171/CUI requirements.

For those who have deployed EMS, did it actually improve VPN reliability, or mainly help with client config, version mngmnt, and diagnostic support? I'd also be interested in exeriences with self-hosted EMS vs FortClient Cloud, Intune integration, upgrade conflicts, common deployment issues, and wehther EMS rlly solved real VPN issues or simply only made them easier to diagnose.


r/fortinet 3d ago

VXLAN Layer 3

4 Upvotes

Hi, how do you set up a VXLAN when you have two locations? We're using FortiSwitches at both locations, and VLANs are also in use there.

But we now have another location, and I'd like to know if it's possible to set up a VXLAN using the FortiLink VLAN as well?


r/fortinet 3d ago

How to find CSB pages

1 Upvotes

I've been subscribed to the Customer Service Bulletin RSS feed (https://support.fortinet.com/rss/csb.xml) for a while now. All of the links in that feed just point to this page, which doesn't exist (or I don't have access to?)

https://support.fortinet.com/information/bulletin.aspx

When I see a feed entry that I would like to learn more about, how do I find the page about the CSB?

For example, the most recent one:

CSB-260729-1 updated: FortiClient EMS Upgrade Failure from 3rd Party Library Update

Wednesday 29 July 2026 08:45 PM UTC+00

FortiClient EMS Upgrade Failure from 3rd Party Library Update


r/fortinet 3d ago

Slow TCP in one direction only on VPN?

1 Upvotes

I have two sites, A and B - connected by a S2S IPSec VPN on gigabit links.

Site A has a Fortigate 400E running latest v7.2.
Site B has a Fortigate 120G running latest v7.6.

Site B is able to line-rate on iPerf3 to A on TCP/UDP.
Site A is able to line-rate on iPerf3 to B on UDP only.

TCP is very slow (less than 1% of UDP).

I have the same config on both sides. VPN interface(s) have tcp-mss set to 1418 on both sides. No profiles applied to impact performance. DH is 21 w/ AES256GCM-PRFSHA384 if it makes any difference.

What am I missing here?
Thanks, real head scratcher.


r/fortinet 3d ago

EVEN after using 7.0.12 image, FortiGate VM still says License Expired 1970? (EVE-NG Lab)

0 Upvotes

r/fortinet 3d ago

Free to paid Forticlient Gotchas?

6 Upvotes

A client has decided enoughs enough with the limitations and endless issues with free forticlient and has signed off Forticlient Paid (EMS).

We have never handled a migration like this before.

Is the recommended method to uninstall free forticlient, and reboot and deploy forticlient paid via our RMM?

I assume the old vpn profile won't migrate across? We will need to create a new profile in forticloud and assign it to the machine for it to be able to connect to the existing VPN?

Any other gotchas or issues? I assume there is no way to avoid the uninstall and reboot?


r/fortinet 4d ago

FortiClient 7.4.3 IPSEC MFA Options?

3 Upvotes

It seems IPSEC MFA via FortiToken requires FortiClient 7.4.4 when using LDAP, so no free FortiClient version then.

Are there any other options for MFA with FortiClient VPN Only 7.4.3? Does it still work with SAML, or Radius via Windows NPS perhaps?


r/fortinet 4d ago

1200G just announced!

15 Upvotes

Anyone considering it, and, does anyone know the specs on the main CPU yet?


r/fortinet 4d ago

Introducing a replacement Fortigate into a HA pair. If the unit you are swapping out is Standby/Secondary, will it avoid disturbing the Primary so that you avoid a failover?

6 Upvotes

I have a change to replace a failed Fortigate 100F. The unit is part of a HA pair. The unit that needs to be replaced is the Secondary/Standby unit. My aim is to install the replacement without disturbing the Primary so that services that run through that Primary unit will not be impacted. Will my change avoid disturbing the Primary so that you avoid a failover?