r/fortinet

Forticlient SAML SSO break on Edge

USER A pc , domain joined only.

Edge browser login with user A m365 profile.

No Microsoft defender, no conditional access.

Edge + User A = SAML SSO login failed. M365 prompted, user key in password and 2FA, returned result is empty response.

Edge + User B = success

Chrome + User A = Success

Any settings that might goes wrong for the Edge profile that blocking this SAML SSO process?

reddit.com
u/chillbro_123 — 16 hours ago

FortiClient EMS 7.4.7 to 7.4.8 Upgrade results in broken Installer Links

Has anyone had any issues upgrading from FortiClient EMS 7.4.7 to 7.4.8?

We upgraded FortiClient EMS from 7.4.7 to 7.4.8. This is running on Ubuntu Server 24.04. Immediately after the upgrade, all installer downloads on TCP 10443 returned HTTP 404, including preexisting 7.4.7 packages and newly created 7.4.8 packages.

The physical installer files existed under /opt/forticlientems/data/clients/installers, were valid regular files, and were readable by Apache’s www-data account. Apache correctly rewrote download requests to the EMS Django /installers/nouid and /installers/fctuid handlers. Both handlers immediately returned HTTP 404 despite correct site=default selection.

Reloading systemd and restarting Apache did not resolve the issue. Restoring the complete pre-upgrade EMS 7.4.7 snapshot immediately restored normal port-10443 file downloads using the same hostname, certificate, network path, storage, and packages.

Has anyone seen the same issue or know of a bug ID or workaround? If not, I'll open a case with TAC.

reddit.com
u/vabello — 21 hours ago

Help with AP management, if possible?

Hello, I am wondering if it's possible to manage AP's without a fortiswitch? Company just bought a Fortigate to be used but they are sticking to the old Entrasys switch. I have it connected but it keeps using the main internet (10.1.1.x) and I am unable to find where to assign the proper VLAN tag for it. It needs to go to on the (10.1.2.x). Old switch has the proper VLANs tagged, now I just need to figure out how to get the AP to use the right VLAN.

reddit.com
u/RAAonly — 1 day ago

IP-Framed IPSecv2 Fortigate 7.4

Unfortunately, the option to assign an IP address to a user is not working. In the RADIUS test on the firewall, I can see that it receives an IP address along with the user’s details. Unfortunately, the address is not assigned to the tunnel and the user is allocated an address from the pool. On Windows, RADIUS EAP-MSCHAPv2 is included in the Windows configuration. On the firewall, in the ph1 configuration, I have `set assign-ip-from usrgrp`.

Now, one more question. Should the addresses to be assigned to the user come from the pool

`set ipv4-start-ip 10.xxx.xxx.1`

set ipv4-end-ip 10.xxx.xxx.254

Or should they be outside this range? I’ve tested both approaches. Neither of them worked.

reddit.com
u/szczebrzeszyn09 — 1 day ago

Is fortigate filtering photos of passwords?

Hi guys, sorry for the dumb question.

Minutes ago I was taking a photo from inside Whatsapp (to me) of my desktop screen with the LAPS password in the Entra admin console. The photo did not deliver, there were the clock icon. Tried several times and same problem. I was connected to my company wireless network, and fortigate is the wireless controller. I disabled wifi on my mobile and soon after I got the two blue checkmarks. I went to the firewall policy that my mobile devices use and I do not have any DLP enabled...

Are there any default settings on the fortigate that prevent "sensitive" data to traverse (forward) it?

EDIT: I forgot to also say that I took pics of random things on my desk (keyboard, etc) and they delivered correctly while connected to the wifi.

Thanks

reddit.com
u/bianko80 — 1 day ago

FAZ Reports with annoying ::ffff on firmware 7.6.4

Hello everyone,
I have had the FAZ uplifted to the above firmware and now I am getting ::fff appended to all the reports, I even went to the built in chartbuilder after having done a search on source and destination and still get the ::ffff. Any ideas how to fix this ?

https://preview.redd.it/jwgp917kbikh1.png?width=624&format=png&auto=webp&s=af2edebe11e59d8f8b8823a54baded6b100204d3

https://preview.redd.it/0eaofpgdbikh1.png?width=281&format=png&auto=webp&s=256a5a361295a31cd27ea0303aa24480a01f72cf

reddit.com
u/Able_Mail_917 — 1 day ago

My boss basically forced me to get the NSE4. Six months later I'm glad he did, for a reason he definitely didnt intend.

My boss basically forced me to get the NSE4. Six months later I'm glad he did, for a reason he definitely didnt intend.

I do desktop support at a mid size logistics company. Ticket queue, printers, the occasional switch port. Fine job, not a career.

Management here worships certs. Not skills, not tickets closed, certs. There's an actual matrix on SharePoint mapping acronyms to pay bands. My manager told me straight up that my raise was blocked until I had "something networking". He wanted NSE4 because we run Fortinet everywhere.

I thought it was silly, I said I dont touch the firewalls, we have a network team for that, let me do the CCNA at least. He said the matrix says NSE4. So I studied for two months on my own time, and passed first try.

Got the raise. Four percent. no big deal.

Then in March they outsourced the entire network team to an MSP. Eleven people gone. And because I was the only person left in the building with a Fortinet cert, I wasnt just kept, they moved me into the role the MSP was supposed to be overseeing. New title and thirty percent bump, and I got the job i was working towards without even intending to do so.

TL;DR: got strong armed into a cert I didn't want, then it was the only reason I survived a layoff. The system is dumb, learn to play it anyway.

reddit.com
u/Hazbend — 2 days ago

Application control not working on ROBLOX

I would like to manage my child's gaming time on ROBLOX.

Created new Application control rule:

  • Blocked all categories
  • Allowed ROBLOX only

Firewall policy:

  • Enabled SSL deep inspection
  • Enabled upper application control rule

I found "high UDP ports" is required. But it's blocked by "Unknown Applications" of new Application control rule.

Game can be played after modified Application control rule to,

  • Blocked all categories
  • Allowed ROBLOX
  • Allowed Unknown Applications

Could the root cause be that the application control database is not up to date?

Thanks

reddit.com
u/mailliwal — 1 day ago
▲ 11 r/fortinet+1 crossposts

Former IT reset Fortinet Gateway Password

What's the best way to get back in? It's a Gateway, 7 switches, and 65 APs. I've asked the client who sold them the gear it's been through the hands of 2 MSPs and no one seems to know passwords. Transitional passwords between the last 2 MSPs (not ours) are not right.

I want to work veryhard to make sure we don't brick this stuff and get into a mess.

It's newer gear, so unlikely the maintainer account is still in place on this firmware.

How do we go about getting access back/proving ownership to Fortinet?

EDIT: We were able to track down credentials from MSP 2. Thanks for all the responses.

reddit.com
u/wowitsdave — 2 days ago

Anyone using Python or Ansible with FortiGate in production? What does it actually look like?

Managing FortiGate across 100+ sites and starting to think about automation. Curious what people are actually doing vs what's theoretically possible:

  1. Are you using FortiGate's REST API, Ansible (fortinet.fortios collection), or something else for automation?
  2. What's your most useful script or playbook — what problem does it actually solve day to day?
  3. Is FortiManager's built-in API enough for most use cases or do you still need to write custom Python on top of it?
  4. For someone learning — should they start with the REST API directly, or go straight to Ansible?
  5. Has knowing FortiGate automation specifically made you more attractive to employers or is it still too niche?
reddit.com
u/wh00is007 — 2 days ago

Forticlient VPN free, SSO to Entra, External Browser. Isn't passing auth off to client after browser auth succeeds.

****Resolved

Forticlient 7.4.3 1.8758

Just started happening, no configuration changes.

Edge opens, completed login and MFA Auth, hangs at https://login.microsoftonline.com/common/SAS/ProcessAuth and never sends the completed auth back to forticlient.

Checking if anyone else is experiencing this.

Failure reason on Entra side: The session has expired or is invalid due to re-authentication checks by conditional access.

CA policies same as they have ever been.

We have very few users so haven't gone EMS yet.

Thanks

reddit.com
u/brosauces — 2 days ago

Advpn routing question

Hello everyone,

If I have lets say a Hub and spokes with 2 ISPs. For the ADVPN I will have 4 tunnels between each sopke and hub 1-1, 1-2, 2-1, 2-2....right?

Anyways my question is how is asymmetrical routing handle here? Hub might think one overlay is better, spoke might chose a different one. Hows is this handled?

reddit.com
u/26Jack26 — 3 days ago

FortiClient IPSec IKEv2 VPN on iOS

Hello everyone! I'm trying to configure RA IPSec VPN with IKEv2. My issue is, the gateway looks like thiks:

edit "Dialup_cert_2"

set type dynamic

set interface "VL1461"

set ike-version 2

set authmethod signature

set net-device disable

set mode-cfg enable

set ipv4-dns-server1 192.168.104.252

set proposal aes128-sha256 aes256-sha256 aes128gcm-prfsha256 aes256gcm-prfsha384 chacha20poly1305-prfsha256

set dpd on-idle

set dhgrp 5 14 20

set eap enable

set eap-identity send-request

set eap-cert-auth enable

set cert-peer-username-validation cn

set certificate "wildcard"

set peer "IKE2_TEST"

set ipv4-start-ip 10.0.1.1

set ipv4-end-ip 10.0.1.254

set ipv4-netmask 255.255.255.0

set dpd-retryinterval 60

next

end

My peer looks like this:

sh user peer IKE2_TEST

config user peer

edit "IKE2_TEST"

set ca "CA_Cert_4"

set cn "O=A, C=B, OU=C"

next

end

And everytime I try to connect to the gateway on my iPhone, I get the following debug:

ike V=root:0:Dialup_cert_2:26319: peer identifier IPV4_ADDR 192.168.0.72
ike V=root:0:Dialup_cert_2:26319: re-validate gw ID
ike V=root:0:Dialup_cert_2:26319: gw validation failed

When I try to actually input certificate fields in the localid, I get the following:

ike V=root:0:Dialup_cert_2:26341: received peer identifier FQDN 'O=A,C=B,OU=C '
ike V=root:0:Dialup_cert_2:26341: re-validate gw ID
ike V=root:0:Dialup_cert_2:26341: gw validation failed

I do understand that the firewall reads it like a string, not like actual certificate fields. My question is: is there a way make FortiClient send it correctly? Perhaps some service characters or something like that. Otherwise I'll be rolling back to IKEv1.

Any help is appreciated! Thanks in advance!

reddit.com
u/Even-Camel7593 — 3 days ago

Unskippable Mandatory FortiCare registrationg...really Fortinet?

Tried to setup a 90G for the first time like many other models thought it would be straight froward , was welcome with a mandatory fortigate registration for forticare. I wouldn't mind this infact I prefer it to link it straight away except I tried two methods to give it internet on the WAN port (even a phone ethernet tethering) and neither worked to find the reseller and YOU CAN'T SKIP IT THIS SCREEN UNLESS YOU USE CONSOLE CONNECTION.

So you are stuck unless you have a console cable to turn off enforcement but of course this does not come in the box, is this a joke? Did this really get signed off without considering a bypass method for the customer?

It's idiotic, heres my constructive feedback. Either give the option to skip it via Web GUI or stop being cheap and supply the cable for console connection. You already charge a handling fee I'm sure that can be included in the cost.

Has anyone else had it fail to get a WAN connection from the start and had this annoying issue?

reddit.com
u/-Sidwho- — 4 days ago
▲ 178 r/fortinet

Got this From Used Market !

I know nothing about firewalls, and I bought this to learn!

u/TechJoseph — 5 days ago

IKEv2 Client VPN with FAC and AD Authenticating but client timed out

Hi All

Hope anyone here is able to assist as logging issues with forti is more frustrating than dealing with this issue.

Layout.
Client VPN (EMS and free)
Firewall to FAC to AD

I created a new IPSec with IKEv2, I tested and got it all working then after a bit I had to VPN in again and it didn't work.
I logged on to the AD and checked the account password was not expired and the account was not locked out.
Tried VPN again and it times out.
I then reset the AD account password to the same as it was and the VPN worked.

The next day the same thing happened.
I checked the FAC and the Firewall logs and all logs show that the authentication was successful but the FortiClient timed out.

Timeout it set to 60.

This is happening on the free client and EMS. And I cant find any logs showing anything real in terms of there being an issue.

Anyone ever experience anything similar?

Im happy to share redacted configs if anyone needs.

reddit.com
u/sparcmo — 4 days ago

FortiGate Transparent Proxy Policy

Hi, we use Transparent Proxy Policies for destination FQDN's only, but I can't really understand why would we do it if we can just stay with the IPv4 Firewall Policy and apply all security profiles there.

Can someone explain the differences in behaviors? as traffic needs to match the IPv4 Policy first anyway and I can't see any real benefit just management overhead.

reddit.com
u/djguitarroy — 4 days ago

First time managing FortiWeb - courses only covered ~30%, feeling lost. Looking for guidance on how to actually get proficient

Hi everyone,

I recently stepped into managing a live, deployed FortiWeb environment as my first time ever working with the appliance. I've completed a couple of official courses, but honestly, they only covered about 30% to 40% of what I'm dealing with day-to-day. I don't have a formal development or heavy AppSec background, and some colleagues mentioned that dev experience is needed, which has me feeling a bit overwhelmed and clueless about what's actually happening under the hood.

Right now, I'm diving heavily into the official administration documentation because it seems like the only place that covers the device end-to-end. Specifically, I'm currently facing practical operational tasks like onboarding new websites into production.

Could the community share some guidance and best practices on how to bridge this gap and get truly proficient? I'm looking for:

  • Reading & Resource Roadmap: Beyond the official admin guide, what documentation sections, admin guides, or troubleshooting references are absolute must-reads to cover almost everything comprehensively?
  • Handling False Positives: What are the most common beginner mistakes when tuning false positives, and how do you handle them safely without accidentally lowering your security posture?
  • Essential Skills: For someone without a software development background, what specific concepts (HTTP protocols, regular expressions, JSON/XML structures) do I need to master to feel confident managing WAF rules?

Any advice, recommended workflows, or "lessons learned" from seasoned FortiWeb admins would be hugely appreciated. Thanks!

reddit.com
u/mohammedalrawii — 4 days ago

Confirming if Forticlient or Fortigate SSL VPN are still free as for August 2026

I would try to deploy some Fortigate SSL vpn with forticlient. But I wanna have some extra confirmation from you guys whether they are still free as to date.

reddit.com
u/roti_kaya_42 — 5 days ago
▲ 6 r/fortinet+1 crossposts

FortiGate VS Aryaka

My company is going through a merger and we have Ayaka SDWAN and firewalls on one side and FortiNet FortiGate on the other side for SDWAN and Internet points of presence.

I’m currently reviewing both sides and meeting with vendors, but I’m interested to see real world applications on if one is better than the other. Or is one more preferred where a major enterprise with closer to 100 sites.

We don’t use either one of them for client VPN access. This is strictly just for facility and site Internet, and SDWAN

reddit.com
u/RevolutionaryCare138 — 5 days ago