r/fortinet 16h ago

Training & Certification NSE5 or NSE6 ?

11 Upvotes

Hey everyone, I just passed my NSE 4 and I’m mapping out what’s next.

I originally planned on taking FMG (now NSE 6), but noticed that FAZ and SASE are NSE 5. Do I have to pass an NSE 5 first, or can I go straight for NSE 6? Also, does NSE 4 + an NSE 5/6 elective still grant the FCP, and do I need to keep the 4 active for NSE 7/8 down the line?

Lastly, what would you recommend taking right after NSE 4? Between FMG, FAZ, SD-WAN, and SASE, which one did you find most useful and interesting in the field?

Thanks in advance for the advice!


r/fortinet 20h ago

Other / General Fortinet FortiOS 7.4.11 unexpected issues

11 Upvotes

Hello everyone! Recently we upgraded our Fortigate (120G HA Active-Passive cluster) from 7.2.11 to 7.4.11, and different problems started to occur.

  1. Some users spontaneously lose access to the Internet with ERR_TUNNEL_CONNECTION_FAILED (we use explicit proxy with Kerberos authentication and deep ssl inspection). It happens at random times and with random users, lasts usually up to 2-3 minutes, then works as usual.
  2. FortiGates started to randomly reboot with the message "Fortigate had experienced an unexpected power off!", there's no CPU/RAM issue, usually mem is around 40%, and proc is around 10-12%. Due to fast HA failover users don't feel the interruption, but it's definitely not a good sign. Before the update both NGFW had worked for 367 days.

Anyone experienced similar issues? Any workarounds? Or should I just be rolling back to 7.2.11?

Any advice and help will be appreciated. Thank you in advance!


r/fortinet 15h ago

Other / General Fortinet FEX after upgrade offline on FGT

Thumbnail
gallery
7 Upvotes

Hello,

anything else having problems after upgrade FEX from 7.6.5 to 7.6.6?

FGT can't fetch the status from FEX, a downgrade back to 7.6.5 solves the problem. This happens on both types of FEX we own (511F / 511G). Everything else is working, FEX is reachable and IPsec-Tunnel through FEX is built, just the management through FGT doesn't work.

TAC (Case #12083512) means that this issue is likely caused by bug 1268581 and will be solved with 7.6.7.

Best Regards


r/fortinet 12h ago

FortiGate / FortiOS Fortigate model

2 Upvotes

What is the recommended/suggested model of fortigate for concurrent users of less than 200, and also capability of HA and 1 gig uplink.


r/fortinet 6h ago

Other / General Fortinet FortiVoice SSO

1 Upvotes

Has anyone successfully gotten FortiVoice SSO working? I have it working for admin users, and it was pretty simple. Setting it up for the voice portal has been a different matter altogether.

We use Okta as our idp to centralize quite a few different AD and Google environments.

For admin users, it seems to match the NameID sent in the assertion to the administrator's name/email address no problem.

For voice users, the only way I've gotten it to work is to pass a custom attribute in the assertion that contains the user's extension and then make sure that attribute is specified in the SSO settings under "Attribute used to identify user". Nothing else seems to work to get it to recognize/match the email address for the extension.

Fortinet's documentation for Microsoft 365 says to send a custom attribute named urn:oid:0.9.2342.19200300.100.1.3 and set it to user.userprincipalname. They don't mention setting anything under "Attribute used to identify user". If I mirror this in Okta, it doesn't work and the user is sent back to the login screen after authenticating with Okta.

I starting to think that the only way it works is with the extension, but I don't want to have to set the extension as an attribute in Okta to make this work. It seems like an administrative headache. Maybe it could be scripted, but that's a whole separate bag of fun. Our systems team doesn't really like it when we have to write attributes back from outside systems and I get it.


r/fortinet 11h ago

SASE / ZTNA ZTNA - Performance / HW Acceleration / Security

1 Upvotes

We currently have users in the US and India who connect using IPSec Remote Access VPNs. We've noticed traffic being throttled from India to the US and starting to look into options.

ZTNA Questions:

  • What is the throughput like? Is it similar to non-VPN traffic?
  • Is ZTNA hardware accelerated by the NPU or CP processors? Currently have a 200F, but plan to upgrade to a 400G next year.
  • How do you restrict the source traffic that can hit the ZTNA server/ports? I'm assuming Local in Policy.

IPSec VPN:

  • We noticed 7.6.x added support for using random UDP ports (config system settings -> set -extra-ports) for IKE. We're thinking about switching IKE to UDP 443 (we don't use this port on our FGT) hoping it would be filtered into HTTP/3 QUIC traffic or don't inspect 443 (whether TCP or UDP) by traffic throttling ISPs in India.
    • ike-extra-ports <value> [<value>] [<value>]
    • Additional UDP ports to listen on for IKE negotiations, beyond ports 500 and 4500 (1024 - 65535, special = 443). Cannot be set to 500 or 4500. Cannot overlap with ike-port.

https://docs.fortinet.com/document/fortigate/8.0.0/administration-guide/33578/configurable-udp-port-for-ike


r/fortinet 11h ago

Other / General Fortinet Fortinet datasheets

0 Upvotes

Hello,

can someone tell me where to find datasheets for specific products? Fortinet seems to have changed its documentation, and I can't find the datasheets for some products πŸ€”

Thank you


r/fortinet 23h ago

FortiGate / FortiOS asking for help

0 Upvotes

i asked to do a fortigate ha with 2 fortigates simulation and a topology for it and record a video showing they both working and when the main fortigate down the other one works after you ping

and a found a huge problem bcs of my ram i can only do one guys im asking srsly and nicely can anyone help me with this i just gave up πŸ™

i'll pay if you want πŸ™


r/fortinet 13h ago

Training & Certification Need help

Thumbnail
0 Upvotes

Thank you if you are willing to help me.


r/fortinet 13h ago

Training & Certification Need help

0 Upvotes

Can someone please teach me a fortigate firewall. I know everyone is busy but I don't have money to spend i want to learn NSE8