EasyManuals Logo

Fortinet FortiGate Series Administration Guide

Fortinet FortiGate Series
764 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #331 background imageLoading...
Page #331 background image
System Maintenance Enabling push updates
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903 331
http://docs.fortinet.com/Feedback
If you have redundant connections to the Internet, the FortiGate unit also sends the
SETUP message when one Internet connection goes down and the FortiGate unit fails
over to another Internet connection.
In transparent mode, if you change the management IP address, the FortiGate unit also
sends the SETUP message to notify the FDN of the address change.
Enabling push updates through a NAT device
If the FDN connects only to the FortiGate unit through a NAT device, you must configure
port forwarding on the NAT device and add the port forwarding information to the push
update configuration. Port forwarding enables the FDN to connect to the FortiGate unit
using UDP on either port 9443 or an override push port that you specify.
If the external IP address of the NAT device is dynamic (PPPoE or DHCP), the FortiGate
unit is unable to receive push updates through a NAT device.
The following procedures configure the FortiGate unit to push updates through a NAT
device. These procedures also include adding port forwarding virtual IP and a firewall
policy to the NAT device.
Figure 175: Example network: Push updates through a NAT device
The overall process is:
1 Register the FortiGate unit on the internal network so that it has a current support
license and can receive push updates. For more information, see “Registering your
Fortinet product” on page 26.
2 Configure the following FortiGuard options on the FortiGate unit on the internal
network.
Enable Allow push updates.
Enable Use override push IP and enter the IP address. Usually this is the IP
address of the external interface of the NAT device.
If required, change the override push update port.
3 Add a port forwarding virtual IP to the NAT device.
Set the external IP address of the virtual IP to match the override push update IP.
Usually this is the IP address of the external interface of the NAT device.
Add a firewall policy to the FortiGate NAT device that includes the port forwarding virtual
IP.
Internal
network
NAT Device
Internet
FDN Server
172.16.35.144
(external interface)
Virtual IP
10.20.6.135
(external interface)
Note: Push updates are not supported if the FortiGate unit must use a proxy server to
connect to the FDN. See “To enable scheduled updates through a proxy server” on
page 330 for more information.

Table of Contents

Other manuals for Fortinet FortiGate Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiGate Series and is the answer not in the manual?

Fortinet FortiGate Series Specifications

General IconGeneral
ModelFortiGate Series
CategoryFirewall
ThroughputVaries by model
InterfacesVaries by model
Concurrent SessionsVaries by model
VPN SupportYes
High AvailabilityYes
Firewall ThroughputVaries by model
VPN ThroughputVaries by model
IPS ThroughputVaries by model
NGFW ThroughputVaries by model
Threat Protection ThroughputVaries by model
New Sessions per SecondVaries by model
Power SupplyVaries by model
Security FeaturesFirewall, IPS, Application Control, Web Filtering, Antivirus, VPN
Virtual DomainsYes
Form FactorDesktop, Rackmount

Related product manuals