SlideShare a Scribd company logo
1 of 8
Download to read offline
FORTIGATE FIREWALL HOW TO
ONLINE SERVICES

www.ipmax.it
INTRODUCTION
Now our firewall is connected to the Internet, so we could try to use this setup to set
the system time and verify the subscription to the FortiGuard services.
FortiGuard services allow the firewall to be up to date on its virus, spyware and
vulnerability signatures. Web filtering lists are also updated through FortiGuard
services.
It’s important that you have a valid subscription to the FortiGuard services in order to
get the above mentioned updates.
NTP
To configure system time by NTP go to the System > Status dashboard and click on
"Change" in the System Time row. Configure the firewall to be an NTP client as shown in
the following picture.
In our example we use FortGuard NTP servers
for time synchronization, but you could use
your preferred ones. The time zone could also
be modified as per your needs.
The FortiGate unit could also be configured to
be an NTP server. During the NTP server
configuration, you can select one or more
interfaces on which listen to NTP client
association requests.
FORTIGUARD SERVICES
FortiGuard services configuration is very
simple: you must subscribe them and
register your FortiGate unit. The FortiGate
firewall will connect to the FortiGuard
services automatically, but your
intervention is needed in order to verify
that all subscribed services are reachable
and the associated license is not expired.
As you could see from the License
Information dashboard widget (on the
right), Active services are marked with a
green check, expired ones are marked
with a red cross and unreachable ones are
marked with a gray cross.
FORTIGUARD SERVICES TROUBLESHOOT
Sometime may happen that your FortiGate firewall is not able to connect to the
FortiGuard services onto the Internet. This situation has been shown in the previous
slide when a service is marked with a gray cross.
Because FortiGuard services require an Internet connection, you must verify that they
are reachable: connect to the firewall CLI and execute a ping test ond/or a traceroute
with the following commands.
execute ping www.fortiguard.com
execute traceroute www.fortiguard.com

Sometimes there is a policy or a web filtering rule that blocks FortiGuard services, so
verify that such configuration is not in place.
FORTIGUARD SERVICES TROUBLESHOOT CONTINUED
You can also view the FortiGuard
connection status by going to System >
Config > FortiGuard.
At the end of this menu, you could also
change the L4 port used by the
FortiGuard services. This configuration
is very important because sometimes
the default port (port 53) is blocked by
your ISP or inside your network (it’s the
same port used by DNS!).
The other available port to be used for
the FortiGuard services is port 8888.
MORE NEEDS?
See hints on www.ipmax.it
Or email us your questions to info_ipmax@ipmax.it
IPMAX
IPMAX is a Fortinet Partner in Italy.
IPMAX is the ideal partner for companies seeking quality in products and
services. IPMAX guarantees method and professionalism to support its
customers in selecting technologies with the best quality / price ratio, in the
design, installation, commissioning and operation.

IPMAX srl
Via Ponchielli, 4
20063 Cernusco sul Naviglio (MI) – Italy
+39 02 9290 9171

More Related Content

Viewers also liked

Javascript for php developer
Javascript for php developerJavascript for php developer
Javascript for php developer
Dang Tuan
 
1948 Arab–Israeli
1948 Arab–Israeli1948 Arab–Israeli
1948 Arab–Israeli
jakblack
 
Israeli-Palestinian Conflict
Israeli-Palestinian ConflictIsraeli-Palestinian Conflict
Israeli-Palestinian Conflict
theironegoodson
 
Similarities
SimilaritiesSimilarities
Similarities
ippnw
 

Viewers also liked (18)

WWI 5 Weapons
WWI 5 WeaponsWWI 5 Weapons
WWI 5 Weapons
 
Javascript for php developer
Javascript for php developerJavascript for php developer
Javascript for php developer
 
The Invention of Nuclear Weapons
The Invention of Nuclear WeaponsThe Invention of Nuclear Weapons
The Invention of Nuclear Weapons
 
The Arab Spring: A simple compartmental model for the dynamics of a revolution
The Arab Spring: A simple compartmental model for the dynamics of a revolutionThe Arab Spring: A simple compartmental model for the dynamics of a revolution
The Arab Spring: A simple compartmental model for the dynamics of a revolution
 
Heroines And Heroes Of Sindh Long March
Heroines And Heroes Of Sindh Long MarchHeroines And Heroes Of Sindh Long March
Heroines And Heroes Of Sindh Long March
 
Cold war Photo Essay World History
Cold war Photo Essay World HistoryCold war Photo Essay World History
Cold war Photo Essay World History
 
Red Star Over China (Speaker: Vincent Lee Kwun-leung) [Part 2]
Red Star Over China (Speaker: Vincent Lee Kwun-leung) [Part 2]Red Star Over China (Speaker: Vincent Lee Kwun-leung) [Part 2]
Red Star Over China (Speaker: Vincent Lee Kwun-leung) [Part 2]
 
Topic 1 intro power and ideas
Topic 1 intro power and ideasTopic 1 intro power and ideas
Topic 1 intro power and ideas
 
Chapter3
Chapter3Chapter3
Chapter3
 
1948 Arab–Israeli
1948 Arab–Israeli1948 Arab–Israeli
1948 Arab–Israeli
 
Israeli-Palestinian Conflict
Israeli-Palestinian ConflictIsraeli-Palestinian Conflict
Israeli-Palestinian Conflict
 
Similarities
SimilaritiesSimilarities
Similarities
 
Poverty and Hunger Reduction – a new mix of growth and social protection poli...
Poverty and Hunger Reduction – a new mix of growth and social protection poli...Poverty and Hunger Reduction – a new mix of growth and social protection poli...
Poverty and Hunger Reduction – a new mix of growth and social protection poli...
 
Nuclear power
Nuclear powerNuclear power
Nuclear power
 
Lesson 3 fundamentalism
Lesson 3   fundamentalismLesson 3   fundamentalism
Lesson 3 fundamentalism
 
Chapter9
Chapter9Chapter9
Chapter9
 
Nuclear power plant
Nuclear power plantNuclear power plant
Nuclear power plant
 
Report on HISTORY OF MONEY IN CHINA
Report on HISTORY OF MONEY IN CHINAReport on HISTORY OF MONEY IN CHINA
Report on HISTORY OF MONEY IN CHINA
 

More from IPMAX s.r.l.

More from IPMAX s.r.l. (12)

Cisco Switch How To - Secure a Switch Port
Cisco Switch How To - Secure a Switch PortCisco Switch How To - Secure a Switch Port
Cisco Switch How To - Secure a Switch Port
 
Huawei ARG3 Router How To - Troubleshooting OSPF: Netmask mismatch
Huawei ARG3 Router How To - Troubleshooting OSPF: Netmask mismatchHuawei ARG3 Router How To - Troubleshooting OSPF: Netmask mismatch
Huawei ARG3 Router How To - Troubleshooting OSPF: Netmask mismatch
 
Huawei ARG3 Router How To - Troubleshooting OSPF: Router ID Confusion
Huawei ARG3 Router How To - Troubleshooting OSPF: Router ID ConfusionHuawei ARG3 Router How To - Troubleshooting OSPF: Router ID Confusion
Huawei ARG3 Router How To - Troubleshooting OSPF: Router ID Confusion
 
Huawei Switch S5700 How To - Configuring single-tag vlan mapping
Huawei Switch S5700  How To - Configuring single-tag vlan mappingHuawei Switch S5700  How To - Configuring single-tag vlan mapping
Huawei Switch S5700 How To - Configuring single-tag vlan mapping
 
Huawei SAN Storage How To - Configuring the i-SCSI Communication Protocol
Huawei SAN Storage How To - Configuring the i-SCSI Communication ProtocolHuawei SAN Storage How To - Configuring the i-SCSI Communication Protocol
Huawei SAN Storage How To - Configuring the i-SCSI Communication Protocol
 
Huawei SAN Storage How To - ISM management application setup
Huawei SAN Storage How To - ISM management application setupHuawei SAN Storage How To - ISM management application setup
Huawei SAN Storage How To - ISM management application setup
 
Huawei SAN Storage How To - Assigning Management IP Address
Huawei SAN Storage How To - Assigning Management IP AddressHuawei SAN Storage How To - Assigning Management IP Address
Huawei SAN Storage How To - Assigning Management IP Address
 
Huawei Switch How To - Configuring a basic DHCP server
Huawei Switch How To - Configuring a basic DHCP serverHuawei Switch How To - Configuring a basic DHCP server
Huawei Switch How To - Configuring a basic DHCP server
 
Fortigate Firewall How to - DLP
Fortigate Firewall How to - DLPFortigate Firewall How to - DLP
Fortigate Firewall How to - DLP
 
HUAWEI Switch HOW-TO - Configuring link aggregation in static LACP mode
HUAWEI Switch HOW-TO - Configuring link aggregation in static LACP modeHUAWEI Switch HOW-TO - Configuring link aggregation in static LACP mode
HUAWEI Switch HOW-TO - Configuring link aggregation in static LACP mode
 
FortiGate Firewall How-To: WEB Filtering
FortiGate Firewall How-To: WEB FilteringFortiGate Firewall How-To: WEB Filtering
FortiGate Firewall How-To: WEB Filtering
 
FortiGate Firewall HOW-TO - DMZ
FortiGate Firewall HOW-TO - DMZFortiGate Firewall HOW-TO - DMZ
FortiGate Firewall HOW-TO - DMZ
 

Recently uploaded

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 

Recently uploaded (20)

Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 

FortiGate Firewall HOW-TO - Online Services

  • 1. FORTIGATE FIREWALL HOW TO ONLINE SERVICES www.ipmax.it
  • 2. INTRODUCTION Now our firewall is connected to the Internet, so we could try to use this setup to set the system time and verify the subscription to the FortiGuard services. FortiGuard services allow the firewall to be up to date on its virus, spyware and vulnerability signatures. Web filtering lists are also updated through FortiGuard services. It’s important that you have a valid subscription to the FortiGuard services in order to get the above mentioned updates.
  • 3. NTP To configure system time by NTP go to the System > Status dashboard and click on "Change" in the System Time row. Configure the firewall to be an NTP client as shown in the following picture. In our example we use FortGuard NTP servers for time synchronization, but you could use your preferred ones. The time zone could also be modified as per your needs. The FortiGate unit could also be configured to be an NTP server. During the NTP server configuration, you can select one or more interfaces on which listen to NTP client association requests.
  • 4. FORTIGUARD SERVICES FortiGuard services configuration is very simple: you must subscribe them and register your FortiGate unit. The FortiGate firewall will connect to the FortiGuard services automatically, but your intervention is needed in order to verify that all subscribed services are reachable and the associated license is not expired. As you could see from the License Information dashboard widget (on the right), Active services are marked with a green check, expired ones are marked with a red cross and unreachable ones are marked with a gray cross.
  • 5. FORTIGUARD SERVICES TROUBLESHOOT Sometime may happen that your FortiGate firewall is not able to connect to the FortiGuard services onto the Internet. This situation has been shown in the previous slide when a service is marked with a gray cross. Because FortiGuard services require an Internet connection, you must verify that they are reachable: connect to the firewall CLI and execute a ping test ond/or a traceroute with the following commands. execute ping www.fortiguard.com execute traceroute www.fortiguard.com Sometimes there is a policy or a web filtering rule that blocks FortiGuard services, so verify that such configuration is not in place.
  • 6. FORTIGUARD SERVICES TROUBLESHOOT CONTINUED You can also view the FortiGuard connection status by going to System > Config > FortiGuard. At the end of this menu, you could also change the L4 port used by the FortiGuard services. This configuration is very important because sometimes the default port (port 53) is blocked by your ISP or inside your network (it’s the same port used by DNS!). The other available port to be used for the FortiGuard services is port 8888.
  • 7. MORE NEEDS? See hints on www.ipmax.it Or email us your questions to info_ipmax@ipmax.it
  • 8. IPMAX IPMAX is a Fortinet Partner in Italy. IPMAX is the ideal partner for companies seeking quality in products and services. IPMAX guarantees method and professionalism to support its customers in selecting technologies with the best quality / price ratio, in the design, installation, commissioning and operation. IPMAX srl Via Ponchielli, 4 20063 Cernusco sul Naviglio (MI) – Italy +39 02 9290 9171