Fortinet Fortigate-5000 series Administration Manual page 169

Hide thumbs Also See for Fortigate-5000 series:
Table of Contents

Advertisement

System Maintenance
FortiGate Version 3.0 MR4 Administration Guide
01-30004-0203-20070102
Push updates when FortiGate IP addresses change
The SETUP message that the FortiGate unit sends when you enable push
updates includes the IP address of the FortiGate interface to which the FDN
connects. The interface used for push updates is the interface configured in the
default route of the static routing table.
The FortiGate unit sends the SETUP message if you change the IP address of
this interface manually or if you have set the interface addressing mode to DHCP
or PPPoE and your DHCP or PPPoE server changes the IP address.
The FDN must be able to connect to this IP address for your FortiGate unit to be
able to receive push update messages. If your FortiGate unit is behind a NAT
device, see
"Enabling push updates through a NAT device" on page
If you have redundant connections to the Internet, the FortiGate unit also sends
the SETUP message when one Internet connection goes down and the FortiGate
unit fails over to the other Internet connection.
In Transparent mode if you change the management IP address, the FortiGate
unit also sends the SETUP message to notify the FDN of the address change.
Enabling push updates through a NAT device
If the FDN can only connect to the FortiGate unit through a NAT device, you must
configure port forwarding on the NAT device and add the port forwarding
information to the push update configuration. Using port forwarding, the FDN
connects to the FortiGate unit using UDP on either port 9443 or an override push
port that you specify.
Note: You cannot receive push updates through a NAT device if the external IP address of
the NAT device is dynamic (for example, set using PPPoE or DHCP).
FortiGuard Center
169.
169

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents