Skip to main content
ymasaki
Staff
Staff
March 27, 2020

Technical Tip: Change FortiGuard server port for URL rating

  • March 27, 2020
  • 0 replies
  • 5006 views

Description

 

This article describes how to change the FortiGuard server port for URL rating.

FortiClient sends web filter URL rating requests to the FortiGuard server on UDP/8888 by default.
Sometimes ISP blocks UDP/8888 and this port can be changed to UDP/53 via the XML config file.

Solution

 

To change the port via FortiClient XML config file directly.

 

  1. Go to Settings -> System and select 'Backup' to export the XML config file.


 
  1. Open the XML config file with the text editor and add <url>fgd1.fortigate.com:53</url> in the location below.

    <categories>
           <fortiguard>
           <enabled>1</enabled>
           <url>fgd1.fortigate.com:53</url>
           <rate_ip_addresses>1</rate_ip_addresses>

  2. Restore the XML config file.
 
 
 
Change the port via the FortiClient XML config file from EMS.
 
  1. Go to Endpoint Profiles -> Web Filter Profile -> 'Your Profile' (In this example, the EMS Console version is 7.2.4).
  2. Enable the Advanced setting and go to XML Configuration to add <url>fgd1.fortigate.com:53</url> in the location below.
 
webfilter_ems.png

 

If the URL rating issue is present, modify:
 
EMS 00.png

 

Once the port is changed to UDP/53, FortiClient starts sending URL requests to the FortiGuard server on UDP/53.
In Wireshark, the packet entry appears like the following.
 
 
Related documents:
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!