Skip to main content
BensonLEI
New Member
November 18, 2020
Solved

Can not access Fortiguard severs ( for device registration )

  • November 18, 2020
  • 1 reply
  • 6225 views

Can not access Fortiguard severs

Hi, guys,   My Forti600E can not access Fortiguard servers ( for device registration, any Fortinet services), network infrastructure is:   The Forti600E has few network links : 1. The device is using Fortinet DNS services : 208.91.112.53 & 208.91.112.52 2. The default route (0.0.0.0/0.0.0.0) can point to internal network. 3. The route table to Fortinet DNS services are implicitly defined, as the following route table:   Forti600E-01 # get router info routing-table all Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP            O - OSPF, IA - OSPF inter area            N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2            E1 - OSPF external type 1, E2 - OSPF external type 2            i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area           * - candidate default   Routing table for VRF=0 S*    0.0.0.0/0 [10/0] via 10.0.0.250, port2 C      10.0.0.248/30 is directly connected, port2 C      10.10.32.88/29 is directly connected, LL_10M C      10.86.2.0/29 is directly connected, LeaseLine C      10.101.1.0/24 is directly connected, mgmt C      10.102.2.0/30 is directly connected, EXT_Zone C      10.102.2.4/30 is directly connected, INT_Zone S      10.131.1.23/32 [10/0] via 10.102.2.6, INT_Zone S      10.171.4.127/32 [10/0] via 10.101.1.254, mgmt                                  [10/0] via 10.101.2.254, mgmt C      100.100.100.100/32 is directly connected, port2 C      200.200.200.0/24 is directly connected, port2 S      208.91.112.52/32 [10/0] via 10.101.1.254, mgmt S      208.91.112.53/32 [10/0] via 10.101.1.254, mgmt Forti600E-01 #               Tested result: Forti600E-01 # get system dns primary : 208.91.112.53 secondary : 208.91.112.52 dns-over-tls : disable ssl-certificate : Fortinet_Factory domain : ip6-primary : :: ip6-secondary : :: timeout : 5 retry : 2 dns-cache-limit : 5000 dns-cache-ttl : 1800 cache-notfound-responses: disable source-ip : 0.0.0.0 interface-select-method: auto Forti600E-01 #     Forti600E-01 # exe ping 208.91.112.52 PING 208.91.112.52 (208.91.112.52): 56 data bytes 64 bytes from 208.91.112.52: icmp_seq=0 ttl=49 time=233.8 ms 64 bytes from 208.91.112.52: icmp_seq=1 ttl=49 time=233.7 ms 64 bytes from 208.91.112.52: icmp_seq=2 ttl=49 time=233.7 ms 64 bytes from 208.91.112.52: icmp_seq=3 ttl=49 time=233.8 ms 64 bytes from 208.91.112.52: icmp_seq=4 ttl=49 time=233.8 ms --- 208.91.112.52 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 233.7/233.7/233.8 ms   Forti600E-01 # exe ping 208.91.112.53 PING 208.91.112.53 (208.91.112.53): 56 data bytes 64 bytes from 208.91.112.53: icmp_seq=0 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=1 ttl=49 time=237.2 ms 64 bytes from 208.91.112.53: icmp_seq=2 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=3 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=4 ttl=49 time=237.3 ms --- 208.91.112.53 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 237.2/237.2/237.3 ms Forti600E-01 #     But the Forti600E can not connect to FortiGuard servers (WAN IP is unknown), as the attached, and recommendation ?   Many thanks in advance.  

    Best answer by boneyard

    For FortiGuard you need more then just those DNS server, see which hostnames (and thus IPs) are required

     

    https://docs.fortinet.com...cols/649403/fortiguard

    1 reply

    boneyard
    boneyardAnswer
    Valued Contributor
    November 18, 2020

    For FortiGuard you need more then just those DNS server, see which hostnames (and thus IPs) are required

     

    https://docs.fortinet.com...cols/649403/fortiguard

    BensonLEI
    BensonLEIAuthor
    New Member
    November 19, 2020

    Hi, Boneyard,

     

    Thanks so much for your useful link.

     

    If the default route is not routed/pointed to ISP lines, and I have defined/routed the dedicated Fortiguard services via the mgmt network link for internet traffic ( for example, 10.101.1.254 ); and the tested results as below:

     

     

    Forti600E-01 # get router info routing-table all ........... S* 0.0.0.0/0 [10/0] via 10.0.0.250, port2 S 63.137.229.1/32 [10/0] via 10.101.1.254, mgmt S 96.45.33.86/32 [10/0] via 10.101.1.254, mgmt S 208.91.112.52/32 [10/0] via 10.101.1.254, mgmt S 208.91.112.53/32 [10/0] via 10.101.1.254, mgmt S 209.222.147.36/32 [10/0] via 10.101.1.254, mgmt

     

     

    Forti600E-01 # exe ping service.fortiguard.net PING guard.fortinet.net (209.222.147.36): 56 data bytes

    Forti600E-01 # exe ping update.fortiguard.net PING fds1.fortinet.com (96.45.33.86): 56 data bytes

    Forti600E-01 # exe ping support.fortinet.com PING support.fortinet.com (63.137.229.1): 56 data bytes

    Forti600E-01 # exe ping 208.91.112.52 PING 208.91.112.52 (208.91.112.52): 56 data bytes 64 bytes from 208.91.112.52: icmp_seq=0 ttl=49 time=233.9 ms 64 bytes from 208.91.112.52: icmp_seq=1 ttl=49 time=233.8 ms ....

    --- 208.91.112.52 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 233.8/233.8/233.9 ms

    Forti600E-01 # exe ping 208.91.112.53 PING 208.91.112.53 (208.91.112.53): 56 data bytes 64 bytes from 208.91.112.53: icmp_seq=0 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=1 ttl=49 time=237.3 ms ....

    --- 208.91.112.53 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 237.2/237.2/237.3 ms

    Forti600E-01 # exe ping 209.222.147.36 PING 209.222.147.36 (209.222.147.36): 56 data bytes

    --- 209.222.147.36 ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss

    Forti600E-01 # exe ping 96.45.33.86 PING 96.45.33.86 (96.45.33.86): 56 data bytes 64 bytes from 96.45.33.86: icmp_seq=0 ttl=51 time=127.6 ms 64 bytes from 96.45.33.86: icmp_seq=1 ttl=51 time=127.6 ms .....

    --- 96.45.33.86 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 127.5/127.7/128.4 ms

     

    Forti600E-01 # exe ping 63.137.229.1 PING 63.137.229.1 (63.137.229.1): 56 data bytes

    --- 63.137.229.1 ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss

    Forti600E-01 #

     

     

    The same problem, I can not register the Forti600E, any advice.

     

     

    Thanks a lot

    boneyard
    Valued Contributor
    November 19, 2020

    the route via mgmt doesn't filter anything right? it is full internet access?

     

    there two articles are useful to go through, specially the debug in the last one. it might show which extra IPs are needed or fail now.

     

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD30088

     

    https://kb.fortinet.com/kb/viewContent.do?externalId=FD32121

     

       # diag debug enable    # diag debug application update 255    # exec update-now