Skip to main content
kelv1n
New Member
March 9, 2015
Question

Configuring Fortigates to get Fortiguard update from FMG? how?

  • March 9, 2015
  • 17 replies
  • 26456 views

Hi

 

We're running Fortigates with v5.2.x and FMG 5.2.1.

 

How do you tell a fortigate to check FMG for Fortiguard updates before going to the proper Fortiguard Service Service?

 

The fortiOS manual say

config system central-management
 set fortimanager-fds-sigupdate-override enable
 set sig-update-server-1 10.10.10.10
 set sig-update-server-2 20.20.20.20
 set sig-update-server-3 30.30.30.30
end

 

But none of these commands actually exist in the CLI.

 

I've seen other websites stating run "set fortimanager-fds-override enable" but this doesn't exist anymore.

 

    17 replies

    AndreaSoliva
    New Member
    March 9, 2015

    Hi

     

    even I have to say I do not work with 5.2 at the moment because it is too buggy for me I would say following:

     

    config system central-management set mode normal set type fortimanager set fmg "3.3.3.3" #set fmg-source-ip 0.0.0.0 set schedule-config-restore enable set schedule-script-restore enable set allow-push-configuration enable set allow-pushd-firmware enable set allow-remote-firmware-upgrade enable set allow-monitor enable #set serial-number set vdom root set enc-algorithm default config server-list edit 1 set server-type upate server-address 0.0.0.0 end end

     

    The config which points the FGT to FMG is the "config server list". Again I'm not sure but it is visible in this way for me. There is also a addtional command which should be probably disable which means:

     

    include-default-servers {enable | disable}  Enable or disable inclusion of public FortiGuard servers in the override server list.

     

    Because this command enables default FortiGuard server etc. I would recommend to disable the stuff because you do not want to use FortiGuard.

     

    Hope this helps

     

    have fun

     

    Andrea

    Anne
    New Member
    February 29, 2016

    Hi there,

     

    I have the exact same config and the Fortimanager is not pushing the updates to the Fortigates

    scao_FTNT
    Staff
    Staff
    February 29, 2016

    have you enabled service access on FMG interface?

     

    FMG-VM64 # conf sys interface (interface)# ed port1 (port1)# set serviceaccess  fclupdates            FortiClient updates access.  fgtupdates            FortiGate updates access.  webfilter-antispam    Web filtering and antispam access.

     

    Thanks

     

    Simon

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!