Skip to main content
Saba1989
New Member
July 8, 2018
Question

set source-ip

  • July 8, 2018
  • 3 replies
  • 10555 views

hi guys i had a serious problem with my firewall i have a 500D fortigate and it takes place in one data center, because of data center's policies ,wan interfaces of fortigate have private IP and they do not have public ip and the addreses of them are 192.168.23.74 and 192.168.23.78. this fortigate has 2 vdom (root and data). when i check fortiguard service i realize IPS and AV can not being update. the seller company configured license by (system autoupdate tunneling) in global and said to me i should set public ip on wan interface but i shouldn't change it as data center's policy

i configure this in global:

"

config system fortiguard set port 8888 set source-ip 192.168.23.74 end

"

but i don't see any change. what should i do? is my configure wrong?

 

 

    3 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    July 9, 2018

    I never changed the default setting for FortiGuard at my FG30E, means it's using the default values like port = 8888 and source-ip = 0.0.0.0 because it's sitting behind another FGT, which is doing NAT.  But it's working fine communicating with GortiGuard.

    Then, something else is causing not to be able to reach FortiGuard. Check the license information, like it's registered, and support&license is not expired, etc.  

    rdumitrescu
    New Member
    July 9, 2018
    I see that you are using vdoms. Make sure that the management vdom (by default root) can reach the Fortiguard servers
    sw2090
    SuperUser
    SuperUser
    July 18, 2018

    zeynab: did you check your routes on your FGT? You either have to have a default route via the Loadbalancer (if you use it) or at least one default route over one wan interface.

    Also you have to be sure that there is a gateway in the subnet(s) the wan ports are in that can get you into the internet.

    If you don't have a default route at all your FGT cannot connect to Fortinet Services at the internet.

     

    hth

    Sebastian

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!