FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ssteo
Staff
Staff
Article Id 317815
Description This article describes the FortiGuard IP address range.
Scope FortiGate.
Solution

FortiGuard IP address range can be found in the FortiGate Internet Service Database.

Login to FortiGate GUI -> Policy & Objects -> Internet Service Database and filter the keyword 'Fortiguard'.

 

fortiguard.png

 

Edit 'Fortinet-FortiGuard' -> View/Edit Entries and it will be possible to view the IP address/Port/Protocol that is used to communicate with the FortiGuard server.

 

view fortiguard.png

 

The same information can also be found in CLI with the below commands:

 

FG # diagnose internet-service id | grep Fortinet-FortiGuard
ID: 1245324 name: "Fortinet-FortiGuard"
ID: 1245454 name: "Fortinet-FortiGuard.Secure.DNS"
ID: 1245514 name: "Fortinet-FortiGuard.SOCaaS"

FG # diagnose internet-service id 1245324
Internet Service: 1245324(Fortinet-FortiGuard)
Version: 00007.04063
Timestamp: 202502191125
Number of Entries: 330
12.34.97.0-12.34.97.255 country(840) region(2039) city(1106) blocklist(0x0) reputation(5), popularity(5) domain(0) botnet(0) proto(6) port(25 53 80 443 465 514 541-542 853 2195-2196 5223 8000 8686 8888 8890 9582)
12.34.97.0-12.34.97.255 country(840) region(2039) city(1106) blocklist(0x0) reputation(5), popularity(5) domain(0) botnet(0) proto(17) port(53 5246 8888)