Description | This article explains how to add redundant FortiGuard anycast server IPs in scenarios where only a single server IP is configured on a FortiGate. |
Scope | FortiGate. |
Solution |
FortiGates running v7.4.7 or earlier that use FortiGuard Web Filtering services may experience limited redundancy when communicating with FortiGuard servers using the anycast method.
To detect and use a secondary redundant FortiGuard Anycast server IP, the urlfilter daemon must be manually restarted. This allows the FortiGate to learn additional FortiGuard server addresses and maintain redundancy in case of service interruptions.
Verification steps:
diagnose debug rating For FortiGates with their location set to the USA, the presence of only a single IP indicates that the unit has not yet discovered additional FortiGuard IP addresses
diagnose test application urlfilter 99 Expected output after the restart: When update-server-location is set to automatic under FortiGuard configurations for US customers, it resolves to the global Anycast IP along with the two US Anycast IPs.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.