| Description | This article describes how to handle a scenario where FortiGuard updates via a proxy server fail. |
| Scope | FortiGate. |
| Solution |
When FortiGate devices are configured to use a proxy server for FortiGuard updates, the behavior of the CONNECT request to the proxy may vary depending on DNS configuration. Understanding this behavior is important when configuring proxies that strictly enforce URL-based CONNECT requests.
Behavior Overview.
FortiGate typically resolves the domain names of FortiGuard (FDN) servers locally before establishing a connection. As a result, the CONNECT request sent to the proxy may contain the resolved IP address of the FortiGuard server instead of the domain name.
If the proxy is configured to accept only URL-based CONNECT requests (i.e., containing hostnames), it may reject these IP-based requests. This is expected behavior based on how FortiGate handles DNS resolution for update services.
Configuration Guidance.
To ensure FortiGate can successfully communicate with FortiGuard servers through a proxy, consider the following options:
Note: Removing DNS settings from FortiGate should be done during off-production hours, as it may affect other services on the firewall that rely on DNS resolution. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.