Created on
07-20-2021
10:40 PM
Edited on
08-29-2024
04:25 AM
By
Stephen_G
Description
This article describes how the 'Server Override Mode Strict' option for FortiGuard Proxy can change upon upgrade.
Scope
An upgraded FortiManager from 6.0 (or below) to 6.2 (or above).
Solution
The FortiManager-FortiGuard feature which uses the web proxy to reach the public FortiGuard server cannot work anymore if 'Server Override Mode' is set to Strict upon upgrading to 6.2 (or above).
Contest.
Sometimes, the customer needs to upgrade to 6.2 or above from FortiManager version 6.0 or below.
If the FortiGuard feature was using a web proxy to access to public FortiGuard server and 'Server Override Mode' was set to strict, FortiManager may no longer be able to reach FortiGuard via web proxy.
As a consequence, FortiGates requiring IPS/AV updates will not get any more recent package updates.
Normally, the customer has a FortiGuard configuration on FortiManager like below:
config fmupdate server-override-status
set mode strict
end
config fmupdate av-ips web-proxy
set address "1.2.3.4"
set port 8080
set status enable
set username "proxy_user"
end
Related articles:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.