- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiGate: Unable to connect to FortiGuard servers (FortiGate - Router -FortiGate - Internet)
Hi Team,
I am having trouble with FortiGate connection to FortiGuard server with this error reflecting in the GUI:
"Unable to connect to FortiGuard servers"
Current topology is:
FortiGate (with Issue) ---- Router ---- Another FortiGate ---- Internet
I can ping below:
exec ping service.fortiguard.net
exec ping update.fortiguard.net
exec ping guard.fortinet.net
Diag Debug Rating:
2 Servers Listed and has F flags in it
Already changed between protocol 8888 and 53 (no 443 available in my FG)
Already enabled and disabled the anycast
Management VDOM is 'root'
Config:
config system fortiguard
set fortiguard-anycast disable
set protocol udp
set port 8888
set sdns-server-ip 208.91.112.220 <-
end
Anything else which I can try to make the server reachable?
Thanks!
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @heyyo ,
You have already tried to change to protocol tcp, right?
I assume that your license is still valid.
Which FOS version are you running?
Can you post the output of the following commands, please:
get system status | grep Version
diag debug rating
#change the port and/or the protocol on the system fortiguard configuration and save it (end)
diag debug rating 1 #<---leave this running for 20 seconds, then press 'q' to stop.
diag test application dnsproxy 2
diag test application dnsproxy 3
You can also try to add a second server IP on the fortiguard config:
config system fortiguard
set sdns-server-ip 208.91.112.220 194.69.172.53
end
Best regards,
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
Did you check on you frontal FG if it is blocking the traffic from your internal FG to internet?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may run below debug command to have an idea of the issue
diag debug reset
diag debug application update -1
diag debug enable
execute update-now
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Unable-to-connect-to-FortiGuard-serv...
Arnold Dimailig
TAC Engineer
