Hi all,
I hope you're well.
I am installing 4 x 120G FortiGates into a DC, but these firewalls will not be on the edge therefore no direct internet access. Another layer of firewalls is in front, I need to create an explicit list of IPs, domains, services etc to provide to the individuals who currently manage them to ensure the FortiGates has access to required services for NGFW features.
I am currently building a policy on a lab firewall with what I know and can see is required but is there an explicit list available so I can ensure everything is covered?
Thanks,
Dan.
Solved! Go to Solution.
I think you can get it just by combining between these two tables.
FortiGuard
| AV/IPS update | TCP/443, TCP/8890 |
Cloud Application Database | TCP/9582 | |
FortiGuard Queries | UDP/53, UDP/8888 | |
TCP/53, TCP/443, TCP/8888 | ||
DNS | UDP/53, UDP/8888 | |
Registration | TCP/443 | |
Alert Email, Virus sample | TCP/25 | |
Management, Firmware, SMS, Licensing, Policy Override | TCP/443 | |
Central Management, Analysis | TCP/541 | |
IPv4 FGFM tunnel | TCP/541 | |
IPv6 FGFM tunnel | TCP/542 | |
Secure DNS filter | TCP/53, TCP/853 | |
IPAM Service | TCP/443 | |
IoT Service | TCP/443 | |
FortiDDNS | TCP/443 | |
FortiGuard persistent connection for updates (2U and VM models only) | TCP/443 |
Service Non-Anycast FQDN addresses Anycast Domain name
| FortiGuard Object download | update.fortiguard.net | globalupdate.fortinet.net |
| Querying service (web-filtering, anti-spam ratings) over HTTPS | securewf.fortiguard.net | globalguardservice.fortinet.net |
| Querying service (web-filtering, anti-spam ratings) over UDP | service.fortiguard.net | Service only in Unicast |
| Device info Collection | Service only in Anycast | globaldevcollect.fortinet.net |
| Device info Query | Service only in Anycast | globaldevquery.fortinet.net |
| FortiGate Cloud logging | logctrl1.fortinet.com | globallogctrl.fortinet.net |
| FortiGate Cloud management | mgrctrl1.fortinet.com | globalmgrctrl.fortinet.net |
| FortiGate Cloud messaging | msgctrl1.fortinet.com | globalmsgctrl.fortinet.net |
| FortiGate Cloud sandbox | aptctrl1.fortinet.com | globalaptctrl.fortinet.net |
| GUI icon download | productapi.fortinet.net | globalproductapi.fortinet.net |
| FortiCare registration | directregistration.fortinet.com | globalregistration.fortinet.net |
| Secure DNS | sdns.fortinet.net | globalsdns.fortinet.net |
| FortiCloud FortiClient | forticlient.fortinet.net | globalfctupdate.fortinet.net |
| FortiMobile Tokens | directregistration.fortinet.com | globalftm.fortinet.net |
| EMS cloud | forticlient-emsproxy.forticloud.com | forticlient-emsproxy.forticloud.com |
| DDNS | ddns.fortinet.net | globalddns.fortinet.net |
| GeoIP | gip.fortinet.net | globalgip.fortinet.net |
Ref:
https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/160067/outgoing-ports
https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/622145/anycast-and-unicast-services
Hope it helps.
I think you can get it just by combining between these two tables.
FortiGuard
| AV/IPS update | TCP/443, TCP/8890 |
Cloud Application Database | TCP/9582 | |
FortiGuard Queries | UDP/53, UDP/8888 | |
TCP/53, TCP/443, TCP/8888 | ||
DNS | UDP/53, UDP/8888 | |
Registration | TCP/443 | |
Alert Email, Virus sample | TCP/25 | |
Management, Firmware, SMS, Licensing, Policy Override | TCP/443 | |
Central Management, Analysis | TCP/541 | |
IPv4 FGFM tunnel | TCP/541 | |
IPv6 FGFM tunnel | TCP/542 | |
Secure DNS filter | TCP/53, TCP/853 | |
IPAM Service | TCP/443 | |
IoT Service | TCP/443 | |
FortiDDNS | TCP/443 | |
FortiGuard persistent connection for updates (2U and VM models only) | TCP/443 |
Service Non-Anycast FQDN addresses Anycast Domain name
| FortiGuard Object download | update.fortiguard.net | globalupdate.fortinet.net |
| Querying service (web-filtering, anti-spam ratings) over HTTPS | securewf.fortiguard.net | globalguardservice.fortinet.net |
| Querying service (web-filtering, anti-spam ratings) over UDP | service.fortiguard.net | Service only in Unicast |
| Device info Collection | Service only in Anycast | globaldevcollect.fortinet.net |
| Device info Query | Service only in Anycast | globaldevquery.fortinet.net |
| FortiGate Cloud logging | logctrl1.fortinet.com | globallogctrl.fortinet.net |
| FortiGate Cloud management | mgrctrl1.fortinet.com | globalmgrctrl.fortinet.net |
| FortiGate Cloud messaging | msgctrl1.fortinet.com | globalmsgctrl.fortinet.net |
| FortiGate Cloud sandbox | aptctrl1.fortinet.com | globalaptctrl.fortinet.net |
| GUI icon download | productapi.fortinet.net | globalproductapi.fortinet.net |
| FortiCare registration | directregistration.fortinet.com | globalregistration.fortinet.net |
| Secure DNS | sdns.fortinet.net | globalsdns.fortinet.net |
| FortiCloud FortiClient | forticlient.fortinet.net | globalfctupdate.fortinet.net |
| FortiMobile Tokens | directregistration.fortinet.com | globalftm.fortinet.net |
| EMS cloud | forticlient-emsproxy.forticloud.com | forticlient-emsproxy.forticloud.com |
| DDNS | ddns.fortinet.net | globalddns.fortinet.net |
| GeoIP | gip.fortinet.net | globalgip.fortinet.net |
Ref:
https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/160067/outgoing-ports
https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/622145/anycast-and-unicast-services
Hope it helps.
| User | Count |
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.