Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dan_Eng52
Contributor II

FortiGuard Services List

Hi all, 

 

I hope you're well. 

 

I am installing 4 x 120G FortiGates into a DC, but these firewalls will not be on the edge therefore no direct internet access. Another layer of firewalls is in front, I need to create an explicit list of IPs, domains, services etc to provide to the individuals who currently manage them to ensure the FortiGates has access to required services for NGFW features.   

 

I am currently building a policy on a lab firewall with what I know and can see is required but is there an explicit list available so I can ensure everything is covered? 

Thanks, 

Dan. 

1 Solution
AEK
SuperUser
SuperUser

I think you can get it just by combining between these two tables.

 

FortiGuard

 

AV/IPS update

TCP/443, TCP/8890

Cloud Application Database

TCP/9582

FortiGuard Queries

UDP/53, UDP/8888

TCP/53, TCP/443, TCP/8888

DNS

UDP/53, UDP/8888

Registration

TCP/443

Alert Email, Virus sample

TCP/25

Management, Firmware, SMS, Licensing, Policy Override

TCP/443

Central Management, Analysis

TCP/541

IPv4 FGFM tunnel

TCP/541

IPv6 FGFM tunnel

TCP/542

Secure DNS filter

TCP/53, TCP/853

IPAM Service

TCP/443

IoT Service

TCP/443

FortiDDNS

TCP/443

FortiGuard persistent connection for updates (2U and VM models only)

TCP/443

 

 

Service Non-Anycast FQDN addresses Anycast Domain name

FortiGuard Object downloadupdate.fortiguard.netglobalupdate.fortinet.net
Querying service (web-filtering, anti-spam ratings) over HTTPSsecurewf.fortiguard.netglobalguardservice.fortinet.net
Querying service (web-filtering, anti-spam ratings) over UDPservice.fortiguard.netService only in Unicast
Device info CollectionService only in Anycastglobaldevcollect.fortinet.net
Device info QueryService only in Anycastglobaldevquery.fortinet.net
FortiGate Cloud logginglogctrl1.fortinet.comgloballogctrl.fortinet.net
FortiGate Cloud managementmgrctrl1.fortinet.comglobalmgrctrl.fortinet.net
FortiGate Cloud messagingmsgctrl1.fortinet.comglobalmsgctrl.fortinet.net
FortiGate Cloud sandboxaptctrl1.fortinet.comglobalaptctrl.fortinet.net
GUI icon downloadproductapi.fortinet.netglobalproductapi.fortinet.net
FortiCare registrationdirectregistration.fortinet.comglobalregistration.fortinet.net
Secure DNSsdns.fortinet.netglobalsdns.fortinet.net
FortiCloud FortiClientforticlient.fortinet.netglobalfctupdate.fortinet.net
FortiMobile Tokensdirectregistration.fortinet.comglobalftm.fortinet.net
EMS cloudforticlient-emsproxy.forticloud.comforticlient-emsproxy.forticloud.com
DDNSddns.fortinet.netglobalddns.fortinet.net
GeoIPgip.fortinet.netglobalgip.fortinet.net

 

Ref:

https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/160067/outgoing-ports

https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/622145/anycast-and-unicast-services

Hope it helps.

AEK

View solution in original post

AEK
1 REPLY 1
AEK
SuperUser
SuperUser

I think you can get it just by combining between these two tables.

 

FortiGuard

 

AV/IPS update

TCP/443, TCP/8890

Cloud Application Database

TCP/9582

FortiGuard Queries

UDP/53, UDP/8888

TCP/53, TCP/443, TCP/8888

DNS

UDP/53, UDP/8888

Registration

TCP/443

Alert Email, Virus sample

TCP/25

Management, Firmware, SMS, Licensing, Policy Override

TCP/443

Central Management, Analysis

TCP/541

IPv4 FGFM tunnel

TCP/541

IPv6 FGFM tunnel

TCP/542

Secure DNS filter

TCP/53, TCP/853

IPAM Service

TCP/443

IoT Service

TCP/443

FortiDDNS

TCP/443

FortiGuard persistent connection for updates (2U and VM models only)

TCP/443

 

 

Service Non-Anycast FQDN addresses Anycast Domain name

FortiGuard Object downloadupdate.fortiguard.netglobalupdate.fortinet.net
Querying service (web-filtering, anti-spam ratings) over HTTPSsecurewf.fortiguard.netglobalguardservice.fortinet.net
Querying service (web-filtering, anti-spam ratings) over UDPservice.fortiguard.netService only in Unicast
Device info CollectionService only in Anycastglobaldevcollect.fortinet.net
Device info QueryService only in Anycastglobaldevquery.fortinet.net
FortiGate Cloud logginglogctrl1.fortinet.comgloballogctrl.fortinet.net
FortiGate Cloud managementmgrctrl1.fortinet.comglobalmgrctrl.fortinet.net
FortiGate Cloud messagingmsgctrl1.fortinet.comglobalmsgctrl.fortinet.net
FortiGate Cloud sandboxaptctrl1.fortinet.comglobalaptctrl.fortinet.net
GUI icon downloadproductapi.fortinet.netglobalproductapi.fortinet.net
FortiCare registrationdirectregistration.fortinet.comglobalregistration.fortinet.net
Secure DNSsdns.fortinet.netglobalsdns.fortinet.net
FortiCloud FortiClientforticlient.fortinet.netglobalfctupdate.fortinet.net
FortiMobile Tokensdirectregistration.fortinet.comglobalftm.fortinet.net
EMS cloudforticlient-emsproxy.forticloud.comforticlient-emsproxy.forticloud.com
DDNSddns.fortinet.netglobalddns.fortinet.net
GeoIPgip.fortinet.netglobalgip.fortinet.net

 

Ref:

https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/160067/outgoing-ports

https://docs.fortinet.com/document/fortigate/7.6.0/fortios-ports/622145/anycast-and-unicast-services

Hope it helps.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors