Would someone know the list of ip from the fortiguard network and also the ip that the fortigate register into the fortiguard network so i can create this route?Enter " get webfilter status" on the CLI to get a list of IP addresses for the FortiGuard servers -- though I bet this list changes from time to time and region to region. Fortigate needs to be connected to the outside network to be able to generate that list. (An nslookup on service.fortiguard.net appears to return some of these IP addresses, though.) Whether the fgt uses the same servers for registering is a good question. The actual service (for FortiGuard quires) is accessible via port 53 (same as DNS) or port 8888. If this is the same port you could always open a port on your existing firewall, allowing the fgt to communicate through it. (Somewhere in some of the FortiGuard troubleshooting guides it mentions being able to set an IP address for the Fortigate to use if it is not able to locate the FortiGuard servers via DNS.)
 
					
				
			
			
				NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Maybe the diagnose hints from Support can be helpful: https://forum.fortinet.com/FindPost/97283
livo
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.