Some of our Fortigates are located behind other firewalls and the only way for those Fortigates to reach the Internet is via a web proxy. We were able to configure Fortiguard to use the web proxy to reach FDN to pull AV,IPS etc auto updates. Is there a way to configure threat feeds to use a web proxy too? If the answer is yes, how is this configured?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Katoomba,
Thank you for reaching out. There are no proxy settings for threat feed config. The follow are all available options in threat feed config for single entry:
config system external-resource
edit "1"
set uuid 5e39a17e-9869-51ef-9ac4-bc0202c62a13
set status enable
set type category
set update-method feed
set category 0
set username ''
set password ENC 4Nk7HoxGM3Ge/vpXvdDgBVT7qceKK7azQNwpIr0ctpOtdIj+zpbYEWAKLX5lM1foeUNstHIHBXmG9rtGtYIW4WR9GL2hCvbWVAtty7hoRn2Y6ZQgIPt89ARWSGtV95NyD8h4V77g0paHVkhdfdEvb4q9t9Ts6/wlUCDXwSDVMLItWQku1QADxNOVe7L/itT31HtyIVlmMjY3dkVA
set comments ''
set resource ''
set user-agent ''
set server-identity-check none
set refresh-rate 5
set source-ip 0.0.0.0
set interface-select-method auto
next
end
Thank you,
saleha
Created on 11-01-2024 06:56 AM Edited on 11-01-2024 08:30 AM
Is there a way to get the Fortigate to use a web proxy for ALL of its access to web sites (not for firewall policy but for the Fortigate's own use)? You can configure Fortigates to access fortiguard (FDN) using a proxy. Shown below:
config system fortiguard
proxy-server-ip
proxy-server-port
proxy-username
proxy-password
end
Are you saying that you cannot configure a Fortigate to access web sites using a web proxy? How is a Fortigate supposed to access a threat feed if the only available way to access the threat feed is via direct network access?
Hi Katoomba,
Thank you for the reply. The FortiGate can be an internal firewall with no direct internet access however in this case it can be setup with a route to access the internet via another firewall or router either for specific destinations or in the case of default/last resort route. In this scenario the internal FortiGate would send the external traffic to the next device upstream. It would the the next device upstream that has the role to pass that traffic to the destination or next hop. What I meant previously is there is no option for proxy settings in the threat feed configuration unlike the Fortiguard config where we do have such a feature available:
Ref article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-updates-using-a-proxy-server/ta...
Thank you,
saleha
Hi Saleha,
i have the same problem with a FortiGate behind a Proxy Server. Autoupdate Tunneling is already configured but the thread feeds don't run.
Is there any other solution?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.