Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlexFerenX
New Contributor

What's "FDNI"?

There a multiple references to "FDNI" acronym (seemingly, referring to FortiGuard Distribution Network servers), but I cannot find exact expansion. Once and for all, what's "FDNI"?

19 REPLIES 19
AlexFerenX

@xshkurti 

> When you configure Fortiguard servers, ...

 

Unless I configure FortiManager as local FDS, I never configure (Public) "Fortiguard servers" ... Fortigate just knows them based on my "update-server-location" preference.

 

> .. One of those services is a list of servers that will provide you some rating values for specific websites.

:

> FDNI is not some list that you specify somewhere, is a list of servers that FortiGuard will provide you ...

 

(Again) how does Fortigate obtain the list of (available Public FDN) servers? Perchance, retrieved from querying update.fortiguard.net?

xshkurti

Fortigate will retreive that list from FortiGuard services. No other way.

AlexFerenX

@xshkurti 

> Fortigate will retreive that list from FortiGuard services.

 

Of those specified in Anycast and unicast services, which?

xshkurti

We dont have visibility in backend servers so can not give an answer about that section. There are servers that respond in anycast and there are servers that respond in unicast traffic.
You can do some packet capture to find that out.

AlexFerenX

In Troubleshooting Tip: Unable to connect to FortiGuard servers can see "FortiGuard Server List requests to FortiGuard – 1027 UDP / 1031 UDP." but not associated destination FQDN - it would be great to know what it is.

 

Neither UDP/1027 nor UDP/1031 are mentioned Outgoing Ports - is that a mistake or an omission?

AlexFerenX

@xshkurti  That's ancient - who can rely on that?

xshkurti

Port number list containing 65535 different ports is even older, but it hasn't changed for 50 years :)
BTW, that doc is updated in 2021.

AlexFerenX

@xshkurti(As Fortinet-er) can you confirm current utilisation of UDP/1027 and UDP/1031?

 

xshkurti

I can confirm that this port list is accurate:
Traffic Types and TCP/UDP Ports used by F... - Fortinet Community
And that different servers use different ports for different reasons. One of them might be as redundant if some ports are blocked by ISP.
In your Fortigate you can do some traffic capture to see which port is your device using.

Labels
Top Kudoed Authors