Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BensonLEI
Contributor

Can not access Fortiguard severs ( for device registration )

Can not access Fortiguard severs

Hi, guys,   My Forti600E can not access Fortiguard servers ( for device registration, any Fortinet services), network infrastructure is:   The Forti600E has few network links : 1. The device is using Fortinet DNS services : 208.91.112.53 & 208.91.112.52 2. The default route (0.0.0.0/0.0.0.0) can point to internal network. 3. The route table to Fortinet DNS services are implicitly defined, as the following route table:   Forti600E-01 # get router info routing-table all Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP            O - OSPF, IA - OSPF inter area            N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2            E1 - OSPF external type 1, E2 - OSPF external type 2            i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area           * - candidate default   Routing table for VRF=0 S*    0.0.0.0/0 [10/0] via 10.0.0.250, port2 C      10.0.0.248/30 is directly connected, port2 C      10.10.32.88/29 is directly connected, LL_10M C      10.86.2.0/29 is directly connected, LeaseLine C      10.101.1.0/24 is directly connected, mgmt C      10.102.2.0/30 is directly connected, EXT_Zone C      10.102.2.4/30 is directly connected, INT_Zone S      10.131.1.23/32 [10/0] via 10.102.2.6, INT_Zone S      10.171.4.127/32 [10/0] via 10.101.1.254, mgmt                                  [10/0] via 10.101.2.254, mgmt C      100.100.100.100/32 is directly connected, port2 C      200.200.200.0/24 is directly connected, port2 S      208.91.112.52/32 [10/0] via 10.101.1.254, mgmt S      208.91.112.53/32 [10/0] via 10.101.1.254, mgmt Forti600E-01 #               Tested result: Forti600E-01 # get system dns primary : 208.91.112.53 secondary : 208.91.112.52 dns-over-tls : disable ssl-certificate : Fortinet_Factory domain : ip6-primary : :: ip6-secondary : :: timeout : 5 retry : 2 dns-cache-limit : 5000 dns-cache-ttl : 1800 cache-notfound-responses: disable source-ip : 0.0.0.0 interface-select-method: auto Forti600E-01 #     Forti600E-01 # exe ping 208.91.112.52 PING 208.91.112.52 (208.91.112.52): 56 data bytes 64 bytes from 208.91.112.52: icmp_seq=0 ttl=49 time=233.8 ms 64 bytes from 208.91.112.52: icmp_seq=1 ttl=49 time=233.7 ms 64 bytes from 208.91.112.52: icmp_seq=2 ttl=49 time=233.7 ms 64 bytes from 208.91.112.52: icmp_seq=3 ttl=49 time=233.8 ms 64 bytes from 208.91.112.52: icmp_seq=4 ttl=49 time=233.8 ms --- 208.91.112.52 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 233.7/233.7/233.8 ms   Forti600E-01 # exe ping 208.91.112.53 PING 208.91.112.53 (208.91.112.53): 56 data bytes 64 bytes from 208.91.112.53: icmp_seq=0 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=1 ttl=49 time=237.2 ms 64 bytes from 208.91.112.53: icmp_seq=2 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=3 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=4 ttl=49 time=237.3 ms --- 208.91.112.53 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 237.2/237.2/237.3 ms Forti600E-01 #     But the Forti600E can not connect to FortiGuard servers (WAN IP is unknown), as the attached, and recommendation ?   Many thanks in advance.  

2 Solutions
boneyard
Valued Contributor

For FortiGuard you need more then just those DNS server, see which hostnames (and thus IPs) are required

 

https://docs.fortinet.com...cols/649403/fortiguard

View solution in original post

boneyard
Valued Contributor

the route via mgmt doesn't filter anything right? it is full internet access?

 

there two articles are useful to go through, specially the debug in the last one. it might show which extra IPs are needed or fail now.

 

https://kb.fortinet.com/kb/documentLink.do?externalID=FD30088

 

https://kb.fortinet.com/kb/viewContent.do?externalId=FD32121

 

   # diag debug enable    # diag debug application update 255    # exec update-now

View solution in original post

4 REPLIES 4
boneyard
Valued Contributor

For FortiGuard you need more then just those DNS server, see which hostnames (and thus IPs) are required

 

https://docs.fortinet.com...cols/649403/fortiguard

BensonLEI

Hi, Boneyard,

 

Thanks so much for your useful link.

 

If the default route is not routed/pointed to ISP lines, and I have defined/routed the dedicated Fortiguard services via the mgmt network link for internet traffic ( for example, 10.101.1.254 ); and the tested results as below:

 

 

Forti600E-01 # get router info routing-table all ........... S* 0.0.0.0/0 [10/0] via 10.0.0.250, port2 S 63.137.229.1/32 [10/0] via 10.101.1.254, mgmt S 96.45.33.86/32 [10/0] via 10.101.1.254, mgmt S 208.91.112.52/32 [10/0] via 10.101.1.254, mgmt S 208.91.112.53/32 [10/0] via 10.101.1.254, mgmt S 209.222.147.36/32 [10/0] via 10.101.1.254, mgmt

 

 

Forti600E-01 # exe ping service.fortiguard.net PING guard.fortinet.net (209.222.147.36): 56 data bytes

Forti600E-01 # exe ping update.fortiguard.net PING fds1.fortinet.com (96.45.33.86): 56 data bytes

Forti600E-01 # exe ping support.fortinet.com PING support.fortinet.com (63.137.229.1): 56 data bytes

Forti600E-01 # exe ping 208.91.112.52 PING 208.91.112.52 (208.91.112.52): 56 data bytes 64 bytes from 208.91.112.52: icmp_seq=0 ttl=49 time=233.9 ms 64 bytes from 208.91.112.52: icmp_seq=1 ttl=49 time=233.8 ms ....

--- 208.91.112.52 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 233.8/233.8/233.9 ms

Forti600E-01 # exe ping 208.91.112.53 PING 208.91.112.53 (208.91.112.53): 56 data bytes 64 bytes from 208.91.112.53: icmp_seq=0 ttl=49 time=237.3 ms 64 bytes from 208.91.112.53: icmp_seq=1 ttl=49 time=237.3 ms ....

--- 208.91.112.53 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 237.2/237.2/237.3 ms

Forti600E-01 # exe ping 209.222.147.36 PING 209.222.147.36 (209.222.147.36): 56 data bytes

--- 209.222.147.36 ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss

Forti600E-01 # exe ping 96.45.33.86 PING 96.45.33.86 (96.45.33.86): 56 data bytes 64 bytes from 96.45.33.86: icmp_seq=0 ttl=51 time=127.6 ms 64 bytes from 96.45.33.86: icmp_seq=1 ttl=51 time=127.6 ms .....

--- 96.45.33.86 ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 127.5/127.7/128.4 ms

 

Forti600E-01 # exe ping 63.137.229.1 PING 63.137.229.1 (63.137.229.1): 56 data bytes

--- 63.137.229.1 ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss

Forti600E-01 #

 

 

The same problem, I can not register the Forti600E, any advice.

 

 

Thanks a lot

boneyard
Valued Contributor

the route via mgmt doesn't filter anything right? it is full internet access?

 

there two articles are useful to go through, specially the debug in the last one. it might show which extra IPs are needed or fail now.

 

https://kb.fortinet.com/kb/documentLink.do?externalID=FD30088

 

https://kb.fortinet.com/kb/viewContent.do?externalId=FD32121

 

   # diag debug enable    # diag debug application update 255    # exec update-now

BensonLEI

Bingo.

 

It works !!

 

After adding these the following IP:

 

1. fds1.fortinet.com (96.45.33.86) 2. 173.243.138.68 3. 173.243.138.66 4. 173.243.140.6

 

 

Labels
Top Kudoed Authors