12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

System Maintenance<br />

FortiGuard Center<br />

FortiGuard Services<br />

The <strong>FortiGate</strong> unit supports the following update features:<br />

• User-initiated updates from the FDN,<br />

• Hourly, daily, or weekly scheduled antivirus and attack definition updates from<br />

the FDN,<br />

• Push updates from the FDN,<br />

• Update status including version numbers, expiry dates, and update dates and<br />

times,<br />

• Push updates through a NAT device.<br />

You must register the <strong>FortiGate</strong> unit on the Fortinet support web page. To register<br />

your <strong>FortiGate</strong> unit, go to Product Registration and follow the instructions.<br />

To receive scheduled updates, the <strong>FortiGate</strong> unit must be able to connect to the<br />

FDN using HTTPS on port 443. For information about configuring scheduled<br />

updates, see “To enable scheduled updates” on page 194.<br />

You can also configure the <strong>FortiGate</strong> unit to receive push updates. For this to<br />

succeed, the FDN must be able to route packets to the <strong>FortiGate</strong> unit using UDP<br />

port 9443. For information about configuring push updates, see “To enable push<br />

updates” on page 195. If the <strong>FortiGate</strong> unit is behind a NAT device, see “Enabling<br />

push updates through a NAT device” on page 196.<br />

Worldwide coverage of FortiGuard services are provided by FortiGuard Service<br />

Points. When your <strong>FortiGate</strong>unit connects to the FDN, it is connecting to the<br />

closest FortiGuard Service Point. Fortinet adds new Service Points as required.<br />

By default, the <strong>FortiGate</strong> unit <strong>com</strong>municates with the closest Service Point. If the<br />

Service Point be<strong>com</strong>es unreachable for any reason, the <strong>FortiGate</strong> unit contacts<br />

another Service Point and information is available within seconds. By default, the<br />

<strong>FortiGate</strong> unit <strong>com</strong>municates with the Service Point via UDP on port 53.<br />

Alternately, the UDP port used for Service Point <strong>com</strong>munication can be switched<br />

to port 8888 by going to System > Maintenance > FortiGuard Center.<br />

If you need to change the default FortiGuard Service Point host name, use the<br />

hostname keyword in the system fortiguard CLI <strong>com</strong>mand. You cannot<br />

change the FortiGuard Service Point name using the web-based manager.<br />

For detailed information about FortiGuard services, see the FortiGuard Center<br />

web page.<br />

FortiGuard Antispam Service<br />

FortiGuard Antispam is an antispam system from Fortinet that includes an IP<br />

address black list, a URL black list, and spam filtering tools. The IP address black<br />

list contains IP addresses of email servers known to be used to generate spam.<br />

The URL black list contains URLs of websites found in spam email.<br />

FortiGuard Antispam processes are <strong>com</strong>pletely automated and configured by<br />

Fortinet. With constant monitoring and dynamic updates, FortiGuard Antispam is<br />

always current. Enable or disable FortiGuard Antispam in firewall protection<br />

profiles. For more information, see “Spam filtering options” on page 336.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 187

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!