12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

FortiGuard Center<br />

System Maintenance<br />

Push updates when <strong>FortiGate</strong> IP addresses change<br />

The SETUP message that the <strong>FortiGate</strong> unit sends when you enable push<br />

updates includes the IP address of the <strong>FortiGate</strong> interface to which the FDN<br />

connects. The interface used for push updates is the interface configured in the<br />

default route of the static routing table.<br />

The <strong>FortiGate</strong> unit sends the SETUP message if you change the IP address of<br />

this interface manually or if you have set the interface addressing mode to DHCP<br />

or PPPoE and your DHCP or PPPoE server changes the IP address.<br />

The FDN must be able to connect to this IP address for your <strong>FortiGate</strong> unit to be<br />

able to receive push update messages. If your <strong>FortiGate</strong> unit is behind a NAT<br />

device, see “Enabling push updates through a NAT device” on page 196.<br />

If you have redundant connections to the Internet, the <strong>FortiGate</strong> unit also sends<br />

the SETUP message when one Internet connection goes down and the <strong>FortiGate</strong><br />

unit fails over to the other Internet connection.<br />

In Transparent mode if you change the management IP address, the <strong>FortiGate</strong><br />

unit also sends the SETUP message to notify the FDN of the address change.<br />

Enabling push updates through a NAT device<br />

If the FDN can only connect to the <strong>FortiGate</strong> unit through a NAT device, you must<br />

configure port forwarding on the NAT device and add the port forwarding<br />

information to the push update configuration. Using port forwarding, the FDN<br />

connects to the <strong>FortiGate</strong> unit using UDP on either port 9443 or an override push<br />

port that you specify.<br />

Note: You cannot receive push updates through a NAT device if the external IP address of<br />

the NAT device is dynamic (for example, set using PPPoE or DHCP).<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

196 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!