12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

System Maintenance<br />

FortiGuard Center<br />

Figure 113:Example network: Push updates through a NAT device<br />

Internet<br />

FDN<br />

Server<br />

NAT Device<br />

Push Updates<br />

Internal Network<br />

General procedure<br />

Use the following steps to configure the <strong>FortiGate</strong> unit on the internal network and<br />

the NAT device so that the <strong>FortiGate</strong> unit on the internal network can receive push<br />

updates:<br />

1 Register and license the <strong>FortiGate</strong> unit on the internal network so that it can<br />

receive push updates.<br />

2 Configure the FortiGuard Center of the <strong>FortiGate</strong> unit on the internal network.<br />

• Allow push updates<br />

• Add an override push update IP. Usually this would be the IP address of the<br />

external interface of the NAT device<br />

• If required, change the override push update port<br />

3 Add a port forwarding virtual IP to the NAT device.<br />

• Set the external IP address of the virtual IP to match the override push update<br />

IP. Usually this would be the IP address of the external interface of the NAT<br />

device.<br />

4 Add a firewall policy to the <strong>FortiGate</strong> NAT device that includes the port forwarding<br />

virtual IP.<br />

To configure the FortiGuard Center of the <strong>FortiGate</strong> unit on the internal<br />

network<br />

1 Go to System > Maintenance > FortiGuard Center.<br />

2 Select Allow Push Update.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 197

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!