病毒防护定义和攻击定义更新

病毒和攻击定义升级及注册

 

 

本节描述了以下内容: ·连接到 Forti 响应发布网络 ·配置周期性更新 ·配置更新日志 ·添加后备服务器 ·手工更新病毒防护定义和攻击定义 ·配置推送更新

·通过 NAT 设备的推送更新 ·通过代理服务器定期更新

连接到 Forti 响应发布网络

FortiGate 设备必须能够连接到 Forti 响应发布网络 (FDN)才能接受病毒防护和 攻击定义更新。FortiGate 设备使用 HTTPS 协议和 8890 端口连接 FDN。ForitGate 外部 接口必须能够使用 8890 端口连接到更新中心。要配置定期更新,请见 第 97 页 配置周期性更新

也可以将 FortiGate 配置为允许推送更新。推送更新由 FDN 使用 UDP 端口 9443 和 HTTPS 协议提供给 FortiGate 设备。要接收推送更新,FDN 必须有一条使用 UDP 端口 9443 连接到 ForitGate 外部接口的路径。要配置推送更新,请见 第 99 页 配置 推送更新

FDN 是 Forti 响应分布服务器 (FDS)组成的一个世界范围的网络。当您的 FortiGate 设备连接到 FDN 时,它实际上连接的是最近的 FDS。这是因为所有的 FortiGate 设备内部都保存了一个 FDS 地址列表。这个地址列表根据 FortiGate 设备的 时区设置,按照距离这个时区的远近排序。要确保 FortiGate 设备从最近的 FDS 接收 更新,进入系统 > 配置 > 时间并确认您根据您所在的区域正确选择了时区设置。

以下方法可以确认 FortiGate 设备能否连接到 FDN:

1 进入 系统 > 配置 > 时间 并确保时区已经根据您所在的区域正确地设置了。

2 进入 系统 > 更新

3 单击更新。

FortiGate 设备将测试它到 FDN 的连接。测试结果显示在系统更新页的顶部:

表 1: 连接到 FDN

连接

状态

说明

 

 

 

 

Forti 响应发布网络

可用

FortiGate 设备可以连接到 FDN。您可以将 FortiGate

 

 

 

设备配置为定期更新。请见 第 97 页 配置周期性

 

 

 

更新

 

 

 

 

 

 

不可用

FortiGate 设备无法连接到 FDN。您 需要配置您的

 

 

 

FortiGate 设备和您的网络使使得 FortiGate 设备可以

 

 

 

连接到互联网和 FDN。例如,您可能需要在 FortiGate

 

 

 

设备的路由表中添加路由或配置您的网络以允许

 

 

 

FortiGate 设备使用 HTTPS 协议通过端口 8443 连接到互

 

 

 

联网。

 

 

 

您可能还需要连接到一个 Forti 响应服务器代理以接受

 

 

 

推送更新。请见 第 98 页 添加后备服务器

 

 

 

 

96

美国飞塔有限公司

Page 108
Image 108
Fortinet 500 连接到 Forti 响应发布网络, ·通过 Nat 设备的推送更新 ·通过代理服务器定期更新, 进入 系统 更新。, 单击更新。 FortiGate 设备将测试它到 FDN 的连接。测试结果显示在系统更新页的顶部:

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.