Virus and attack definitions updates and registration |
|
|
|
|
|
|
| Enabling push updates |
|
|
|
|
|
|
| ||
Figure 24: Example network topology: Push updates through a NAT device | ||||||||
|
|
|
|
|
|
|
| FortiResponse |
|
|
|
|
|
|
|
| Distribution |
|
|
|
|
|
|
|
| Network (FDN) |
Internet | Push update to | |||||||
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
| IP address 64.230.123.149 |
|
|
|
|
|
|
|
| and port 45001 |
| External IP |
| ||||||
| 64.230.123.149 | Virtual IP maps | ||||||
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
| 64.230.123.149:45001 | |
Esc | Enter |
| ||||||
NAT Device |
|
|
|
|
|
|
| to |
|
|
|
|
|
|
| ||
|
|
|
|
|
|
|
| 192.168.1.99:9443 |
External IP or
Management IP 192.168.1.99
I N T E R N A L | E X T E R N A L | D M Z | HA | 1 | 2 | 3 | 4 | CONSOLE | USB |
Esc | Enter |
| P W R |
8 |
|
Internal Network
General procedure
Use the following steps to configure the FortiGate NAT device and the FortiGate unit on the internal network so that the FortiGate unit on the internal network can receive push updates:
1Add a port forwarding virtual IP to the FortiGate NAT device.
2Add a firewall policy to the FortiGate NAT device that includes the port forwarding virtual IP.
3Configure the FortiGate unit on the internal network with an override push IP and port.
125 |