Virus and attack definitions updates and registration

 

 

 

 

 

 

 

Enabling push updates

 

 

 

 

 

 

 

Figure 24: Example network topology: Push updates through a NAT device

 

 

 

 

 

 

 

 

FortiResponse

 

 

 

 

 

 

 

 

Distribution

 

 

 

 

 

 

 

 

Network (FDN)

Internet

Push update to

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

IP address 64.230.123.149

 

 

 

 

 

 

 

 

and port 45001

 

External IP

 

 

64.230.123.149

Virtual IP maps

 

 

 

 

 

 

 

 

FortiGate-300

 

 

 

 

 

 

 

64.230.123.149:45001

Esc

Enter

 

NAT Device

 

 

 

 

 

 

 

to

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

192.168.1.99:9443

FortiGate-800

External IP or

Management IP 192.168.1.99

I N T E R N A L

E X T E R N A L

D M Z

HA

1

2

3

4

CONSOLE

USB

Esc

Enter

 

P W R

8

 

Internal Network

General procedure

Use the following steps to configure the FortiGate NAT device and the FortiGate unit on the internal network so that the FortiGate unit on the internal network can receive push updates:

1Add a port forwarding virtual IP to the FortiGate NAT device.

2Add a firewall policy to the FortiGate NAT device that includes the port forwarding virtual IP.

3Configure the FortiGate unit on the internal network with an override push IP and port.

FortiGate-800 Installation and Configuration Guide

125

Page 125
Image 125
Fortinet FortiGate-800 manual 125, General procedure