FortiGuard Management – FortiManager 5.2

FortiGuard web filter and email filter settings

Configure the following settings:

Connection to FDS server(s) Configure connections for overriding the default built-in FDS or web proxy server for web filter and email filter settings.

To override an FDS server for web filter and email filter services, see Overriding default IP addresses and ports.

To enable web filter and email filter service updates using a web proxy server, see Enabling updates through a web proxy.

Use Override Server

Address for FortiClient

Configure to override the default built-in FDS so that you can use a port or specific FDN server. Select the add icon to add additional override servers.

Select the delete icon to remove entries.

Use Override Server

Address for

FortiGate/FortiMail

Configure to override the default built-in FDS so that you can use a port or specific FDN server. Select the add icon to add additional override servers. Select the delete icon to remove entries.

To override the default server for updating FortiGate device’s

FortiGuard services, see “FortiGuard Management” on page 414.

Use Web Proxy Configure the FortiManager system’s built-in FDS to connect to the FDN through a web proxy.

To enable updates using a web proxy, see “FortiGuard Management” on page 413.

Log Settings Configure logging of FortiGuard web filtering, email filter, and antivirus query events.

To configure logging of FortiGuard web filtering and email filtering events, see “FortiGuard Management” on page 417

Override FortiGuard server (Local FortiManager)

Configure and enable alternate FortiManager FDS devices, rather than using the local FortiManager system. You can set up as many alternate FDS locations, and select what services are used.

Override FortiGuard server

Configure the following settings:

Additional number of private FortiGuard servers (excluding this one) (1) + Select the add icon to add a private FortiGuard server. Select the delete icon to remove entries.

When adding a private server, you must type its IP address and time zone.

Enable Antivirus and IPS

Update Service for Private

Server

When one or more private FortiGuard servers are configured, update antivirus and IPS through this private server instead of using the default FDN.

This option is available only when a private server has been configured.

Enable Web Filter and Email When one or more private FortiGuard servers are configured, update the Filter Update Service for Priv- web filter and email filter through this private server instead of using the ate Server default FDN.

This option is available only when a private server has been configured.

Allow FortiGates to access pub- When one or more private FortiGuard servers are configured, managed lic FortiGuard servers when FortiGate units will go to those private servers for FortiGuard updates.

private servers unavailable        Enable this feature to allow those FortiGate units to then try to access the public FDN servers if the private servers are unreachable.

This option is available only when a private server has been configured.


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

This entry was posted in Administration Guides, FortiManager and tagged , , on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.