nerdexam
Fortinet

NSE4 · Question #100

A FortiGate is configured to receive push updates from the FortiGuard Distribution Network, however, updates are not being received. Which are two reasons for this problem? (Choose two.)

The correct answer is B. There is a NAT device between the FortiGate and the FortiGuard Distribution Network. D. The external facing interface of the FortiGate is configured to get the IP address from a DHCP. The question asks for two reasons why a FortiGate configured for FortiGuard push updates might not receive them.

Submitted by yuriko_h· Apr 18, 2026FortiGate Deployment and System Configuration

Question

A FortiGate is configured to receive push updates from the FortiGuard Distribution Network, however, updates are not being received. Which are two reasons for this problem? (Choose two.)

Options

  • AThe FortiGate is connected to multiple ISPs.
  • BThere is a NAT device between the FortiGate and the FortiGuard Distribution Network.
  • CThe FortiGate is in Transparent mode.
  • DThe external facing interface of the FortiGate is configured to get the IP address from a DHCP

How the community answered

(45 responses)
  • A
    16% (7)
  • B
    76% (34)
  • C
    9% (4)

Why each option

The question asks for two reasons why a FortiGate configured for FortiGuard push updates might not receive them.

AThe FortiGate is connected to multiple ISPs.

Being connected to multiple ISPs (e.g., in a redundant setup) does not inherently prevent FortiGuard push updates, provided the routing is configured correctly to reach the FDN and the IPsec tunnel can establish over an active path.

BThere is a NAT device between the FortiGate and the FortiGuard Distribution Network.Correct

FortiGuard push updates use IPsec VPN tunnels, which can be disrupted or prevented from establishing if a NAT device is present between the FortiGate and the FortiGuard Distribution Network, as NAT can interfere with IPsec's negotiation.

CThe FortiGate is in Transparent mode.

A FortiGate operating in Transparent mode can still receive FortiGuard updates, as its management functions, including FortiGuard communication, are handled by its management IP address and relevant routing.

DThe external facing interface of the FortiGate is configured to get the IP address from a DHCPCorrect

If the external interface obtains its IP address via DHCP and this IP address changes, the IPsec tunnel used for push updates will break, requiring the FortiGate's external interface to have a static, publicly routable IP for reliable updates.

Concept tested: FortiGuard push update troubleshooting

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/360061/push-updates

Topics

#FortiGuard updates#Network troubleshooting#NAT#Dynamic IP

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice