NSE4 · Question #364
A FortiGate is configured to receive push updates from the FortiGuard Distribution Network, however, they are not being received. Which is one reason for this problem?
The correct answer is D. The external facing interface of the FortiGate is configured to get the IP address from a DHCP. FortiGuard push updates may fail if the external-facing interface relies on DHCP for its IP address, as this configuration can sometimes interfere with the persistent connections required for push notifications.
Question
A FortiGate is configured to receive push updates from the FortiGuard Distribution Network, however, they are not being received. Which is one reason for this problem?
Options
- AThe FortiGate is connected to multiple ISPs.
- BFortiGuard scheduled updates are enabled in the FortiGate configuration.
- CThe FortiGate is in Transparent mode.
- DThe external facing interface of the FortiGate is configured to get the IP address from a DHCP
How the community answered
(54 responses)- A2% (1)
- B4% (2)
- C7% (4)
- D87% (47)
Why each option
FortiGuard push updates may fail if the external-facing interface relies on DHCP for its IP address, as this configuration can sometimes interfere with the persistent connections required for push notifications.
Being connected to multiple ISPs (e.g., with SD-WAN) does not inherently prevent FortiGuard push updates, as long as connectivity to FDN is stable over at least one path.
FortiGuard scheduled updates are an alternative to push updates (pull vs. push), but enabling scheduled updates does not *prevent* push updates from being received if the FortiGate is configured for them; rather, it's a different update method.
A FortiGate in Transparent mode still requires management access and can receive FortiGuard updates, including push updates, provided it has proper network connectivity and routing to the FDN.
FortiGuard push updates rely on persistent connections from the FortiGate to the FortiGuard Distribution Network, which can be disrupted if the external interface's IP address is dynamically assigned via DHCP and subsequently changes or if NAT mappings are unstable, making a static IP address generally more reliable for push services.
Concept tested: FortiGuard push update requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/242270/fortiguard-updates
Topics
Community Discussion
No community discussion yet for this question.