Connecting to FortiGuard services
Configuring push updates
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
Revision 2
93
•
You can use scheduled updates or manually initiate updates as alternatives or in
conjunction with push updates. If protection from the latest viral threats is a high priority,
you could configure both scheduled updates and push updates, using scheduled updates
as a failover method to increase the likelihood that the FortiMail unit will still periodically
retrieve updates if connectivity is interrupted during a push notification. Using push
updates, however, can potentially cause short disruptions to antivirus scans that can occur
if the FortiMail unit applies push updates during peak volume times. For
additional/alternative update methods, see
“Configuring scheduled updates” on page 91
and
“Manually requesting updates” on page 94
Before configuring push updates, first verify that the FortiMail unit can connect to the FDN
or override server. For details, see
“To verify scheduled update connectivity” on page 89
.
To configure push updates
1
Go to
Maintenance > FortiGuard > Update
in the advanced mode of the web-based
manager.
2
Enable
Allow Push Update
.
3
If the FortiMail unit is behind a firewall or router performing NAT, enable
Use override
push IP
and enter the external IP address and port number of the NAT device.
You must also configure the NAT device with port forwarding or a virtual IP to forward
push notifications (UDP port 9443) to the FortiMail unit.
For example, if the FortiMail unit is behind a FortiGate unit, configure the FortiGate unit
with a virtual IP that forwards push notifications from its external network interface to
the private network IP address of the FortiMail unit. Then, on the FortiMail unit,
configure
Use override push IP
with the IP address and port number of that virtual IP.
For details on configuring virtual IPs and/or port forwarding, see the documentation for
the NAT device.
If you do not enable
Use override push IP
, the FDN will send push notifications to the
IP address of the FortiMail unit, which must be a public network IP address routable
from the Internet.
4
Click
Apply
.
The FortiMail unit notifies the FDN of its IP address or, if configured, the override push
IP. When an update is available, the FDN will send push notifications to this IP address
and port number.
5
Click
Refresh
.
A dialog appears, notifying you that the process could take a few minutes.
Note:
Push updates require that the external IP address of the NAT device is
not
dynamic
(such as an IP address automatically configured using DHCP). If dynamic, when the IP
address changes, the override push IP will become out-of-date, causing subsequent push
updates to fail.
Summary of Contents for FortiMail-100
Page 1: ...FortiMail Secure Messaging Platform Version 4 0 Patch 1 Install Guide...
Page 173: ...www fortinet com...
Page 174: ...www fortinet com...