Fortinet white logo
Fortinet white logo

Administration Guide

FortiGate GovRamp support

FortiGate GovRamp support

A GovRamp FortiGate SKU entitles the FortiGate to use dedicated FortiGuard servers located in the United States. It also entitles customers to access their support tickets through a dedicated FortiCare service located in the United States.

When you purchase a GovRamp FortiGate, you will receive a FortiGate that automatically boots up in GovRamp mode. It will contact the dedicated FortiGuard server to learn the rest of its entitlement.

All FortiGuard services that are supported by the GovRamp device are United States-based and use a specific FQDN. The FortiGuard servers only support connections through Anycast. Any unused cloud services are disabled on the FortiGate.

Supported FortiGuard services

The following table lists supported FortiGuard services:

Feature or service

FQDN

IP address

FortiGate firmware upgrade Contract / License Update

update.fortinetgov.com

23.249.62.6

FortiGuard Query

guardservice.fortinetgov.com

23.249.62.16

Video Query

videoquery.fortinetgov.com

23.249.62.18

SDNS

sdns.fortinetgov.com

23.249.62.53

Geo IP address Database

gip.fortinetgov.com

23.249.62.16

Device Query

devquery.fortinetgov.com

23.249.62.16

Default DNS server

23.249.63.52 / 23.249.63.53

Default NTP server

ntp1.fortinetgov.com

ntp2.fortinetgov.com

23.249.63.60/23.249.63.61

23.249.63.62 23.249.63.63

Unsupported FortiGuard services

The following lists the unsupported FortiGuard services:

  • FortiCare server connection

  • Central management to FortiManager or FortiGuard

  • Logging to FortiAnalyzer

  • FortiSandbox (FSA) and FSA Cloud configuration

  • FortiGuard DDNS service

  • FortiSwitch authorization

  • FortiExtender pre-authorization

  • Local FortiClient EMS

  • FortiClient EMS cloud

  • Product API: Device vulnerability on GUI device assets

  • Security fabric CSF: Configured as root

  • Security fabric CSF: Configured as leaf

  • Alert email - User must configure their own email server

  • FortiNDR

  • Email Filter query to RBL_SERVER (dnsbl.sorbs.net)

  • FortiToken server connection

  • Logging to FortiGate Cloud server

  • SD-WAN overlay

  • Activating FortiGate Cloud account

  • Regular FortiGuard DNS setting

  • FortiAP pre-authorization

  • Security rating under Security Fabric

  • Attack Surface Security Rating

The following lists FortiGuard services that are subject to limitations:

  • Security Rating, FortiSwitch, FortiAP, FortiClient, FortiExplorer, and FortiNAC related automation stitch, trigger, or action

Blocking unsupported features on GovRamp devices

When trying to enable services that are not supported on GovRamp devices, an error will be returned in the GUI and CLI. Likewise, some features are hidden in the GUI if they are disabled for GovRamp devices.

In the following example, the user attempts to enable FortiAnalyzer on a GovRamp FortiGate which is an unsupported service on GovRamp devices.

To view GovRamp device unsupported feature errors:
  1. In the CLI, verify that the device has a GovRamp license:

    # get system status 
    Version: FortiGate-1101E v7.6.4,build3596,250820 (GA.F)
    First GA patch build date: 240724
    Current Security Level: High
    Firmware Signature: certified
    ...
    License Status: GovRAMP
    ...
  2. Test configuring the unsupported feature in the GUI:

    1. In the GUI, go to Security Fabric > Fabric Connectors.

    2. Edit Logging & Analytics.

    3. Attempt to enable FortiAnalyzer.

      An error is displayed and the Switch Controller feature is hidden.

  3. Test configuring the unsupported feature in the CLI:

    1. Attempt to enable FortiAnalyzer.

      config log fortianalyzer setting 
          set status enable 
              Cannot enable FortiAnalyzer logging when GovRAMP license is used.
              node_check_object fail! for status enable
      
              value parse error before 'enable'
              Command fail. Return code -39

      An error is displayed.

FortiGate GovRamp support

FortiGate GovRamp support

A GovRamp FortiGate SKU entitles the FortiGate to use dedicated FortiGuard servers located in the United States. It also entitles customers to access their support tickets through a dedicated FortiCare service located in the United States.

When you purchase a GovRamp FortiGate, you will receive a FortiGate that automatically boots up in GovRamp mode. It will contact the dedicated FortiGuard server to learn the rest of its entitlement.

All FortiGuard services that are supported by the GovRamp device are United States-based and use a specific FQDN. The FortiGuard servers only support connections through Anycast. Any unused cloud services are disabled on the FortiGate.

Supported FortiGuard services

The following table lists supported FortiGuard services:

Feature or service

FQDN

IP address

FortiGate firmware upgrade Contract / License Update

update.fortinetgov.com

23.249.62.6

FortiGuard Query

guardservice.fortinetgov.com

23.249.62.16

Video Query

videoquery.fortinetgov.com

23.249.62.18

SDNS

sdns.fortinetgov.com

23.249.62.53

Geo IP address Database

gip.fortinetgov.com

23.249.62.16

Device Query

devquery.fortinetgov.com

23.249.62.16

Default DNS server

23.249.63.52 / 23.249.63.53

Default NTP server

ntp1.fortinetgov.com

ntp2.fortinetgov.com

23.249.63.60/23.249.63.61

23.249.63.62 23.249.63.63

Unsupported FortiGuard services

The following lists the unsupported FortiGuard services:

  • FortiCare server connection

  • Central management to FortiManager or FortiGuard

  • Logging to FortiAnalyzer

  • FortiSandbox (FSA) and FSA Cloud configuration

  • FortiGuard DDNS service

  • FortiSwitch authorization

  • FortiExtender pre-authorization

  • Local FortiClient EMS

  • FortiClient EMS cloud

  • Product API: Device vulnerability on GUI device assets

  • Security fabric CSF: Configured as root

  • Security fabric CSF: Configured as leaf

  • Alert email - User must configure their own email server

  • FortiNDR

  • Email Filter query to RBL_SERVER (dnsbl.sorbs.net)

  • FortiToken server connection

  • Logging to FortiGate Cloud server

  • SD-WAN overlay

  • Activating FortiGate Cloud account

  • Regular FortiGuard DNS setting

  • FortiAP pre-authorization

  • Security rating under Security Fabric

  • Attack Surface Security Rating

The following lists FortiGuard services that are subject to limitations:

  • Security Rating, FortiSwitch, FortiAP, FortiClient, FortiExplorer, and FortiNAC related automation stitch, trigger, or action

Blocking unsupported features on GovRamp devices

When trying to enable services that are not supported on GovRamp devices, an error will be returned in the GUI and CLI. Likewise, some features are hidden in the GUI if they are disabled for GovRamp devices.

In the following example, the user attempts to enable FortiAnalyzer on a GovRamp FortiGate which is an unsupported service on GovRamp devices.

To view GovRamp device unsupported feature errors:
  1. In the CLI, verify that the device has a GovRamp license:

    # get system status 
    Version: FortiGate-1101E v7.6.4,build3596,250820 (GA.F)
    First GA patch build date: 240724
    Current Security Level: High
    Firmware Signature: certified
    ...
    License Status: GovRAMP
    ...
  2. Test configuring the unsupported feature in the GUI:

    1. In the GUI, go to Security Fabric > Fabric Connectors.

    2. Edit Logging & Analytics.

    3. Attempt to enable FortiAnalyzer.

      An error is displayed and the Switch Controller feature is hidden.

  3. Test configuring the unsupported feature in the CLI:

    1. Attempt to enable FortiAnalyzer.

      config log fortianalyzer setting 
          set status enable 
              Cannot enable FortiAnalyzer logging when GovRAMP license is used.
              node_check_object fail! for status enable
      
              value parse error before 'enable'
              Command fail. Return code -39

      An error is displayed.