Explicit proxy communication to FortiGate Cloud and FortiGuard servers from FortiGate is enabled. A proxy server can be configured in the FortiGuard settings so that all FortiGuard connections under the
forticldd process can be established through the proxy server.
Not all FortiGuard services are supported by these proxy settings. For example, web filter service traffic to FortiGuard will not be directed to the configured proxy.
- Configure FortiGate B as a proxy server:
config firewall proxy-policy edit 1 set proxy explicit-web set dstintf "wan1" set srcaddr "all" set dstaddr "all" set service "webproxy" set action accept set schedule "always" set logtraffic all set users "guest1" next end config user local edit "guest1" set type password set passwd 123456 next end config authentication scheme edit "local-basic" set method basic set user-database "local-user-db" next end config authentication rule edit "local-basic-rule" set srcaddr "all" set ip-based disable set active-auth-method "local-basic" next end
- Configure a firewall policy on FortiGate B to allow FortiGate A to get DNS resolution:
config firewall policy edit 1 set name "dns" set srcintf "port18" set dstintf "wan1" set srcaddr "all" set dstaddr "all" set action accept set schedule "always" set service "DNS" set fsso disable set nat enable next end
- Configure the FortiGuard proxy settings on FortiGate A:
config system fortiguard set proxy-server-ip 10.2.2.2 set proxy-server-port 8080 set proxy-username "guest1" set proxy-password 123456 end
- On FortiGate A, log in to FortiGate Cloud to activate the logging service:
execute fortiguard-log login <username> <password>
- On FortiGate A, view the
forticldddebug message to see the connection to the log controller through the proxy server:
# diagnose test application forticldd 1