Incorporated User Manual switch FortiGate 4000

130 Fortinet Inc.
Enabling push updates Virus and attack definitions updates and registration
Example: push updates through a NAT device
This example describes how to configure a FortiGate NAT device to forward push
updates to a FortiGate unit installed on its internal network. For the FortiGate unit on
the internal network to receive push updates, the FortiGate NAT device must be
configured with a port forwarding virtual IP. This virtual IP maps the IP address of the
external interface of the FortiGate NAT device and a custom port to the IP address of
the FortiGate unit on the internal network. This IP address can either be the external
IP address of the FortiGate unit if it is operating in NAT/Route mode, or the
Management IP address of the FortiGate unit if it is operating in Transparent mode.
Figure 37: Example network topology: Push updates through a NAT device
Note: You cannot receive push updates through a NAT device if the external IP address of the
NAT device is dynamic (for example, set using PPPoE or DHCP).