FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ap
Staff
Staff
Article Id 274113
Description

It is possible that FortiGate might block Windows updates due to security profile inspection by an Antivirus profile, Web Filter profile, or Application control profile.

This article describes how to allow only Windows updates without making any changes to existing security profiles.

Scope FortiGate, Windows update.
Solution
  1. Create a firewall policy with 'Microsoft-Microsoft.Update' ISDB (Internet service database) as a destination in firewall policy without any security profile applied.
 
image.png

 

 

image.png

 

  1. Move it to the top above all firewall policies (or above the firewall policy that blocks Windows updates):
 

image.png

 

After configuring the firewall policy as above, retry Windows updates and it will be successful.

Contributors