Test connectivity in the CLI: execute ping www.fortinet.com .
| Cause Category | Specific Issue | FortiOS Versions Affected | |----------------|----------------|----------------------------| | | Firewall policy blocking outbound HTTPS to FortiGuard | All | | DNS Resolution | Cannot resolve update.fortiguard.net or fortiguard.com | All | | SSL/TLS | Expired or untrusted FortiGate system certificate | 6.2+, 7.0+ | | FortiGuard Filtering | Web/DNS filter blocking FortiGuard itself | 6.4+ | | Service Availability | Regional FortiGuard outage or maintenance | Rare, but occurs | | Proxy Configuration | Explicit web proxy not configured or bypassed | All | | Licensing | Expired FortiGuard Unified or DDNS license | 7.2+ | | Bug/Firmware | Known bug in specific builds (e.g., 7.0.1–7.0.5) | See table below |
A successful connection will return an output listing active connections, server selections, and your current registered DDNS hostname status without errors. In the GUI, navigating to will now correctly populate the DDNS "Domain" dropdown list with options like fortiddns.com , fortidns.info , and centurylinkddns.com .
: If your WAN interface uses DHCP or PPPoE, it may automatically adopt the ISP's DNS servers, which might not resolve FortiGuard internal domains properly. Test connectivity in the CLI: execute ping www
Troubleshooting "Unable to Load FortiGuard DDNS Servers List" on FortiGate Firewalls
Ensure they are valid (e.g., 8.8.8.8 , 1.1.1.1 , or your internal resolvers). Also verify:
execute curl -k "https://service.fortinet.com/api/v1/ddns/servers" : If your WAN interface uses DHCP or
However, a notoriously frustrating error message often appears when administrators attempt to configure or refresh the DDNS provider list on a FortiGate appliance:
If the error persists, consider these less common but potential causes.
Change your FortiGate system DNS to reliable, public servers like Fortinet Guard DNS or Google DNS. Change your FortiGate system DNS to reliable, public
The "Unable to load FortiGuard DDNS servers list" error on FortiGate firewalls is typically a networking or configuration issue that can be systematically resolved. The path to a solution begins with verifying your FortiGate's basic DNS and internet connectivity before moving on to the core CLI configurations. The most effective fixes often involve disabling DNS override, disabling FortiGuard anycast, and manually specifying the DDNS server's IP address.
In the CLI, you see:
MRT Key V3.77.zip
| Date | 2025-06-14 13:44:01 |
| Filesize | 600.00 MB |
| Visits | 420 |
| Downloads | 229 |