firewall is "Unable to load FortiGuard DDNS servers list," it typically indicates a communication failure between the device and FortiGuard

Manual CLI Configuration (Works Even When List Fails)

execute fortiguard refresh-now execute ddns refresh-list

  1. Check system date/time and NTP — fix if wrong.
  2. Test DNS resolution for services.fortiguard.net — change DNS if failing.
  3. Ping/traceroute FortiGuard hosts — verify routing.
  4. Verify outbound policies allow TCP/443 and UDP/TCP/53.
  5. Check for SSL inspection or intercepting proxy — bypass for FortiGuard or import proxy CA.
  6. Temporarily point FortiGate's DNS to a public resolver and retest DDNS load.
  7. Upgrade FortiOS if device is on a release with known issues.
  8. If unresolved, capture debug logs and open a Fortinet support case including logs and steps performed.

Solution:

Common Symptoms

Network > DNS > Dynamic DNS

This report details the diagnosis and resolution of an issue where a FortiGate firewall fails to populate the Dynamic DNS (DDNS) server list provided by FortiGuard. This issue typically manifests in the Graphical User Interface (GUI) under , where the "DDNS Server" dropdown menu is empty or displays a loading error. Without this list, administrators cannot configure automatic DDNS updates for domains hosted on FortiGuard servers.

Confirm proxy or explicit web-proxy settings

    ————————
    Download popup form

    Unable To Load Fortiguard Ddns Servers List On Fortigate Firewalls May 2026

    firewall is "Unable to load FortiGuard DDNS servers list," it typically indicates a communication failure between the device and FortiGuard

    Manual CLI Configuration (Works Even When List Fails)

    execute fortiguard refresh-now execute ddns refresh-list firewall is "Unable to load FortiGuard DDNS servers

    1. Check system date/time and NTP — fix if wrong.
    2. Test DNS resolution for services.fortiguard.net — change DNS if failing.
    3. Ping/traceroute FortiGuard hosts — verify routing.
    4. Verify outbound policies allow TCP/443 and UDP/TCP/53.
    5. Check for SSL inspection or intercepting proxy — bypass for FortiGuard or import proxy CA.
    6. Temporarily point FortiGate's DNS to a public resolver and retest DDNS load.
    7. Upgrade FortiOS if device is on a release with known issues.
    8. If unresolved, capture debug logs and open a Fortinet support case including logs and steps performed.

    Solution:

    Common Symptoms

    Network > DNS > Dynamic DNS

    This report details the diagnosis and resolution of an issue where a FortiGate firewall fails to populate the Dynamic DNS (DDNS) server list provided by FortiGuard. This issue typically manifests in the Graphical User Interface (GUI) under , where the "DDNS Server" dropdown menu is empty or displays a loading error. Without this list, administrators cannot configure automatic DDNS updates for domains hosted on FortiGuard servers. Check system date/time and NTP — fix if wrong

    Confirm proxy or explicit web-proxy settings Default gateway Static routes Interface status