Technical Tip: Flow-based virus definitions not updating
Description
This article describes flow-based virus definitions not updating or getting connectivity failure.
Scope
FortiOS v7.x and higher.
Solution
After running the diagnose autoupdate versions, the following output on the CLI will appear:
Flow-based Virus Definitions
---------
Version: 1.00000
Contract Expiry Date: Sun Mar 5 2023
Last Updated using manual update on Mon Apr 9 18:07:00 2018
Last Update Attempt: Wed Mar 25 08:25:36 2020
Result: Connectivity failure
Flow-Based virus definitions are only updated if an anti-virus profile is actively assigned to a flow-based firewall policy.
Try to create a flow-based policy and add an anti-virus security profile, or it is possible to add the Anti-Virus security profile to the existing flow-based policy on the firewall.
Once the security profile is added, run 'execute update-av' and wait for a few mins for the database to get updated.
Additionally, if use-extreme-db is enabled under the antivirus settings, the FortiGate will not update the 'Flow-based Virus Definitions'. Instead, it will update the 'Extreme set'.
config antivirus settings
set use-extreme-db enable <-- This indicates that extreme-db is enabled.
end
The flow-based database provides 'in the wild' viruses as well as some commonly seen viruses on the network.
Flow-based virus scanning is an alternative to file-based virus scanning, providing better performance but lower coverage rates than file-based virus scanning.
