Skip to main content
rameshk_FTNT
Staff
Staff
August 7, 2009

Technical Tip: How to Downgrade/Rollback the AV definitions, IPS definitions or IPS engine on a FortiGate unit

  • August 7, 2009
  • 0 replies
  • 19007 views

Description

 
This article describes how to downgrade IPS/Antivirus engine versions. FortiOS will not accept the upload to a FortiGate unit of an Antivirus definition or IPS definition/engine that is older than the one that is currently installed on the unit. 

 

Scope

 

FortiOS versions 5.x, 6.x, 7.x.

Solution

 
Installed Antivirus and IPS engine versions are checked by running:
 
diag autoupdate versions | grep "IPS Attack" -A 6
diag autoupdate versions | grep "AV Engine" -A 6
 
AV-Old.png
 
If a normal file is uploaded to proceed with the downgrade process, a 'Firewall has all the updates found in the given file' or a 'Failed to upgrade database' error message will be reported.
 
The downgrade procedure is as follows:
 
  1. From the FortiGate CLI, launch the command:
   
diagnose autoupdate downgrade enable
 
  1. From the FortiGate GUI, import the Antivirus definition, and IPS definition/engine needed.

  2. From the FortiGate CLI, launch the command:

diagnose autoupdate downgrade disable

  1. Verify if the downgrade process is fine from CLI:

    diagnose autoupdate versions
 

AV-Downgraded.png

 

  1. If necessary, disable scheduled updates from FortiGuard Distribution Network to keep imported signatures/prevent automatic updates:

config system autoupdate schedule
    set status disable
end
 
Related article:
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.