Skip to main content
acastellani
Staff
Staff
March 4, 2015

Technical Tip: How to manually update the Virus Definition database or AntiVirus Engine

  • March 4, 2015
  • 0 replies
  • 53181 views

Description

 
This article describes how to manually update the Antivirus Definition and Engine for a FortiGate.

 

Scope

 

FortiGate, FortiManager.


Solution

 

It is recommended to have automatic updates enabled in either the FortiGate or the FortiManager that manages updates for the FortiGates without internet access.
Doing so allows the FortiGates to benefit from the latest virus definition packages as soon as they are updated.
 
To update the definitions manually instead:
 
  1. Log in to the Customer Service & Support web portal at Support.

  2. Navigate to Support -> Service updates -> Download and find the FortiGate device model to update. 

  3. Select the corresponding link for 'Virus Definition' and download the '.ETDB' file after completing the security check.

  4. Optionally, verify the file integrity (Technical Tip: How to verify downloaded firmware checksum) by comparing the locally generated MD5 hash of the file with the one provided at the (MD5) link.
 
AV UPDATE.PNG
 
This process will upgrade both the Antivirus definitions and the Antivirus engine.
 
The Antivirus engines are not publicly available for download. They are usually provided through technical support cases to help address certain unwanted behaviors.
 
How to check current versions.

In the Web GUI:
Navigate to System -> FortiGuard -> Antivirus Definitions.
 
AlexCFTNT_2-1668075195303.png
 
In the CLI:

Run the following command to check the current Antivirus definition or engine versions:

diagnose autoupdate versions | grep Virus -A2
diagnose autoupdate versions | grep Engine -A2
 
AlexCFTNT_0-1668075065878.png

 


In this case, the Virus Definitions version is 0, and the Antivirus engine shows (6.)276 (the same as in the GUI example).
The 6. is not relevant - this is only used to identify the FortiOS version that it comes with.
 
Updating the Antivirus Definition or Antivirus engine can only be done through the Web GUI after selecting'Upgrade Database':

AlexCFTNT_3-1668075996365.png

 

Sometimes, for the AntiVirus engines provided by support representatives, there may be a warning that requires confirmation:

 

AlexCFTNT_4-1668076098160.png

 

In some cases, the 'Failed to upgrade database' may appear:

 

AlexCFTNT_5-1668076142877.png

 

This occurs if the AntiVirus engine is not meant to be used in the FortiOS version currently being run, or, less likely, if the file integrity has been compromised (usually due to incomplete downloads). 


antivirus failed update.PNG


AntiVirus Package file names: 

vsigupdate-OS7.60_7.049_GA_signed_ENG_ALL.pkg <---- This pkg file is valid for FortiOS v7.6.x.

vsigupdate-OS7.40_7.051_GA_signed_ENG_ALL.pkg <----- This pkg file is valid for FortiOS v7.4.x.

 

In this example, an upgrade is performed from version 276 to 283:

 

AlexCFTNT_6-1668076308858.png

 

The following message appears briefly:

 

AlexCFTNT_7-1668076423250.png

 

After refreshing, the version change is reflected in the AntiVirus status.

 

AlexCFTNT_8-1668076477341.png
 
V7.4.x: The option for updating the Antivirus Definition has changed; it has been moved under the 'Advanced Malware Protection':

 

1.jpg

 

V7.6.x: The Option for updating the Antivirus Definition remains the same but the Graphical user interface has changed.

 

2.jpg

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.