Technical Tip: Resolving IPS definition version mismatch on FortiGate
| Description | This article describes why some FortiGate devices display different IPS definition versions (for example, 35.172 vs 36.172) and how to interpret this behavior correctly. |
| Scope | FortiGate. |
| Solution | When a new IPS engine is downloaded via FortiGuard, the major IPS definition version increases:
For the same minor version :
This behavior is expected and is not a FortiOS bug.
The change from 35.x to 36.x is a label change tied to the IPS engine generation. For the same minor version, detection coverage and update history are identical between 35.x and 36.x. This is normal behavior with automatic IPS updates and does not require any manual changes to the IPS package.
If a device is to be displayed with the same IPS definition version as the FortiGuard IPS page (e.g., for operational or compliance reasons), it must be adjusted manually using the IPS package.
Example procedure (package file versions are examples):
diagnose autoupdate downgrade enable
GUI: System -> FortiGuard -> License Information. CLI:
diagnose autoupdate versions | grep -A 4 "Attack Extended Definitions" |
