Troubleshooting Tip: FMWP signatures not available for virtual patching
| Description | This article describes why Firmware Virtual Patch (FMWP) signatures may not be visible or enabled on a FortiGate device and clarifies the expected behavior of virtual patching. |
| Scope | FortiOS. |
| Solution | How virtual patching works:
FMWP signatures are not available in the output below.
diagnose ips vpatch fmwp-status Enabled FMWP signatures: 0
The command above shows vulnerabilities applicable to the current FortiOS version. FMWP signatures are only enabled when the FortiGate is vulnerable to a known issue. If the device is not affected by any known vulnerabilities, no FMWP signatures will be pushed or enabled. This is expected behavior, not an issue. For example, the above output is from FortiOS 7.4.11 which is currently not impacted by any vulnerabilities.
To manually enable all FMWP signatures for testing purposes:
diagnose ips vpatch fmwp-enable-all This is intended only for testing/verification. It forces activation of signatures regardless of vulnerability status.
Note:
|
