Latency During Fortiguard Updates
FGT-1500D (HA) (A-P)
FortiOS v5.4.8
IPS Extended DB Enabled
During scheduled Fortiguard updates, a constantly running UDP data stream is temporarily interrupted causing significant service disruption. The Fortiguard updates were moved from 12 AM to 4 AM and the problem followed the time change. Recently changed the updates from daily to weekly (Sunday @ 4 AM) and the problem now only occurs on Sunday @ 4 AM. This issue was occurring when the device was running v5.0.10 as well. We have worked with Fortinet Support at length with no avail. I have not been able to find any previous discussions of this type of problem but I figured a shot in the dark in the forum may yield something to go on/investigate.
Fortinet did mention the following: "During an update, the FortiGate unit will continue to detect to scan network traffic. Sessions occurring right before an update will be scanned using the current signatures. Sessions that occur during the update, when the signature database is reloading, will be on hold until the signatures load, at which point the new signatures are used to scan these sessions. Sessions occurring right after the update will also use the new signatures."
I'm wondering if there is a way to modify this "holding" behavior to allow the traffic to continue passing until the IPS engine has been reloaded with the new signatures?
Any Suggestions Are Appreciated!
