Skip to main content
chpa
New Member
October 26, 2017
Question

No updates on my IPS Engine

  • October 26, 2017
  • 21 replies
  • 43868 views

Hello,

 

I have a problem to update automatically my IPS Engine.

Actually I have a cluster of Fortigate-200D and configured some vdoms. Here my output of the command "get system auto-update versions".

 

IPS Attack Engine --------- Version: 3.00430 Contract Expiry Date: Mon Apr 30 2018 Last Updated using manual update on Thu Sep 14 12:55:16 2017 Last Update Attempt: Sun Jun 18 15:56:24 2017 Result: No Updates

Can someone help me ?

 

Thanks

21 replies

hmtay_FTNT
Staff
Staff
October 26, 2017

Hello chpa,

 

IPS Engine 3.430 is the latest version that we provide as the GA build. We do not provide an update for the engine regularly.

chpa
chpaAuthor
New Member
October 26, 2017

Hi HoMing,

 

Thanks for your reply,  I will check if the new version will be uploaded from the fortigate.

I have a last question:

Is it normal this message below ?

 

"Last Update Attempt: Sun Jun 18 15:56:24 2017 Result: No Updates"

 

Thank you in advance

hmtay_FTNT
Staff
Staff
October 26, 2017

Did you turn on automatic updates? That looks like your Fortigate does not regularly try to update the databases.

 

chpa
chpaAuthor
New Member
October 27, 2017

Hi Ken,

 

From my vdom root I can ping and do traceroute to all of the FortiGrd servers. I don't have any upstream filters or any SNAT  involved.

About your question "Is root your management-vdom for updates?", I'm not sure but actually I dont have a dedicate port for management. These cluster is managed from their public IP.

From a host on my LAN interface I can ping, telnet to a FDS  server on port 443.

 

 

emnoc
New Member
October 27, 2017

Let me clarify

 

1: in global context ( assuming you have vdom ) you might have change the  management vdom to another one

 

2: run  "show system global" and see if the vdom was set as root or something else. Whatever vdom that's define has TO HAVE AN ADDRESS  and  be able to reach the update servers

 

chpa
chpaAuthor
New Member
October 30, 2017

My management-vdom is the vdom "root". To be sure I configured on my Fortigates this :

  config global config system global       set management-vdom root end

 

 

From my vdom root I can ping the update server.

 

(root) # execute ping fds1.fortinet.com PING fds1.fortinet.com (173.243.138.66): 56 data bytes 64 bytes from 173.243.138.66: icmp_seq=0 ttl=49 time=159.8 ms 64 bytes from 173.243.138.66: icmp_seq=1 ttl=49 time=159.7 ms 64 bytes from 173.243.138.66: icmp_seq=2 ttl=49 time=159.9 ms 64 bytes from 173.243.138.66: icmp_seq=3 ttl=49 time=159.7 ms 64 bytes from 173.243.138.66: icmp_seq=4 ttl=49 time=159.8 ms --- fds1.fortinet.com ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 159.7/159.7/159.9 ms

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.