FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pavankr5
Staff
Staff
Article Id 256486

 

Description This article describes how to disable the FortiGuard scheduled updates.
Scope FortiGate.
Solution

This setting will disable all signature and engine updates automatically downloaded from the FortiGuard Distribution Network.
FortiGate will no longer automatically update IPS or AV engines, as well as IPS, Application Control, AV, or other signatures.


Engines or signatures locally present on the device will be used for any further UTM inspection.
Disabling this feature can be useful, for example, when a specific engine or signature should be downgraded and remain installed on the old version.

 

The risk is that signatures or even the engines can get outdated and may not detect new attacks. Updates should only be disabled for test reasons or as a temporary workaround for technical issues until the root cause is resolved.

 

Use the following commands in the CLI to stop FortiGuard scheduled updates.

 

config system autoupdate schedule
    set status disable
end

 

Alternatively, disable it in the GUI: navigate to System -> Fortiguard ->FortiGuard Updates and disable it by unchecking 'scheduled updates'.

 

scheduled-update.PNG

 

It confirms that the scheduled updates were disabled and will appear in the notification section.


scheduled updates disabled.PNG