Skip to main content
oarslan
Staff
Staff
February 21, 2022

Technical Tip: How to upgrade application control definitions manually

  • February 21, 2022
  • 0 replies
  • 24656 views

Description

This article describes how to update application control definitions manually.

Scope

FortiGate.

Solution

By default, if the FortiGate has internet connectivity and application control is used, the database will be updated automatically as part of the scheduled FortiGuard updates. To verify if autoupdate is enabled, run the following command:

show system autoupdate schedule


If autoupdate is enabled but not working, refer to Technical Tip: Application Control Signatures are not updated automatically.

If necessary, application control definitions can be upgraded manually. This is also the case if the FortiGate is on an air-gapped environment where local breakout to the internet is not available. Before upgrading, it is possible to check the current database version by running below command:

diagnose autoupdate versions


before.png

 

To download the latest update package manually, go to Fortinet Support under Support -> Service Updates.

 

app.png

 

Download the Application Control Definition by choosing the Fortinet Product and the FortiOS version matching the firewall's current Minor Version. Minor versions are firmware branches, such as v6.4, v7.0, v7.2, and v7.4.

Most service updates are maintained under 'vX.Y.0', and this is the correct OS version to select in most cases. If there are multiple OS Versions for the current minor version and it is not clear which OS version to select, check the GA version (such as v7.6.0, v7.4.0, v7.2.0 etc) and download the latest 'Application Definition' file.


47d41fa8.png



Because of an upcoming DLP database enhancement, the v7.4.8 and v7.6.3 OS Versions are added to the dropdown as of Q1 2025, but only include a new version of the DLP database. Select v7.4.8 or v7.6.3 if DLP signatures is required for v7.4.8, v7.6.3, or later. For other definitions, such as Attack Definition, Application Definition and others, select the GA version of the firmware (v7.6.0, v7.4.0, v7.2.0 etc).

v7_6_3_dropdown.png


Note:

The database update packages will only be available for download if there is a valid FortiGuard support contract registered on the account.


To upload the update package:


On the FortiGate GUI, browse System -> FortiGuard -> Application Control Signatures -> Actions -> Upgrade Database and upload the definition file downloaded from the support site.

 

For version 7.6 and above:


dc3eeca9.png


For version 7.4 and below:

7496b64b.png


After the upgrade, verify again if the version has been updated by running the following command and checking the version information.

 

diagnose autoupdate versions | grep "Application Definitions" -A 6


after.png

 

The procedure outlined above can be used to manually update other firewall databases as well, including antivirus signatures (Virus Definitions) and IPS signatures (Attack Definitions). For a list of database abbreviations and names, see Technical Tip: Deciphering FortiGuard database abbreviations and subscriptions/services.

    Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
    Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.