FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rameshk_FTNT
Staff
Staff
Article Id 192541

Description

 
This article describes how to downgrade IPS/Antivirus engine versions. FortiOS will not accept the upload to a FortiGate unit of an Antivirus definition or IPS definition/engine that is older than the one that is currently installed on the unit. 

 

Scope

 

FortiOS versions 5.x, 6.x, 7.x.

Solution

 
Installed Antivirus and IPS engine versions are checked by running:
 
diag autoupdate versions | grep "IPS Attack" -A 6
diag autoupdate versions | grep "AV Engine" -A 6
 
AV-Old.png
 
If a normal file is uploaded to proceed with the downgrade process, a 'Firewall has all the updates found in the given file' or a 'Failed to upgrade database' error message will be reported.
 
The downgrade procedure is as follows:
 
  1. From the FortiGate CLI, launch the command:
   
diagnose autoupdate downgrade enable
 
  1. From the FortiGate GUI, import the Antivirus definition, and IPS definition/engine needed.

  2. From the FortiGate CLI, launch the command:

diagnose autoupdate downgrade disable

  1. Verify if the downgrade process is fine from CLI:

    diagnose autoupdate versions
 

AV-Downgraded.png

 

  1. If necessary, disable scheduled updates from FortiGuard Distribution Network to keep imported signatures/prevent automatic updates:

config system autoupdate schedule
    set status disable
end
 
Related article: