FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nathan_h
Staff
Staff
Description This articles discusses about upgrading IPS Engine on a High Availability (HA) Cluster of FortiGate devices.
Scope FortiGate.
Solution

1) Before IPS Engine upgrade.

 

The below command shows that IPS Engine 7.00043 is in use on Primary Fortigate.

 

FGT_1 # diag autoupdate versions | grep -A 2 "IPS A"
IPS Attack Engine
---------
Version: 7.00043

 

FGT_1 # get sys status | grep HA
Current HA mode: a-p, primary

 

The below command is used to move to the secondary unit in an HA Cluster.

 

FGT_1 # exec ha manage 0 admin

 

FGT_2 # get sys status | grep HA
Current HA mode: a-p, secondary

 

FGT_2 # diag autoupdate versions | grep -A 2 "IPS A"
IPS Attack Engine
---------
Version: 7.00043

 

All the units in an HA Cluster are running the same IPS Engine 7.00043.


2) Upgrading IPS Engine on the Primary FortiGate.

 

Go to System -> FortiGuard -> Intrusion Prevention -> Actions -> Upgrade Database -> Select file -> Upload the IPS Engine and select 'OK'.

 

nathan_h_2-1641008646298.png

 

nathan_h_1-1641008624214.png

 

Once the IPS Engine has been upgraded successfully, the below command is use to restart the ipsmonitor process.

 

# diag test application ipsmonitor 99

 

3) After IPS Engine upgrade.

 

FGT_1 # get sys status | grep "Version:\|HA"
Version: FortiGate-VM64 v7.0.2,build0234,211019 (GA)
Current HA mode: a-p, primary

 

FGT_1 # diag autoupdate versions | grep -A 2 "IPS A"
IPS Attack Engine
---------
Version: 7.00044

 

FGT_1 # exec ha manage 0 admin

 

FGT_2 # get sys status | grep "Version:\|HA"
Version: FortiGate-VM64 v7.0.2,build0234,211019 (GA)
Current HA mode: a-p, secondary

 

FGT_2 # diag autoupdate versions | grep -A 2 "IPS A"
IPS Attack Engine
---------
Version: 7.00044

 

The above output shows that IPS Engine 7.00044 is running on both units of HA Cluster. Note that upgrading the IPS Engine on a Primary unit automatically upgrades it on the second unit as well.

 

Related article:

https://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-manually-upgrade-the-IPS-Engine/ta...