FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ssavin
Staff
Staff
Article Id 254431
Description

 

This article describes how to fix the issue when the external connector threat feed status is in the 'Unavailable' connection status.

 

Scope

 

FortiGate.

 

Solution

 

For more info about Threat feeds, visit the below link:

Threat feeds

 

 

In some cases, the external connector has the connection status immediately after creation.

 

unavailable status.png

 

Other symptoms of this behavior are:

  • No packets while running a sniffer.
  • Running the debug 'diag debug application forticron 448' returns only '# fcron_ext_handle_cmd_update()-427: command update 'test2''.

 

This behavior is caused by the external database update being disabled.

 

config system fortiguard

    set update-extdb disable

 

Re-enabling this option restores communication between the firewall and the server that hosts the threat feed IP list.

 

If the issue persists, ensure that the firewall can reach the external feed server by testing network connectivity using 'execute ping'. If connectivity is confirmed but the problem remains, and both FortiCron Debug and Sniffer do not show any packets, restart the 'forticron' process using the below command:

 

fnsysctl killall forticron

 

Related documents:

Threat feeds

Technical Tip: External threat list (threat feed) is not working (connector is showing down)

Troubleshooting Tip: External Connector-Threat Feeds support format