Description | This article describes how to handle behavior where FortiGuard updates using a proxy fail due to a host header missing in HTTP 1.1. |
Scope | FortiOS v7.2, FortiOS v7.4. |
Solution |
Configure proxy tunneling for IPS updates.
config system autoupdate tunneling
FortiGate (global) # diagnose debug application update -1 FortiGate (global) # diagnose debug enable FortiGate (global) #execute update-now FortiGate (global) # eupd_fds_load_default_server[939]-Resolve and add fds globalupdate.fortinet.net ip address failed. SGLSFW07 (global) # upd_fds_load_default_server6[1046]-Resolve and add fds globalupdate.fortinet.net ipv6 address failed. ] response=[HTTP/1.1 400 Bad Request
The converted Wireshark analysis reveals that the HTTP/1.1 Host header is absent in the FortiGuard web proxy requests. Hypertext Transfer Protocol
The issue has been identified and fixed on FortiOS v7.4.8. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.