FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
anikolov
Staff
Staff
Article Id 388821
Description This article describes a possible cause and solution for FortiGate, which is not updating.
Scope FortiGate, FortiSASE.
Solution

To identify an issue with the update of a FortiGate, the KB article below explains all of the steps to troubleshoot it:

Troubleshooting Tip: Failure on update or contact FortiGuard

 

In case the debug from the update daemon returns messages similar to the output below:

 

"Cert error 19, self signed certificate in certificate chain."

"Server certificate failed verification. Error: 19 (self signed certificate in certificate chain), depth: 1, subject: <certificate>"
"SSL_connect failes: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed"
"Failed SSL connecting (5,0,Success)"

 

It might be the case that there is another device blocking the FortiGate from reaching FortiGuard. In the sample logs above, it was another FortiSASE which a deep inspection of the traffic was compromising the update. Setting this traffic to a certificate inspection fixes the issue.