Created on
08-22-2024
07:40 AM
Edited on
11-27-2025
12:55 AM
By
Jean-Philippe_P
| Description | This article describes how to resolve a scenario where the manual upgrade of the IPS engine fails with the error 'Failed to upgrade database'. |
| Scope | Firewall with BIOS security level set to 2. |
| Solution |
If the BIOS security level is set to 2, the firewall will reject the manually uploaded unsigned engine and give the following error:
Verify the BIOS security level using the 'get system status' command on the CLI:
get system status
To change the security level:
diagnose autoupdate downgrade enable
After executing the command, upload the required IPS engine file, and once the IPS upgrade has completed successfully, revert the setting to its default state by running the command:
diagnose autoupdate downgrade disable
Additional Information: In some environments, downtime for rebooting the device to lower the security level is not acceptable. In such cases, if the firewall is managed by FortiManager, the device administrator can import the required IPS engine package into FortiManager and install it directly. This allows the IPS engine to be upgraded without reducing the security level or rebooting the firewall.
Note: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.