FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Nivedha
Staff
Staff
Article Id 240579
Description This article describes how to troubleshoot a missing IP in the ISDB database.
Scope FortiGate, FortiGuard, FortiOS ISDB internet-service.
Solution

If subnets are missing in the ISDB, verify in the CLI whether these IPs are part of any ISDBs.

To match 52.96.0.0/16, run the following command:

 

diagnose internet-service match root 52.96.0.0 255.252.0.0

 

The output shows all Internet Services that are matched:


Internet Service: 11337935(Malicious-Malicious.Server), matched num: 8
Internet Service: 327880(Microsoft-Office365.Published), matched num: 3145728
Internet Service: 327902(Microsoft-Office365.Published.Optimize), matched num: 3145728
Internet Service: 327791(Microsoft-Outlook), matched num: 262144
Internet Service: 327786(Microsoft-Azure), matched num: 512
Internet Service: 327681(Microsoft-Web), matched num: 1048576
Internet Service: 327682(Microsoft-ICMP), matched num: 262144
Internet Service: 327683(Microsoft-DNS), matched num: 524288
Internet Service: 327684(Microsoft-Outbound_Email), matched num: 1048576
Internet Service: 327686(Microsoft-SSH), matched num: 262144
Internet Service: 327687(Microsoft-FTP), matched num: 524288
Internet Service: 327688(Microsoft-NTP), matched num: 524288
Internet Service: 327689(Microsoft-Inbound_Email), matched num: 1048576
Internet Service: 327694(Microsoft-LDAP), matched num: 1048576
Internet Service: 327695(Microsoft-NetBIOS.Session.Service), matched num: 524288
Internet Service: 327696(Microsoft-RTMP), matched num: 524288
Internet Service: 327704(Microsoft-NetBIOS.Name.Service), matched num: 262144
Internet Service: 327680(Microsoft-Other), matched num: 524288

 

If this is not correct, raise a query with the ISDB team using the ISDB contact page.

 

Note:

The following commands can be used to update the ISDB database to ensure it's using the latest available entries from FortiGuard:

 

diagnose debug disable

diagnose debug reset

diagnose debug application update -1

diagnose debug enable

execute update-ffdb-on-demand

 

  • Wait for 1-2 minutes before stopping.

To stop debugging:

 

diagnose debug disable

diagnose debug reset

 

As an alternative, starting from FortiOS v7.6.4, FQDN address groups can be added from the ISDB menu on firewall policies in the GUI. This enables handling cases for frequently changed or missing IP addresses in the ISDB database. For more information, refer to GUI support for FQDN address groups within the ISDB 7.6.4.