Hi guys,
I have a customer's FortiGate without UTM licenses such as AntiVirus or Web Filtering. I have read that Application Control is a free service from release 5.6.1 on.
Application Control is now a free FortiGuard service and the database for Application Control signatures is separate from the IPS database
I can see that the FortiGate has the Application Control Signatures correctly updated, but the IPS licenses are expired since customer didn't purchase these type of licenses, and Application Control uses the IPS engine. Then, what is the impact of these mismatches? Will the FortiGate perform Application Control correctly?
Regards,
Julián
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Julian,
Yes, your Application Control will function normally. The IPS Definition is relatively updated 2-3 days ago. That's the right version.
Homing
Sorry, I means Application Control signatures. (in the past, Application Control signatures were in IPS Definitions. Wrong term now.)
IPS Definitions contain the signature, IPS Engine is the engine that does the IPS controls.
Hi guys,
Any tip?
Regards,
Julián
Hi Julian,
Yes, your Application Control will function normally. The IPS Definition is relatively updated 2-3 days ago. That's the right version.
Homing
Hi Homing,
Please, two more questions about this:
1. Why was the IPS Definition updated if the FortiGate has no IPS license?
2. What's the difference between IPS Definitions and IPS Engine?
Regards,
Julián
Sorry, I means Application Control signatures. (in the past, Application Control signatures were in IPS Definitions. Wrong term now.)
IPS Definitions contain the signature, IPS Engine is the engine that does the IPS controls.
Hi Homing,
Ah ok, then IPS signatures and IPS Definitions are the same thing? And the term IPS Definitions shouldn't be use nowadays?
Regards,
Julián
Hey Julian,
IPS Definitions means just IPS signatures now instead of both IPS and Application Control.
Homing
Hi Homing,
Ok, it is clear now. I noticed that my IPS Engine is not the last version (I have version 3.00426 and last version is 3.00430 I think). Because Application Control uses IPS Engine and my engine is not updated to last version, does it have any impact in Application Control? Can the IPS Engine be updated automatically via FortiGuard or should it be updated manually? Thank you very much.
Regards,
Julián
The IPS engine is updated automatically via the FortiGuard service. It can take some time for revisions.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.