Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rwpatterson
Valued Contributor III

A/V & IPS out of sync

Being relatively new to an A-A setup, how do you get into the slave unit to update the signatures without having to break the stack and do it individually? Thanks in advance. Have a great weekend.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
6 REPLIES 6
Carl_Wallmark
Valued Contributor

Easy: in CLI: conf global execute ha manage <id of slave> now you are inside the slave

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
rwpatterson
Valued Contributor III

Thanks for that. Will play in the morning.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
ede_pfau
SuperUser
SuperUser

Do you have a sync issue or why would you not rely on the cluster management doing the updates for you? Usually the primary updates the signatures on the slaves, via the HA link. This is a must on an A-A cluster but is also the case on an A-P cluster:
fw01 # get sys stat
 Version: Fortigate-310B v4.0,build0196,100319 (MR1 Patch 4)
 Virus-DB: 12.00346(2010-09-13 00:11)
 Extended DB: 12.00346(2010-09-13 00:12)
 IPS-DB: 2.00861(2010-09-10 02:10)
 FortiClient application signature package: 1.215(2010-09-12 20:36)
 ...
 Current HA mode: a-p, master
 ...
 
 fw01 # exe ha manage 0
 
 fw02 $ get sys stat
 Version: Fortigate-310B v4.0,build0196,100319 (MR1 Patch 4)
 Virus-DB: 12.00346(2010-09-13 00:11)
 Extended DB: 12.00346(2010-09-13 00:12)
 IPS-DB: 2.00846(2010-08-11 12:54)
 FortiClient application signature package: 0.0(2010-09-13 08:58)
 
 
I cannot remember ever doing it manually. If I had to it wouldn' t be feasable in regular intervals.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Jan_Scholten
Contributor

I had the issue once, with the slave not having the latest signatures (see http://support.fortinet.com/forum/tm.asp?m=63296&appid=&p=&mpage=1&key=&language=&tmode=&smode=&s=#63296) I am not sure whether the slave was/should be able to reach FDN (may be a Firewall between FGT and Internet). It even got that far that the slave didn' t show a updated licence, resulting in a " The licence will expire in 2 days" Error. According to FGT Support, this should have no impact on the cluster (aparently it hadn' t) but left a bad taste.. I switched prioritys to change the master now it updated the signatures and licence, but the slave was stuck.. maybe it was a connection error in my setup, pinging fdn from slave was not possible.
emnoc
Esteemed Contributor III

In my experience, I never had problems with the slave being out of sync. Upon a failure and the slave becomes active, and the slave has an active license, it will automatically sync it' s AV/IPS signatures.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rwpatterson
Valued Contributor III

Ok. All is well. I made the mistake of taking the version from the 40Net support site. It told me my versions were out of date when in fact they are up to date. Waste of Bandwidth....

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors