Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ofirbo
New Contributor II

Can't create Geography address, country/region field is empty

Hi,

 

I'm using Fortigate-30E running FortiOS v6.2.16 build1392 (GA).

 

Not sure when it happened, but I can't create geography address anymore. It worked in the past.

As can be seen in the picture, the country/region field is empty with no entries.

 

forti.PNG

 

Please advise,

Thanks, Ofir

1 Solution
ofirbo
New Contributor II

Hi,

After I've opened a ticket, I received from Fortinet a custom build (FGT_30E-v6-build5262-FORTINET.out) which solved the problem after upgrading.

 

View solution in original post

18 REPLIES 18
AEK
SuperUser
SuperUser

Hello Ofir

Please share the following:

diagnose firewall ipgeo country-list
diagnose geoip ip2country 1.1.1.1
diagnose autoupdate versions | grep -A5 Geo

 

You may also need to update the GeoIP DB (if you have a valid subscription):

execute update-geo-ip
diagnose autoupdate versions | grep -A5 Geo

 

Also try create a GeoIP address object via CLI and see if it works:

config firewall address
edit "geo_US"
set type geography
set country "US"
next
end

 

Hope it helps.

AEK
AEK
ofirbo
New Contributor II

Hi AEK, attached are the requested outputs:

 

FortiGate-30E # diagnose firewall ipgeo country-list
Total countries loaded:0

 

FortiGate-30E # diagnose geoip ip2country 1.1.1.1
Invalid IP or IPv6 address

 

FortiGate-30E # diagnose autoupdate versions | grep -A5 Geo
IP Geography DB
---------
Version: 0.00000
Contract Expiry Date: n/a
Last Updated using manual update on Tue Nov 30 00:00:00 1999
Last Update Attempt: Fri Apr 18 15:29:03 2025

 

Can't add address object using CLI, getting the same error when trying to set country:

FortiGate-30E # config firewall address

FortiGate-30E (address) # edit "geo_US"
new entry 'geo_US' added

FortiGate-30E (geo_US) # set type geography

FortiGate-30E (geo_US) # set country "US"
Invalid country code: US
node_check_object fail! for country US

value parse error before 'US'
Command fail. Return code -89

 

I believe I have a valid subscription, but the DB update isn't working...

 

AEK

Can you show the status of other DBs?

diagnose autoupdate versions
AEK
AEK
ofirbo
New Contributor II

FortiGate-30E # diagnose autoupdate versions

AV Engine
---------
Version: 6.00165
Contract Expiry Date: Fri Aug 29 2025
Last Updated using manual update on Tue Aug 24 09:30:44 2021
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Virus Definitions
---------
Version: 93.02502
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Fri Apr 18 14:50:36 2025
Last Update Attempt: Fri Apr 18 14:50:36 2025
Result: Updates Installed

Extended set
---------
Version: 93.02502
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Fri Apr 18 14:50:36 2025
Last Update Attempt: Fri Apr 18 14:50:36 2025
Result: Updates Installed

Mobile Malware Definitions
---------
Version: 93.02502
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Fri Apr 18 14:50:36 2025
Last Update Attempt: Fri Apr 18 14:50:36 2025
Result: Updates Installed

IPS Attack Engine
---------
Version: 5.00280
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Tue Aug 24 20:20:16 2021
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

IPS Config Script
---------
Version: 1.00009
Contract Expiry Date: Fri Aug 29 2025
Last Updated using manual update on Thu Jun 6 14:02:00 2019
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Attack Definitions
---------
Version: 31.00992
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Thu Apr 17 20:51:05 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Attack Extended Definitions
---------
Version: 0.00000
Contract Expiry Date: Fri Aug 29 2025
Last Updated using manual update on Mon Jan 1 00:00:00 2001
Last Update Attempt: Wed Sep 1 12:49:57 2021
Result: Connectivity failure

Application Definitions
---------
Version: 31.00992
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Thu Apr 17 20:51:05 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Industrial Attack Definitions
---------
Version: 6.00741
Contract Expiry Date: n/a
Last Updated using manual update on Tue Dec 1 02:30:00 2015
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: Unauthorized

Botnet Definitions
---------
Version: 4.00940
Contract Expiry Date: Fri Aug 29 2025
Last Updated using manual update on Thu Apr 10 08:52:05 2025
Last Update Attempt: Tue Apr 15 02:32:22 2025
Result: No Updates

Botnet Domain Database
---------
Version: 3.01233
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Fri Apr 18 04:51:06 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Internet-service Database Apps
---------
Version: 7.04137
Contract Expiry Date: n/a
Last Updated using scheduled update on Fri Apr 18 04:51:06 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Internet-service Mini Database Maps
---------
Version: 7.04137
Contract Expiry Date: n/a
Last Updated using scheduled update on Fri Apr 18 04:51:06 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Device and OS Identification
---------
Version: 1.00185
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Fri Apr 11 20:29:06 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

URL White list
---------
Version: 4.00562
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Thu Apr 17 18:51:21 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

IP Geography DB
---------
Version: 0.00000
Contract Expiry Date: n/a
Last Updated using manual update on Tue Nov 30 00:00:00 1999
Last Update Attempt: Fri Apr 18 15:34:54 2025
Result: Installation failed

Certificate Bundle
---------
Version: 1.00056
Contract Expiry Date: n/a
Last Updated using manual update on Tue Feb 25 15:00:00 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Malicious Certificate DB
---------
Version: 1.00531
Contract Expiry Date: Fri Aug 29 2025
Last Updated using scheduled update on Tue Apr 15 00:34:20 2025
Last Update Attempt: Fri Apr 18 14:51:21 2025
Result: No Updates

Modem List
---------
Version: 1.048

 

ofirbo
New Contributor II

Okay I tried to add debug to update process, this is the output:

 

installUpdObjRest[800]-Step 9:Delete backup /tmp/update.backup
installUpdObjRest[823]-Step 10:Tell parent to respawn
doInstallUpdatePackage[1007]-Full obj found for IPGE000
doInstallUpdatePackage[1017]-Updating obj IPGE
installUpdateObject[342]-Step 1:Unpack obj 28, Total=1, cur=0
installUpdateObject[371]-Step 2:Prepare temp file for obj 28
installUpdObjRest[679]-Step 5:No need to back /etc/geoip_db.gz
installUpdObjRest[684]-Step 6:Copy new object /tmp/upd7KXEs9->/etc/geoip_db.gz
installUpdObjRest[731]-Failed to copy new obj file /tmp/upd7KXEs9 to /etc/geoip_db.gz, errno=28, No space left on device

 

 

It seems that the problem is low space? How can I clear the space on the device in order to finish the installation correctly?

 

Thanks,

Ofir

funkylicious

hi,

have a look at https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Disk-Space-utilization-over-90-on-th... maybe it will help as a starting point.

"jack of all trades, master of none"
"jack of all trades, master of none"
AEK
SuperUser
SuperUser

Hi Ofir

I'm afraid you will need to format the device and reinstall FOS. According to @knaveenkumar 's tech tip this is the solution for this issue.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Unable-to-Create-the-GEO-block-polic...

 

AEK
AEK
AEK

But before the above solution, you may try the two below solutions as last resort (use GeoIP v2 instead of GeoIP v3.

https://docs.fortinet.com/document/fortigate/6.2.16/fortios-release-notes/413989

Hope it helps.

AEK
AEK
ofirbo
New Contributor II

Hi, sorry for the delay.

 

Regarding the GeoIP v2 solution, if the fortigate is already with the latest firmware (FortiOS v6.2.16 build1392 (GA)) is this solution irrelevant? I didn't understand from the article what is the exact operation that change the DB from v3 to v2.

 

Is there a possibility to mount an external USB flash drive to enlarge space and install without formatting the unit to factory default?

 

Thanks

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors