Hi - weird one that has never happened before...
https://imgur.com/gjjth76
Everything is fine license-wise except for this "Industrial Attack Definitions" expiring. This occurs on both of our Fortigate 101F's.
The contract was renewed and applied over a month ago, so it's not an update issue it seems. The Industrial DB's definitions have also been updating just fine.
We purchased:
1 FC-10-F101F-809-02-12 1 Year coverage for FortiGate 101F include:
Hardware Advanced HW
Firmware & General Updates
Enhanced Support Premium
Telephone Support Premium
Advanced Malware Protection
FortiGuard IPS Service
FortiGuard URL, DNS & Video Filtering Service
AntiSpam
FortiConverter Service 8x5
FortiGuard Attack Surface Security Service
FortiGuard AI-based Sandbox Service
DLP
Whats the deal? Am I going to lose IDS? Do we need to remove anything from our policies to prevent blocked traffic?
These are several years old now and this has never happened before. It's just odd it's happening to both devices because it seems like everything should be fine.
I followed the steps here and nothing changed:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Industrial-database-fails-to-update/...
Thanks!
Solved! Go to Solution.
Hi
On the support portal, try check the subscription status of your FortiGate if it contains industrial DB.
You should open a CS ticket or contact your local FTNT account manager or your FTNT reseller. And while you fix this issue I think you don't need to disable anything, since (if I'm not wrong) the subscription is for signature updates. So your FGT should keep the existing signatures even if they are not updated.
Greetings!
It could be due to Fortiguard update.
Could you please run the debugs to check the update received from the FortiGuard server
diagnose debug application update -1
diagnose debug enable
execute update-now
Also, check the contract date at Asset Management.
Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Hi
On the support portal, try check the subscription status of your FortiGate if it contains industrial DB.
You should open a CS ticket or contact your local FTNT account manager or your FTNT reseller. And while you fix this issue I think you don't need to disable anything, since (if I'm not wrong) the subscription is for signature updates. So your FGT should keep the existing signatures even if they are not updated.
Created on 01-15-2025 02:32 PM Edited on 01-16-2025 07:15 AM
*editing due to double post. Unable to delete.
Thanks - this was helpful. I replied already but it's not showing up.
Anyway, looks like our reseller sold us a different contract this year than in years prior.
This year, we received FC-10-F101F-809-02-12 and the previous years, we received FC-10-F101F-811-02-12.
The difference is "Fortiguard OT Security Service". So, I can't really find what it does specifically but do I need it? Fortiguard is updating just fine without errors but it appears we'd need a new contract/license from our reseller to fix this.
Does anyone know if this is needed to keep our IDS and Web Filter turned on in our policies? We're not an industrial shop with IOT and we dont use deep packet inspection, we're a finance org.
Thanks, it looks like we don't need this.
Will everything in IDS (we use defaults) continue to work ok if we just let it expire?
We dont use deep packet inspection and don't have custom signatures or anything.
OT Security Service is for industrial equipment, like factories and so. If you are finance org and you use this firewall for IT only (not OT) then you definitely don't need it.
Created on 01-16-2025 07:18 AM Edited on 01-16-2025 07:19 AM
Awesome - thank you AEK and FTNT support for the input.
I was just told by our reseller that they removed OT Security Service from the Enterprise bundle last year and now it's a la carte. Good to know, this will probably come up again then for some other users so hopefully they see this.
Thanks again!
User | Count |
---|---|
2636 | |
1400 | |
810 | |
677 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.