Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FirewallsrHard
New Contributor II

Contract Renewed but Industrial DB Expiring in 4 Days?

Hi - weird one that has never happened before...
https://imgur.com/gjjth76

Everything is fine license-wise except for this "Industrial Attack Definitions" expiring. This occurs on both of our Fortigate 101F's.
The contract was renewed and applied over a month ago, so it's not an update issue it seems. The Industrial DB's definitions have also been updating just fine.

We purchased:
1 FC-10-F101F-809-02-12 1 Year coverage for FortiGate 101F include:
Hardware Advanced HW
Firmware & General Updates
Enhanced Support Premium
Telephone Support Premium
Advanced Malware Protection
FortiGuard IPS Service
FortiGuard URL, DNS & Video Filtering Service
AntiSpam
FortiConverter Service 8x5
FortiGuard Attack Surface Security Service
FortiGuard AI-based Sandbox Service
DLP


Whats the deal? Am I going to lose IDS? Do we need to remove anything from our policies to prevent blocked traffic?

These are several years old now and this has never happened before. It's just odd it's happening to both devices because it seems like everything should be fine.

I followed the steps here and nothing changed:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Industrial-database-fails-to-update/...



Thanks!

1 Solution
AEK
SuperUser
SuperUser

Hi

On the support portal, try check the subscription status of your FortiGate if it contains industrial DB.

You should open a CS ticket or contact your local FTNT account manager or your FTNT reseller. And while you fix this issue I think you don't need to disable anything, since (if I'm not wrong) the subscription is for signature updates. So your FGT should keep the existing signatures even if they are not updated.

AEK

View solution in original post

AEK
10 REPLIES 10
Dhruvin_patel

Greetings!

 

It could be due to Fortiguard update.

Could you please run the debugs to check the update received from the FortiGuard server

 

diagnose debug application update -1

diagnose debug enable

execute update-now

 

Also, check the contract date at Asset Management.

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-enable-FortiGate-s-FortiGuard...

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-license-falsely-shows-as-e...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-license-expiry-date-incorrect/ta...

 

Regards!

If you have found a solution, please like and accept it to make it easily accessible for others.

Dhruvin Patel
dingjerry_FTNT

Hi @FirewallsrHard ,

 

If you can PM me with the SN, I can take a look.

Regards,

Jerry
AEK
SuperUser
SuperUser

Hi

On the support portal, try check the subscription status of your FortiGate if it contains industrial DB.

You should open a CS ticket or contact your local FTNT account manager or your FTNT reseller. And while you fix this issue I think you don't need to disable anything, since (if I'm not wrong) the subscription is for signature updates. So your FGT should keep the existing signatures even if they are not updated.

AEK
AEK
FirewallsrHard
New Contributor II

*editing due to double post. Unable to delete.

FirewallsrHard
New Contributor II

Thanks - this was helpful. I replied already but it's not showing up.

Anyway, looks like our reseller sold us a different contract this year than in years prior.
This year, we received FC-10-F101F-809-02-12 and the previous years, we received FC-10-F101F-811-02-12.

The difference is "Fortiguard OT Security Service". So, I can't really find what it does specifically but do I need it? Fortiguard is updating just fine without errors but it appears we'd need a new contract/license from our reseller to fix this.

Does anyone know if this is needed to keep our IDS and Web Filter turned on in our policies? We're not an industrial shop with IOT and we dont use deep packet inspection, we're a finance org.

FirewallsrHard

Thanks, it looks like we don't need this.

Will everything in IDS (we use defaults) continue to work ok if we just let it expire?
We dont use deep packet inspection and don't have custom signatures or anything.

AEK

OT Security Service is for industrial equipment, like factories and so. If you are finance org and you use this firewall for IT only (not OT) then you  definitely don't need it.

AEK
AEK
FirewallsrHard
New Contributor II

Awesome - thank you AEK and FTNT support for the input.

I was just told by our reseller that they removed OT Security Service from the Enterprise bundle last year and now it's a la carte. Good to know, this will probably come up again then for some other users so hopefully they see this.

Thanks again!

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors