Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Extreme antivirus database not updated

In my new Fortigate-200B (firmware MR2 279) extreme antivirus database status : " 0.00000 (Updated 2003-01-01 via Manual Update)" Somebody knows the solution?
10 REPLIES 10
Carl_Wallmark
Valued Contributor

Hi, have you enabled updates ??

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C

Yes, push updates is enabled, all other engines and databases updated
ejhardin
Contributor

The extreme database is no longer available for the 200b models.
Not applicable

Why? what reason? had to be supported
abelio

Hi,
ORIGINAL: Roms Why? what reason? had to be supported
Let me comment some points about this. fortiOS 4.2 introduced the capability of include 3 virus database as options to choose ( four db actually included ' flow' , but this is another question): - standard (the known ' zoo' or wild list in fortinet jargon) - extended (an extended set including the former one) - extreme (above ' extended' plus complete viruses database) How to choose? Is your choice. Is a matter of perfomance and criteria; As many characteristics of FTG units, you need to know your network, to get the maximum from your UTM unit; it' s not matter of " enable everything all the time in all situations" to be ' more secure' . To enable ' extreme' viruses db you' ll need extra storage and memory, near 1GB; not only units can allocate such db; 200B, 620B, 1240B can do it. To enable extreme db you need use CLI commands:
 config antivirus settings
     set default-db extreme
 end
 
Anyway, many AV vendors sell its units saying ' n- zillions of viruses detected' , (including ping-pong virus in its databases, even when your plattform cannot ever be afected by such viruses). In your shoes, i' ll test it a lot several weeks and maybe you wan to roll back your conf to extended or normal conf. Your call. regards,

regards




/ Abel

regards / Abel
ejhardin
Contributor

Actually I know a lot about this issue as I have been working with two support techs and the development team on this issue. The extreme database was released to the 200b’s but it was a mistake. The extreme database is the same that the FortiClient uses and is over 200mb in size. I have a 200b and the amount of memory that extreme database was using to load the definitions (even if you are not using it) was really high. After fixing the memory leak and high CPU with the new 164 IPS engine (I was one of the early testers) my memory was idling at 69%. After the tech manually deleted the extreme database from my box the memory dropped to 31%. The development team and other agreed to remove the extreme database from the FortiGuard servers. So it is no longer available for the 200b. I have a support ticket from the dev team stating that in 4.2.2 (4.2 patch 2) the extreme database will be removed from the GUI. The 200b can’t support the extreme database and most likely never will. Don’t worry you are not missing much. FYI, it doesn’t matter what you enable or change on the config the extreme database is not available for down for the 200b model.
abelio

Thanks for share this experience I was arguing with only my docs and certfication material, clearly outdated as you comment; We still waiting new 200B units here to do actual testing. best regards

regards




/ Abel

regards / Abel
Not applicable

Thanks
gili
New Contributor

i am still suffering from 66-70% memory utilization on my 200B unit. it is really affecting my security as the unit enters conserve mode and session fail few min from restart. i am waiting for support to deal but if anyone knows how to delete the extra DB, please post thanks
http://www.meteorit.co.il
http://www.meteorit.co.il
Labels
Top Kudoed Authors