I am using an FG-61F with firmware version v7.2.8 build1639 (GA). Since last night, I have been continuously receiving the following two messages:
I have already tried the solution provided in this article:
https://community.fortinet.com/t5/Support-Forum/FortiGate-database-signature-invalid-on-FGT-60F-7-2/...,
but it seems to be ineffective.
How can I resolve the issue of the invalid signature and the update failure?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Broadtec,
Try the following procedure:
Step1: Run the following commands
diag autoupdate version | grep 'Internet-service' -A6
diagnose internet-service clear /data2/ffdb_app
diagnose internet-service clear /data2/ffdb_map
execute update-now
Step2: Wait 3-5 min
Step3: Run the following command againdiag autoupdate version | grep 'Internet-service' -A6
After executing the command, I received the following message:
=======================================================
FortiGate-61F # diag autoupdate version | grep 'Internet-service' -A6
Internet-service Standard Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 13:50:30 2024
Last Update Attempt: Fri Jun 21 13:56:37 2024
Result: No Updates
FortiGate-61F # diagnose internet-service clear /data2/ffdb_app
File /data2/ffdb_app has been successfully deleted.
FortiGate-61F # diagnose internet-service clear /data2/ffdb_map
File /data2/ffdb_map has been successfully deleted.
FortiGate-61F # diag autoupdate version | grep 'Internet-service' -A6
Internet-service Standard Database
---------
Version: 0.00000 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 13:50:30 2024
Last Update Attempt: Fri Jun 21 13:56:37 2024
Result: No Updates
FortiGate-61F # execute update-now
FortiGate-61F # diag autoupdate version | grep 'Internet-service' -A6
Internet-service Standard Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 14:17:51 2024
Last Update Attempt: Fri Jun 21 14:17:51 2024
Result: Updates Installed
FortiGate-61F #
=======================================================
I will observe for a day to confirm if the issue has been resolved.
Monitor it for a day and if logs are still populating by then, please raise a ticket with TAC.
Hello,
I encountered the same issue on my side (FortiGate 201E, FortiOS v7.2.8 build 1639) also starting yesterday. Executed commands recommended by @DPadula and in the CLI it seems OK:
FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Thu Jun 20 17:25:00 2024
Last Update Attempt: Fri Jun 21 10:48:09 2024
Result: No Updates
FortiGate-Cluster-Name (global) # diag internet-service clear /data2/ffdb_app
File /data2/ffdb_app has been successfully deleted.
FortiGate-Cluster-Name (global) # diag internet-service clear /data2/ffdb_map
File /data2/ffdb_map has been successfully deleted.
FortiGate-Cluster-Name (global) # execute update-now
FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Thu Jun 20 17:25:00 2024
Last Update Attempt: Fri Jun 21 11:08:49 2024
Result: No Updates
FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 11:09:04 2024
Last Update Attempt: Fri Jun 21 11:09:04 2024
Result: Updates Installed
## checking back later
FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 11:09:04 2024
Last Update Attempt: Fri Jun 21 11:17:30 2024
Result: No Update
But when I check the system logs for this manually initiated update in the WebUI, the issue seems to have been encountered as before:
I'll keep an eye on it as recommended as I'm not entierly confident the issue was resolved.
Best regards
Hi lst3010,
Glad that I could help, once you check again in few days mark the reply as solution to help other on our community.
Thank you for the reply.
However, I was mistaken, as the issue has reappeared.
Seeing the same logs starting at 11:42 am EDT yesterday.
This issue is fixed from IPS Malicious URL Database 5.00088. Could you please try a "exe update-ips" (if its not updated already based on your schedule) and check?
This issue resolved itself after 24 hours and did not recur while I was on leave.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.