Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Broadtec
New Contributor II

FG61F idsurldb signature is missing or invalid

I am using an FG-61F with firmware version v7.2.8 build1639 (GA). Since last night, I have been continuously receiving the following two messages:

  1. Fortigate scheduled update failed.
  2. Fortigate idsurldb signature is missing or invalid.

I have already tried the solution provided in this article:
https://community.fortinet.com/t5/Support-Forum/FortiGate-database-signature-invalid-on-FGT-60F-7-2/...,
but it seems to be ineffective.

How can I resolve the issue of the invalid signature and the update failure?

9 REPLIES 9
DPadula
Staff
Staff

Hi Broadtec,

 

Try the following procedure:

 

Step1: Run the following commands

diag autoupdate version | grep 'Internet-service' -A6
diagnose internet-service clear /data2/ffdb_app
diagnose internet-service clear /data2/ffdb_map
execute update-now


Step2: Wait 3-5 min

 

Step3: Run the following command again
diag autoupdate version | grep 'Internet-service' -A6

Regards
DPadula
Broadtec
New Contributor II

After executing the command, I received the following message:
=======================================================

FortiGate-61F # diag autoupdate version | grep 'Internet-service' -A6
Internet-service Standard Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 13:50:30 2024
Last Update Attempt: Fri Jun 21 13:56:37 2024
Result: No Updates

FortiGate-61F # diagnose internet-service clear /data2/ffdb_app
File /data2/ffdb_app has been successfully deleted.

FortiGate-61F # diagnose internet-service clear /data2/ffdb_map
File /data2/ffdb_map has been successfully deleted.

FortiGate-61F # diag autoupdate version | grep 'Internet-service' -A6
Internet-service Standard Database
---------
Version: 0.00000 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 13:50:30 2024
Last Update Attempt: Fri Jun 21 13:56:37 2024
Result: No Updates

FortiGate-61F # execute update-now

FortiGate-61F # diag autoupdate version | grep 'Internet-service' -A6
Internet-service Standard Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 14:17:51 2024
Last Update Attempt: Fri Jun 21 14:17:51 2024
Result: Updates Installed

FortiGate-61F #

=======================================================

I will observe for a day to confirm if the issue has been resolved.

candawi
Staff
Staff

Monitor it for a day and if logs are still populating by then, please raise a ticket with TAC.

lst3010
New Contributor

Hello,

 

I encountered the same issue on my side (FortiGate 201E, FortiOS v7.2.8 build 1639) also starting yesterday. Executed commands recommended by @DPadula and in the CLI it seems OK:

FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Thu Jun 20 17:25:00 2024
Last Update Attempt: Fri Jun 21 10:48:09 2024
Result: No Updates

FortiGate-Cluster-Name (global) # diag internet-service clear /data2/ffdb_app
File /data2/ffdb_app has been successfully deleted.

FortiGate-Cluster-Name (global) # diag internet-service clear /data2/ffdb_map
File /data2/ffdb_map has been successfully deleted.

FortiGate-Cluster-Name (global) # execute update-now

FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Thu Jun 20 17:25:00 2024
Last Update Attempt: Fri Jun 21 11:08:49 2024
Result: No Updates

FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 11:09:04 2024
Last Update Attempt: Fri Jun 21 11:09:04 2024
Result: Updates Installed

## checking back later

FortiGate-Cluster-Name (global) # diagnose autoupdate version | grep 'Internet-service' -A6
Internet-service Full Database
---------
Version: 7.03741 signed
Contract Expiry Date: n/a
Last Updated using manual update on Fri Jun 21 11:09:04 2024
Last Update Attempt: Fri Jun 21 11:17:30 2024
Result: No Update

 

But when I check the system logs for this manually initiated update in the WebUI, the issue seems to have been encountered as before:

2024-06-21T1118_fortigate_update-failure.png

 

I'll keep an eye on it as recommended as I'm not entierly confident the issue was resolved.

 

Best regards

DPadula

Hi lst3010,

Glad that I could help, once you check again in few days mark the reply as solution to help other on our community. 
Thank you for the reply. 

Regards
DPadula
Broadtec
New Contributor II

I noticed that the system time on the FG-61F was 15 minutes slow, and the NTP time synchronization with time.windows.com had failed for some reason. After correcting the time and running execute update-now, there were no error messages.

However, I was mistaken, as the issue has reappeared.

rfinney
New Contributor

Seeing the same logs starting at 11:42 am EDT yesterday.

srajeswaran

This issue is fixed from IPS Malicious URL Database 5.00088. Could you please try a "exe update-ips" (if its not updated already based on your schedule) and check?

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Broadtec
New Contributor II

This issue resolved itself after 24 hours and did not recur while I was on leave.NO NAME.png

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors