Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nflnetwork29
New Contributor III

FortiGuard IPS Service

How do i force an update of the IPS db? I did a quick check and got this error message. 

 

    • Databases: Virus, IPS, Application Control, etc. versions and dates are listed. Critically, the IPS and Proxy-IPS databases are from 2015.
  1. IMMEDIATELY UPDATE THE IPS AND PROXY-IPS DATABASES. This is the top priority due to the significant security vulnerability. Check other database versions as well.
3 REPLIES 3
dingjerry_FTNT

Hi @nflnetwork29 ,

 

You may run "exe update-ips" to manually update the IPS DB/Engine.

Regards,

Jerry
nflnetwork29

it appears they are still not updating correctly

 

Attack Definitions
---------
Version: 6.00741 signed
Contract Expiry Date: Tue Jun 8 2027
Last Updated using manual update on Tue Dec 1 02:30:00 2015
Last Update Attempt: Sun Jan 19 08:24:44 2025
Result: Connectivity failure

 

 

Proxy Attack Definitions
---------
Version: 6.00741 signed
Contract Expiry Date: Tue Jun 8 2027
Last Updated using manual update on Tue Dec 1 02:30:00 2015
Last Update Attempt: Sun Jan 19 08:24:44 2025
Result: Connectivity failure

 

nflnetwork29

Are these settings optimal?


@nflnetwork29 wrote:

it appears they are still not updating correctly

 

Attack Definitions
---------
Version: 6.00741 signed
Contract Expiry Date: Tue Jun 8 2027
Last Updated using manual update on Tue Dec 1 02:30:00 2015
Last Update Attempt: Sun Jan 19 08:24:44 2025
Result: Connectivity failure

 

 

Proxy Attack Definitions
---------
Version: 6.00741 signed
Contract Expiry Date: Tue Jun 8 2027
Last Updated using manual update on Tue Dec 1 02:30:00 2015
Last Update Attempt: Sun Jan 19 08:24:44 2025
Result: Connectivity failure

 


show full-configuration ips global
config ips global
set fail-open disable
set database extended
set traffic-submit enable
set anomaly-mode continuous
set session-limit-mode heuristic
set socket-size 64
set engine-count 0
set sync-session-ttl enable
set np-accel-mode basic
set ips-reserve-cpu disable
set cp-accel-mode advanced
set deep-app-insp-timeout 0
set deep-app-insp-db-limit 0
set exclude-signatures ot
set packet-log-queue-depth 128
set ngfw-max-scan-range 4096
set av-mem-limit 0
config tls-active-probe
set interface-select-method auto
end
end

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors