Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Katoomba
New Contributor III

FortiManager FortiGuard Exporting Packages and Manually Restoring onto FortiGates

Question

How is it possible to export packages from FortiManager FortiGuard in a format that they can then be imported into FortiGate manually (using the: "execute restore <av | ips>" tftp command)?

 

Background

It is possible to apply AV and IPS packages to a FortiGate by downloading the current packages from FortiCloud and then applying them using the "execute restore <av | ips> tftp commands.

It is also possible to downgrade a FortiGate to a previous AV or IPS package by contacting the TAC and requesting a previous version. TAC will provide the previous package. Before using the execute restore command, you must apply: "diagnose autoupdate downgrade enable". Then, use the "execute restore ..." command to tftp the TAC provided package to the FortiGate. See article: Technical-Tip-How-to-downgrade-or-rollback-IPS-engine

 

FortiManager FortiGuard Service

FortiManager FortiGuard downloads packages from Fortinet (FDN) and decompresses the package components and then installs those sub components into the FortiManager FortiGuard service. FortiGates are configured to point to the FortiManager FortiGuard service so that they can then download packages from FortiManager FortiGuard. FortiManager FortiGuard can be configured to control which versions of which packages will be downloaded by FortiGates.

It is possible to export the component packages that are stored on the FortiManager.

However, all of my attempts to take any of those packages and apply them to the FortiGates results in errors. The example below was an attempt to restore a package that was exported from FortiManager FortiGuard. Two attempts were made using "other" and "ips" parameters. Both attempts failed.

 

 

 

fortigate (global) # execute restore other tftp /Fortinet/packages/2525_fds_objects_2024-10-18.pkg 172.16.31.15
This operation will overwrite the current other objects!
Do you want to continue? (y/n)y
Please wait...
Connect to tftp server 172.16.31.15 ...
Get other objects from tftp server OK.
Command fail. Return code 49

fortigate (global) # execute restore ips tftp /Fortinet/packages/2525_fds_objects_2024-10-18.pkg 172.16.31.15
This operation will overwrite the current IPS package!
Do you want to continue? (y/n)y
Please wait...
Connect to tftp server 172.16.31.15 ...
Get IPS database from tftp server OK.
Command fail. Return code -64

 

 

 

1) Is there a way to export packages from FortiManager FortiGuard and to restore them onto FortiGates using the "execute restore ..." command?

2) If not, what is the purpose of exporting/importing packages in FortiManager FortiGuard service?

3) Is there a table that lists the meaning of the different error codes (49 and -64 in the example above)?

Katoomba
Katoomba
0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors