Question
How is it possible to export packages from FortiManager FortiGuard in a format that they can then be imported into FortiGate manually (using the: "execute restore <av | ips>" tftp command)?
Background
It is possible to apply AV and IPS packages to a FortiGate by downloading the current packages from FortiCloud and then applying them using the "execute restore <av | ips> tftp commands.
It is also possible to downgrade a FortiGate to a previous AV or IPS package by contacting the TAC and requesting a previous version. TAC will provide the previous package. Before using the execute restore command, you must apply: "diagnose autoupdate downgrade enable". Then, use the "execute restore ..." command to tftp the TAC provided package to the FortiGate. See article: Technical-Tip-How-to-downgrade-or-rollback-IPS-engine
FortiManager FortiGuard Service
FortiManager FortiGuard downloads packages from Fortinet (FDN) and decompresses the package components and then installs those sub components into the FortiManager FortiGuard service. FortiGates are configured to point to the FortiManager FortiGuard service so that they can then download packages from FortiManager FortiGuard. FortiManager FortiGuard can be configured to control which versions of which packages will be downloaded by FortiGates.
It is possible to export the component packages that are stored on the FortiManager.
However, all of my attempts to take any of those packages and apply them to the FortiGates results in errors. The example below was an attempt to restore a package that was exported from FortiManager FortiGuard. Two attempts were made using "other" and "ips" parameters. Both attempts failed.
fortigate (global) # execute restore other tftp /Fortinet/packages/2525_fds_objects_2024-10-18.pkg 172.16.31.15
This operation will overwrite the current other objects!
Do you want to continue? (y/n)y
Please wait...
Connect to tftp server 172.16.31.15 ...
Get other objects from tftp server OK.
Command fail. Return code 49
fortigate (global) # execute restore ips tftp /Fortinet/packages/2525_fds_objects_2024-10-18.pkg 172.16.31.15
This operation will overwrite the current IPS package!
Do you want to continue? (y/n)y
Please wait...
Connect to tftp server 172.16.31.15 ...
Get IPS database from tftp server OK.
Command fail. Return code -64
1) Is there a way to export packages from FortiManager FortiGuard and to restore them onto FortiGates using the "execute restore ..." command?
2) If not, what is the purpose of exporting/importing packages in FortiManager FortiGuard service?
3) Is there a table that lists the meaning of the different error codes (49 and -64 in the example above)?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards
Hello katoomba,
Could you please open a ticket with our support:
https://support.fortinet.com/welcome/#/
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.