- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Forticlient 5.09 stopped getting definition update
I have noticed on a handful of my Forticlient's stopped receiving virus definition updates. The log states cannot obtain updates. Update server responded with unauthorized access.
Fortigate version 5.11
Forticlient version 5.09
I have also tried update one of the workstations to 5.2.4 and it still cant get updates.
Thanks
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry. What I meant was it shall be fixed in a further FortiClient release.
You are right that 5.0.11 is not available. The latest is 5.0.10 and it has this bug.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you run from administrative command line: update_task.exe -s fd_01 , and paste the whole output here?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Also what does you logs show for updates?
Ken
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here you go:
C:\Program Files (x86)\Fortinet\FortiClient>update_task.exe -s fd_01 Software update status = -1 Initializing... serial: FGT90D3Z13007514 attempt 1 of 3 Serial number: FGT90D3Z13007514 Try to connect to server 96.45.33.101:80 Server using FCP ver 3.3 support FCT resume data_items: 00000000FSCI00000000000000000000*00000000FDNI00000000000000000000*05 001000FVEN00500-1.26-9999999999*05001000FVDB00500-6.696-9999999999*05000000FVDB0 0000-28.102-1509160608*05000000FVDB01300-28.83-1509151101*05000000FVDB01200-28.1 1-1509120908*05000000FVDB01400-28.102-1509160608*05000000FVDB00200-1.23-11032120 54*05000000FVDB00100-1.637-1311051411*05000000FVEN00100-5.220-9999999999*0500000 0FVEN00600-2.52-9999999999*05000000FVEN00800-5.9-9999999999*05000000FVEN00900-1. 383-9999999999 update process received object(1 of 3): FCPR00000 update process received object(2 of 3): FSCI00000 update process received object(3 of 3): FDNI00000 Now move object FDNI from obj_2_a09104__unpacked to C:\Program Files (x86)\Forti net\FortiClient\vir_sig\fdni.conf
attempt 2 of 3 Serial number: FGT90D3Z13007514 Try to connect to server 96.45.33.99:80 Server using FCP ver 3.3 support FCT resume data_items: 00000000FSCI00000000000000000000*00000000FDNI00000000000000000000*05 001000FVEN00500-1.26-9999999999*05001000FVDB00500-6.696-9999999999*05000000FVDB0 0000-28.102-1509160608*05000000FVDB01300-28.83-1509151101*05000000FVDB01200-28.1 1-1509120908*05000000FVDB01400-28.102-1509160608*05000000FVDB00200-1.23-11032120 54*05000000FVDB00100-1.637-1311051411*05000000FVEN00100-5.220-9999999999*0500000 0FVEN00600-2.52-9999999999*05000000FVEN00800-5.9-9999999999*05000000FVEN00900-1. 383-9999999999 update process received object(1 of 3): FCPR00000 update process received object(2 of 3): FSCI00000 update process received object(3 of 3): FDNI00000 Now move object FDNI from obj_2_a09104__unpacked to C:\Program Files (x86)\Forti net\FortiClient\vir_sig\fdni.conf
attempt 3 of 3 Serial number: FGT90D3Z13007514 Try to connect to server 96.45.33.105:80 Server using FCP ver 3.3 support FCT resume data_items: 00000000FSCI00000000000000000000*00000000FDNI00000000000000000000*05 001000FVEN00500-1.26-9999999999*05001000FVDB00500-6.696-9999999999*05000000FVDB0 0000-28.102-1509160608*05000000FVDB01300-28.83-1509151101*05000000FVDB01200-28.1 1-1509120908*05000000FVDB01400-28.102-1509160608*05000000FVDB00200-1.23-11032120 54*05000000FVDB00100-1.637-1311051411*05000000FVEN00100-5.220-9999999999*0500000 0FVEN00600-2.52-9999999999*05000000FVEN00800-5.9-9999999999*05000000FVEN00900-1. 383-9999999999 update process received object(1 of 3): FCPR00000 update process received object(2 of 3): FSCI00000 update process received object(3 of 3): FDNI00000 Now move object FDNI from obj_2_a09104__unpacked to C:\Program Files (x86)\Forti net\FortiClient\vir_sig\fdni.conf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here are what the logs say.
9/28/2015 2:00:03 AM Notice Update id=96823 msg="Checking for updates." 9/28/2015 2:00:03 AM Notice Update id=96813 msg="Software updates are disabled." 9/28/2015 5:00:06 AM Notice Update id=96823 msg="Checking for updates." 9/28/2015 5:00:06 AM Notice Update id=96813 msg="Software updates are disabled." 9/28/2015 7:23:56 AM Notice Console id=96810 user= msg="Customer initiated a software update request." 9/28/2015 7:23:56 AM Notice Update id=96823 msg="Checking for updates." 9/28/2015 7:23:56 AM Notice Update id=96813 msg="Software updates are disabled." 9/28/2015 8:00:02 AM Notice Update id=96823 msg="Checking for updates." 9/28/2015 8:00:02 AM Notice Update id=96813 msg="Software updates are disabled." 9/28/2015 9:58:49 AM Notice Update id=96823 msg="Checking for updates." 9/28/2015 9:58:49 AM Notice Update id=96813 msg="Software updates are disabled."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you make changes in your profile for the client? I would look at the following in your xml syntax;
<update> <use_custom_server>0</use_custom_server> <server></server> <port></port> <failoverport>0</failoverport> <fail_over_to_fdn>1</fail_over_to_fdn> <update_action>notify_only</update_action> <scheduled_update> <enabled>0</enabled> <type>interval</type> <update_interval_in_hours>1</update_interval_in_hours> </scheduled_update> </update>
) disable 1 enabled
Also ensure fortiguard lookups are working, if it can't find the FGS than it can't acquire the updates. Also if you using any proxies , make sure they are allowing the updates.
They the client asks for the update based on the list of fgs servers & needs access to these.
e.g
208.91.112.139 HTTP /fdsupdate
Ken
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you unregister the fortigate does the FClient work with gaining updates?
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes it works when I unregister it. So does that indicate a issue with the Fortigate firewall?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes
So is the FW active with a subscription license? And is updated?
Please run diag debug app update -1 and then execute update-av
Does this fail? Is the source-ip good ?
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I entered those commands on the fortigate and nothing happens
The unit is up to date with Fortiguard subscriptions
