Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
menatwork
New Contributor II

Forticlient stopps updating AV-definitions out of nowhere

Hi folks,

out of nowhere our Forticlients stopped pulling av definitions at about 130 clients. We have not altered our settings. During our tests (after the av-pull stopped working) we tried any variant of fortinet-connectoin (global/us/europe/anycast).

 

Nothing is working. When we do a:

update_task.exe -s vd_01 

 

it does 3 attempts like:

 

attempt 3 of 3
server_ip:fcteuupdate.fortinet.net
port=443
bRetrieveContractOnly=0
get_update_objs(), ip=fcteuupdate.fortinet.net, port=443
Serial number: FCT8001609414060
update_settings.dwRestrictRegions:2

...
...
conn host:fcteuupdate.fortinet.net
conn port:443
7C2B0000:error:8000274C:system library:BIO_connect:Unknown error:crypto\bio\bio_sock2.c:114:calling connect()
7C2B0000:error:10000067:BIO routines:BIO_connect:connect error:crypto\bio\bio_sock2.c:116:
7C2B0000:error:8000274C:system library:conn_state:Unknown error:crypto\bio\bss_conn.c:177:calling connect(fcteuupdate.fortinet.net, 443)
7C2B0000:error:10000067:BIO routines:conn_state:connect error:crypto\bio\bss_conn.c:226:
http_none err:Error connecting to server
FR_connect_compat err! ci:0,ip:f,port:443
...
..

 

Also if we connect a impacted notebook to a separate 4G Router (with no filtering / av ...) the problem persists.

 

Not having the latest av-defs on 130 clients is not that nice... I created a support ticket....

 

Any ideas on this? Any help would be nice.

6 REPLIES 6
menatwork
New Contributor II

Further investigations may indicate that Fortinet is unable to serve update-servers to EU region, with a speed that is enough to do the av-signature updates, cause sometimes e.g. at 02.00am updates are working at my member-servers it seems.

 

This leads me to the opinion that (as I thought) the configuration is ok.

 

If you ask me, this is not acceptable for a product we paid  a high amount of Euros.

I understand that there may be times with some server-troubles, but having about 130 clients with outdated av-sigs for about 3 days+ now and only can watch how things develop, being unable to do anything against, is a great thing.

 

Thank you Fortinet!

 

PS: I know that the "AV" is not the only line of defense.

Anthony_E
Community Manager
Community Manager

Hello menatwork,

 

I m sorry to read your bad experience. I will try to find a FortiClient expert to help you ASAP.

 

Best regards,

Anthony-Fortinet Community Team.
menatwork
New Contributor II

Hello Anthony,

thank you very much. I also have a ticket active, but (and I know this from another ticket we issued concerning Forticlient) this will take time, tons of debug-exports and (most time) leads to nothing.

 

Really no offense, but we are getting more and more annoyed, when it is coming to the Forticlient.

Anthony_E
Community Manager
Community Manager

Oh sincerely there is no offense taken and I just understood you could feel annoyed and did not want you to feel not listened to.

In any case, we will be there anytime and I hope your issues will be solved soon!

Anthony-Fortinet Community Team.
menatwork
New Contributor II

Just for your information. Updates seem like to start working again today (without any action on our side).

 

If this is not weird, I don't know what it is.....

Anthony_E
Community Manager
Community Manager

Thank you for the update!

 

Anthony-Fortinet Community Team.
Labels
Top Kudoed Authors