Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chpa
New Contributor

No updates on my IPS Engine

Hello,

 

I have a problem to update automatically my IPS Engine.

Actually I have a cluster of Fortigate-200D and configured some vdoms. Here my output of the command "get system auto-update versions".

 

IPS Attack Engine --------- Version: 3.00430 Contract Expiry Date: Mon Apr 30 2018 Last Updated using manual update on Thu Sep 14 12:55:16 2017 Last Update Attempt: Sun Jun 18 15:56:24 2017 Result: No Updates

Can someone help me ?

 

Thanks

21 REPLIES 21
emnoc
Esteemed Contributor III

Hmm

 

 

Maybe a reboot or call to  suppport.  But before you do that, re-run a diag sniffer packet < interface name>  "host  place the  fortiguard server address  and tcp"

 

 

e.g

 

diag sniffer packet wan1 "host 209.222.136.7 and tcp"

 

Do you see any SYN and SYN-ACK?

 

if yes, that means you hit the server? If you see no traffic than maybe back to DNS  settings? Do you see your device talking to  DNS servers that are configured ?

 

 

e.g

 

diag sniffer packet wan1 "host 1.1.1.1. and port 53" 5

 

 

1.1.1.1 would be your  wan1 or   address used for  DNS  sources. You should see some message that has  DNS fortinet in the output

 

 

   dns-version-1.fortinet.com

 

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
chpa
New Contributor

I know it's been a while but the problem has not resolved.

I do a diag sniffer packet wan1 "host 96.45.33.82 and tcp" but I see only syn packet and not syn-ack from Fortinet update server.

diag sniffer packet wan1 "host 96.45.33.80 and tcp" interfaces=[wan1] filters=[host 96.45.33.80 and tcp] 5.168706 x.x.x.x.11050 -> 96.45.33.80.443: syn 1428589376 29.168579 x.x.x.x.11050 -> 96.45.33.80.443: syn 1428589376

has anybody any idea about this problem ?Any suggestion ?

 

Thanks in advance

Labels
Top Kudoed Authors