ATP Series - signature Update not always working?

Options
Mario
Mario Posts: 104  Ally Member
First Anniversary 10 Comments Friend Collector Zyxel Certified Network Engineer Level 1 - Security
Hi
I discovered by accident that the signature update on ATP firewalls works very unreliably.
ATP200 with 5.31

ATP200 with 5.30 (AV is from 2022-07-16 -> more then one MONTH!)


on two other Firewalls (ATP200 & ATP500) I did a manual serach for the update, then I have real up-to-date signatures

Can anyone please post the status of his devices?
Thanks
Mario
«1

All Replies

  • AndreaC
    AndreaC Posts: 6
    First Anniversary Friend Collector First Comment
    Options
    I have the same problem on most of the devices updated to version 5.31.
    @Mario you say it is a bug, I have not found information about that.
    Can anyone confirm?
  • mMontana
    mMontana Posts: 1,300  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    For what it's worth... Lab firmware 5.31 Patch0 WK31 (no pun intended) has been released which fixes some of the issues. Lab firmwares for the various ZLD 5.x devices can be found here.
    Devices are dual firmware capable, so maybe for someone upgrade to the latest firmware (the running one or the backup one) might be worth the shot.
    If you wish, wait for Zyxel representatives for confirmation about the reliability of the url provided by me.
    I'm using 4.72 WK28 for some devices of my customers, due to the recent vulnerability disclosure.
  • Zyxel_Kevin
    Zyxel_Kevin Posts: 755  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @Mario, @AndreasC
    Could you kindly install the latest weekly firmware ? The weekly have fixed the issue. 
    https://support.zyxel.eu/hc/en-us/articles/360005438274-Weekly-Firmware-Support-Version-Lab-Version
    Thank you
    Kevin
  • Mario
    Mario Posts: 104  Ally Member
    First Anniversary 10 Comments Friend Collector Zyxel Certified Network Engineer Level 1 - Security
    Options
    Hi Kevin
    I still have problems with FW V5.31(ABFU.0)ITS-22WK31-r104914 on an ATP500.
    See the screenshot from today, signature is from 2022-08-21 and the last check was 2022-08-23 12:51


    After forcing an update I got a new signature from 2022-08-22!
    I created a ticket for this issue.


  • AndreaC
    AndreaC Posts: 6
    First Anniversary Friend Collector First Comment
    Options
    i have the same issue described by mario on ATP200 and on all features. The manual update, updates the definitions correctly, while the scheduled update does not update anything
  • Zyxel_Kevin
    Zyxel_Kevin Posts: 755  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @Mario , @AndreasC
    Please kindly find the Inbox. 
    I have provided Date Firmware, Please confirm if the problem still exists.
    Thank you
    Kevin
     
  • Mario
    Mario Posts: 104  Ally Member
    First Anniversary 10 Comments Friend Collector Zyxel Certified Network Engineer Level 1 - Security
    Options
    @Zyxel_Kevin thanks for the firmware. Installed on 3 device last night, now I keep an eye on it.
  • AndreaC
    Options
    @Zyxel_KevinAfter upgrading an ATP200 from firmware V5.31(ABFW.0)ITS-22WK31 to V5.32(ABFW.0), the antimalware definitions do not update and are stuck on 11/11/2022


    How can i solve this issue?
  • Zyxel_Kevin
    Zyxel_Kevin Posts: 755  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @AndreaC
    Please kindly provide the remote GUI access by private message. 
    Please see inbox , you can restrict those ip addresses . 
    Thank you
    Kevin
  • AndreaC
    Options
    Hi @Zyxel_Kevin today i try one more time manual update as i did yesterday, and Antimalware signature updated to 2.1.1.20221219.0 but Threat Intelligence Machine Learning still at 1.0.0.20221111.0
    I've also noted that other ATP with 5.32 installed does not update antimalware definition, until i manually update.

Security Highlight