Signature upgrade

This help contains the following topics:

Introduction

A signature library is a collection of common signatures used for service identification. The company's official website releases up-to-date signatures in the form of signature library files. You can manually download the files or configure the device to automatically download the files to update the signature libraries. You can also restore the signature library to the factory defaults for a service module. The signature libraries include the IPS signature library, URL filtering signature library, Web application protection, location identification signature library, APR signature library, virus signature library, IP reputation signature library, URL reputation signature library, and domain reputation signature library.

Signature library upgrade

The following methods are available for updating the signature library for a DPI service module:

Signature library rollback to factory defaults

If filtering false alarms or filtering exceptions occur on a DPI service module frequently, you can roll back its signature library to the factory default version.

vSystem support information

Support of non-default vSystems for this feature depends on the device model. This feature is available on the Web interface only if it is supported.

Licensing requirements

To upgrade the signature library for a DPI service module such as APR, IPS, anti-virus, Web application protection, URL filtering, IP reputation, domain reputation, or URL reputation, you must purchase and install the required license. After the license for a DPI service module expires, you can still use the existing signature library, but you can no longer upgrade the signature library. For more information about licensing, see the license management help.

Restrictions and guidelines

Configure signature library upgrade and rollback

You can configure a proxy server through which the device can access the company's official website for automatic or immediate online signature library update.

Configure automatic signature library update

Perform this task to configure automatic signature library update for a DPI service module.

For automatic signature library update to work correctly, make sure the device can access the company's official website to obtain the latest signature file.

Procedure

  1. Click the System tab.

  2. In the navigation pane, select Upgrade Center > Signature Upgrade.

  3. Click the box in the Auto update column for a signature library.

    In this example, click the box in the Auto update column for the IPS signature library.

    The Configure Scheduled Update For IPS Signature Library window opens.

  4. Set the scheduled update time.

    The automatic signature library update starts actually at a random time between the following time points:

    • One hour before the scheduled update time.

    • One hour after the scheduled update time.

  5. Click OK.

Trigger immediate online update

Anytime you find a release of new signature library version on the company's official website, you can trigger the device to immediately update the local signature library.

Procedure

  1. Click the System tab.

  2. In the navigation pane, select Upgrade Center > Signature Upgrade.

  3. Click Online update in the Actions column for the signature library.

  4. Click OK in the confirmation dialog box that opens.

Perform a manual signature library update

Perform this task to manually update the signature libraries for DPI service modules by using locally stored signature files.

Use this method if the device cannot access the signature database services on the company's official website.

Store the update file on the master device for successful signature library update.

Procedure

  1. Click the System tab.

  2. In the navigation pane, select Upgrade Center > Signature Upgrade.

  3. On the page that opens, click Signature Database Services in the Actions column for a signature library to access the signature database service area at the official website. You can download signature files as needed.

  4. Click Manual update in the Actions column for a signature library. In this example, click Manual update for the IPS signature library.

    The Update IPS Signature Library window opens.

  5. Click Select to select the local update file.

  6. Click OK.

Configure the signature library server

To update the signature library, the device must access the signature library server on the company's official website to obtain the signature file.

Perform this task to configure the signature library server parameters.

Procedure

  1. Click the System tab.

  2. In the navigation pane, select Upgrade Center > Signature Upgrade.

  3. Click Configure Signature Library Server.

    The Configure Signature Library Server window opens.

  4. Configure the signature library server settings.

    Table-1 Signature library server configuration items

    Item

    Description

    Source IP

    Configure the source IP address used by the device to send online upgrade request packets to the signature library server.

    • Specify a source interface—Select this option and then select an interface from the interface list. The device uses the IP address of the specified interface as the source IP address of online upgrade request packets.

    • Specify a source IP—Select this option and then specify the IP address type and enter the IP address. The specified IP address is used as the source IP address of online upgrade request packets.

    Destination VRF

    Configure the VRF to which the signature library server belongs. When the device is connected to the signature library server through VRF, you must specify the VRF in this field. If you do not specify the VRF, signature library upgrade will fail.

  5. Click OK.

Test signature library server connectivity

Signature library server connectivity test identifies the connection status between the device and the signature library server during a signature library upgrade to confirm successful connection to the server. After you click Test signature library server connectivity, the device will attempt to connect to the signature library server and return the result of the connection status. If the connection fails, the administrator can troubleshoot connection issues based on the interface prompts, ensuring that the device can successfully perform a signature library upgrade.

To test signature library server connectivity:

  1. Click the System tab.

  2. In the navigation pane, select Upgrade Center > Signature Upgrade.

  3. Click Test signature library server connectivity. The device will attempt to connect to the signature library server and return the result of the connection status.

Configure a proxy server

The device must access the company's official website for immediate or scheduled signature library update. If direct connectivity is not available, the device can access the company's official website through the specified proxy server.

Procedure

  1. Click the System tab.

  2. In the navigation pane, select Upgrade Center > Signature Upgrade.

  3. Click Configure proxy server.

    The Configure Proxy Server window opens.

  4. Configure the proxy server settings, including the server address, port number, login username, and login password.

  5. Click OK.

Roll back a signature library

  1. Click the System tab.

  2. In the navigation pane, select Upgrade Center > Signature Upgrade.

  3. Click Roll back in the Actions column for a signature library. In this example, click Roll back for the IPS signature library.

    The Roll Back IPS Signature Library window opens.

  4. Select Roll back to factory default.

  5. Click Apply.