Introduction
This document describes why a Cisco Email Security Appliance (ESA) administrator receives a warning message from an appliance after an upgrade that states that the Sophos Anti-Virus database is expired.
Contributed by Dominic Yip and Stephan Bayer, Cisco TAC Engineers.
Post-AsyncOS Upgrade, "sophos antivirus - The Anti-Virus database on this system is expired" Warning Message
On an ESA, after you upgrade to a new version of AsyncOS and complete the required reboot, an administrator might receive a warning message similar to this:
The Warning message is:
sophos antivirus - The Anti-Virus database on this system is expired. Although the system
will continue to scan for existing viruses, new virus updates will no
longer be available. Please run avupdate to update to the latest engine
immediately. Contact Cisco IronPort Customer Support if you have any
questions.
Current Sophos Anti-Virus Information:
SAV Engine Version 5.33
IDE Serial Unknown
Last Engine Update Tue Mar 7 01:19:08 2017
Last IDE Update Tue Mar 7 01:19:08 2017
Version: 11.0.0-028
Serial Number: 111A80C64EA901221AAA-1A11EB54A111
Timestamp: 13 Mar 2017 14:57:21 -0400
This warning message indicates that the Anti-Virus engine's associated database and rules package are not current for the upgraded version of AsyncOS at the time of appliance startup. The ESA will check for Anti-Virus engine updates after it comes online and will update to the current version.
Verify Current Sophos Version
In order to verify the engine version of Sophos, enter antivirusstatus sophos (or, avstatus sophos) in the CLI in order to view the current Anti-Virus engine version.
myesa.local> avstatus sophos
SAV Engine Version 3.2.07.366.3_5.36
IDE Serial 2017032603
Last Engine Update 26 Mar 2017 13:24 (GMT +00:00)
Last IDE Update 26 Mar 2017 13:24 (GMT +00:00)
Compare the version from the warning message received earlier to the engine version output of the status command. After you validate that the appliance has reached out and updated, you can safely ignore this warning message.
Force Update Sophos
You can also enter the command avupdate force in order to request an immediate update to the Anti-Virus engine and rules. After you enter the force command, enter tail updater_logs in order to view the update in progress. This might take a few minutes to reach out to the updater, get the proper packages, and then download and install as needed. An example of this is:
(myesa.local)> avupdate force
Sophos Anti-Virus updates:
Requesting forced update of Sophos Anti-Virus.
McAfee Anti-Virus updates:
Requesting update of virus definitions
(Machine 122.local)> tail updater_logs
Press Ctrl-C to stop.
Sun Mar 26 09:20:39 2017 Info: Server manifest specified an update for sophos
Sun Mar 26 09:20:39 2017 Info: sophos was signalled to start a new update
Sun Mar 26 09:20:39 2017 Info: sophos processing files from the server manifest
Sun Mar 26 09:20:39 2017 Info: sophos started downloading files
Sun Mar 26 09:20:39 2017 Info: sophos waiting on download lock
Sun Mar 26 09:20:39 2017 Info: sophos acquired download lock
Sun Mar 26 09:20:39 2017 Info: sophos beginning download of remote file
"http://stage-updates.ironport.com/sophos/4.4/ide/default_esa/1490526336"
Sun Mar 26 09:20:41 2017 Info: sophos released download lock
Sun Mar 26 09:20:41 2017 Info: sophos successfully downloaded file
"sophos/4.4/ide/default_esa/1490526336"
Sun Mar 26 09:20:41 2017 Info: sophos waiting on download lock
Sun Mar 26 09:20:41 2017 Info: sophos acquired download lock
Sun Mar 26 09:20:41 2017 Info: sophos beginning download of remote file
"http://stage-updates.ironport.com/sophos/libsavi/1488816512"
Sun Mar 26 09:24:58 2017 Info: sophos released download lock
Sun Mar 26 09:24:58 2017 Info: sophos successfully downloaded file
"sophos/libsavi/1488816512"
Sun Mar 26 09:24:58 2017 Info: sophos started applying files
Sun Mar 26 09:24:58 2017 Info: sophos updating component ide
Sun Mar 26 09:24:58 2017 Info: sophos updating component libsavi
Sun Mar 26 09:24:58 2017 Info: sophos updated engine,ide links successfully
Sun Mar 26 09:24:58 2017 Info: sophos cleaning up base dir /data/third_party/sophos
Sun Mar 26 09:24:58 2017 Info: sophos sending version details
{'sophos': {'version': '5.36', 'ide': '2017032603'}} to hermes
Sun Mar 26 09:24:58 2017 Info: sophos verifying applied files
Sun Mar 26 09:24:58 2017 Info: sophos updating the client manifest
Sun Mar 26 09:24:58 2017 Info: sophos update completed
Sun Mar 26 09:24:58 2017 Info: sophos waiting for new updates
The key in the updater_logs to look for is the "update completed" and "waiting for new updates" log lines. Once those are displayed, you can enter the avstatus sophos command again in order to verify that the version and dates are updated.