Solution |

To perform a downgrade from FortiOS v7.2.5 + to FortiOS v6.4 - use a different security level (the default is security level 2) in the BIOS options. Power down the FortiGate and interrupt the booting sequence once it is booting up by pressing any key at the first prompt. Follow the steps below:
 Press any key to display configuration menu...
.............................
[C]: Configure TFTP parameters.
[R]: Review TFTP parameters.
[T]: Initiate TFTP firmware transfer.
[F]: Format boot device.
[I]: System information.
[B]: Boot with backup firmware and set as default.
[Q]: Quit menu and continue to boot.
[H]: Display this list of options.
Enter C,R,T,F,I,B,Q,or H: <--- Press 'I' for System Information
[S]: Set serial port baudrate.
[R]: Set restricted mode.
[T]: Set menu timeout.
[U]: Set security level.
[I]: Display system information.
[E]: Reset system configuration
[Q]: Quit this menu.
[H]: Display this list of options.
Enter S,R,T,U,I,E,Q,or H:
Press 'U' for 'Set security level':
 Â In the security level menu, choose 'Use security level 1 or 0'. Perform the reboot again - the FortiGate will reboot with FortiOS v6.4.
Note: When upgrading back to higher FortiOS v7.2.5+ or above, ensure that the Security Level is set to 0.
If FortiGate runs with newer BIOS version which supports only new Security Level Naming convention with level low (level 1) and high (level 2) then FortiOS upgrade will fail and the only possible option would be booting from secondary partition or image firmware restoration from BIOS menu.
Related documentation: |