Troubleshooting Tip: Unable to boot the firewall or load firmware image
| Description | This article describes an issue that prevents booting the firewall or loading a firmware image and offers a solution. |
| Scope | FortiGate v6.X and v7.X. |
| Solution | The error appears as one of the following:
Fatal error: Loading FOS fails!
Or:
Fatal error: AV engine file authentication failed!
To solve the issue, follow the steps below.
Note: The following procedure requires a console cable. These actions cannot be performed via SSH or GUI web console, as the connection will be lost during the reboot.
Step 1: Restart the Firewall using the CLI. While the device restarts, press any key to see boot options.
Initializing boot device... Initializing MAC... NP6XLITE#0 Please wait for OS to boot, or press any key to display the configuration menu. [C]: Configure TFTP parameters. [R]: Review TFTP parameters. [T]: Initiate TFTP firmware transfer. [F]: Format boot device. [I]: System information. >>>>>>>>>>>>>>>>>> Select This Option [B]: Boot with backup firmware and set as default. [Q]: Quit menu and continue to boot. [H]: Display this list of options.
Step 2: Enter option I.
Enter C,R,T,F,I,B,Q,or H: [S]: Set serial port baudrate. [R]: Set restricted mode. [T]: Set menu timeout. [U]: Set security level. [I]: Display system information. [E]: Reset system configuration. [P]: Normal POST test. [Q]: Quit this menu. [H]: Display this list of options.
Step 3: Enter option U.
Enter C,R,T,F,I,B,Q,or H: [S]: Set serial port baudrate. [R]: Set restricted mode. [T]: Set menu timeout. [U]: Set security level. [I]: Display system information. [E]: Reset system configuration. [P]: Normal POST test. [Q]: Quit this menu. [H]: Display this list of options.
Step 4: Enter option 1to set the security level to 1.
Enter option 1 to set security level to 1 Enter S,R,T,U,I,E,P,Q,or H: [0]: Level 0 - Check image silently [1]: Level 1 - Check image with result only [2]: Level 2 - Check image and reinforce validity Enter security level setting [2]:. Done
Step 5: Load the firmware image from the TFTP server. This can be done by following the steps seen in this KB article: Technical Tip: Formatting and loading FortiGate firmware image using TFTP
Note: If the user is getting a System Halt message during boot like this:
System is starting... If it is running v6.4.13, v7.0.12, 7.2.5, or 7v.4.0, it is necessary to change the BIOS/Security level to 1 or 0. This issue has been resolved in v6.4.15:2115, v7.0.13:0550, v7.2.6:1548, v7.4.1:2413.
Related articles: Technical Tip: Loading FortiGate firmware image using TFTP. Technical Tip: Installing firmware from system reboot. Troubleshooting Tip: Downgrade of FortiOS fails due to BIOS check Enhance BIOS-level signature and file integrity checking - FortiGate 7.4.0 new features |
