Technical Tip: Pre-Upgrade Checklist for FortiMail Firmware Upgrades
Description
This article describes how to prepare for a FortiMail firmware upgrade, including recommended pre-upgrade checks, backup procedures, and validation steps to help ensure a successful upgrade.
Scope
FortiMail.
Solution
Before upgrading the FortiMail firmware, complete the following preparation steps:
Review the Release Notes:
Review the release notes for the target firmware version and pay attention to:
New features and enhancements.
Resolved issues.
Known issues and limitations.
Upgrade considerations and special instructions.
Platform support requirements.
This information helps identify potential impacts to the existing deployment before the upgrade is performed.
Verify the Supported Upgrade Path from the release notes:
Confirm that the planned upgrade path is supported.
To verify:
Check the currently installed firmware version.
Review the upgrade path documentation for the target firmware version.
Perform any required intermediate upgrades if necessary.
Attempting an unsupported upgrade path may result in upgrade failure or unexpected behavior.
Check System Health:
Verify that the FortiMail system is operating normally before proceeding.
Recommended checks:
CPU and memory utilization.
Available disk space.
Mail queue status.
System event logs.
Existing alarms or warnings.
Any existing issues should be resolved before beginning the upgrade.
Back Up the Configuration:
Create a configuration backup before performing the upgrade.
Navigate to: System -> Maintenance -> Backup & Restore.
Save the configuration file to a secure location.
A recent backup allows recovery of the system configuration if required.
Verify Licensing and Support Status:
Confirm that:
The FortiMail license is valid.
Required security services are active.
The support contract is current.
This ensures access to firmware images, documentation, and technical support if assistance is required.
Verify High Availability (HA) Status:
For HA deployments:
Confirm all cluster members are online.
Verify synchronization status.
Review the recommended HA upgrade procedure.
Ensure failover functionality is operating correctly.
Resolving HA issues before upgrading can help prevent service interruptions.
7. Schedule a Maintenance Window:
Plan the upgrade during a maintenance window to minimize impact on mail services.
Consider:
Business operating hours.
Expected upgrade duration.
Rollback requirements.
Stakeholder communication.
Verify Administrative Access:
Ensure the following access methods are available before starting the upgrade:
GUI access.
CLI access.
Console access (if applicable).
Administrative credentials.
Alternative access methods may be required if troubleshooting becomes necessary after the upgrade.
Download the Firmware Image:
Download the firmware image before the maintenance window.
Verify that:
The firmware matches the FortiMail model or VM platform.
The intended firmware version is selected.
The file has been downloaded successfully.
Having the image available locally avoids delays during the upgrade.
Record Current System Information:
Document the current system status, including:
Firmware version.
Network settings.
HA status.
Mail routing configuration.
License information.
This information can be useful for troubleshooting and rollback procedures.
Prepare Post-Upgrade Validation Checks:
After the upgrade is complete, verify:
Mail flow functionality.
SMTP connectivity.
Antispam services.
Antivirus services.
Mail queue processing.
HA synchronization status.
System logs for errors.
