Skip to main content
jasonhong
Staff & Editor
Staff & Editor
January 2, 2023

Technical Tip: How to download and import firmware images into FortiManager

  • January 2, 2023
  • 0 replies
  • 11750 views

Description

 

This article describes how to manually download firmware images from the Fortinet support portal and import them into FortiManager. For this demonstration, a FortiGate will be upgraded using a manually imported firmware image in FortiManager.

 

Scope

 

FortiManager.

 

Solution

 

  1. When upgrading a FortiGate via FortiManager via the toolbar option under More -> Firmware Upgrade, the user will be presented with a list of available firmware versions from FortiGuard. Once the preferred firmware version is selected, FortiManager will proceed to download the firmware image from the public FortiGuard servers before loading it into the FortiGate device for the upgrade process.

  2. In case the download was stuck, it is possible to use public DNS instead or try performing the below config change on FortiManager CLI, then restart the FDS service and test downloading the image:

config fmupdate service
unset avips
end


To restart the FDS service:

diagnose fmupdate service-restart fds


firmwareupgrade.png

 

fgdimages.png

 

  1. As an alternative to FortiManager downloading the firmware image from the public FortiGuard server (check the related article to see if FortiManager is properly connected to FortiGuard), the user can manually download the firmware image from the Fortinet Support Portal (support.fortinet.com/Download/FirmwareImages.aspx) and then import the downloaded firmware image into FortiManager by navigating to FortiGuard -> Firmware Images -> Local Images and selecting 'Import'.

 

This benefits the user in terms of having the firmware image locally present in FortiManager before the FortiGate device upgrade to reduce the time needed to have FortiManager download the firmware image from the public FortiGuard server during the upgrade process.

 

importimage.png

 

  1. Once the firmware image is downloaded from the support portal and imported into FortiManager as a local image, the user will be able to select the imported local image in FortiManager during the upgrade process.

 

localimage.png


Note:

Take the configuration backup from FortiGate and FortiManager before the firmware upgrade, just incase need to revert to the previous firmware version.

Make sure the FortiGate serial number is mentioned in the FortiManager database contract details with a valid firmware contract if the firmware upgrade is going to be done using FortiManager.

 

Confirm through the output of this command and check the date beside the 'FMWR' section in the output.

 

diagnose fmgupdate dbcontract <FortiGate Serial number>

 

Related documents:

Technical Tip: Using Firmware Manager CLI and API

CLI command to confirm if FMG is communicating with FDS server

Technical Tip: Verifying FortiGuard connectivity on FortiManager

Technical Tip: Upgrading FortiManager/FortiAnalyzer best practice

Technical Tip: How to locate a FortiAnalyzer device image for upgrade/reinstallation in a support site

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!