Skip to main content
bhagat_sudhir
New Member
October 12, 2015
Solved

Active - Passive Firmware upgrade Process

  • October 12, 2015
  • 9 replies
  • 25263 views

Hi Experts,

 

We are running Fortigate 300C firewall in HA (Active - Passive). Pls share step-by-step process for upgrading the Firmware for Active Passive HA (remotely).

 

Regards

SB 

    Best answer by awasfi_FTNT

    Hello,

     

    Please refer to the following document (page 176):

    http://docs.fortinet.com/d/fortigate-high-availability-ha-2

     

    Recommend before the upgrade:

    1) Check the release notes for supported upgrade path, special notices, product integration, known issues and limitations if any.

    2) Backup configuration before and after each upgrade.

    3) Plan a maintenance window for the upgrade.

    3) Have some one available on the remote site in case something went wrong during the upgrade.

    4) Make sure check sum is matching between cluster members using the following CLI commands:

    # get sys ha status # diag sys ha showcsum

    # execute ha manage <Slave ID>   <<-- could be 0 or 1, check "get sys ha status" results

    $ diag sys ha showcsum

    $ exit

     

    The results of "diag sys ha showcsum" should be the same on all levels (all/global/vdoms)

     

    Regards,

    9 replies

    bhagat_sudhir
    New Member
    October 13, 2015

    please reply

    awasfi_FTNT
    Staff
    Staff
    October 13, 2015

    Hello,

     

    Please refer to the following document (page 176):

    http://docs.fortinet.com/d/fortigate-high-availability-ha-2

     

    Recommend before the upgrade:

    1) Check the release notes for supported upgrade path, special notices, product integration, known issues and limitations if any.

    2) Backup configuration before and after each upgrade.

    3) Plan a maintenance window for the upgrade.

    3) Have some one available on the remote site in case something went wrong during the upgrade.

    4) Make sure check sum is matching between cluster members using the following CLI commands:

    # get sys ha status # diag sys ha showcsum

    # execute ha manage <Slave ID>   <<-- could be 0 or 1, check "get sys ha status" results

    $ diag sys ha showcsum

    $ exit

     

    The results of "diag sys ha showcsum" should be the same on all levels (all/global/vdoms)

     

    Regards,

    ede_pfau
    SuperUser
    SuperUser
    October 14, 2015

    As best practice, reboot the cluster before upgrading.

    For a A/P cluster the actual downtime during a cluster reboot is quite short, maybe 9 pings.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!