Skip to main content
adGmail
New Member
February 25, 2020
Solved

FG on 5.6 ADOM on 5.4

  • February 25, 2020
  • 2 replies
  • 3040 views

Hi All,

 

As i start upgrading Fortigates, i'll be in an interim configuration where some of the firewalls are on 5.6, but the ADOM is still  on 5.4. What limitations are there in this configuration?

 

Is it still possible to provision new VDOMs on a 5.6 firewall?

Can I still pull migrated policy from a newly created VDOM on a 5.6 firewall?

 

Thanks

    Best answer by Alexis_G

    You are supposed not to use FMG with the upgraded in 5.6 FGTs (push policy).

    If meanwhile upgrading all Fortigates there are some in 5.6 and some other in 5.4, you could directly edit policies in 5.6 FGTs and when  finally you upgrade ADOM then you can retrieve configuration and policies from all FGTs.

    Hope it helps

     

    2 replies

    Alexis_G
    Alexis_GAnswer
    New Member
    February 25, 2020

    You are supposed not to use FMG with the upgraded in 5.6 FGTs (push policy).

    If meanwhile upgrading all Fortigates there are some in 5.6 and some other in 5.4, you could directly edit policies in 5.6 FGTs and when  finally you upgrade ADOM then you can retrieve configuration and policies from all FGTs.

    Hope it helps

     

    sw2090
    SuperUser
    SuperUser
    February 25, 2020

    I have done similar but from 5.6 to 6.0. Unfortunately FMG is screwed up on this. The only way to do this and not do anything completely anew is the way you wrote. Even TAC agrees with this but does not recommend it

    When I did this I completely lost all interface mappings in FMG first. TAC found a way to re-apply a backup to get them back. Still this sucks majorly. Seems to be a case Fortinet did not really consider :\

     

    The recommended way would be to remove the FGT from the Adom, upgrade it and put it into a new admon for the new firmare version. But this would require me to redo 100s of interface and address mappings and also it would create a load of useless policy packages. Also I would have to redo the complete default policy package for the new adom since you cannot export or import it. This is not what I understand in central management....

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!