First firmware upgrade on an HA cluster and I screwed it up.
We have 2 fortigate 100EF in an HA cluster that needed to be upgraded (were on 7.0.2) and my boss asked if I wanted to give it a shot. He said it was straightforward and that it does the failover itself and all that. Upgrade path was to be .2 -> .5 -> .7 Well I think I got ahead of myself and somehow set the secondary (f2) to upgrade to .7 while the primary (f1) was rebooting to move to .5. This also briefly took down our sites since both FW were down at the same time (we're an e-commerce company).
So now f1 is on 7.0.5 and is the active primary and f2 is on 7.0.7 but f2 is out of sync and f1 still needs to come up to .7... I'm not a real sysadmin or network guy we don't have one. I tried a couple cli commands I saw online. Recalculate, and there was some force sync command too. Neither helped. I also tried the one to force HA failover to make f2 the primary but that didn't either (my boss thought this might help but I guess I wasn't surprised because the HA cluster is basically just 1 box right now I think).
Part of me thinks if I just do the upgrade to .7 on f1 that maybe they'll sync back up and all will be well. Would just have to eat a site outage again for a few minutes while it reboots? Not ideal I know. Another idea the team had was drop f2 out of the cluster but I think without sending someone to the sever farm to be ready to unplug stuff that we would run into network collisions? Any help or thoughts you guys have is appreciated.
