Skip to main content
srsiddiqui
New Member
September 2, 2018
Question

FortiOS 5.2.10 - 5.4.1 RMA Claimed

  • September 2, 2018
  • 1 reply
  • 11581 views

Hi,

As per the TAC recommendations we had to Flash Format the 100D and eventually it didn't came back up. FortiOS version 5.2.10

 

So we have got the RMA claimed with FortiOS 5.4.1. Since the support contract was 24x7 but we received the device on 4th day after the claim was initiated and was bit in hurry to live it. So we have imported the config of 5.2.10 to 5.4.1 and started working. This was 3 weeks back. Link Monitor was configured with 2 ISP's

 

Started facing issues with all the options enabled on a single policy that is UTM, Deep inspection & SSL Certificate that users complaining that Websites are not opening properly "the webpage is unreachable", Error Connection Timeout, Error Connection Closed, DNS Host Suffix issues on three major browsers

 

As per TAC, The current configuration which you have on the fortigate is corrupted as well. Hence, you will have to flash format the box. Install 5.2.10 and reload configuration of 5.2.10. Then you can go to firmware 5.4.1 following a proper upgrade path. Upgrade path information is present in the support portal. Unfortunately, you will have to redo all the configurations which you had done on 5.4.1 in those 3 weeks

 

If UTM features in disabled in policy then there is no issue in Browsing

 

Since their is a lot of configuration done, device was running in Head Office. If we try to redo the complete config than it will take around 3-4 days of downtime which is not possible at all. Further if something missed out than it will be managed afterwards.

 

Is there any work around for converting the configuration of 5.2.10 to 5.4.1, remove Link-Monitor config part and again configure WAN LLB in order to minimize the downtime to max 1 day.

    1 reply

    SecurityPlus
    Explorer III
    September 2, 2018
    Was your 100D firewall working properly when running 5.2.10? Do you have a config backup when it was running 5.2.10 successfully? What prompted using or upgrading to FortiOS 5.4.1?
    srsiddiqui
    New Member
    September 2, 2018

    yes 100D was working fine before, before RMA the device was having ongoing CPU spike issues and have to restart the firewall sometimes 2-3 times a day or after 7-10 working days

     

    Yes i have the backup with me

     

    New device came with 5.4.1, I didnt downgraded it