Skip to main content
boozely25
New Member
January 19, 2018
Solved

FortiOS Upgrade to 5.6.3

  • January 19, 2018
  • 3 replies
  • 14604 views

We upgraded our 500D from 5.6.2 to 5.6.3. In Policy&Objects-->ipv4 Policy we lost all our section labels, there is no Column Name for Seq #,  and no option that I can find to to Create Section Labels. Is this a bug or is there something we need to turn back on?

    Best answer by bommi

    Fortinet removed the section labels:

    http://kb.fortinet.com/kb/documentLink.do?externalID=FD40956

    3 replies

    bommi
    bommiAnswer
    New Member
    January 19, 2018
    boozely25
    boozely25Author
    New Member
    January 19, 2018

    Thank you

    hecht
    New Member
    January 23, 2018

    This is marked as a know issue.

    I've got an answere from the support team.

    Issue: There is no option to insert section label  Development has made major changes in the back-end of the GUI to fix many GUI related bugs.  Unfortunately, option "insert section label" has been removed from FortiOS v5.6.3.  Development is aware of that and there is a Feature Request already made to get this feature back.  I am afraid nothing much can be done from TAC support point of view, and we do not have an ETA of fix where this is coming back or not.

    The bug is list in the release note as known issues (Bug ID 456566)

     

     

    Jordan_Thompson_FTNT
    Staff
    Staff
    January 23, 2018

    This issue has been fixed in 5.4.8. You will also see a fix in 5.6.4 and 6.0.

     

    The KB article will be updated to reflect that.

    echo
    Explorer II
    February 2, 2018

    We upgraded yesterday. Today when I started creating new rules, I was glad that our huge list of about 800 policies in many sections on our 1500D does not load 20 seconds any more -- after every return to the general list, and on the fastest browser that I could find for this (Firefox, and this used my computer's CPU power as it turned out). But the sections were all expanded. Strange. I collapsed them all one by one and few minutes later I found that they were expanded again when I went back to the list of policies. What? Then I found that thankfully, there is a right-click on any group that helps collapsing them all but returning to the list, they are all expanded. I thought we would open a ticket for this. Now, from the above link I saw that it has been written like that deliberately! Also, pgup, pgdown and arrows don't work when viewing policies (I guess they started working at one point but now it is gone) so I have to use mouse every time to scroll the huge list. I am sorry, but I don't understand this. Still, collapsing the list every time is still quicker than waiting for the list to load so there is improvement in time in everyday work.

    fortiboy
    New Member
    September 15, 2018

    HI

    Kindly advise me best practices to upgrade fortiOS 5.4.3 to 5.4.4 in HA active passive mode.

    i have given 20 minutes of time for MW..

    Do I need to break HA and upgrade one by one

    or any confg alteration to be done to move traffic to secondary ?

    thanks in advance !

     

    Fortiboy

     

     

     

     

    ede_pfau
    SuperUser
    SuperUser
    September 15, 2018

    @fortiboy: why bother to hijack a thread? Opening one yourself is free on these forums...

     

    Anyway, no, you don't need to do anything of what you suggested.

    First, get the backup of both the master and (!) the slave unit - a management port is helpful.

    Second, disable HA port monitoring if used. Re-enable ten minutes after the upgrade when everything has settled.

     

    Then, in the WebGUI, start the upgrade. First, the slave will be upgraded, then the cluster fails over and the master is upgraded. Depending on your HA settings, the cluster will fail over again.

     

    To obtain the shortest possible interruption (in the range of a few seconds) set the HA parameter 'HA priority' equal, and do not enable 'HA override'.

     

    Finally, I would not upgrade to v5.4.4 because v5.4.10 is already published. That is, many bug fixes are available beyond v5.4.4.