FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
lmarinovic
Staff
Staff
Article Id 195508

Description

 

This article describes the officially supported upgrade path for FortiAuthenticator.

 

Be aware that downgrading will reset the FortiAuthenticator settings to FACTORY-DEFAULT.
FortiAuthenticator can only be reverted to a previous working version by restoring an existing config backup.
It is recommended to create a config backup before performing each upgrade.

 

Scope

 

FortiAuthenticator.


Solution

 

Before upgrading it is recommended to research the Release Notes and check for Known Issues and New Features.
 
Release Notes state provide information about which FortiAuthenticator models are supported and which firmware releases it is supported to upgrade from.


The following are the supported upgrade paths for FortiAuthenticator:

 

Upgrade path to v.6.6.2 through other v6.6.x:

  • 6.2.1 → 6.5.4 → 6.6.1 → 6.6.2.

  • 6.1.0 → 6.2.0 → 6.3.3 → 6.6.1 or 6.6.2.

  • 6.0.7 → 6.6.1 or 6.6.2.

  • 6.2.1 → 6.5.4 → 6.6.0 → 6.6.2.

  • 6.1.0 → 6.2.0 → 6.3.3 → 6.6.0 → 6.6.2.

  • 6.0.7 → 6.6.0 → 6.6.2.

 

Upgrade path to v.6.6.2 through v6.5.x:

  • 6.2.1 → 6.5.3 or  6.5.5 → 6.6.2.

  • 6.1.0 → 6.2.0 → 6.3.3 → 6.5.5 → 6.6.2.

  • 6.0.7 → 6.5.5 → 6.6.2.

  • 6.2.1 → 6.5.2 → 6.5.3 → 6.5.5 → 6.6.2.

  • 6.1.0 → 6.2.0 → 6.3.3 → 6.5.3 → 6.5.5 → 6.6.2.

  • 6.0.7 → 6.5.3 → 6.5.5 → 6.6.2.

  • 6.5.0 → 6.5.1 → 6.5.2 → 6.5.3 → 6.5.5 → 6.6.2.

 

Upgrade path to v.6.6.2 through v6.4.x:

  • 6.2.1 → 6.3.x → 6.4.X → 6.5.6 → 6.6.2.

  • 6.1.0 → 6.2.0 → 6.3.3 → 6.4.X → 6.5.6 → 6.6.2.

  • 6.0.7 → 6.4.X → 6.5.6 → 6.6.2.

 

From older versions:

  • 3.2.1 → 3.3.0 → 4.0.0 → 6.0.4 → 6.0.5 → 6.0.7 → 6.4.X → 6.5.6 → 6.6.2.

  • 3.2.1 → 3.3.0 → 4.0.0 → 6.0.4 → 6.3.3 → 6.4.X → 6.5.6 → 6.6.2.

  • 3.2.1 → 3.3.0 → 4.0.0 → 6.0.4 → 6.2.1 → 6.4.X → 6.5.6 → 6.6.2.

 

FortiAuthenticator v6.6.2 requires at least 4GB of RAM.

FortiAuthenticator v6.6.2 build 1669 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.6.2, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator v6.0.7, then upgrade to v6.6.2 directly.

  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to 6.3.3, then upgrade to v6.6.2.

  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade to 6.6.2 directly.

  • Keep in mind that SHA1 signing algorithms are no longer supported as per release notes. 
  • These certificates can be used in LDAP, SAML, Syslog, SCEP/CMP, SSO Mobility agent, or admin UI. If this signing algorithm is used, see to change the certificate before the upgrade. Upgrading without doing so may severely impact the environment.

 

FortiAuthenticator v6.6.1 requires at least 4GB of RAM.

FortiAuthenticator v6.6.1 build 1660 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.6.1, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator v6.0.7, then upgrade to 6.6.1 directly.

  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.6.1.

  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade to 6.6.1 directly.

  • Keep in mind that SHA1 signing algorithms are no longer supported as per release notes. 

  • These certificates can be used in LDAP, SAML, Syslog, SCEP/CMP, SSO Mobility agent or admin UI. If this signing algorithm is used, see to change the certificate before the upgrade. Upgrading without doing so may severely impact the environment.

 

FortiAuthenticator v6.6.0 requires at least 4GB of RAM.

FortiAuthenticator v6.6.0 build 1617 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.6.0, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator v6.0.7, then upgrade to 6.6.0 directly.

  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to v6.3.3, then upgrade to v6.6.0.

  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade to v6.6.0 directly.

  • Keep in mind that SHA1 signing algorithms are no longer supported as per release notes. 

  • These certificates can be used in LDAP, SAML, Syslog, SCEP/CMP, SSO Mobility agent, or admin UI. If this signing algorithm is used, see to change the certificate before the upgrade. Upgrading without doing so may severely impact the environment.

 

FortiAuthenticator v6.5.6 requires at least 4GB of RAM.

FortiAuthenticator v6.5.6 build 1391 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to 6.0.7, then upgrade to v6.5.6, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator v6.0.7, then upgrade to 6.5.6 directly.

  • If currently running FortiAuthenticator between v6.1.0 and 6.2.0, first upgrade to v6.3.3, then upgrade to v6.5.6.

  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade tov 6.5.6 directly.

 

FortiAuthenticator v6.5.5 requires at least 4GB of RAM.

 

FortiAuthenticator 6.5.5 build 1385 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.5.5, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.
  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.5.5 directly.
  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.5.5
  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.5.5 directly.

 

FortiAuthenticator v6.5.4 requires at least 4GB of RAM.

FortiAuthenticator v6.5.4 build 1377 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to 6.0.7, then upgrade to v6.5.4, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator v6.0.7, then upgrade to v6.5.4 directly.

  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to v6.3.3, then upgrade to v6.5.4.

  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade to 6.5.4 directly.

 

FortiAuthenticator v6.5.3 requires at least 4GB of RAM.

FortiAuthenticator v6.5.3 build 1355 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.5.3, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator v6.0.7, then upgrade to v6.5.3 directly.

  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to v6.3.3, then upgrade to v6.5.3.

  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade to v6.5.3 directly.

 

FortiAuthenticator v6.5.2 requires at least 4GB of RAM.

FortiAuthenticator v6.5.2 build 1329 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.5.2. Otherwise, the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.
  • If currently running FortiAuthenticator v6.0.7, then upgrade to v6.5.2 directly.
  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to v6.3.3, then upgrade to v6.5.2.
  • If currently running FortiAuthenticator v6.2.1 or later, upgrade to v6.5.2 directly.

 

FortiAuthenticator v6.5.1 requires at least 4GB of RAM.

FortiAuthenticator 6.5.1 build 1295 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.5.1, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance.
  • If currently running FortiAuthenticator v6.0.7, then upgrade to v6.5.1 directly.
  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to v6.3.3, then upgrade to v6.5.1.
  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade to v6.5.1 directly.

 

FortiAuthenticator v6.5.0 requires at least 4GB of RAM.

FortiAuthenticator v6.5.0 build 1286 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.5.0. Otherwise, the following message will display: 'Image validation failed: The firmware image model number is different from the appliance's.'
  • If currently running FortiAuthenticator v6.0.7, then upgrade to v6.5.0 directly.
  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to v6.3.3, then upgrade to v6.5.0.
  • If currently running FortiAuthenticator v6.2.1 or later, then upgrade to v6.5.0 directly.


FortiAuthenticator v6.4.X.

FortiAuthenticator v6.4.X officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator v6.0.5 or older, first upgrade to v6.0.7, then upgrade to v6.4.X. Otherwise, the following message will display: 'Image validation failed: The firmware image model number is different from the appliances.'
  • If currently running FortiAuthenticator v6.0.7, then upgrade to v6.4.X directly.
  • If currently running FortiAuthenticator between v6.1.0 and v6.2.0, first upgrade to v6.3.3, then upgrade to v6.4.X.
  • If currently running FortiAuthenticator between v6.2.1 and v6.3.x, then upgrade to v6.4.X directly.

 

FortiAuthenticator v6.5.X and v6.6.X supports:

  • FortiAuthenticator 200E.
  • FortiAuthenticator 300F.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 3000F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

FortiAuthenticator v6.4.X supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 300F.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator v6.3.3.

FortiAuthenticator v6.3.3 build 0692 officially supports upgrades from FortiAuthenticator v6.0.4 and higher. All other versions of FortiAuthenticator must first be upgraded to v6.0.4 or above before upgrading to v6.3.3.


FortiAuthenticator v6.3.3 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 300F.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).


FortiAuthenticator v6.3.2.
FortiAuthenticator v6.3.2 build 0687 officially supports upgrades from FortiAuthenticator v6.0.4 and higher. All other versions of FortiAuthenticator must first be upgraded to v6.0.4 or above before upgrading to v6.3.2.


FortiAuthenticator v6.3.2 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 300F.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

FortiAuthenticator v6.3.1.
FortiAuthenticator v6.3.1 build 0682 officially supports an upgrade from FortiAuthenticatorv 6.0.4 and higher. All other versions of FortiAuthenticator must first be upgraded to v6.0.4 or above before upgrading to v6.3.1.

FortiAuthenticator v6.3.1 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator v6.3.0.
FortiAuthenticator v6.3.0 build 0670 officially supports an upgrade from FortiAuthenticator v6.0.4 and higher. All other versions of FortiAuthenticator must first be upgraded to v6.0.4 or above before upgrading to v6.3.0.

FortiAuthenticator v6.3.0 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator v6.2.1.
FortiAuthenticator v6.2.1 build 0552 officially supports upgrades from FortiAuthenticator v6.0.4 and higher. All other versions of FortiAuthenticator must first be upgraded to v6.0.4 or above before upgrading to v6.2.1.

FortiAuthenticator v6.2.1 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator v6.2.0.
FortiAuthenticator v6.2.0 build 0542 officially supports upgrades from FortiAuthenticator v6.0.4 and higher. All other versions of FortiAuthenticator must first be upgraded to v6.0.4 or above before upgrading to v6.2.0.

FortiAuthenticator v6.2.0 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, and Oracle OCI).

FortiAuthenticator v6.1.2.
FortiAuthenticator v6.1.2 build 0420 officially supports upgrades from FortiAuthenticator v6.0.4 and higher. All earlier versions of FortiAuthenticator must first be upgraded to v6.0.4 before upgrading to v6.1.2.

FortiAuthenticator v6.1.2 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, and Oracle OCI).


FortiAuthenticator v6.1.1.
FortiAuthenticator v6.1.1 build 0413 officially supports upgrades from FortiAuthenticator v6.1.0 and v6.0.4.
All other versions of FortiAuthenticator have to first be upgraded to 6.0.4 before upgrading to 6.1.1, otherwise, the following message will be displayed:

Image validation failed: The firmware image model number is different from the appliance's.
When upgrading existing KVM and Xen virtual machines to FortiAuthenticator 6.1.1 from FortiAuthenticator 6.0.4, increase first the size of the virtual hard disk drive containing the operating system image (not applicable for AWS & OCI Cloud Marketplace upgrades).

See the release notes for more details.

FortiAuthenticator v6.1.1 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, and Oracle OCI).


FortiAuthenticator v6.0.4.
FortiAuthenticator v6.0.4 build 0059 officially supports upgrades from all versions of FortiAuthenticator v4.x, v5.x, and v6.0.x.
All prior versions have to be upgraded to FortiAuthenticator v6.0.4 before they can upgrade to FortiAuthenticator v6.1.0 and later.

FortiAuthenticator v6.0.4 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, AWS, Azure, and OCI).


FortiAuthenticator v6.0.3.
FortiAuthenticator v6.0.3 build 0058 officially supports upgrades from all versions of FortiAuthenticator v4.x, v5.x, and v6.0.x.

FortiAuthenticator v6.0.3 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • ForiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, AWS, Azure, and OCI).


FortiAuthenticator v5.5.0.
FortiAuthenticator v5.5.0 build 0366 officially supports upgrades from all versions of FortiAuthenticator v4.x.x and v5.x.x.

FortiAuthenticator v5.5.0 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000C.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, and Xen).

 
Upgrading the FortiAuthenticator 3000D from v4.0.x to v4.1.x is not supported.

The workaround for this model is to upgrade from any v4.0.x version directly to v4.2.0 or higher (skipping all v4.1.x versions).

If install v4.1.x firmware is on a FortiAuthenticator 3000D it stops responding.
The system can run again by restoring valid firmware using the TFTP boot process.
FortiAuthenticator 4.0.0.

FortiAuthenticator v4.0 build 0008 officially supports an upgrade from FortiAuthenticator v3.3.

FortiAuthenticator 4.0 supports.

  • FortiAuthenticator 200D.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 1000C.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 3000B.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator VM (VMWare & Hyper-V).

 
FortiAuthenticator v4.0 build 0008 does not support upgrades from releases before FortiAuthenticator v3.3.

Upgrade via FortiAuthenticator v3.3, following instructions shown in the relevant firmware release notes.

FortiAuthenticator 3.3.
FortiAuthenticator v3.3 build 0176 officially supports upgrade from FortiAuthenticator v3.0

FortiAuthenticator v3.3 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 1000C.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 3000B. 
  • FortiAuthenticator 3000D.
  • FortiAuthenticator VM (VMWare & Hyper-V).


FortiAuthenticator v3.3 build 0176 does not support upgrades from releases before FortiAuthenticator v3.0.
Upgrade via FortiAuthenticator v3.0, following instructions shown in the relevant firmware release notes from the support portal.

Related documents:

Technical Tip: How to upgrade a FortiAuthenticator HA cluster

Upgrading from 4.x/5.x/6.x

Technical Tip: How to manually download and upgrade FortiAuthenticator firmware image on FortiAuthen...