Description |
This article describes the new paid-tier Firmware Profile feature that is present in FortiGate Cloud as well as how administrators can control this feature for FortiGates connected with paid FortiGate Cloud subscriptions.
|
Scope | FortiGate Cloud, FortiGate. |
Solution |
FortiGate Cloud v24.2.0 introduced a new feature called Automatic Upgrades which allows administrators to automatically schedule/handle upgrades to the latest patch release for each of the managed FortiGates. Later in FortiGate Cloud version 24.3.0, the feature was refined into the Firmware Profiles option which allows admins to create and assign profiles to further control how upgrades are managed.
Currently, user can create custom profiles and assign to FortiGates with a paid-tier FortiGate Cloud subscription:
General Notes for Firmware Profiles:
Disabling Firmware Profiles: Applying the latest patch ensures that newly discovered vulnerabilities do not impact production FortiGates. It is therefore recommended to use this option even when there is an option to disable this setting on a paid subscription. However, in circumstances where a customer would like to manually perform the upgrades, these methods can be used:
Note: FortiGate Cloud firmware profile is independent of the local 'automatic patch-level upgrade' described in the FortiOS Administration Guide. Configuring a FortiGate Cloud firmware profile including 'None' will neither prevent nor force the local patch-level upgrade function. See the KB article Technical Tip: Understanding Automatic Patch Upgrade: FortiGate Cloud Premium vs Local Setting.
To assign a firmware profile in FortiGate Cloud, select the FortiGate -> Group Management -> Assign Firmware Profile:
How to create custom Firmware Profiles on FortiGate Cloud:
How to assign Firmware Profiles to FortiGates on FortiGate Cloud:
Note: The 'Enable|Disable' option for 'Auto Upgrade Status ' has been removed from the v25.1a 'Firmware profile' to simplify UI design.
How to check which Firmware Profiles are assigned to FortiGates on FortiGate Cloud:
Note: By February 28, 2025, FortiGates that do not currently have an active FortiGate Cloud subscription will need to update to the most recent firmware patch within seven days of the patch GA release. See Technical Tip: Security enforcement change for FortiGates provisioned to FortiGate Cloud without act... for details.
Related documents: Technical Tip: Understanding Automatic Patch Upgrade: FortiGate Cloud Premium vs Local Setting Firmware Profile - FortiGate Cloud administration guide |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.