Description |
This article describes about the issue where, while upgrading a two chassis a-p environment, the secondary node upgrades itself and the failover does not automatically take place.
The upgrade process is initiated from the master. Slave upgrades itself. Master reports slave is back online but the failover never takes place. Master counts down until the upgrade times out, slave reverts its firmware to the initial version and the upgrade process is finished. (Both members are in starting FortiOS version and no failover happens. Meaning no service disruption but the upgrade is not completed either). Comlog of slave will report one successful upgrade and 20 minutes after the message of rollback:
(In case there is console connectivity, the same messages could be tracked through console as well). Upgrade failure does not happen for all the paths. Remark : 6.2.8 to 6.4.4 upgrade completes without issues. This article is only for the upgrade that does not complete. |
Scope | 5K - SLBC (a-p) / 6.2.8 -> 6.4.7 upgrade |
Solution |
Normally, the workflow that is expected would be, After master reports the slave member is all up, failover should take place with a 'Force-to-' flag and initial master upgrades itself.
Forcing the failover manually once the slave Firewall blade is up and running helps with the failing upgrade process.
Following the below steps will help with the upgrade that is not completed properly:
1) Perform the regular checks, get backup etc, verify cluster is in sync.
Seeing 'All members of the secondary chassis are up' message on Master FortiGate Blade is a prerequisite to proceed.
Remark: DO NOT do the failover with PRIORITY!
11) Once the upgrade operation is finished and units are in sync, make sure to remove the 'force-slave-state' flag using the command -> 'diagnose system ha force-slave-state clear 3'
Information on Comlog feature : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-COMLog-feature/ta-p/195390 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.