FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Matt_B
Staff
Staff
Article Id 350540
Description This article discusses expected scenarios in which FortiGate will show its firmware as up to date, and how to diagnose if this message is accurate.
Scope FortiGate v7.
Solution

System -> Fabric Management -> Upgrade', shows ‘The firmware is up to date’ and Upgrade Status as 'Up to date' if the device is not able to retrieve Upgrade Path information from FortiGuard.

 

For example, a FortiGate running v7.0.14 may show its current firmware as up to date even if there is a later v7.0 release.

 

6_nolist.PNG

5_nolist.png

 

This will occur in the following situations:

  • The firmware does have Upgrade Path information and is up to date within its Minor Version.
  • The device has been unable to connect to FortiGuard Distribution Servers to check its image list for at least 24 hours with no configuration change. This can happen if there's an ongoing network or DNS issue.
  • The device’s FortiGuard or DNS settings have recently changed, and the device is not currently able to connect to FortiGuard.
  • The device has no valid license or was unable to retrieve its license.


See FortiOS firmware version terminology for the differences between Major, Minor, and Patch versions.


Verifying current firmware and troubleshooting FortiGuard connectivity issues:

If a device shows a warning 'Unable to connect to FortiGuard Servers', follow the troubleshooting steps in the article Unable to connect to FortiGuard Servers to restore connectivity.

 

The most common causes of FortiGuard connectivity loss are DNS lookup or licensing issues. Once it is able to connect to FortiGuard, the device will automatically update the available firmware information.

 

6_yeslist.PNG

 

In CLI, 'diagnose test application forticldd 14' will show 'Image list is empty' if the device has no current firmware information:

 

LabFGT-A # diagnose test application forticldd 14
Image list is empty.
LabFGT-A #


Available firmware versions in a Minor Version have Release Notes. It is also possible to subscribe to an RSS feed of Fortinet firmware releases, as shown in the article Subscribe to RSS feeds for alerts on new Fortinet firmware releases

release notes.png

 

Even if the FortiGate has no FortiGuard connectivity, it is still possible to upgrade the device via manual firmware upload. See the article How to manually download Firmware of FortiGate and how to upload it on FortiGate


'Up to date' means up to date within the current Minor Version:

The firmware page will show the current firmware as up to date if there are no further Patch Versions in the branch, even if the End of Support date for the current Minor Version (e.g. v7.0, v7.2) has passed. If the device can retrieve upgrade path information from FortiGuard, other Minor Versions will show under the ‘All Upgrades’ page. The End of Support date for FortiOS v7.0 is 2025-09-30.

 

9_yeslist.PNG

 

Where possible it is strongly recommended to track Product Life Cycle information and plan to upgrade in advance of the End of Engineering Support Date.  See the article Product Life Cycle Information on Fortinet products

Beginning in v7.4, upgrading to a different Minor Version requires a valid support contract, see Supports preventing major and minor version firmware upgrades when support contract expires

Contributors