Created on
07-21-2024
05:12 AM
Edited on
10-20-2025
09:33 PM
By
Anthony_E
| Description | This article provides instructions to disable automatic firmware upgrades on FortiGate devices through FortiManager and FortiGuard. |
| Scope | FortiGate, FortiManager. |
| Solution |
Disabling Firmware Upgrades through FortiManager. To disable automatic firmware upgrades on FortiGate devices managed by FortiManager, perform the following steps:
config system central-management
Disabling Auto-Firmware Upgrade through FortiGuard. To disable the auto-firmware upgrade feature through FortiGuard, perform the following steps:
config system fortiguard
This auto-firmware-upgrade feature is only available for FortiGate v7.2.1 and later.
From the GUI it can be done from the option System -> Firmware Registration -> Automatic patch upgrade enabled -> Disable automatic patch upgrades.
config system federated-upgrade
Cancel Any Scheduled Upgrades. Run the following command to cancel any immediate or scheduled upgrades:
execute federated-upgrade cancel
This command will prompt the user to confirm the cancellation: Type Y and enter.
Note:
To completely deactivate automatic patch upgrades for a FortiGate connected to FortiGate Cloud, ensure to disable the patch upgrade settings within FortiGate Cloud as well.
Additional Note:
Starting with v7.4.8, v7.6.4, and v8.0.0, a new behavior has been introduced on unlicensed or expired-support FortiGate devices. If support is not valid, the FortiGate will automatically schedule a firmware upgrade to the latest patch in its current minor version. This is managed through the CLI under 'config system federated-upgrade', where the upgrade schedule becomes visible. However, this scheduled upgrade cannot be cancelled, only postponed for up to seven days using the command 'execute auto-upgrade delay-installation'. There is no limit on the number of times this can be delayed. For more details, read the article: Technical Tip: Disable auto-upgrade for unlicensed FortiGates
Note:
If from the GUI, under Firmware Registration, there is no Disable automatic patch upgrade, the following path can be checked under System -> FortiGuard.
Related article:
Technical Tip: Disable auto-upgrade for unlicensed FortiGates |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.