During FortiGate BIOS boot-up, any keystroke from the console interrupt the boot-up sequence for entering in BIOS menu options:
FortiGate-60F (23:24-08.29.2019) Ver:05000006 Serial number: FGT60FTKxxxxxx CPU: 1200MHz Total RAM: 2 GB Initializing boot device... Initializing MAC... nplite#0 Please wait for OS to boot, or press any key to display configuration menu..
This behavior could cause issues in some data center/user environments with specific terminal servers/other devices connected to the FortiGate console port, which may randomly spit out ASCI letters during the boot process and stuck FortiGate in the BIOS menu.
To avoid this is possible to enable 'restricted mode' where only the specific key combinations 'Ctrl+B' can trigger the BIOS menu and other keystrokes to the console will be ignored during boot up.
Following the procedure to enable 'restricted mode':
- Connect a PC to FortiGate's console port:Technical Tip: How to connect to the FortiGate and FortiAP console port
- Restart the FortiGate.
- When the console displays 'Press any key to display configuration menu...', press any other key:
FortiGate-60F (23:24-08.29.2019) Ver:05000006 Serial number: FGT60FTKxxxxxx CPU: 1200MHz Total RAM: 2 GB Initializing boot device... Initializing MAC... nplite#0 Please wait for OS to boot, or press any key to display configuration menu..
- Press 'I' to enter on System Information menu:
[C]: Configure TFTP parameters. [R]: Review TFTP parameters. [T]: Initiate TFTP firmware transfer. [F]: Format boot device. [I]: System information. [B]: Boot with backup firmware and set as default. [Q]: Quit menu and continue to boot. [H]: Display this list of options.
Enter C,R,T,F,I,B,Q,or H: I
- In the next menu, press 'R' to enter in Restricted mode options:
[S]: Set serial port baudrate. [R]: Set restricted mode. [T]: Set menu timeout. [U]: Set security level. [I]: Display system information. [E]: Reset system configuration. [Q]: Quit this menu. [H]: Display this list of options.
Enter S,R,T,U,I,E,Q,or H: R
- Press '1' to enable restricted mode:
[1]: Enable restricted mode, only Ctrl+B can enter configuration menu [2]: Disable restricted mode
Enter restricted mode setting [Disable]: 1
- Exit from the menu by pressing 'Q':
[S]: Set serial port baudrate. [R]: Set restricted mode. [T]: Set menu timeout. [U]: Set security level. [I]: Display system information. [E]: Reset system configuration. [Q]: Quit this menu. [H]: Display this list of options.
Enter S,R,T,U,I,E,Q,or H: Q
- Press again 'Q' to continue the FortiGate boot process:
[C]: Configure TFTP parameters. [R]: Review TFTP parameters. [T]: Initiate TFTP firmware transfer. [F]: Format boot device. [I]: System information. [B]: Boot with backup firmware and set as default. [Q]: Quit menu and continue to boot. [H]: Display this list of options.
Enter C,R,T,F,I,B,Q,or H: Q
After this procedure, 'restricted mode' is enabled and on the next FortiGate boot, the console will show:
FortiGate-60F (23:24-08.29.2019) Ver:05000006 Serial number: FGT60FTKxxxxxx CPU: 1200MHz Total RAM: 2 GB Initializing boot device... Initializing MAC... nplite#0 Please wait for OS to boot, or press Ctrl+B to display configuration menu......
Only the 'Ctrl+B' combinations key will permit to enter in configuration BIOS menu.
|