FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Renante_Era
Staff
Staff
Article Id 335205
Description

This article describes how to properly reload a FortiGate firmware and config. 

Downgrading to previous firmware versions results in configuration loss on all models. Only the following settings are retained:

  • operation mode
  • interface IP/management IP
  • static route table
  • DNS settings
  • admin user account
  • session helpers
  • system access profiles

FortiOS 7.2.9 Release Notes

Scope FortiOS 7.x, 7.2.x, 7.4.x.
Solution

A full backup configuration, preferably before the firmware upgrade, is needed to reload the firmware.

The steps are as follows to avoid configuration loss:

  1. Log in to the FortiGate GUI and backup the current configuration.

Screenshot 2024-08-21 105347.png

 

Screenshot 2024-08-21 110257.png

 

  1. Confirm the backup config (<filename>.conf) firmware version. If unsure, check the version at the first line of the backup config which can be viewed by a text editor such as Notepad or Notepad++. Do not save any changes when closing the file to avoid corrupting the backup config.

  2. Open System -> Fabric Management and select the FortiGate device.

 

FabricManagement.jpg

 

  1. Select Upgrade and open the All Downgrades tab, then select the downgraded firmware. Alternatively, use File Upload and browse to the downloaded firmware.


FabricManagement_Downgrade.jpg

 

  1. Once the firmware downgrade is complete, open admin>Configuration>Restore as shown in Step 1 but select Restore instead of Backup. Once the FortiGate completes the reboot, confirm the current firmware version using the following command:

get system status