FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jlim11
Staff
Staff
Article Id 335933
Description This article describes the process of restoring a configuration file with a lower firmware version to a current FortiGate running with a higher firmware version.
Scope FortiOS
Solution

When backing up the configuration file, It can be encrypted(with password) or unencrypted.

 

To restore an encrypted configuration file:
It is required to be the same hardware model and same firmware version/build + password(which is set during backup).

 

To restore an unencrypted configuration file:
It is only required to be the same hardware model.

 

When restoring the configuration file with a lower version to a FortiGate running a higher firmware version, FortiGate will attempt to upgrade the configuration. This is similar to how it uses upgrade scripts on the existing configuration when upgrading the firmware.

 

However, It is still highly recommended to match the firmware on FortiGate to the firmware listed in the configuration file to avoid any configuration errors.

Even if restoring the configuration file is successful, some configuration errors may be observed.


It is possible to check any configuration error after restoring the configuration file by using the following command:

 

diagnose debug config-error-log read


Related articles:
Technical Tip: How to clear the config error log

Contributors