The content you are looking for has been archived. View related content below.
Created on
05-13-2005
12:00 AM
Edited on
12-26-2024
06:59 AM
By
salemneaz
Description
This article describes how to upgrade FortiGate firmware. FortiGate administrators whose access profiles contain system configuration read and write privileges and the FortiGate admin user can change the FortiGate firmware.
Download the most recent firmware build from the Fortinet Technical Support website at http://support.fortinet.com/.
Scope
FortiGate.
Solution
Usage Awareness and preparation checklist before the upgrade:
v5.2.x and v5.4.x:
To upgrade the firmware:
The FortiGate unit uploads the firmware image file, upgrades to the new firmware version, restarts, and displays the FortiGate login. This process takes a few minutes.
v5.6.x, v6.0.x and v6.2.x:
v7.0.x:
v7.2.x, and v7.4.x:
v7.6.x:
3.Then select Two Option will appear "Full Fabric Upgrade" and "FortiGate only", select the appropriate option.
4. At the example "FortiGate only" has been selected, and then click "Next"
5. At the Next window Recommended , All Upgrades, All Downgrades, and File Upload.
6. At the example "All Upgrades" option has been selected.
7. Click on the "Select" option and proceed to the next Section.
8. At this section select "Immediate" or a scheduled update can be selected as well using the "Specify" option.
9. Choose "Specify" if the upgrade needs to be performed automatically at a later time.
10. Then proceed to the "Review" section, "Confirm and Backup Config" and the Firewall will be upgraded to the target Version.
Upgrading the firmware through the CLI.
Before starting, ensure a TFTP server is running and accessible to the FortiGate unit.
Step 1: Copy the new firmware image file to the root directory of the TFTP server.
Step 2: Log into the CLI.
Step 3: Make sure the FortiGate unit can connect to the TFTP server.
Use the following command to ping the computer running the TFTP server. For example, if the IP address of the TFTP server is 192.168.1.168:
execute ping 192.168.1.168
Enter the following command to copy the firmware image from the TFTP server to the FortiGate unit:
execute restore image tftp <filename> <tftp_ipv4>
The FortiGate unit responds with the message:
This operation will replace the current firmware version!
Do you want to continue? (y/n)
Type y. The FortiGate unit will upload the firmware image file, upgrade to the new firmware version, and restart. This process takes a few minutes.
Reconnect to the CLI.
Updating the firmware on FortiGate.
Browse to support.fortinet.com and log in.
Upgrading From the Details window.
Load the firmware and reboot by going to the menu tabs on the left of the interface window. Go to System -> Dashboard -> Status -> System Information -> Firmware Version -> Details.
The FortiGate will reboot.
Upload and Boot to Firmware at a later time or Boot to Previous Firmware.
Loading the other partition can be useful to quickly downgrade to the previous working firmware.
However, there are a few considerations to be aware of:
In the CLI, use the following commands.
To list partitions and check if they are active:
diag sys flash list
To indicate what partition to boot from the next time the device reboots (Partition 1 is the primary and Partition 2 is the secondary):
execute set-next-reboot <primary|secondary>
To reboot the FortiGate:
execute reboot
If the FortiGuard License for Firmware and General Updates is renewed and is not reflected on FortiGate, then execute following command to synchronize license information with portal:
execute update-now
If the device is in HA cluster, both the devices should have valid license to fetch firmware upgrades from FortiGuard.
once the command is executed, if firmware updates is available it can be seen on the device or on the top-right notification count will highlighted.
More information on loading the secondary partition can be found in the following documents:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.