FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
DPadula
Staff & Editor
Staff & Editor
Article Id 268042
Description This article describes how to upgrade three or more FortiGates in HA A-P mode.
Scope FortiOS 7.2.x and above.
Solution

In a few environments that request high availability, a HA solution with two FortiGates in A-P mode might not be enough. A third FortiGate can be added to the HA setup to increase the availability. 

 

Network diagram.PNG

For the sake of this article, a simple network diagram has been provided showing three FortiGates connected to each other via three different switches. Only one switch with more than 8 ports and 3 VLANs would be necessary, but to keep the network diagram easy to draw three switches were used instead of one. 

 

Step 1: Check if the three FortiGate are in sync. This can be checked under System -> HA. Once all three devices are in sync, continue with the upgrade. In case there are not, fix the sync issue first before the next step.

 

3xFGT A-P.PNG

Step 2: Go to System -> Fabric Management, select FortiGate, and select Upgrade.

 

Upgrade menu.PNG

 

Step 3: In this article, proceed with a manual upgrade by uploading the FortiOS file, but this is not necessary. The automatic upgrade can be used as well.

Select File Upload -> Browse, then select the file. Select Continue.

 

Upgrade to 7.2.5.PNG

 

Step 3: Wait for the process to finish, the FortiGate GUI will only show a message Validating and installing image but the console access will show a progress bar.

 

Validanting.PNG

 

HA upgrade CLI.PNG

 

HA upgrade CLI 02.PNG

Step 4: After the reboot, the HA GUI will show the devices out of sync. 

 

Out of sync GUI.png

Just wait, the sync process has started and can be seen via the console.

 

sync happening 02.PNG

Checking via console it is possible to see that the three FortiGates have been updated to version 7.2.5 and are in sync.

 

show status after upgrade.PNG

CLI in sync.PNG