Description |
This article describes downgrade issues due to an enhanced BIOS-level signature and file integrity checking. A solution is offered. |
Scope |
FortiGate running BIOS version 5000100, 6000100, or newer. |
Solution |
If the FortiGate device is running BIOS version 5000100 or 6000100 (or newer), the user will not be able to downgrade to 6.0, 6.2, or any other FortiOS versions below the ones listed here:
7.4.0 new features - enhance BIOS level signature and file integrity checking
The device will not work and will display this error when booting up:
Booting OS...
We recommend upgrading FortiOS to a version that supports the BIOS security check to maximize the security posture of the device. Only if the upgrade of FortiOS is not possible then please follow the instructions below in order to change the BIOS security level.
To perform the downgrade in this case, the BIOS security level needs to be lowered down to 0:
To change the BIOS security level, ensure a console cable is connected, which is required to access the necessary menus. Then, follow this sequence in the BIOS menu:
Reboot FortiGate.
FortiGate-60F During the reboot process Fortigate will print a message on the console "press any key to display configuration menu", then press a key to access the BIOS. [C]: Configure TFTP parameters.
Enter C,R,T,F,I,B,Q,or H:
Enter S,R,T,U,I,E,P,Q,or H:
After this, follow the instructions to close the menu and boot the device (this will typically consist of pressing Q, then Q again).
Additional note: It is possible to check the security level currently set before rebooting the unit or after changing it with the command 'get system status'.
get system status
Warning: Be advised that modifying this parameter will impact the overall security posture of the device and/or network. It could potentially allow a local user with access to the appliance to install or run modified, malicious code in the system. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.