FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pkumari
Staff
Staff
Article Id 353899
Description This article describes how to troubleshoot the error 'Retry count exceeded; starting again' when formatting and loading a FortiGate firmware image using TFTP.
Scope FortiOS.
Solution

When uploading the firmware using TFTP, there may be an issue with the TFTP server to the firewall connectivity where the following error can be seen.

 

tftp.png

 

To address the 'retry count exceeded' issue during a TFTP transfer, follow these steps:

 

  1. Check the network connectivity between the devices involved in the TFTP transfer.
  2. Verify the TFTP server settings and ensure they are correctly configured.
  3. Restart the TFTP server and the device initiating the transfer.
  4. Monitor the TFTP transfer process for any errors or issues that may be causing the retries to exceed the limit.
  5. Disable the windows firewall.
  6. Verify the TFTPD settings & enable the 'PXE Compatibility' checkbox as below.

 

pxe.png

 

Note:
Network connectivity between FortiGate and TFTP server can be tested using option 'Diagnose networking' when accessing boot menu.  After accessing boot menu, press 'C' to configure TFTP parameter and then 'N' to diagnose network and finally option '1' to ping the TFTP server.

[C]: Configure TFTP parameters.
[R]: Review TFTP parameters.
[T]: Initiate TFTP firmware transfer.
[F]: Format boot device.
[I]: System information.
[B]: Boot with backup firmware and set as default.
[Q]: Quit menu and continue to boot.
[H]: Display this list of options.

Enter C,R,T,F,I,B,Q,or H: C


[P]: Set firmware download port.
[D]: Set DHCP mode.
[I]: Set local IP address.
[S]: Set local subnet mask.
[G]: Set local gateway.
[V]: Set local VLAN ID.
[T]: Set remote TFTP server IP address.
[F]: Set firmware file name.
[E]: Reset TFTP parameters to factory defaults.
[R]: Review TFTP parameters.
[N]: Diagnose networking(ping).
[Q]: Quit this menu.
[H]: Display this list of options.

Enter P,D,I,S,G,V,T,F,E,R,N,Q,or H:N


[1]: Ping remote TFTP server.
[2]: Ping gateway.
[3]: Ping specified IP address.
[Q]: Quit this menu.
[H]: Display this list of options.

Enter 1,2,3,Q,or H: 1