Created on
01-06-2023
06:32 AM
Edited on
12-18-2024
07:12 AM
By
Stephen_G
Description
This article describes how to fix HA (High Availability) cluster upgrade failure which results to each firewall in cluster having different OS version.
Scope
FortiGate HA Active Passive.
Solution
Uninterruptible HA cluster upgrade mode (the default) will upgrade the secondary device before the primary.
In most failure cases with this option, the secondary device is successfully upgraded to a newer version while the primary device stays on the current OS version.
This problem can occur with any OS version and device model.
Pre-checklist:
The primary unit most likely has no newer image on its flash storage:
diagnose sys flash list
Partition Image TotalSize(KB) Used(KB) Use% Active
1 FG100F-6.04-FW-build1914-211117 253920 102616 40% No
2 FG100F-7.00-FW-build0367-221005 253920 110112 43% Yes
3 ETDB-90.07704 3021708 790996 26% No
Image build at Oct 5 2022 22:02:56 for b0367
diagnose sys ha dump-by kernel
<hatalk> HA information.
<hatalk> group_id=13, nvcluster=1, mode=2, load_balance=0, schedule=3, ldb_udp=0.
<hatalk> nvcluster=1, mode=2, ses_pickup=1, delay=0, load_balance=0
schedule=3, ldb_udp=0, upgrade_mode=0. <----- Upgrade_mode should be '0'. If not, reboot the firewall to reset this to 0.
Since each unit has a different OS version, the cluster status will be out-of-sync.
However, the session sync should still be running.
If all prerequisites are met, follow the steps below. Otherwise, contact Fortinet TAC for additional help.
If this step did not work and it is not possible to upload the image, follow step 2:
In this case, be sure that the secondary can take over the traffic in normal conditions.
Downgrade through the CLI with the following command:
execute set-next-reboot {primary | secondary} <-- Make sure the older image is there.
See this article for more information.
If none of the steps above work, try the following:
Note:
If the problem still persists after following the steps above, contact Fortinet TAC for further assistance.
Related documents:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.