FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
bmehta
Staff
Staff
Article Id 421928
Description This article describes the issue of FortiGate boots with secondary partition and a step-by-step guide to troubleshoot and resolve the issue.
Scope FortiGate.
Solution

FortiGate may boot from the previously known working partition (secondary partition) if the primary partition becomes corrupted. This behavior can occur after events such as an unexpected power loss or sudden shutdown.

This event can also cause FortiManager to trigger an auto-retrieve operation because the secondary partition may contain an older configuration.

To troubleshoot the issue of FortiGate booting up with secondary partition after an unexpected power off, follow these steps:

  1. Verify the Active and Backup Partitions: Use the following command to confirm whether the FortiGate has booted from the secondary partition:

     

diagnose sys flash list

flashlist.jpg
This will display the active and backup firmware partitions.

  1. Review system event logs under Log & Report for an event msg="Fortigate had experienced an unexpected power off!" and correlate the timestamp of this event with the time the device switched to the secondary partition.
  2. Attempt to boot into the correct Partition. Use one of the following CLI commands to instruct the FortiGate to boot from a specific partition during the next reboot:

     

execute set-next-reboot primary 


execute set-next-reboot secondary

 

For more information, see Technical Tip: Selecting an alternate firmware for the next reboot.

 

  1. Connect to the FortiGate console and observe the boot process. The console output is the only reliable method to identify partition corruption or disk-related errors during startup.

  2. To correct issues with a corrupted partition, perform a firmware upgrade. During the upgrade, the FortiGate attempts to repair the primary partition automatically. If the device continues to boot from the secondary partition after upgrading, this may indicate hardware disk errors.

  3. A TFTP format and reinstalling of OS can also be tried if the device is already on latest firmware. If none of the above steps help consult technical support for a possible RMA. For more information, see Technical Tip: Formatting and loading FortiGate firmware image using TFTP.
Contributors