FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Anonymous
Not applicable
Article Id 200582
Description

This article describes how to handle the error 'Image upgrade failed' that occurs while upgrading the FortiGate from GUI.

 

fortigate-upgrade-03.png

Scope

FortiGate.

Solution

Try one of the subsequent options:

  1. Clear the browser cache and cookies.
  2. Try another browser.
  3. Use incognito mode.
  4. Verify if FortiGuard is connected so the firmware can be downloaded.

 

If it fails, either fix the FortiGuard connectivity or try to download the image from Support:

Support -> Firmware download -> Download.

 

Then upload the Firmware image to FortiGate by following this KB article: Technical Tip: How to manually download Firmware of FortiGate and how to upload it on FortiGate.

 

  1. An error may also occur when upgrading to an interim or special build. In such cases, the BIOS security level must be adjusted.

Note:

The FortiGate BIOS security level cannot be modified using standard CLI commands such as:

config system global

    set bios-security-level low

end

 

config system global

    set bios-security-level high

end


To change the BIOS security level, the device must be rebooted and accessed through the console port.

The details are explained in the following document: BIOS-level signature and file integrity checking during downgrade

 

To check the current security level, use the following command:

 

get system status

 

Note:
The default Security Level will be 2, and change to Security Level 1 for the Firmware Upgrade issue, once the upgrade is done without any issue, and revert to Security Level 2:

 

get system status 

Version: FortiGate-VM64-KVM v7.2.7,build1577,240131 (GA.M)
Security Level: 1
Firmware Signature: certified
Virus-DB: 1.00000(2018-04-09 18:07)

 

If there is no console access or the FortiGate is in a remote location, the issue can also be resolved by rebooting the FortiGate, especially if the FortiGate has been up for quite some time, and then proceeding with the Firmware upgrade.

 

Try upgrading the firmware using a different browser, such as Chrome, Firefox, or Edge, or use Incognito/Private Browsing mode. In some cases, browser-specific issues such as cached content, stale cookies, or incomplete script execution may interfere with the firmware upload process via the FortiGate GUI. Using an alternate browser or private session helps avoid these issues and ensures a clean firmware upgrade.

 

Note:

In some cases, this error is observed in IOS operating systems. It is recommended to use Chrome instead of Safari to perform the upgrade.

 

Related documents:

Troubleshooting Tip: Unable to boot the firewall or load firmware image

BIOS-level signature and file integrity checking