FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
contreraspa
Staff
Staff
Article Id 389372
Description This article describes how to resolve a situation when a FortiGate is upgraded from versions 7.2.X to version 7.4.X, and after the upgraded FortiLink interface and all its references are removed, and how to fix it.
Scope FortiGate all versions previous 7.4.X
Solution

Sometimes when a firmware upgrade is performed from versions 7.2.X to version 7.4.X, the FortiLink interface and all its references are removed after the upgrade.

The FortiLink interface in version 7.2.X shows it has administrative access SSH enabled:

 

fortilink with ssh.png

 

Due to a fix for bug ID #870083 in versions 7.4.0 and above, a restriction was introduced so FortiLink interfaces only allow ping and fabric as means of administrative access (set allowaccess ping fabric). Since the FortiLink interface has other administrative access than these two, is not migrated during the firmware upgrade and the references are removed.

To allow the interface to be migrated during the upgrade, SSH access must be removed from the interface. However, this cannot be completed in the GUI or CLI:


fortilink error removing ssh.png

 

To fix this error, there are two options. The first one is removing all the FortiLink interface references in the configuration, disabling the FortiLink option in the interface, and then setting the administrative access to ping and fabric. After, FortiLink must be enabled and all of the references will be added again. This can be a long/complex job depending on the configuration.

The second option is to perform a configuration backup , edit the file, and remove the SSH access from the FortiLink interface. After, the modified configuration file must be restored on the FortiGate. After this, the FortiLink interface will only show ping and fabric as administrative access:

 

fortilink without ssh.png

 

A firmware upgrade to versions 7.4.X can then be performed and the FortiLink interface will be migrated as expected.