FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
zromano
Staff & Editor
Staff & Editor
Article Id 420398
Description This article describes how it might be possible to recover a FortiGate that is not starting correctly and is stuck in a boot loop.
Scope FortiGate.
Solution

In rare cases, it might happens that the FortiGate remains stuck in a boot loop and cannot boot up correctly.
This may happen for example after an unexpected power off or after a failed upgrade.

 

If this happens, depending on where in the booting process the device encounter the problem, it might be possible to recover the FortiGate by loading the secondary partition from the BIOS.

 

Note: For this procedure, a console cable is required (it is not possible to perform this with SSH or HTTPS access):
Technical Tip: How to connect to the FortiGate console port

 

If the FortiGate shows the following line during the booting process, pressing any key will enter the BIOS:

 

Press any key to display configuration menu...

 

In the BIOS menu, select "Boot with backup firmware and set as default.":

 

[C]: Configure TFTP parameters.
[R]: Review TFTP parameters.
[T]: Initiate TFTP firmware transfer.
[F]: Format boot device.
[B]: Boot with backup firmware and set as default. <<<<<<<<<<<<<
[I]: System configuration and information.
[Q]: Quit menu and continue to boot.
[H]: Display this list of options.

 

Enter C,R,T,F,B,I,Q,or H:


The FortiGate will load the secondary partition and boot.

 

Loading backup firmware from boot device...


Verifying the integrity of system files.

Reading boot image 6212342 bytes.
Initializing firewall...

System is starting...
Starting system maintenance...


FortiGate login:

 

Note: Normally, the secondary partition contains the configuration before the last firmware upgrade (this could also be used as a rollback option).
This means that the configuration and firmware will not be the desired one. Therefore upgrading and restoring the most recent configuration should be required.

Contributors