FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rvillaroman
Staff
Staff
Article Id 229006
Description This article describes why, in some cases, an automatic upgrade (via the GUI) fails because of too many factors like FortiGate being unable to connect to the FortiGuard server, or a delay in connecting to the server to complete the firmware download and upgrade.
Scope FortiGate.
Solution

In the event that the message 'Image upgrade failed' appears, attempt the following workarounds to avoid this error on the next upgrade.

  1. Use another browser, clear Cache and Cookies, or use an incognito Window to log in to FortiGate GUI and then, try to perform the automatic upgrade (online).
  2. If the above step did not help, manually download and install the firmware from the support portal. Manually upgrade the FortiGate by using System -> Firmware -> Upload Firmware -> Browse and using the file obtained in this step.
  3. If there are 2 FortiGates in the HA cluster, make sure to upgrade the secondary FortiGate via the primary FortiGate. Do not update the secondary FortiGate directly while it is in the HA cluster.

 

The problem could be encountered on the FortiGate model 90G/91G/120G/121G in HA cluster mode. This is an isolated case and related to a known issue. Firmware upgrade from v7.0.16 to higher firmware version (v7.0.17, v7.2.x, v7.4.x, or v7.6.x).

 

Another workaround for the 90G/91G/120G/121G is to lower the security level via Console. For more information: Technical Tip: FortiGate 90G/91G/120G/121G HA cluster unable to upgrade due to error (Firmware image... 


The workaround is to disable HA or shut down one of the HA members and then upgrade separately. If these steps do not work, open a TAC case for further troubleshooting, analysis, and resolution.

 

Also, provide the output of the below debug from both units if the device is in the HA cluster while reproducing the issue:

 

diagnose debug enable
diagnose test application hasync 10
diagnose test application hasync 30
diagnose debug application hasync -1
diagnose debug console timestamp enable

 

Related documents:

Upgrading FortiGates in an HA cluster - FortiGate administration guide

Technical Tip: FortiGate HA upgrade procedure and the status during the upgrade