FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
lingky88
Staff
Staff
Article Id 249118
Description This article describes how to schedule an upgrade for FortiGates using FortiManager.
Scope FortiManager.
Solution

1) If the FortiManager is operating in a closed network and is unable to download FortiGuard Images, it is possible to download the firmware image from the support portal and upload it manually into FortiManager under FortiGuard -> Local Images ->Import  -> Upload the firmware image.

 

lingky88_0-1678847783350.png

 

2) Create a new firmware template by navigating to Device Manager -> Firmware Templates and select 'Create New'.

 

lingky88_1-1678847821743.png

 

3) Under 'Upgrade Details', select 'Create New' in the firmware template and then select the appropriate product, platform, and version to be upgraded to.

 

lingky88_2-1678847886260.png

 

4) Under 'Install Window', select the schedule type and select the start time and end time for the upgrade activity.

The start time specifies the time to start the upgrade, whereas the end time specifies the time to end the upgrade.

It is also a best practice to select the 'Follow The Recommended Upgrade Path' option under Upgrade Options.

 

Note:

If the upgrade is not completed by the end time, the upgrade stops.

 

lingky88_3-1678847992739.png

 

5) Assign the firmware template to the device to be upgraded.

 

lingky88_4-1678848042665.png

 

lingky88_5-1678848052095.png

 

6) When the firmware template is running at the scheduled time, a notification will appear on the FortiManager showing the progress of the managed device upgrade that is taking place.

 

lingky88_6-1678848088369.png

 

7) After the upgrade has been completed, the notification disappears, and it is possible to verify the firmware version both on FortiManager and FortiGate.

 

Screenshot 2023-03-15 202310.png

 

lingky88_8-1678848154299.png

 

Troubleshooting:

 

- On FortiManager:

 

# exe tac report
# diagnose fwmanager fwm-log

 

- On the FortiGate:


# exe tac report

 

- While performing the upgrade:


# diagnose debug application fgfmsd 255