I have been slowly rolling out 7.2.9 to our 90G Fortigates, and I have noticed consistently that in our HA pair configurations the update will install on the secondary then fail on the primary and I have to reboot the primary then push the update again and it finally goes through. This has happened on 3 different pairs. Has anyone else seen this issue?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Nanduu,
When updating firmware in an HA pair configuration, it is common for the update to be installed on the secondary FortiGate first before failing on the primary FortiGate due to the following reasons:
1. **Sync Issue**: Sometimes, there might be synchronization issues between the primary and secondary FortiGates, causing the update to fail on the primary FortiGate after being successfully installed on the secondary.
2. **Resource Conflict**: The primary FortiGate might be handling more traffic or processes, leading to resource conflicts during the update process, resulting in a failure.
3. **Configuration Mismatch**: If there are differences in configurations between the primary and secondary FortiGates, it can cause the update to fail on the primary FortiGate.
To address this issue, you can try the following steps:
1. **Check Synchronization**: Ensure that the primary and secondary FortiGates are properly synchronized before initiating the update process.
2. **Verify Resources**: Make sure that the primary FortiGate has enough resources available to handle the update process without conflicts.
3. **Configuration Consistency**: Verify that the configurations on both FortiGates are consistent to prevent any update failures due to configuration mismatches.
Also, please refer to the below document to fix an HA (High Availability) cluster upgrade failure:
Yes
Re: FortiOS 7.2.9 for 120G series seems to break H... - Fortinet Community
Same here, update stuck on slave, and then primary was on old version, we never got it fixed or working, always, HA interface on a 120G seems to be missing ...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1529 | |
1027 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.