Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
unpredictable1
New Contributor

Can you view the previous firmware before an upgrade?

I have a FortiWifi 60E that I got in the first half of 2017, I did a newb mistake this morning in upgrading the firmware straight to v5.4.8, build6501 instead of following the proper upgrade path.

My problem is, I don't recall the previous firmware. I believe it was 5.4.3 but really not certain.

I did take a backup of the config before doing the upgrade but when I try to revert back, still comes up 5.4.8

 

My router still works outside of the Wifi from the Fortigate is barely usable. (I'm thinking I might have other problems I haven't come across yet)

 

Is there a way to dissect the config file I have? Should I download a firmware and start fresh at a certain revision?

9 REPLIES 9
Markus
Valued Contributor

Hi, Welcome to the forum You can see the version in the backup file. Opened in text editor, the first line shows something similar #config-version=FWF60E-5.6.3-FW-build1547-171204 I would recommend that you download this version and downgrade your FG. Then it should be possible to restore the configuration. Some points to cover for downgrading http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-best-practices-54/Firmware/Performing...

 

Good luck


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
ede_pfau

My suggestion would be to keep calm and have a look first which parts of the config are damaged - if any. Going from v5.4.x directly to v5.4.8 isn't nice as an upgrade may include transformations of parts of the config where e.g. the syntax has changed. These transform routines are included in the firmware image and run automatically.

 

This would really be detrimental if you skipped from one FortiOS main version to another. Currently, there is v5.2, v5.4, v5.6 and (soon, bleeding edge) v6.0 as the main OS versions. But in my experience skipping a patch release will only affect small parts of the config. It would be wise to first assess the damage before downgrading as this will 100% revert the FGT to factory defaults. If you don't have physical access to the FGT this will be really a showstopper.

 

Just download the current config (without password a.k.a. as cleartext) and compare that with a diff tool to your backup. Chances are high that only the version comment in the first line and all encrypted strings are different. The latter will still be valid.

If you upgraded from, say v5.2, to v5.4 there might be more places which differ. You could patch these manually, either in the config file, or via GUI/CLI of the live FGT.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
emnoc
Esteemed Contributor III

What you could do if you have a latest backup at the time of the upgrade

 

1>  revert back to   the previous version ( the  image is on the 2nd partition that's now in active )

 

2> reload that  previous version

 

3> restore the cfg

 

4>  and now upgrade using the  FTNT-support  upgrade migration path

 

Make backups along the way

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
emnoc
Esteemed Contributor III

BTW here's the cmds  for step #1 above. I believe all versions of  FortiOS support this.

 

diag sys flash list

exe set-next-reboot secondary

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
unpredictable1

Guys, I sincerely appreciate all this help so quickly. Last night I found out you can open the configs with a wordpad/notepad and here is what I found:

 

Before upgrade:

FWF60E-5.04-FW-build1111-161216

After upgrade:

FWF60E-5.04-FW-build1183-180118

 

Everything with the router so far seems fine except that Wifi is almost unuable. I tried loading the previous *.conf file by putting it onto a USB and doing a auto load on restart. (I tried both CLI and GUI methods, always comes back with the latest config)

 

Now that I have much better information for you wall with the versions posted, are you recommendations the same?

ede_pfau

You have not mentioned whether you have physical access to the FGT or not.

If you do, downgrade to v5.4.3 (= build 1111) and restore the saved config. This is what your old state was.

Then, if you like, upgrade to v5.4.8 b 1183 after reading the Release Notes (!). Proceed in the sequence of patches given.

 

If you don't have direct access, compare both configs with a text diff tool (e.g. WinMerge) to spot the differences. Maybe this alone will give you a clue what has changed in the wireless section.

Otherwise, review the WiFi settings and the policies from/to WiFi. There is no fundamental functionality that has changed in the WiFi part between these patches.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
unpredictable1

I will have physical access tonight, the router is at my home. I have remote access here now but will obviously lose connection if I do a firmware downgrade that will have no config. I''m going to try what you folks have said. Thanks!

unpredictable1

Actually, just so I'm clear on this - I'm restoring from the secondary partition and not downloading a fresh copy of v5.4.3 (= build 1111) then restoring my config to that...forgive my beginner comments.

 

 

unpredictable1

I'm back on my v5.4.3,build5873 (GA).

 

Wifi performance is still terrible - I'll probably have to hit a wifi forum section for that...I think It might be interfering with another AP(s) in the house.

Labels
Top Kudoed Authors