I have a FTG80C in working environment, And I will enter an additional FTG80C. I wonder if someone already set an active-active HA (High Availability) cluster with firmware 5.2.2 over fortigate´s 80C and are an stable solution, or what kind of bugs are find out additional to FTG80C documented on fortinet knowledge base; Does firmware 5.2.2 overwhelm hardware limits of ftg80´s in HA ?, and which one more stable firmware do you recommend to my HA cluster of FTG80C: 5.09, 5.0.11 or 5.2.2 Note: UTM configuration an VPN´s are already using half or my hardware resources on my stand alone FTG80C configuration over a fortios 4.0 MR3 patch 10, I am supporting around 60 LAN user´s 5 VPN IP-sec connections, with medium traffic.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
From the given information i can understand that fortigate unit is already consuming more hardware resources, first you need to fix that, you can identify which process is consuming high memory/cpu using below command
diag sys top 4 30 (press 'q' stop)
As such there is no particular bugs are reported on 80C, i recommend to upgrade the firrmware version to 5.0.9
Make sure to connect the console port for both the units when upgrading and capture all the messages
And also please follow steps
4.0 MR3 patch10 -> 4.3.11 -> 4.3.18 -> 5.0.7 -> 5.0.9 or: 4.0 MR3 patch10-> 4.3.11 -> 4.3.18 -> 5.0.7 -> 5.2.2 My recommendation is to upgrade to 5.0.9 If you will backup the config file before and after each upgrade and you will use the right firmware image for 80C,you should not have any issue. Please just make sure you also don t have high CPU/memory on the firewall before upgrading the unit. Upgrade Path: http://docs.fortinet.com/...-Upgradepath.pdf General upgrade recommendations: Before performing any upgrade, and particularly when upgrading between MR versions, it is *absolutely essential* to read all relevant Release Notes documents for all versions in the upgrade path. These are short, but important documents. Release Notes documents for each firmware version are located in the same folder of Fortinet Download area, as firmware image files. Release notes explain which upgrade path you should follow. You may download Firmware Images here (customer login needed): [link]https://support.fortinet.com/ [/link] go to "Download" > "Firmware Images" > "FortiGate" Also, *before and after* any upgrade, *always backup your current config file*, so that you will keep a safe way back. If you have multiple upgrade steps, please backup after each firmware release is installed. The Fortinet Documentation website provides detailed instructions for installation and upgrade: [link]http://docs.fortinet.com/ [/link] Firmware Upgrade Document http://kb.fortinet.com/kb...0%200%2045196244 HIGH AVAILABILITY (HA) UPGRADES Please refer to the HA Guide for information on the upgrade procedures for HA configurations. HA Guide MR3 : http://docs.fortinet.com/...te-ha-40-mr3.pdf When operating in an HA cluster, FortiGate devices can be upgraded automatically with the HA option "uninterruptable-upgrade" which is enabled by default. The advantages of the uninterruptable upgrade process are: - Allows the Administrator to upgrade all devices of a cluster in a single operation (from the GUI, click Dashboard --> Status --> Firmware Version --> upgrade). - It upgrades (all) Slave(s) unit(s) before upgrading the Master, making the necessary failover for a minimum downtime. Please ensure you backup the configuration file before each upgrade. Please do go through the release notes before any upgrade. Kindly refer you to follow the steps from this KB document: http://kb.fortinet.com/kb...0%200%2039132136 or from this one,if you prefer the manual upgrade procedure of a FortiGate HA cluster http://kb.fortinet.com/kb...0%200%2045256491
let me know how you proceed
Hi,
From the given information i can understand that fortigate unit is already consuming more hardware resources, first you need to fix that, you can identify which process is consuming high memory/cpu using below command
diag sys top 4 30 (press 'q' stop)
As such there is no particular bugs are reported on 80C, i recommend to upgrade the firrmware version to 5.0.9
Make sure to connect the console port for both the units when upgrading and capture all the messages
And also please follow steps
4.0 MR3 patch10 -> 4.3.11 -> 4.3.18 -> 5.0.7 -> 5.0.9 or: 4.0 MR3 patch10-> 4.3.11 -> 4.3.18 -> 5.0.7 -> 5.2.2 My recommendation is to upgrade to 5.0.9 If you will backup the config file before and after each upgrade and you will use the right firmware image for 80C,you should not have any issue. Please just make sure you also don t have high CPU/memory on the firewall before upgrading the unit. Upgrade Path: http://docs.fortinet.com/...-Upgradepath.pdf General upgrade recommendations: Before performing any upgrade, and particularly when upgrading between MR versions, it is *absolutely essential* to read all relevant Release Notes documents for all versions in the upgrade path. These are short, but important documents. Release Notes documents for each firmware version are located in the same folder of Fortinet Download area, as firmware image files. Release notes explain which upgrade path you should follow. You may download Firmware Images here (customer login needed): [link]https://support.fortinet.com/ [/link] go to "Download" > "Firmware Images" > "FortiGate" Also, *before and after* any upgrade, *always backup your current config file*, so that you will keep a safe way back. If you have multiple upgrade steps, please backup after each firmware release is installed. The Fortinet Documentation website provides detailed instructions for installation and upgrade: [link]http://docs.fortinet.com/ [/link] Firmware Upgrade Document http://kb.fortinet.com/kb...0%200%2045196244 HIGH AVAILABILITY (HA) UPGRADES Please refer to the HA Guide for information on the upgrade procedures for HA configurations. HA Guide MR3 : http://docs.fortinet.com/...te-ha-40-mr3.pdf When operating in an HA cluster, FortiGate devices can be upgraded automatically with the HA option "uninterruptable-upgrade" which is enabled by default. The advantages of the uninterruptable upgrade process are: - Allows the Administrator to upgrade all devices of a cluster in a single operation (from the GUI, click Dashboard --> Status --> Firmware Version --> upgrade). - It upgrades (all) Slave(s) unit(s) before upgrading the Master, making the necessary failover for a minimum downtime. Please ensure you backup the configuration file before each upgrade. Please do go through the release notes before any upgrade. Kindly refer you to follow the steps from this KB document: http://kb.fortinet.com/kb...0%200%2039132136 or from this one,if you prefer the manual upgrade procedure of a FortiGate HA cluster http://kb.fortinet.com/kb...0%200%2045256491
let me know how you proceed
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.