Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
WeekEnd-Engineer

Critical issue | FortiGate ON-Prem lost Serial Number after upgrade from 7.4.8 to 7.4.10

 

Environment

  • Platform: FortiGate (hardware appliance)

  • HA mode: Active / Passive

  • FortiOS current version: 7.4.8

  • Target version: 7.4.10

  • HA priorities:

    • Unit A (Master): priority 200

    • Unit B (Slave): priority 100

Expected upgrade behavior (normal case)

Based on Fortinet documentation and past experience, the expected HA upgrade sequence is:

  1. Firmware upgrade starts on the slave unit (B).

  2. Slave reboots and temporarily disconnects from HA.

  3. Cluster fails over to the upgraded slave.

  4. Firmware upgrade is then applied to the former master (A) in background.

  5. Final failback occurs according to HA priority (unit A becomes master again).

Observed behavior / Issue description

During the upgrade from 7.4.8 to 7.4.10 (firmware uploaded via GUI using .out file downloaded from fortinet official source):

  • The upgrade process took more than 20 minutes, significantly longer than usual.

  • HA became disconnected, and unit B (slave) was no longer visible from the cluster GUI.

  • Accessing unit B directly via Console & Management port (HTTPS)

I observed the following:

  • FortiOS 7.4.10 was installed successfully.

  • The license was present and recognized.

  • However, the serial number had changed to: FGT1XX0000000001

This serial number appears to be a generic / placeholder serial, which is highly concerning in a production environment.

Immediate mitigation actions taken

To protect the production environment, I took the following steps:

1. HA isolation

  • Physically disconnected the HA interface cable on unit B.

  • Objective: prevent any risk of synchronization or propagation of the issue to the master unit (A).

2. Manual downgrade on unit B

  • Performed a manual downgrade on unit B to FortiOS 7.4.8 using the .out file.

  • After reboot:

    • Original serial number was restored

    • Configuration was intact

    • System behavior returned to normal

3. HA reconnection

  • Reconnected the HA interface cable.

  • Cluster returned to a stable Active/Passive state.


Questions for the Fortinet community

1. Incident handling

  • Was isolating the HA link and downgrading the slave the correct remediation approach in this situation?

  • Are there safer or recommended containment procedures when a unit shows a default serial number after an upgrade?

2. Root cause analysis

  • What could cause a FortiGate to:

    • Boot with a generic serial number

    • While still recognizing its license?

3. Troubleshooting methodology

What would be the recommended diagnostic steps to investigate this type of incident?

Examples:

  • Specific diagnose sys ha or diagnose hardware commands

  • Logs to collect before retrying the upgrade

  • Whether execute factoryreset or execute restore image is recommended in such cases

  • Whether Fortinet advises offline upgrade (console + TFTP) instead of GUI for HA clusters, and is it recommanded to start upgrade from Slave one.

4. Prevention / best practices

  • Are there known issues upgrading HA clusters from 7.4.8 to 7.4.10? (nothing about SN changing mentionned in release Note)

  • Any Fortinet advisories related to serial number anomalies during upgrade?

  • Recommended pre-upgrade checks specific to HA environments?

 

Maybe someone struggled with same issue?

I will apprecaite any advise how to deal with it.

Many thanks

.
.
1 REPLY 1
HarryTran
Staff
Staff

Hi @WeekEnd-Engineer,

Thanks for your detail feedback!

Could you let me know the model of your FortiGates, I will try to duplicate the issue in my lab?

Regards,

Harry

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors