Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vidmooreda
New Contributor

Firmware Auto-update?

Is it just ME... or is auto-update the most dangerous and asinine thing I have ever heard? Me (for one) working in ICS/OT security, shiver at the thought of anything auto-updating. My compliance officers would shoot me in the f4ce if I ever suggested it. With the bugs in new releases, there is no way on earth I would consider this. Is there anyone out there that would actually enable this (or not disable it)? I'm interested in hearing more opinions than what my own paranoid brain is willing to offer. #fortigate #fortimanager #fortinet 

CySA, CCNA, NSE1-5, Other Squigleys.
CySA, CCNA, NSE1-5, Other Squigleys.
1 Solution
Toshi_Esumi
SuperUser
SuperUser

Most likely some of FTNT's influential customers, also probably the biggest, requested this feature to ease their workload, and responsibility in case any attacks happen, to keep up with all vulnerability issues and their fixes, which requiring immediate upgrades to all regardless how many they manage.

As long as a way to control the operation, including disabling the feature to go manual, auto-upgrade is probably a good option for many to consider once the FortiOS in the major version reaches its real maturity (not by x.xM version name) like x.8, x.9 or x.10 level since, at that time, main reasons for new releases are all vulnerability fixes and all other bug fixes. Rarely cause a new big issues all the sudden, although in the history more than 10 year span to the past there were a few issues started in later version.
Keep it in mind, the auto-upgrade wouldn't go beyond the current major version it's running now, like jumping from 7.2 to 7.4, or 7.4 to 7.6. That still has to be executed manually. We never do those "jumps" until the next major version reaches like x.8, x.9 or later, I feel auto-upgrade might not be so bad after all. But we would like more control for our own and our customers' FGT's running version of the software and we disable it for all of them. But again I see it's an option to be considered in some situations in my opinion.

Toshi

View solution in original post

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

Most likely some of FTNT's influential customers, also probably the biggest, requested this feature to ease their workload, and responsibility in case any attacks happen, to keep up with all vulnerability issues and their fixes, which requiring immediate upgrades to all regardless how many they manage.

As long as a way to control the operation, including disabling the feature to go manual, auto-upgrade is probably a good option for many to consider once the FortiOS in the major version reaches its real maturity (not by x.xM version name) like x.8, x.9 or x.10 level since, at that time, main reasons for new releases are all vulnerability fixes and all other bug fixes. Rarely cause a new big issues all the sudden, although in the history more than 10 year span to the past there were a few issues started in later version.
Keep it in mind, the auto-upgrade wouldn't go beyond the current major version it's running now, like jumping from 7.2 to 7.4, or 7.4 to 7.6. That still has to be executed manually. We never do those "jumps" until the next major version reaches like x.8, x.9 or later, I feel auto-upgrade might not be so bad after all. But we would like more control for our own and our customers' FGT's running version of the software and we disable it for all of them. But again I see it's an option to be considered in some situations in my opinion.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors