Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
premvishwakarma
New Contributor

Firmware Upgrade - 5.2.1 to 5.4.1

Hello,

I am new to Fortinet.

I need help to upgrade firmware of my Fortinet Device.

I have FG-500D  Qty. 2 nos.  in HA Mode.

current firmaware version is 5.2.1and want to upgrade to 5.4.1

 

Please help for the above.

 

Regards,

Prem Vishwakarma

 

7 REPLIES 7
Alby23
Contributor II

http://cookbook.fortinet....grade-paths-fortios/3/

and

http://docs.fortinet.com/...65/fortigate-ha-54.pdf

and please, please, please read the release notes for every upgrade step.

 

Just as a personal note, for me it could be a little early to use 5.4.x in a model like the 500D if it's put in production environment.

Without knowing the real environment, I'll stay on 5.2.8 but it's only a personal preference and I'll move on 5.4 with release 2 or 3 (in those kind of models).

Toshi_Esumi

One additional info to Alby23's post: Based on the release notes of 5.4.1, 5.4.0 had multiple issues related to upgrades, which were fixed by 5.4.1. So I would avoid those upgrade paths via 5.4.0.

 

And my personal feeling about 5.4 stability is same as Alby23. 

seadave

I agree.  We have two 500Ds and we've had issues with 5.4.  I shouldn't have jumped in the pool so early, but I have a bad habit of being attracted to shinny things :)

 

We are not running HA, one is for prod and one is for testing.  We've had issues with IPSec VPN interface locking up and I think IPS as I'm getting little to know events related to IPS triggers in my FAZ.  I think staying with 5.2.8 for now is your best bet.

premvishwakarma

Thank you all for sharing the information and experiences. 

FG500Ds are using in Data center for productivity. 

I'll wait for 2nd or 4th release. OR will go with 5.2.8

Thanks & Regards,

Prem Vishwakarma

 

 

premvishwakarma
New Contributor

Please help me to the steps and procedure for up gradation the Firmware of my FG500D.

I have two nos of FG500D are in are in cluster HA Active- active mode.

I want to do in minimal downtime. what is the best practice for upgrading firmware in active-active HA mode.

 

Regards,

Prem

 

 

 

pcraponi

Hi,

 

First: did not update to version 5.4. Go to 5.2.8 only (5.4 is a very new version and it has bugs...).

 

Second: Enable Session Pickup on HA configuration. Check if both device are with sync ok. So, in theory, you will have no downtime.

** To check the Sync files, go to CLI on Master device and enter: diagnose sys ha cluster-csum

 

It will output the Checksum of both units. The values need be the same.

 

Regards,

Paulo R., NSE8

Regards, Paulo Raponi

Regards, Paulo Raponi
ede_pfau

One more piece of advice for short failovers: disable HA link monitors before the upgrade, re-enable after cluster has settled with the new firmware. Even FTNT recommends this.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors