Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rege142
New Contributor

Firmware upgrade policy

This morning we received this e-mail

Dear Customer, We are reaching out to inform you about an important update regarding FortiGates provisioned to FortiGate Cloud without active subscriptions. To ensure robust security posture of your devices, starting Feb 28, 2025 FortiGate devices without an active FortiGate Cloud subscription will be required to upgrade to the latest firmware patch within 7 days of patch GA release. This change ensures enhanced security, reliability, and compliance with the latest features and updates provided by FortiGate Cloud. FortiGate Cloud will provide notification and prompts for upgrade when new patches are available on the web portal and the option to configure the upgrade time/day window of choice within 7-day schedule for convenience. Please note that cloud access and log upload to FortiGate Cloud can be restricted if not upgraded for devices without subscription https://mobdro.bio/ .

What does this mean for you:

⁠To maintain uninterrupted service, make sure to apply firmware updates promptly within the 7-day window for devices without subscription. FortiOS auto-patch upgrade feature can be used to stay on the latest firmware patches.

⁠For all devices, review your FortiGate Cloud subscription status and firmware upgrade settings to ensure devices are up to date with the latest firmware patch versions. Reminding feature is available for devices with active FortiGate Cloud subscription only.

How are you all looking at this? Because of bugs etc we Follow the recommended guide but not always the newest

11 REPLIES 11
adambomb1219
SuperUser
SuperUser

Sounds reasonable to me and inline with other vendor's management solutions.  Note this only applies to firewalls without subscriptions.  If you pay for FortiGate Cloud or manage with a FortiManager you have MUCH greater controls on firmware.

IrbkOrrum
Contributor

We got this as well and I'm not very happy about it.  I think we only use FortiCloud "free" for the logging and don't have a "subscription" but I'm not really sure.  My biggest problem is, I can't guarantee that I can upgrade my firewalls within 7 days of an update.  These are all in production environments and the only time I could potentially update them is on a Sunday when any outage will cause minimal downtime to production.  Further, before any updates can be applied I need to check the release notes and go through a change control board.  If a update comes out on a friday afternoon, I've missed the window to submit it to my change control board, I won't be able to do the update that sunday so I won't be within compliance.  I've got a ticket open with support to figure out 1. If I'm actually effected by this and what happens if I'm not in compliance. 2 What do I need to purchase to not be forced into firmware upgrades that I don't want.  I've chatted with web support and they didn't even seem to fully understand the situation either.  

popeboy1
New Contributor

I am just trying to verify that this email applies to our installation.  I have attached a pic of our FortiGate Cloud licensing.  I believe it will apply to us but wanted to make sure.

Fortigate Cloud Licensing.JPG

 

 

 

 

 

 

 

Also, what happens if you are out of compliance?  I just recently had to wait a month to apply an update when an authentication change in the fortigate broke Duo authentication and we had to roll back an update to allow VPN access.

IrbkOrrum

Yeah, I'm in the same boat as far as trying to figure out if it effects me and what happens when you're out of compliance.

Screenshot_1.jpg

ichnobyte
New Contributor

I spoke with live chat support and they indicated that it is necessary to have a ‘paid subscription’ in order not to be affected by the new restrictions.

 

The remaining doubt is on the point ‘Please note that cloud access and log upload to FortiGate Cloud can be restricted if not upgraded for devices without subscription’.

What does this actually entail?

IrbkOrrum

According to support "If you don't upgrade within the 7 days access to the current logs could be restricted and new logs might not be recorded in the Cloud. Once the upgrade is completed access to the Logs and new logs will be recorded".  So what that means to me is, if you aren't on the firmware revision they require, your logs won't successfully ship to forticloud, so you won't get your free 7 days worth of logs.  Once you upgrade, logging should be back online again.

mattias_larsson
New Contributor

If anyone else is wondering, I just got confirmation from Fortinet support that the "latest firmware patch" means in the current major version you are in. So if you are in 7.2.x then it's the latest 7.2.x patch, if you are in 7.4.x then it's the latest 7.4.x patch, etc.

ichnobyte

I hope they are talking about the Mature version and not the Feature ...

mattias_larsson

Yes, it's the Mature version.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors