Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
greminn
New Contributor III

Fortigate 100A from MR1 P3 to MR3 P6

Hi There, We have an Fortigate 100A which has been running MR1 Patch 3 - we are about to have some downtime for our equipment which will allow us time to upgrade the firmware of the firewall. We will be taking backups of the config as well copies of all the settings... Any gotchas with going from MR1 P3 to MR3 P6? Many thanks! Simon
4 REPLIES 4
harald21
Contributor

Hello Simon, FortiOS 4.00 MR3patch6 is still unstable - use FOS 4.00 MR2patch11 instead. Sincerely Harald
greminn
New Contributor III

Thanks for the reply - im interested to know the main reasons why this is the case? Is not this the software that fortinet say to use (MR3patch6)? Would there be any issues going from MR1 P3 to MR2patch11? Thanks Simon
jtfinley

Would there be any issues going from MR1 P3 to MR2patch11?
Yes if trying to do it remotely. What I' d suggest is doing it in 2-3 phases. Check the Release notes of MR2p2 to see if your build is eligible for the upgrade. Then upgrade to a later firmware of MR2, then to MR3. Always check release notes for upgrade eligibility. I once made the mistake of going from MR1 to MR3 and it fubar' d the config taking it offline. Luckily it was only a few minutes away - ended up formatting the flash, TFTP the new firmware and reloaded old config.
ede_pfau
SuperUser
SuperUser

Absolutely - with Fortinet products, follow the advice in the Release Notes before upgrading anything. From MR1 to MR2, some internal structures changed which could mean that you would loose some settings. Same for the upgrade from MR2 to MR3. It' s clearly laid out in the Release Notes. The upgrade path, i.e. from which version you can upgrade to the next higher MR, is always given in the RN. Patch level never need a minimum level to be applied to. And I too recommend MR2 patch 11 as being very stable, small footprint in memory, no trouble with 100% CPU on some processes etc. etc. If you absolutely NEED the 4.3 features do the upgrade in the lab and let it run under load for a couple of days before you deploy the FGT at a remote site.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors