Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
onalswina
New Contributor

How bad can a Fortigate FW upgrade go?

In the past few months, there were quite a few urgent updates to be applied, I never delegated them and only did them when I can afford to spend several hours in case something goes bad, but I don't know why I never had an FW update go wrong, I am thinking now its time to delegate to the L2 helpdesk.

 

What's your take on this? what was your worst experience with Fortigate Firmware upgrades?

https://omegle.onl/ vshare
7 REPLIES 7
abarushka
Staff
Staff

Hello,

 

It is recommended to check the release notes for known issues before scheduling upgrade during maintenance window.

FortiGate
srajeswaran
Staff
Staff

Generally the upgrades are smooth and don't take long.  As abarushka mentioned, please check the release notes especially the known issues section to make sure you are not hitting any critical issues.

If you have a Cluster setup, you may break the cluster and upgrade nodes individually. Upgrade one node, move traffic to the upgraded node, monitor for sometime, if everything works fine upgrade the other node and join back in cluster.

If things are not stable after upgrade, move the traffic back to non-upgraded node and then downgrade the upgraded node.

Detailed process can be found in https://community.fortinet.com/t5/FortiGate/Technical-Note-Manual-upgrade-procedure-of-a-FortiGate-H...

 

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Richie_C
Staff
Staff

Preparation is key. A few more things to consider:

  • Make sure you follow the recommended upgrade path
  • Backup the configuration
  • Have console access to the device
  • Have pre checks to create a baseline 
  • Have post checks for after the upgrade
Take a backup before making any changes
mhe
Contributor II

... and make sure that you have downloaded both the current and the new firmware before upgrading. The current one in case you need to go back (flash via TFTP)

abarushka

Hello,

 

In certain scenario it is possible to boot from secondary partition:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Selecting-an-alternate-firmware-for-the-ne...

FortiGate
Markus_M

Adding to this - prechecks:

see that HA and general data and functionality is good. Especially if there are HA problems - don't upgrade the potentially broken database.

 

And one other nice thing that is often ignored:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Selecting-an-alternate-firmware-for-the-ne...

FortiGate can boot from an alternate sector that contains the last firmware version right before this upgrade was done. Upgrade path is of course only the last step. If you have no upgrade paths to walk since you're always up-to-date on the branch, this is a like-snapshot way of restoring functionality.

Immu
New Contributor III

Labels
Top Kudoed Authors