In the past few months, there were quite a few urgent updates to be applied, I never delegated them and only did them when I can afford to spend several hours in case something goes bad, but I don't know why I never had an FW update go wrong, I am thinking now its time to delegate to the L2 helpdesk.
What's your take on this? what was your worst experience with Fortigate Firmware upgrades?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
It is recommended to check the release notes for known issues before scheduling upgrade during maintenance window.
Generally the upgrades are smooth and don't take long. As abarushka mentioned, please check the release notes especially the known issues section to make sure you are not hitting any critical issues.
If you have a Cluster setup, you may break the cluster and upgrade nodes individually. Upgrade one node, move traffic to the upgraded node, monitor for sometime, if everything works fine upgrade the other node and join back in cluster.
If things are not stable after upgrade, move the traffic back to non-upgraded node and then downgrade the upgraded node.
Detailed process can be found in https://community.fortinet.com/t5/FortiGate/Technical-Note-Manual-upgrade-procedure-of-a-FortiGate-H...
Preparation is key. A few more things to consider:
... and make sure that you have downloaded both the current and the new firmware before upgrading. The current one in case you need to go back (flash via TFTP)
Hello,
In certain scenario it is possible to boot from secondary partition:
Adding to this - prechecks:
see that HA and general data and functionality is good. Especially if there are HA problems - don't upgrade the potentially broken database.
And one other nice thing that is often ignored:
FortiGate can boot from an alternate sector that contains the last firmware version right before this upgrade was done. Upgrade path is of course only the last step. If you have no upgrade paths to walk since you're always up-to-date on the branch, this is a like-snapshot way of restoring functionality.
My bad experiences with firmware upgrades:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.