Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SoulSeekkor
New Contributor

HowToFix - FWF90DPOE - Policies/IPSec/Etc Stop Working w/ FortiOS 5.4.1

Hi everyone, I'm simply posting this in case someone else has similar issues with this model or some other people after installing 5.4.1.  After upgrading to 5.4.1 from 5.4 everything worked perfectly...until I had to power down the device and move to another location.  After moving it I noticed strange behavior, WAN to Internal policies stop functioning completely (not even a last accessed date on them), I couldn't ping from the FortiWifi to anything internal, my IPSec tunnel wouldn't come up, and my devices were unable to pull DHCP unless they had an IP reservation set.

 

If you come across this you will want to follow these steps:

1) Backup configuration.

2) Downgrade to 5.2.8.

3) Upgrade back to 5.4 (no higher).

4) Restore configuration.

 

I tried many variations of upgrades/downgrades and everything worked with 5.4.1 until you rebooted the device, factory reset and downgrade to 5.4 didn't help at that point.

 

Hopefully this helps anyone else that runs into this and saves them the hours it took me sorting it all out.

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

I haven't experienced myself but the release notes of 5.4.1 says it fixed various problems on 5.4.0 related to upgrading from 5.2.x. So if I had 5.2.8 running steadily and if I decided to go to 5.4.x, I would skip 5.4.0 but go higher directly to avoid those known issues. Since I'm reading some posts related to 5.4.1 including yours, I'm still holding upgrading ours and our customers to 5.4.x.

SoulSeekkor

I went from 5.2.8 straight to 5.4.1 as well, everything worked perfectly.  Unfortunately after a reboot all of the same problems came back.  I'm just hoping it won't be another 6 months for an updated firmware to resolve the issue.

Toshi_Esumi

Please open a case with TAC. Otherwise the fix might not go in to the next release even after 6 months.

SoulSeekkor

Already have a ticket open. :)

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors