- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is FortiGate firmware upgraded automatically by FortiGuard?
Hi,
I have noticed that the version of FortiGate firmware is upgraded from v7.2.5 to v7.2.6 somehow.
Nothing was done manually.
Is this normal thing?
Is firmware upgraded automatically?
By FortiGuard?
Regards,
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
auto-firmware-upgrade is a new feature since 7.2.1: https://docs.fortinet.com/document/fortigate/7.2.0/new-features/369092/enable-automatic-firmware-upd...
Pre-existing configurations should stick to it being disabled, but I am not sure what the default is for new deployments. The CLI guide suggests it may vary per model: https://docs.fortinet.com/document/fortigate/7.2.6/cli-reference/94620/config-system-fortiguard
edit: To confirm if this happened to you, check your System event log for event 32263 ( https://docs.fortinet.com/document/fortigate/7.2.6/fortios-log-message-reference/32263/32263-log-id-... ), which logs when such auto-upgrade is scheduled. Note: If you have a disk-less unit, be mindful that memory-stored logs are wiped with a reboot.
Additionally, starting from 7.2.6/7.4.1, these fversions set the auto-upgrade option to enabled for all sub-100 models: https://docs.fortinet.com/document/fortigate/7.2.6/fortios-release-notes/230510/changes-in-default-b...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thank you for your reply.
The configuration shows auto-firmware-upgrade is disable as below:
--
#show full-configurat
config system fortiguard
set auto-firmware-upgrade disable
--
Are there any other possibilities that the firmware is automatically upgraded?
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am not aware of any other autonomous way of upgrading.
I would strongly recommend digging through the System Event logs (if they're available), this could tell you where the firmware image was taken from and who/what initiated the procedure.
