Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
v20100
New Contributor III

Upgrade from 5.4.8 to 5.6.5

Hi

Performed some minor upgrades within the 5.4 range but first time for a major one.

I read the release notes and Fortinet Security Fabric upgrade guide but still have some questions:

1) Step 3 Upgrade all end points to Forticlients 5.6.0 or later: Is it compulsory. We only use Forticlient for SSL VPN client with no Forticlient enforcement or telemetry?

 

2) Step 10: in FortiOS 5.6.5, enable Forticlient enforcement: Is it compulsory? if it is, I am guessing it is compulsory to update the client first as per step 3?!

 

At some stage, I read that upgrading from 5.4.5 to 5.6.0 breaks all your IPSEC VPN PSK. Is it still the case from 5.4.8 to 5.6.5?

 

Any other areas I need to be aware of?

 

Thanks in advance

 

3 REPLIES 3
bommi
Contributor III

Hi,

 

if you just use Forticlient for VPN you dont need the Steps 3 and 10 of the security fabric upgrade guide.

 

I never got hit by the ipsec psk problem in several upgrades from 5.4.x to 5.6.x.

But I did the upgrade to fortios >= 5.6.3 with had several workarounds for this issue.

 

Best Regards

Dominik

NSE 4/5/7

NSE 4/5/7
Toshi_Esumi

The PSK issue has been fixed by 5.6.4. If you have a zone including both parent interface and vlan subinterface, the members would be removed after the upgrade. It will be fixed with 5.6.6. I posted this issue with another thread.

https://forum.fortinet.com/tm.aspx?m=163237

 

v20100
New Contributor III

Thank you both!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors