Hi
Performed some minor upgrades within the 5.4 range but first time for a major one.
I read the release notes and Fortinet Security Fabric upgrade guide but still have some questions:
1) Step 3 Upgrade all end points to Forticlients 5.6.0 or later: Is it compulsory. We only use Forticlient for SSL VPN client with no Forticlient enforcement or telemetry?
2) Step 10: in FortiOS 5.6.5, enable Forticlient enforcement: Is it compulsory? if it is, I am guessing it is compulsory to update the client first as per step 3?!
At some stage, I read that upgrading from 5.4.5 to 5.6.0 breaks all your IPSEC VPN PSK. Is it still the case from 5.4.8 to 5.6.5?
Any other areas I need to be aware of?
Thanks in advance
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
if you just use Forticlient for VPN you dont need the Steps 3 and 10 of the security fabric upgrade guide.
I never got hit by the ipsec psk problem in several upgrades from 5.4.x to 5.6.x.
But I did the upgrade to fortios >= 5.6.3 with had several workarounds for this issue.
Best Regards
Dominik
NSE 4/5/7
The PSK issue has been fixed by 5.6.4. If you have a zone including both parent interface and vlan subinterface, the members would be removed after the upgrade. It will be fixed with 5.6.6. I posted this issue with another thread.
https://forum.fortinet.com/tm.aspx?m=163237
Thank you both!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.