Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Infotech22
Contributor

Upgrades of Firmware / Automation

Hello forum,

I would like to know how many of you are dealing with upgrades of firmware from Fortinet Devices.
We have a range of Fortinet equipment, FortiGates, FortiAZ, FortiSwitches, FortiAPs.
We have them on multiple locations.

How you guys are dealing with upgrades, where to look if the upgrade is suitable for us, what type of automation you use, etc..

It's really hard to catch up with everything since I'm not just a Fortinet guy. I'm System Admin so I have a lot of other task's and its getting overwhelmed.. 

 

1 Solution
Jakob-AHHG
Contributor II

Hi @Infotech22 

We have 2 ways:

Manual (local or via FortiManager )

Automated via FortiManager.

 

We are on latest FMG (74.2), and there you find it under:
Device Manager: Firmware Templates:

FMG Firmware Templates.png
 
Create a Template, and assign desired FW versions to the products, either generic or specific:
 
FMG Firmware Templates Model details.png

You can then schedule the template run run as desired, or run it manually.

 

 

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK

View solution in original post

Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
14 REPLIES 14
Jakob-AHHG
Contributor II

Hi @Infotech22 

We have 2 ways:

Manual (local or via FortiManager )

Automated via FortiManager.

 

We are on latest FMG (74.2), and there you find it under:
Device Manager: Firmware Templates:

FMG Firmware Templates.png
 
Create a Template, and assign desired FW versions to the products, either generic or specific:
 
FMG Firmware Templates Model details.png

You can then schedule the template run run as desired, or run it manually.

 

 

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Infotech22

Thank you @Jakob-AHHG,

We already have FortiManager but last external company didn't use it and suggest to us that we don't need it for 4 locations. But it's 8 Firewalls, 20+ switches, 20-30 AP's etc.

Firewall Policies can't be the same so we couldn't use the template but for upgrades is still really good to us then.

Jakob-AHHG

OK, we run 16 locations, and have them split in 3 Policy Groups for FW rules, and I currently have 4 FW Templates.


Granted, there are management stuff that is easier to do directly on a device, but when it's all in sync on FGM, you know what's going on, and it's easier to troubleshoot in tandem with FortiAnalyzer.

 

And if you then start to figure out Scripts, to do CLI config changes on multiple FortiGates, initiated from FGM, life becomes a lot less tedious.. ;) 

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Infotech22

Yes of course, some small stuff like address object's etc its really useful to have them synced across all locations.

As I can see that you are experienced in this area, let me know where I can contact you to learn from you ;)

Jakob-AHHG

Still learning, have been using FortiNet for two years now, but have 22 FG's and close to 100 FortiSwitches in the setup now.
Just about to replace Wifi on a complete hotel with FortiAP's (from Cisco).
So 270 FortiAP's being installed the next few weeks.

Arp-Hansen Hotel Group is in Copenhagen, Denmark - and all our sites is here in DK.

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Infotech22

It's a big infrastructure to be in. And it's also great for experience that you will gain.
Our infrastructure is lot smaller but its in different countries.
Engineering and Software Development so I need to hop on on the Fortinet train as fast as I can to help company achieve the most security we can get with this.

Hope your implementation goes well

johnlloyd_13

hi,

do you recommend FG firmware on local device instead of FMG fimware template?

does local FG firmware upgrade "breaks" any device or FW policy in FMG? or will it auto update?

Thanks,
John
Thanks,John
Jakob-AHHG

If you manually upgrade a device, Manager will just update the status when it comes back online. It does not break anything, but is simply a more slow process, but you are in detailed control.

You can do the 'manual' upgrade of a single device, either on the devices own interface, that requires you manually download the FW from Fortinet, or you can select it in the Switch Manager part of Manager and initiate a manual update from there, selecting the desired FW version.

 

If you run a FW Template on a group of devices, Manager will show you what devices needs updates, and let you initiate that process.

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
AEK
SuperUser
SuperUser

Hello

where to look if the upgrade is suitable for us

For me the rule is simple:

  • Always start with a mature/recommended version
  • Read release notes before update/upgrade, i.e.: known bugs, new features, ...
  • Typically update the firmware every time there is a new patch, e.g.: from 7.0.12 to 7.0.13
  • Do not upgrade unless there is a new feature that is required and/or until the new release is mature. E.g.: 6.4.x to 7.0.x
AEK
AEK
Labels
Top Kudoed Authors