Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
johnlloyd_13
Contributor

Upload firmware only in Primary FW?

hi,

i recently did a HA firmware upgrade following an upgrade path.

the selection of HA primary kept changing due to high uptime.

my question is, do i need to keep "forcing" back HA to original primary or just proceed to upload the firmware on the current primary (secondary unit).

the serial with 795 is the original primary/active and 836 is the secondary/passive.

 

# get system ha status
HA Health Status: OK
Model: FortiGate-xxF
Mode: HA A-P
Group Name: xxFW01_CLUSTER
Group ID: 0
Debug: 0
Cluster Uptime: 264 days 9:33:6
Cluster state change time: 2024-10-03 15:04:23
Primary selected using:
<2024/10/03 15:04:23> vcluster-1: FGxx836 is selected as the primary because its uptime is larger than peer member FGxx795.
<2024/10/03 15:01:40> vcluster-1: FGxx836 is selected as the primary because it's the only member in the cluster.
<2024/10/03 15:01:31> vcluster-1: FGxx836 is selected as the primary because UPGRADE_SECONDARY flag is set on peer member FGxx795.
<2024/10/03 14:59:19> vcluster-1: FGxx795 is selected as the primary because UPGRADE_PRIMARY flag is unset on peer member FGxx836.
ses_pickup: disable

 

<SNIP>

 

vcluster 1: work 169.254.0.1
Primary: FGxx836, HA operating index = 0
Secondary: FGxx795, HA operating index = 1    <<< THIS IS THE ORIGNAL PRIMARY, KEPT DOING "execute ha failover set 1" IN SERIAL WITH 836 THEN UPGRADE/UPLOAD FIRMWARE TO ORIGINAL PRIMARY

1 Solution
ndumaj

Hi,
You can proceed with upgrade process via GUI regardless of the serial number of the original primary/active.

BR

- Happy to help, hit like and accept the solution -

View solution in original post

4 REPLIES 4
johnlloyd_13

hi,

so i keep going with the upgrade path and upload the firmware file on the "primary" role regardless of the serial number of the original primary/active?

note there's no HA override or pre-empt in our environment.

ndumaj

Hi,
You can proceed with upgrade process via GUI regardless of the serial number of the original primary/active.

BR

- Happy to help, hit like and accept the solution -
Toshi_Esumi

You need to understand HA's primary selection criteria before setting up HA to make the HA behavior as you desire.
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/996846/ha-primary-unit-selec...
As described in the admin guide, if you don't set the priority/override, the uptime is the first and most deciding factor. However, if uptime difference between them is less than 5 min, the unit with the highest serial number takes the primary role. This means, when the upgrade on both units is complete, then if the lower serial number unit is the primary at that time, they communicate and swap the role over at the end.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors