After upgrading the firmware of the FortiGate 200F in an HA setup from 7.0.5 to 7.2.2, the VPN tunnel configuration was lost. Ideally, we would like to upgrade all the way to version 7.4.3. Please advise on how to prevent the VPN tunnel settings from being erased during the upgrade, and whether there is a recommended upgrade path that avoids this issue.
Additionally, the FortiGate 200F is connected to a media converter (ONU) provided by the ISP on the WAN side. Before the upgrade, the device was able to automatically obtain an IP address even with the interface set to 0.0.0.0. However, after the upgrade, it no longer receives an IP address.
We reverted the firmware to the previous version and restored the backed-up configuration, but the IP address is still not being assigned. Although the configuration matches exactly with the pre-upgrade state, we suspect that some internal setting may have changed.
We would greatly appreciate your guidance on how to ensure the VPN tunnel settings are preserved during the upgrade, and how to restore automatic IP address assignment from the ONU.
7.0.5 to 7.2.2 is the right upgrade path.
In normal conditions IPsec config is not lost after upgrade.
Please run this command before and after the upgrade, and share the output.
diag debug config-error-log read
This will let us check if there is config errors before and after the upgrade.
Thank you for your response.
The IP address of the interface that the tunnel passes through is not configured manually, as it is assigned via DHCP from the carrier’s ONU. However, after the firmware upgrade and also after reverting to the original firmware, the IP address is no longer automatically assigned, which might be affecting the situation.
Since reverting to the original firmware did not restore communication, I am currently using a fixed IP address to establish communication.
Next time I attempt this again, I plan to run the commands you provided to check and verify.
User | Count |
---|---|
2552 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.