Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zato02
New Contributor II

VPN tunnels lost after 7.0.5 → 7.2.2 upgrade on FortiGate 200F

After upgrading the firmware of the FortiGate 200F in an HA setup from 7.0.5 to 7.2.2, the VPN tunnel configuration was lost. Ideally, we would like to upgrade all the way to version 7.4.3. Please advise on how to prevent the VPN tunnel settings from being erased during the upgrade, and whether there is a recommended upgrade path that avoids this issue.

Additionally, the FortiGate 200F is connected to a media converter (ONU) provided by the ISP on the WAN side. Before the upgrade, the device was able to automatically obtain an IP address even with the interface set to 0.0.0.0. However, after the upgrade, it no longer receives an IP address.

We reverted the firmware to the previous version and restored the backed-up configuration, but the IP address is still not being assigned. Although the configuration matches exactly with the pre-upgrade state, we suspect that some internal setting may have changed.

We would greatly appreciate your guidance on how to ensure the VPN tunnel settings are preserved during the upgrade, and how to restore automatic IP address assignment from the ONU.

2 REPLIES 2
AEK
SuperUser
SuperUser

7.0.5 to 7.2.2 is the right upgrade path.

In normal conditions IPsec config is not lost after upgrade.

Please run this command before and after the upgrade, and share the output.

diag debug config-error-log read 

 This will let us check if there is config errors before and after the upgrade.

AEK
AEK
Zato02
New Contributor II

Thank you for your response.
The IP address of the interface that the tunnel passes through is not configured manually, as it is assigned via DHCP from the carrier’s ONU. However, after the firmware upgrade and also after reverting to the original firmware, the IP address is no longer automatically assigned, which might be affecting the situation.

Since reverting to the original firmware did not restore communication, I am currently using a fixed IP address to establish communication.

Next time I attempt this again, I plan to run the commands you provided to check and verify.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors