Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
stefano_gobbi
New Contributor

problem with HA after firmware upgrade

hello to everybody, I have two Fortigate 110C in HA cluster. I have update the firmware from MR1 to MR3 on Forti master . I have read all the docs about upgrade from MR1 to MR3. And I did it. after the reboot of the master, it cannot see the slave with the firmware release MR1. I have read that for working HA, the cluster unit must have the same firmware. Actually I connect to Forti remotly by Avocent. So I thought to modify the IP address of the slave, disable all the other interfaces, modify HA from a-a to standalone connect via https with the new IP address set, to update the firmware. But it doesn' t work. I cannot access forti slave via https, even I set a different IP. do you have any idea? do I miss something? Onother work around is to downgrade the firmware on forti master... What do you think? thanks. bye.
8 REPLIES 8
Matthijs
New Contributor II

you can try to update the slave with the command execute restore image ftp etc... but i have never tried that. The best thing is to go over there, factory default the secondary unit, upgrade it and join it in the cluster again ;)
stefano_gobbi
New Contributor

hi, thanks for the replay. Actually the forti unit istoo farway from me! I have an further information then the message I posted yesterday. I processed the following steps for upgrading the forti cluster: I upgraded on forti master from v4 MR1 patch 6 -> v4 MR1 patch 10 -> v4 MR3 patch 5 -> v4 MR3 patch 7. the master is updated on the last release, instead the slave is updated to v4 MR1 patch 10. After that, the slave is out from the cluster. maybe because of eh too different firmware version. do you think if I downgrade the master from v4 MR3 patch 7 to v4 MR3 patch 5 could resolve the problem? maybe the master force to upgrade the slave. what do you think? thanks.
Matthijs
New Contributor II

Can you ask someone to provide remote support? Create a usb stick with a config file called fgt_system.conf with a new config backup of your master and only hostname and HA priority changed and the 4.3.7 image as image.out. Let someone disconnect the interfaces put the USB stick in and reboot the unit. Then re-connect everything and it should work.
ede_pfau
SuperUser
SuperUser

Nice idea with the USB stick but...this procedure will have to be applied to the SLAVE as it didn' t upgrade. Before doing that you' d have to disconnect the slave unit (because of the duplicate IP addresses). So all in all you need someone onsite to fix this. Doesn' t help you much but this kind of situation does not happen often. Maybe there were too many intermediate steps, or not enoough time inbetween upgrades to allow the slave to be upgraded by the master. What is the location of that cluster?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
harald21
Contributor

Hi, when you upgrade der firmware in a HA environment, both units are upgraded at the same time - so normaly you dont have to upgrade the slave firmware manually. When you connect to the master unit, do you see one or two units? (System => Dashboard => Status => System information => Cluster members) Sincerely Harald
Matthijs
New Contributor II

You can ofcourse try to get hands-on help here on the forum ;)
stefano_gobbi
New Contributor

thanks to all for the replay! in the cluster I have only the master in the cluster. the slave is disconnected from the cluster, insn' t? I entered on the by avocent on slave by CLI. I have seen the slave is on the version MR1 patch10, so it did an upgrade step. now I think the slave is out of the cluster because the different firmware version, MR3 patch 7 on the master and MR1 patch 10 on the slave. on forti docs, I have read that MR3 patch 7 does not support MR1 patch 10. so I think if I downgrade the master (upgrade the MR3 patch 5, which support upgrade from MR1 patch 10), the slave should enter on the cluster and should be upgraded. what do you think? I don' t have remote support soon!!! thanks!
stefano_gobbi
New Contributor

hello to everybody, I have tried to downgrade the master with the same firmware version of the slave. after all, the master and the slave didn' t see each other. I have read that the cluster unit should synchronize each other once the firmware have the same version. the both unit have the same configuration. I have tried to disconnect the slave in standalone mode. but I have got an error. the error shows that wan1 cannot get a mac address. but I have noticed that I cannot manage wan1, neither set status down or up seems to work. I have tried to add a mac address, but still cannot connect to the slave (setting a new IP address) do you all have any idea? the firmware of the slave is MR1 path 10, do you know if there is some problem with this patch?? thanks!! bye
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors