Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Hieuvm
New Contributor II

How to keep the connections when perform firmware update? 2 Fortinet 100e firewall with HA

We have 2 Application servers that have some applications connect locally to pg-pool on the same server. 2 Postgresql Databases servers, stacking switch between AP servers to firewall and stacking switch between firewall to DB servers. When we updated the firewall firmware, we have about 1 minute downtime for fail-over process between the firewall devices. After that, the pg-pool connection to database server disconnected once and re-connected after that. But the application still timeout and disconnect. I would like to know if there is a way to update firewall firmware on 1 firewall without network disconnection? Thank you!

12 REPLIES 12
Toshi_Esumi

If not enabled, the down period should start at the point b) in my previous comment. Then go down again (if came back up once) at the point c).

Toshi

Hieuvm
New Contributor II

Yes. That is the case of my problem. I will enable session-pickup and try it again. Thank you Mr.Toshi.

Toshi_Esumi

If you have many sessions (very busy) on the FGTs, you might still experience some down time even with session-pickup enabled at the point c). Because the swapping at point c) is almost immediate when the original primary came back up after the upgrade is done, without any time to sync the sessions with the original secondary/temporay primary.
At the point b), the original primary waits a while until all possible secondary units reply to it for the completion of secondary upgrades, which gives some time for the secondary to sync the sessions with the primary before the swap.

Toshi

Labels
Top Kudoed Authors