Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

Upgrading Of HA firewall - synchronisation fails

Whenever I upgrade a HA firewall, there will be synchronisation errors.

How do you solve it other than upgrading the secondary firewall after the primary manually?

Isnt the firmware supposed to be pushed down automatically?

3 REPLIES 3
srajeswaran
Staff
Staff

Ideally there won't be a sync issue (it may take few minutes to sync initially). Did you follow the recommended upgrade path  (https://docs.fortinet.com/upgrade-tool) ?

Can you share the errors you are seeing along with the versions?

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

parteeksharma

Dear BusinessUser,
Hope you are doing good.
If you are performing an HA cluster upgrade, it will automatically push the image to secondary device. If your FortiGate is in HA cluster, refer the below document for HA cluster firmware upgrade

https://docs.fortinet.com/document/fortigate/6.4.0/cookbook/247944/upgrading-fortigates-in-an-ha-clu...

To check the issue related to cluster synchronization after firmware upgrade, please check if both devices in cluster are upgraded and then you can follow below document for the cluster synchronization issue:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-HA-synchronization-issue-cluster-out...

Regards,
Parteek


RachelGomez123
Contributor

When upgrading a HA firewall, synchronization errors can occur between the primary and secondary firewalls. To address this issue:

Verify the HA configuration for any misconfigurations.
Upgrade the primary firewall first and ensure synchronization before upgrading the secondary firewall.
Check firmware compatibility and review release notes for guidance.
Troubleshoot synchronization errors by verifying connectivity, restarting the synchronization process, and checking logs.
Contact vendor support for further assistance if needed.
Automatic firmware push depends on the firewall vendor and configuration, with some offering this feature while others require manual intervention. Consult vendor documentation for specifics.

Regards,

Rachel Gomez

 

Labels
Top Kudoed Authors