FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
vkulik
Staff
Staff
Article Id 197336

Description

After a product update it is often necessary to upgrade other related devices in order to maintain the compatibility.  This article provides generic recommendations on how to perform firmware updates of Fortinet products, explains the order in which to upgrade different devices and provides a guide to determine the correct upgrade path.


Solution

If multiple different Fortinet devices are being used then they should always be updated in the order: FortiManager > FortiAnalyzer > FortiGate > FortiClient.

As a rule of thumb the FortiManager and the FortiAnalyzer must be at the same or higher version as the most updated managed device otherwise some functionality may not work correctly.

When upgrading from one MR to another, ALWAYS be on the latest patch release of the current MR before updating to the next.

Consult the product release notes to find the correct upgrade path.  The product release notes are available as pdf files in the 'Download Firmware Images' section of the Fortinet Support Web Portal.  Each release note contains an upgrade information section which explains the correct upgrade path.

vkulik_FD32011_forti46a.jpg

When upgrading from a very old build it is possible that no direct upgrade path will be available.  In this case the upgrade will have to be performed using a few intermediate steps in order to retain the configuration.  Check Release notes from target version back to the current version in order to determine all the intermediate steps.

Ensure that a backup is taken of the configuration file prior to each upgrade step.  In the event of a problem during the upgrade this will allow a rollback with the installation of the latest stable build and restoration of the configuration from the backup.

When upgrading FortiAnalyzer consider also a backup of logs prior to the upgrade in addition to a backup of the configuration file. The CLI guide in the FortiAnalyzer section of the Fortinet Technical Documentation web site provides additional details regarding the backup of logs.

 

Contributors