FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jiahoong112
Staff
Staff
Article Id 282624
Description

This article describes how to downgrade firmware between major releases on FortiGate.

 

Examples of Major Release downgrades are from v7.4.x to v7.2.x.

Minor Release downgrades are like from v7.2.5 to v7.2.3. 

Scope FortiGate.
Solution

When performing a Major Release upgrade, there can usually be changes in CLI syntax.

During the initial upgrade, the syntax and some CLI commands will change accordingly. However, when downgrading from a Major Release to another Major Release, the new syntax will not revert back to the old. As a result, weird or unexpected issues may happen. 

 

Note:

Firmware downgrade is the reverse of the upgrade path. 

For example: Upgrade path is 7.2.3 -> v7.2.6 -> v7.4.2 --- Downgrade path for this would be v7.4.2 -> v7.2.6 -> v7.2.3.

 

To avoid this problem, just restore the config that was automatically taken when the FortiGate was being upgraded in the first place, to the newly downgraded FortiGate version.

For example, if an upgrade from v7.2.5 to v7.4.0 was done, the config for v7.2.5 would have already been taken initially.

If issues are faced after the downgrade from v7.4.0 to v7.2.5, simply restore the config that was previously taken on v7.2.5.

 

For the firmware downgrade/upgrade procedure, follow this related KB article: 

Technical Tip: Upgrade/downgrade firmware in FortiOS 7.2

 

If there is no option to downgrade the firmware, simply download the firmware from: https://support.fortinet.com and manually Upload it to the FortiGate.  

 

Disclaimer:

Fortinet TAC does NOT provide stand-by support for firmware upgrades/downgrades. Call the Fortinet Support Hotline only when an issue is encountered during the upgrade/downgrade process.