Fortinet black logo

Handbook

Firmware upgrades

6.0.0
Copy Link
Copy Doc ID 4afb0436-a998-11e9-81a4-00505692583a:258529
Download PDF

Firmware upgrades

Fortinet recommends using the following steps to upgrade the firmware of the FortiGates in an FGSP deployment. Follow these steps whether or not you have enabled configuration synchronization.

For an example FGSP deployment with two FortiGates (FGT-1 and FGT-2):

  1. Switch all traffic to FGT-1.

    Configure the load balancer or router that distributes traffic between the FortiGates to send all traffic to one of the FortiGates in the FGSP deployment (in this case FGT-1).

  2. Disconnect FGT-2 from your network.

    Make sure to also disconnect the interfaces that allow heartbeat and synchronization communication with FGT-1. You want to prevent FGT-2 from communicating with FGT-1.

  3. Upgrade the firmware of FGT-2.
  4. Re-connect FGT-2's traffic interfaces (but not the interfaces used for heartbeat and synchronization communication with FGT-1).
  5. Switch all traffic to the newly upgraded FGT-2.

    Configure the load balancer or router that distributes traffic between the FortiGates to send all traffic to the FortiGate with upgraded firmware.

  6. Upgrade the firmware of FGT-1 (while heartbeat and synchronization communication with FGT-2 remains disconnected).
  7. Reconnect the FGT-2 interfaces that allow heartbeat and synchronization communication between FGT-1 and FGT-2.
  8. Restore the original traffic distribution between FGT-1 and FGT-2.

    Configure the load balancer or router to again distribute traffic to both FortiGates in the FGSP deployment.

Firmware upgrades

Fortinet recommends using the following steps to upgrade the firmware of the FortiGates in an FGSP deployment. Follow these steps whether or not you have enabled configuration synchronization.

For an example FGSP deployment with two FortiGates (FGT-1 and FGT-2):

  1. Switch all traffic to FGT-1.

    Configure the load balancer or router that distributes traffic between the FortiGates to send all traffic to one of the FortiGates in the FGSP deployment (in this case FGT-1).

  2. Disconnect FGT-2 from your network.

    Make sure to also disconnect the interfaces that allow heartbeat and synchronization communication with FGT-1. You want to prevent FGT-2 from communicating with FGT-1.

  3. Upgrade the firmware of FGT-2.
  4. Re-connect FGT-2's traffic interfaces (but not the interfaces used for heartbeat and synchronization communication with FGT-1).
  5. Switch all traffic to the newly upgraded FGT-2.

    Configure the load balancer or router that distributes traffic between the FortiGates to send all traffic to the FortiGate with upgraded firmware.

  6. Upgrade the firmware of FGT-1 (while heartbeat and synchronization communication with FGT-2 remains disconnected).
  7. Reconnect the FGT-2 interfaces that allow heartbeat and synchronization communication between FGT-1 and FGT-2.
  8. Restore the original traffic distribution between FGT-1 and FGT-2.

    Configure the load balancer or router to again distribute traffic to both FortiGates in the FGSP deployment.