Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jakob-AHHG
Contributor II

FortiGate/FortiAp Rolling Upgrade does not work?

Hi All,

 

I'm installing 250+ FortiAP's on a new site, and to test rolling-wtp-upgrade, I disabled "FortiAP auto firmware provisioning" so I could test 'rolling-upgrade'.

 

FG: 7.4.3

 

1: Rolling Upgrade never gets past first 5 AP's

Selecting many AP's (10-25 tested here), after enabling rolling-wtp-upgrade and starting a FW upgrade from the FortiGate, it always start FW upgrade on first semi-randomly-selected AP's, but after those 5 move to 'Reboting...' it never moves on. I have let it run more that 30 minutes multible times.

Anyone have this working?

 

2: Disabling Rolling Upgrade still uses RU..? ;)

Now, after I went to CLI and disabled rolling-wtp-upgrade, I did 2 more upgrades on 25 AP's, but FG is still only updating the first 5 AP's in the list.. 

 

Is this feature (hidden in CLI) just not mature, or broken, in 7.4.3??

 

After this, I've set up a Firmware Template in FortiManager and updated all the AP's from there. That seems to have worked, but not in a rolling-upgrade way, so ones we go into production monday, I will have to consider when we do this.

 

config wireless-controller setting

  set rolling-wtp-upgrade disable

end

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
7 REPLIES 7
Anthony_E
Community Manager
Community Manager

Hello Jakob,

 

I hope you are doing well :)!


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Jakob,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
ebilcari
Staff
Staff

This looks like a behavior caused by Hitless Rolling AP upgrade, "The APs are then upgraded in staggered process with some APs being immediately upgraded while others continue to provide Wi-Fi service to clients and are placed in a standby queue"

You can also enable automatic firmware updates and let FGT take car of the upgrade procedure.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Jakob-AHHG

Hi @ebilcari 
Yes, I had that enabled via CLI, but it never moves on from the first 5 AP's it starts upgrading when started. I have waited for at least an hour 2-3 times, with same results:

5 gets upgraded, the rest is left on old version.

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
ebilcari

What is the status for the other APs, are they showing the status "ISSU queued"? If yes, that means that they have connected clients that can't migrate to other APs and they will be upgraded at a later time.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Jakob-AHHG

Ok, I will give it another go, and test.

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob-AHHG

Hmm, re-enabled the rolling-update:

vFG-WLC-PHO (setting) # show
config wireless-controller setting
set country DK
set duplicate-ssid enable
set rolling-wtp-upgrade enable
set darrp-optimize-schedules "default-darrp-optimize"
end

Selected 23 AP's, and selected a local FW image.

Hit Update, and then it updated 16 AP's in first go, and instantly the last AP's when the first rebooted... 

Now the Progress has ended in 'Rebooting...' on all AP's, and has been like that for 15 minutes.
Opening the FG/WLC via a new browser, the AP's are back online a long time ago...

Jakob Peterhänsel,
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Jakob Peterhänsel,IT System Admin,Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Labels
Top Kudoed Authors