Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Supercalar
New Contributor

How to upgrade firmware FGT200D Using the HA Active-Active

How to upgrade firmware FGT200D Using the HA Active-Active

 

Can I login to web UI to Master and put firmware and upgrade  or I have to disable any function before  

 

FGT200D not enable vdom

6 REPLIES 6
ede_pfau
SuperUser
SuperUser

You can log in via GUI to the cluster (not to the master, in case you have mgmt ports configured), and initiate the upgrade. The cluster master will schedule the upgrade for the slave first, reboot it, fail over and upgrade itself.

 

There is not much you need to configure before starting. I would recommend (as FTNT) to disable HA port monitoring during the process.

 

Of course, keep an image of the currently running firmware at hand, as well as the current backup - for both master and slave (here the mgmt ports comes in...), and please, READ the Release Notes. Check what's changed and dependencies towards FortiClient, FortiMail, FortiSandbox, FortiAnalyzer, FortiAP.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Alexis_G
Contributor II

The easiest way is to login from GUI on master and upload firmware. Master will first upgrade the subordinary unit, the subordinary will reload, then the master will upgrade and then reload.

 

Considerations you need to examine:

Read release notes especially when upgrade path is needed.

Preemtion settings : (set override enable | disable)

session sync settings : (session-pickup {disable | enable})

Also its good to have console access (not only ssh) during upgrade to see the output.

 

 

--------------------------------------------

If all else fails, use the force !

-------------------------------------------- If all else fails, use the force !
Supercalar

Thank you for the information

Supercalar

I have one more question. If downgrading to a previous version. How can I do that

Alexis_G

If it was production , you need also the config while on previous configuratio, The downgrade is the same procedure. Upload the FortiOS and downgrade.

 

If you upgrade lateley then the previous Firmware along with the previous configuration co-exists in another partition, so you select (after you chech that exists) to boot from the other partition.

// Disk inventory  diagnose system flash list  diagnose system disk  execute set-next-reboot {primary | secondary} // selecting which firmware will be used at the next reboot

--------------------------------------------

If all else fails, use the force !

-------------------------------------------- If all else fails, use the force !
Alexis_G
Contributor II

You need first to read the release notes and the upgrade guide, and / or upgrade path

then you take config backup

then uploade FortiOS on Primary. Primary will itself first upgrade the secondary, the secondary will reload, then the primary will upgrade, reload, finish.

 

--------------------------------------------

If all else fails, use the force !

-------------------------------------------- If all else fails, use the force !
Labels
Top Kudoed Authors