Fortinet white logo
Fortinet white logo

Upgrade information

Upgrade information

Refer to the Upgrade Path Tool (https://docs.fortinet.com/upgrade-tool) in the Fortinet documentation library to find supported upgrade paths for all FortiGate models and firmware versions.

A similar upgrade path tool is also available from Fortinet Support: https://support.fortinet.com.

See also, Upgrade information in the FortiOS 6.2.9 release notes.

In some cases, these upgrade path tools may recommend slightly different upgrade paths. If that occurs, the paths provided by both tools are supported and you can use either one.

Note

After the firmware upgrade is complete, you should check the NP queue priority configuration. In some cases the NP queue priority configuration may be incorrect after a firmware upgrade. For more information, see Check the NP queue priority configuration after a firmware upgrade.

If your FortiGate is currently running FortiOS 6.2.6 or 6.2.7 firmware and is licensed for hyperscale firewall features, you can follow a normal firmware upgrade process to upgrade to FortiOS 6.2.9.

If you are currently operating a FortiGate-4200F, 4201F, 4400F, or 4401F running FortiOS 6.2.5 or older and a hyperscale firewall license, you can upgrade in one step to FortiOS 6.2.9 because upgrading to FortiOS 6.2.9 will remove the existing hyperscale firewall configuration but the hyperscale firewall license will still be active. You can go ahead and create a new hyperscale firewall configuration for FortiOS 6.2.9.

If you are currently operating a FortiGate-4200F, 4201F, 4400F, or 4401F without a hyperscale firewall license you can use the upgrade path to upgrade to FortiOS 6.2.9. To configure hyperscale firewall features, activate your hyperscale firewall license and set up the hyperscale firewall configuration.

Caution

The FortiOS 6.2.9 hyperscale firewall configuration is very different from the 6.2.5 configuration. Upgrading a FortiGate-4200F, 4201F, 4400F, or 4401F from FortiOS 6.2.5 to 6.2.9 will require significant time for preparation and planning before the firmware upgrade and significant downtime after the firmware upgrade to create the new configuration.

To upgrade an HA cluster from FortiOS 6.2.5 and older

Recommended procedure for upgrading an HA cluster from FortiOS 6.2.5 and older to FortiOS 6.2.9:

  1. Disconnect the backup FortiGate from the cluster.

  2. Upgrade the backup FortiGate's firmware to FortiOS 6.2.9 and set the configuration to factory defaults.

  3. Create the new FortiOS 6.2.9 hyperscale firewall configuration on the backup FortiGate.

    Fortinet Support can assist with setting up the new configuration.

  4. When the backup FortiGate is reconfigured and the configuration tested you can swap network connections from the primary FortiGate to the backup FortiGate with minimal downtime.

  5. Then you can upgrade the firmware on the primary FortiGate and reset it to factory defaults.

  6. Apply the new hyperscale configuration to the primary FortiGate.

    Do this before reforming the cluster, since some configurations may require restarting the FortiGate.

  7. Add the primary FortiGate back to the cluster to re-form the cluster.

To upgrade a standalone FortiGate from FortiOS 6.2.5 and older

To upgrade a standalone FortiGate from FortiOS 6.2.5 and older to FortiOS 6.2.9, Fortinet recommends preparing the new configuration on a test device if possible before configuring your production FortiGate. Fortinet Support can help with planning, configuration, and conversion.

Upgrade information

Upgrade information

Refer to the Upgrade Path Tool (https://docs.fortinet.com/upgrade-tool) in the Fortinet documentation library to find supported upgrade paths for all FortiGate models and firmware versions.

A similar upgrade path tool is also available from Fortinet Support: https://support.fortinet.com.

See also, Upgrade information in the FortiOS 6.2.9 release notes.

In some cases, these upgrade path tools may recommend slightly different upgrade paths. If that occurs, the paths provided by both tools are supported and you can use either one.

Note

After the firmware upgrade is complete, you should check the NP queue priority configuration. In some cases the NP queue priority configuration may be incorrect after a firmware upgrade. For more information, see Check the NP queue priority configuration after a firmware upgrade.

If your FortiGate is currently running FortiOS 6.2.6 or 6.2.7 firmware and is licensed for hyperscale firewall features, you can follow a normal firmware upgrade process to upgrade to FortiOS 6.2.9.

If you are currently operating a FortiGate-4200F, 4201F, 4400F, or 4401F running FortiOS 6.2.5 or older and a hyperscale firewall license, you can upgrade in one step to FortiOS 6.2.9 because upgrading to FortiOS 6.2.9 will remove the existing hyperscale firewall configuration but the hyperscale firewall license will still be active. You can go ahead and create a new hyperscale firewall configuration for FortiOS 6.2.9.

If you are currently operating a FortiGate-4200F, 4201F, 4400F, or 4401F without a hyperscale firewall license you can use the upgrade path to upgrade to FortiOS 6.2.9. To configure hyperscale firewall features, activate your hyperscale firewall license and set up the hyperscale firewall configuration.

Caution

The FortiOS 6.2.9 hyperscale firewall configuration is very different from the 6.2.5 configuration. Upgrading a FortiGate-4200F, 4201F, 4400F, or 4401F from FortiOS 6.2.5 to 6.2.9 will require significant time for preparation and planning before the firmware upgrade and significant downtime after the firmware upgrade to create the new configuration.

To upgrade an HA cluster from FortiOS 6.2.5 and older

Recommended procedure for upgrading an HA cluster from FortiOS 6.2.5 and older to FortiOS 6.2.9:

  1. Disconnect the backup FortiGate from the cluster.

  2. Upgrade the backup FortiGate's firmware to FortiOS 6.2.9 and set the configuration to factory defaults.

  3. Create the new FortiOS 6.2.9 hyperscale firewall configuration on the backup FortiGate.

    Fortinet Support can assist with setting up the new configuration.

  4. When the backup FortiGate is reconfigured and the configuration tested you can swap network connections from the primary FortiGate to the backup FortiGate with minimal downtime.

  5. Then you can upgrade the firmware on the primary FortiGate and reset it to factory defaults.

  6. Apply the new hyperscale configuration to the primary FortiGate.

    Do this before reforming the cluster, since some configurations may require restarting the FortiGate.

  7. Add the primary FortiGate back to the cluster to re-form the cluster.

To upgrade a standalone FortiGate from FortiOS 6.2.5 and older

To upgrade a standalone FortiGate from FortiOS 6.2.5 and older to FortiOS 6.2.9, Fortinet recommends preparing the new configuration on a test device if possible before configuring your production FortiGate. Fortinet Support can help with planning, configuration, and conversion.