BIOS-level signature and file integrity checking during downgrade
When downgrading to a version of FortiOS prior to 6.4.13, 7.0.12, and 7.2.5 that does not support BIOS-level signature and file integrity check during bootup, the following steps should be taken if the BIOS version of the FortiGate matches the following versions:
-
6000100 or greater
-
5000100 or greater
To downgrade or upgrade to or from a version that does not support BIOS-level signature and file integrity check during bootup:
-
If the current security level is 2, change the security level to 0. This issue does not affect security level 1 or below.
-
Downgrade to the desired FortiOS firmware version.
-
If upgrading back to 6.4.13, 7.0.12, 7.2.5, 7.4.0, or later, ensure that the security level is set to 0.
-
Upgrade to the desired FortiOS firmware version.
-
Change the security level back to 2.
To verify the BIOS version:
The BIOS version is displayed during bootup:
Please stand by while rebooting the system. Restarting system FortiGate-1001F (13:13-05.16.2023) Ver:06000100
To verify the security level:
# get system status Version: FortiGate-VM64 v7.4.2,build2571,231219 (GA.F) First GA patch build date: 230509 Security Level: 1
To change the security level:
-
Connect to the console port of the FortiGate.
-
Reboot the FortiGate (
execute reboot
) and enter the BIOS menu. -
Press [
I
] to enter the System Information menu -
Press [
U
] to enter the Set security level menu -
Enter the required security level.
-
Continue to boot the device.