Fortinet black logo

BIOS-level signature and file integrity checking during downgrade

BIOS-level signature and file integrity checking during downgrade

When downgrading to a version of FortiOS prior to 6.4.13, 7.0.12, and 7.2.5 that does not support BIOS-level signature and file integrity check during bootup, the following steps should be taken if the BIOS version of the FortiGate matches the following versions:

  • 6000100 or greater

  • 5000100 or greater

To downgrade or upgrade to or from a version that does not support BIOS-level signature and file integrity check during bootup:
  1. If the current security level is 2, change the security level to 0. This issue does not affect security level 1 or below.

  2. Downgrade to the desired FortiOS firmware version.

  3. If upgrading back to 6.4.13, 7.0.12, 7.2.5, 7.4.0, or later, ensure that the security level is set to 0.

  4. Upgrade to the desired FortiOS firmware version.

  5. Change the security level back to 2.

To verify the BIOS version:

The BIOS version is displayed during bootup:

Please stand by while rebooting the system.
Restarting system
FortiGate-1001F (13:13-05.16.2023)
Ver:06000100
To verify the security level:
# get system status
Version: FortiGate-VM64 v7.4.2,build2571,231219 (GA.F)
First GA patch build date: 230509
Security Level: 1
To change the security level:
  1. Connect to the console port of the FortiGate.

  2. Reboot the FortiGate (execute reboot) and enter the BIOS menu.

  3. Press [I] to enter the System Information menu

  4. Press [U] to enter the Set security level menu

  5. Enter the required security level.

  6. Continue to boot the device.

BIOS-level signature and file integrity checking during downgrade

When downgrading to a version of FortiOS prior to 6.4.13, 7.0.12, and 7.2.5 that does not support BIOS-level signature and file integrity check during bootup, the following steps should be taken if the BIOS version of the FortiGate matches the following versions:

  • 6000100 or greater

  • 5000100 or greater

To downgrade or upgrade to or from a version that does not support BIOS-level signature and file integrity check during bootup:
  1. If the current security level is 2, change the security level to 0. This issue does not affect security level 1 or below.

  2. Downgrade to the desired FortiOS firmware version.

  3. If upgrading back to 6.4.13, 7.0.12, 7.2.5, 7.4.0, or later, ensure that the security level is set to 0.

  4. Upgrade to the desired FortiOS firmware version.

  5. Change the security level back to 2.

To verify the BIOS version:

The BIOS version is displayed during bootup:

Please stand by while rebooting the system.
Restarting system
FortiGate-1001F (13:13-05.16.2023)
Ver:06000100
To verify the security level:
# get system status
Version: FortiGate-VM64 v7.4.2,build2571,231219 (GA.F)
First GA patch build date: 230509
Security Level: 1
To change the security level:
  1. Connect to the console port of the FortiGate.

  2. Reboot the FortiGate (execute reboot) and enter the BIOS menu.

  3. Press [I] to enter the System Information menu

  4. Press [U] to enter the Set security level menu

  5. Enter the required security level.

  6. Continue to boot the device.