Fortinet white logo
Fortinet white logo

Administration Guide

Upgrading all devices

Upgrading all devices

On the System > Firmware & Registration page, use the Upgrade all button to upgrade firmware on all supported devices. Supported devices include FortiGate, FortiAP, FortiExtender, and FortiSwitch, and the option is available for Security Fabric and non-Security Fabric devices.

Click the Upgrade all button and choose what device types to upgrade. The FortiGate Upgrade wizard opens to help you complete the following steps:

  • Choose Upgrade Type

  • Select Firmware

  • Choose Schedule

  • Review

To upgrade all device firmware in the GUI:
  1. Log in to the FortiGate GUI as an administrative user.

    When you are upgrading the Security Fabric, you must log in to the root FortiGate.

  2. Go to System > Firmware & Registration, click Upgrade all, and select one of the following options:

    Upgrade all > Devices

    Upgrades all devices, including FortiGate, FortiAP, FortiSwitch, and FortiExtender devices.

    Upgrade all > Extension devices

    Upgrades all FortiAP, FortiSwitch, and FortiExtender devices.

    Upgrade all > FortiAPs

    Upgrades all FortiAP devices.

    Upgrade all > FortiExtenders

    Upgrades all FortiExtender devices.

    Upgrade all > FortiSwitches

    Upgrades all FortiSwitch devices.

    The FortiGate Upgrade wizard opens to the Choose Upgrade Type step.

  3. On the Choose Upgrade Type step, select Full Fabric upgrade, and click Next to proceed to the Select Firmware step.

  4. For the Select Firmware step:

    1. Select firmware from one of the following tabs:

      Recommended

      Displays the recommended firmware from FortiGuard.

      When the devices are running the latest firmware from FortiGuard, the following message is displayed: The firmware is up to date.

      All Upgrades

      Displays all available firmware from FortiGuard.

      When the devices are running the latest firmware from FortiGuard, the following message is displayed: No upgrades available.

      Note

      On managed FortiAP, FortiExtender, and FortiSwitch devices, the upgrade adheres to the respective compatibility matrix information maintained on the FortiGuard Distribution Network (FDN).

    2. If the selected firmware version spans multiple builds in the upgrade path, choose one of the following options:

      Follow upgrade path

      Automatically upgrade to each firmware in the upgrade path before upgrading to the selected version. Recommended.

      FortiGate automatically completes the upgrades, including any required reboots, by downloading the chosen firmware directly from FortiGuard.

      Directly update to v<version and build number>

      Bypass the upgrade path to immediately upgrade FortiGate to the selected firmware. A warning message is displayed: Upgrading to v<version and build number> directly may result in the loss of configuration.

      Information about the selected firmware is displayed for you to consider. For example, when upgrading from mature firmware to feature firmware, a warning message appears about the maturity level of the selected firmware for the upgrade. See Firmware maturity levels for more information.

    3. Click Next to proceed to the Choose Schedule step.

  5. For the Choose Schedule step:

    1. Choose a schedule:

      Immediate

      Select to start the upgrade immediately after completing the FortiGate Upgrade wizard.

      Specify

      Select to schedule a date and time to start the upgrade after completing the FortiGate Upgrade wizard.

      Note

      When you schedule a date and time to start the upgrade, the configuration is backed up when the upgrade starts at the scheduled date and time. If the scheduled upgrade occurs after further configuration changes are made, the latest changes will not be saved in a new backup configuration file.

    2. Click Next to proceed to the Review step.

  6. For the Review step, review the upgrade plan, and click Confirm and Backup Config to proceed. The Confirm dialog box is displayed.

  7. Click Yes to start the upgrade. The Important dialog box is displayed.

  8. Read the information and click Close.

  9. Use the Firmware Upgrade tray to monitor upgrade progress.

    The FortiGate unit backs up the current configuration to the management computer, uploads the firmware image file, upgrades to the new firmware version, and restarts. This process takes a few minutes.

To upgrade all device firmware in the CLI:

The following options are available in execute federated-upgrade <option>:

Option

Description

cancel

Cancel the currently configured upgrade.

initialize

Set up a federated upgrade.

status

Show the current status of a federated upgrade.

restart

Restart the currently configured federated upgrade.

Note

The config system federated-upgrade command is read-only. Attempting to configure federated upgrade using the config command will show the following error message:

Federated upgrade cannot be configured directly.
Please use 'execute federated-upgrade ...' to configure.

Upgrading all devices

Upgrading all devices

On the System > Firmware & Registration page, use the Upgrade all button to upgrade firmware on all supported devices. Supported devices include FortiGate, FortiAP, FortiExtender, and FortiSwitch, and the option is available for Security Fabric and non-Security Fabric devices.

Click the Upgrade all button and choose what device types to upgrade. The FortiGate Upgrade wizard opens to help you complete the following steps:

  • Choose Upgrade Type

  • Select Firmware

  • Choose Schedule

  • Review

To upgrade all device firmware in the GUI:
  1. Log in to the FortiGate GUI as an administrative user.

    When you are upgrading the Security Fabric, you must log in to the root FortiGate.

  2. Go to System > Firmware & Registration, click Upgrade all, and select one of the following options:

    Upgrade all > Devices

    Upgrades all devices, including FortiGate, FortiAP, FortiSwitch, and FortiExtender devices.

    Upgrade all > Extension devices

    Upgrades all FortiAP, FortiSwitch, and FortiExtender devices.

    Upgrade all > FortiAPs

    Upgrades all FortiAP devices.

    Upgrade all > FortiExtenders

    Upgrades all FortiExtender devices.

    Upgrade all > FortiSwitches

    Upgrades all FortiSwitch devices.

    The FortiGate Upgrade wizard opens to the Choose Upgrade Type step.

  3. On the Choose Upgrade Type step, select Full Fabric upgrade, and click Next to proceed to the Select Firmware step.

  4. For the Select Firmware step:

    1. Select firmware from one of the following tabs:

      Recommended

      Displays the recommended firmware from FortiGuard.

      When the devices are running the latest firmware from FortiGuard, the following message is displayed: The firmware is up to date.

      All Upgrades

      Displays all available firmware from FortiGuard.

      When the devices are running the latest firmware from FortiGuard, the following message is displayed: No upgrades available.

      Note

      On managed FortiAP, FortiExtender, and FortiSwitch devices, the upgrade adheres to the respective compatibility matrix information maintained on the FortiGuard Distribution Network (FDN).

    2. If the selected firmware version spans multiple builds in the upgrade path, choose one of the following options:

      Follow upgrade path

      Automatically upgrade to each firmware in the upgrade path before upgrading to the selected version. Recommended.

      FortiGate automatically completes the upgrades, including any required reboots, by downloading the chosen firmware directly from FortiGuard.

      Directly update to v<version and build number>

      Bypass the upgrade path to immediately upgrade FortiGate to the selected firmware. A warning message is displayed: Upgrading to v<version and build number> directly may result in the loss of configuration.

      Information about the selected firmware is displayed for you to consider. For example, when upgrading from mature firmware to feature firmware, a warning message appears about the maturity level of the selected firmware for the upgrade. See Firmware maturity levels for more information.

    3. Click Next to proceed to the Choose Schedule step.

  5. For the Choose Schedule step:

    1. Choose a schedule:

      Immediate

      Select to start the upgrade immediately after completing the FortiGate Upgrade wizard.

      Specify

      Select to schedule a date and time to start the upgrade after completing the FortiGate Upgrade wizard.

      Note

      When you schedule a date and time to start the upgrade, the configuration is backed up when the upgrade starts at the scheduled date and time. If the scheduled upgrade occurs after further configuration changes are made, the latest changes will not be saved in a new backup configuration file.

    2. Click Next to proceed to the Review step.

  6. For the Review step, review the upgrade plan, and click Confirm and Backup Config to proceed. The Confirm dialog box is displayed.

  7. Click Yes to start the upgrade. The Important dialog box is displayed.

  8. Read the information and click Close.

  9. Use the Firmware Upgrade tray to monitor upgrade progress.

    The FortiGate unit backs up the current configuration to the management computer, uploads the firmware image file, upgrades to the new firmware version, and restarts. This process takes a few minutes.

To upgrade all device firmware in the CLI:

The following options are available in execute federated-upgrade <option>:

Option

Description

cancel

Cancel the currently configured upgrade.

initialize

Set up a federated upgrade.

status

Show the current status of a federated upgrade.

restart

Restart the currently configured federated upgrade.

Note

The config system federated-upgrade command is read-only. Attempting to configure federated upgrade using the config command will show the following error message:

Federated upgrade cannot be configured directly.
Please use 'execute federated-upgrade ...' to configure.