Fortinet black logo

Zero Touch Provisioning - Firmware Rectification

Copy Link
Copy Doc ID 97ad1787-8bb4-11e9-81a4-00505692583a:580990
Download PDF

Zero Touch Provisioning - Firmware Rectification

A target firmware version can be associated with model devices, forcing the mapped device (serial number) to upgrade when first connected.

To configure firmware rectification:
  1. Go to Device Manager > Add Device. Select Enforce Firmware Version to upgrade the model device image. Select the firmware version from the drop-down to the version to be upgraded to after auto-link. This feature works while adding a model device by Serial Number as well as by Pre-shared key.

  2. Optionally, assign a Policy Package, Device Provisioning Profile, and Group to the FortiGate model device.

  3. Go to Device Manager > Device & Groups. Trigger model device auto-link from a real FortiGate using one of the following methods:
    • Use FortiCloud to push the FortiManager serial number and IP address to FortiGate to trigger auto-link.
    • Use DHCP to assign FortiManager IP address to FortiGate. Since there is no FortiManager serial number, ensure the FortiManager Device Manager has the correct username and password for the FortiGate.
    • Log on to FortiGate. Specify the FortiManager IP address.
  4. FortiManager will show the firmware upgrade path since the linked FortiGate is version 6.0.4 and the Enforced Firmware Version is 6.0.5.

  5. The model device configuration is auto-installed, the selected policy package is assigned, and the template is also installed.

  6. The model device is then synced to the real FortiGate, the firmware version is upgraded, and the package is installed.

Zero Touch Provisioning - Firmware Rectification

A target firmware version can be associated with model devices, forcing the mapped device (serial number) to upgrade when first connected.

To configure firmware rectification:
  1. Go to Device Manager > Add Device. Select Enforce Firmware Version to upgrade the model device image. Select the firmware version from the drop-down to the version to be upgraded to after auto-link. This feature works while adding a model device by Serial Number as well as by Pre-shared key.

  2. Optionally, assign a Policy Package, Device Provisioning Profile, and Group to the FortiGate model device.

  3. Go to Device Manager > Device & Groups. Trigger model device auto-link from a real FortiGate using one of the following methods:
    • Use FortiCloud to push the FortiManager serial number and IP address to FortiGate to trigger auto-link.
    • Use DHCP to assign FortiManager IP address to FortiGate. Since there is no FortiManager serial number, ensure the FortiManager Device Manager has the correct username and password for the FortiGate.
    • Log on to FortiGate. Specify the FortiManager IP address.
  4. FortiManager will show the firmware upgrade path since the linked FortiGate is version 6.0.4 and the Enforced Firmware Version is 6.0.5.

  5. The model device configuration is auto-installed, the selected policy package is assigned, and the template is also installed.

  6. The model device is then synced to the real FortiGate, the firmware version is upgraded, and the package is installed.