Fortinet black logo

Performing a clean firmware installation

Copy Link
Copy Doc ID ffe46156-9bab-11eb-b70b-00505692583a:365302
Download PDF

Performing a clean firmware installation

Performing a clean firmware installation can be useful if:

  • You are unable to connect to the FortiVoice Gateway using the web‑based manager or the CLI.
  • You want to install firmware without preserving any existing configuration.
  • A firmware version that you want to install requires that you format the boot device (see the Release Notes accompanying the firmware).

Unlike upgrading or downgrading firmware, performing a clean firmware installation re-images the boot device. Also, a clean installation can only be done during a boot interrupt, before network connectivity is available, and therefore requires a local console connection to the CLI. A clean installation cannot be done through a network connection.

Caution

Back up your configuration before beginning this procedure, if possible. A clean installation resets the configuration, including the IP addresses of network interfaces. For information on backups, see Backing up the configuration. For information on reconnecting to a FortiVoice Gateway whose network interface configuration has been reset, see Reconnecting to the FortiVoice Gateway.

Caution

If you are reverting to a previous FortiVoice Gateway version, you might not be able to restore your previous configuration from the backup configuration file.

To perform a clean firmware installation
  1. Download the firmware file from the Fortinet Customer Service and Support website.
  2. Connect your management computer to the FortiVoice Gateway console port using an RJ-45 to DB-9 serial cable or a null-modem cable.
  3. Initiate a local console connection from your management computer to the CLI of the FortiVoice Gateway, and log in as the admin administrator, or an administrator account that has system configuration read and write privileges.
  4. Connect port1 of the FortiVoice Gateway directly to the same subnet as a TFTP server.
  5. Copy the new firmware image file to the root directory of the TFTP server.
  6. Verify that the TFTP server is currently running, and that the FortiVoice Gateway can reach the TFTP server.

    To use the FortiVoice Gateway CLI to verify connectivity, if it is responsive, enter the following command:

    execute ping 192.168.2.99

    where 192.168.2.99 is the IP address of the TFTP server.

  7. Enter the following command to restart the FortiVoice Gateway:

    execute reboot

    or power off and then power on the FortiVoice Gateway.

  8. As the FortiVoice Gateway starts, a series of system startup messages are displayed.

    Press any key to display configuration menu........

  9. Immediately press a key to interrupt the system startup.
    Caution

    You have only 3 seconds to press a key. If you do not press a key soon enough, the FortiVoice Gateway reboots and you must log in and repeat the execute reboot command.

    If you successfully interrupt the startup process, the following messages appear:

    [G]: Get firmware image from TFTP server.

    [F]: Format boot device.

    [B]: Boot with backup firmware and set as default.

    [I]: Configuration and information.

    [Q]: Quit menu and continue to boot with default firmware.

    [H]: Display this list of options.

    Enter G,F,B,I,Q,or H:

  10. If the firmware version requires that you first format the boot device before installing firmware, type F. (Format boot device) before continuing.
  11. Type G to get the firmware image from the TFTP server.

    The following message appears:

    Enter TFTP server address [192.168.2.99]:

  12. Type the IP address of the TFTP server and press Enter.

    The following message appears:

    Enter Local Address [192.168.1.188]:

  13. Type a temporary IP address that can be used by the FortiVoice Gateway to connect to the TFTP server.

    The following message appears:

    Enter File Name [image.out]:

  14. Type the firmware image file name and press Enter.

    The FortiVoice Gateway downloads the firmware image file from the TFTP server and displays a message similar to the following:

    Save as Default firmware/Backup firmware/Run image without saving:[D/B/R]

  15. Type D.

    The FortiVoice Gateway downloads the firmware image file from the TFTP server. The FortiVoice Gateway installs the firmware and restarts. Time required varies by the size of the file and the speed of your network connection.

    The FortiVoice Gateway reverts the configuration to default values for that version of the firmware.

  16. Clear the cache of your web browser and restart it to ensure that it reloads the web-based manager and correctly displays all tab, button, and other changes.
  17. To verify that the firmware was successfully installed, log in to the CLI and type:

    get system status

    The firmware version number appears.

  18. Either reconfigure the FortiVoice Gateway or restore the configuration file from a backup. For details, see Restoring the configuration.

Performing a clean firmware installation

Performing a clean firmware installation can be useful if:

  • You are unable to connect to the FortiVoice Gateway using the web‑based manager or the CLI.
  • You want to install firmware without preserving any existing configuration.
  • A firmware version that you want to install requires that you format the boot device (see the Release Notes accompanying the firmware).

Unlike upgrading or downgrading firmware, performing a clean firmware installation re-images the boot device. Also, a clean installation can only be done during a boot interrupt, before network connectivity is available, and therefore requires a local console connection to the CLI. A clean installation cannot be done through a network connection.

Caution

Back up your configuration before beginning this procedure, if possible. A clean installation resets the configuration, including the IP addresses of network interfaces. For information on backups, see Backing up the configuration. For information on reconnecting to a FortiVoice Gateway whose network interface configuration has been reset, see Reconnecting to the FortiVoice Gateway.

Caution

If you are reverting to a previous FortiVoice Gateway version, you might not be able to restore your previous configuration from the backup configuration file.

To perform a clean firmware installation
  1. Download the firmware file from the Fortinet Customer Service and Support website.
  2. Connect your management computer to the FortiVoice Gateway console port using an RJ-45 to DB-9 serial cable or a null-modem cable.
  3. Initiate a local console connection from your management computer to the CLI of the FortiVoice Gateway, and log in as the admin administrator, or an administrator account that has system configuration read and write privileges.
  4. Connect port1 of the FortiVoice Gateway directly to the same subnet as a TFTP server.
  5. Copy the new firmware image file to the root directory of the TFTP server.
  6. Verify that the TFTP server is currently running, and that the FortiVoice Gateway can reach the TFTP server.

    To use the FortiVoice Gateway CLI to verify connectivity, if it is responsive, enter the following command:

    execute ping 192.168.2.99

    where 192.168.2.99 is the IP address of the TFTP server.

  7. Enter the following command to restart the FortiVoice Gateway:

    execute reboot

    or power off and then power on the FortiVoice Gateway.

  8. As the FortiVoice Gateway starts, a series of system startup messages are displayed.

    Press any key to display configuration menu........

  9. Immediately press a key to interrupt the system startup.
    Caution

    You have only 3 seconds to press a key. If you do not press a key soon enough, the FortiVoice Gateway reboots and you must log in and repeat the execute reboot command.

    If you successfully interrupt the startup process, the following messages appear:

    [G]: Get firmware image from TFTP server.

    [F]: Format boot device.

    [B]: Boot with backup firmware and set as default.

    [I]: Configuration and information.

    [Q]: Quit menu and continue to boot with default firmware.

    [H]: Display this list of options.

    Enter G,F,B,I,Q,or H:

  10. If the firmware version requires that you first format the boot device before installing firmware, type F. (Format boot device) before continuing.
  11. Type G to get the firmware image from the TFTP server.

    The following message appears:

    Enter TFTP server address [192.168.2.99]:

  12. Type the IP address of the TFTP server and press Enter.

    The following message appears:

    Enter Local Address [192.168.1.188]:

  13. Type a temporary IP address that can be used by the FortiVoice Gateway to connect to the TFTP server.

    The following message appears:

    Enter File Name [image.out]:

  14. Type the firmware image file name and press Enter.

    The FortiVoice Gateway downloads the firmware image file from the TFTP server and displays a message similar to the following:

    Save as Default firmware/Backup firmware/Run image without saving:[D/B/R]

  15. Type D.

    The FortiVoice Gateway downloads the firmware image file from the TFTP server. The FortiVoice Gateway installs the firmware and restarts. Time required varies by the size of the file and the speed of your network connection.

    The FortiVoice Gateway reverts the configuration to default values for that version of the firmware.

  16. Clear the cache of your web browser and restart it to ensure that it reloads the web-based manager and correctly displays all tab, button, and other changes.
  17. To verify that the firmware was successfully installed, log in to the CLI and type:

    get system status

    The firmware version number appears.

  18. Either reconfigure the FortiVoice Gateway or restore the configuration file from a backup. For details, see Restoring the configuration.