Fortinet Document Library

Version:


Table of Contents

Deploying FortiGate-VMX

Resources

Upgrade Path Tool
5.6.3
Download PDF
Copy Link

Upgrades

To upgrade FortiGate-VMX, you must first upgrade FortiGate-VMX SVM, then upgrade the VMX security nodes. For information about required files, see Deployment files.

  1. To upgrade the FortiGate-VMX SVM, obtain the upgrade file: FGT_VM64_SVM-v6-buildXXXX-FORTINET.out (Upgrade).
  2. Log into the SVM management GUI at https://<IP_address>. From the Firmware menu, upload the .out file. The system reboots automatically.
  3. To upgrade the VMX security nodes, do one of the following:
    1. For a small number of VMX nodes, manually apply the FGT_VM64_VMX-v6-buildXXXX-FORTINET.out (Upgrade) file in the same way you applied to the SVM. Log into the VMX security node management GUI at https://<IP_address>, and from the Firmware menu, upload the VMX's .out file. The system reboots automatically.
    2. For a large number of VMX nodes, it is recommended to use NSX. This method is also recommended if you do not have direct access to each node's port 443 (for example, if VMX segments are isolated and only SVM has access to them).

    Note the FortiGate-VMX versions for SVM and VMX security nodes must match. Otherwise, SVM and VMX security nodes will not communicate properly. VMX security nodes will not appear as managed firewalls in SVM's management console, and firewall policies may not be as functional as expected.

    For the supported upgrade path, refer to the Fortinet cookbook. Note FortiOS is applicable to FortiGate products including the FortiGate-VMX.

Resources

Upgrades

To upgrade FortiGate-VMX, you must first upgrade FortiGate-VMX SVM, then upgrade the VMX security nodes. For information about required files, see Deployment files.

  1. To upgrade the FortiGate-VMX SVM, obtain the upgrade file: FGT_VM64_SVM-v6-buildXXXX-FORTINET.out (Upgrade).
  2. Log into the SVM management GUI at https://<IP_address>. From the Firmware menu, upload the .out file. The system reboots automatically.
  3. To upgrade the VMX security nodes, do one of the following:
    1. For a small number of VMX nodes, manually apply the FGT_VM64_VMX-v6-buildXXXX-FORTINET.out (Upgrade) file in the same way you applied to the SVM. Log into the VMX security node management GUI at https://<IP_address>, and from the Firmware menu, upload the VMX's .out file. The system reboots automatically.
    2. For a large number of VMX nodes, it is recommended to use NSX. This method is also recommended if you do not have direct access to each node's port 443 (for example, if VMX segments are isolated and only SVM has access to them).

    Note the FortiGate-VMX versions for SVM and VMX security nodes must match. Otherwise, SVM and VMX security nodes will not communicate properly. VMX security nodes will not appear as managed firewalls in SVM's management console, and firewall policies may not be as functional as expected.

    For the supported upgrade path, refer to the Fortinet cookbook. Note FortiOS is applicable to FortiGate products including the FortiGate-VMX.