Firmware upgrades
Fortinet Technologies Inc.
FIMs and FPMs that are missing or that show
in_sync=0
are not synchronized. To synchronize an FIM or FPM
that is not synchronized, log into the CLI of the FIM or FPM and restart it using the
execute reboot
command. If
this does not solve the problem, contact Fortinet Support at
.
If you enter the
diagnose sys confsync status | grep in_sy
command before the FIM has completely
restarted, it will not appear in the command output. As well, the Configuration Sync Monitor will temporarily show
that it is not synchronized.
5.
Once the FPM is operating normally, log back in to the primary FIM CLI and enter the following command to reset
the FPM to normal operation:
diagnose load-balance switch set-compatible <slot> disable
Configuration synchronization errors will occur if you do not reset the FPM to normal operation.
Installing FIM firmware from the BIOS after a reboot
Use the following procedure to upload firmware from a TFTP server to an FIM. The procedure involves creating a
connection between the TFTP server and one of the FIM MGMT interfaces. You don't have to use a MGMT interface on
the FIM that you are upgrading.
This procedure also involves connecting to the FIM CLI using a FortiGate-7000F front panel System Management
Module console port. From the console session, the procedure describes how to restart the FIM, interrupt the boot
process, and follow FIM BIOS prompts to install the firmware.
During this procedure, the FIM will not be able to process traffic. However, the other FIM and the FPMs should continue
to operate normally.
1.
Set up a TFTP server and copy the firmware file to the TFTP server default folder.
2.
Set up your network to allow traffic between the TFTP server and one of the FIM MGMT interfaces.
3.
Using the console cable supplied with your FortiGate-7000F, connect the SMM Console 1 port on the FortiGate-
7000F to the USB port on your management computer.
4.
Start a terminal emulation program on the management computer. Use these settings:
Baud Rate (bps) 9600, Data bits 8, Parity None, Stop bits 1, and Flow Control None.
5.
Press Ctrl-T to enter console switch mode.
6.
Repeat pressing Ctrl-T until you have connected to the FIM to be updated. Example prompt for the FIM in slot 2:
<Switching to Console: FIM02 (9600)>
7.
Optionally log in to the FIM's CLI.
8.
Reboot the FIM.
You can do this using the
execute reboot
command from the CLI or by pressing the power switch on the FIM
front panel.
9.
When the FIM starts up, follow the boot process in the terminal session, and press any key when prompted to
interrupt the boot process.
10.
To set up the TFTP configuration, press C.
11.
Use the BIOS menu to set the following. Change settings only if required.
[P]: Set image download port:
MGMT1 (the connected MGMT interface.)
[D]: Set DHCP mode:
Disabled
[I]: Set local IP address:
The IP address of the MGMT interface that you want to use to connect to the
TFTP server. This address must not be the same as the FortiGate-7000F management IP address and cannot
conflict with other addresses on your network.
FortiGate-7121F System Guide
40