Yuri Slobodyanyuk Blog on Information Security 2024年07月23日
How to downgrade Fortigate Fortios version without losing the configuration
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Fortigate系统升级简单,但降级时配置文件的兼容性是个问题。文章详细介绍了如何在升级过程中保存配置,以便在需要时安全降级至早期版本,同时提出了一种官方支持的配置转换工具FortiConverter。

📝 升级Fortigate系统前需找到正确的升级路径,并通过管理员界面备份当前配置。

🚀 有有效订阅时,可直接从Fortiguard服务器升级;否则需上传Fortios镜像文件。

🔙 降级操作复杂,因为不同版本间配置命令可能存在差异,直接应用高版本配置至低版本系统会出错。

💾 为安全降级,建议在每次升级后备份配置。若未备份中间升级配置,降级可能造成配置丢失或功能失效。

🔧 FortiConverter是官方支持的配置转换工具,可帮助在不同型号和固件版本间转换配置,但可能涉及额外费用。

Upgrading Fortigate Fortios version is easy:

    Find the correct upgrade path for the model you havehttps://docs.fortinet.com/upgrade-tool

    Back up the current configuration: Admin → Configuration → Backup

    If your Fortigate has an active subscription - upgrade directly from theFortiguard servers, and if not - upload each Fortios image as a local file.

Downgrading is not that straightforward. The reason is that major versionreleases (and many times minor) change the configuration commands in some way -remove, add, move location. And when upgrading, the Fortios "upgrades" theconfiguration file as well fixing the differences between releases. E.g. inFortiOS 5.x, and 6.x you configure SD-WAN as config system virtual-wan-link,but in FortiOS 7.x it was replaced with config system sd-wan. When you followthe upgrade path, Fortigate takes care of it automatically. But if you decide todowngrade, it is NOT being done at all. As a consequence, you cannot applyFortiOS 7.2 configuration backup to the FortiOS 6.4 Fortigate. Actually, theFortigate will issue an error if you try to, as the firmware version is in theheader of the config file.

The best way to downgrade and keep the configuration is to save configuration oneach upgrade step - upgraded 6.4.3 → 6.4.9? Back up the configuration. Inthis case, you can freely reset to factory defaults the Fortigate, downgrade toany version you want, say from 7.2 to 6.4.9, then upload the backed upconfiguration of version 6.4.9.

If you didn’t save configuration on the intermediate upgrades, then there is arisk to decide upon. The risk is that downgrading to lower versions, may delete,render not working various parts of the Fortigate configuration. And there is notool to calculate this risk or help with assessing what is going to happen tothe configuration. In my opinion it is safer to manually copy & paste importantconfiguration parts after downgrading the factory-defaulted configuration.

The officially supported way to convert the Fortigate configuration betweendifferent models and firmware versions is FortiConverter. The FortiConvertercomes either as a standalone software paid yearly (expensive), or as a one-timeservice from the Fortinet support.

Follow me on https://www.linkedin.com/in/yurislobodyanyuk/ not to miss what Ipublish on Linkedin, Github, blog, and more.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Fortigate 系统升级 配置备份 FortiConverter
相关文章