Sora Yazılım
Network security, server and software solutions from Türkiye

FortiOS Upgrade Guide: Upgrade Path, Checks and Rollback Plan

In short: A FortiOS upgrade should never be improvised: record each device's version and firmware licence, pick the target from Fortinet's recommended release list and release notes, follow every hop the Upgrade Path Tool returns, upgrade in a maintenance window with an encrypted backup and console access, then verify and keep a rollback plan ready.

Why should a FortiOS upgrade not be postponed?

A firewall vulnerability sits on an internet-facing door, and every postponed FortiGate firmware update adds steps to the next urgent patch. The 4 October 2026 release of CISA's Known Exploited Vulnerabilities (KEV) catalog contains 20 entries that name FortiOS, 7 of them added after 1 January 2025. We cover tracking and prioritisation in our guide to firewall vulnerabilities and patch management.

NIST SP 800-40 Rev. 4 treats patching as preventive maintenance and notes that delayed routine patching makes emergency patching harder, since earlier patches must go in first. In FortiOS that means a longer multi-hop upgrade path when a critical advisory lands.

How do you find the current release and choose a target?

The Version line of get system status shows release, build and maturity tag (GA.M = Mature, GA.F = Feature). Per device, record model, serial, version, HA role, FortiManager/FortiAnalyzer link, VPN types and licence expiry. Check the life cycle (GA, end of engineering support or EOES, end of support or EOS) in FortiCloud or on Fortinet's Product Life Cycle page.

Start with the "Recommended release for FortiOS" article on the Fortinet Community. In that list, current as of June 2026 and reviewed quarterly, recommended releases are typically Mature, installed on at least 40,000 FortiGates and free of high-severity vulnerabilities without a workaround. Older models stay on the last release they support; compare model families on our FortiGate solutions page. FortiOS 8.0.0 release notes appeared on 21 April 2026, but the 8.0 branch is not in the June 2026 list.

CriterionWhere to verifyDecision rule
Recommended releaseRecommended release for FortiOSTarget it unless you have a specific reason.
Maturity tagFirmware & Registration, release notesMature in production; Feature only when needed and tested.
Model supportRelease notes, "Supported models"If the model is not listed, plan a hardware refresh.
Upgrade pathUpgrade Path ToolSize the window for hops and reboots.
Integrated productsFortiOS Compatibility ToolUpgrade FortiManager/FortiAnalyzer first if needed.
Life cycleProduct Life Cycle, FortiCloudPrefer a branch far from EOES.

What is the FortiGate upgrade path, and can you skip versions?

The upgrade path is the sequence of intermediate releases from your version to the target, each step tested by Fortinet; do not skip them. The Upgrade Path Tool returns the shortest validated path; each hop is a full install, and services should stabilise between hops. Examples for a FortiGate-60F, taken from the tool on 7 October 2026:

StartHops → targetInstalls
7.0.127.0.14 → 7.2.10 → 7.4.8 → 7.6.64
7.2.87.2.10 → 7.4.8 → 7.6.63
7.4.37.4.5 → 7.4.7 → 7.6.4 (Feature) → 7.6.64

A newer start does not always mean a shorter path, and a Mature target can still pass through a Feature build. Per the Fortinet Community upgrade path article, skipping hops can cause configuration loss, faulty feature migration and boot failures; the GUI wizard also warns of configuration loss on direct upgrades.

Which checks should you run before upgrading?

Check the licence, release notes, integrations, console access, admin passwords and automatic upgrade setting.

  • Firmware licence: Firmware downloads need a valid Firmware & General Updates (FMWR) licence; on 7.4.2 and later, a new major or minor release also needs the licence to expire after that release's first GA date. diagnose test update info contract | grep FMWR shows the date; if it has lapsed, FortiGate licence renewal comes first.
  • Release notes: Read "Special notices", "Upgrade information" and "Known issues" for every hop; they change after release. The 7.6.7 notes (2 June 2026) had their known issues updated many times up to 6 October 2026.
  • Integrations: Confirm FortiManager, FortiAnalyzer, FortiAP, FortiSwitch and FortiClient compatibility.
  • Console access: If the unit hangs, recover via console; have someone on site.
  • Passwords: From 7.6.5, an administrator password without at least 12 characters, upper and lower case, a number and a special character must be changed before login.
  • Automatic upgrades: Patch upgrades are on by default; a new patch installs after 3 days in a 02:00–04:00 window, within the same minor release, but not on Fabric members, FortiManager-managed units or HA secondaries. Since 7.4.9 and 7.6.4, forced upgrades on devices with an invalid FMWR licence or an EOES release cannot be cancelled; execute auto-upgrade delay-installation postpones one by 7 days per run.

How should you back up the configuration?

Back up before upgrading, encrypted and off the device. The wizard's "Confirm and Backup Config" downloads the configuration to your computer; keep a separate, clearly named backup too.

  • Encryption uses AES-GCM; the file cannot be restored without its password.
  • Use execute backup config for the restore file and execute backup full-config for a full copy including default values.
  • Password-masked backups are for third parties; Fortinet does not recommend restoring them.
  • Also keep the licence file and the firmware image of the current release.

How do you run the upgrade step by step in a maintenance window?

Upgrade in an approved window, in Security Fabric order, verifying each hop. Each hop is a reboot, so leave troubleshooting time.

  1. Set the order. Managing devices go first; per the 7.6.7 notes: FortiAnalyzer, FortiManager, FortiGates, managed FortiExtender, FortiSwitch and FortiAP, then FortiClient EMS and FortiClient. In a Security Fabric, all FortiGates must run the same release.
  2. Start with a pilot. As NIST SP 800-40 suggests for phased deployment, upgrade a low-criticality branch unit first.
  3. Run the wizard. In System > Firmware & Registration, select the device, click Upgrade, choose the target and use "Follow upgrade path" to install the hops in order; confirm with "Confirm and Backup Config".
  4. Pause between hops. If you target each hop separately, check version and traffic after each reboot.
  5. Verify the image. For uploaded files, compare the checksum with the support portal.
  6. Update signatures. After the final hop, run execute update-now and move on to verification.

How does the upgrade order work in an HA cluster?

In an FGCP cluster the upgrade is uninterrupted by default: subordinate units are upgraded first, a new primary is selected from the upgraded units, and the former primary is upgraded last. If all subordinates stop responding, the primary keeps running and waits for one to rejoin.

  • Confirm in System > HA > Status that the configuration is synchronised.
  • Enable session-pickup for TCP and session-pickup-connectionless for UDP and ICMP.
  • Avoid reboot-requiring CLI changes in the same window; all members may reboot at once.
  • set upgrade-mode simultaneous is disabled by default; it is faster but interrupts traffic.
  • With FGSP, traffic moves to one unit while the others are isolated and upgraded in turn.

What should you verify after the upgrade?

The upgrade ends when critical services pass testing, per Fortinet's validation list:

  • Read configuration errors with diagnose debug config-error-log read and confirm the version with get system status.
  • Watch CPU, memory and session count.
  • Test traffic flow, security inspection, VPN connectivity and authentication.
  • Check that application control and web filtering still work, including rules that control generative AI use.
  • If a feature misbehaves, compare pre- and post-upgrade configurations.
  • Check FortiManager, FortiAnalyzer, FortiAP and FortiSwitch connectivity, take a fresh backup and notify the teams.

What should the rollback plan look like?

Write the rollback plan before upgrading. Fortinet does not recommend downgrading, advises contacting support first and ranks the methods as follows:

  1. Secondary partition boot via console: a physical unit starts with its previous firmware and configuration (not on VMs), but only the previous image: after 7.2.9 → 7.4.0 → 7.4.4 you land on 7.4.0.
  2. Clean install via TFTP: the configuration returns to factory defaults, then you restore the backup taken on that release; Fortinet calls this the cleanest route.
  3. Downgrade in the GUI: according to the release notes, a downgrade keeps only operation mode, interface and management IPs, static routes, DNS, the admin account, session helpers and access profiles.

In an HA cluster a downgrade hits all members at once. Without a lab unit, you can test a new image from memory via console and TFTP; the next reboot restores the old one.

Which changes between releases cause the most trouble?

Most problems come from removed features and changed defaults. Examples from the FortiOS 7.6.7 release notes:

ChangeWho is affectedPrecaution
SSL VPN tunnel mode removed from 7.6.3; settings are not carried over.All modelsMove to IPsec VPN first: FortiOS 7.6 SSL VPN migration plan.
Local-in, DoS, interface, multicast and TTL policies and central SNAT maps on an SD-WAN zone member can be deleted on the way to 7.4.6 or 7.6.1+ (fixed in 7.6.3).This setup on 7.4.5, 7.6.0 GA or earlierExport them first; recreate manually.
cp-accel-mode defaults to none on 2 GB memory models.4xF/6xF familiesMonitor CPU usage.
1000auto speed removed on the 1000F/1001F in 7.6.1.SFP+ interfacesIf the link drops, set 1000full.
Password policy enforced from 7.6.5.Weak admin passwordsUpdate passwords in advance.

FortiOS upgrade checklist: which evidence should you keep?

Our template for turning Fortinet's steps into a change record:

PhaseCheckEvidence
PlanningModel, version, maturity tag, FMWR dateCommand output
PlanningTarget release and rationaleLinks to list and notes
PlanningUpgrade pathUpgrade Path Tool export (CSV/JSON)
PreparationIntegrated product compatibilityCompatibility Tool result
PreparationEncrypted backup, licence file, current imageFile names, location
ExecutionConsole access, HA sync, session pickupWindow approval, HA status screen
VerificationError log, resources, VPN, integrationsTest list results
Close-outNew backup, auto-upgrade setting, noticeClose-out note

A single device without SSL VPN can be handled in-house. HA clusters, multiple branches, releases several hops behind or a pending VPN migration turn the job into a change project. Sora Yazılım's firewall maintenance and management service runs firmware plans, pre-upgrade backups and HA checks on a schedule; scope is set by contract. More about Sora Yazılım.

To map your devices' versions and upgrade paths together, send us the models and current releases. Get a Quote

FAQ

Can I skip intermediate releases in a FortiOS upgrade?

It is not recommended. Fortinet states that every hop from the Upgrade Path Tool is tested and that skipping can cause configuration loss, faulty feature migration and boot problems. Even when a note says skipping avoids a bug, Fortinet advises against it; follow the path and apply the notes' manual fixes.

Should I choose the newest FortiOS release or the recommended one?

In production, usually the recommended one. Fortinet's quarterly list generally shows widely deployed Mature builds; as of June 2026 that is 7.6.6 for most current models. Pick the newest only for a needed feature or fix, after reading the notes and testing.

Can a FortiGate with an expired support contract be upgraded?

Usually not to a new major or minor release: on FortiOS 7.4.2 and later, that requires the FMWR licence to expire after the target's first GA date, and an invalid licence disables FortiGuard upgrades. Since 7.4.9 and 7.6.4, such devices are forced onto the latest patch of their minor release. Renew the licence first, then plan.

Does upgrading an HA cluster cause downtime?

In the default uninterrupted mode traffic keeps flowing: subordinates upgrade first, a new primary is selected, then the former primary upgrades. Enable session pickup for TCP and connectionless session pickup for UDP and ICMP. Fortinet still asks for a backup, a window and a supported path first.

Should automatic firmware upgrades stay enabled?

It depends on your change management. Automatic upgrades only install patches within the same minor release and by default wait 3 days, then run in a 02:00–04:00 window, which helps small sites stay current. Where changes need approval, disable them and patch in planned windows. Forced upgrades on unlicensed or EOES devices cannot be cancelled.

When does it make sense to have a service provider run FortiOS upgrades?

HA clusters, several sites, releases several hops behind, a pending SSL VPN migration or remote units without console access make outside support useful. Our firewall maintenance and management service puts firmware plans and backups on a schedule. Contact us with your device list.

Conclusion

  • Choose the target from the recommended list, maturity tag, model support and notes.
  • Do not skip Upgrade Path Tool hops; size the window for them.
  • Keep an encrypted backup, licence file and starting image off the device.
  • Check HA sync; upgrade managing devices first.
  • Write verification and rollback steps in advance.

To run FortiOS upgrades as scheduled maintenance, we can build the firmware plan with you from your inventory.

Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com

Sources

  1. Firmware Upgrade Guide — Fortinet Document Library, updated 16 December 2025. How to upgrade, Why upgrade (accessed 7 October 2026)
  2. Upgrade Path Tool, FortiGate-60F — Fortinet. docs.fortinet.com (accessed 7 October 2026)
  3. Recommended release for FortiOS — Fortinet Community, June 2026. community.fortinet.com (accessed 7 October 2026)
  4. Upgrade path and firmware upgrade articles — Fortinet Community. Upgrade path, Upgrades and downgrades (accessed 7 October 2026)
  5. FortiOS 7.6.7 Release Notes — Fortinet, 2026. Upgrade, Fabric, Downgrade, SSL VPN, SD-WAN, cp-accel, SFP+, Password, Change Log (accessed 7 October 2026)
  6. FortiOS 7.6.7 Administration Guide — Fortinet. HA, Automatic, Required, Licence, Maturity, Upgrading, Backups, Testing (accessed 7 October 2026)
  7. FortiOS 8.0.0 Release Notes, Change Log — Fortinet, 2026. docs.fortinet.com (accessed 7 October 2026)
  8. SP 800-40 Rev. 4 — NIST, April 2022. csrc.nist.gov (accessed 7 October 2026)
  9. Known Exploited Vulnerabilities Catalog, version 2026.10.04 — CISA. raw.githubusercontent.com (accessed 7 October 2026)

How this article was prepared

Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical details were checked against the vendor and official sources linked in the text as of 7 October 2026.

Related articles

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support