โšก Onwuachi Control Plane

FortiGate HA Upgrade Runbook (AWS Production)

FortiGate HA Upgrade Runbook (AWS Production)

Overview

Standardized process for performing a zero-downtime firmware upgrade on FortiGate HA clusters in AWS.

Architecture:

Upgrade Flow

[Primary Active]
      โ”‚
      โ–ผ
[Upgrade Secondary]
      โ”‚
      โ–ผ
[Failover โ†’ Secondary Active]
      โ”‚
      โ–ผ
[Upgrade Primary]
      โ”‚
      โ–ผ
[Primary Rejoins]
      โ”‚
      โ–ผ
[HA Sync + Stable State]

Pre-Maintenance Requirements

Execution Summary

  1. Upgrade initiated from GUI on primary node
  2. Secondary upgraded first, automatically
  3. Failover occurs during process
  4. Primary upgraded and rejoins cluster
  5. HA re-synchronizes

Validation Criteria

Success Criteria

Latest Execution (Reference)

Operational notes: always validate firmware matches platform; never upgrade if HA is not clean; let HA automation handle sequencing.

“Game Day” Reference (What You Actually Use Live)

Before you click upgrade:

โœ“ HA in-sync?
โœ“ Backup downloaded?
โœ“ Correct firmware file?
โœ“ Monitoring open?

Start upgrade: System โ†’ Firmware โ†’ Upload โ†’ Confirm

Watch for this:

1. Secondary upgrades
2. Secondary becomes ACTIVE
3. Primary upgrades
4. Primary rejoins
5. HA sync completes

If something looks off:

get system ha status

Look for: missing node, out-of-sync โ€” both are red flags.

Final check โ€” you want: same firmware, HA OK, sessions flowing:

get system status
get system ha status
diagnose sys session stat

Optional force-failover test:

execute ha failover set 1

Done when:

HA = OK
In Sync
Traffic Stable

System Context

โ† Back to Kb