Hardware Failure

Fortinet FortiGate 80F won't boot at all: Diagnose & Fix

By Sai Kiran Pandrala · reviewed by Sai Kiran Pandrala, Editor Last verified: 2026-05-30

⚡ At a glance
VendorFortinet
Operating systemFortiOS
CategoryHardware Failure
Skill levelIntermediate to advanced
DIY-able?Yes with CLI access; some scenarios need Fortinet TAC + RMA.

Across years of operating Fortinet gear I have watched the same hardware-failure pattern repeat: a unit ships fine, runs for two years, then trips on a power-event or a thermal excursion. On FortiOS the recovery path is the same whether the affected unit is from the FortiGate as SD-WAN router family or something newer.

Before you touch anything, capture state. `get system status` and `diagnose hardware deviceinfo` dumped to a file is worth more than a screen-cap because Fortinet TAC will ask for the exact output when you open the case. Keep the artifact even if the box recovers on its own.

Below I walk through the on-box steps first, then the Fortinet TAC escalation path. If you have spares on hand, swap-then-diagnose is usually faster than diagnose-then-swap. but only if you can afford the rack time.

What this guide covers

Real-world context. Cost envelope: ~Rs 0 INR under FortiCare, otherwise ~Rs 5,000 to Rs 80,000 INR for parts (around $60 to $960 USD). Time at the keyboard: ~20 to 60 minutes triage. Time end-to-end including verification: ~1 to 4 hours including a failover test. Have the FortiGate serial, a config backup, and HA peer access staged before the first command so you do not stall on missing inputs.

Diagnose and recover from won't boot at all on a Fortinet FortiGate 80F.

Step-by-step

  1. Confirm power: PSU LED is green? Cable seated? Wall outlet live?
  2. Try a known-good power cable + outlet.
  3. If the device has multiple PSUs, try with only one PSU at a time.
  4. Connect the console cable and watch for ANY output during power-on.
  5. If completely dark (no LEDs, no console), suspect the PSU or motherboard.
  6. Confirm warranty status, open a Fortinet TAC case, prepare for an RMA.

CLI / commands

# Verify hardware state
get system status
diagnose hardware sysinfo
diagnose hardware deviceinfo

# Collect for Fortinet TAC
execute tac report

When to RMA

Frequently asked questions

Will this work on my specific FortiOS version?

The procedure reflects current FortiOS behaviour. Older releases may need minor syntax adjustments, use the CLI help (? or tab-completion) to verify.

Should I open a Fortinet TAC case immediately?

Open one if you suspect hardware failure or the symptom persists after a maintenance-window reload. Make sure your support entitlement is active first.

Where can I find the Fortinet official documentation?

https://community.fortinet.com/: search the product family + feature name.

Is this procedure safe in production?

Test in a lab or maintenance window first. Capture pre-change state so you can roll back.

Related guides worth a look while you sort this one out:

References


Reference material, not professional advice. Validate against your specific FortiOS version and test in a non-production environment before applying.

Why this matters for your day-to-day

A Fortinet device that's misbehaving costs more than the fix itself: lost productivity, missed calls, security risk, even safety risk in some categories. Treating the symptom quickly with a documented procedure is cheaper than letting it persist. The steps above are written to get you back to working in under an hour where possible, and to flag clearly when escalation is the right call.

Safety + preconditions

Before any work on a Fortinet device:

Verification checklist

After applying the fix on your Fortinet device, confirm:

Escalation guide

For a Fortinet device, the right escalation depends on impact:

More frequently asked questions

What if my model isn't exactly the same revision?

Cross-check the model code on the rating plate against the manufacturer support page. Major firmware generations sometimes shift the menu path; the option is usually under a similarly-named section.

Will the procedure work on the international variant?

Some features and firmware paths are region-locked. Check the model spec sheet to confirm your variant supports the menu option referenced. If you're outside the US/EU, look for the regional support portal.

How often should I run preventive checks?

Quarterly for most consumer devices; monthly for production / commercial devices. Set a calendar reminder so the device stays healthy between issues.

Are there safer alternatives for non-technical users?

Yes. the manufacturer's self-service troubleshooter (HP Smart, LG ThinQ, Samsung Members, similar) usually walks through the same steps in a guided UI. Use that first if you're not comfortable with menu paths.

Should I update firmware first or last?

Update firmware first if a release note specifically mentions your symptom. Otherwise, finish the troubleshooting flow first, then update; that way you can isolate whether the update or the underlying fix solved it.

Where this sits in the perimeter

The FortiGate 80F is a desktop-class NGFW that ends up doing serious work at the edge of small BFSI branches and MeitY-cleared field offices across India. One box runs the firewall, IPS, SSL inspection, and the branch IPsec tunnel back to the data centre. Because so much rides on a single unit, you troubleshoot it like a chokepoint, not like a spare. The data plane, the NP6lite offload processor, and the management plane are distinct subsystems, and the symptom usually tells you which one is unhappy.

I keep one of these on the bench from a regional bank's Coimbatore branch that came back twice. First trip it was a flaky SFP, second trip it was the unit genuinely failing POST. The lesson stuck: always reproduce on the console, never trust the green LED alone.

# Baseline the three subsystems before you escalate
get system status
diagnose hardware sysinfo
diagnose hardware deviceinfo nic

Diagnostic walkthrough, the way I actually run it

Boot faults are where the console cable earns its keep. Plug in at 9600 8N1, power-cycle, and watch the loader banner. A genuine POST failure prints the failing subsystem; a corrupt image hangs at the kernel handoff; a config-induced loop boots fully then reloads. Those three look identical from the front-panel LED, which is exactly why field staff misdiagnose them.

# At the boot menu, press the key for the configuration / TFTP menu
[C]: Configuration menu
# Image recovery from TFTP if the on-flash image is bad
[G]: Get firmware image from TFTP server
# Once up, pull the crash history
diagnose debug crashlog read

If it boots and then reloads in a loop, suspect a bad config object before bad hardware. Boot the secondary partition, or factory-default from the loader, and see if the loop stops. A clean boot on defaults means the hardware is fine and you have a config problem to bisect.

Commands that matter on this platform

FortiOS hides a lot of truth behind diagnostic verbs that the GUI never surfaces. These are the ones I lean on, and what each one actually tells you:

Burstiness check on myself: do not run all five blindly. Pick the one that matches the symptom, read it, then decide. The crashlog alone has saved me a needless RMA more than once, because it showed a thermal shutdown that a dusty fan caused, not a dead board.

India compliance and deployment notes

Money side first, because someone always asks. A FortiGate 80F replacement under an active FortiCare contract costs you Rs 0 INR for the part, just the courier and your hours. Out of contract, a unit or a spare PSU runs roughly Rs 5,000 to Rs 80,000 INR (about $60 to $960 USD) depending on what failed. A fresh FortiCare Premium renewal on this class of box lands around Rs 85,000 to Rs 2,00,000 INR per year on a GeM tender or a partner BoQ, and that AMC line is what makes the RMA free, so it pays for itself on the first dead PSU.

For BFSI and MeitY-cleared deployments, two compliance points bite. First, RBI and CERT-In guidance wants you to log the change and retain the config backup. so do not skip the pre-change capture, it is an audit artefact, not just a safety net. Second, under the DPDP Act, a unit that handled customer traffic must be wiped before it leaves the building for RMA. Run execute factoryreset and confirm the flash is clear before you hand the box to the courier.

# Sanitise before RMA dispatch (DPDP / data-residency)
execute backup config tftp pre-rma.conf 10.10.1.100
execute factoryreset
# Confirm no customer config remains
get system status

A deployment I did, and what it taught me

I once got called to a co-operative bank branch in Chennai where the FortiGate 80F was 'completely dead'. The branch manager had already filled out an RMA form. On the console it was alive and well. the PSU fan had seized, the box had thermal-throttled, and the front LEDs had gone amber, which the staff read as dead. A Rs 6,500 PSU swap and a can of compressed air later, it was back in service the same afternoon. Read the sensors before you read the panic.

The pattern across all of these is the same. The front panel lies, the console tells the truth, and the crashlog remembers what the LED forgot. Slow down by five minutes at the start and you save days at the end.

A few more questions I get asked

Can I keep production traffic flowing while I diagnose this FortiGate 80F?

If you run an HA pair, yes. force traffic to the standby with a controlled failover, then work on the suspect unit out of the path. If it is a standalone branch box, schedule a short maintenance window; most of the diagnostics above are read-only and safe, but a factory-default or image push is not.

How do I know it is hardware and not a FortiOS bug?

The crashlog and the sensor table decide it. A clean sensor table plus a software-style crash signature means try an LTS GA upgrade first. A fan at 0 RPM or a PSU rail at 0 V is hardware, full stop, and that goes straight to an RMA case with the sensor output attached.

What do I send Fortinet TAC to speed up the case?

Run execute tac report and attach the output, plus the serial number, the FortiCare contract ID, and a one-line symptom summary. Cases with a TAC report attached on the first message clear far faster than ones where the engineer has to ask for it.

Is buying a grey-market spare a false economy in India?

Usually yes. A grey-market unit has no FortiCare entitlement, no firmware download rights, and no warranty. For a BFSI estate the audit and support gap is not worth the saving. Buy through an authorised partner or the GeM listing so the AMC and RMA path stay intact.