Skip to content

Check fortios-version

Overview

Checks the installed FortiOS version against the endoflife.date API and alerts if the version is end-of-life or if newer major, minor, or patch releases are available. By default, alerts 30 days before the official EOL date. The offset is configurable.

Important Notes:

  • The check reaches a FortiGate appliance over the network, so it needs the FortiOS REST API enabled and an API token, which it passes as --password.

Data Collection:

  • Queries the FortiOS REST API endpoint /api/v2/monitor/system/firmware/ to read the installed version
  • Compares against the endoflife.date API to determine EOL status and available updates
  • Caches endoflife.date responses locally for 24 hours to reduce external requests

Fact Sheet

Fact Value
Check Plugin Download https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/fortios-version
Nagios/Icinga Check Name check_fortios_version
Check Interval Recommendation Every day
Can be called without parameters No (--hostname and --password are required)
Runs on Cross-platform
Compiled for Windows No (runs with Python interpreter)
Uses State File $TEMP/linuxfabrik-lib-version.db

Help

usage: fortios-version [-h] [-V] [--always-ok] [--check-major] [--check-minor]
                       [--check-patch] -H HOSTNAME [--insecure]
                       [--no-perfdata] [--no-proxy] [--offset-eol OFFSET_EOL]
                       --password PASSWORD [--proxy PROXY] [--timeout TIMEOUT]
                       [--unreachable-severity {ok,warn,crit,unknown}]

Checks the installed FortiOS version against the endoflife.date API and alerts
if the version is end-of-life or if newer major, minor, or patch releases are
available. By default, alerts 30 days before the official EOL date. The offset
is configurable.

options:
  -h, --help            show this help message and exit
  -V, --version         show program's version number and exit
  --always-ok           Always returns OK.
  --check-major         Alert when a new major release is available, even if
                        the current version is not yet EOL. Example: running
                        v26 (not yet EOL) and v27 is available.
  --check-minor         Alert when a new major.minor release is available,
                        even if the current version is not yet EOL. Example:
                        running v26.2 (not yet EOL) and v26.3 is available.
  --check-patch         Alert when a new major.minor.patch release is
                        available, even if the current version is not yet EOL.
                        Example: running v26.2.7 (not yet EOL) and v26.2.8 is
                        available.
  -H, --hostname HOSTNAME
                        FortiOS-based Appliance address, optional including
                        port ("192.0.2.1:443").
  --insecure            This option explicitly allows insecure SSL
                        connections.
  --no-perfdata         Suppress the performance data section from the output.
                        The status message and the exit code are unaffected,
                        so alerting keeps working while trending data is
                        dropped.
  --no-proxy            Do not use a proxy, not even one the environment
                        names. Overrides `--proxy`.
  --offset-eol OFFSET_EOL
                        Alert n days before ("-30") or after an EOL date ("30"
                        or "+30"). Default: -30 days
  --password PASSWORD   FortiOS REST API access token.
  --proxy PROXY         Proxy to reach the target through. The scheme defaults
                        to `http` when omitted. Overrides the proxy the
                        environment names (`http_proxy`, `https_proxy`,
                        `all_proxy`) together with the exceptions it lists in
                        `no_proxy`, and is itself overridden by `--no-proxy`.
                        Without either parameter the environment applies.
                        Credentials belong into the environment variable
                        rather than here, because a command-line argument is
                        visible to every user on the host. Example:
                        `--proxy=http://proxy.example.com:3128`.
  --timeout TIMEOUT     Network timeout in seconds. Default: 3 (seconds)
  --unreachable-severity {ok,warn,crit,unknown}
                        State to report when the online source is unreachable.
                        What is used instead - bundled offline data, a cached
                        copy, or nothing at all - is named in the output, and
                        a clean result then only covers what that fallback
                        could confirm. Default: ok

Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/fortios-version/

Usage Examples

./fortios-version --hostname=fortigate-cluster.example.com --password=mypass

Output:

FortiOS v6.0.1 (EOL 2022-09-29 -30d [WARNING])

States

The end-of-life verdict, the --check-major / --check-minor / --check-patch alerts, --offset-eol, --always-ok and what happens when endoflife.date cannot be reached work the same way in every endoflife.date-based version plugin. They are described in Version Plugins.

Perfdata / Metrics

Name Type Description
fortios-version Number Installed FortiOS version as float. For example, "6.0.1" becomes "6.01".

Credits, License