Known issues
Known issues are organized into the following categories:
To inquire about a particular bug or report a bug, please contact Customer Service & Support.
New known issues
The following issues have been identified in version 7.4.7.
Firewall
|
Bug ID |
Description |
|---|---|
|
1148166 |
Source port translation was not permitted with traffic to UDP port 7001. |
GUI
|
Bug ID |
Description |
|---|---|
|
1152464 |
The DHCP reservation widget incorrectly validates based on the subnet instead of individual IP addresses. |
|
1153294 |
Custom HTML content does not render correctly on login pages when configured through the FortiGate web interface or CLI. |
HA
|
Bug ID |
Description |
|---|---|
|
1151668 |
Interface bandwidth widget doesn't display HB and Managed port. |
IPsec VPN
|
Bug ID |
Description |
|---|---|
|
1152486 |
Unable to select policy-based IPsec tunnel in the firewall policy for SD-WAN member while configuring in GUI. |
REST API
|
Bug ID |
Description |
|---|---|
|
1154124 |
Adding dynamic fabric addresses via the FortiNAC REST API fails due to an issue with HTTP header validation. |
Routing
|
Bug ID |
Description |
|---|---|
|
1142290 |
An error message appears in FortiGate when attempting to add the ssl.root interface to a route-map via the GUI. |
Security Fabric
|
Bug ID |
Description |
|---|---|
|
1156006 |
SFTP backup fails when triggered through automation stitch on a FortiGate in an HA cluster using Windows-style paths. |
System
|
Bug ID |
Description |
|---|---|
|
945871 |
D-NAT functionality fails when using a Software Switch in explicit mode due to incorrect session matching during packet forwarding. |
|
1012577 |
Traffic on WAN interface is dropped when policy-offload-level (under config system setting) is set to dos-offload. |
|
1054955 |
USB GPIO and host function were not set up properly on 9xG and 12xG. |
|
1085407 |
FortiGate unresponsive when |
|
1091551 |
Hardware limitation on the NP7 platform causes the following QTM related issues:
|
|
1104410 |
The FortiGate-120G SFP ports fail to establish connectivity when configured with 'set speed 1000full' due to improper auto-negotiation handling. |
|
1105321 |
FG-4201F with NP7 network processors shows EIF0_IGR and EIF1_IGR usage stuck at 100% and host softirq stuck at 99% after running the iptunnel traffic. |
|
1116220 |
FortiGate 3601E 25Gauto link not coming up using DAC cables. |
|
1146354 |
The network interface settings page fails to load on certain FortiGate models when the admin profile does not have the System > Configuration > Read/Write permission. |
|
1164174 |
Configuration loss on FGT-60F when FortiGate enters extreme conserve mode |
|
1170282 |
FortiGate HA becomes out of sync after provisioning a certificate by using ACME protocol. |
Upgrade
|
Bug ID |
Description |
|---|---|
|
1097503 |
Fabric upgrade from 7.2.9 to 7.4.5 failed. |
User & Authentication
|
Bug ID |
Description |
|---|---|
|
1148767 |
FSSO users show in small letters, user filtering is not working, and PIE charts are not visible. |
VM
|
Bug ID |
Description |
|---|---|
|
1146370 |
AWS bootstrap is unable to parse IAM role profile properly due to the length. |
Existing known issues
The following issues have been identified in a previous version of FortiOS and remain in FortiOS 7.4.7.
Explicit Proxy
|
Bug ID |
Description |
|---|---|
|
1026362 |
Web pages do not load when |
Firewall
|
Bug ID |
Description |
|---|---|
|
959065 |
On the Policy & Objects > Traffic Shaping page, when deleting or creating a shaper, the counters for the other shapers are cleared. |
|
994986 |
The By Sequence view in the Firewall policy list may incorrectly show a duplicate implicit deny policy in the middle of the list. This is purely a GUI display issue and does not impact policy operation. The Interface Pair View and Sequence Grouping View do not have this issue. |
|
1004263 |
Session counters are not updated when ASIC offload is enabled on firewall policy. FortiGate GUI displays incorrect information in the "Bytes" and "Last Used" columns. |
|
1057080 |
On the Firewall Policy page, search results do not display in an expanded format. |
|
1078662 |
If an interface on an NP7 platform has the
Workaround: config system interface
edit xxx
unset egress-shaping-profile
next
end
|
|
1114635 |
In the GUI, cannot filter Address objects correctly when using CIDR notation. |
|
1117165 |
Leaving the To configure GTP APN traffic shaping: config gtp apn-shaper
edit <policy-id>
set apn [<apn-name> <apngrp-name> ...]
set rate-limit <limit>
set action {drop | reject}
set back-off-time <time>
next
end
|
FortiGate 6000 and 7000 platforms
|
Bug ID |
Description |
|---|---|
|
790464 |
After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond. |
|
911244 |
FortiGate 7000E IPv6 routes may not be synchronized correctly among FIMs and FPMs. |
|
976521 |
High CPU usage by the node process occurs when loading 7000 policies due to fetching all statistics in one request. |
|
1006759 |
After an HA failover, there is no IPsec route in the kernel. Workaround: Bring down and bring up the tunnel. |
|
1026665 |
On the FortiGate 7000F platform with virtual clustering enabled and syslog logging configured, when running the |
|
1048808 |
If the secondary reboots, after it rejoins the cluster SIP sessions are not resynchronized. |
|
1060619 |
CSF is not working as expected. |
|
1070365 |
FGCP HA session synchronization may stop working as expected on a FortiGate 7000F cluster managed by FortiManager. This happens if the HA configuration uses management interfaces as session synchronization interfaces by configuring the config system ha
set session-sync-dev 1-M1 1-M2
end
The problem occurs when FortiManager updates the configuration of the FortiGate 7000F devices in the cluster it incorrectly changes to the VDOM of the management interfaces added to the You can work around the problem by re-configuring the |
| 1092728 | On FortiGate 6000 and 7000 platforms, fragmented IPv6 traffic is randomly dropped. |
|
1109601 |
Graceful upgrades fail when hatalk daemon restarts, disrupting slbha state synchronization during FortiOS version transitions. |
GUI
|
Bug ID |
Description |
|---|---|
|
853352 |
When viewing entries in slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100000 entries. |
|
885427 |
Suggest showing the SFP status information on the faceplate of FGR-60F/60F-3G4G devices. |
|
1047963 |
High Node.js memory usage when building FortiManager in Report Runner fails. Occurs when FortiManager has a slow connection, is unreachable from the FortiGate (because FMG is behind NAT), or the IP is incorrect. |
|
1055197 |
On FortiGate G series models with dual WAN links, the Interface Bandwidth widget may show an incorrect incoming and outgoing bandwidth count where the actual traffic does not match the display numbers. |
|
1071907 |
There is no setting for the type option on the GUI for npu_vlink interface. |
|
1114549 |
Authorization of FEXT devices fails when using the FortiGate GUI. |
|
1145907 |
Bandwidth widget does not report the traffic correctly for backup VLAN interfaces. |
HA
|
Bug ID |
Description |
|---|---|
|
781171 |
When performing HA upgrade in the GUI, if the secondary unit takes several minutes to boot up, the GUI may show a misleading error message Image upgrade failed due to premature timeout. This is just a GUI display issue and the HA upgrade can still complete without issue. |
|
1000808 |
FortiGate in an HA setup has an unnecessary primary unit selection when a new member joins or reboots one member in the VC cluster when the VC has more than 2 units. |
|
1107137 |
The secondary FortiGate with an HA Reserved Management Interface cannot be accessed using HTTPS after upgrading from version 7.4.3. |
|
1135376 |
When HA members are not registered under the same FortiCare account, the HA cluster cannot obtain contract info of all members from FortiGuard servers. |
|
1137565 |
vSN support was added in 7.2.9, 7.4.6, and 7.6.1. FG-100F/101F do not yet support vSN and logical-sn. No workaround until the devices support vSN. |
|
1226122 |
System > HA: There is no upgrade button on secondary GUI page when HA in local-only or secondary-only MVC upgrade mode. Workaround: upgrade the secondary via the command line. |
Hyperscale
|
Bug ID |
Description |
|---|---|
|
1024274 |
When Hyperscale logging is enabled with multicast log, the log is not sent to servers that are configured to receive multicast logs. |
|
1025908 |
Session count on peer device is 50% less during FGSP testing in new setups using VRRP-based configuration. |
Intrusion Prevention
|
Bug ID |
Description |
|---|---|
|
1117043 |
After upgrade, event log shows This issue only affects physical FortiGate models with the following IPS engine versions:
To determine the IPS Engine versions, use the command: get sys fortiguard-service status | grep 'IPS/FlowAV Engine' Workaround: Power off the FortiGate. Wait 30 seconds, and then power on the FortiGate. Note: Reboot using the CLI is not an effective workaround and requires additional steps. After executing |
IPsec VPN
|
Bug ID |
Description |
|---|---|
|
866413 |
Traffic over GRE tunnel over IPsec tunnel, or traffic over IPsec tunnel with GRE encapsulation is not offloaded on NP7-based units. |
|
897871 |
GRE over IPsec does not work in transport mode. |
|
970703 |
FortiGate 6K and 7K models do not support IPsec VPN over vdom-link/npu-vlink. |
|
1012615 |
IPsec VPN traffic is dropped after upgrading to version 7.4.3. |
|
1110093 |
IPsec SA offloading stops on some FortiGate models when handling more than 50,000 concurrent secure associations. |
|
1140823 |
IPsec tunnels become stuck on spoke np6xlite, causing ESP packet drops after extended operation due to improper vifid formation during multiple rekey operations. |
Log & Report
|
Bug ID |
Description |
|---|---|
|
1113588 |
FortiGate prompts error Fetching data from Disk is taking longer than expected. Suggest trying a different log source or check the availability of Disk. when viewing logs for the last 7 days from disk or FortiAnalyzer. |
|
1148101 |
Logs fail to appear in FortiAnalyzer, and FortiView sources are missing from the Dashboard. |
Proxy
|
Bug ID |
Description |
|---|---|
|
1035490 |
The firewall policy works with proxy-based inspection mode on FortiGate models with 2GB RAM after an upgrade. Workaround: After an upgrade, reboot the FortiGate. |
|
1060812 |
Botnet detection fails in transparent proxy setups caused by implementation error. |
Routing
|
Bug ID |
Description |
|---|---|
|
903444 |
The |
|
1040655 |
From version 7.4.1, when there is ECMP routes, local out traffic may use a different route/port to connect out to the server. Workaround: for critical traffic which is sensitive to source IP address, specify the interface or SD-WAN for the traffic using the config system fortiguard
set interface-select-method specify
set interface "wan1"
end
|
Security Fabric
|
Bug ID |
Description |
|---|---|
|
903922 |
Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation. |
|
1011833 |
FortiGate experiences a CPU usage issue in the node process when there multiple administrator sessions running simultaneously on the GUI in a Security Fabric with multiple downstream devices. This may result in slow loading times for multiple GUI pages. |
|
1021684 |
In some cases, the Security Fabric topology does not load properly and displays a Failed to load Topology Results error. |
|
1150382 |
Security profile names containing two forward slashes (//) cause the webpage to become unresponsive when attempting to edit. |
|
1076439 |
Security Fabric Asset Identity Center shows "Failed to load user device store data". |
|
1149817 |
Security Fabric > Physical Topology: Fortilink Tier2 switch shows directly connected to FortiGate on Security Fabric - Physical Topology page. The correct topology can be seen on the WiFi & Switch Controller > Managed FortiSwitches > Topology view. |
SSL VPN
|
Bug ID |
Description |
|---|---|
|
1058211 |
Traffic could not go though SSL VPN tunnel when DTLS is enabled with a loopback interface as source address. |
Switch Controller
|
Bug ID |
Description |
|---|---|
|
1114032 |
The GUI becomes slow or unresponsive when transceiver-related API requests fail. |
|
1138263 |
FortiSwitch port configurations fail to update and GUI display issues occur when user-info process overloads system resources with excessive connections. |
|
1146176 |
config sync error on managed FSW after upgrade when "Name" field and port exported are configured on the same FSW. |
|
1150215 |
Offline FSWs show as offline in the GUI topology view but show as online in the list view. |
System
|
Bug ID |
Description |
|---|---|
|
901621 |
On the NP7 platform, setting the interface configuration using set inbandwidth <x> or set outbandwidth <x> commands stops traffic flow. Workaround: Change the NP7 config system npu set default-qos-type policing end |
|
992323, 1056133, 1075607, 1082413, 1084898 |
Traffic interrupted when traffic shaping is enabled on 9xG and 12xG. |
|
1021903 |
The le-switch member list does not update when the role of an interface is changed in a lan-extension environment. |
|
1046484 |
After shutting down a SOC4 FortiGate (FGT-40F/FGT-61F/FGT-81F/FGT-100F) using the "execute shutdown" command, the system automatically boots up again. |
|
1048496 |
On FortiGate, the |
|
1057131 |
A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate. |
|
1069208 |
If the DHCP offer contains padding when DHCP relay is used, the DHCP relay deletes the padding before relaying the packet. |
|
1078541 |
The FortiFirewall 2600F model may become stuck after a fresh image burn. Upgrading from a previous version stills works. Workaround: power cycle the unit. |
|
1089143 |
The time change in FOS is restored after reboot. The RTC node is not created correctly so the time change cannot be kept in RTC. |
|
1102416 |
Cannot push |
|
1113436 |
Packets are dropped when using auto-asic-offload with 802.1AD over LACP on FortiGate due to missing MAC address assignment on QinQ lag interfaces. |
|
1114298 |
FortiGate Cloud remote login triggers 2 admin login events (1 successful and 1 unsuccessful for PKI admin). |
|
1117005 |
CPU spikes and management access issues occur on certain FortiGate models post-upgrade when IPsec Phase 1 NPU-offload is enabled during maintenance. |
|
1140755 |
When attempting to delete a software switch interface, it becomes permanently hidden due to an unreverted temporary flag. |
Upgrade
|
Bug ID |
Description |
|---|---|
|
1087263 |
Upgrading an FGCP HA cluster of FortiGates with NP7 processors from 7.2.8, 7.2.9, or 7.2.10 to FortiOS 7.4.4, 7.4.5, 7.4.6, or 7.4.7 may cause the cluster to experience an infinite reboot loop. This issue has been resolved by FortiOS 7.4.8. You can work around this problem by either disconnecting the FortiGates from the cluster, upgrading them individually, and then reforming the cluster, or by upgrading the cluster from 7.2.x to 7.2.10 and then to 7.4.8. |
|
1104649 |
In 7.4.6 and 7.4.7, if a local-in policy or local-in-policy6 is used in an interface in version 7.4.5, or any previous GA version that was part of the SD-WAN zone, the policies are deleted or show empty values after upgrading to version 7.4.6 or 7.4.7. Workaround: After upgrading to 7.4.6 or 7.4.7, users must manually recreate these policies and assign them to the appropriate SD-WAN zone. |
|
1114550 |
FortiExtender shows as offline after upgrading FGT from 7.4.5 to 7.4.6. Workaround: Reboot FortiExtender manually. |
User & Authentication
|
Bug ID |
Description |
|---|---|
|
884462 |
NTLM authentication does not work with Chrome. |
|
972391 |
RADIUS group usage not displayed correctly in GUI when used for firewall admin authentication. |
|
1080234 |
For FortiGate (versions 7.2.10 and 7.4.5 and later) and FortiNAC (versions 9.2.8 and 9.4.6 and prior) integration, when testing connectivity/user credentials against FortiNAC that acts as a RADIUS server, the FortiGate GUI and CLI returns an invalid secret for the server error. This error is expected when the FortiGate acts as the direct RADIUS client to the FortiNAC RADIUS server due to a change in how FortiGate handles RADIUS protocol in these versions. However, the end-to-end integration for the clients behind the FortiGate and FortiNAC is not impacted. Workaround: confirm the connectivity between the end clients and FortiNAC by checking if the clients can still be authorized against the FortiNAC as normal. |
|
1082800 |
When performing LDAP user searches from the GUI against LDAP servers with a large number of users (more than 100000), FortiGate may experience a performance issue and not operate as expected due to the HTTPSD process consuming too much memory. User may need to stop the HTTPSD process or perform a reboot to recover. Workaround: Perform an LDAP user search using the CLI. |
|
1112718 |
When RADIUS server has the config user radius
edit <radius server>
set require-message-authenticator disable
next
end
This is only a GUI display issue and the end-to-end integration with RADIUS server should still work. Workaround: user can confirm if the connection to RADIUS server via CLI command
|
|
1157003 |
Agentless FSSO connector issues occur when using Windows 2025 due to MS introduced additional restrictions to remote Event log reading. |
VM
|
Bug ID |
Description |
|---|---|
|
978021 |
In FTP passive mode with GWLB setup, Geneve header VNI lengths are zero in syn-ack packets, leading to retransmission issues. |
|
1082197 |
VLAN traffic fails to pass through E810-XXV NIC with SFP28 transceiver and 25G speed after enabling DPDK. |
|
1094274 |
FortiOS becomes unresponsive when sending IPv6 traffic over MLX5 network adapters due to incorrect WQE handling. |
WiFi Controller
|
Bug ID |
Description |
|---|---|
|
814541 |
When there are extra large number of managed FortiAP devices (over 500) and large number of WiFi clients (over 5000), the Managed FortiAPs page and FortiAP Status widget can take a long time to load. This issue does not impact FortiAP operation. |
|
949682 |
Intermittent traffic disruption observed in cw_acd caused by a rare error condition. |
|
964757 |
The FortiGate fails to generate debug/sniffer logs for a user when connecting to a specific SSID despite showing station logs with radius requests and challenges, while other SSIDs function correctly. |
|
1050915 |
On the WiFi & Switch Controller > Managed FortiAPs page, when upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware. Workaround: Upgrade the FortiAPs in smaller batches of up to 20 devices to avoid performance impacts. |
|
1080094 |
High memory usage may occur due to offline station entries not being automatically cleaned up over time. |
|
1083395 |
In an HA environment with FortiAPs managed by primary FortiGate, the secondary FortiGate GUI Managed FortiAP page may show the FortiAP status as offline if the FortiAP traffic is not routed through the secondary FortiGate. This is only a GUI issue and does not impact FortiAP operation. |
ZTNA
|
Bug ID |
Description |
|---|---|
|
819987 |
Mapped drives become inaccessible after laptop reboots when using FortiGate ZTNA access proxy with FQDN destinations. |
|
1020084 |
Health check on the ZTNA realserver does not work as expected if a blackhole route is added to the realserver address. |