Fortinet white logo
Fortinet white logo

Known issues

Known issues

Known issues are organized into the following categories:

To inquire about a particular bug or report a bug, please contact Customer Service & Support.

New known issues

The following issues have been identified in version 7.4.7.

Firewall

Bug ID

Description

1148166

Source port translation was not permitted with traffic to UDP port 7001.

GUI

Bug ID

Description

1152464

The DHCP reservation widget incorrectly validates based on the subnet instead of individual IP addresses.

1153294

Custom HTML content does not render correctly on login pages when configured through the FortiGate web interface or CLI.

HA

Bug ID

Description

1151668

Interface bandwidth widget doesn't display HB and Managed port.

IPsec VPN

Bug ID

Description

1152486

Unable to select policy-based IPsec tunnel in the firewall policy for SD-WAN member while configuring in GUI.

REST API

Bug ID

Description

1154124

Adding dynamic fabric addresses via the FortiNAC REST API fails due to an issue with HTTP header validation.

Routing

Bug ID

Description

1142290

An error message appears in FortiGate when attempting to add the ssl.root interface to a route-map via the GUI.

Security Fabric

Bug ID

Description

1156006

SFTP backup fails when triggered through automation stitch on a FortiGate in an HA cluster using Windows-style paths.

System

Bug ID

Description

945871

D-NAT functionality fails when using a Software Switch in explicit mode due to incorrect session matching during packet forwarding.

1012577

Traffic on WAN interface is dropped when policy-offload-level (under config system setting) is set to dos-offload.

1054955

USB GPIO and host function were not set up properly on 9xG and 12xG.

1085407

FortiGate unresponsive when default-qos-type is set to shaping.

1091551

Hardware limitation on the NP7 platform causes the following QTM related issues:

  • Incorrect checksum for fragments after QTM. The workaround is to not parse Layer4 after QTM.

  • Packets longer than 6000 bytes cause QTM unresponsiveness.

  • Refresh issue causes QTM unresponsiveness. The workaround is to use one refresh list.

  • MTU is not honored after QTM, so packets are not fragmented.

1104410

The FortiGate-120G SFP ports fail to establish connectivity when configured with 'set speed 1000full' due to improper auto-negotiation handling.

1105321

FG-4201F with NP7 network processors shows EIF0_IGR and EIF1_IGR usage stuck at 100% and host softirq stuck at 99% after running the iptunnel traffic.

1116220

FortiGate 3601E 25Gauto link not coming up using DAC cables.

1146354

The network interface settings page fails to load on certain FortiGate models when the admin profile does not have the System > Configuration > Read/Write permission.

1164174

Configuration loss on FGT-60F when FortiGate enters extreme conserve mode

1170282

FortiGate HA becomes out of sync after provisioning a certificate by using ACME protocol.

Upgrade

Bug ID

Description

1097503

Fabric upgrade from 7.2.9 to 7.4.5 failed.

User & Authentication

Bug ID

Description

1148767

FSSO users show in small letters, user filtering is not working, and PIE charts are not visible.

VM

Bug ID

Description

1146370

AWS bootstrap is unable to parse IAM role profile properly due to the length.

Existing known issues

The following issues have been identified in a previous version of FortiOS and remain in FortiOS 7.4.7.

Explicit Proxy

Bug ID

Description

1026362

Web pages do not load when persistent-cookie is disabled for session-cookie-based authentication with captive-portal.

Firewall

Bug ID

Description

959065

On the Policy & Objects > Traffic Shaping page, when deleting or creating a shaper, the counters for the other shapers are cleared.

994986

The By Sequence view in the Firewall policy list may incorrectly show a duplicate implicit deny policy in the middle of the list. This is purely a GUI display issue and does not impact policy operation.

The Interface Pair View and Sequence Grouping View do not have this issue.

1004263

Session counters are not updated when ASIC offload is enabled on firewall policy. FortiGate GUI displays incorrect information in the "Bytes" and "Last Used" columns.

1057080

On the Firewall Policy page, search results do not display in an expanded format.

1078662

If an interface on an NP7 platform has the set inbandwidth XXX, set outbandwidth XXX, and set egress-shaping-profile XX settings, the following issues may occur:

  • Fragment packet checksum is incorrect.

  • MTU is not honored when sending packets out.

  • QTM hangs and blocks traffic when packet size is larger than 6000 bytes.

Workaround:

config system interface
    edit xxx
        unset egress-shaping-profile
    next
end

1114635

In the GUI, cannot filter Address objects correctly when using CIDR notation.

1117165

Leaving the apn field empty in a GTP APN traffic shaping policy means that the policy will not match any traffic. Consequently, APN traffic shaping can only be applied to specific APNs.

To configure GTP APN traffic shaping:

config gtp apn-shaper
    edit <policy-id>
        set apn [<apn-name> <apngrp-name> ...]
        set rate-limit <limit>
        set action {drop | reject}
        set back-off-time <time>
    next
end

FortiGate 6000 and 7000 platforms

Bug ID

Description

790464

After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond.

911244

FortiGate 7000E IPv6 routes may not be synchronized correctly among FIMs and FPMs.

976521

High CPU usage by the node process occurs when loading 7000 policies due to fetching all statistics in one request.

1006759

After an HA failover, there is no IPsec route in the kernel.

Workaround: Bring down and bring up the tunnel.

1026665

On the FortiGate 7000F platform with virtual clustering enabled and syslog logging configured, when running the diagnose log test command from a primary vcluster VDOM, some FPMs may not send log messages to the configured syslog servers.

1048808

If the secondary reboots, after it rejoins the cluster SIP sessions are not resynchronized.

1060619

CSF is not working as expected.

1070365

FGCP HA session synchronization may stop working as expected on a FortiGate 7000F cluster managed by FortiManager. This happens if the HA configuration uses management interfaces as session synchronization interfaces by configuring the session-sync-dev option, for example:

config system ha
    set session-sync-dev 1-M1 1-M2
end

The problem occurs when FortiManager updates the configuration of the FortiGate 7000F devices in the cluster it incorrectly changes to the VDOM of the management interfaces added to the session-sync-dev command from mgmt-vdom to vsys_ha and the interfaces stop working as session sync interfaces.

You can work around the problem by re-configuring the session-sync-dev option on the FortiGate 7000F cluster (this resets the VDOM of the session sync interfaces to vsys_ha) and then retrieving the FortiGate configuration from FortiManager. This synchronizes the correct configuration to FortiManager.

1092728 On FortiGate 6000 and 7000 platforms, fragmented IPv6 traffic is randomly dropped.

1109601

Graceful upgrades fail when hatalk daemon restarts, disrupting slbha state synchronization during FortiOS version transitions.

GUI

Bug ID

Description

853352

When viewing entries in slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100000 entries.

885427

Suggest showing the SFP status information on the faceplate of FGR-60F/60F-3G4G devices.

1047963

High Node.js memory usage when building FortiManager in Report Runner fails. Occurs when FortiManager has a slow connection, is unreachable from the FortiGate (because FMG is behind NAT), or the IP is incorrect.

1055197

On FortiGate G series models with dual WAN links, the Interface Bandwidth widget may show an incorrect incoming and outgoing bandwidth count where the actual traffic does not match the display numbers.

1071907

There is no setting for the type option on the GUI for npu_vlink interface.

1114549

Authorization of FEXT devices fails when using the FortiGate GUI.

1145907

Bandwidth widget does not report the traffic correctly for backup VLAN interfaces.

HA

Bug ID

Description

781171

When performing HA upgrade in the GUI, if the secondary unit takes several minutes to boot up, the GUI may show a misleading error message Image upgrade failed due to premature timeout.

This is just a GUI display issue and the HA upgrade can still complete without issue.

1000808

FortiGate in an HA setup has an unnecessary primary unit selection when a new member joins or reboots one member in the VC cluster when the VC has more than 2 units.

1107137

The secondary FortiGate with an HA Reserved Management Interface cannot be accessed using HTTPS after upgrading from version 7.4.3.

1135376

When HA members are not registered under the same FortiCare account, the HA cluster cannot obtain contract info of all members from FortiGuard servers.

1137565

vSN support was added in 7.2.9, 7.4.6, and 7.6.1. FG-100F/101F do not yet support vSN and logical-sn.

No workaround until the devices support vSN.

1226122

System > HA: There is no upgrade button on secondary GUI page when HA in local-only or secondary-only MVC upgrade mode.

Workaround: upgrade the secondary via the command line.

Hyperscale

Bug ID

Description

1024274

When Hyperscale logging is enabled with multicast log, the log is not sent to servers that are configured to receive multicast logs.

1025908

Session count on peer device is 50% less during FGSP testing in new setups using VRRP-based configuration.

Intrusion Prevention

Bug ID

Description

1117043

After upgrade, event log shows logdesc="IPSA driver update failed" msg="Fail to update IPSA driver status!".

This issue only affects physical FortiGate models with the following IPS engine versions:

  • IPS Engine version: 7.550 - 7.567

  • IPS Engine version: 7.1019 - 7.1039

To determine the IPS Engine versions, use the command:

get sys fortiguard-service status | grep 'IPS/FlowAV Engine'

Workaround: Power off the FortiGate. Wait 30 seconds, and then power on the FortiGate.

Note: Reboot using the CLI is not an effective workaround and requires additional steps. After executing exec shutdown, unplug the power to the FortiGate. Wait one minute, and the power on the FortiGate.

IPsec VPN

Bug ID

Description

866413

Traffic over GRE tunnel over IPsec tunnel, or traffic over IPsec tunnel with GRE encapsulation is not offloaded on NP7-based units.

897871

GRE over IPsec does not work in transport mode.

970703

FortiGate 6K and 7K models do not support IPsec VPN over vdom-link/npu-vlink.

1012615

IPsec VPN traffic is dropped after upgrading to version 7.4.3.

1110093

IPsec SA offloading stops on some FortiGate models when handling more than 50,000 concurrent secure associations.

1140823

IPsec tunnels become stuck on spoke np6xlite, causing ESP packet drops after extended operation due to improper vifid formation during multiple rekey operations.

Log & Report

Bug ID

Description

1113588

FortiGate prompts error Fetching data from Disk is taking longer than expected. Suggest trying a different log source or check the availability of Disk. when viewing logs for the last 7 days from disk or FortiAnalyzer.

1148101

Logs fail to appear in FortiAnalyzer, and FortiView sources are missing from the Dashboard.

Proxy

Bug ID

Description

1035490

The firewall policy works with proxy-based inspection mode on FortiGate models with 2GB RAM after an upgrade.

Workaround: After an upgrade, reboot the FortiGate.

1060812

Botnet detection fails in transparent proxy setups caused by implementation error.

Routing

Bug ID

Description

903444

The diagnose ip rtcache list command is no longer supported in the FortiOS 4.19 kernel.

1040655

From version 7.4.1, when there is ECMP routes, local out traffic may use a different route/port to connect out to the server.

Workaround: for critical traffic which is sensitive to source IP address, specify the interface or SD-WAN for the traffic using the interface-select-method command for nearly all local-out traffic. For example:

config system fortiguard
    set interface-select-method specify
    set interface "wan1"
end

Security Fabric

Bug ID

Description

903922

Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation.

1011833

FortiGate experiences a CPU usage issue in the node process when there multiple administrator sessions running simultaneously on the GUI in a Security Fabric with multiple downstream devices. This may result in slow loading times for multiple GUI pages.

1021684

In some cases, the Security Fabric topology does not load properly and displays a Failed to load Topology Results error.

1150382

Security profile names containing two forward slashes (//) cause the webpage to become unresponsive when attempting to edit.

1076439

Security Fabric Asset Identity Center shows "Failed to load user device store data".

1149817

Security Fabric > Physical Topology: Fortilink Tier2 switch shows directly connected to FortiGate on Security Fabric - Physical Topology page.

The correct topology can be seen on the WiFi & Switch Controller > Managed FortiSwitches > Topology view.

SSL VPN

Bug ID

Description

1058211

Traffic could not go though SSL VPN tunnel when DTLS is enabled with a loopback interface as source address.

Switch Controller

Bug ID

Description

1114032

The GUI becomes slow or unresponsive when transceiver-related API requests fail.

1138263

FortiSwitch port configurations fail to update and GUI display issues occur when user-info process overloads system resources with excessive connections.

1146176

config sync error on managed FSW after upgrade when "Name" field and port exported are configured on the same FSW.

1150215

Offline FSWs show as offline in the GUI topology view but show as online in the list view.

System

Bug ID

Description

901621

On the NP7 platform, setting the interface configuration using set inbandwidth <x> or set outbandwidth <x> commands stops traffic flow.

Workaround: Change the NP7 default-qos-type setting from shaping to policing. This requires a restart of the device for the configuration to take effect:

config system npu
   set default-qos-type policing
end

992323, 1056133, 1075607, 1082413, 1084898

Traffic interrupted when traffic shaping is enabled on 9xG and 12xG.

1021903

The le-switch member list does not update when the role of an interface is changed in a lan-extension environment.

1046484

After shutting down a SOC4 FortiGate (FGT-40F/FGT-61F/FGT-81F/FGT-100F) using the "execute shutdown" command, the system automatically boots up again.

1048496

On FortiGate, the snmp daemon does not work as expected resulting in the SNMP queries timing out.

1057131

A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate.

1069208

If the DHCP offer contains padding when DHCP relay is used, the DHCP relay deletes the padding before relaying the packet.

1078541

The FortiFirewall 2600F model may become stuck after a fresh image burn. Upgrading from a previous version stills works.

Workaround: power cycle the unit.

1089143

The time change in FOS is restored after reboot. The RTC node is not created correctly so the time change cannot be kept in RTC.

1102416

Cannot push config sfp-dsl enable and vectoring under interface.

1113436

Packets are dropped when using auto-asic-offload with 802.1AD over LACP on FortiGate due to missing MAC address assignment on QinQ lag interfaces.

1114298

FortiGate Cloud remote login triggers 2 admin login events (1 successful and 1 unsuccessful for PKI admin).

1117005

CPU spikes and management access issues occur on certain FortiGate models post-upgrade when IPsec Phase 1 NPU-offload is enabled during maintenance.

1140755

When attempting to delete a software switch interface, it becomes permanently hidden due to an unreverted temporary flag.

Upgrade

Bug ID

Description

1087263

Upgrading an FGCP HA cluster of FortiGates with NP7 processors from 7.2.8, 7.2.9, or 7.2.10 to FortiOS 7.4.4, 7.4.5, 7.4.6, or 7.4.7 may cause the cluster to experience an infinite reboot loop. This issue has been resolved by FortiOS 7.4.8.

You can work around this problem by either disconnecting the FortiGates from the cluster, upgrading them individually, and then reforming the cluster, or by upgrading the cluster from 7.2.x to 7.2.10 and then to 7.4.8.

1104649

In 7.4.6 and 7.4.7, if a local-in policy or local-in-policy6 is used in an interface in version 7.4.5, or any previous GA version that was part of the SD-WAN zone, the policies are deleted or show empty values after upgrading to version 7.4.6 or 7.4.7.

Workaround: After upgrading to 7.4.6 or 7.4.7, users must manually recreate these policies and assign them to the appropriate SD-WAN zone.

1114550

FortiExtender shows as offline after upgrading FGT from 7.4.5 to 7.4.6.

Workaround: Reboot FortiExtender manually.

User & Authentication

Bug ID

Description

884462

NTLM authentication does not work with Chrome.

972391

RADIUS group usage not displayed correctly in GUI when used for firewall admin authentication.

1080234

For FortiGate (versions 7.2.10 and 7.4.5 and later) and FortiNAC (versions 9.2.8 and 9.4.6 and prior) integration, when testing connectivity/user credentials against FortiNAC that acts as a RADIUS server, the FortiGate GUI and CLI returns an invalid secret for the server error.

This error is expected when the FortiGate acts as the direct RADIUS client to the FortiNAC RADIUS server due to a change in how FortiGate handles RADIUS protocol in these versions. However, the end-to-end integration for the clients behind the FortiGate and FortiNAC is not impacted.

Workaround: confirm the connectivity between the end clients and FortiNAC by checking if the clients can still be authorized against the FortiNAC as normal.

1082800

When performing LDAP user searches from the GUI against LDAP servers with a large number of users (more than 100000), FortiGate may experience a performance issue and not operate as expected due to the HTTPSD process consuming too much memory. User may need to stop the HTTPSD process or perform a reboot to recover.

Workaround: Perform an LDAP user search using the CLI.

1112718

When RADIUS server has the require-message-authenticator setting disabled, the GUI RADIUS server dialogs Test connectivity and Test user credentials still check for the message-authenticator value and incorrectly fail the test with missing authenticator error message.

config user radius
    edit <radius server>
        set require-message-authenticator disable
    next
end

This is only a GUI display issue and the end-to-end integration with RADIUS server should still work.

Workaround: user can confirm if the connection to RADIUS server via CLI command

diagnose test authserver radius <server> <method> <user> <password>.

1157003

Agentless FSSO connector issues occur when using Windows 2025 due to MS introduced additional restrictions to remote Event log reading.

VM

Bug ID

Description

978021

In FTP passive mode with GWLB setup, Geneve header VNI lengths are zero in syn-ack packets, leading to retransmission issues.

1082197

VLAN traffic fails to pass through E810-XXV NIC with SFP28 transceiver and 25G speed after enabling DPDK.

1094274

FortiOS becomes unresponsive when sending IPv6 traffic over MLX5 network adapters due to incorrect WQE handling.

WiFi Controller

Bug ID

Description

814541

When there are extra large number of managed FortiAP devices (over 500) and large number of WiFi clients (over 5000), the Managed FortiAPs page and FortiAP Status widget can take a long time to load. This issue does not impact FortiAP operation.

949682

Intermittent traffic disruption observed in cw_acd caused by a rare error condition.

964757

The FortiGate fails to generate debug/sniffer logs for a user when connecting to a specific SSID despite showing station logs with radius requests and challenges, while other SSIDs function correctly.

1050915

On the WiFi & Switch Controller > Managed FortiAPs page, when upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware.

Workaround: Upgrade the FortiAPs in smaller batches of up to 20 devices to avoid performance impacts.

1080094

High memory usage may occur due to offline station entries not being automatically cleaned up over time.

1083395

In an HA environment with FortiAPs managed by primary FortiGate, the secondary FortiGate GUI Managed FortiAP page may show the FortiAP status as offline if the FortiAP traffic is not routed through the secondary FortiGate.

This is only a GUI issue and does not impact FortiAP operation.

ZTNA

Bug ID

Description

819987

Mapped drives become inaccessible after laptop reboots when using FortiGate ZTNA access proxy with FQDN destinations.

1020084

Health check on the ZTNA realserver does not work as expected if a blackhole route is added to the realserver address.

Known issues

Known issues

Known issues are organized into the following categories:

To inquire about a particular bug or report a bug, please contact Customer Service & Support.

New known issues

The following issues have been identified in version 7.4.7.

Firewall

Bug ID

Description

1148166

Source port translation was not permitted with traffic to UDP port 7001.

GUI

Bug ID

Description

1152464

The DHCP reservation widget incorrectly validates based on the subnet instead of individual IP addresses.

1153294

Custom HTML content does not render correctly on login pages when configured through the FortiGate web interface or CLI.

HA

Bug ID

Description

1151668

Interface bandwidth widget doesn't display HB and Managed port.

IPsec VPN

Bug ID

Description

1152486

Unable to select policy-based IPsec tunnel in the firewall policy for SD-WAN member while configuring in GUI.

REST API

Bug ID

Description

1154124

Adding dynamic fabric addresses via the FortiNAC REST API fails due to an issue with HTTP header validation.

Routing

Bug ID

Description

1142290

An error message appears in FortiGate when attempting to add the ssl.root interface to a route-map via the GUI.

Security Fabric

Bug ID

Description

1156006

SFTP backup fails when triggered through automation stitch on a FortiGate in an HA cluster using Windows-style paths.

System

Bug ID

Description

945871

D-NAT functionality fails when using a Software Switch in explicit mode due to incorrect session matching during packet forwarding.

1012577

Traffic on WAN interface is dropped when policy-offload-level (under config system setting) is set to dos-offload.

1054955

USB GPIO and host function were not set up properly on 9xG and 12xG.

1085407

FortiGate unresponsive when default-qos-type is set to shaping.

1091551

Hardware limitation on the NP7 platform causes the following QTM related issues:

  • Incorrect checksum for fragments after QTM. The workaround is to not parse Layer4 after QTM.

  • Packets longer than 6000 bytes cause QTM unresponsiveness.

  • Refresh issue causes QTM unresponsiveness. The workaround is to use one refresh list.

  • MTU is not honored after QTM, so packets are not fragmented.

1104410

The FortiGate-120G SFP ports fail to establish connectivity when configured with 'set speed 1000full' due to improper auto-negotiation handling.

1105321

FG-4201F with NP7 network processors shows EIF0_IGR and EIF1_IGR usage stuck at 100% and host softirq stuck at 99% after running the iptunnel traffic.

1116220

FortiGate 3601E 25Gauto link not coming up using DAC cables.

1146354

The network interface settings page fails to load on certain FortiGate models when the admin profile does not have the System > Configuration > Read/Write permission.

1164174

Configuration loss on FGT-60F when FortiGate enters extreme conserve mode

1170282

FortiGate HA becomes out of sync after provisioning a certificate by using ACME protocol.

Upgrade

Bug ID

Description

1097503

Fabric upgrade from 7.2.9 to 7.4.5 failed.

User & Authentication

Bug ID

Description

1148767

FSSO users show in small letters, user filtering is not working, and PIE charts are not visible.

VM

Bug ID

Description

1146370

AWS bootstrap is unable to parse IAM role profile properly due to the length.

Existing known issues

The following issues have been identified in a previous version of FortiOS and remain in FortiOS 7.4.7.

Explicit Proxy

Bug ID

Description

1026362

Web pages do not load when persistent-cookie is disabled for session-cookie-based authentication with captive-portal.

Firewall

Bug ID

Description

959065

On the Policy & Objects > Traffic Shaping page, when deleting or creating a shaper, the counters for the other shapers are cleared.

994986

The By Sequence view in the Firewall policy list may incorrectly show a duplicate implicit deny policy in the middle of the list. This is purely a GUI display issue and does not impact policy operation.

The Interface Pair View and Sequence Grouping View do not have this issue.

1004263

Session counters are not updated when ASIC offload is enabled on firewall policy. FortiGate GUI displays incorrect information in the "Bytes" and "Last Used" columns.

1057080

On the Firewall Policy page, search results do not display in an expanded format.

1078662

If an interface on an NP7 platform has the set inbandwidth XXX, set outbandwidth XXX, and set egress-shaping-profile XX settings, the following issues may occur:

  • Fragment packet checksum is incorrect.

  • MTU is not honored when sending packets out.

  • QTM hangs and blocks traffic when packet size is larger than 6000 bytes.

Workaround:

config system interface
    edit xxx
        unset egress-shaping-profile
    next
end

1114635

In the GUI, cannot filter Address objects correctly when using CIDR notation.

1117165

Leaving the apn field empty in a GTP APN traffic shaping policy means that the policy will not match any traffic. Consequently, APN traffic shaping can only be applied to specific APNs.

To configure GTP APN traffic shaping:

config gtp apn-shaper
    edit <policy-id>
        set apn [<apn-name> <apngrp-name> ...]
        set rate-limit <limit>
        set action {drop | reject}
        set back-off-time <time>
    next
end

FortiGate 6000 and 7000 platforms

Bug ID

Description

790464

After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond.

911244

FortiGate 7000E IPv6 routes may not be synchronized correctly among FIMs and FPMs.

976521

High CPU usage by the node process occurs when loading 7000 policies due to fetching all statistics in one request.

1006759

After an HA failover, there is no IPsec route in the kernel.

Workaround: Bring down and bring up the tunnel.

1026665

On the FortiGate 7000F platform with virtual clustering enabled and syslog logging configured, when running the diagnose log test command from a primary vcluster VDOM, some FPMs may not send log messages to the configured syslog servers.

1048808

If the secondary reboots, after it rejoins the cluster SIP sessions are not resynchronized.

1060619

CSF is not working as expected.

1070365

FGCP HA session synchronization may stop working as expected on a FortiGate 7000F cluster managed by FortiManager. This happens if the HA configuration uses management interfaces as session synchronization interfaces by configuring the session-sync-dev option, for example:

config system ha
    set session-sync-dev 1-M1 1-M2
end

The problem occurs when FortiManager updates the configuration of the FortiGate 7000F devices in the cluster it incorrectly changes to the VDOM of the management interfaces added to the session-sync-dev command from mgmt-vdom to vsys_ha and the interfaces stop working as session sync interfaces.

You can work around the problem by re-configuring the session-sync-dev option on the FortiGate 7000F cluster (this resets the VDOM of the session sync interfaces to vsys_ha) and then retrieving the FortiGate configuration from FortiManager. This synchronizes the correct configuration to FortiManager.

1092728 On FortiGate 6000 and 7000 platforms, fragmented IPv6 traffic is randomly dropped.

1109601

Graceful upgrades fail when hatalk daemon restarts, disrupting slbha state synchronization during FortiOS version transitions.

GUI

Bug ID

Description

853352

When viewing entries in slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100000 entries.

885427

Suggest showing the SFP status information on the faceplate of FGR-60F/60F-3G4G devices.

1047963

High Node.js memory usage when building FortiManager in Report Runner fails. Occurs when FortiManager has a slow connection, is unreachable from the FortiGate (because FMG is behind NAT), or the IP is incorrect.

1055197

On FortiGate G series models with dual WAN links, the Interface Bandwidth widget may show an incorrect incoming and outgoing bandwidth count where the actual traffic does not match the display numbers.

1071907

There is no setting for the type option on the GUI for npu_vlink interface.

1114549

Authorization of FEXT devices fails when using the FortiGate GUI.

1145907

Bandwidth widget does not report the traffic correctly for backup VLAN interfaces.

HA

Bug ID

Description

781171

When performing HA upgrade in the GUI, if the secondary unit takes several minutes to boot up, the GUI may show a misleading error message Image upgrade failed due to premature timeout.

This is just a GUI display issue and the HA upgrade can still complete without issue.

1000808

FortiGate in an HA setup has an unnecessary primary unit selection when a new member joins or reboots one member in the VC cluster when the VC has more than 2 units.

1107137

The secondary FortiGate with an HA Reserved Management Interface cannot be accessed using HTTPS after upgrading from version 7.4.3.

1135376

When HA members are not registered under the same FortiCare account, the HA cluster cannot obtain contract info of all members from FortiGuard servers.

1137565

vSN support was added in 7.2.9, 7.4.6, and 7.6.1. FG-100F/101F do not yet support vSN and logical-sn.

No workaround until the devices support vSN.

1226122

System > HA: There is no upgrade button on secondary GUI page when HA in local-only or secondary-only MVC upgrade mode.

Workaround: upgrade the secondary via the command line.

Hyperscale

Bug ID

Description

1024274

When Hyperscale logging is enabled with multicast log, the log is not sent to servers that are configured to receive multicast logs.

1025908

Session count on peer device is 50% less during FGSP testing in new setups using VRRP-based configuration.

Intrusion Prevention

Bug ID

Description

1117043

After upgrade, event log shows logdesc="IPSA driver update failed" msg="Fail to update IPSA driver status!".

This issue only affects physical FortiGate models with the following IPS engine versions:

  • IPS Engine version: 7.550 - 7.567

  • IPS Engine version: 7.1019 - 7.1039

To determine the IPS Engine versions, use the command:

get sys fortiguard-service status | grep 'IPS/FlowAV Engine'

Workaround: Power off the FortiGate. Wait 30 seconds, and then power on the FortiGate.

Note: Reboot using the CLI is not an effective workaround and requires additional steps. After executing exec shutdown, unplug the power to the FortiGate. Wait one minute, and the power on the FortiGate.

IPsec VPN

Bug ID

Description

866413

Traffic over GRE tunnel over IPsec tunnel, or traffic over IPsec tunnel with GRE encapsulation is not offloaded on NP7-based units.

897871

GRE over IPsec does not work in transport mode.

970703

FortiGate 6K and 7K models do not support IPsec VPN over vdom-link/npu-vlink.

1012615

IPsec VPN traffic is dropped after upgrading to version 7.4.3.

1110093

IPsec SA offloading stops on some FortiGate models when handling more than 50,000 concurrent secure associations.

1140823

IPsec tunnels become stuck on spoke np6xlite, causing ESP packet drops after extended operation due to improper vifid formation during multiple rekey operations.

Log & Report

Bug ID

Description

1113588

FortiGate prompts error Fetching data from Disk is taking longer than expected. Suggest trying a different log source or check the availability of Disk. when viewing logs for the last 7 days from disk or FortiAnalyzer.

1148101

Logs fail to appear in FortiAnalyzer, and FortiView sources are missing from the Dashboard.

Proxy

Bug ID

Description

1035490

The firewall policy works with proxy-based inspection mode on FortiGate models with 2GB RAM after an upgrade.

Workaround: After an upgrade, reboot the FortiGate.

1060812

Botnet detection fails in transparent proxy setups caused by implementation error.

Routing

Bug ID

Description

903444

The diagnose ip rtcache list command is no longer supported in the FortiOS 4.19 kernel.

1040655

From version 7.4.1, when there is ECMP routes, local out traffic may use a different route/port to connect out to the server.

Workaround: for critical traffic which is sensitive to source IP address, specify the interface or SD-WAN for the traffic using the interface-select-method command for nearly all local-out traffic. For example:

config system fortiguard
    set interface-select-method specify
    set interface "wan1"
end

Security Fabric

Bug ID

Description

903922

Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation.

1011833

FortiGate experiences a CPU usage issue in the node process when there multiple administrator sessions running simultaneously on the GUI in a Security Fabric with multiple downstream devices. This may result in slow loading times for multiple GUI pages.

1021684

In some cases, the Security Fabric topology does not load properly and displays a Failed to load Topology Results error.

1150382

Security profile names containing two forward slashes (//) cause the webpage to become unresponsive when attempting to edit.

1076439

Security Fabric Asset Identity Center shows "Failed to load user device store data".

1149817

Security Fabric > Physical Topology: Fortilink Tier2 switch shows directly connected to FortiGate on Security Fabric - Physical Topology page.

The correct topology can be seen on the WiFi & Switch Controller > Managed FortiSwitches > Topology view.

SSL VPN

Bug ID

Description

1058211

Traffic could not go though SSL VPN tunnel when DTLS is enabled with a loopback interface as source address.

Switch Controller

Bug ID

Description

1114032

The GUI becomes slow or unresponsive when transceiver-related API requests fail.

1138263

FortiSwitch port configurations fail to update and GUI display issues occur when user-info process overloads system resources with excessive connections.

1146176

config sync error on managed FSW after upgrade when "Name" field and port exported are configured on the same FSW.

1150215

Offline FSWs show as offline in the GUI topology view but show as online in the list view.

System

Bug ID

Description

901621

On the NP7 platform, setting the interface configuration using set inbandwidth <x> or set outbandwidth <x> commands stops traffic flow.

Workaround: Change the NP7 default-qos-type setting from shaping to policing. This requires a restart of the device for the configuration to take effect:

config system npu
   set default-qos-type policing
end

992323, 1056133, 1075607, 1082413, 1084898

Traffic interrupted when traffic shaping is enabled on 9xG and 12xG.

1021903

The le-switch member list does not update when the role of an interface is changed in a lan-extension environment.

1046484

After shutting down a SOC4 FortiGate (FGT-40F/FGT-61F/FGT-81F/FGT-100F) using the "execute shutdown" command, the system automatically boots up again.

1048496

On FortiGate, the snmp daemon does not work as expected resulting in the SNMP queries timing out.

1057131

A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate.

1069208

If the DHCP offer contains padding when DHCP relay is used, the DHCP relay deletes the padding before relaying the packet.

1078541

The FortiFirewall 2600F model may become stuck after a fresh image burn. Upgrading from a previous version stills works.

Workaround: power cycle the unit.

1089143

The time change in FOS is restored after reboot. The RTC node is not created correctly so the time change cannot be kept in RTC.

1102416

Cannot push config sfp-dsl enable and vectoring under interface.

1113436

Packets are dropped when using auto-asic-offload with 802.1AD over LACP on FortiGate due to missing MAC address assignment on QinQ lag interfaces.

1114298

FortiGate Cloud remote login triggers 2 admin login events (1 successful and 1 unsuccessful for PKI admin).

1117005

CPU spikes and management access issues occur on certain FortiGate models post-upgrade when IPsec Phase 1 NPU-offload is enabled during maintenance.

1140755

When attempting to delete a software switch interface, it becomes permanently hidden due to an unreverted temporary flag.

Upgrade

Bug ID

Description

1087263

Upgrading an FGCP HA cluster of FortiGates with NP7 processors from 7.2.8, 7.2.9, or 7.2.10 to FortiOS 7.4.4, 7.4.5, 7.4.6, or 7.4.7 may cause the cluster to experience an infinite reboot loop. This issue has been resolved by FortiOS 7.4.8.

You can work around this problem by either disconnecting the FortiGates from the cluster, upgrading them individually, and then reforming the cluster, or by upgrading the cluster from 7.2.x to 7.2.10 and then to 7.4.8.

1104649

In 7.4.6 and 7.4.7, if a local-in policy or local-in-policy6 is used in an interface in version 7.4.5, or any previous GA version that was part of the SD-WAN zone, the policies are deleted or show empty values after upgrading to version 7.4.6 or 7.4.7.

Workaround: After upgrading to 7.4.6 or 7.4.7, users must manually recreate these policies and assign them to the appropriate SD-WAN zone.

1114550

FortiExtender shows as offline after upgrading FGT from 7.4.5 to 7.4.6.

Workaround: Reboot FortiExtender manually.

User & Authentication

Bug ID

Description

884462

NTLM authentication does not work with Chrome.

972391

RADIUS group usage not displayed correctly in GUI when used for firewall admin authentication.

1080234

For FortiGate (versions 7.2.10 and 7.4.5 and later) and FortiNAC (versions 9.2.8 and 9.4.6 and prior) integration, when testing connectivity/user credentials against FortiNAC that acts as a RADIUS server, the FortiGate GUI and CLI returns an invalid secret for the server error.

This error is expected when the FortiGate acts as the direct RADIUS client to the FortiNAC RADIUS server due to a change in how FortiGate handles RADIUS protocol in these versions. However, the end-to-end integration for the clients behind the FortiGate and FortiNAC is not impacted.

Workaround: confirm the connectivity between the end clients and FortiNAC by checking if the clients can still be authorized against the FortiNAC as normal.

1082800

When performing LDAP user searches from the GUI against LDAP servers with a large number of users (more than 100000), FortiGate may experience a performance issue and not operate as expected due to the HTTPSD process consuming too much memory. User may need to stop the HTTPSD process or perform a reboot to recover.

Workaround: Perform an LDAP user search using the CLI.

1112718

When RADIUS server has the require-message-authenticator setting disabled, the GUI RADIUS server dialogs Test connectivity and Test user credentials still check for the message-authenticator value and incorrectly fail the test with missing authenticator error message.

config user radius
    edit <radius server>
        set require-message-authenticator disable
    next
end

This is only a GUI display issue and the end-to-end integration with RADIUS server should still work.

Workaround: user can confirm if the connection to RADIUS server via CLI command

diagnose test authserver radius <server> <method> <user> <password>.

1157003

Agentless FSSO connector issues occur when using Windows 2025 due to MS introduced additional restrictions to remote Event log reading.

VM

Bug ID

Description

978021

In FTP passive mode with GWLB setup, Geneve header VNI lengths are zero in syn-ack packets, leading to retransmission issues.

1082197

VLAN traffic fails to pass through E810-XXV NIC with SFP28 transceiver and 25G speed after enabling DPDK.

1094274

FortiOS becomes unresponsive when sending IPv6 traffic over MLX5 network adapters due to incorrect WQE handling.

WiFi Controller

Bug ID

Description

814541

When there are extra large number of managed FortiAP devices (over 500) and large number of WiFi clients (over 5000), the Managed FortiAPs page and FortiAP Status widget can take a long time to load. This issue does not impact FortiAP operation.

949682

Intermittent traffic disruption observed in cw_acd caused by a rare error condition.

964757

The FortiGate fails to generate debug/sniffer logs for a user when connecting to a specific SSID despite showing station logs with radius requests and challenges, while other SSIDs function correctly.

1050915

On the WiFi & Switch Controller > Managed FortiAPs page, when upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware.

Workaround: Upgrade the FortiAPs in smaller batches of up to 20 devices to avoid performance impacts.

1080094

High memory usage may occur due to offline station entries not being automatically cleaned up over time.

1083395

In an HA environment with FortiAPs managed by primary FortiGate, the secondary FortiGate GUI Managed FortiAP page may show the FortiAP status as offline if the FortiAP traffic is not routed through the secondary FortiGate.

This is only a GUI issue and does not impact FortiAP operation.

ZTNA

Bug ID

Description

819987

Mapped drives become inaccessible after laptop reboots when using FortiGate ZTNA access proxy with FQDN destinations.

1020084

Health check on the ZTNA realserver does not work as expected if a blackhole route is added to the realserver address.