FortiSwitch-VLAN with per-device mapping enabled
For customers upgrading from a version prior to FortiManager 7.4.9 or 7.6.5 with a FortiSwitch-VLAN with per-device mapping enabled, FortiManager may unset the interface configuration. Specifically, it may "unset allowaccess" on each VLAN interface.
To correct this issue, run the following command after upgrading FortiManager:
diagnose cdb manual-fix adom <adom name> fspvlan-dyn-ipv4allowaccess
The dynamic mappings will inherit allowaccess settings from the parent entry.