FortiOS 7.0.17 release notes
FortiOS 7.0.17 is a maintenance and security release fixing four functional defects and six CVEs. The supplied notes also list 62 existing known issues and direct administrators to Fortinet's model-specific Upgrade Path Tool.
Official Fortinet release notes ↗Security fixes
- #1093598CVE-2024-50571
CVE-2024-50571 fixed
FortiOS 7.0.17 is no longer vulnerable.
- #1100972CVE-2024-52965
CVE-2024-52965 fixed
FortiOS 7.0.17 is no longer vulnerable.
- #1103505CVE-2024-55591
CVE-2024-55591 fixed
FortiOS 7.0.17 is no longer vulnerable.
- #1108301CVE-2025-22254
CVE-2025-22254 fixed
FortiOS 7.0.17 is no longer vulnerable.
- #1109252CVE-2025-25252
CVE-2025-25252 fixed
FortiOS 7.0.17 is no longer vulnerable.
- #1112305CVE-2025-22258
CVE-2025-22258 fixed
FortiOS 7.0.17 is no longer vulnerable.
Upgrade notes
Use the model-specific Upgrade Path Tool
Supported paths depend on the FortiGate model and current version. In Fortinet's Upgrade Path Tool, select FortiGate / FortiOS, the product model, current version, and target version, then click Go to obtain the supported sequence.
Resolved issues
- #1110382
GUI password login bypassed HTTPS PKI requirement
Fixed an issue where an administrator could log in to the GUI over HTTPS with a password even when `admin-https-pki-required` was enabled.
- #989677
REST API JavaScript dependencies updated
Updated JavaScript components to the latest Long Term Support version.
- #935297
AWS probe appeared in default SD-WAN checks
Fixed `aws.amazon.com` being listed in the SD-WAN default health-check list.
- #1101837
Insufficient SSL VPN SAML session expiration
Fixed insufficient session expiration in SSL VPN when using SAML authentication.
Known issues
- #1117475
SSL VPN SAML login fails with internal browser
FortiClient cannot connect to FortiGate SSL VPN using SAML login when an internal browser is selected as the SAML authentication user agent.
- #1117005
IPsec NPU offload can cause post-upgrade CPU spikes
On certain FortiGate models, CPU spikes and management-access problems can occur after upgrade when IPsec Phase 1 NPU offload is enabled during maintenance.
- #843554
GUI can alter the first IP service object's protocol
Creating an IP-protocol firewall service in the GUI may silently modify the protocol number of the first IP-type service, potentially affecting policies such as those using `ALL` on some 6K and 7K platforms. Workaround: create the service in the CLI or place a non-IP service first, for example: `config firewall service custom`; `edit "unused"`; `set tcp-portrange 1`; `next`; `move "unused" before "ALL"`; `end`.
- #912740
FortiManager policies may split into separate sequence groups
After upgrading a FortiManager-managed FortiGate to 7.0.13, unique `global-label` values may create separate sequence groups for each policy. Workaround: drag policies into the correct group or remove `global-label` from each member except the leading policy.
- #951984
Local-out DNAT may select the wrong route
The best output route may not be found for local-out DNAT traffic.
- #941521
FortiView category filter fails in Japanese GUI
The Category filter on Dashboard > FortiView Websites does not work in the Japanese GUI.
- #440197
FortiGuard override server status displays Unknown
The System > FortiGuard page may show Unknown for a working AntiVirus and IPS update override server. This is display-only; the override continues to function.
- #677806
Global VDOM view misreports IPsec tunnel status
With VDOM mode enabled, Network > Interfaces in Global view may show IPsec interfaces from non-management VDOMs as UP. The VDOM view is accurate.
- #685431
Large firewall policy lists load slowly
Policy & Objects > Firewall Policy can take about 30 seconds or longer to load with more than 20,000 policies. Workaround: configure policies through the CLI.
- #707589
Certificate reference count and deletion result can be wrong
System > Certificates may show an incorrect reference count and permit an attempted deletion of a referenced certificate. The deletion fails despite a success message; remove all references before deletion.
- #708005
Firefox cannot paste into SSL VPN SSH terminal
Users cannot paste text into the SSL VPN web portal SSH terminal emulator in Firefox. Workaround: use Chrome, Edge, or Safari.
- #755177
GUI incorrectly rejects the 7.0.1-to-7.0.2 path
The GUI displays an invalid-upgrade-path warning when upgrading firmware from 7.0.1 to 7.0.2.
- #810225
First administrator password change shows undefined
An undefined error appears when an administrator password is changed for the first time on NP7 platforms.
- #853352
Internet Service Database pane cannot reach final entries
The View/Edit Entries pane under Policy & Objects > Internet Service Database cannot scroll to the end when it contains more than 100,000 entries.
- #881678
GUI cannot edit very large prefix lists
Editing a prefix list with many rules under Network > Routing Objects fails with an integer-range error. Workaround: edit the prefix list through the CLI.
- #898902
Two-factor toggle loads slowly with many VDOMs
With more than 200 VDOMs, System > Administrators may take over one minute to load the Two-factor Authentication toggle. Other settings are unaffected. Workaround: configure `two-factor-authentication` under `config system admin` in the CLI.
- #974988
Valid account license can still trigger expiration notice
The GUI may show a FortiManager Cloud expiration notification for an expired device-level license even when a valid account-level license exists. Functionality is unaffected.
- #1102588
High security level blocks graceful HA upgrade
On FortiGate 12xG and 9xG devices, graceful upgrade of the secondary HA node fails at high security level. Workaround: disable HA and upgrade units separately, or temporarily lower the security level and restore it afterward.
- #771857
Hyperscale policies expose unsupported VIP options
Hyperscale firewall policies do not support VIP features `srcfltr`, `srcintf-fltr`, `service`, `arp-reply`, `nat-source-vip`, or port forwarding, although these appear in the CLI or GUI for IPv4 and IPv6 VIP configuration.
- #811109
Selected hyperscale interfaces cannot join an LAG
HA1, HA2, AUX1, and AUX2 interfaces cannot be added to an LAG on FortiGate 4200F, 4201F, 4400F, and 4401F.
- #836976
Changing hyperscale log processor may drop sessions
Sessions may be dropped when dynamically changing a hyperscale policy's hardware log server `log-processor` from `hardware` to `host`. Make this change during quiet periods.
- #838654
Implicit-deny hit count omits hardware NAT46 and NAT64
The implicit-deny policy hit count does not increment for hardware sessions carrying NAT46 or NAT64 traffic.
- #842659
IPv6 FTS address negation is incorrect
`srcaddr-negate` and `dstaddr-negate` do not work correctly for IPv6 traffic with FTS.
- #843132
New hyperscale ACLs may be delayed
ACL policies added while a hyperscale VDOM is processing traffic can take longer than expected to become effective; traffic intended to be blocked may be allowed during the transition.
- #843197
NPU session list omits policy-route data
The NPU session list does not display policy-route information for traffic routed through a policy route on NPU-accelerated models.
- #843266
Hyperscale diagnostic lacks route and session counters
A diagnostic command is unavailable for showing `hit_count` and `last_used` for policy routes and NPU sessions in a hyperscale VDOM.
- #843305
NPD policy-route parsing error appears at boot
The console can report `PARSE SKIP ERROR=17 NPD ERR PBR ADDRESS` during system startup.
- #844421
IP pool diagnostic output is wrong for overload pools
The `diagnose firewall ippool list` command does not produce correct output for overload-type IP pools.
- #845269
GUI disables CGN endpoint-independent filtering
Editing a hyperscale policy with an overload CGN IP pool causes the GUI to disable `cgn-eif`, regardless of its previous state.
- #846520
NPD or LPMD can be terminated for low memory
The out-of-memory killer may terminate NPD or LPMD after mixed-session traffic and HA failover.
- #895951
EIF NPU setup rate incorrectly reports zero
`diagnose sys npu-session stat` incorrectly reports a `setup rate` of `0` for EIF sessions.
- #941784
FG-480xF hyperscale sessions do not synchronize
Hardware session synchronization does not work on FG-480xF devices in hyperscale mode.
- #986656
HA primary reports zero NPU session state
The HA primary's NPU session list can contain many sessions while NPU session state reports `0`.
- #993343
NAT46 fragment-header option can interrupt the kernel
A kernel interruption can occur in a hyperscale VDOM when `set nat46-generate-ipv6-fragment-header` is enabled.
- #1024902
NPU session statistics miscount FTP sessions
After FTP traffic passes, `npu-session stat` does not report the actual session count accurately.
- #761754
Down IPsec aggregate route remains active
An IPsec aggregate static route is not marked inactive when its IPsec aggregate is down.
- #945367
ADVPN shortcuts do not inherit disabled source checking
Disabling `src-check` reverse-path forwarding on the parent tunnel is not inherited by ADVPN shortcuts.
- #850642
Concurrent configuration changes can suppress traffic logs
Traffic logs may not appear when numerous configuration changes occur simultaneously.
- #1001497
Invalid HTTP date can trigger conserve mode
FortiGate may enter conserve mode when a missing or invalid HTTP date is posted through the web proxy.
- #614691
Large Security Fabric topology slows the GUI
GUI performance is slow in a Fabric topology with more than 50 downstream devices.
- #794703
Security Rating checks return incorrect results
The Rogue AP Detection and FortiCare Support checks in Security Rating reports may show incorrect results.
- #862424
Security Rating may cause conserve mode on large tables
Running Security Rating reports on a FortiGate with more than 1,000 firewall policies, addresses, or other table entries may cause conserve mode.
- #903922
Large Fabric topology views load slowly
Physical and logical Security Fabric topology views load slowly with many downstream FortiGates, FortiSwitches, FortiAPs, and endpoint traffic. This is a GUI-only issue and does not affect downstream operation.
- #847664
Hardware error message can appear after burn or reboot
The console may display `mce: [Hardware Error]` after a fresh image burn or reboot.
- #861962
One-gigabit aggregate interface cannot pass traffic
An 802.3ad aggregate configured for 1 Gbps may have an unlit port LED and pass no traffic. Affected platforms are 110xE, 220xE, 330xE, 340xE, and 360xE.
- #934708
CMDB server cannot acquire var_zone lock
The cmdbsvr process may fail to secure the var_zone lock because another process holds it indefinitely.
- #935158
Missing GUI redirect file message appears after reboot
The console may print `check_gui_redir_file: No such file or directory` after reboot.
- #975496
FortiGate 200F is slow between 1G and 10G interfaces
Download and upload performance may be slow when traffic traverses from a 1G interface to a 10G interface on FortiGate 200F.
- #1082256
BIOS level 2 upgrade can fail integrity checking
Upgrading from 7.0.15 to 7.0.16 with BIOS security level 2 may produce `System file integrity check failed!`.
- #800935
ESXi VLAN interface over LACP does not work
An ESXi VLAN interface based on LACP is nonfunctional.
- #1082304
Selected VM platforms can encounter kernel upgrade errors
ARM64 KVM, AWS, and OCI FortiGate VMs and VM64 OPC can encounter a kernel error while upgrading from 7.0.15 to 7.0.16. The OCI bare-metal kernel image is unsupported in 7.0.16 when upgrading from 7.0.13, 7.0.14, or 7.0.15.
- #766126
Video filter does not automatically show block page
The block replacement page is not automatically pushed to replace video content when a video filter blocks it.
- #814541
Large FortiAP deployments load slowly in the GUI
With more than 500 managed FortiAPs and 5,000 WiFi clients, the Managed FortiAPs page and FortiAP Status widget can take a long time to load. FortiAP operation is unaffected.
- #1004338
NP7 WiFi DHCP-relay traffic fails after restart
After an upgrade or reboot on NP7 platforms, WiFi data cannot pass when the SSID VLAN interface uses DHCP Relay Server.
- #819987
ZTNA mapped drives fail after laptop reboot
Mapped drives can become inaccessible after a laptop reboots when using a FortiGate ZTNA access proxy with FQDN destinations.
- #848222
ZTNA TCP forwarding fails with FQDN real server
ZTNA TCP forwarding does not work when the real server uses an FQDN address type. Publicly resolvable FQDNs are not recommended because the internal DNS database zone may override them; after reboot, the private address may not take effect and the real server may not be found.