FortiOS 7.4.10 release notes
FortiOS 7.4.10 adds setup and LAN Edge enhancements, changes several security-sensitive defaults, revises NP7 traffic shaping behavior, and resolves issues across security inspection, networking, VPN, HA, GUI, routing, and platform components. The supplied excerpt is truncated during the SD-WAN resolved-issues section and contains no release date, build number, CVEs, upgrade-path guidance, or standalone known-issues list.
Official Fortinet release notes ↗What's new
- #1183975
Setup wizard supports gateway configuration and offline licensing
The setup wizard can configure a gateway for internet connectivity and FortiCare registration. Air-gapped deployments can upload an offline license file directly.
- #1238520
Seven-day pre-registration setup period
Models requiring registration before full GUI and CLI access now permit full configuration for seven days before registration becomes mandatory.
- #1185772
FortiWiFi defaults hardened and simplified
Default soft-switch interfaces and open SSIDs were removed across FortiWiFi platforms. On 4xF, 6xF, and G-series models, the default WiFi VAP remains in tunnel mode with predefined IP, DHCP, and firewall policy settings. On 8xF-2R models, VAPs use bridge mode with the hardware switch, obtain DHCP through the internal interface, and remain subject to firewall policy control.
- #1217645
802.1X supported on virtual switches within software switches
802.1X can now be enabled when the software switch's `intra-switch-policy` is set to `explicit`, allowing dynamic VLAN control and traffic regulation.
Breaking changes
- #1176942
IKE SAML local-in matching is more restrictive
When `auth-ike-saml-port` is used, iprope matches local-in traffic only if the destination port equals `auth-ike-saml-port` and the destination interface has `ike-saml-server` enabled.
- #1204277
FortiGuard auto-update schedule now defaults to daily
The default FortiGuard package update schedule changed from automatic to daily.
- #1207557
Anycast VM activation uses dedicated FQDNs
When Anycast is enabled, VM license activation uses `vmactivation1.fortinet.net`, `vmactivation2.fortinet.net`, and `vmactivation3.fortinet.net` instead of general update FQDNs. Firewall and DNS allowlists may need adjustment.
- #1225202
Same-interface traffic redirects are disabled by default
The defaults for `allow-traffic-redirect` and `ipv6-allow-traffic-redirect` changed from enabled to disabled. Upgrade forcibly changes both settings to disabled even if previously enabled. Same-interface redirected traffic therefore requires an explicit firewall policy. To restore routing-only redirection, manually enable the settings. Configuration: `config system global set allow-traffic-redirect disable set ipv6-allow-traffic-redirect disable end`
NP7 QoS type is no longer selectable between policing and shaping
For NP7-offloaded sessions, `default-qos-type` can only be `policing`; the previous selectable form `config system npu set default-qos-type {policing | shaping} end` is no longer available. Policy shaping, per-IP shaping, and regular port shaping use TPE policing. Interface shaping profiles use QTM shaping.
Features removed
NP7 default-qos-type shaping option removed
The `shaping` value is no longer supported for `config system npu` → `set default-qos-type`; only `policing` can be configured.
Resolved issues
- #1153880
Large HTTP/2 uploads fail with proxy-mode antivirus
Large file uploads over HTTP/2 failed when proxy-mode AntiVirus and deep inspection were enabled.
- #1181573
Flow-mode SSL inspection omits correct AKID
SSL inspection did not correctly add the Authority Key Identifier when flow mode DPI was enabled.
- #1205692
FTP blocked through SOCKS5 with Application Control
FTP traffic was blocked when Application Control was enabled over SOCKS5.
- #1217478
IEC 60870-5-104 detection becomes incomplete after IPS session clear
IEC 60870-5-104 detection could become incomplete after clearing an IPS session. The stated workaround was to clear the system session.
- #1151824
DNS requests across VRFs discarded as retransmissions
Queries from different VRFs with identical transaction IDs and source and destination addresses were treated as retransmissions and discarded.
- #1086668
FortiGate fails to connect to valid EMS Cloud VDOMs
An expired EMS Cloud license on the global FortiCare account prevented connections even when other VDOMs had valid access keys.
- #1207648
Frequent TPM requests disconnect EMS Cloud
Frequent TPM requests from httpsd caused intermittent EMS Cloud disconnections.
- #1074353
Explicit proxy fast fallback uses IPv4 in IPv6-only setup
Fast fallback incorrectly used an IPv4 DNS address to connect to a server in an IPv6-only setup.
- #1094870
FTPS data connections fail under flow-mode FTP policies
FTPS data connections failed with flow-mode firewall policies configured for the FTP service.
- #1116834
Explicit-proxy HTTPS authentication prompt is missing
The authentication pop-up did not appear for HTTPS access when proxy authentication rules, `webproxy-forward-server`, and certificate inspection were configured.
- #1202441
Captive portal unavailable after upgrade with forward server
Clients using a forward server could not reach the captive portal for internet access after a firmware upgrade.
- #1209746
FTP proxy intermittently fails through NPU VDOM link
FTP Proxy experienced intermittent connectivity through an NPU VDOM link.
- #1152839
Asymmetric ICMPv6 blocked by anti-replay
Asymmetric routing caused ICMPv6 traffic to be blocked when the original direction was NPU-offloaded but the reply direction was not.
- #1170304
NPU offload causes slow sites with oversized packets
Websites loaded slowly because packets larger than MSS generated many fragmentation-needed packets when firewall-policy NPU offload was enabled.
- #1171392
Low-TTL packets receive no response under deny-all policy
FortiGate did not respond when it received a low-TTL packet while a deny-all policy was configured.
- #1176942
IKE SAML port responds on VIP or IP pool addresses
`auth-ike-saml-port` responded on VIP or IP pool addresses when interface IP addresses did not match.
- #1187335
RTSP helper fails to rewrite destination under SNAT
Video playback was disrupted because the RTSP session helper did not rewrite the destination field when SNAT was applied.
- #1189618
NPU offload with IPS drops packets
Packets were dropped when both `auto-asic-offload` and IPS were enabled.
- #1200717
VIP port forwarding incorrectly permits local-in traffic
Traffic was allowed by local-in policy 4294967295 when a VIP used port forwarding.
- #1204026
FortiGate 900G address table limited at 20,000 entries
The firewall address table reached an unintended 20,000-entry limitation on FortiGate 900G under FortiOS 7.4.
- #1204648
Secondary SCTP session fails with different source port
A secondary SCTP session failed when an existing SCTP session used a source port different from the expected session.
- #1209080
NPU offload with egress shaping disrupts traffic
Traffic disruption occurred when `egress-shaping-profile` was enabled with NPU offload.
- #1212608
Passive FTP fails through helper session
FTP passive mode did not work through the helper session.
- #1215851
Removing EMAC VLAN loops packets to same trunk
Packets were sent back over the same trunk interface when an EMAC VLAN was removed from an EMAC-over-LAG setup.
- #1216936
NetBIOS broadcasts forwarded despite disabled setting
NetBIOS broadcast packets were forwarded on the same interface even when `netbios-forward` was disabled.
- #1218523
Hardware offload drops ICMP packets
ICMP packets were dropped when hardware offloading was enabled.
- #1211372
Confsyncd fails when file sizes change between scans
An error condition occurred in confsyncd when file sizes changed between scans.
- #1214688
Fragmented UDP-ESP packets are not forwarded
FortiGate failed to forward received fragmented UDP-ESP packets.
- #1219115
SSL VPN load balancing fails on 6K and 7K split ports
SSL VPN load balancing did not work correctly when `split-port` was set to `1-M1` and `1-M2` on FortiGate 6000 and 7000 platforms.
- #1222830
Standby FIM02 primary worker causes management loss
Management access was lost when FIM02 on the standby chassis became the primary worker.
- #1098643
Node.js and WebSocket stale-connection failures
Stale WebSocket connections caused persistent memory allocation errors or Node.js restarts.
- #1154487
GUI times out for never-expiring admin profiles
The GUI page timed out when the administrator profile used the never-timeout option.
- #1172647
Anycast makes filtering services unavailable
Filtering services became unavailable when Anycast was enabled.
- #1215061
Node.js closed-socket writes cause memory usage
Node.js writing to a closed socket caused memory-usage problems.
- #1219066
ZTNA posture tag unexpectedly enables NAT
Toggling a security posture tag in a ZTNA policy automatically enabled NAT.
- #1223404
Chromium browsers cannot save packet captures
Saving a packet capture failed in Chromium-based browsers.
- #1228733
LDAP password removed when GUI dialog is confirmed
The LDAP password was removed when the user pressed OK.
- #1033784
FGCP aggregate-member change disrupts traffic
Changing an aggregate-interface member in FGCP active-active mode disrupted traffic.
- #1042297
HA becomes out of sync after upgrade from 7.4.3
An `ips.sensor` attribute change without recalculation of the cached checksum caused HA synchronization failure after upgrading from 7.4.3.
- #1096472
Moving VDOMs between VClusters disrupts traffic
Traffic was disrupted while moving VDOMs between VClusters.
- #1141528
Azure vWAN secondary HA unit consumes high CPU
The secondary unit experienced high CPU usage when started in an Azure vWAN SD-WAN NGFW deployment with dynamic rerouting.
- #1212718
FGFM tunnel remains down after HA failover
An undestroyed FGFM session prevented creation of a new session after HA failover.
- #1217228
GCP split brain deletes route table
A split-brain condition in GCP caused route-table deletion.
- #1225919
Large FQDN packets fail to synchronize in autoscaling
Large FQDN response packets caused packet-size problems during synchronization in autoscaling environments.
- #1226672
HA EMAC VLAN member answers ARP and drops packets
A slave EMAC VLAN member responded to ARP requests in an HA setup using LACP and VLAN, resulting in packet loss.
- #1218291
Hyperscale CGNAT VDOM causes memory usage issues
CGNAT VDOM configuration caused memory-usage problems in hyperscale deployments.
- #1219541
Changing hyperscale interface VDOM disrupts traffic
Traffic was disrupted when an interface's VDOM was changed.
- #1064078
IPsec egress shaper fails across multiple NPUs
Egress shaping did not enforce bandwidth limits on VPN IDs using IPIP-encapsulated IPsec interfaces because forwarding across multiple NPUs was handled incorrectly.
- #1068626
SOC4 IPsec outbound process can become unresponsive
IPsec traffic could stop in SOC4 corner cases when the outbound process became unresponsive.
- #1075112
IKED memory growth triggers conserve mode
IKED consumed increasing memory and could force the device into conserve mode.
- #1090200
Transport-mode IPsec rejects nonzero protocol
A transport-mode IPsec phase 2 configuration could not successfully set a nonzero protocol.
- #1127782
GRE over transport-mode IPsec fails anti-spoof check
Traffic using GRE encapsulation through phase 2 transport mode was dropped by anti-spoof checking.
- #1146975
SOC4 IPsec fails with NPU offload
IPsec tunnel problems occurred on SOC4 platforms when NPU offload was enabled.
- #1170094
IKE errors occur over TCP transport
An error condition occurred in IKE when TCP transport was used.
- #1180324
IKE SAML port 10443 is lost after reboot or update
The `auth-ike-saml-port` setting was lost when configured as 10443 and the FortiGate rebooted or was updated.
- #1186237
Remote-access VPN churn causes high CPU under load
CPU utilization increased under high traffic and session load when remote-access VPN users connected or disconnected.
- #1199265
SOC4 IPsec engine hangs intermittently
IPsec tunnels became stuck and traffic was intermittently disrupted when the engine hung on SOC4.
- #1199815
IKE and kernel tunnel state become inconsistent
IPsec traffic was intermittently disrupted when IKE tunnel status became out of sync with the kernel.
- #1200709
DPDK enablement intermittently disrupts BGP
Enabling DPDK caused intermittent BGP disruption.
- #1204679
Fragmented RADIUS packets fail over IPsec
RADIUS authentication failed when packets fragmented over IPsec tunnels.
- #1206506
IPsec tunnel-manager write sequencing disrupts traffic
A write-sequence problem in the IPsec tunnel manager caused traffic disruption.
- #1218538
Changing IPsec tunnel ID drops traffic
Traffic dropped when a tunnel ID changed from a random `10.0.0.x` address to the remote gateway's public IP.
- #1077638
NGFW mode blocks established TCP sessions
FortiGate could incorrectly block packets belonging to established TCP sessions when no corresponding IPS session existed.
- #1091118
Oversized packets produce delayed ACKs
Packets exceeding the MTU caused delayed acknowledgments and unintended behavior.
- #1129130
NGFW mode intermittently disrupts legitimate sessionless traffic
Legitimate traffic that did not create a session could be disrupted in NGFW mode.
- #1140846
HTTP/2 processing triggers IPS engine errors
The IPS engine exhibited unexpected behavior while processing HTTPS traffic over HTTP/2 in certain configurations.
- #1144684
RTSP decoder causes high CPU with multiple streams
Inefficient RTSP decoder resource management caused high CPU usage while processing multiple streams.
- #1162794
SCADA dissector causes IPS engine failure
The SCADA dissector caused unintended IPS engine behavior.
- #1182461
Many HTTP/2 streams consume excessive memory
Multiple HTTP/2 connections with many open streams caused high memory usage.
- #1191598
HTTP/2 streams cause high IPS CPU usage
HTTP/2 connections containing many open streams caused high CPU usage.
- #1193876
Improper HTTP/2 stream closure leaks memory
HTTP/2 streams were not closed correctly, causing memory-usage issues.
- #1210836
IPS AnonPages growth triggers conserve mode
A gradual increase in IPS engine AnonPages memory forced the system into conserve mode.
- #1214836
Archive outbreak scanning triggers IPS error
The IPS engine encountered an error when `outbreak-prevention-archive-scan` was enabled.
- #1218008
Lua stack exhaustion causes IPS engine errors
IPS engines encountered an error when the Lua stack size was exceeded.
- #1218520
QUIC-triggered IPS error causes BFD flaps
QUIC traffic triggered an IPS engine error that caused BFD sessions to flap.
- #1162518
FortiAnalyzer connectivity lost after switching to SD-WAN
FortiGate lost connectivity with FortiAnalyzer after `interface-select-method` was changed to SD-WAN and DNS resolution failed.
- #1171020
2FA timeout omits SSL VPN authentication logs
Authentication logs were missing when two-factor authentication timed out during SSL VPN authentication.
- #1180182
HA reboot alert email fails
Alert email was not sent when the device rebooted in HA mode.
- #1124557
WAD scheduled restart configuration causes failure
WAD encountered an error when `wad-restart-mode` was `time` and `wad-restart-start-time` and `wad-restart-end-time` were configured.
- #1178184
Flow-mode DPI rejects unexpected SSL record
SSL errors occurred for a specific website because of an unexpected record type when Web Filtering and DPI were enabled in flow mode.
- #1197212
WAD prioritizes wrong CA bundle for cross-signed certificates
WAD preferred the default FortiGuard CA bundle over user-installed CAs while building chains for cross-signed server certificates.
- #1228854
SSL location conversion suppresses HTTP 302
HTTP status 302 was not forwarded to clients when `ssl-http-location-conversion` was enabled.
- #1113929
SD-WAN selects incorrect rule with fib-best-match
An incorrect SD-WAN rule was selected when `fib-best-match` was configured under a zone.
- #1162962
LAG flap disrupts BGP service
BGP service was disrupted when a LAG interface flapped.
- #1196770
BGP default route not installed with default originate capability
The BGP default route was not installed when `capability-default-originate` was enabled.
- #1197960
Top-priority QoS traffic causes BGP peer flaps
BGP peers flapped under stressful traffic on an interface configured with top-priority QoS.
Special notices
NP7 QTM fixes alter traffic-shaping architecture
QTM fixes address incorrect checksums after fragmentation, hangs from packets longer than 6000 bytes, hangs during refresh, and failure to honor MTU and fragment packets. NP7 policy, per-IP, and ordinary port shaping use TPE; interface shaping profiles, also called Multiclass Shaping (MCS), use QTM.
NP7 interface shaping profiles limited to 100 interfaces
QTM-based shaping profiles are supported on physical, LAG, and VLAN interfaces over physical or LAG links, with a maximum of 100 interfaces.