FortiOS 7.4.10 release notes

synced 2026-08-02

FortiOS 7.4.10 adds setup and LAN Edge enhancements, changes several security-sensitive defaults, revises NP7 traffic shaping behavior, and resolves issues across security inspection, networking, VPN, HA, GUI, routing, and platform components. The supplied excerpt is truncated during the SD-WAN resolved-issues section and contains no release date, build number, CVEs, upgrade-path guidance, or standalone known-issues list.

Official Fortinet release notes ↗

What's new

  • #1183975

    Setup wizard supports gateway configuration and offline licensing

    The setup wizard can configure a gateway for internet connectivity and FortiCare registration. Air-gapped deployments can upload an offline license file directly.

  • #1238520

    Seven-day pre-registration setup period

    Models requiring registration before full GUI and CLI access now permit full configuration for seven days before registration becomes mandatory.

  • #1185772

    FortiWiFi defaults hardened and simplified

    Default soft-switch interfaces and open SSIDs were removed across FortiWiFi platforms. On 4xF, 6xF, and G-series models, the default WiFi VAP remains in tunnel mode with predefined IP, DHCP, and firewall policy settings. On 8xF-2R models, VAPs use bridge mode with the hardware switch, obtain DHCP through the internal interface, and remain subject to firewall policy control.

  • #1217645

    802.1X supported on virtual switches within software switches

    802.1X can now be enabled when the software switch's `intra-switch-policy` is set to `explicit`, allowing dynamic VLAN control and traffic regulation.

Breaking changes

  • #1176942

    IKE SAML local-in matching is more restrictive

    When `auth-ike-saml-port` is used, iprope matches local-in traffic only if the destination port equals `auth-ike-saml-port` and the destination interface has `ike-saml-server` enabled.

  • #1204277

    FortiGuard auto-update schedule now defaults to daily

    The default FortiGuard package update schedule changed from automatic to daily.

  • #1207557

    Anycast VM activation uses dedicated FQDNs

    When Anycast is enabled, VM license activation uses `vmactivation1.fortinet.net`, `vmactivation2.fortinet.net`, and `vmactivation3.fortinet.net` instead of general update FQDNs. Firewall and DNS allowlists may need adjustment.

  • #1225202

    Same-interface traffic redirects are disabled by default

    The defaults for `allow-traffic-redirect` and `ipv6-allow-traffic-redirect` changed from enabled to disabled. Upgrade forcibly changes both settings to disabled even if previously enabled. Same-interface redirected traffic therefore requires an explicit firewall policy. To restore routing-only redirection, manually enable the settings. Configuration: `config system global set allow-traffic-redirect disable set ipv6-allow-traffic-redirect disable end`

  • NP7 QoS type is no longer selectable between policing and shaping

    For NP7-offloaded sessions, `default-qos-type` can only be `policing`; the previous selectable form `config system npu set default-qos-type {policing | shaping} end` is no longer available. Policy shaping, per-IP shaping, and regular port shaping use TPE policing. Interface shaping profiles use QTM shaping.

Features removed

  • NP7 default-qos-type shaping option removed

    The `shaping` value is no longer supported for `config system npu` → `set default-qos-type`; only `policing` can be configured.

Resolved issues

  • #1153880

    Large HTTP/2 uploads fail with proxy-mode antivirus

    Large file uploads over HTTP/2 failed when proxy-mode AntiVirus and deep inspection were enabled.

  • #1181573

    Flow-mode SSL inspection omits correct AKID

    SSL inspection did not correctly add the Authority Key Identifier when flow mode DPI was enabled.

  • #1205692

    FTP blocked through SOCKS5 with Application Control

    FTP traffic was blocked when Application Control was enabled over SOCKS5.

  • #1217478

    IEC 60870-5-104 detection becomes incomplete after IPS session clear

    IEC 60870-5-104 detection could become incomplete after clearing an IPS session. The stated workaround was to clear the system session.

  • #1151824

    DNS requests across VRFs discarded as retransmissions

    Queries from different VRFs with identical transaction IDs and source and destination addresses were treated as retransmissions and discarded.

  • #1086668

    FortiGate fails to connect to valid EMS Cloud VDOMs

    An expired EMS Cloud license on the global FortiCare account prevented connections even when other VDOMs had valid access keys.

  • #1207648

    Frequent TPM requests disconnect EMS Cloud

    Frequent TPM requests from httpsd caused intermittent EMS Cloud disconnections.

  • #1074353

    Explicit proxy fast fallback uses IPv4 in IPv6-only setup

    Fast fallback incorrectly used an IPv4 DNS address to connect to a server in an IPv6-only setup.

  • #1094870

    FTPS data connections fail under flow-mode FTP policies

    FTPS data connections failed with flow-mode firewall policies configured for the FTP service.

  • #1116834

    Explicit-proxy HTTPS authentication prompt is missing

    The authentication pop-up did not appear for HTTPS access when proxy authentication rules, `webproxy-forward-server`, and certificate inspection were configured.

  • #1202441

    Captive portal unavailable after upgrade with forward server

    Clients using a forward server could not reach the captive portal for internet access after a firmware upgrade.

  • #1209746

    FTP proxy intermittently fails through NPU VDOM link

    FTP Proxy experienced intermittent connectivity through an NPU VDOM link.

  • #1152839

    Asymmetric ICMPv6 blocked by anti-replay

    Asymmetric routing caused ICMPv6 traffic to be blocked when the original direction was NPU-offloaded but the reply direction was not.

  • #1170304

    NPU offload causes slow sites with oversized packets

    Websites loaded slowly because packets larger than MSS generated many fragmentation-needed packets when firewall-policy NPU offload was enabled.

  • #1171392

    Low-TTL packets receive no response under deny-all policy

    FortiGate did not respond when it received a low-TTL packet while a deny-all policy was configured.

  • #1176942

    IKE SAML port responds on VIP or IP pool addresses

    `auth-ike-saml-port` responded on VIP or IP pool addresses when interface IP addresses did not match.

  • #1187335

    RTSP helper fails to rewrite destination under SNAT

    Video playback was disrupted because the RTSP session helper did not rewrite the destination field when SNAT was applied.

  • #1189618

    NPU offload with IPS drops packets

    Packets were dropped when both `auto-asic-offload` and IPS were enabled.

  • #1200717

    VIP port forwarding incorrectly permits local-in traffic

    Traffic was allowed by local-in policy 4294967295 when a VIP used port forwarding.

  • #1204026

    FortiGate 900G address table limited at 20,000 entries

    The firewall address table reached an unintended 20,000-entry limitation on FortiGate 900G under FortiOS 7.4.

  • #1204648

    Secondary SCTP session fails with different source port

    A secondary SCTP session failed when an existing SCTP session used a source port different from the expected session.

  • #1209080

    NPU offload with egress shaping disrupts traffic

    Traffic disruption occurred when `egress-shaping-profile` was enabled with NPU offload.

  • #1212608

    Passive FTP fails through helper session

    FTP passive mode did not work through the helper session.

  • #1215851

    Removing EMAC VLAN loops packets to same trunk

    Packets were sent back over the same trunk interface when an EMAC VLAN was removed from an EMAC-over-LAG setup.

  • #1216936

    NetBIOS broadcasts forwarded despite disabled setting

    NetBIOS broadcast packets were forwarded on the same interface even when `netbios-forward` was disabled.

  • #1218523

    Hardware offload drops ICMP packets

    ICMP packets were dropped when hardware offloading was enabled.

  • #1211372

    Confsyncd fails when file sizes change between scans

    An error condition occurred in confsyncd when file sizes changed between scans.

  • #1214688

    Fragmented UDP-ESP packets are not forwarded

    FortiGate failed to forward received fragmented UDP-ESP packets.

  • #1219115

    SSL VPN load balancing fails on 6K and 7K split ports

    SSL VPN load balancing did not work correctly when `split-port` was set to `1-M1` and `1-M2` on FortiGate 6000 and 7000 platforms.

  • #1222830

    Standby FIM02 primary worker causes management loss

    Management access was lost when FIM02 on the standby chassis became the primary worker.

  • #1098643

    Node.js and WebSocket stale-connection failures

    Stale WebSocket connections caused persistent memory allocation errors or Node.js restarts.

  • #1154487

    GUI times out for never-expiring admin profiles

    The GUI page timed out when the administrator profile used the never-timeout option.

  • #1172647

    Anycast makes filtering services unavailable

    Filtering services became unavailable when Anycast was enabled.

  • #1215061

    Node.js closed-socket writes cause memory usage

    Node.js writing to a closed socket caused memory-usage problems.

  • #1219066

    ZTNA posture tag unexpectedly enables NAT

    Toggling a security posture tag in a ZTNA policy automatically enabled NAT.

  • #1223404

    Chromium browsers cannot save packet captures

    Saving a packet capture failed in Chromium-based browsers.

  • #1228733

    LDAP password removed when GUI dialog is confirmed

    The LDAP password was removed when the user pressed OK.

  • #1033784

    FGCP aggregate-member change disrupts traffic

    Changing an aggregate-interface member in FGCP active-active mode disrupted traffic.

  • #1042297

    HA becomes out of sync after upgrade from 7.4.3

    An `ips.sensor` attribute change without recalculation of the cached checksum caused HA synchronization failure after upgrading from 7.4.3.

  • #1096472

    Moving VDOMs between VClusters disrupts traffic

    Traffic was disrupted while moving VDOMs between VClusters.

  • #1141528

    Azure vWAN secondary HA unit consumes high CPU

    The secondary unit experienced high CPU usage when started in an Azure vWAN SD-WAN NGFW deployment with dynamic rerouting.

  • #1212718

    FGFM tunnel remains down after HA failover

    An undestroyed FGFM session prevented creation of a new session after HA failover.

  • #1217228

    GCP split brain deletes route table

    A split-brain condition in GCP caused route-table deletion.

  • #1225919

    Large FQDN packets fail to synchronize in autoscaling

    Large FQDN response packets caused packet-size problems during synchronization in autoscaling environments.

  • #1226672

    HA EMAC VLAN member answers ARP and drops packets

    A slave EMAC VLAN member responded to ARP requests in an HA setup using LACP and VLAN, resulting in packet loss.

  • #1218291

    Hyperscale CGNAT VDOM causes memory usage issues

    CGNAT VDOM configuration caused memory-usage problems in hyperscale deployments.

  • #1219541

    Changing hyperscale interface VDOM disrupts traffic

    Traffic was disrupted when an interface's VDOM was changed.

  • #1064078

    IPsec egress shaper fails across multiple NPUs

    Egress shaping did not enforce bandwidth limits on VPN IDs using IPIP-encapsulated IPsec interfaces because forwarding across multiple NPUs was handled incorrectly.

  • #1068626

    SOC4 IPsec outbound process can become unresponsive

    IPsec traffic could stop in SOC4 corner cases when the outbound process became unresponsive.

  • #1075112

    IKED memory growth triggers conserve mode

    IKED consumed increasing memory and could force the device into conserve mode.

  • #1090200

    Transport-mode IPsec rejects nonzero protocol

    A transport-mode IPsec phase 2 configuration could not successfully set a nonzero protocol.

  • #1127782

    GRE over transport-mode IPsec fails anti-spoof check

    Traffic using GRE encapsulation through phase 2 transport mode was dropped by anti-spoof checking.

  • #1146975

    SOC4 IPsec fails with NPU offload

    IPsec tunnel problems occurred on SOC4 platforms when NPU offload was enabled.

  • #1170094

    IKE errors occur over TCP transport

    An error condition occurred in IKE when TCP transport was used.

  • #1180324

    IKE SAML port 10443 is lost after reboot or update

    The `auth-ike-saml-port` setting was lost when configured as 10443 and the FortiGate rebooted or was updated.

  • #1186237

    Remote-access VPN churn causes high CPU under load

    CPU utilization increased under high traffic and session load when remote-access VPN users connected or disconnected.

  • #1199265

    SOC4 IPsec engine hangs intermittently

    IPsec tunnels became stuck and traffic was intermittently disrupted when the engine hung on SOC4.

  • #1199815

    IKE and kernel tunnel state become inconsistent

    IPsec traffic was intermittently disrupted when IKE tunnel status became out of sync with the kernel.

  • #1200709

    DPDK enablement intermittently disrupts BGP

    Enabling DPDK caused intermittent BGP disruption.

  • #1204679

    Fragmented RADIUS packets fail over IPsec

    RADIUS authentication failed when packets fragmented over IPsec tunnels.

  • #1206506

    IPsec tunnel-manager write sequencing disrupts traffic

    A write-sequence problem in the IPsec tunnel manager caused traffic disruption.

  • #1218538

    Changing IPsec tunnel ID drops traffic

    Traffic dropped when a tunnel ID changed from a random `10.0.0.x` address to the remote gateway's public IP.

  • #1077638

    NGFW mode blocks established TCP sessions

    FortiGate could incorrectly block packets belonging to established TCP sessions when no corresponding IPS session existed.

  • #1091118

    Oversized packets produce delayed ACKs

    Packets exceeding the MTU caused delayed acknowledgments and unintended behavior.

  • #1129130

    NGFW mode intermittently disrupts legitimate sessionless traffic

    Legitimate traffic that did not create a session could be disrupted in NGFW mode.

  • #1140846

    HTTP/2 processing triggers IPS engine errors

    The IPS engine exhibited unexpected behavior while processing HTTPS traffic over HTTP/2 in certain configurations.

  • #1144684

    RTSP decoder causes high CPU with multiple streams

    Inefficient RTSP decoder resource management caused high CPU usage while processing multiple streams.

  • #1162794

    SCADA dissector causes IPS engine failure

    The SCADA dissector caused unintended IPS engine behavior.

  • #1182461

    Many HTTP/2 streams consume excessive memory

    Multiple HTTP/2 connections with many open streams caused high memory usage.

  • #1191598

    HTTP/2 streams cause high IPS CPU usage

    HTTP/2 connections containing many open streams caused high CPU usage.

  • #1193876

    Improper HTTP/2 stream closure leaks memory

    HTTP/2 streams were not closed correctly, causing memory-usage issues.

  • #1210836

    IPS AnonPages growth triggers conserve mode

    A gradual increase in IPS engine AnonPages memory forced the system into conserve mode.

  • #1214836

    Archive outbreak scanning triggers IPS error

    The IPS engine encountered an error when `outbreak-prevention-archive-scan` was enabled.

  • #1218008

    Lua stack exhaustion causes IPS engine errors

    IPS engines encountered an error when the Lua stack size was exceeded.

  • #1218520

    QUIC-triggered IPS error causes BFD flaps

    QUIC traffic triggered an IPS engine error that caused BFD sessions to flap.

  • #1162518

    FortiAnalyzer connectivity lost after switching to SD-WAN

    FortiGate lost connectivity with FortiAnalyzer after `interface-select-method` was changed to SD-WAN and DNS resolution failed.

  • #1171020

    2FA timeout omits SSL VPN authentication logs

    Authentication logs were missing when two-factor authentication timed out during SSL VPN authentication.

  • #1180182

    HA reboot alert email fails

    Alert email was not sent when the device rebooted in HA mode.

  • #1124557

    WAD scheduled restart configuration causes failure

    WAD encountered an error when `wad-restart-mode` was `time` and `wad-restart-start-time` and `wad-restart-end-time` were configured.

  • #1178184

    Flow-mode DPI rejects unexpected SSL record

    SSL errors occurred for a specific website because of an unexpected record type when Web Filtering and DPI were enabled in flow mode.

  • #1197212

    WAD prioritizes wrong CA bundle for cross-signed certificates

    WAD preferred the default FortiGuard CA bundle over user-installed CAs while building chains for cross-signed server certificates.

  • #1228854

    SSL location conversion suppresses HTTP 302

    HTTP status 302 was not forwarded to clients when `ssl-http-location-conversion` was enabled.

  • #1113929

    SD-WAN selects incorrect rule with fib-best-match

    An incorrect SD-WAN rule was selected when `fib-best-match` was configured under a zone.

  • #1162962

    LAG flap disrupts BGP service

    BGP service was disrupted when a LAG interface flapped.

  • #1196770

    BGP default route not installed with default originate capability

    The BGP default route was not installed when `capability-default-originate` was enabled.

  • #1197960

    Top-priority QoS traffic causes BGP peer flaps

    BGP peers flapped under stressful traffic on an interface configured with top-priority QoS.

Special notices

  • NP7 QTM fixes alter traffic-shaping architecture

    QTM fixes address incorrect checksums after fragmentation, hangs from packets longer than 6000 bytes, hangs during refresh, and failure to honor MTU and fragment packets. NP7 policy, per-IP, and ordinary port shaping use TPE; interface shaping profiles, also called Multiclass Shaping (MCS), use QTM.

  • NP7 interface shaping profiles limited to 100 interfaces

    QTM-based shaping profiles are supported on physical, LAG, and VLAN interfaces over physical or LAG links, with a maximum of 100 interfaces.