FortiOS 7.4.12 release notes

synced 2026-07-31

FortiOS 7.4.12 adds registration-aware firmware controls and improved upgrade automation, changes NGFW fail-closed behavior and pre-registration CLI access, revises NP7 traffic shaping behavior, and resolves issues across firewall, HA, VPN, IPS, proxy, system, authentication, VM, and other components.

Official Fortinet release notes ↗

What's new

  • #1260021

    Manual firmware changes during initial setup

    During the 7-day setup period, administrators can manually upgrade or downgrade through the GUI or CLI. After that period, device registration is required.

  • #1250003

    New firmware-upgrade automation workflow

    Adds the default automation stitch Firmware Upgrade Complete, trigger Auto Firmware Upgrade Complete, and action Auto Upgrade Complete Email Notification. Firmware-upgrade email wording is clearer, and the former Firmware Upgrade Notification default stitch is disabled.

  • #1127168

    Improved extension-device upgrade prompts and reporting

    Administrators can dismiss selected firmware-upgrade prompts for extension devices. Distinct log IDs identify automatic versus manual upgrades, email alerts provide detailed status, and the login GUI requests confirmation of the auto-upgrade preference after auto-upgrade is disabled and an update is performed.

  • #1256067

    ForcedUpdate support in FortiGuard communication

    FCPC accepts a ForcedUpdate flag and major.minor.patch-build version information. If a FortiGate firmware license is invalid, FortiGuard can ignore the license check and allow an upgrade when the source and target firmware share the same major and minor version. Logs, notifications, and automation stitches more clearly identify automatic and required upgrades.

Breaking changes

  • #1240706

    NGFW policy mode now fails closed without IPS sockets

    NGFW policy-mode VDOMs now drop traffic when IPS sockets are unavailable, including during startup, IPS engine upgrades, or manual IPS shutdown, instead of potentially bypassing inspection.

  • #1245249

    More CLI configuration allowed before registration

    Pre-registration access now includes `config firewall policy`, `config router setting`, `config router static`, `config router static6`, `config system admin`, `config system central-management`, `config system dns`, `config system interface`, `config system pppoe-interface`, and `config system settings` to support central management, ZTP, and LTP.

  • NP7 QoS selection is no longer configurable between policing and shaping

    For NP7-offloaded sessions, `config system npu` with `set default-qos-type {policing | shaping}` can no longer select shaping; `default-qos-type` can only be set to `policing`. Policy, per-IP, and regular port shaping use TPE, while interface shaping profiles use QTM.

Resolved issues

  • #1156066

    Application control failure over EMAC VLAN interfaces

    Communication no longer breaks when application control is used in a policy over EMAC VLAN interfaces.

  • #1260248

    Protocol Enforcement did not block DNS over TCP

    Protocol Enforcement now blocks applicable DNS-over-TCP traffic when non-DNS TCP traffic uses port 53.

  • #1243152

    Incorrect EDNS cookies for cached DNS entries

    Corrects client and server cookies returned for cached entries with conditional forwarding and EDNS cookies.

  • #1254680

    DNS-over-TLS failure on FortiGate 201E

    Fixes DNS-over-TLS failure on FortiGate 201E running FortiOS 7.4.10.

  • #1076355

    WAD error with multiple upstream responses

    Corrects an error condition while WAD handles multiple responses from an upstream server.

  • #1247518

    HTTP 303 redirect loop with SWG SSO

    Fixes an HTTP 303 redirect loop when accessing websites through an SWG SSO connection.

  • #1257127

    Explicit-proxy video-filter request handling

    Corrects unexpected behavior when video filtering is enabled and multiple requests target the same video ID.

  • #1272260

    WAD error handling 100 Continue and 200 OK

    Corrects an error condition while handling server responses containing 100 Continue and 200 OK status codes.

  • #1279480

    High CPU from large-scale SWG SAML authentication

    Resolves CPU usage issues caused by SAML authentication with SWG and many users.

  • #1219051

    MSI files not blocked in flow mode

    File filtering now blocks applicable MSI downloads in flow mode.

  • #1157120

    GRE offload failure with zero tunnel key

    Fixes traffic failure when GRE pass-through uses a tunnel key of zero during offload.

  • #1240706

    Traffic bypass while IPS engine unavailable

    Fixes possible traffic bypass in NGFW policy-based mode while the IPS engine is unavailable.

  • #1256278

    SoC5 packet loss with ingress shaping

    Fixes packet loss when ASIC offloading is enabled on SoC5 models with an ingress shaping profile.

  • #1253034

    Incorrect VLAN counters with fastpath disabled

    VLAN interfaces no longer show zero receive/transmit bytes and packets when fastpath is disabled on FortiGate 6000/7000 platforms.

  • #1272827

    FGT7081F forwarding failure after HA failover

    Fixes traffic forwarding failure when the primary FPM does not send GARP to the connected switch after failover.

  • #1274545

    Both HA nodes responding to ARP

    Prevents both nodes from responding to ARP requests after the HA table is edited under `config system ha`.

  • #1278206

    HTTPS GUI failure with Low Encryption license

    Restores HTTPS GUI access after upgrading to FortiOS 7.4.11 when using a Low Encryption license.

  • #1216459

    HA upgrade verification failure at High BIOS security

    Fixes verification failure during HA image upgrade when BIOS security level is High.

  • #1220647

    HA-port RX drops after i40e driver upgrade

    Corrects RX drops on HA1 and HA2 ports after upgrading the i40e driver.

  • #1221816

    Network instability after primary FIM reboot

    Fixes instability when the primary FIM is rebooted after failover using `diagnose sys ha reset-uptime`.

  • #1235313

    Traffic disruption after upgrade failover

    Fixes disruption when many firewall policies are installed after failover during a cluster upgrade.

  • #1237317

    No receive traffic with unicast heartbeat and SR-IOV

    Restores receive traffic when unicast heartbeat is enabled on FortiGate-VM64 with SR-IOV.

  • #1240288

    Secondary sends packets with cluster MAC after failover

    Corrects packets sent by the secondary member with the cluster MAC address after failover.

  • #1244944

    HA heartbeat loss from unrestricted highest priority

    Fixes heartbeat loss when highest priority is not restricted to heartbeat, routing, and LACP traffic.

  • #1271901

    Azure SDN token reuse after HA failover

    Fixes authentication failures caused by Azure SDN connectors reusing incorrect tenant tokens after failover.

  • #1275737

    HA VM license warning with virtual clustering

    Fixes License Status: Warning when the root VDOM is active on the primary of a FortiGate-VM HA active-passive cluster using VDOMs and virtual clustering.

  • #1245165

    Hyperscale drops ICMPv6 Packet Too Big

    Fixes dropped ICMPv6 type 2 packets when SIP ALG and Hyperscale are enabled.

  • #1201212

    IPsec reply traffic dropped by anti-spoofing

    Fixes reply traffic drops when the anti-spoof check fails.

  • #1209759

    IKEv2 ASN1DN validation with multiple OU fields

    Fixes IKEv2 connection failure with a gw validation failed error when the peer ASN1DN ID has multiple OU fields.

  • #1211532

    IPsec selector mismatch triggers anti-spoof drop

    Fixes traffic drops caused by mismatched source IP and selector range.

  • #1218530

    Duo Proxy LDAP MFA error

    Corrects an error condition when Duo Proxy LDAP is used with MFA.

  • #1229448

    IKEv2 peer selection with AES256GCM proposals

    Fixes peer-selection failure with AES256GCM-PRFSHAxxx encryption proposals.

  • #1246635

    IPsec Phase 2 rekey deletes incorrect CHILD-SA

    Fixes tunnel disruption when rekey completes with deletion of the wrong CHILD-SA.

  • #1257646

    High CPU from IPsec-over-TCP RST

    Fixes high CPU usage when IPsec over TCP receives an RST packet.

  • #1264833

    SAML IPsec failure over tunnel SSID

    Fixes SAML IPsec VPN connection failure when the client is connected through a Wi-Fi Tunnel SSID.

  • #983372

    IPS engine error accessing Google Safe Browsing

    Corrects an IPS engine error when accessing safebrowsing.google.com.

  • #1040242

    Inline IPS YouTube channel blocking failure

    Fixes channel-page blocking when an inline IPS video-filter profile contains both channel and category settings.

  • #1116920

    IPS engine error upgrading from 7.0.8 to 7.4.6

    Corrects an IPS engine error encountered on this upgrade path.

  • #1157469

    Traffic outage when disabling nTurbo

    Existing sessions are now marked appropriately to prevent an outage when nTurbo acceleration is disabled.

  • #1197659

    IPS engine error processing HTTP traffic

    Corrects an IPS engine error during HTTP processing.

  • #1249177

    High IPS CPU while scanning SMB

    Resolves high CPU usage during SMB traffic scanning.

  • #1259235

    IPS engine error during 7.4.11 upgrade

    Corrects an ipsengine error encountered during upgrade to FortiOS 7.4.11.

  • #1263949

    IPS error switching packet-layer modes

    Corrects an IPS engine error when switching packet-layer modes.

  • #1269354

    IPS error with unusual TLS 1.3 stacks

    Corrects an IPS engine error while handling unusual TLS 1.3 stacks.

  • #1273729

    IPS error under high application-traffic volume

    Corrects an IPS error when handling high volumes of application traffic.

  • #1278367

    IPS engine CPU usage issue

    Resolves excessive CPU usage during ipsengine operation.

  • #1240481

    IPS packet logs not removed by retention policy

    IPS log-packet files are now cleaned up when retention exceeds maximum-log-age.

  • #1266492

    Secondary HA logs missing from FortiAnalyzer Cloud

    Restores secondary-unit logs for HA clusters running FortiOS 7.4.9 and later.

  • #1272019

    GeoIP database update error

    Corrects an error condition in the GeoIP database during updates.

  • #1171499

    SSL inspection omitted certificate chain

    Restores certificate-chain transmission during SSL inspection after upgrade.

  • #1189141

    WAD error with large query responses

    Corrects an error condition while WAD handles large query responses.

  • #1211374

    HTTP/2 VIP memory growth with HTTP/1.1 server

    Fixes high memory usage when HTTP/2 is enabled on a firewall VIP whose real server supports only HTTP/1.1.

  • #1245569

    HTTP virtual server empty response for large pageSize

    Fixes empty responses when pageSize exceeds 105 on a FortiGate HTTPS virtual server.

  • #1257158

    WAD proxy web-filter SSL stress error

    Corrects a WAD error during proxy web-filter SSL stress tests.

  • #1151848

    IPv6 BGP flap with Dell Sonic peer

    Fixes IPv6 BGP flapping when a FortiGate FGSP cluster connects to Dell Sonic.

  • #1243609

    BGP flapping during external-route redistribution

    Fixes route flapping when external routes are redistributed into BGP.

  • #1203917

    SD-WAN interface incorrectly reports Unknown

    The interface status no longer becomes Unknown while the health-check SLA is good.

  • #1214345

    SSL-VPN high memory usage with multiple VDOMs

    Fixes high memory usage in multi-VDOM SSL-VPN deployments.

  • #1216477

    SSL-VPN blocked addresses cleared too early

    Prevents blocked IP addresses from being cleared before login-block-time expires when VDOMs have different settings.

  • #1240901

    SSL-VPN HTTP/1.0 PCI scan failure

    Fixes PCI scanning on the SSL-VPN port when HTTP/1.0 is used.

  • #1241533

    SSL-VPN daemon error with policy schedules

    Corrects an sslvpnd error while handling firewall policy schedules during peer-user authentication.

  • #1272207

    SSL-VPN concatenated username and OTP failure

    Fixes authentication failure on FortiOS 7.4.11 when username and OTP are concatenated.

  • #1232304

    FortiSwitches offline after 7.2.10 upgrade

    Fixes managed FortiSwitches going offline when FortiGate is upgraded from 7.2.10 to 7.4.x.

  • #1269920

    FortiSwitch firmware download from FortiGuard fails

    Fixes firmware download failure when one firewall attempts to obtain FortiSwitch firmware from FortiGuard.

  • #1160683

    CAPWAP fragments dropped on virtual switch

    Fixes Windows Wi-Fi clients failing to obtain DHCP addresses because fragmented CAPWAP packets were dropped.

  • #1214384

    IPv6 processing with invalid destination entries

    Corrects unexpected FortiGate behavior while processing IPv6 traffic with invalid destination entries.

  • #1232383

    Kernel error under VXLAN multicast stress

    Corrects unexpected kernel behavior under stressful multicast traffic through VXLAN in a switch interface.

  • #1246914

    Kernel error forwarding NAF ICMP errors

    Corrects unexpected kernel behavior when forwarding ICMP error messages from NAF devices.

  • #1260308

    High memory use during SYN flood detection

    Fixes high memory usage when SYN flood attack behavior is detected.

  • #1263001

    WWAN IPsec instability on FortiGate 51G

    Fixes dial-up IPsec instability after upgrading from 7.4.9 to 7.4.11.

  • #1264495

    FGT200G and FGT201G throughput drops to zero

    Fixes zero throughput during netperf testing caused by enabled 1G SFP autonegotiation.

  • #1265180

    FortiCarrier logging memory issue

    Fixes memory usage caused by logging on FortiCarrier-4400F.

  • #1268947

    High CPU editing VLANs in web UI

    Fixes high CPU usage when creating or editing a VLAN interface through the GUI.

  • #1135049

    Database update race after FortiOS upgrade

    Fixes an update-daemon error caused by updating databases while CMDB is still loading its JSON file.

  • #1252663

    D-series serial number corruption after upgrade

    Prevents the serial number changing to FGT0000000000001 on D-series devices with older BIOS when upgrading to 7.4.10, 7.4.11, 7.6.5, or 7.6.6.

  • #1256067

    Required auto-upgrade failure on unlicensed devices

    Fixes required automatic upgrades that may fail on unlicensed or end-of-support devices.

  • #1215197

    FNBAMD errors following multiple AIA links

    Fixes errors while downloading intermediate CAs through multiple Authority Information Access links.

  • #1218458

    Hardware-token activation blocked by CMDB permissions

    Fixes hardware token activation failure when CMDB write permission is enforced.

  • #1228793

    CMPv2 auto-enrollment with intermediate CA fails

    Fixes certificate auto-enrollment through CMPv2 using an intermediate CA certificate after upgrade.

  • #1237504

    FNBAMD error with multi-address DNS responses

    Corrects an fnbamd error when DNS responses contain multiple IP addresses.

  • #1253914

    TACACS+ accounting logs missing per VDOM

    Restores accounting logs when the TACACS+ accounting server uses per-VDOM interfaces.

  • #1257281

    OpenLDAP TLS 1.3 negotiation with PQC parameters

    Fixes LDAPS negotiation failure when FortiGate connects to OpenLDAP using TLS 1.3 and PQC parameters.

  • #1259154

    Authentication failure during certificate rotation

    Fixes authentication failure when certificate rotation occurs on a standalone HA primary FortiGate.

  • #1244347

    Azure trusted-launch validation failure

    Fixes trusted launch failure for FGT_VM64_AZURE.

  • #1245936

    FortiManager IPv6 VM license validation failure

    Fixes FortiGate-VM license validation through FortiManager using an IPv6 address.

  • #1260183

    Unexpected VM license validation in air-gapped AWS

    Corrects license-validation behavior when FortiGate connects to FortiManager in an air-gapped AWS environment.

  • #1260751

    KVM boot failure upgrading from 7.2.12

    Fixes FortiGate KVM boot failure after upgrading from 7.2.12 to 7.4.11.

  • #1274753

    Secondary VM license warning after upgrade

    Fixes a license-status warning when the secondary validates its VM license after upgrading to 7.4.10 or 7.4.11.

  • #1261505

    YouTube video-filter failure after API update

    Restores effective video blocking after a YouTube API change.

  • #1268027

    YouTube main-page channel blocking issue

    Fixes video blocking from the YouTube main page when channel filters are used.

Special notices

  • NP7 QTM defects corrected

    Fixes incorrect fragment checksums after QTM, hangs caused by packets longer than 6000 bytes, hangs during refresh, and failure to honor MTU and fragment packets after QTM.

  • NP7 shaping-module assignment

    Policy traffic shaping, per-IP shaping, and regular port shaping with outbandwidth but no shaping profile always use TPE. Interface shaping profiles, also called Multiclass Shaping, use QTM on physical, LAG, or VLAN interfaces. At most 100 interfaces can have shaping profiles.