FortiOS 7.4.12 release notes
FortiOS 7.4.12 adds registration-aware firmware controls and improved upgrade automation, changes NGFW fail-closed behavior and pre-registration CLI access, revises NP7 traffic shaping behavior, and resolves issues across firewall, HA, VPN, IPS, proxy, system, authentication, VM, and other components.
Official Fortinet release notes ↗What's new
- #1260021
Manual firmware changes during initial setup
During the 7-day setup period, administrators can manually upgrade or downgrade through the GUI or CLI. After that period, device registration is required.
- #1250003
New firmware-upgrade automation workflow
Adds the default automation stitch Firmware Upgrade Complete, trigger Auto Firmware Upgrade Complete, and action Auto Upgrade Complete Email Notification. Firmware-upgrade email wording is clearer, and the former Firmware Upgrade Notification default stitch is disabled.
- #1127168
Improved extension-device upgrade prompts and reporting
Administrators can dismiss selected firmware-upgrade prompts for extension devices. Distinct log IDs identify automatic versus manual upgrades, email alerts provide detailed status, and the login GUI requests confirmation of the auto-upgrade preference after auto-upgrade is disabled and an update is performed.
- #1256067
ForcedUpdate support in FortiGuard communication
FCPC accepts a ForcedUpdate flag and major.minor.patch-build version information. If a FortiGate firmware license is invalid, FortiGuard can ignore the license check and allow an upgrade when the source and target firmware share the same major and minor version. Logs, notifications, and automation stitches more clearly identify automatic and required upgrades.
Breaking changes
- #1240706
NGFW policy mode now fails closed without IPS sockets
NGFW policy-mode VDOMs now drop traffic when IPS sockets are unavailable, including during startup, IPS engine upgrades, or manual IPS shutdown, instead of potentially bypassing inspection.
- #1245249
More CLI configuration allowed before registration
Pre-registration access now includes `config firewall policy`, `config router setting`, `config router static`, `config router static6`, `config system admin`, `config system central-management`, `config system dns`, `config system interface`, `config system pppoe-interface`, and `config system settings` to support central management, ZTP, and LTP.
NP7 QoS selection is no longer configurable between policing and shaping
For NP7-offloaded sessions, `config system npu` with `set default-qos-type {policing | shaping}` can no longer select shaping; `default-qos-type` can only be set to `policing`. Policy, per-IP, and regular port shaping use TPE, while interface shaping profiles use QTM.
Resolved issues
- #1156066
Application control failure over EMAC VLAN interfaces
Communication no longer breaks when application control is used in a policy over EMAC VLAN interfaces.
- #1260248
Protocol Enforcement did not block DNS over TCP
Protocol Enforcement now blocks applicable DNS-over-TCP traffic when non-DNS TCP traffic uses port 53.
- #1243152
Incorrect EDNS cookies for cached DNS entries
Corrects client and server cookies returned for cached entries with conditional forwarding and EDNS cookies.
- #1254680
DNS-over-TLS failure on FortiGate 201E
Fixes DNS-over-TLS failure on FortiGate 201E running FortiOS 7.4.10.
- #1076355
WAD error with multiple upstream responses
Corrects an error condition while WAD handles multiple responses from an upstream server.
- #1247518
HTTP 303 redirect loop with SWG SSO
Fixes an HTTP 303 redirect loop when accessing websites through an SWG SSO connection.
- #1257127
Explicit-proxy video-filter request handling
Corrects unexpected behavior when video filtering is enabled and multiple requests target the same video ID.
- #1272260
WAD error handling 100 Continue and 200 OK
Corrects an error condition while handling server responses containing 100 Continue and 200 OK status codes.
- #1279480
High CPU from large-scale SWG SAML authentication
Resolves CPU usage issues caused by SAML authentication with SWG and many users.
- #1219051
MSI files not blocked in flow mode
File filtering now blocks applicable MSI downloads in flow mode.
- #1157120
GRE offload failure with zero tunnel key
Fixes traffic failure when GRE pass-through uses a tunnel key of zero during offload.
- #1240706
Traffic bypass while IPS engine unavailable
Fixes possible traffic bypass in NGFW policy-based mode while the IPS engine is unavailable.
- #1256278
SoC5 packet loss with ingress shaping
Fixes packet loss when ASIC offloading is enabled on SoC5 models with an ingress shaping profile.
- #1253034
Incorrect VLAN counters with fastpath disabled
VLAN interfaces no longer show zero receive/transmit bytes and packets when fastpath is disabled on FortiGate 6000/7000 platforms.
- #1272827
FGT7081F forwarding failure after HA failover
Fixes traffic forwarding failure when the primary FPM does not send GARP to the connected switch after failover.
- #1274545
Both HA nodes responding to ARP
Prevents both nodes from responding to ARP requests after the HA table is edited under `config system ha`.
- #1278206
HTTPS GUI failure with Low Encryption license
Restores HTTPS GUI access after upgrading to FortiOS 7.4.11 when using a Low Encryption license.
- #1216459
HA upgrade verification failure at High BIOS security
Fixes verification failure during HA image upgrade when BIOS security level is High.
- #1220647
HA-port RX drops after i40e driver upgrade
Corrects RX drops on HA1 and HA2 ports after upgrading the i40e driver.
- #1221816
Network instability after primary FIM reboot
Fixes instability when the primary FIM is rebooted after failover using `diagnose sys ha reset-uptime`.
- #1235313
Traffic disruption after upgrade failover
Fixes disruption when many firewall policies are installed after failover during a cluster upgrade.
- #1237317
No receive traffic with unicast heartbeat and SR-IOV
Restores receive traffic when unicast heartbeat is enabled on FortiGate-VM64 with SR-IOV.
- #1240288
Secondary sends packets with cluster MAC after failover
Corrects packets sent by the secondary member with the cluster MAC address after failover.
- #1244944
HA heartbeat loss from unrestricted highest priority
Fixes heartbeat loss when highest priority is not restricted to heartbeat, routing, and LACP traffic.
- #1271901
Azure SDN token reuse after HA failover
Fixes authentication failures caused by Azure SDN connectors reusing incorrect tenant tokens after failover.
- #1275737
HA VM license warning with virtual clustering
Fixes License Status: Warning when the root VDOM is active on the primary of a FortiGate-VM HA active-passive cluster using VDOMs and virtual clustering.
- #1245165
Hyperscale drops ICMPv6 Packet Too Big
Fixes dropped ICMPv6 type 2 packets when SIP ALG and Hyperscale are enabled.
- #1201212
IPsec reply traffic dropped by anti-spoofing
Fixes reply traffic drops when the anti-spoof check fails.
- #1209759
IKEv2 ASN1DN validation with multiple OU fields
Fixes IKEv2 connection failure with a gw validation failed error when the peer ASN1DN ID has multiple OU fields.
- #1211532
IPsec selector mismatch triggers anti-spoof drop
Fixes traffic drops caused by mismatched source IP and selector range.
- #1218530
Duo Proxy LDAP MFA error
Corrects an error condition when Duo Proxy LDAP is used with MFA.
- #1229448
IKEv2 peer selection with AES256GCM proposals
Fixes peer-selection failure with AES256GCM-PRFSHAxxx encryption proposals.
- #1246635
IPsec Phase 2 rekey deletes incorrect CHILD-SA
Fixes tunnel disruption when rekey completes with deletion of the wrong CHILD-SA.
- #1257646
High CPU from IPsec-over-TCP RST
Fixes high CPU usage when IPsec over TCP receives an RST packet.
- #1264833
SAML IPsec failure over tunnel SSID
Fixes SAML IPsec VPN connection failure when the client is connected through a Wi-Fi Tunnel SSID.
- #983372
IPS engine error accessing Google Safe Browsing
Corrects an IPS engine error when accessing safebrowsing.google.com.
- #1040242
Inline IPS YouTube channel blocking failure
Fixes channel-page blocking when an inline IPS video-filter profile contains both channel and category settings.
- #1116920
IPS engine error upgrading from 7.0.8 to 7.4.6
Corrects an IPS engine error encountered on this upgrade path.
- #1157469
Traffic outage when disabling nTurbo
Existing sessions are now marked appropriately to prevent an outage when nTurbo acceleration is disabled.
- #1197659
IPS engine error processing HTTP traffic
Corrects an IPS engine error during HTTP processing.
- #1249177
High IPS CPU while scanning SMB
Resolves high CPU usage during SMB traffic scanning.
- #1259235
IPS engine error during 7.4.11 upgrade
Corrects an ipsengine error encountered during upgrade to FortiOS 7.4.11.
- #1263949
IPS error switching packet-layer modes
Corrects an IPS engine error when switching packet-layer modes.
- #1269354
IPS error with unusual TLS 1.3 stacks
Corrects an IPS engine error while handling unusual TLS 1.3 stacks.
- #1273729
IPS error under high application-traffic volume
Corrects an IPS error when handling high volumes of application traffic.
- #1278367
IPS engine CPU usage issue
Resolves excessive CPU usage during ipsengine operation.
- #1240481
IPS packet logs not removed by retention policy
IPS log-packet files are now cleaned up when retention exceeds maximum-log-age.
- #1266492
Secondary HA logs missing from FortiAnalyzer Cloud
Restores secondary-unit logs for HA clusters running FortiOS 7.4.9 and later.
- #1272019
GeoIP database update error
Corrects an error condition in the GeoIP database during updates.
- #1171499
SSL inspection omitted certificate chain
Restores certificate-chain transmission during SSL inspection after upgrade.
- #1189141
WAD error with large query responses
Corrects an error condition while WAD handles large query responses.
- #1211374
HTTP/2 VIP memory growth with HTTP/1.1 server
Fixes high memory usage when HTTP/2 is enabled on a firewall VIP whose real server supports only HTTP/1.1.
- #1245569
HTTP virtual server empty response for large pageSize
Fixes empty responses when pageSize exceeds 105 on a FortiGate HTTPS virtual server.
- #1257158
WAD proxy web-filter SSL stress error
Corrects a WAD error during proxy web-filter SSL stress tests.
- #1151848
IPv6 BGP flap with Dell Sonic peer
Fixes IPv6 BGP flapping when a FortiGate FGSP cluster connects to Dell Sonic.
- #1243609
BGP flapping during external-route redistribution
Fixes route flapping when external routes are redistributed into BGP.
- #1203917
SD-WAN interface incorrectly reports Unknown
The interface status no longer becomes Unknown while the health-check SLA is good.
- #1214345
SSL-VPN high memory usage with multiple VDOMs
Fixes high memory usage in multi-VDOM SSL-VPN deployments.
- #1216477
SSL-VPN blocked addresses cleared too early
Prevents blocked IP addresses from being cleared before login-block-time expires when VDOMs have different settings.
- #1240901
SSL-VPN HTTP/1.0 PCI scan failure
Fixes PCI scanning on the SSL-VPN port when HTTP/1.0 is used.
- #1241533
SSL-VPN daemon error with policy schedules
Corrects an sslvpnd error while handling firewall policy schedules during peer-user authentication.
- #1272207
SSL-VPN concatenated username and OTP failure
Fixes authentication failure on FortiOS 7.4.11 when username and OTP are concatenated.
- #1232304
FortiSwitches offline after 7.2.10 upgrade
Fixes managed FortiSwitches going offline when FortiGate is upgraded from 7.2.10 to 7.4.x.
- #1269920
FortiSwitch firmware download from FortiGuard fails
Fixes firmware download failure when one firewall attempts to obtain FortiSwitch firmware from FortiGuard.
- #1160683
CAPWAP fragments dropped on virtual switch
Fixes Windows Wi-Fi clients failing to obtain DHCP addresses because fragmented CAPWAP packets were dropped.
- #1214384
IPv6 processing with invalid destination entries
Corrects unexpected FortiGate behavior while processing IPv6 traffic with invalid destination entries.
- #1232383
Kernel error under VXLAN multicast stress
Corrects unexpected kernel behavior under stressful multicast traffic through VXLAN in a switch interface.
- #1246914
Kernel error forwarding NAF ICMP errors
Corrects unexpected kernel behavior when forwarding ICMP error messages from NAF devices.
- #1260308
High memory use during SYN flood detection
Fixes high memory usage when SYN flood attack behavior is detected.
- #1263001
WWAN IPsec instability on FortiGate 51G
Fixes dial-up IPsec instability after upgrading from 7.4.9 to 7.4.11.
- #1264495
FGT200G and FGT201G throughput drops to zero
Fixes zero throughput during netperf testing caused by enabled 1G SFP autonegotiation.
- #1265180
FortiCarrier logging memory issue
Fixes memory usage caused by logging on FortiCarrier-4400F.
- #1268947
High CPU editing VLANs in web UI
Fixes high CPU usage when creating or editing a VLAN interface through the GUI.
- #1135049
Database update race after FortiOS upgrade
Fixes an update-daemon error caused by updating databases while CMDB is still loading its JSON file.
- #1252663
D-series serial number corruption after upgrade
Prevents the serial number changing to FGT0000000000001 on D-series devices with older BIOS when upgrading to 7.4.10, 7.4.11, 7.6.5, or 7.6.6.
- #1256067
Required auto-upgrade failure on unlicensed devices
Fixes required automatic upgrades that may fail on unlicensed or end-of-support devices.
- #1215197
FNBAMD errors following multiple AIA links
Fixes errors while downloading intermediate CAs through multiple Authority Information Access links.
- #1218458
Hardware-token activation blocked by CMDB permissions
Fixes hardware token activation failure when CMDB write permission is enforced.
- #1228793
CMPv2 auto-enrollment with intermediate CA fails
Fixes certificate auto-enrollment through CMPv2 using an intermediate CA certificate after upgrade.
- #1237504
FNBAMD error with multi-address DNS responses
Corrects an fnbamd error when DNS responses contain multiple IP addresses.
- #1253914
TACACS+ accounting logs missing per VDOM
Restores accounting logs when the TACACS+ accounting server uses per-VDOM interfaces.
- #1257281
OpenLDAP TLS 1.3 negotiation with PQC parameters
Fixes LDAPS negotiation failure when FortiGate connects to OpenLDAP using TLS 1.3 and PQC parameters.
- #1259154
Authentication failure during certificate rotation
Fixes authentication failure when certificate rotation occurs on a standalone HA primary FortiGate.
- #1244347
Azure trusted-launch validation failure
Fixes trusted launch failure for FGT_VM64_AZURE.
- #1245936
FortiManager IPv6 VM license validation failure
Fixes FortiGate-VM license validation through FortiManager using an IPv6 address.
- #1260183
Unexpected VM license validation in air-gapped AWS
Corrects license-validation behavior when FortiGate connects to FortiManager in an air-gapped AWS environment.
- #1260751
KVM boot failure upgrading from 7.2.12
Fixes FortiGate KVM boot failure after upgrading from 7.2.12 to 7.4.11.
- #1274753
Secondary VM license warning after upgrade
Fixes a license-status warning when the secondary validates its VM license after upgrading to 7.4.10 or 7.4.11.
- #1261505
YouTube video-filter failure after API update
Restores effective video blocking after a YouTube API change.
- #1268027
YouTube main-page channel blocking issue
Fixes video blocking from the YouTube main page when channel filters are used.
Special notices
NP7 QTM defects corrected
Fixes incorrect fragment checksums after QTM, hangs caused by packets longer than 6000 bytes, hangs during refresh, and failure to honor MTU and fragment packets after QTM.
NP7 shaping-module assignment
Policy traffic shaping, per-IP shaping, and regular port shaping with outbandwidth but no shaping profile always use TPE. Interface shaping profiles, also called Multiclass Shaping, use QTM on physical, LAG, or VLAN interfaces. At most 100 interfaces can have shaping profiles.