FortiOS 7.4.8 release notes

build 2795synced 2026-07-31

FortiOS 7.4.8 build 2795 release information and supported-platform notes. The supplied content contains supported models and open issues, but no new-feature, security-fix, or resolved-issue sections.

Official Fortinet release notes ↗

Upgrade notes

  • FortiOS 7.4.8 base build

    The release is FortiOS 7.4.8 build 2795.

  • Supported FortiGate models

    FG-40F, FG-40F-3G4G, FG-50G, FG-50G-5G, FG-50G-DSL, FG-50G-SFP, FG-50G-SFP-POE, FG-51G, FG-51G-5G, FG-51G-SFP-POE, FG-60E, FG-60E-DSL, FG-60E-DSLJ, FG-60E-POE, FG-60F, FG-61E, FG-61F, FG-70F, FG-71F, FG-80E, FG-80E-POE, FG-80F, FG-80F-BP, FG-80F-DSL, FG-80F-POE, FG-81E, FG-81E-POE, FG-81F, FG-81F-POE, FG-90E, FG-91E, FG-90G, FG-91G, FG-100F, FG-101F, FG-120G, FG-121G, FG-140E, FG-140E-POE, FG-200E, FG-200F, FG-201E, FG-201F, FG-200G, FG-201G, FG-300E, FG-301E, FG-400E, FG-400E-BP, FG-401E, FG-400F, FG-401F, FG-500E, FG-501E, FG-600E, FG-601E, FG-600F, FG-601F, FG-800D, FG-900D, FG-900G, FG-901G, FG-1000D, FG-1000F, FG-1001F, FG-1100E, FG-1101E, FG-1800F, FG-1801F, FG-2000E, FG-2200E, FG-2201E, FG-2500E, FG-2600F, FG-2601F, FG-3000D, FG-3000F, FG-3001F, FG-3100D, FG-3200D, FG-3200F, FG-3201F, FG-3300E, FG-3301E, FG-3400E, FG-3401E, FG-3500F, FG-3501F, FG-3600E, FG-3601E, FG-3700D, FG-3700F, FG-3701F, FG-3960E, FG-3980E, FG-4200F, FG-4201F, FG-4400F, FG-4401F, FG-4800F, FG-4801F, FG-5001E, FG-5001E1, FG-6000F, FG-7000E, and FG-7000F.

  • Supported FortiWiFi models

    FWF-40F, FWF-40F-3G4G, FWF-50G, FWF-50G-5G, FWF-50G-DSL, FWF-50G-SFP, FWF-51G, FWF-60E, FWF-60E-DSL, FWF-60E-DSLJ, FWF-60F, FWF-61E, FWF-61F, FWF-80F-2R, FWF-80F-2R-3G4G-DSL, FWF-81F-2R, FWF-81F-2R-3G4G-DSL, FWF-81F-2R-POE, and FWF-81F-2R-3G4G-POE.

  • Supported FortiGate Rugged models

    FGR-60F, FGR-60F-3G4G, FGR-70F, and FGR-70F-3G4G.

  • Supported FortiFirewall models

    FFW-1801F, FFW-2600F, FFW-3001F, FFW-3501F, FFW-3980E, FFW-4200F, FFW-4400F, FFW-4401F, FFW-4801F, FFW-VM64, and FFW-VM64-KVM.

  • Supported FortiGate VM models

    FG-ARM64-AWS, FG-ARM64-AZURE, FG-ARM64-GCP, FG-ARM64-KVM, FG-ARM64-OCI, FG-VM64, FG-VM64-ALI, FG-VM64-AWS, FG-VM64-AZURE, FG-VM64-GCP, FG-VM64-HV, FG-VM64-IBM, FG-VM64-KVM, FG-VM64-OPC, FG-VM64-RAXONDEMAND, and FG-VM64-XEN.

  • Special-branch build validation

    Special-branch models must report Branch point 2795. Run `get system status` and verify the Branch point field.

  • Special branch build 5164

    FG-30G, FG-31G, FWF-30G, and FWF-31G are released on build 5164.

  • Special branch build 6345

    FGR-50G-5G, FG-70G-POE, FGR-70G, FGR-70G-5G-DUAL, FG-71G, FG-71G-POE, FWF-70G, FWF-70G-POE, and FWF-71G are released on build 6345.

  • FGR-70G-5G special branch build

    FGR-70G-5G is released on build 6402.

  • FortiGate 6000F platform support

    Supported models are FG-6001F, FG-6300F, FG-6301F, FG-6500F, and FG-6501F.

  • FortiGate 7000E platform support

    Supported models are FG-7030E, FG-7040E, and FG-7060E.

  • FortiGate 7000F platform support

    Supported models are FG-7081F and FG-7121F.

Known issues

  • #1103272

    Deny proxy policies may use the wrong SSL certificate

    SSL certificates are misapplied when FortiGate processes requests with deny actions in proxy policies.

  • #1056600

    WAD initialization dependency failure

    Improper dependency management can cause initialization ordering problems or missing dependencies in the WAD module.

  • #1088905

    Virtual-server HTTP health check ignores configured host

    The health check always uses an IP address as the host even when a full URL is configured in http-get.

  • #1104569

    FPM may hang after upgrade

    On FortiGate 6000/7000, confsynchbd can fail to release a lock because of a file-permission issue, causing an FPM to hang after upgrade.

  • #1147340

    Duplicate interfaces cause chassis synchronization failures

    Repeated unresolved HA configuration merges can create duplicate interface entries, persistent synchronization failures, and redundant logs on FortiGate 6000/7000.

  • #1153360

    Chassis counters mismatch or overflow

    Counter values may not match totals and can overflow during continuous clearing on certain FortiGate models.

  • #1159714

    NP7 netdevice references fail after cfg-save revert

    Configuration changes following enablement of `cfg-save revert` can produce unexpected behavior because of unresolved netdevice references in the NP7 driver.

  • #1171521

    FortiGate 7000F FPM may hang after chassis restart

    An FPM may hang during login and remain out of sync after any chassis restart, including a firmware upgrade, because confsynchbd becomes stuck after a management heartbeat from the primary FIM. Workaround: place the active SMM and primary FIM in the same slot, such as FIM1 and SMM1; use the SMM `smm_switch` command to change the active SMM; then reboot all FPMs. This is not a permanent fix.

  • #1173956

    Large EMA tags can break policy matching

    EMA Tag entries containing too many addresses may not be inserted correctly as dynamic address objects, causing traffic to miss the related firewall policy.

  • #1145475

    Dashboard widget changes may drop multicast traffic

    Adding or removing the Interface Bandwidth widget can cause multicast traffic to be dropped.

  • #1149411

    Topology pages increase Node.js memory use

    Erroneous memory allocation occurs when the Logical and Physical Topology pages are used.

  • #1033083

    HA session synchronization can trigger conserve mode

    Sessions are not synchronized correctly, leaving many sessions on the primary and causing the standby to enter conserve mode.

  • #1068674

    PBA logs missing during HA failover

    Port block allocation logs may be missing during an HA failover.

  • #1162432

    Renaming IPsec interface may cause HA split brain

    Renaming an IPsec phase1-interface in a cluster with many VDOMs can cause split brain.

  • #1179351

    Factory-certificate private keys fail to load

    FortiGate may fail to load factory-certificate private keys into fgfmd because they are classified incorrectly.

  • #1210147

    Certificate can leave HA out of sync

    A certificate-related condition can cause HA synchronization failure.

  • #1155548

    Hyperscale host logging increases session count

    With host logging (log2host) enabled, session counts may rise after several days and reduce throughput and CPS performance. Workaround: restart the FortiGate.

  • #1219541

    Changing interface VDOM disrupts hyperscale traffic

    Changing an interface's VDOM can disrupt traffic. Workaround: replace default route 0.0.0.0/0 with static routes 0.0.0.0/1 and 128.0.0.0/1.

  • #1101897

    IPsec sent-byte counters spike

    Race conditions during counter rollback can produce abnormal spikes in VPN sent-byte statistics.

  • #1125487

    IKE resumption gateway switch fails

    Gateway switching can fail during IKE session resumption when moving from a FortiGate without Azure AD auto-connect enabled to one with it.

  • #1130821

    Long user agents truncate attack-context logs

    Attack-context logging can produce incomplete entries for attacks involving long user-agent strings.

  • #1116771

    User-device-store lacks a memory percentage limit

    The proxy user-device-store requires a limit based on a percentage of total system memory.

  • #969992

    SCTP may use stale routes

    Under certain conditions, FortiGate may route SCTP traffic using outdated routes rather than the current optimal path.

  • #1133796

    IPv6 routes remain in kernel table

    IPv6 routes can become stuck in the kernel routing table.

  • #1150878

    IPoE tunnel unavailable in bandwidth widget

    The IPoE tunnel interface cannot be selected in the Interface Bandwidth widget.

  • #1171689

    BGP redistribution can select the wrong route

    Route maps can select an incorrect route during BGP redistribution because parent protocol distances are handled improperly.

  • #1199707

    Asymmetric SD-WAN path disrupts SIP over TCP

    SIP traffic can fail when TCP SYN-ACK packets use a different egress interface than SYN packets. Workaround: use UDP for SIP.

  • #1164811

    SSL VPN web mode denied after 2GB-model upgrade

    After an upgrade, SSL VPN web mode can display Access Denied on 2GB models.

  • #991285

    VXLAN hubs forward broadcasts between peers

    Certain FortiGate models configured as VXLAN hubs in a hub-and-spoke topology may unexpectedly forward broadcasts between peers.

  • #1084819

    FGT-80F and 81F shared WAN ports go down

    LACP/shared ports wan1 and wan2 may remain down after an upgrade or reboot because of hardware shared-port medium changes.

  • #1136616

    VLAN dashboard graphs missing

    The dashboard Interface widget does not show graphs for some VLAN interfaces.

  • #1145397

    GUI user-exemption edits behave unexpectedly

    GUI and CLI data-structure differences can cause unexpected behavior while editing user exemption configurations.

  • #1156262

    Global session-limit configuration rejected

    Configuring the maximum number of sessions in global resources can return an "Input value is invalid." error.

  • #1164332

    NP7 stops forwarding after DFR reassembly

    NP7 may stop forwarding traffic after reassembling a large packet in DFR.

  • #1197885

    7.4.7-to-7.4.8 upgrade may increase memory use

    ASLR can cause memory-usage problems when upgrading from 7.4.7GA to 7.4.8GA. Workaround: disable proxy-inline-ips.

  • #1135049

    Database update races with CMDB loading

    After an upgrade, the update daemon may attempt to update databases while CMDB is loading the JSON file, producing an error condition.

  • #1118212

    FortiToken push approval does not complete captive authentication

    Captive-portal authentication can fail after FortiToken push approval during RADIUS authentication through FortiAuthenticator for remote groups.

  • #1122979

    GUI RADIUS test omits custom NAS-ID

    A custom NAS-ID is not sent to the RADIUS server when connectivity is tested through the GUI.

  • #1113362

    Azure FortiGate VM cannot join Security Fabric tree

    FGT_VM_AZURE may fail to connect to other FortiGates in the Security Fabric tree.

  • #1125437

    DHCP-client interface distance ignored on VM

    The `set distance` option does not work on VM interfaces configured as DHCP clients.

  • #1172881

    DPDK IPsec fragmentation can crash IPS engine

    The IPS engine may crash with DPDK enabled under stressed, fragmented IPsec traffic when `system affinity-packet-redistribution` is used.

  • #1144969

    WiFi Client page shows mismatched IP details

    IP address information on the WiFi Client GUI page may not match.

  • #1121978

    GUI ZTNA mapping creation corrupts existing URLs

    Adding an HTTPS/HTTP ZTNA server mapping through the GUI may fail with a duplicate-entry error; exiting after cancellation can alter URLs in existing entries.

  • #1026362

    Captive portal fails without persistent cookies

    Web pages do not load when `persistent-cookie` is disabled for session-cookie-based authentication with captive portal.

  • #959065

    Traffic-shaper changes clear other counters

    Creating or deleting a shaper on Policy & Objects > Traffic Shaping clears counters for other shapers.

  • #1004263

    ASIC offload leaves policy counters stale

    With ASIC offload enabled, session counters are not updated and the GUI shows incorrect Bytes and Last Used values.

  • #1114635

    GUI address filtering fails with CIDR

    Address objects cannot be filtered correctly in the GUI using CIDR notation.

  • #1148166

    Source-port translation fails for UDP 7001

    Source-port translation is not permitted for traffic to UDP port 7001.

  • #911244

    FortiGate 7000E IPv6 routes may not synchronize

    IPv6 routes may not synchronize correctly among FIMs and FPMs.

  • #1006759

    IPsec kernel route disappears after chassis HA failover

    After HA failover on FortiGate 6000/7000, the IPsec route may be absent from the kernel. Workaround: bring the tunnel down and then up.

  • #1070365

    FortiManager changes session-sync interface VDOM

    On managed FortiGate 7000F virtual clusters, FortiManager can change management interfaces configured with `session-sync-dev` from mgmt-vdom to vsys_ha, stopping session synchronization. Workaround: reconfigure `session-sync-dev` on the cluster and retrieve the FortiGate configuration into FortiManager.

  • #1092728

    FortiGate 6000 and 7000 drop fragmented IPv6 traffic

    Fragmented IPv6 traffic may be dropped randomly.

  • #1149342

    VDOM migration can cause BGP flapping

    Concurrent IP address management during VDOM migration can cause unexpected source-IP use on outbound connections and BGP flapping.

  • #781171

    HA GUI may falsely report image-upgrade failure

    If the secondary takes several minutes to boot, the GUI may time out and display Image upgrade failed even though the HA upgrade can complete successfully.

  • #1135376

    HA contract information unavailable across FortiCare accounts

    If HA members are not registered to the same FortiCare account, the cluster cannot obtain contract information for all members from FortiGuard.

  • #1226122

    Secondary HA GUI lacks MVC upgrade button

    The secondary GUI has no upgrade button in local-only or secondary-only MVC upgrade mode. Workaround: upgrade the secondary through the command line.

  • #866413

    GRE over IPsec is not offloaded on NP7

    Traffic over GRE over IPsec, or IPsec traffic with GRE encapsulation, is not offloaded on NP7-based units.

  • #897871

    GRE over IPsec fails in transport mode

    GRE over IPsec does not work in transport mode.

  • #970703

    FortiGate 6K and 7K do not support IPsec over vdom-link

    IPsec VPN over vdom-link or npu-vlink is unsupported on FortiGate 6000 and 7000 models.

  • #1140823

    NP6xlite spoke IPsec tunnels can become stuck

    After extended operation and multiple rekeys, incorrect vifid formation can leave tunnels stuck and cause ESP packet drops.

  • #1035490

    2GB proxy inspection may require post-upgrade reboot

    Proxy-based inspection behavior on 2GB RAM models may require recovery after an upgrade. Workaround: reboot the FortiGate after upgrading.

  • #1040655

    Local-out ECMP traffic may use a different route

    Since FortiOS 7.4.1, local-out traffic with ECMP routes may use a different route or port. For source-IP-sensitive traffic, use `interface-select-method` to specify an interface or SD-WAN path.

  • #1150382

    Security profile names with double slashes freeze GUI

    Editing a security profile whose name contains two forward slashes (//) can make the web page unresponsive.

  • #1156006

    HA automation SFTP backup fails with Windows paths

    An automation-stitch SFTP backup can fail on an HA FortiGate when Windows-style paths are used.

  • #1085407

    FortiGate can become unresponsive with shaping default QoS

    The device may become unresponsive when `default-qos-type` is set to `shaping`.

  • #1113436

    QinQ over LACP drops offloaded packets

    Packets may be dropped with auto-ASIC-offload and 802.1AD over LACP because QinQ LAG interfaces lack a MAC-address assignment.

  • #1164174

    FGT-60F may lose configuration in extreme conserve mode

    Configuration loss can occur on FGT-60F when it enters extreme conserve mode.

  • #1170282

    ACME certificate provisioning desynchronizes HA

    Provisioning a certificate through ACME can leave FortiGate HA out of sync.

  • #1114550

    FortiExtender appears offline after 7.4.5-to-7.4.6 upgrade

    FortiExtender may show offline after upgrading FortiGate from 7.4.5 to 7.4.6. Workaround: reboot FortiExtender manually.

  • #1082800

    Large GUI LDAP searches can exhaust HTTPSD memory

    GUI LDAP searches against directories with more than 100000 users can consume excessive HTTPSD memory and impair operation. Recovery may require stopping HTTPSD or rebooting. Workaround: perform LDAP user searches through the CLI.

  • #1157003

    Windows Server 2025 restrictions affect agentless FSSO

    Agentless FSSO connector issues can occur because Windows 2025 adds restrictions to remote Event Log reading.

  • #814541

    Large FortiAP deployments load slowly

    With over 500 managed FortiAPs and over 5000 WiFi clients, the Managed FortiAPs page and FortiAP Status widget can take a long time to load; FortiAP operation is unaffected.

  • #1080094

    Offline WiFi stations can drive high memory use

    Offline station entries may not be cleaned up automatically, causing high memory usage over time.

  • #819987

    ZTNA mapped drives fail after laptop reboot

    Mapped drives may become inaccessible after a laptop reboot when the FortiGate ZTNA access proxy uses FQDN destinations.