FortiOS 7.4.8 release notes
FortiOS 7.4.8 build 2795 release information and supported-platform notes. The supplied content contains supported models and open issues, but no new-feature, security-fix, or resolved-issue sections.
Official Fortinet release notes ↗Upgrade notes
FortiOS 7.4.8 base build
The release is FortiOS 7.4.8 build 2795.
Supported FortiGate models
FG-40F, FG-40F-3G4G, FG-50G, FG-50G-5G, FG-50G-DSL, FG-50G-SFP, FG-50G-SFP-POE, FG-51G, FG-51G-5G, FG-51G-SFP-POE, FG-60E, FG-60E-DSL, FG-60E-DSLJ, FG-60E-POE, FG-60F, FG-61E, FG-61F, FG-70F, FG-71F, FG-80E, FG-80E-POE, FG-80F, FG-80F-BP, FG-80F-DSL, FG-80F-POE, FG-81E, FG-81E-POE, FG-81F, FG-81F-POE, FG-90E, FG-91E, FG-90G, FG-91G, FG-100F, FG-101F, FG-120G, FG-121G, FG-140E, FG-140E-POE, FG-200E, FG-200F, FG-201E, FG-201F, FG-200G, FG-201G, FG-300E, FG-301E, FG-400E, FG-400E-BP, FG-401E, FG-400F, FG-401F, FG-500E, FG-501E, FG-600E, FG-601E, FG-600F, FG-601F, FG-800D, FG-900D, FG-900G, FG-901G, FG-1000D, FG-1000F, FG-1001F, FG-1100E, FG-1101E, FG-1800F, FG-1801F, FG-2000E, FG-2200E, FG-2201E, FG-2500E, FG-2600F, FG-2601F, FG-3000D, FG-3000F, FG-3001F, FG-3100D, FG-3200D, FG-3200F, FG-3201F, FG-3300E, FG-3301E, FG-3400E, FG-3401E, FG-3500F, FG-3501F, FG-3600E, FG-3601E, FG-3700D, FG-3700F, FG-3701F, FG-3960E, FG-3980E, FG-4200F, FG-4201F, FG-4400F, FG-4401F, FG-4800F, FG-4801F, FG-5001E, FG-5001E1, FG-6000F, FG-7000E, and FG-7000F.
Supported FortiWiFi models
FWF-40F, FWF-40F-3G4G, FWF-50G, FWF-50G-5G, FWF-50G-DSL, FWF-50G-SFP, FWF-51G, FWF-60E, FWF-60E-DSL, FWF-60E-DSLJ, FWF-60F, FWF-61E, FWF-61F, FWF-80F-2R, FWF-80F-2R-3G4G-DSL, FWF-81F-2R, FWF-81F-2R-3G4G-DSL, FWF-81F-2R-POE, and FWF-81F-2R-3G4G-POE.
Supported FortiGate Rugged models
FGR-60F, FGR-60F-3G4G, FGR-70F, and FGR-70F-3G4G.
Supported FortiFirewall models
FFW-1801F, FFW-2600F, FFW-3001F, FFW-3501F, FFW-3980E, FFW-4200F, FFW-4400F, FFW-4401F, FFW-4801F, FFW-VM64, and FFW-VM64-KVM.
Supported FortiGate VM models
FG-ARM64-AWS, FG-ARM64-AZURE, FG-ARM64-GCP, FG-ARM64-KVM, FG-ARM64-OCI, FG-VM64, FG-VM64-ALI, FG-VM64-AWS, FG-VM64-AZURE, FG-VM64-GCP, FG-VM64-HV, FG-VM64-IBM, FG-VM64-KVM, FG-VM64-OPC, FG-VM64-RAXONDEMAND, and FG-VM64-XEN.
Special-branch build validation
Special-branch models must report Branch point 2795. Run `get system status` and verify the Branch point field.
Special branch build 5164
FG-30G, FG-31G, FWF-30G, and FWF-31G are released on build 5164.
Special branch build 6345
FGR-50G-5G, FG-70G-POE, FGR-70G, FGR-70G-5G-DUAL, FG-71G, FG-71G-POE, FWF-70G, FWF-70G-POE, and FWF-71G are released on build 6345.
FGR-70G-5G special branch build
FGR-70G-5G is released on build 6402.
FortiGate 6000F platform support
Supported models are FG-6001F, FG-6300F, FG-6301F, FG-6500F, and FG-6501F.
FortiGate 7000E platform support
Supported models are FG-7030E, FG-7040E, and FG-7060E.
FortiGate 7000F platform support
Supported models are FG-7081F and FG-7121F.
Known issues
- #1103272
Deny proxy policies may use the wrong SSL certificate
SSL certificates are misapplied when FortiGate processes requests with deny actions in proxy policies.
- #1056600
WAD initialization dependency failure
Improper dependency management can cause initialization ordering problems or missing dependencies in the WAD module.
- #1088905
Virtual-server HTTP health check ignores configured host
The health check always uses an IP address as the host even when a full URL is configured in http-get.
- #1104569
FPM may hang after upgrade
On FortiGate 6000/7000, confsynchbd can fail to release a lock because of a file-permission issue, causing an FPM to hang after upgrade.
- #1147340
Duplicate interfaces cause chassis synchronization failures
Repeated unresolved HA configuration merges can create duplicate interface entries, persistent synchronization failures, and redundant logs on FortiGate 6000/7000.
- #1153360
Chassis counters mismatch or overflow
Counter values may not match totals and can overflow during continuous clearing on certain FortiGate models.
- #1159714
NP7 netdevice references fail after cfg-save revert
Configuration changes following enablement of `cfg-save revert` can produce unexpected behavior because of unresolved netdevice references in the NP7 driver.
- #1171521
FortiGate 7000F FPM may hang after chassis restart
An FPM may hang during login and remain out of sync after any chassis restart, including a firmware upgrade, because confsynchbd becomes stuck after a management heartbeat from the primary FIM. Workaround: place the active SMM and primary FIM in the same slot, such as FIM1 and SMM1; use the SMM `smm_switch` command to change the active SMM; then reboot all FPMs. This is not a permanent fix.
- #1173956
Large EMA tags can break policy matching
EMA Tag entries containing too many addresses may not be inserted correctly as dynamic address objects, causing traffic to miss the related firewall policy.
- #1145475
Dashboard widget changes may drop multicast traffic
Adding or removing the Interface Bandwidth widget can cause multicast traffic to be dropped.
- #1149411
Topology pages increase Node.js memory use
Erroneous memory allocation occurs when the Logical and Physical Topology pages are used.
- #1033083
HA session synchronization can trigger conserve mode
Sessions are not synchronized correctly, leaving many sessions on the primary and causing the standby to enter conserve mode.
- #1068674
PBA logs missing during HA failover
Port block allocation logs may be missing during an HA failover.
- #1162432
Renaming IPsec interface may cause HA split brain
Renaming an IPsec phase1-interface in a cluster with many VDOMs can cause split brain.
- #1179351
Factory-certificate private keys fail to load
FortiGate may fail to load factory-certificate private keys into fgfmd because they are classified incorrectly.
- #1210147
Certificate can leave HA out of sync
A certificate-related condition can cause HA synchronization failure.
- #1155548
Hyperscale host logging increases session count
With host logging (log2host) enabled, session counts may rise after several days and reduce throughput and CPS performance. Workaround: restart the FortiGate.
- #1219541
Changing interface VDOM disrupts hyperscale traffic
Changing an interface's VDOM can disrupt traffic. Workaround: replace default route 0.0.0.0/0 with static routes 0.0.0.0/1 and 128.0.0.0/1.
- #1101897
IPsec sent-byte counters spike
Race conditions during counter rollback can produce abnormal spikes in VPN sent-byte statistics.
- #1125487
IKE resumption gateway switch fails
Gateway switching can fail during IKE session resumption when moving from a FortiGate without Azure AD auto-connect enabled to one with it.
- #1130821
Long user agents truncate attack-context logs
Attack-context logging can produce incomplete entries for attacks involving long user-agent strings.
- #1116771
User-device-store lacks a memory percentage limit
The proxy user-device-store requires a limit based on a percentage of total system memory.
- #969992
SCTP may use stale routes
Under certain conditions, FortiGate may route SCTP traffic using outdated routes rather than the current optimal path.
- #1133796
IPv6 routes remain in kernel table
IPv6 routes can become stuck in the kernel routing table.
- #1150878
IPoE tunnel unavailable in bandwidth widget
The IPoE tunnel interface cannot be selected in the Interface Bandwidth widget.
- #1171689
BGP redistribution can select the wrong route
Route maps can select an incorrect route during BGP redistribution because parent protocol distances are handled improperly.
- #1199707
Asymmetric SD-WAN path disrupts SIP over TCP
SIP traffic can fail when TCP SYN-ACK packets use a different egress interface than SYN packets. Workaround: use UDP for SIP.
- #1164811
SSL VPN web mode denied after 2GB-model upgrade
After an upgrade, SSL VPN web mode can display Access Denied on 2GB models.
- #991285
VXLAN hubs forward broadcasts between peers
Certain FortiGate models configured as VXLAN hubs in a hub-and-spoke topology may unexpectedly forward broadcasts between peers.
- #1084819
FGT-80F and 81F shared WAN ports go down
LACP/shared ports wan1 and wan2 may remain down after an upgrade or reboot because of hardware shared-port medium changes.
- #1136616
VLAN dashboard graphs missing
The dashboard Interface widget does not show graphs for some VLAN interfaces.
- #1145397
GUI user-exemption edits behave unexpectedly
GUI and CLI data-structure differences can cause unexpected behavior while editing user exemption configurations.
- #1156262
Global session-limit configuration rejected
Configuring the maximum number of sessions in global resources can return an "Input value is invalid." error.
- #1164332
NP7 stops forwarding after DFR reassembly
NP7 may stop forwarding traffic after reassembling a large packet in DFR.
- #1197885
7.4.7-to-7.4.8 upgrade may increase memory use
ASLR can cause memory-usage problems when upgrading from 7.4.7GA to 7.4.8GA. Workaround: disable proxy-inline-ips.
- #1135049
Database update races with CMDB loading
After an upgrade, the update daemon may attempt to update databases while CMDB is loading the JSON file, producing an error condition.
- #1118212
FortiToken push approval does not complete captive authentication
Captive-portal authentication can fail after FortiToken push approval during RADIUS authentication through FortiAuthenticator for remote groups.
- #1122979
GUI RADIUS test omits custom NAS-ID
A custom NAS-ID is not sent to the RADIUS server when connectivity is tested through the GUI.
- #1113362
Azure FortiGate VM cannot join Security Fabric tree
FGT_VM_AZURE may fail to connect to other FortiGates in the Security Fabric tree.
- #1125437
DHCP-client interface distance ignored on VM
The `set distance` option does not work on VM interfaces configured as DHCP clients.
- #1172881
DPDK IPsec fragmentation can crash IPS engine
The IPS engine may crash with DPDK enabled under stressed, fragmented IPsec traffic when `system affinity-packet-redistribution` is used.
- #1144969
WiFi Client page shows mismatched IP details
IP address information on the WiFi Client GUI page may not match.
- #1121978
GUI ZTNA mapping creation corrupts existing URLs
Adding an HTTPS/HTTP ZTNA server mapping through the GUI may fail with a duplicate-entry error; exiting after cancellation can alter URLs in existing entries.
- #1026362
Captive portal fails without persistent cookies
Web pages do not load when `persistent-cookie` is disabled for session-cookie-based authentication with captive portal.
- #959065
Traffic-shaper changes clear other counters
Creating or deleting a shaper on Policy & Objects > Traffic Shaping clears counters for other shapers.
- #1004263
ASIC offload leaves policy counters stale
With ASIC offload enabled, session counters are not updated and the GUI shows incorrect Bytes and Last Used values.
- #1114635
GUI address filtering fails with CIDR
Address objects cannot be filtered correctly in the GUI using CIDR notation.
- #1148166
Source-port translation fails for UDP 7001
Source-port translation is not permitted for traffic to UDP port 7001.
- #911244
FortiGate 7000E IPv6 routes may not synchronize
IPv6 routes may not synchronize correctly among FIMs and FPMs.
- #1006759
IPsec kernel route disappears after chassis HA failover
After HA failover on FortiGate 6000/7000, the IPsec route may be absent from the kernel. Workaround: bring the tunnel down and then up.
- #1070365
FortiManager changes session-sync interface VDOM
On managed FortiGate 7000F virtual clusters, FortiManager can change management interfaces configured with `session-sync-dev` from mgmt-vdom to vsys_ha, stopping session synchronization. Workaround: reconfigure `session-sync-dev` on the cluster and retrieve the FortiGate configuration into FortiManager.
- #1092728
FortiGate 6000 and 7000 drop fragmented IPv6 traffic
Fragmented IPv6 traffic may be dropped randomly.
- #1149342
VDOM migration can cause BGP flapping
Concurrent IP address management during VDOM migration can cause unexpected source-IP use on outbound connections and BGP flapping.
- #781171
HA GUI may falsely report image-upgrade failure
If the secondary takes several minutes to boot, the GUI may time out and display Image upgrade failed even though the HA upgrade can complete successfully.
- #1135376
HA contract information unavailable across FortiCare accounts
If HA members are not registered to the same FortiCare account, the cluster cannot obtain contract information for all members from FortiGuard.
- #1226122
Secondary HA GUI lacks MVC upgrade button
The secondary GUI has no upgrade button in local-only or secondary-only MVC upgrade mode. Workaround: upgrade the secondary through the command line.
- #866413
GRE over IPsec is not offloaded on NP7
Traffic over GRE over IPsec, or IPsec traffic with GRE encapsulation, is not offloaded on NP7-based units.
- #897871
GRE over IPsec fails in transport mode
GRE over IPsec does not work in transport mode.
- #970703
FortiGate 6K and 7K do not support IPsec over vdom-link
IPsec VPN over vdom-link or npu-vlink is unsupported on FortiGate 6000 and 7000 models.
- #1140823
NP6xlite spoke IPsec tunnels can become stuck
After extended operation and multiple rekeys, incorrect vifid formation can leave tunnels stuck and cause ESP packet drops.
- #1035490
2GB proxy inspection may require post-upgrade reboot
Proxy-based inspection behavior on 2GB RAM models may require recovery after an upgrade. Workaround: reboot the FortiGate after upgrading.
- #1040655
Local-out ECMP traffic may use a different route
Since FortiOS 7.4.1, local-out traffic with ECMP routes may use a different route or port. For source-IP-sensitive traffic, use `interface-select-method` to specify an interface or SD-WAN path.
- #1150382
Security profile names with double slashes freeze GUI
Editing a security profile whose name contains two forward slashes (//) can make the web page unresponsive.
- #1156006
HA automation SFTP backup fails with Windows paths
An automation-stitch SFTP backup can fail on an HA FortiGate when Windows-style paths are used.
- #1085407
FortiGate can become unresponsive with shaping default QoS
The device may become unresponsive when `default-qos-type` is set to `shaping`.
- #1113436
QinQ over LACP drops offloaded packets
Packets may be dropped with auto-ASIC-offload and 802.1AD over LACP because QinQ LAG interfaces lack a MAC-address assignment.
- #1164174
FGT-60F may lose configuration in extreme conserve mode
Configuration loss can occur on FGT-60F when it enters extreme conserve mode.
- #1170282
ACME certificate provisioning desynchronizes HA
Provisioning a certificate through ACME can leave FortiGate HA out of sync.
- #1114550
FortiExtender appears offline after 7.4.5-to-7.4.6 upgrade
FortiExtender may show offline after upgrading FortiGate from 7.4.5 to 7.4.6. Workaround: reboot FortiExtender manually.
- #1082800
Large GUI LDAP searches can exhaust HTTPSD memory
GUI LDAP searches against directories with more than 100000 users can consume excessive HTTPSD memory and impair operation. Recovery may require stopping HTTPSD or rebooting. Workaround: perform LDAP user searches through the CLI.
- #1157003
Windows Server 2025 restrictions affect agentless FSSO
Agentless FSSO connector issues can occur because Windows 2025 adds restrictions to remote Event Log reading.
- #814541
Large FortiAP deployments load slowly
With over 500 managed FortiAPs and over 5000 WiFi clients, the Managed FortiAPs page and FortiAP Status widget can take a long time to load; FortiAP operation is unaffected.
- #1080094
Offline WiFi stations can drive high memory use
Offline station entries may not be cleaned up automatically, causing high memory usage over time.
- #819987
ZTNA mapped drives fail after laptop reboot
Mapped drives may become inaccessible after a laptop reboot when the FortiGate ZTNA access proxy uses FQDN destinations.