Skip to main content
dchao_FTNT
Staff
Staff
May 5, 2026

Technical Tip: FortiGate-VMs in Microsoft Azure running on MANA (Microsoft Azure Network Adapter) enabled hosts

  • May 5, 2026
  • 1 reply
  • 2950 views

Description

This article describes the support for new MANA (Microsoft Azure Network Adapter) hardware for existing VM Size Families. The new hardware provides higher throughputs and lower latency and is only supported on FortiOS v7.6.1 and later. Previous FortiOS versions 7.6.0 and below do not support the new MANA Network Interface.


Microsoft plans to roll out the MANA NIC on legacy Infrastructure (Standard_Dv5 and lower). This change will impact all FortiOS versions below 7.6.1 that are paired with MANA NIC and will cause the network driver to switch to the default synthetic path driver (NetVsc).

The use of the network driver (NetVsc) can result in lower firewall throughput compared to the Mellanox ConnectX hardware equivalent.  Thus impacting the performance of FortiGate-VM deployed on Azure.

Scope

FortiGate-VM on Azure Cloud.

Solution

To prevent FortiGate VMs from being provisioned on MANA-enabled hosts, it is recommended to use the temporary opt-out mechanism (effective until May 31st 2027) by applying the appropriate tags, as outlined in the MANA support for Network Virtual Appliances (NVAs).


Note that any VMs that are stopped (deallocated), restarted, or redeployed may be reassigned to MANA-enabled hosts and therefore impacted by this change. Tagging resources appropriately can help temporarily alleviate this issue.


To take full advantage of new MANA hardware and Azure Boost performance enhancements and features, upgrade to FortiOS v7.6.1 and later, which would provide support for the new MANA network cards with higher throughput and reliability.

How to check whether a VM is running on MANA-enabled hardware

FGTVM # diagnose hardware lspci -v

7870:00:00.0 Class 0200: Device 1414:00ba
Subsystem: Device 1414:00b9
Physical Slot: 1
Flags: bus master, fast devsel, latency 0, NUMA node 0
Memory at fc2000000 (64-bit, prefetchable) [size=32M]
Memory at fc4000000 (64-bit, prefetchable) [size=32K]
Capabilities: [70] Express Endpoint, MSI 00
Capabilities: [b0] MSI-X: Enable+ Count=1024 Masked-
Capabilities: [100] Alternative Routing-ID Interpretation (ARI)
Kernel driver in use: mana


For Azure VWAN NVA deployments, LegacyVMNVA tags will be applied automatically to both existing and new deployments. After the 31 May 2027 deadline, NVA will be gradually migrated to the new MANA hardware.


Related documents:

    1 reply

    New Member
    June 19, 2026

    Hello,

    I would like to clarify the scope for other Fortinet products hosted in Azure. Does this hardware rollout also impact FortiManager (FMG) and FortiAnalyzer (FAZ) VMs?

    If so:

    1. In which versions will MANA support be natively introduced for FMG/FAZ?

    2. Given that FMG/FAZ are management/logging planes rather than data planes, is the performance degradation from the NetVSC fallback practically noticeable for these services?

    Thanks in advance for the clarification.,

    Alejandro.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!