Skip to main content
adimailig
Staff & Editor
Staff & Editor
December 27, 2024

Technical Tip: Local-in-Policy is Missing after upgrading to v7.4.6, v7.4.7 or v7.6.1

  • December 27, 2024
  • 0 replies
  • 3070 views
Description This article explains why local-in-policy is missing after upgrading to v7.4.6, v7.4.7 or v7.6.1.
Scope FortiGate v7.4.6, v7.4.7, v7.6.1.
Solution

If the local-in-policy use interface was part of the SD-WAN zone, this policy will be deleted after upgrading to v7.4.6, v7.4.7 or v7.6.1: Policies that use an interface show missing or empty values after an upgrade

The behavior is due to New Feature ID: 1071495: New features or enhancements

  • Local-in policy.
  • DoS policy.
  • Interface policy.
  • Multicast policy.
  • TTL policy.
  • Central SNAT map.
  • This update simplifies policy management and boosts operational efficiency.

 

When running commands 'diagnose debug config-error-log read', it will show below output:

 

diagnose debug config-error-log read
>>> "set" "intf" "port2" @ root.firewall.local-in-policy.1:value parse error (error -651)
>>> "next" @ root.firewall.local-in-policy.1:failed command (error 1)
>>> "set" "intf" "port1" @ root.firewall.local-in-policy.2:value parse error (error -651)
>>> "next" @ root.firewall.local-in-policy.2:failed command (error 1)


After upgrading to v7.4.6, v7.4.7 or v7.6.1, local-in-policies should be manually created and assigned the appropriate SD-WAN Zone.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!