Bug Report: FortiGate 40F v7.2.11 Crash leading to loss of configuration
Product: FortiGate 40F
Firmware Version: v7.2.11 build 1740
Severity: Critical
Category: System Stability / Configuration Persistence
Summary
Under low-memory conditions, the FortiGate 40F experiences a critical failure where the active firewall policy configuration is completely erased, resulting in total loss of internet-bound traffic and administrative lockout.
Steps to Reproduce
Deploy a FortiGate 40F running firmware version 7.2.11 (build 1740).
Configure approximately 10 or more IP and domain threat feeds (external threat feeds).
Add an additional external IP threat feed, referencing it in a policy.
Observe system behavior as the new feed is added and activated.
Observed Behavior
The FortiGate becomes unresponsive for approximately 10 minutes.
All outbound internet traffic halts.
Management interface (e.g., GUI, SSH) becomes temporarily inaccessible.
Upon restoration of access, all firewall policies are missing.
CLI command show firewall policy returns no output, indicating full policy loss.
Expected Behavior
The FortiGate should enter conserve mode if memory usage exceeds thresholds.
Firewall policies and configurations should remain intact.
System should not discard critical configuration (e.g., firewall policy) under memory pressure.
Impact
Complete network outage due to loss of all firewall rules.
Manual reconfiguration required or restore from backup.
Critical disruption in production environments.
I have only observed this once and was able to restore from a cloud backup but I figured I would share in case others observe similar behavior.
