Skip to main content
FdiPerna
New Member
April 1, 2024
Question

Firmware 7.2.8 issue - interface link automatically set down -

  • April 1, 2024
  • 2 replies
  • 3893 views

Good morning,
I have a Fortigate cluster (#100F), with firmware 7.2.7, when upgrading to version 7.2.8, the link of a physical interface, is automatically disabled and is shown as down.
Our LAN is 10.0.0.0.0/16 and the interface in question has the IP 192.168.201.102/30, which allows us to connect to another network through an ASA.
I did the downgrade, restoring the previous configuration and everything works fine again, so obviously this is due to some new feature...
Please, could you give me some idea of "where to start to untie the knot" (or in another words, to understand what it is due to)??
Thank you very much!

2 replies

amrit
Staff & Editor
Staff & Editor
April 1, 2024

There is a known bug in FortiOS 7.2.8--> 925554--> On the Network > Interfaces page, hardware and software switches show VLAN interfaces as down instead of up. The actual status of the VLAN interface can be verified using the commandline :  https://docs.fortinet.com/document/fortigate/7.2.8/fortios-release-notes/236526/known-issues

Check if you are hitting this issue, it will be fixed in the next release. 
Note: this is only a cosmetic issue you can check the actual status of an interface from the commandline 
config system interface 
edit <interfacename>
show full | grep status 
end 
end
diag hardware device info nic <interface name>

FdiPerna
FdiPernaAuthor
New Member
April 2, 2024

Good morning, thank you for your answer..., I will check if this is the case....

ede_pfau
SuperUser
SuperUser
April 1, 2024

@FdiPerna: can you confirm that the interface in question is indeed part of a hw/sw switch?

FdiPerna
FdiPernaAuthor
New Member
April 2, 2024

Good morning, thank you for your answer..., no, the interface is defined as a physical interface, not as part of a hardware switch....

smaruvala
Staff
Staff
April 2, 2024

Hi,

 

- Was there any logs collected during the issue which @amrit mentioned?

- I tried to upgrade a 101F firewall to 7.2.8 in the lab and I did not face any issue in which the physical interface was down.

 

Regards,

Shiva