Skip to main content
Visitor II
June 10, 2026
Solved

Fortigate NPU cannot handle the bug of Airplay multicast correctly

  • June 10, 2026
  • 6 replies
  • 80 views

We use 600F and hosted switches and APs in the 7.2.13 system.

After testing and TAC confirmation, the 600Fwith7.2 system will discard multicast of tunnel SSIDs.

Users cannot use Airplay to discover Apple TV through tunnel SSID,even though I have already configured multicast and IPv4 policies according to KB.

We have two suggestions, either use 'set capwap-offload disable' or try upgrading to 7.4 or higher for testing.

But we currently do not plan to upgrade to 7.4 because it is not possible to directly configure switch ports such as "loop gurad" and "stp budp guard" on the web management page, and these features are precisely the reasons why we chose Fortinet.

I would like to know if Fortinet will fix this bug in FortiiOS7.2?

Thanks.

Best answer by sjoshi

Hi ​@Dunboba ,

 

Regarding a fix in v7.2, since v7.2 has come to end of engineering support that is if any issue is concluded as a bug a fix will be there on v7.4, v7.6.

Also have you tested by running set capwap-offload disable” if that fixes the issue?

Yes the load will be on CPU but need to confirm if disabling offload can fix the issue or not.

To get active engineering support the FortiGate should be in 7.4.

 

I can see loop guard , STP BPDU guard is still available from GUI in 7.4

https://docs.fortinet.com/document/fortiswitch/7.4.8/fortilink-guide/801175/configuring-dhcp-blocking-stp-and-loop-guard-on-managed-fortiswitch-ports

 

 

6 replies

DunbobaAuthor
Visitor II
June 10, 2026

Users connects to the SSID of the tunnel, and AppleTV connects to the wired LAN.

sjoshi
Staff
Staff
June 10, 2026

Hi ​@Dunboba 

Can you share the Bug ID if you are aware or you can share the TAC ticket number.

Also are you ok with the workaround suggested “set capwap-offload disable”

Thanks, Salon
DunbobaAuthor
Visitor II
June 10, 2026

Hi, ​@sjoshi 

Thank you for your reply. Our invoice number is: # 11874400
The operation of 'set capwap-offload disable' will cause an increase of Fortigate CPU. We are currently evaluating this operation internally, but there is no conclusion yet. I really hope to see conventional multicast policies solve this problem, as described in KB.

sjoshi
Staff
sjoshiAnswer
Staff
June 10, 2026

Hi ​@Dunboba ,

 

Regarding a fix in v7.2, since v7.2 has come to end of engineering support that is if any issue is concluded as a bug a fix will be there on v7.4, v7.6.

Also have you tested by running set capwap-offload disable” if that fixes the issue?

Yes the load will be on CPU but need to confirm if disabling offload can fix the issue or not.

To get active engineering support the FortiGate should be in 7.4.

 

I can see loop guard , STP BPDU guard is still available from GUI in 7.4

https://docs.fortinet.com/document/fortiswitch/7.4.8/fortilink-guide/801175/configuring-dhcp-blocking-stp-and-loop-guard-on-managed-fortiswitch-ports

 

 

Thanks, Salon
DunbobaAuthor
Visitor II
June 10, 2026

@sjoshi Thank you for your patient guidance, 

We have tried to enable DTLS encryption for AP, similar to the purpose of 'set capwap-offload disable', and the results show that AirPlay is working properly.So I believe that 'set capwap-offload disable' can also take effect.

We just redeployed 7.4.13 in the testing environment and found that there is still no ‘loop protection” and “STP root protection” in the "Enable Features" column, but they were found in “more columns”, so they all exist,  Just no longer in the original position and not displayed by default.

We have set a new direction:  upgrade to version 7.4 at the appropriate time.

Thank you very much for your support.

sjoshi
Staff
Staff
June 10, 2026

Great your have come to the conclusion.

Also refer to the release note before upgrading it to newer version.

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Thanks, Salon
DunbobaAuthor
Visitor II
June 11, 2026

We have planned a version upgrade this weekend and will test whether the new version can handle AirPlay's multicast traffic properly.

New Member
June 10, 2026

We use 600F and hosted switches and APs in the 7.2.13 system.

After testing and TAC confirmation, the 600Fwith7.2 system will discard multicast of tunnel SSIDs.

Users cannot use Airplay to discover Apple TV through tunnel SSID,even though I have already configured multicast and IPv4 policies according to KB.

We have two suggestions, either use 'set capwap-offload disable' or try upgrading to 7.4 or higher for testing.

But we currently do not plan to upgrade to 7.4 because it is not possible to directly configure switch ports such as "loop gurad" and "stp budp guard" on the web management page, and these features are precisely the reasons why we chose Fortinet.

I would like to know if Fortinet will fix this bug in FortiiOS7.2? site

Thanks.

 

This is most likely caused by NPU offloading interfering with multicast (mDNS/AirPlay) traffic. A quick test is to disable hardware acceleration for the affected policy. Also ensure UDP 5353 is allowed and multicast/mDNS is properly handled between VLANs. In many cases, this resolves the issue.

DunbobaAuthor
Visitor II
June 11, 2026

Yes, it has been confirmed that it is caused by NPU. Many Fortigate models exhibit different results for the same configuration and system version, which is very frustrating.

DunbobaAuthor
Visitor II
June 15, 2026

We conducted a system upgrade yesterday and are currently using version 7.4.12. Good news, the new version of tunnel SSID can handle multicast normally. Bad news, if blocking VLAN internal traffic is enabled, multicast will not function properly.