Created on
‎07-23-2025
11:47 PM
Edited on
‎08-26-2025
11:08 PM
By
Jean-Philippe_P
Description | This article describes that when upgrading to v7.4.8, DHCP obtains the static route priority that takes precedence over custom-defined. |
Scope | FortiGate v7.4.8. |
Solution |
In earlier versions, if a DHCP interface obtains a static route and a manually configured static route with the same AD, the user can define a different priority for route selection. Details for Static Route Priority: Technical Tip: Routing behavior depending on distance and priority for static routes, and Policy Bas...
In v7.2.11, ports 3 and 1 are both outgoing interfaces for Internet traffic. Port 3 obtains the IP address from the ISP site via DHCP.
To manually select port1 as the primary link, define a priority in the static route with a value of 16 will take effect in the routing table:
DCHP-Client # get router info routing-table all Routing table for VRF=0 DCHP-Client # show sys interface port3
In v7.4.8, the custom priority is not working as expected without any configuration change under Interface and static route.
See output below:
DCHP-Client # get router info routing-table all Routing table for VRF=0
The static route was chosen for port3 without honouring custom-defined priority, which currently shows a priority of 1 for port3; however, in the custom-defined setting under 'static route', priority has been configured as 16, which has not been changed in the configuration perspective.
This issue is currently still under investigation with the developer team. This article will be updated once the investigation is done. Here is a workaround for now.
Workaround: Define the priority under the DHCP interface level. See screenshot below. After priority has been defined (default 1) under the DHCP interface, the routing selection will honour the priority settings.
Note: This issue is caused by the side effect of New Feature Request 0896227; this change was only introduced in v7.4 and later. It will use origin as a tie breaker when the distance is the same. DHCP routes have a higher origin value in this design; it will take precedence over the static route. Recommendation will be to use either DHCP routes or manually specify the static route under routing configuration, and avoid using duplicate methods to get the static route. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.