| Description | This article describes how to fix issues with GRE passthrough traffic matching implicit deny for return traffic in 90G devices. |
| Scope | FortiGate. |
| Solution | After upgrading from the v7.2 branch to v7.4.8, there might be issues with GRE passthrough traffic between Aruba APs and Aruba WLC. For traffic that was working initially before the upgrade, now, for the return traffic from WLC towards the Aruba APs, traffic is seen matching the implicit deny rule on the FortiGate, causing the APs not to register and authenticate correctly. The denies can be seen either in the Forward Logs of the FortiGate, or when running the below debug flow: diagnose debug reset
This is being investigated internally and is expected to be resolved in future versions. Currently, there is no timeline for the fix.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.