| Description | This article describes issues with virtual servers in HTTP mode after upgrading to the newer versions of the v7.4 branch, such as v7.4.2-v7.4.7. |
| Scope | FortiGate. |
| Solution |
Consider the following configuration working in v7.4.1.
config firewall vip
After upgrading to v7.4.2 or later, this configuration will no longer work and may cause issues when attempting to access internal servers. This is considered a misconfiguration, since HTTPS traffic should not be handled by an HTTP virtual server.
To resolve the issue, change the server-type to HTTPS or TCP.
config firewall vip
Note: The real server port must match the server-type. For internal ports different from 443/80, use the TCP server-type. To change its server-type, the virtual server object must be removed from existing firewall policies. After changing the server-type, reapply the virtual server as the destination to the intended firewall policies and verify that the internal resource is now accessible. See Troubleshooting Tip: Virtual Server Type greyed out. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.