| Description |
This article describes that when DFR reassembly is enabled on a FortiGate in firmware version 7.4.8, the FortiGate may hit a known issue (ID 1164332). A PBA leak occurs when oversized reassembled packets are sent to NP7. This causes HA and LACP packets to be dropped, eventually leading to:
|
| Scope |
This issue is observed when all the following conditions are met:
If the reassembled packet exceeds 16 KB, the NP7 buffer manager may become corrupted, causing PBA leaks and dropping system-control packets (HA, LACP, etc.).
This issue is documented in the FortiOS 7.4.8 Release Notes Known Issues section. |
| Solution |
Disable IP-Reassembly in the NPU with:
config system npu
Note: Reboot is not required.
The following debug commands can help confirm whether NP7 entered an erroneous state and if PBA buffers are exhausted:
diagnose npu np7 pba all |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.