FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mkhabbazi
Staff
Staff
Article Id 280864
Description

This article explains a behavior that has changed and causes the Security Fabric configuration to be disabled for a Fabric Root FortiGate.

Upgrading FortiOS firmware to versions 7.2.6 or 7.4.1 on the units with 2GB, that are configured as a root FortiGate of a Security Fabric, will cause the Security Fabric configuration to be disabled after the upgrade.

 

Example of a FortiGate 60F configured as Fabric Root running FortiOS 7.2.5.

 

MicrosoftTeams-image (2).png

 

 

Configuration from CLI:


config system csf
    set status enable
    set group-name "FTNT"
    set fixed-key ENC
end

 

After the firmware upgrade from v7.2.5 to v7.2.6, downstream FortiGates will present the following Fabric Status in the Security Fabric Setup connector.

MicrosoftTeams-image (2).png

Configuration is then set to Standalone, which means Security Fabric is disabled.
Note that the option to configure this device as Fabric Root is no longer available.

 

MicrosoftTeams-image (1).png

From CLI, the following message will be presented when trying to set it as Fabric Root:

 

config system csf
    set status enable
end


...


2GB-RAM models cannot be a Security Fabric root.
Please set the upstream.
object set operator error, -39, roll back the setting
Command fail. Return code -39

Scope

FortiGate-40F, 60E, 60F, 80E, and 90E series devices and their variants running FortiOS v7.2.6 and v7.4.1.

Solution

Per the new design to reduce memory consumption on FortiGate models with 2 GB RAM, FortiOS 7.2.6 and 7.4.1 and above cannot be configured as root of the Security Fabric topology.

Those devices can only be a Downstream or Standalone device of a Security Fabric.

The affected models are the FortiGate 40F, 60E, 60F, 80E, and 90E series devices and their variants.

Note:
FortiGate VMs with 2GB of RAM are not affected.


Related Documents:

FortiOS 7.2.6 - FortiGate models with 2 GB RAM cannot be a Security Fabric root
FortiOS 7.4.1 - FortiGate models with 2 GB RAM cannot be a Security Fabric root
Technical Tip: Configuring the root FortiGate and downstream FortiGates in Security Fabric

Comments
mauromarme
Staff
Staff

All of them are low end models.
Thanks for the info!