Description |
This article explains a behavior that has changed and causes the Security Fabric configuration to be disabled for a Fabric Root FortiGate.
Example of a FortiGate 60F configured as Fabric Root running FortiOS 7.2.5.
Configuration from CLI:
After the firmware upgrade from v7.2.5 to v7.2.6, downstream FortiGates will present the following Fabric Status in the Security Fabric Setup connector.
Configuration is then set to Standalone, which means Security Fabric is disabled.
From CLI, the following message will be presented when trying to set it as Fabric Root:
config system csf
|
Scope |
FortiGate-40F, 60E, 60F, 80E, and 90E series devices and their variants running FortiOS v7.2.6 and v7.4.1. |
Solution |
Per the new design to reduce memory consumption on FortiGate models with 2 GB RAM, FortiOS 7.2.6 and 7.4.1 and above cannot be configured as root of the Security Fabric topology. Those devices can only be a Downstream or Standalone device of a Security Fabric. The affected models are the FortiGate 40F, 60E, 60F, 80E, and 90E series devices and their variants.
FortiOS 7.2.6 - FortiGate models with 2 GB RAM cannot be a Security Fabric root |
All of them are low end models.
Thanks for the info!
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.