| Description |
This article describes a known upgrade issue that affects FortiLink interfaces with a non-default allowaccess ('Administrative Access') configuration. |
| Scope | FortiGate v7.4.x. |
| Solution |
This issue occurs when a FortiLink-enabled interface's allowaccess configuration includes any protocols other than ping and fabric. This was possible in previous firmware versions, but is not permitted in v7.4. After upgrading to v7.4, the FortiLink-enabled interface is lost, and any configured VLAN or FortiSwitch referencing the interface is also lost.
For example:
config system interface edit "fortilink" set vdom "root" next end
Upgrading the device to v7.4 will cause this interface to be lost and generate additional errors visible with the command 'diagnose debug config-error-log read':
diagnose debug config-error-log read
In v7.2, it is not possible to change the allowaccess settings manually on FortiLink-enabled interfaces, see the article Troubleshooting Tip: FortiLink error message after interface changing. For this reason, modifying the configuration file directly is required to resolve this issue.
Preventing the issue before the upgrade:
config system interface edit "fortilink_name" ... ... set allowaccess ping fabric ... next end
For physical devices permitting rollback to the previous v7.2, revert to the previous firmware and configuration following the article Technical Tip: Selecting an alternate firmware for the next reboot and follow the prevention steps above.
If it is not possible to revert the device to the previous v7.2 safely, an administrator may modify a v7.2 configuration file to include the correct 'set allowaccess ping fabric' configuration and restore it to the device with v7.4 firmware. Uploading a configuration taken on a different firmware version can introduce errors, and it may be necessary to correct any additional errors showing in 'diagnose debug config-error-log read' manually. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.