| Description | This article describes a behavior observed on certain FortiGate models where NetBIOS broadcast packets (UDP port 137/138) are still forwarded even though the interface setting 'set netbios-forward disable' is applied. |
| Scope | FortiGate version 7.0.16, 7.2.10, 7.4.4, and later builds. |
| Solution |
Even with the following configuration applied to the FortiGate interface, the FortiGate continues to forward NetBIOS broadcast packets.
diagnose sniffer packet any "host 192.168.150.100" 4 100 l
Despite netbios-forward being disabled, the packet is forwarded out on the same interface.
The forwarding occurs because the global setting allow-traffic-redirect is enabled by default in FortiOS.
Behavior by FortiOS version: FortiOS 7.0.16 / 7.2.10 / 7.4.4 and later: Earlier FortiOS versions: Workaround:
config system global
This is a known issue and is planned to be fixed in FortiOS 7.4.10, 7.6.5, and 8.0.0. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.