Created on
10-21-2025
11:53 PM
Edited on
10-27-2025
01:38 AM
By
Jean-Philippe_P
| Description |
This article describes why HA is going out of sync post-upgrading to v7.6.3. |
| Scope | FortiOS v7.6.3. |
| Solution |
After upgrading to v7.6.3, FortiGate HA may become out of sync.
This issue is caused by the newly introduced 'zero-day malware stream scanning' feature in the Antivirus profile. The feature automatically maintains an up-to-date malware hash database by removing outdated entries and optimizing performance, without requiring manual input.
This problem is linked to a known issue being tracked. Specifically, the 'set malware-stream' command is missing on the secondary device antivirus profile configuration, which results in the HA pair going out of sync.
As a workaround, either disable this feature or upgrade to v7.6.4, where the issue has been resolved. Please refer Release notes of v7.6.4 before planning the upgrade of the device.
Below is the snapshot of the zero-day malware feature in the Antivirus profile.
If done on CLI, it has to be disabled for each protocol which have been set to be inspected; by default, the action would be set to block.
config antivirus profile |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.