Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
camran
New Contributor

Stable versions of the 7.x.x firmware family

I have Forti devices with the 7.2.x firmware family, and i'm planning security updates to mitigate vulnerabilities. However, the PSIRT vulnerabilities site recommend migrate to 7.4.x family to fix them, and in some cases, the vulnerabilities in that family suggest migrate to 7.6.x.

From your experience, are these family versions stable? Or do they have a lot of bugs?

3 REPLIES 3
RicardoPearce
New Contributor

The newer trains are generally acceptable if you're coming from 7.2.x, but there are a few things to be aware of.

The later patches are stable enough for production, and 7.4.x has developed significantly. The typical bugs are present, but nothing unusual.

Since 7.6.x is still relatively new, it can be a little rough around the edges and receives fixes more frequently. I would only upgrade to 7.6.x if 7.4.x doesn't have the precise PSIRT fixes you require.

Use the most recent 7.4.x patch for the time being and switch to 7.6.x after it settles if stability is your top priority.

bokoljo9
New Contributor

You just described yesterday for me. I'm using forticlient version 7.2.8 on Fortios 7.2.10 and no matter the config I couldn't get auth to work at all. If I only used psk, it would connect, but no split tunneling. Reviewing route print showed it always full tunneled regardless of config. I don't understand how they can be forcing a solution that isn't mature and recommending a Fortios version that breaks fundamental features.

ggarg
Staff
Staff

Hello Camran,

Which vulnerability are you referring to? Since the 7.2.x branch is already out of engineering support, that vulnerability may not be fixed in this release. In the meantime, you can refer to the documentation below to find the recommended FortiOS version for your FGT.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-Release-for-FortiOS/ta-p/22717...

Gautam Garg | TAC Engineer
Fortinet TAC - America East
NSE Certified: 1-4, 7 | CCNP
Office Hours: 8:45-5:45 EST (Mon-Fri)
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors