Fortinet black logo

Known issues

Known issues

The following known issues have been identified with FortiSwitchOS 7.2.1. For inquiries about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

Bug ID Description
382518, 417024, 417073, 417099, 438441 DHCP snooping and dynamic ARP inspection (DAI) do not work with private VLANs (PVLANs).
414972 IGMP snooping might not work correctly when used with 802.1x Dynamic VLAN functionality.
480605 When DHCP snooping is enabled on the FSR-112D-POE, the switched virtual interface (SVI) cannot get the IP address from the DHCP server.

Workarounds:
—Use a static IP address in the SVI when DHCP snooping is enabled on that VLAN.
—Temporarily disable dhcp-snooping on vlan, issue the execute interface dhcpclient-renew <interface> command to renew the IP address. After the SVI gets the IP address from the DHCP server, you can enable DHCP snooping.
510943 The time-domain reflectometer (TDR) function (cable diagnostics feature) reports unexpected values.

Workaround: When using the cable diagnostics feature on a port (with the diagnose switch physical-ports cable-diag <physical port name> CLI command), ensure that the physical link on its neighbor port is down. You can disable the neighbor ports or physically remove the cables.
542031 For the 5xx switches, the diagnose switch physical-ports led-flash command flashes only the SFP port LEDs, instead of all the port LEDs.
548783 Some models support setting the mirror destination to “internal.” This is intended only for debugging purposes and might prevent critical protocols from operating on ports being used as mirror sources.
572052 Backup files from FortiSwitchOS 3.x that have 16-character-long passwords fail when restored on FortiSwitchOS 6.x. In FortiSwitchOS 6.x, file backups fail with passwords longer than 15 characters.

Workaround: Use passwords with a maximum of 15 characters for FortiSwitchOS 3.x and 6.x.
585550 When packet sampling is enabled on an interface, packets that should be dropped by uRPF will be forwarded.
606044/610149 The results are inaccurate when running cable diagnostics on the FS-108E, FS-124E, FS-108E-POE, FS-108E-FPOE, FS-124E-POE, FS-124E-FPOE, FS-148E, and FS-148E-POE models.
609375 The FortiSwitchOS supports four priority levels (critical, high, medium, and low); however, The SNMP Power Ethernet MIB only supports three levels. To support the MIB, a power priority of medium is returned as low for the PoE MIB.

659487

The FS-108E, FS-108E-POE, FS-108E-FPOE, FS-108F, FS-108F-POE, FS-108F-FPOE, FS-124E, FS-124E-POE, FS-124E-FPOE, FS-124F, FS-124F-POE, and FS-124F-FPOE, FS-148E, and FS-148E-POE models support ACL packet counters but not byte counters. The get switch acl counters commands always show the number of bytes as 0.

667079

For the FSR-112D-POE model:

  • If you have enabled IGMP snooping or MLD snooping, the FortiSwitch unit does not support IPv6 functionalities and cannot pass IPv6 protocol packets transparently.

  • If you want to use IGMP snooping or MLD snooping with IPv6 functionalities, you need to enable set flood-unknown-multicast under the config switch global command.

748210

The MAC authentication bypass (MAB) sometimes does not work on the FS-424E when a third-party hub is disconnected and then reconnected.

784585

When a dynamic LACP trunk has formed between switches in an MRP ring, the MRP ring cannot be closed. Deleting the dynamic LACP trunk does not fix this issue. MRP supports only physical ports and static trunks; MRP does not support dynamic LACP trunks.

Workaround: Disable MRP and then re-enable MRP.

793145

VXLAN does not work with the following:

  • log-mac-event

  • DHCP snooping

  • LLDP-assigned VLANs

  • NAC

  • Block intra-VLAN traffic

795041

The VM debug report (System > Debug Report) is missing information for many CLI commands.

840114

When running FortiSwitchOS 7.2.1 build 4755 on the FS-124F-POE, FS-124F-FPOE, FS-148F-POE, and FS-148F-FPOE models, auto-network gets disabled after a reboot or upgrade. After such operations, you need to manually enable auto-network.

Workaround: Enable static ISL on all auto-discovered trunks (ISLs between the FortiSwitch units and the FortiLink trunk between the FortiSwitch unit and the FortiGate device) with the set static-isl enable command.

866231

The set status down command (under config switch physical-port) does not work on the SFP+ ports on the FS-426E-FPOE for certain versions of FortiSwitchOS. If you need to shut down any of the SFP+ ports on the FS-426E-FPOE, do not use FortiSwitchOS 7.0.5, 7.2.0, 7.2.1, or 7.2.2.

Workaround: Upgrade to FortiSwitchOS 7.2.3.

Known issues

The following known issues have been identified with FortiSwitchOS 7.2.1. For inquiries about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

Bug ID Description
382518, 417024, 417073, 417099, 438441 DHCP snooping and dynamic ARP inspection (DAI) do not work with private VLANs (PVLANs).
414972 IGMP snooping might not work correctly when used with 802.1x Dynamic VLAN functionality.
480605 When DHCP snooping is enabled on the FSR-112D-POE, the switched virtual interface (SVI) cannot get the IP address from the DHCP server.

Workarounds:
—Use a static IP address in the SVI when DHCP snooping is enabled on that VLAN.
—Temporarily disable dhcp-snooping on vlan, issue the execute interface dhcpclient-renew <interface> command to renew the IP address. After the SVI gets the IP address from the DHCP server, you can enable DHCP snooping.
510943 The time-domain reflectometer (TDR) function (cable diagnostics feature) reports unexpected values.

Workaround: When using the cable diagnostics feature on a port (with the diagnose switch physical-ports cable-diag <physical port name> CLI command), ensure that the physical link on its neighbor port is down. You can disable the neighbor ports or physically remove the cables.
542031 For the 5xx switches, the diagnose switch physical-ports led-flash command flashes only the SFP port LEDs, instead of all the port LEDs.
548783 Some models support setting the mirror destination to “internal.” This is intended only for debugging purposes and might prevent critical protocols from operating on ports being used as mirror sources.
572052 Backup files from FortiSwitchOS 3.x that have 16-character-long passwords fail when restored on FortiSwitchOS 6.x. In FortiSwitchOS 6.x, file backups fail with passwords longer than 15 characters.

Workaround: Use passwords with a maximum of 15 characters for FortiSwitchOS 3.x and 6.x.
585550 When packet sampling is enabled on an interface, packets that should be dropped by uRPF will be forwarded.
606044/610149 The results are inaccurate when running cable diagnostics on the FS-108E, FS-124E, FS-108E-POE, FS-108E-FPOE, FS-124E-POE, FS-124E-FPOE, FS-148E, and FS-148E-POE models.
609375 The FortiSwitchOS supports four priority levels (critical, high, medium, and low); however, The SNMP Power Ethernet MIB only supports three levels. To support the MIB, a power priority of medium is returned as low for the PoE MIB.

659487

The FS-108E, FS-108E-POE, FS-108E-FPOE, FS-108F, FS-108F-POE, FS-108F-FPOE, FS-124E, FS-124E-POE, FS-124E-FPOE, FS-124F, FS-124F-POE, and FS-124F-FPOE, FS-148E, and FS-148E-POE models support ACL packet counters but not byte counters. The get switch acl counters commands always show the number of bytes as 0.

667079

For the FSR-112D-POE model:

  • If you have enabled IGMP snooping or MLD snooping, the FortiSwitch unit does not support IPv6 functionalities and cannot pass IPv6 protocol packets transparently.

  • If you want to use IGMP snooping or MLD snooping with IPv6 functionalities, you need to enable set flood-unknown-multicast under the config switch global command.

748210

The MAC authentication bypass (MAB) sometimes does not work on the FS-424E when a third-party hub is disconnected and then reconnected.

784585

When a dynamic LACP trunk has formed between switches in an MRP ring, the MRP ring cannot be closed. Deleting the dynamic LACP trunk does not fix this issue. MRP supports only physical ports and static trunks; MRP does not support dynamic LACP trunks.

Workaround: Disable MRP and then re-enable MRP.

793145

VXLAN does not work with the following:

  • log-mac-event

  • DHCP snooping

  • LLDP-assigned VLANs

  • NAC

  • Block intra-VLAN traffic

795041

The VM debug report (System > Debug Report) is missing information for many CLI commands.

840114

When running FortiSwitchOS 7.2.1 build 4755 on the FS-124F-POE, FS-124F-FPOE, FS-148F-POE, and FS-148F-FPOE models, auto-network gets disabled after a reboot or upgrade. After such operations, you need to manually enable auto-network.

Workaround: Enable static ISL on all auto-discovered trunks (ISLs between the FortiSwitch units and the FortiLink trunk between the FortiSwitch unit and the FortiGate device) with the set static-isl enable command.

866231

The set status down command (under config switch physical-port) does not work on the SFP+ ports on the FS-426E-FPOE for certain versions of FortiSwitchOS. If you need to shut down any of the SFP+ ports on the FS-426E-FPOE, do not use FortiSwitchOS 7.0.5, 7.2.0, 7.2.1, or 7.2.2.

Workaround: Upgrade to FortiSwitchOS 7.2.3.