Fortinet black logo

Known issues

Known issues

The following issues have been identified in FortiClient (Windows) 7.0.8. For inquiries about a particular bug or to report a bug, contact Customer Service & Support.

Application Firewall

Bug ID Description
717628 Application Firewall causes issues with Motorola RMS high availability client.

776007

Application Firewall conflict with Windows firewall causes issues updating domain group policies.

814391

FortiClient Cloud application signatures block allowlisted applications.

844997 FortiClient sees several packet losses on different internal resources after connecting telemetry.

823292

FortiClient cannot connect to JVC wireless display.

827788

Threat ID is 0 on Firewall Events.

853451

FortiClient blocks PIA VPN.

853808

FortiClient (Windows) blocks Veeam with messages related to Remote.CMD.Shell and VeeamAgent.exe.

860062

Application Firewall slows down opening Microsoft Active Directory (AD) Users and Computers application.

Endpoint control

Bug ID Description

753151

Updating endpoint status from endpoint notified to deployed takes a long time.

779267 FortiClient (Windows) does not get updated profile and does not sync.
780130 FortiClient (Windows) fails or takes long time to get updated Endpoint Control profile from EMS.

804552

FortiClient shows all feature tabs without registering to EMS after upgrade.

816751

Administrator cannot restore a quarantined file through EMS quarantine management if FortiClient (Windows) registered as onboarding user.

817061

Redeploying from another EMS server causes FortiClient (Windows) to not reconnect to EMS automatically.

819552

After upgrading FortiClient with EMS local onboarding user with LDAP, FortiClient (Windows) prompts for registration authentication.

821024

FortiClient fails to send username to EMS, causing EMS to report it as different users.

827200

EMS displays no user for some devices.

833717

EMS shows endpoints as offline, while they show their own status as online.

834162

LDAP query for AD group check does not execute.

841764 EMS does not show third party features in endpoint information.
855851 EMS remembered list shows many FQDN duplicates.
868230 Connection expiring due to FortiClient Connect license exceeded error occurs.
880167 FortiClient (Windows) cannot register with EMS due to selecting wrong interface to connect to EMS.

899960

FortiESNAC process may stop after switching between two FortiSASE Endpoint Management Services.

Endpoint management

Bug ID Description
760816 Group assignment rules based on IP addresses do not work when using split tunnel.

GUI

Bug ID Description
767998 Free VPN-only client includes Action for invalid EMS certificate in settings.

811742

FortiClient (Windows) does not hide software update options when registered to EMS (regression).

826895

FortiClient ignores the listing order of the configured VPN connections in the GUI and tray.

827394

FortiClient does not report profile change update in Notifications.

847903

Console stops working on Citrix servers with ntdll.dll crash.

871005

GUI has display issue with certificates that contains non ASCII characters.

Install and upgrade

Bug ID

Description

749331 Windows Security setting in Windows displays FortiClient is snoozed when FortiEDR is installed.

769639

FortiDeviceGuard is not installed on Windows Server 2022.

820672 Zero trust network access (ZTNA) driver FortiTransCtrl.sys fails to start on Windows Server 2016.

867982

Blank certificate pops up when upgrading.

900228 On Windows 11 22H2, FortiClient upgrade deployment reboots immediately without asking user when to schedule upgrade regardless of EMS configuration.

Zero Trust tags

Bug ID Description
782394 ZTNA user identity tags do not work.

819120

Zero trust tag rule for AD group does not work when registering FortiClient to EMS with onboarding user.

872794 AD group tag Evaluate on FortiClient feature does not work.

Configuration

Bug ID

Description

730415

FortiClient backs up configuration that is missing locally configured ZTNA connection rules.

User and authentication

Bug ID

Description

765184 RADIUS authentication failover between two servers for high availability does not work well.

Performance

Bug ID

Description

749348 Performance issues after upgrade.

778651

Large downloads and speed tests result in high latency, packet loss, and poor performance.

Zero Trust Telemetry

Bug ID

Description

683542 FortiClient (Windows) fails to register to EMS if registration key contains a special character: " !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~".

792703

FortiClient (Windows) cannot connect to FortiClient Cloud.

Malware Protection and Sandbox

Bug ID

Description

760073 FortiDeviceGuard could not be installed on Windows Server through installer.
793926 FortiShield blocks spoolsv.exe on Citrix virtual machine servers.

825732

SIM-card-slot UEFI feature slows down Windows logon when connected to VPN.

828862

FortiClient does not allow virtual CD-ROM device.

831560

GUI shows ransomware quarantined files after restoration via EMS.

833264 Antiexploit blocks Chrome browser without sharing payload details.
837638 Identifying malware and exploits using signatures received from FortiSandbox does not work.
844988 FortiClient (Windows) does not block USB drive if attempting to copy contents even if WPD/USB is set to be blocked in profile.
857041 Windows 10 security center popup shows both FortiClient and Windows Defender are turned off.
863802 EMS and FortiClient (Windows) cannot detect SentinelOne even if they have product on operating system level.
872970 Bubble notifications do not appear when inserting USB drive in endpoint machine.

876925

Antiexploit protection blocks Microsoft Signing application in Chrome.

Remote Access

Bug ID

Description

727695

FortiClient (Windows) on Windows 10 fails to block SSL VPN when it has a prohibit host tag applied.

728240

SSL VPN negate split tunnel IPv6 address does not work.

728244

Negate split tunnel IPv4 address does not work for dual stack mode using IPv6 access.

730756

For SSL VPN dual stack, GUI only shows IPv4 address.

736353 Multigateway failover does not go back to check previous gateways when failing over to see if they are up.
743106 IPsec VPN XAuth does not work with ECDSA certificates.

744597

SSL VPN disconnects and returns hostcheck timeout after 15 to 20 minutes of connection.

755105

When VPN is up, changes for IP properties-> Register this connection's IP to DNS are not restored after VM reboot from power off.

755482

Free VPN-only client does not show token box on rekey and GUI open.

758424

Certificate works for IPsec VPN tunnel if put it in current user store but fails to work if in local machine.

762986

FortiClient (Windows) does not use second FortiGate to connect to resilient tunnel from FortiTray if it cannot reach first remote gateway.

764863 Dialup IPsec VPN over IPv6 drops packets on inbound direction once FortiClient (Windows) establishes tunnel.

772108

When no_dns_registration=1,Register This Connection's Address in DNS of NW IP properties is not selected after VPN is up.

773920 Endpoint switches network connection after IPsec VPN connection and causes VPN to disconnect.

775633

Automatic failover to second remote gateway does not work when using priority-based IPsec VPN resiliency tunnel.

783412 Browser traffic goes directly to ZTNA site when SSL VPN is connected.
790021 Multifactor authentication using Okta with email notification does not work.
792131 FortiClient (Windows) users report issues with the Save Password feature for SSL VPN.

793893

FortiClient search domains transfer incorrectly to endpoints.

794110

VPN before logon does not work with Okta multifactor authentication and enforcing acceptance of the disclaimer message.

795334

Always up feature does not work as expected when trying to connect to VPN from tray.

800453 SSL VPN with certificate authentication fails to connect on OS start.

801875

FortiClient cannot connect to VPN when there are two gateways listed using SAML.

814488

SSL VPN with <on_os_start_connect> enabled does not work when the machine is put into sleep mode and changes networks.

815528

If allow_local_lan=0 and per-application split tunnel with exclude mode and full tunnel are configured, FortiClient (Windows) should block local RDP/HTTPS traffic.

816826

FortiClient (Windows) has issue with SAML with ErrorCode=-6005 when it reaches 31%.

818155

FortiClient (Windows) sends SAML response to a different IP address than the request it received from.

821879

VPN autoconnect does not work with IKEv2 IPsec VPN and user certificates.

824298

SSL VPN with certificates cannot connect to VPN on Elitebook 850 G5/Elitebook 850 G3 laptops.

824674 After connecting to VPN tunnel with VPN before logon enabled, FortiClient tray icon menu shows Connect to [VPN name] instead of Disconnect.

825365

Disconnecting from VPN does not restore Register this connection's IP to DNS.

829084

Redundant sort method does not work with redundant SAML authentication.

835042

After upgrading FortiClient (Windows), OpenVPN connection fails while FortiClient (Windows) VPN runs with application-based split tunnel enabled.

838030

Citrix application shows blank pages on SSL VPN tunnel.

838231 Users cannot connect to VPN when using SAML authentication with SSL VPN.
841144 Users disconnect from VPN after screen locks on endpoint.
841641 File/print server stops replying to pings.
841970 GUI gets stuck while connecting SAML SSL VPN with Azure AD and Duo multifactor authentication.
843122 Daily error (-6005) occurs with SAML SSL VPN.
847990 Network adapter keeps DNS registration disabled after FortiClient disconnects from SSL VPN.

848389

FortiClient fails to autoconnect to VPN for personal VPN profile.

850494 VPN fails to connect at 98% to hotspot/Wi-Fi when dual stack is enabled.
851093 IPv6 DNS requests do not work.
851600 FortiClient fails to connect to SSL VPN with FQDN resolving to multiple IP addresses when it could not reach resolved IP address.
852507 When connecting to SSL VPN using FortiSSLVPNclient.exe, the VPN adapter IP address is incorrect.
853368 The assigned SSL VPN IP address appears in GUI but is not assigned to SSL VPN FortiClient virtual interface.
854237 FortiClient fails to connect at 98% when connecting to hot spot/Wi-Fi when dual stack is enabled on gateway device.
858696 FortiClient cannot connect to SSL VPN with SAML via satellite Internet service provider.
858806 IKE/IPsec VPN sends the same token code multiple times within a second.
859061 Azure autologin does not work.
861231 VPN tunnel with on_os_start enabled does not start on Windows Server.
863138 TapiSrv does not run.
869362 FortiClient (Windows) has issues with multiple reconnections without reauthentication.
869477 When it fails a self test, FortiClient (Windows) does not enter FIPS error mode and shut down completely.

869577

FortiClient only adds FQDN route every second or third disconnect/reconnect.

869862

FortiSSLVPNclient.exe does not correctly use predfined VPN profiles for corporate or personal VPNs.

870087

Windows feature DeadGatewayDetection does bypass default route via VPN.

871346

When using SAML login with built-in browser, FortiAuthenticator, saved password and autoconnect selected, FortiClient (Windows) cannot remember username and password.

871374

SAML login does not display user warning when opening multiple connection with Limit Users to One SSL-VPN Connection at a Time.

874208

FortiClient cannot dial up SSL VPN tunnel with ECDSA certificate.

877640

If FortiClient is registered to EMS, option to connect to IPsec VPN on OS start fails to work.

877917

FortiClient Cloud SSL VPN is stuck at 40% to connect with FortiProxy enabled.

878070

FortiClient (Windows) intermittently grays out SAML button after device wakes from sleep.

878880

VPN drops between FortiClient and FortiGate if Dead Peer Detection is selected.

885285

SSL VPN network profile is public instead of domain.

887631

Using closest gateway based on TCP round trip time for IPsec VPN resilience does not work if ping is disabled for first gateway.

888602

Autoconnect does not work when based on ping speed/TCP round trip to choose closest FortiGate if FortiClient cannot reach first gateway.

890293

FortiClient cannot trigger self-test when connecting to SSL VPN in FIPS error mode.

890352

IPsec VPN for FIPS-enabled FortiClient fails to work when EMS-pushed IPsec/SSL VPN tunnel contains application split tunnel settings.

891164

FortiClient does not handle EMS-pushed IPsec VPN configuration of encryption/authentication/DH group that FortiClient FIPS does not support.

891202

Autoconnect only when off-fabric does not work properly with user account and MFA with FortiToken for xAuth.

892581

Right click to connect to SSL VPN shows host check error.

Vulnerability Scan

Bug ID

Description

741241 FortiClient (Windows) finds vulnerabilities for uninstalled software.

795393

EMS does not remove vulnerability events after successful patch.

849485 FortiClient wrongly detects AnyDesk vulnerabilities CVE-2021-44426 and CVE-2021-44425.

859508

FortiClient detects wrong vulnerability in patched AutoCAD software.

869253

FortiClient detects vulnerability when the required KB is installed.

Logs

Bug ID

Description

820067 FortiClient forwards logs despite being completely disabled.

849043

SSL VPN add/close action does not show on FortiGate Endpoint Event section.

857784

FortiClient (Windows) cannot send OS logs/system events to FortiAnalyzer.

Web Filter and plugin

Bug ID Description

776089

FortiClient (Windows) does not block malicious sites when Web Filter is disabled.

789017 Web Filter is enabled on FortiSASE profile on EMS when it is already enforced through FortiOS.

812207

Blocked web client shows dropped connection message instead of URL blocked message.

825633

Error revokes certificate accessing outlook.office365.com using Web Filter.

826697 Web Filter affects ConnectWise Automate.
829265 Microsoft Teams offline error occurs in SB 6211.
836906 After FortiClient install, extended uptime results in audio cracking.
870895 Web Filter blocks Docker pull.
871325 Web Filter breaks DW Spectrum.

Avatar and social network login

Bug ID

Description

802471 <enable_manually_entering> parameter does not work.

830117

EMS fails to update email address for endpoint from personal information form in FortiClient (Windows).

878050 Avatar does not update on FortiGate dashboards and FortiGate cannot show updated information.

Multitenancy

Bug ID

Description

780308 EMS automatically migrates endpoints to default site.

ZTNA connection rules

Bug ID

Description

735494

Windows 7 does not support TCP forwarding feature.

773956

FortiClient (Windows) cannot show normal webpage of Internet real server (Dropbox) with ZTNA.

814953

Using an external browser for SSH ZTNA requires restarting FortiClient on Windows 11.

830135 Hosts file becomes empty after disconnecting/reconnecting to EMS multiple times and with fresh install of FortiClient (Windows).

831943

ZTNA client certificate is not removed from user certificate store after FortiClient uninstall.

836246

Going from off-Fabric to on-Fabric does not stop the ZTNA service and keeps endpoint from connecting.

839589

ZTNA TCP forwarding does not work for Goanywhere application.

860430

ZTNA web server displays certificate error when browsing inside of application.

FSSOMA

Bug ID

Description

851036 FortiClient (Windows) does not send IP address using mobility agent to FortiAuthenticator when on-premise.
861953 FortiClient single-sign on mobility agent (FSSOMA) does not send ID to FortiAuthenticator.
862021 Local account can access Internet if FSSOMA is logged in and AD user locks the screen.

Onboarding

Bug ID

Description

811976

FortiClient (Windows) may prioritize using user information from authentication user registered to EMS.

819989

FortiClient (Windows) does not show login prompt when installed with installer using LDAP/local verification.

License

Bug ID

Description

830899 FortiClient connected to EMS loses license.
874676 EMS tags endpoint with existing ZTNA host tags for vulnerability and AV after EMS administrator updates EMS license from Endpoint Protection Platform to Remote Access.

Other

Bug ID

Description

780651 FortiClient (Windows) does not update signatures on expected schedule.
834389 FortiClient (Windows) has incompatibility with Fuji Nexim software.

861070

FortiClient (Windows) allows user to end FortiClient (Windows) processes when FortiShield is running/

865938

FortiClient causes RPC service unavailable error and blank screen when trying to use Remote Desktop Protocol connection to the server.

Known issues

The following issues have been identified in FortiClient (Windows) 7.0.8. For inquiries about a particular bug or to report a bug, contact Customer Service & Support.

Application Firewall

Bug ID Description
717628 Application Firewall causes issues with Motorola RMS high availability client.

776007

Application Firewall conflict with Windows firewall causes issues updating domain group policies.

814391

FortiClient Cloud application signatures block allowlisted applications.

844997 FortiClient sees several packet losses on different internal resources after connecting telemetry.

823292

FortiClient cannot connect to JVC wireless display.

827788

Threat ID is 0 on Firewall Events.

853451

FortiClient blocks PIA VPN.

853808

FortiClient (Windows) blocks Veeam with messages related to Remote.CMD.Shell and VeeamAgent.exe.

860062

Application Firewall slows down opening Microsoft Active Directory (AD) Users and Computers application.

Endpoint control

Bug ID Description

753151

Updating endpoint status from endpoint notified to deployed takes a long time.

779267 FortiClient (Windows) does not get updated profile and does not sync.
780130 FortiClient (Windows) fails or takes long time to get updated Endpoint Control profile from EMS.

804552

FortiClient shows all feature tabs without registering to EMS after upgrade.

816751

Administrator cannot restore a quarantined file through EMS quarantine management if FortiClient (Windows) registered as onboarding user.

817061

Redeploying from another EMS server causes FortiClient (Windows) to not reconnect to EMS automatically.

819552

After upgrading FortiClient with EMS local onboarding user with LDAP, FortiClient (Windows) prompts for registration authentication.

821024

FortiClient fails to send username to EMS, causing EMS to report it as different users.

827200

EMS displays no user for some devices.

833717

EMS shows endpoints as offline, while they show their own status as online.

834162

LDAP query for AD group check does not execute.

841764 EMS does not show third party features in endpoint information.
855851 EMS remembered list shows many FQDN duplicates.
868230 Connection expiring due to FortiClient Connect license exceeded error occurs.
880167 FortiClient (Windows) cannot register with EMS due to selecting wrong interface to connect to EMS.

899960

FortiESNAC process may stop after switching between two FortiSASE Endpoint Management Services.

Endpoint management

Bug ID Description
760816 Group assignment rules based on IP addresses do not work when using split tunnel.

GUI

Bug ID Description
767998 Free VPN-only client includes Action for invalid EMS certificate in settings.

811742

FortiClient (Windows) does not hide software update options when registered to EMS (regression).

826895

FortiClient ignores the listing order of the configured VPN connections in the GUI and tray.

827394

FortiClient does not report profile change update in Notifications.

847903

Console stops working on Citrix servers with ntdll.dll crash.

871005

GUI has display issue with certificates that contains non ASCII characters.

Install and upgrade

Bug ID

Description

749331 Windows Security setting in Windows displays FortiClient is snoozed when FortiEDR is installed.

769639

FortiDeviceGuard is not installed on Windows Server 2022.

820672 Zero trust network access (ZTNA) driver FortiTransCtrl.sys fails to start on Windows Server 2016.

867982

Blank certificate pops up when upgrading.

900228 On Windows 11 22H2, FortiClient upgrade deployment reboots immediately without asking user when to schedule upgrade regardless of EMS configuration.

Zero Trust tags

Bug ID Description
782394 ZTNA user identity tags do not work.

819120

Zero trust tag rule for AD group does not work when registering FortiClient to EMS with onboarding user.

872794 AD group tag Evaluate on FortiClient feature does not work.

Configuration

Bug ID

Description

730415

FortiClient backs up configuration that is missing locally configured ZTNA connection rules.

User and authentication

Bug ID

Description

765184 RADIUS authentication failover between two servers for high availability does not work well.

Performance

Bug ID

Description

749348 Performance issues after upgrade.

778651

Large downloads and speed tests result in high latency, packet loss, and poor performance.

Zero Trust Telemetry

Bug ID

Description

683542 FortiClient (Windows) fails to register to EMS if registration key contains a special character: " !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~".

792703

FortiClient (Windows) cannot connect to FortiClient Cloud.

Malware Protection and Sandbox

Bug ID

Description

760073 FortiDeviceGuard could not be installed on Windows Server through installer.
793926 FortiShield blocks spoolsv.exe on Citrix virtual machine servers.

825732

SIM-card-slot UEFI feature slows down Windows logon when connected to VPN.

828862

FortiClient does not allow virtual CD-ROM device.

831560

GUI shows ransomware quarantined files after restoration via EMS.

833264 Antiexploit blocks Chrome browser without sharing payload details.
837638 Identifying malware and exploits using signatures received from FortiSandbox does not work.
844988 FortiClient (Windows) does not block USB drive if attempting to copy contents even if WPD/USB is set to be blocked in profile.
857041 Windows 10 security center popup shows both FortiClient and Windows Defender are turned off.
863802 EMS and FortiClient (Windows) cannot detect SentinelOne even if they have product on operating system level.
872970 Bubble notifications do not appear when inserting USB drive in endpoint machine.

876925

Antiexploit protection blocks Microsoft Signing application in Chrome.

Remote Access

Bug ID

Description

727695

FortiClient (Windows) on Windows 10 fails to block SSL VPN when it has a prohibit host tag applied.

728240

SSL VPN negate split tunnel IPv6 address does not work.

728244

Negate split tunnel IPv4 address does not work for dual stack mode using IPv6 access.

730756

For SSL VPN dual stack, GUI only shows IPv4 address.

736353 Multigateway failover does not go back to check previous gateways when failing over to see if they are up.
743106 IPsec VPN XAuth does not work with ECDSA certificates.

744597

SSL VPN disconnects and returns hostcheck timeout after 15 to 20 minutes of connection.

755105

When VPN is up, changes for IP properties-> Register this connection's IP to DNS are not restored after VM reboot from power off.

755482

Free VPN-only client does not show token box on rekey and GUI open.

758424

Certificate works for IPsec VPN tunnel if put it in current user store but fails to work if in local machine.

762986

FortiClient (Windows) does not use second FortiGate to connect to resilient tunnel from FortiTray if it cannot reach first remote gateway.

764863 Dialup IPsec VPN over IPv6 drops packets on inbound direction once FortiClient (Windows) establishes tunnel.

772108

When no_dns_registration=1,Register This Connection's Address in DNS of NW IP properties is not selected after VPN is up.

773920 Endpoint switches network connection after IPsec VPN connection and causes VPN to disconnect.

775633

Automatic failover to second remote gateway does not work when using priority-based IPsec VPN resiliency tunnel.

783412 Browser traffic goes directly to ZTNA site when SSL VPN is connected.
790021 Multifactor authentication using Okta with email notification does not work.
792131 FortiClient (Windows) users report issues with the Save Password feature for SSL VPN.

793893

FortiClient search domains transfer incorrectly to endpoints.

794110

VPN before logon does not work with Okta multifactor authentication and enforcing acceptance of the disclaimer message.

795334

Always up feature does not work as expected when trying to connect to VPN from tray.

800453 SSL VPN with certificate authentication fails to connect on OS start.

801875

FortiClient cannot connect to VPN when there are two gateways listed using SAML.

814488

SSL VPN with <on_os_start_connect> enabled does not work when the machine is put into sleep mode and changes networks.

815528

If allow_local_lan=0 and per-application split tunnel with exclude mode and full tunnel are configured, FortiClient (Windows) should block local RDP/HTTPS traffic.

816826

FortiClient (Windows) has issue with SAML with ErrorCode=-6005 when it reaches 31%.

818155

FortiClient (Windows) sends SAML response to a different IP address than the request it received from.

821879

VPN autoconnect does not work with IKEv2 IPsec VPN and user certificates.

824298

SSL VPN with certificates cannot connect to VPN on Elitebook 850 G5/Elitebook 850 G3 laptops.

824674 After connecting to VPN tunnel with VPN before logon enabled, FortiClient tray icon menu shows Connect to [VPN name] instead of Disconnect.

825365

Disconnecting from VPN does not restore Register this connection's IP to DNS.

829084

Redundant sort method does not work with redundant SAML authentication.

835042

After upgrading FortiClient (Windows), OpenVPN connection fails while FortiClient (Windows) VPN runs with application-based split tunnel enabled.

838030

Citrix application shows blank pages on SSL VPN tunnel.

838231 Users cannot connect to VPN when using SAML authentication with SSL VPN.
841144 Users disconnect from VPN after screen locks on endpoint.
841641 File/print server stops replying to pings.
841970 GUI gets stuck while connecting SAML SSL VPN with Azure AD and Duo multifactor authentication.
843122 Daily error (-6005) occurs with SAML SSL VPN.
847990 Network adapter keeps DNS registration disabled after FortiClient disconnects from SSL VPN.

848389

FortiClient fails to autoconnect to VPN for personal VPN profile.

850494 VPN fails to connect at 98% to hotspot/Wi-Fi when dual stack is enabled.
851093 IPv6 DNS requests do not work.
851600 FortiClient fails to connect to SSL VPN with FQDN resolving to multiple IP addresses when it could not reach resolved IP address.
852507 When connecting to SSL VPN using FortiSSLVPNclient.exe, the VPN adapter IP address is incorrect.
853368 The assigned SSL VPN IP address appears in GUI but is not assigned to SSL VPN FortiClient virtual interface.
854237 FortiClient fails to connect at 98% when connecting to hot spot/Wi-Fi when dual stack is enabled on gateway device.
858696 FortiClient cannot connect to SSL VPN with SAML via satellite Internet service provider.
858806 IKE/IPsec VPN sends the same token code multiple times within a second.
859061 Azure autologin does not work.
861231 VPN tunnel with on_os_start enabled does not start on Windows Server.
863138 TapiSrv does not run.
869362 FortiClient (Windows) has issues with multiple reconnections without reauthentication.
869477 When it fails a self test, FortiClient (Windows) does not enter FIPS error mode and shut down completely.

869577

FortiClient only adds FQDN route every second or third disconnect/reconnect.

869862

FortiSSLVPNclient.exe does not correctly use predfined VPN profiles for corporate or personal VPNs.

870087

Windows feature DeadGatewayDetection does bypass default route via VPN.

871346

When using SAML login with built-in browser, FortiAuthenticator, saved password and autoconnect selected, FortiClient (Windows) cannot remember username and password.

871374

SAML login does not display user warning when opening multiple connection with Limit Users to One SSL-VPN Connection at a Time.

874208

FortiClient cannot dial up SSL VPN tunnel with ECDSA certificate.

877640

If FortiClient is registered to EMS, option to connect to IPsec VPN on OS start fails to work.

877917

FortiClient Cloud SSL VPN is stuck at 40% to connect with FortiProxy enabled.

878070

FortiClient (Windows) intermittently grays out SAML button after device wakes from sleep.

878880

VPN drops between FortiClient and FortiGate if Dead Peer Detection is selected.

885285

SSL VPN network profile is public instead of domain.

887631

Using closest gateway based on TCP round trip time for IPsec VPN resilience does not work if ping is disabled for first gateway.

888602

Autoconnect does not work when based on ping speed/TCP round trip to choose closest FortiGate if FortiClient cannot reach first gateway.

890293

FortiClient cannot trigger self-test when connecting to SSL VPN in FIPS error mode.

890352

IPsec VPN for FIPS-enabled FortiClient fails to work when EMS-pushed IPsec/SSL VPN tunnel contains application split tunnel settings.

891164

FortiClient does not handle EMS-pushed IPsec VPN configuration of encryption/authentication/DH group that FortiClient FIPS does not support.

891202

Autoconnect only when off-fabric does not work properly with user account and MFA with FortiToken for xAuth.

892581

Right click to connect to SSL VPN shows host check error.

Vulnerability Scan

Bug ID

Description

741241 FortiClient (Windows) finds vulnerabilities for uninstalled software.

795393

EMS does not remove vulnerability events after successful patch.

849485 FortiClient wrongly detects AnyDesk vulnerabilities CVE-2021-44426 and CVE-2021-44425.

859508

FortiClient detects wrong vulnerability in patched AutoCAD software.

869253

FortiClient detects vulnerability when the required KB is installed.

Logs

Bug ID

Description

820067 FortiClient forwards logs despite being completely disabled.

849043

SSL VPN add/close action does not show on FortiGate Endpoint Event section.

857784

FortiClient (Windows) cannot send OS logs/system events to FortiAnalyzer.

Web Filter and plugin

Bug ID Description

776089

FortiClient (Windows) does not block malicious sites when Web Filter is disabled.

789017 Web Filter is enabled on FortiSASE profile on EMS when it is already enforced through FortiOS.

812207

Blocked web client shows dropped connection message instead of URL blocked message.

825633

Error revokes certificate accessing outlook.office365.com using Web Filter.

826697 Web Filter affects ConnectWise Automate.
829265 Microsoft Teams offline error occurs in SB 6211.
836906 After FortiClient install, extended uptime results in audio cracking.
870895 Web Filter blocks Docker pull.
871325 Web Filter breaks DW Spectrum.

Avatar and social network login

Bug ID

Description

802471 <enable_manually_entering> parameter does not work.

830117

EMS fails to update email address for endpoint from personal information form in FortiClient (Windows).

878050 Avatar does not update on FortiGate dashboards and FortiGate cannot show updated information.

Multitenancy

Bug ID

Description

780308 EMS automatically migrates endpoints to default site.

ZTNA connection rules

Bug ID

Description

735494

Windows 7 does not support TCP forwarding feature.

773956

FortiClient (Windows) cannot show normal webpage of Internet real server (Dropbox) with ZTNA.

814953

Using an external browser for SSH ZTNA requires restarting FortiClient on Windows 11.

830135 Hosts file becomes empty after disconnecting/reconnecting to EMS multiple times and with fresh install of FortiClient (Windows).

831943

ZTNA client certificate is not removed from user certificate store after FortiClient uninstall.

836246

Going from off-Fabric to on-Fabric does not stop the ZTNA service and keeps endpoint from connecting.

839589

ZTNA TCP forwarding does not work for Goanywhere application.

860430

ZTNA web server displays certificate error when browsing inside of application.

FSSOMA

Bug ID

Description

851036 FortiClient (Windows) does not send IP address using mobility agent to FortiAuthenticator when on-premise.
861953 FortiClient single-sign on mobility agent (FSSOMA) does not send ID to FortiAuthenticator.
862021 Local account can access Internet if FSSOMA is logged in and AD user locks the screen.

Onboarding

Bug ID

Description

811976

FortiClient (Windows) may prioritize using user information from authentication user registered to EMS.

819989

FortiClient (Windows) does not show login prompt when installed with installer using LDAP/local verification.

License

Bug ID

Description

830899 FortiClient connected to EMS loses license.
874676 EMS tags endpoint with existing ZTNA host tags for vulnerability and AV after EMS administrator updates EMS license from Endpoint Protection Platform to Remote Access.

Other

Bug ID

Description

780651 FortiClient (Windows) does not update signatures on expected schedule.
834389 FortiClient (Windows) has incompatibility with Fuji Nexim software.

861070

FortiClient (Windows) allows user to end FortiClient (Windows) processes when FortiShield is running/

865938

FortiClient causes RPC service unavailable error and blank screen when trying to use Remote Desktop Protocol connection to the server.