Fortinet black logo

FortiGate-6000 and FortiGate-7000 Release Notes

Known issues

Known issues

The following issues have been identified in FortiGate-6000 and FortiGate-7000 FortiOS 6.2.13 Build 1272. For inquires about a particular bug, please contact Customer Service & Support. The Known issues described in the FortiOS 6.2.13 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.2.13 Build 1272.

Bug ID

Description

822621

HA synchronization problems discovered during configuration synchronization stress testing. The stress test involved repeatedly deleting and adding VDOMs.

823129

The FortiGate-7121F does not load balance ICMPv6 non-0x80/81 traffic as expected. All ICMPv6 non-0x80/81 traffic should be forwarded to the primary FPM. But, for example, ICMPv6 non 0x80/0x81 traffic received by a VLAN added to a LAG is broadcast to all FPMs. The same traffic received by a VLAN added to a physical interface is forwarded to the primary FPM as expected.

866440

Some transceiver information may not be available for some supported transceivers installed in FortiGate-6000 and 7000E QSFP28 interfaces.

888046

After an FGCP HA failover, dialup IPsec VPN tunnel kernel routes may not be available on the new primary FortiGate. The dialup tunnels could still be up, but no traffic can pass through them because the routes are missing. You can work around this problem by entering the command diagnose vpn ike gateway clear name <tunnel-name> for each currently up dialup tunnel. This will bring the tunnel down, and when it comes back up the route will be added to the kernel routing table.

Known issues

The following issues have been identified in FortiGate-6000 and FortiGate-7000 FortiOS 6.2.13 Build 1272. For inquires about a particular bug, please contact Customer Service & Support. The Known issues described in the FortiOS 6.2.13 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.2.13 Build 1272.

Bug ID

Description

822621

HA synchronization problems discovered during configuration synchronization stress testing. The stress test involved repeatedly deleting and adding VDOMs.

823129

The FortiGate-7121F does not load balance ICMPv6 non-0x80/81 traffic as expected. All ICMPv6 non-0x80/81 traffic should be forwarded to the primary FPM. But, for example, ICMPv6 non 0x80/0x81 traffic received by a VLAN added to a LAG is broadcast to all FPMs. The same traffic received by a VLAN added to a physical interface is forwarded to the primary FPM as expected.

866440

Some transceiver information may not be available for some supported transceivers installed in FortiGate-6000 and 7000E QSFP28 interfaces.

888046

After an FGCP HA failover, dialup IPsec VPN tunnel kernel routes may not be available on the new primary FortiGate. The dialup tunnels could still be up, but no traffic can pass through them because the routes are missing. You can work around this problem by entering the command diagnose vpn ike gateway clear name <tunnel-name> for each currently up dialup tunnel. This will bring the tunnel down, and when it comes back up the route will be added to the kernel routing table.