Known issues
The following issues have been identified in version 6.2.2. For inquires about a particular bug or to report a bug, please contact Customer Service & Support.
Anti Virus
Bug ID |
Description |
---|---|
590092 |
Cannot clear |
594696 |
Sample file eicar.exe cannot pass through SMTPS, POP3S, or IMAPS with deep inspection and flow enabled on IPv6 policy. |
Data Leak Prevention
Bug ID |
Description |
---|---|
586689 | Downloading a file with FTP client in EPSV mode will hang. |
591178 |
WAD fails to determine the correct file name when downloading a file from Nextcloud. |
DNS Filter
Bug ID |
Description |
---|---|
583449 |
DNS filter explicit block all (wildcard FQDN) not working in 6.2 firmware. |
582374 |
License shows expiry date of |
586526 |
Unable to change DNS filter profile category action after upgrading from 6.0.5 to 6.2.0. |
Explicit Proxy
Bug ID |
Description |
---|---|
504011 |
FortiGate does not generate traffic logs for SOCKS proxy. |
540091 |
Cannot access explicit FTP proxy via VIP. |
588211 |
WAD cannot learn policy if multiple policies use the same FQDN address. |
590942 |
AV does not forward reply when GET for FTP over HTTP is used. |
594580 |
FTP traffic over HTTP explicit proxy does not generate traffic logs once receiving error message. |
605209 |
LDAP ignores |
Firewall
Bug ID |
Description |
---|---|
584451 |
NGFW default block page partially loads. |
FortiView
Bug ID |
Description |
---|---|
582341 |
On Policies page, consolidated policies are without names and tooltips; tooltips not working for security policies. |
GUI
Bug ID |
Description |
---|---|
282160 |
GUI does not show byte info for aggregate and VLAN interface. |
354464 |
Antivirus archive logging enabled from the CLI will be disabled by editing the antivirus profile in the GUI, even if no changes are made. |
438298 | When VDOM is enabled, the interface faceplate should only show data for interfaces managed by the admin. |
467495 |
A message stating that all source interfaces have no members is erroneously displayed for the explicit proxy policy list when a user enables a policy immediately after pasting or inserting it into the list. |
480731 |
Interface filter get incorrect result (EMAC VLAN, VLAN ID, etc.) when entries are collapsed. |
502962 |
Get "Fail to retrieve info" for default VDOM link on the GUI Interfaces page. |
510685 |
Hardware Switch Row is shown, indicating a number of interfaces but without any interfaces below. |
514632 |
Inconsistent reference count when using ports in HA |
529094 |
When creating an antispam block/allow list entry, Mark as Reject should be grayed out. |
535099 |
The SSID dialog page does not have support for the new MAC address filter. |
537307 |
Gets "Fail to retrieve info" for |
540098 |
GUI does not display the status for VLAN and loopback under status column at Network > interfaces. |
541042 |
Log viewer forwarded traffic does not support multiple filters for one field. |
542544 |
In Log & Report, filtering for blank values (None) always show no results. |
559866 |
When sending CSF proxied request, |
560206 |
Change/remove FortiCloud standalone reference. |
565748 |
New interface pair consolidated policy added via CLI is not displayed on GUI policy page. |
573456 | FortiGate without disk Email Alert Settings page should remove Disk usage exceeds option. |
574101 |
Empty firmware version in managed FortiSwitch from FortiGate GUI. |
579711 | An error occurs while running Security Rating. |
583049 |
Internal Server Error while trying to create new interface. |
582658 |
Email filter page keeps loading and cannot create a new profile when the VDOM admin only has |
584419 |
Application and filter overrides issues. |
584939 |
VPN event logs shows incorrectly when adding two action filters and if the filter action filter contains "-". |
586749 |
Enable/disable Disarm and Reconstruction on GUI only takes effect on SMTP protocol in AV profile. |
587091 |
When logged in as administrator with web filter read/write only privilege, the Web Rating Overrides GUI page cannot load. |
588222 |
WAN Opt. Monitor displays Total Savings as negative integers during file transfers. |
588665 |
Option to reset statistics from Monitor > WAN Opt. Monitor in GUI does not clear the counters. |
599401 |
FortiGuard quota category details displays No matching entries found for local category. |
HA
Bug ID |
Description |
---|---|
479780 | Primary unit fails to send and receive HA heartbeat on config cfg-revert setting on FGT2500E. |
540632 |
In HA, executing reboot. |
575020 |
HA failing config sync on VM01 with error (primary and secondary have different hdisk status) when primary is pre-configured. |
581906 |
HA secondary unit sending out GARP packets in 16-20 seconds after HA monitored interface failed. |
588908 |
FG-3400E |
590931 |
Multiple PPPoE connections on a single interface does not sync PPPoE dynamic assigned IP and cannot start re-negotiation. |
602406 |
In a FortiGate HA cluster, performance SLA (SD-WAN) information does not sync with the secondary unit. |
Intrusion Prevention
Bug ID |
Description |
---|---|
565747 |
IPS engine 5.00027 has several singal 11 crashes on QA_FW. |
586544 |
IPS intelligent mode not working when reflect sessions are created on different physical interfaces. |
586608 |
The CPU consumption of ipsengine gets high with customer configuration file. |
587668 |
IPS engine 5.00035 has signal 11 crash. |
590087 |
When IPS pcap is enabled, traffic is intermittently disrupted after disk I/O reaches IOPS limit. |
608501 |
IPS forwards attacks that are previously identified as dropped. |
IPsec VPN
Bug ID |
Description |
---|---|
582251 | IKEv2 with eap auth peerid validation doesn't work.
|
584982 |
The customer is unable to log in to VPN with RADIUS intermittently. |
Log & Report
Bug ID |
Description |
---|---|
580887 |
No traffic log after reducing miglogd child to 1. |
586038 | VPN tunnel durations are too long in the local reports for FortiOS 6.0.6. |
590598 |
Log viewer application control cannot show any logs (page is stuck loading) . |
590852 |
Log filter can return empty result when there are too many logs, but the filter result is small. |
591523 |
When refreshing logs in GUI, some |
593557 |
Logs to syslog server configured with FQDN addresses fail when the DNS entry gets updated for the FQDN address. |
593907 |
Miglogd still uses the daylight savings time after the daylight savings end. |
602459 |
GUI shows 401 Unauthorized error when downloading forward traffic logs with the time stamp as the filter criterion. |
606533 |
User observes |
Proxy
Bug ID |
Description |
---|---|
573028 | WAD crashes causing traffic interruption. |
580592 |
Policy in proxy-based mode with AV and WAF profile denies access to Nginx with enabled gzip compression. |
582475 |
WAD is crashing with signal 6 in |
587214 |
WAD crash for |
587987 |
In case of TLS 1.3 with certificate inspection and a certificate with an empty CN name, WAD workers would locate a random size for CN name and then cause unexpected high memory usage in WAD workers. |
592153 |
Potential memory leak that will be triggered by certificate inspection CIC connection in WAD. |
594237 |
Slow download speed in proxy-based mode compared to flow-based mode. |
596012 |
Receive SSL fatal alert with source IP 0.0.0.0. |
REST API
Bug ID |
Description |
---|---|
584631 | REST API admin with token unable to configure HA setting (via login session can work). |
Routing
Bug ID |
Description |
---|---|
587700 |
Routing monitor policy view cannot show source and destination data for SD-WAN route and wildcard destination. |
593864 |
Routing table is not always updated when BGP gets an update with changed next hop. |
594685 |
Unable to create the IPsec VPN directly in Network > SD-WAN. |
595937 |
PPPoE interface bandwidth is mistakenly calculated as 0 in SD-WAN. |
666829 |
Application bfdd crashes. |
Security Fabric
Bug ID |
Description |
---|---|
586587 |
Security Fabric widget keep loading when FortiSwitch is in a loop or two FortiSwitches are in |
587758 |
Invalid CIDR format shows as valid by Security Fabric threat feed. |
591015 |
ACI SDN connector dynamic address cannot be resolved. |
592344 |
CSF automation configuration cannot be synced to downstream from root. |
SSL VPN
Bug ID |
Description |
---|---|
505986 | On IE 11, SSL VPN web portal displays blank page title {{::data.portal.heading}} after authentication. |
557806 |
Cannot fully load a website through SSL VPN bookmark. |
585754 |
An SSL VPN bookmark failed to load the GUI of |
584780 |
When the SSL VPN portal theme is set to red, the style is lost in the SSL VPN portal. |
587075 |
SAML login is not stable for SSL VPN, it requires restarting sslvpnd to enable the function. |
591613 |
https://outlook.office365.com cannot be accessed in SSLVPN web portal. |
592935 |
sslvpnd crashed on FortiGate. |
593082 |
SSL VPN bookmark does not load Google Maps on internal server. |
593641 |
Cannot access HTTPS bookmark, get a blank page. |
594247 |
Cannot access https://cdn.i-ready.com through SSL VPN web portal. |
596843 |
Internal website not working in SSL VPN web mode. |
597282 |
The latest FortiOS GUI does not render when accessing it by the SSL VPN portal. |
598659 |
SSL VPN daemon crash. |
Switch Controller
Bug ID |
Description |
---|---|
581370 | FortiSwitch managed by FortiGate not updating RADIUS settings and user group in the FortiSwitch. |
586299 |
Adding factory-reset device to HA fails with |
588584 |
GUI should add support to allow using switch VLAN interface under a tenant VDOM on a managed switch VDOM. |
592111 |
FortiSwitch shows offline CAPWAP response packet getting drop/failed after upgrading from 6.2.2. |
System
Bug ID |
Description |
---|---|
464340 | EHP drops for units with no NP_SERVICE_MODULE. |
484749 |
TCP traffic with |
528052 |
FortiGuard filtering services show as unavailable for read-only admin. |
547712 |
HPE does not protect against DDoS attacks like flood on IKE and BGP destination ports. |
556408 |
Aggregate link does not work for LACP mode active for 60E internal ports, but works for wan1 and wan2 combination. |
570759 |
RX/TX counters for VLAN interfaces based on LACP interface are 0. |
573090 |
Making a change to a policy with inline editing is very slow with large table sizes. |
573973 |
ASIC offloading sessions sticking to interfaces after SD-WAN SLA interface selection. |
578031 |
FortiManager Cloud cannot be removed once the FortiGate has trouble on contract. |
581998 |
Session clash event log found on FG-6500F when passing a lot of same source IP ICMP traffic over Load balance VIP. |
583602 |
Script to purge and re-create a local-in-policy ran against the remote FortiGate directly (in the CLI) is causing auto-update issues. |
586301 |
GUI cannot show default Fortinet logo for replacement messages. |
588202 |
FortiGate returns invalid configuration during FortiManager retrieving configuration. |
589234 |
|
589978 |
|
589517 |
Dedicated management CPU running on high CPU (soft IRQ). |
590295 |
OID for the IPsec VPN phase 2 selector only displays the first one on the list. |
592827 |
FortiGate is not sending DHCP request after receiving offer. |
594157 |
FortiGate accepts invalid configuration from FortiManager. |
594499 |
Communication over PPPoE fails after installing PPPoE configuration from FortiManager. |
595338 |
Unable to execute |
595467 |
Invalid multicast policy created after transparent VDOM restored. |
596180 |
Constant DHCPD crashes. |
602548 |
Some of the clients are not getting their IP through DHCP intermittently. |
603551 |
DHCPv6 relay does not work on FG-2200E. |
604550 |
Locally-originated DHCP relay traffic on non-default VRF may follow route on VRF 0. |
694202 |
|
Upgrade
Bug ID |
Description |
---|---|
586793 |
Address objects have reference to old firewall policy after upgrading from 6.0.6 > 6.2.x NGFW policies. |
User & Device
Bug ID |
Description |
---|---|
587666 |
Mobile token authentication does not work for SSL VPN on SOC3 platforms. Affected models include: FG-60E, FG-60E-POE, FG-61E, FG-80E, FG-80E-POE, FG-81E, FG-81E-POE, FG-100E, FG-100EF, FG-101E, FG-140E, FWF-60E, FWF-61E. |
592253 |
RADIUS state attribute truncated in access request when using third-party MFA (ping ID). |
593116 |
Client PC matching multiple authentication methods (firewall, FSSO, RSSO, WSSO) may not be matched to NGFW policies correctly. |
595583 |
Device identification via LLDP on an aggregate interface does not work. |
597496 |
Guest user log in expires after first log in and no longer works; user is not removed from the firewall authentication list after the set time. |
605404 |
FortiGate does not respond to disclaimer page request when traffic hits a disclaimer-enabled policy with thousands of address objects. |
VM
Bug ID |
Description |
---|---|
575346 |
|
577653 |
vMotion tasks cause connections to be dropped as sessions related to vMotion VMs do not appear on the destination VMX. |
579708 |
Should replace GUI option to register to FortiCare from AWS PAYG with link to portal for registration. |
582123 |
EIP does not failover if the primary FortiGate is rebooted or stopped from the Alibaba Cloud console. |
586954 |
FGCP cluster member reboots in infinite loop and |
587757 |
FG-VM image unable to be deployed on AWS with additional disk of type HDD(st1). |
588436 |
Azure SDN connector unable to connect to Azure Kubernetes integrated with AAD. |
590140 |
FG-VM-LENC unable to validate new license. |
590149 |
Azure FortiGate crashing frequently when MLX4 driver RX jumbo fail. |
590253 |
VLAN not working on fgtvm-hv on hyper-v. |
590780 |
Azure FortiGate-VM (BYOL) unable to boot up when loading a lower vCPU license than the instance's vCPU. |
591563 |
Azure autoscale not syncing after upgrading to 6.2.2. |
592000 |
Alibaba Cloud: multiple VPC route entries fail to switch when HA fails over. |
596430 |
If |
596742 |
Azure SDN connector replicates configuration from primary unit to secondary unit during configuration restore. |
598419 |
Static routes are not in sync on FortiGate Azure. |
VoIP
Bug ID |
Description |
---|---|
599117 |
VoIPd process crash. |
601275 |
MGCP session helper does not NAT the MGCP body. |
Web Filter
Bug ID |
Description |
---|---|
560904 |
In NGFW mode, Security Profiles GUI is missing Web Rating Overrides page. |
WiFi Controller
Bug ID |
Description |
---|---|
520677 |
When editing a FortiAP profile on the FortiGate web UI, the previously selected SSID group(s) cannot be displayed. |
555659 | When FAP is managed across
VDOM links, WiFi client can't join SSID when auto-asic-offload is enabled. |
567011 |
WPA2-Enterprise SSID should support |
567933 |
FAP unable to connect to FortiGate via IPsec VPN tunnel with DTLS policy (clear text). |
572350 |
FortiOS GUI cannot support FAP-U431F and FAP-U433F profiles. Workaround: Edit the |
587586 |
cw_acd crashes multiple times. |
595653 |
FortiGate in transparent mode cannot manage FortiAP devices successfully. |