Resolved issues
The following issues have been fixed in version 6.2.3. For inquires about a particular bug, please contact Customer Service & Support.
Anti Virus
Bug ID |
Description |
---|---|
590092 |
Cannot clear |
Data Leak Prevention
Bug ID |
Description |
---|---|
586689 |
Downloading a file with FTP client in EPSV mode will hang. |
591676 |
Enable file filter password protected blocked for 7Z, RAR, PDF, MSOffice, and MSOfficeX. |
DNS Filter
Bug ID |
Description |
---|---|
561297 |
DNS filtering does not perform well on the zone transfer when a large DNS zone's AXFR response consists of one or more messages. |
563441 |
7K DNS filter breaking DNS zone transfer. |
574980 |
DNS translation is not working when request is checked against the local FortiGate. |
583449 |
DNS filter explicit block all (wildcard FQDN) not working in 6.2 firmware. |
586178 |
In domain threat feed, some URLs cannot be fetched due to SSL error. |
586526 |
Unable to change DNS filter profile category action after upgrading from 6.0.5 to 6.2.0. |
586834 |
With |
Explicit Proxy
Bug ID |
Description |
---|---|
504011 |
FortiGate does not generate traffic logs for SOCKS proxy. |
588211 |
WAD cannot learn policy if multiple policies use the same FQDN address. |
589065 |
FSSO-based NTLM sessions from explicit proxy do not respect timeout duration and type. |
589811 |
|
590942 |
AV does not forward reply when GET for FTP over HTTP is used. |
Firewall
Bug ID |
Description |
---|---|
508015 |
Editing a policy in the GUI changes the FSSO setting to disable. |
558996 |
FortiGate sends type-3 code-1 IP unreachable for VIP. |
583173 |
Policy push from FortiManager failed due to abandoned ISDB entry. |
584451 |
NGFW default block page partially loads. |
585073 |
Adding too many address objects to a local-in policy causes all blocking to fail. |
585122 |
Should not be allowed to rename VIP or address with the same name as an existing VIP group or address group object. |
590039 |
Samsung OEM internet browser cannot connect to FortiGate VS/VIP. |
597110 |
When creating a firewall address with the |
FortiView
Bug ID |
Description |
---|---|
582341 |
On Policies page, consolidated policies are without names and tooltips; tooltips not working for security policies. |
GUI
Bug ID |
Description |
---|---|
282160 |
GUI does not show byte information for aggregate and VLAN interface. |
303651 |
Should hide Override internal DNS option if |
438298 |
When VDOM is enabled, the interface faceplate should only show data for interfaces managed by the admin. |
451306 |
Add a tooltip for IPS Rate Based Signatures. |
460698 |
There is no uptime information in the HA Status widget for the secondary unit's GUI. |
467495 |
A message stating that all source interfaces have no members is erroneously displayed for the explicit proxy policy list when a user enables a policy immediately after pasting or inserting it into the list. |
478472 |
Options 150, 15, and 51 for the DHCP server should not be shown after removing them and having no related configuration in the backend. |
480731 |
Interface filter gets incorrect result (EMAC VLAN, VLAN ID, etc.) when entries are collapsed. |
482437 |
SD-WAN member number is not correct in Interfaces page. |
493527 |
Compliance events GUI page does not load when redirected from the advanced compliance page. |
498892 |
GUI shows wrong relationship between VLAN and physical interface after adding them to a zone. |
499658 |
Editing |
502962 |
Get "Fail to retrieve info" for default VDOM link on Network > Interfaces page. |
505066 |
Not possible to select value for DN field in LDAP GUI browser. |
510685 |
Hardware Switch row is shown indicating a number of interfaces but without any interfaces below. |
514027 |
Cannot disable CORS setting on GUI. |
519102 |
GUI navigation menu notification should match with issue in the dialog box. |
525535 |
OK button greyed out when editing an interface that has DHCP option 224 in the list with FortiClient-On-Net Status enabled. |
531376 |
Get "Internal Server Error" when editing an aggregate link that has a name with a space in it. |
534853 |
Suggest GUI Interfaces list includes SIT tunnels. |
536718 |
Cannot change MAC address setting when configuring a reserved DHCP client. |
536843 |
LACP aggregate interface flaps when adding/removing a member interface (first position in member list). |
537307 |
"Failed to retrieve info" message appears for |
538125 |
Hovering mouse over FortiExtender virtual interface shows incorrect information. |
540098 |
GUI does not display the status for VLAN and loopback in the Network > Interfaces > Status column. |
542544 |
In Log & Report, filtering for blank values (None) always shows no results. |
544442 |
Virtual IPs page should not show port range dialog box when the protocol is ICMP. |
547409 |
Admin with |
552811 |
Scripts pushed from FortiCloud do not show up in System > Advanced Settings when FortiCloud remote access is used. |
553290 |
The tooltip for VLAN interfaces displays as "Failed to retrieve info". |
555687 |
Network mask of a VPN interface is changed to 255.255.255.255 without an actual configuration change. |
559866 |
When sending CSF proxied request, segfault happens (httpsd crashes) if FortiExplorer accesses root FortiGate via the management tunnel. |
560206 |
Change/remove FortiCloud standalone reference. |
563053 |
Warning messages for third-party transceivers were removed in 6.2.1 to prevent excessive RMA or support tickets. In 6.2.2, warnings were re-added for third-party transceivers. |
565748 |
New interface pair consolidated policy added via CLI is not displayed on GUI policy page. |
566414 |
Application Name field shows |
567369 |
Cannot save DHCP Relay configuration when the Relay IP address list is separated by a comma. |
571909 |
SSL VPN Settings page shows undefined error. |
573456 |
FortiGate without disk email alert settings page should remove Disk usage exceeds option. |
573862 |
Signature name should be shown when VDOM admin has WAF read/write permission only. |
574101 |
Empty firmware version in managed FortiSwitch from FortiGate GUI. |
580168 |
Connected routes in the routing monitor are showing up with 1969/12/31 18:59:59 for Up Since times. |
582658 |
Email filter page keeps loading and cannot create a new profile when the VDOM admin only has |
582716 |
Filtering service availability check always fails once anycast is enabled and override server is set. |
583049 |
Internal server error while trying to create a new interface. |
584419 |
Issue with application and filter overrides. |
584426 |
Add Selected button does not show up under FSSO Fabric Connector with custom admin profile. |
584560 |
GUI does not have the option to disable the interface when creating a VLAN interface. |
584949 |
When the link status is up, the aggregate interface status icon is incorrectly displayed in red. |
586604 |
No matching IPS signatures are found when Severity or Target filter is applied. |
586749 |
Enable/disable Disarm and Reconstruction in the GUI only affects the SMTP protocol in AV profiles. |
587091 |
When logged in as administrator with web filter read/write only privilege, the Web Rating Overrides GUI page cannot load. |
587673 |
The Interface Pair View option is always unavailable for the Proxy Policy list. |
587686 |
Wrong warning message, All source interface(s) has no members, appears in Proxy Policy page. |
588028 |
If the Endpoint Control feature is disabled, the exempt options for captive portal are not shown in the GUI. |
588222 |
WAN Opt. Monitor displays Total Savings as negative integers during file transfers. |
588665 |
Option to reset statistics from Monitor > WAN Opt. Monitor in GUI does not clear the counters. |
589085 |
Web filter profile warning message when logged in with read/write admin on VDOM environment. |
592244 |
VIPs dialog page should be able to create VIP with the same extip/extport but different source IP address. |
593433 |
DHCP offset option 2 has to be removed before changing the address range for the DHCP server in the GUI. |
594162 |
Interface hierarchy is not respected in the GUI when a LAG interface belongs to SD-WAN and its VLANs belong to a zone. |
594565 |
Wrong Sub-Category appears in the Edit Web Rating Override page. |
HA
Bug ID |
Description |
---|---|
479780 |
Secondary unit fails to send and receive HA heartbeat when configuring |
540632 |
In HA, |
575020 |
HA failing |
581906 |
HA secondary unit sending out GARP packets in 16-20 seconds after HA monitored interface failed. |
585348 |
|
585675 |
|
586004 |
Moving VDOM via GUI between virtual clusters causes cluster to go out of sync and VDOM state work/standby does not change. |
586835 |
HA secondary unit unable to get checksum from primary unit. HA sync in |
590931 |
Multiple PPPoE connections on a single interface does not sync PPPoE dynamic assigned IP and cannot start re-negotiation. |
Intrusion Prevention
Bug ID |
Description |
---|---|
540718 |
Signal 14 alarm crashes were observed on DFA rebuild. |
579018 |
IPS engine 5.030 signal 14 alarm clock crash at |
586608 |
The CPU consumption of ipsengine gets high with customer configuration file. |
IPsec VPN
Bug ID |
Description |
---|---|
577502 |
OCVPN cannot register—status "Undefined". |
582251 |
IKEv2 with EAP peer ID authentication validation does not work. |
582876 |
ADVPN connections from the hub disconnects one-by-one and IKE gets stuck. |
584982 |
The customer is unable to log in to VPN with RADIUS intermittently. |
Log & Report
Bug ID |
Description |
---|---|
578057 |
Action field in traffic log cannot record security policy action—it shows the consolidated policy action. |
580887 |
No traffic log after reducing miglogd child to 1. |
586038 |
FortiOS 6.0.6 reports too long VPN tunnel durations in local report. |
586854 |
FortiGate sends change notice for global REST APIs once a minute. |
590598 |
Log viewer application control cannot show any logs (page is stuck loading). |
590852 |
Log filter can return empty result when there are too many logs, but the filter result is small. |
591152 |
IPS logs set |
591523 |
When refreshing logs in GUI, some |
593907 |
Miglogd still uses the daylight savings time after the daylight savings end. |
596278 |
|
596398 |
|
599860 |
When |
Proxy
Bug ID |
Description |
---|---|
525328 |
External resource does not support no content length. |
549660 |
WAD crash with signal 11. |
573028 |
WAD crash causing traffic interruption. |
579400 |
High CPU with |
580592 |
Policy in proxy-based mode with AV and WAF profile denies access to Nginx with enabled gzip compression. |
584719 |
WAD reads f |
587214 |
WAD crash for |
587987 |
In case of TLS 1.3 with certificate inspection and a certificate with an empty CN name, WAD workers would locate a random size for CN name and then cause unexpected high memory usage in WAD workers. |
592153 |
Potential memory leak that will be triggered by certificate inspection CIC connection in WAD. |
593365 |
WAD crash due to user learned from proxy not purged from the kernel when user is deleted from proxy or zone with empty interface member. |
594237 |
Slow download speed in proxy-based mode compared to flow-based mode. |
594725 |
WAD memory leak detected on |
596012 |
Receive SSL fatal alert with source IP 0.0.0.0. |
REST API
Bug ID |
Description |
---|---|
587470 | REST API to support revision flag. |
Routing
Bug ID |
Description |
---|---|
371453 |
OSPF translated type 5 LSA not flushed according to RFC-3101. |
524229 |
SD-WAN |
570686 |
FortiOS 6.2.1 introduces asymmetric return path on the hub in SD-WAN after the link change due to SLA on the spoke. |
582078 |
ISDB ID is changed after restoring the configuration under the situation where the FortiGate has a previous ISDB version. |
584095 |
SD-WAN option of |
584477 |
In transparent mode with asymmetric routing, packet in the reply direction does not use asymmetric route. |
585027 |
There is no indication in |
585325 |
IPv6 route cannot be inactive after |
587198 |
After failover/recovery of link, E2 route with non-zero forward address recurses to itself as a next hope. |
587700 |
Routing monitor policy view cannot show source and destination data for SD-WAN route and wildcard destination. |
587970 |
SD-WAN rules |
589620 |
Link monitor with tunnel as |
592599 |
FortiGate sends malformed OSPFv3 LSAReq/LSAck packets on interfaces with MTU = 9k. |
593375 |
OSPF NSSA with multiple ASBRs losing valid external OSPF routes in upstream neighbors as different ASBRs are power cycled. |
593864 |
Routing table is not always updated when BGP gets an update with changed next hop. |
594685 |
Unable to create the IPsec VPN directly in Network > SD-WAN. |
595937 |
PPPoE interface bandwidth is mistakenly calculated as 0 in SD-WAN. |
Security Fabric
Bug ID |
Description |
---|---|
575495 |
FGCP dynamic objects are not populated in the secondary unit. |
586587 |
Security Fabric widget keeps loading when FortiSwitches are in a loop, or the FortiSwitch is in MCLAG mode. |
587758 |
Invalid CIDR format shows as valid by the Security Fabric threat feed. |
589503 |
Threat Feeds show the URL is invalid if there is a special character in the URL. |
591015 |
ACI SDN connector dynamic address cannot be resolved. |
592344 |
CSF automation configuration cannot be synced to downstream from root. |
SSL VPN
Bug ID |
Description |
---|---|
525342 |
In some special cases, SSL VPN main state machine reads function pointer is empty that will cause SSL VPN daemon crash. |
557806 |
Cannot fully load a website through SSL VPN bookmark. |
570171 |
When accessing ACT application through SSL VPN web mode, the embedded calendar request gets wrong response and redirects to login page. |
573787 |
SSL VPN web mode not displaying custom web application's JavaScript parts. |
576288 |
FSSO groups set in rule with SSL VPN interface. |
578908 |
Fails to load bookmark site over SSL VPN portal. |
580377 |
Unable to access https://outlook.office365.com as bookmark in SSL VPN web mode. |
583339 |
Support HSTS |
584780 |
When the SSL VPN portal theme is set to red, the style is lost in the SSL VPN portal. |
585754 |
A VPN SSL bookmark failed to load the Proxmox GUI interface. |
586032 |
Unable to download report from an internal server via SSL VPN web mode connection. |
586035 |
The policy |
587075 |
SAML login is not stable for SSL VPN, it requires restarting |
587117 |
SSL handshake failure with Server Architect in web mode. |
588119 |
There is no OS support for the latest macOS Catalina version (10.15) when using SSL VPN tunnel mode. |
588720 |
SSL VPN web portal bookmarks cannot resolve |
589015 |
SSO does not correctly URL-encode POST-ed credentials. |
590643 |
|
591613 |
https://outlook.office365.com cannot be accessed in SSLVPN web portal. |
592318 |
After |
592935 |
sslvpnd crashed on FortiGate. |
593082 |
SSL VPN bookmark does not load Google Maps on internal server. |
593641 |
Cannot access HTTPS bookmark, get a blank page. |
593850 |
SSL VPN logs out after some users click through the remote application. |
594160 |
Screen shot feature is not working though SSL VPN portal. |
594247 |
Cannot access https://cdn.i-ready.com through SSL VPN web portal. |
595920 |
SSL VPN web mode goes to 99% on a specific bookmark. |
596273 |
sslvpnd worker process crashes, causing a zombie tunnel session. |
596843 |
Internal website not working in SSL VPN web mode. |
597282 |
The latest FortiOS GUI does not render when accessing it by the SSL VPN portal. |
Switch Controller
Bug ID |
Description |
---|---|
581370 |
FortiSwitch managed by FortiGate not updating the RADIUS settings and user group in the FortiSwitch. |
586299 |
Adding factory-reset device to HA fails with |
592111 |
FortiSwitch shows offline CAPWAP response packet getting dropped/failed after upgrading from 6.2.2. |
System
Bug ID |
Description |
---|---|
484749 |
TCP traffic with |
502387 |
X.509 certificate support required for FGFM portocol. |
511790 |
Router info does not update after plugging out/plugging in USB modem. |
528052 |
FortiGuard filtering services show as unavailable for read-only admin. |
534806 |
FGR-30D cannot add ports SFP1 and SFP2 on a virtual hardware switch. |
547712 |
HPE does not protect against DDoS attacks like flood on IKE and BGP destination ports. |
556408 |
Aggregate link does not work for LACP mode active for FG-60E internal ports but works for wan1 and wan2 combination. |
570759 |
RX/TX counters for VLAN interfaces based on LACP interface are 0. |
572003 |
There was a hardware defect in an earlier revision of SSD used for FG-61E. When powering off then powering on in a very short time, the SSD may jump into ROM mode and cannot recover until a power circle. |
573090 |
Making a change to a policy through inline editing is very slow with large table sizes. |
573238 |
Session TTL expiry timer is not reset for VLAN traffic when offloading is enabled. |
573973 |
ASIC offloading sessions sticking to interfaces after SD-WAN SLA interface selection. |
576054 |
Missing |
577423 |
FG-80D and FG-92D kernel error in CLI during FortiGate boot up. |
578259 |
FG-3980E VLANs over LAG interface show no TX/RX statistics. |
578608 |
High CPU usage due to dnsproxy process as high at 99%. |
580038 |
Problems with cmdbsvr while handling a large number of FSSO address groups and security policies. |
581496 |
FG-201E stops sending out packets and NP6lite is stuck. |
581528 |
SSH/RDP sessions are terminated unexpectedly. |
581998 |
Session clash event log found on FG-6500F when passing a lot of the same source IP ICMP traffic over load-balance VIP. |
582520 |
Enabling offloading drops fragmented packets. |
583199 |
|
583602 |
Script to purge and re-create a local-in-policy ran against the remote FortiGate directly (in the CLI) is causing auto-update issues. |
585841 |
Console outputs |
586042 |
NTPD does not requery the DNS server unless it restarts. |
586301 |
GUI cannot show default Fortinet logo for replacement messages. |
586551 |
When an SD-WAN member is disabled or VWL is disabled, |
587498 |
FortiGate sends ICMP type 3 code 3 (port unreachable) for UDP 500 and UDP 520 against vulnerability scan. |
587540 |
NetFlow traffic records sent with wrong interface index 0 ( |
587952 |
|
588035 |
Kernel crashes when sniffing packets on interfaces that are related to EMAC VLAN. |
588202 |
FortiGate returns invalid configuration during FortiManager retrieving configuration. |
589027 |
EMAC VLAN drops traffic when asymmetric roue enabled on internet VDOM. |
589234 |
Local system DNS setting instead of DNS setting acquired from upstream DHCP server was assigned to client under management VDOM. |
589517 |
Dedicated management CPU running on high CPU (soft IRQ). |
589978 |
|
590295 |
OID for the IPsec VPN phase 2 selector only displays the first one on the list. |
591466 |
Cannot change the mask for an existing secondary IP on interfaces. |
592787 |
FortiGate got rebooted automatically due to kernel crash. |
593606 |
|
594157 |
FortiGate accepts invalid configuration from FortiManager. |
594499 |
Communication over PPPoE fails after installing PPPoE configuration from FortiManager. |
595598 |
SOC4 devices may reboot by watchdog after upgrading to FortiOS 6.2.2 (build 6083). Affected platforms: FG-60F, FG-61F, FG-100F, and FG-101F. |
596180 |
Constant DHCPD crashes. |
596421 |
FG-3400E/FG-3600E link is up on 25G ports only when the FEC is disabled on the Ixia tester. |
Upgrade
Bug ID |
Description |
---|---|
586793 |
Address objects have reference to old firewall policy after upgrading from 6.0.6 > 6.2.x NGFW policies. |
User & Device
Bug ID |
Description |
---|---|
567831 |
Local FSSO poller regularly missing logon events. |
583745 |
Wrong categorization of OS from device detection. |
586334 |
Brief connectivity loss on shared service when RDP session is logged in to from local device. |
586394 |
Authentication list entry is not created/updated after changing the client PC with another user in FSSO polling mode. |
587293 |
The session to the SQL database is closed as |
587519 |
fnbamd takes high CPU usage and user not able to authenticate. |
587666 |
Mobile token authentication does not work for SSL VPN on SOC3 platforms. Affected models include: FG-60E, FG-60E-POE, FG-61E, FG-80E, FG-80E-POE, FG-81E, FG-81E-POE, FG-100E, FG-100EF, FG-101E, FG-140E, FWF-60E, FWF-61E. |
592241 |
Gmail POP3 authentication fails with certificate error since version 6.0.5. |
592253 |
RADIUS state attribute truncated in access request when using third-party MFA (ping ID). |
593116 |
Client PC matching multiple authentication methods (firewall, FSSO, RSSO, WSSO) may not be matched to NGFW policies correctly. |
597496 |
Guest user log in expires after first log in and no longer works; user is not removed from the firewall authentication list after the set time. |
VM
Bug ID |
Description |
---|---|
571212 |
Only one CPU core in AWS is being used for traffic processing. |
577653 |
vMotion tasks cause connections to be dropped as sessions related to vMotion VMs do not appear on the destination VMX. |
579708 |
Should replace GUI option to register to FortiCare from AWS PAYG with link to portal for registration. |
582123 |
EIP does not failover if the primary FortiGate is rebooted or stopped from the Alibaba Cloud console. |
586954 |
FGCP cluster member reboots in infinite loop and |
588436 |
Azure SDN connector unable to connect to Azure Kubneretes integrated with AAD. |
589445 |
VM deployed in ESX platform with VMXNET3 does not show the correct speed and duplex settings. |
590140 |
FG-VM-LENC unable to validate new license. |
590149 |
Azure FortiGate crashing frequently when MLX4 driver RX jumbo. |
590253 |
VLAN not working on FortiGate in a Hyper-V deployment. |
590555 |
Allow PAYG AWS VM to bootstrap the configuration first before acquiring FortiCare license. |
590780 |
Azure FortiGate-VM (BYOL) unable to boot up when loading a lower vCPU license than the instance's vCPU. |
591563 |
Azure autoscale not syncing after upgrading to 6.2.2. |
592000 |
In Alibaba Cloud, multiple VPC route entries fail to switch when HA fails over. |
592611 |
HA not fully failing over when using OCI. |
593797 |
FG-VM64-AWS not responding to ICMP6 request when destination IPv6 address is in the neighbor cache entry. |
596430 |
If |
VoIP
Bug ID |
Description |
---|---|
582271 |
Add support for Cisco IP Phone keepalive packet. |
Web Filter
Bug ID |
Description |
---|---|
560904 |
In NGFW mode, Security Profiles GUI is missing Web Rating Overrides page. |
581523 |
Wrong web filter category when using flow-based inspection. |
587120 |
Administrator logged in with web filter read/write privilege cannot create or edit web filter profiles in the GUI. |
590599 |
In flow mode web filter, a certificate warning is triggered when a site redirects HTTP request to HTTPS and if |
WiFi Controller
Bug ID |
Description |
---|---|
520677 |
When editing a FortiAP profile on the FortiGate web UI, the previously selected SSID group(s) cannot be displayed. |
555659 |
When FortiAP is managed with cross VDOM links, the WiFi client cannot join to SSID when |
566054 |
Errors pop up while creating or editing as SSID. |
567011 |
WPA2-Enterprise SSID should support |
567933 |
FortiAP unable to connect to FortiGate via IPsec VPN tunnel with |
572350 |
FortiOS GUI cannot support FAP-U431F and FAP-U433F profiles. |
580169 |
Captive portal (disclaimer) redirect not working for Android phones. |
587586 |
|
Common Vulnerabilities and Exposures
Visit https://fortiguard.com/psirt for more information.
Bug ID |
CVE references |
---|---|
568788 |
FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:
|
576090 |
FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:
|
576941 |
FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:
|
581663 |
FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:
|