Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in version 6.2.3. For inquires about a particular bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

590092

Cannot clear scanunit vdom-stats to reset the statistics on ATP widget.

Data Leak Prevention

Bug ID

Description

586689

Downloading a file with FTP client in EPSV mode will hang.

591676

Enable file filter password protected blocked for 7Z, RAR, PDF, MSOffice, and MSOfficeX.

DNS Filter

Bug ID

Description

561297

DNS filtering does not perform well on the zone transfer when a large DNS zone's AXFR response consists of one or more messages.

563441

7K DNS filter breaking DNS zone transfer.

574980

DNS translation is not working when request is checked against the local FortiGate.

583449

DNS filter explicit block all (wildcard FQDN) not working in 6.2 firmware.

586178

In domain threat feed, some URLs cannot be fetched due to SSL error.

586526

Unable to change DNS filter profile category action after upgrading from 6.0.5 to 6.2.0.

586834

With option error-allow DNS attempts fail when FortiGuard servers are unavailable.

Explicit Proxy

Bug ID

Description

504011

FortiGate does not generate traffic logs for SOCKS proxy.

588211

WAD cannot learn policy if multiple policies use the same FQDN address.

589065

FSSO-based NTLM sessions from explicit proxy do not respect timeout duration and type.

589811

urfilter process does not started when adding a category as dstaddr in a proxy policy with the deny action.

590942

AV does not forward reply when GET for FTP over HTTP is used.

Firewall

Bug ID

Description

508015

Editing a policy in the GUI changes the FSSO setting to disable.

558996

FortiGate sends type-3 code-1 IP unreachable for VIP.

583173

Policy push from FortiManager failed due to abandoned ISDB entry.

584451

NGFW default block page partially loads.

585073

Adding too many address objects to a local-in policy causes all blocking to fail.

585122

Should not be allowed to rename VIP or address with the same name as an existing VIP group or address group object.

590039

Samsung OEM internet browser cannot connect to FortiGate VS/VIP.

597110

When creating a firewall address with the associated-interface setting, CMD gets stuck if there is a large nested address group.

FortiView

Bug ID

Description

582341

On Policies page, consolidated policies are without names and tooltips; tooltips not working for security policies.

GUI

Bug ID

Description

282160

GUI does not show byte information for aggregate and VLAN interface.

303651

Should hide Override internal DNS option if vdom-dns is set to disable.

438298

When VDOM is enabled, the interface faceplate should only show data for interfaces managed by the admin.

451306

Add a tooltip for IPS Rate Based Signatures.

460698

There is no uptime information in the HA Status widget for the secondary unit's GUI.

467495

A message stating that all source interfaces have no members is erroneously displayed for the explicit proxy policy list when a user enables a policy immediately after pasting or inserting it into the list.

478472

Options 150, 15, and 51 for the DHCP server should not be shown after removing them and having no related configuration in the backend.

480731

Interface filter gets incorrect result (EMAC VLAN, VLAN ID, etc.) when entries are collapsed.

482437

SD-WAN member number is not correct in Interfaces page.

493527

Compliance events GUI page does not load when redirected from the advanced compliance page.

498892

GUI shows wrong relationship between VLAN and physical interface after adding them to a zone.

499658

Editing system interface in the GUI causes explicit-web-proxy to become disabled.

502962

Get "Fail to retrieve info" for default VDOM link on Network > Interfaces page.

505066

Not possible to select value for DN field in LDAP GUI browser.

510685

Hardware Switch row is shown indicating a number of interfaces but without any interfaces below.

514027

Cannot disable CORS setting on GUI.

519102

GUI navigation menu notification should match with issue in the dialog box.

525535

OK button greyed out when editing an interface that has DHCP option 224 in the list with FortiClient-On-Net Status enabled.

531376

Get "Internal Server Error" when editing an aggregate link that has a name with a space in it.

534853

Suggest GUI Interfaces list includes SIT tunnels.

536718

Cannot change MAC address setting when configuring a reserved DHCP client.

536843

LACP aggregate interface flaps when adding/removing a member interface (first position in member list).

537307

"Failed to retrieve info" message appears for ha-mgmt-interface in Network > Interfaces.

538125

Hovering mouse over FortiExtender virtual interface shows incorrect information.

540098

GUI does not display the status for VLAN and loopback in the Network > Interfaces > Status column.

542544

In Log & Report, filtering for blank values (None) always shows no results.

544442

Virtual IPs page should not show port range dialog box when the protocol is ICMP.

547409

Admin with netgrp privilege unable to get interface page and got pyfcgid crash (signal 11 (Segmentation fault)).

552811

Scripts pushed from FortiCloud do not show up in System > Advanced Settings when FortiCloud remote access is used.

553290

The tooltip for VLAN interfaces displays as "Failed to retrieve info".

555687

Network mask of a VPN interface is changed to 255.255.255.255 without an actual configuration change.

559866

When sending CSF proxied request, segfault happens (httpsd crashes) if FortiExplorer accesses root FortiGate via the management tunnel.

560206

Change/remove FortiCloud standalone reference.

563053

Warning messages for third-party transceivers were removed in 6.2.1 to prevent excessive RMA or support tickets. In 6.2.2, warnings were re-added for third-party transceivers.

565748

New interface pair consolidated policy added via CLI is not displayed on GUI policy page.

566414

Application Name field shows vuln_id for custom signature, not its application name in logs.

567369

Cannot save DHCP Relay configuration when the Relay IP address list is separated by a comma.

571909

SSL VPN Settings page shows undefined error.

573456

FortiGate without disk email alert settings page should remove Disk usage exceeds option.

573862

Signature name should be shown when VDOM admin has WAF read/write permission only.

574101

Empty firmware version in managed FortiSwitch from FortiGate GUI.

580168

Connected routes in the routing monitor are showing up with 1969/12/31 18:59:59 for Up Since times.

582658

Email filter page keeps loading and cannot create a new profile when the VDOM admin only has emailfilter permission.

582716

Filtering service availability check always fails once anycast is enabled and override server is set.

583049

Internal server error while trying to create a new interface.

584419

Issue with application and filter overrides.

584426

Add Selected button does not show up under FSSO Fabric Connector with custom admin profile.

584560

GUI does not have the option to disable the interface when creating a VLAN interface.

584949

When the link status is up, the aggregate interface status icon is incorrectly displayed in red.

586604

No matching IPS signatures are found when Severity or Target filter is applied.

586749

Enable/disable Disarm and Reconstruction in the GUI only affects the SMTP protocol in AV profiles.

587091

When logged in as administrator with web filter read/write only privilege, the Web Rating Overrides GUI page cannot load.

587673

The Interface Pair View option is always unavailable for the Proxy Policy list.

587686

Wrong warning message, All source interface(s) has no members, appears in Proxy Policy page.

588028

If the Endpoint Control feature is disabled, the exempt options for captive portal are not shown in the GUI.

588222

WAN Opt. Monitor displays Total Savings as negative integers during file transfers.

588665

Option to reset statistics from Monitor > WAN Opt. Monitor in GUI does not clear the counters.

589085

Web filter profile warning message when logged in with read/write admin on VDOM environment.

592244

VIPs dialog page should be able to create VIP with the same extip/extport but different source IP address.

593433

DHCP offset option 2 has to be removed before changing the address range for the DHCP server in the GUI.

594162

Interface hierarchy is not respected in the GUI when a LAG interface belongs to SD-WAN and its VLANs belong to a zone.

594565

Wrong Sub-Category appears in the Edit Web Rating Override page.

HA

Bug ID

Description

479780

Secondary unit fails to send and receive HA heartbeat when configuring cfg-revert setting on FG-2500E.

540632

In HA, management-ip that is set on a hardware switch interface does not respond to ping after executing reboot.

575020

HA failing config sync on VM01 with error (secondary and primary unit have different hdisk status) when primary unit is pre-configured.

581906

HA secondary unit sending out GARP packets in 16-20 seconds after HA monitored interface failed.

585348

default-gateway injected by dynamic-gateway on PPP interface deleted by other interface down.

585675

exe backup disk alllogs ftp command causes FortiGate to enter conserve mode.

586004

Moving VDOM via GUI between virtual clusters causes cluster to go out of sync and VDOM state work/standby does not change.

586835

HA secondary unit unable to get checksum from primary unit. HA sync in Z state.

590931

Multiple PPPoE connections on a single interface does not sync PPPoE dynamic assigned IP and cannot start re-negotiation.

Intrusion Prevention

Bug ID

Description

540718

Signal 14 alarm crashes were observed on DFA rebuild.

579018

IPS engine 5.030 signal 14 alarm clock crash at nturbo_on_event.

586608

The CPU consumption of ipsengine gets high with customer configuration file.

IPsec VPN

Bug ID

Description

577502

OCVPN cannot register—status "Undefined".

582251

IKEv2 with EAP peer ID authentication validation does not work.

582876

ADVPN connections from the hub disconnects one-by-one and IKE gets stuck.

584982

The customer is unable to log in to VPN with RADIUS intermittently.

Log & Report

Bug ID

Description

578057

Action field in traffic log cannot record security policy action—it shows the consolidated policy action.

580887

No traffic log after reducing miglogd child to 1.

586038

FortiOS 6.0.6 reports too long VPN tunnel durations in local report.

586854

FortiGate sends change notice for global REST APIs once a minute.

590598

Log viewer application control cannot show any logs (page is stuck loading).

590852

Log filter can return empty result when there are too many logs, but the filter result is small.

591152

IPS logs set srcintf(role)/dstinf(role) reversely at the time of IPS signature reverse pattern.

591523

When refreshing logs in GUI, some log_se processes are running extremely long and consuming CPU.

593907

Miglogd still uses the daylight savings time after the daylight savings end.

596278

sentdelta and rcvddelta showing 0 if syslog format is set to CSV.

596398

sentdelta and rcvddelta log fields appears as 0 in syslog CEF format.

599860

When logtraffic is set to all, existing sessions cannot change the egress interfaces when the routing table is updated with a new outgoing interface.

Proxy

Bug ID

Description

525328

External resource does not support no content length.

549660

WAD crash with signal 11.

573028

WAD crash causing traffic interruption.

579400

High CPU with authd process caused by WAD paring multiple line content-encoding error and IPC broken between wad and authd.

580592

Policy in proxy-based mode with AV and WAF profile denies access to Nginx with enabled gzip compression.

584719

WAD reads ftp over-limit multi-line response incorrectly.

587214

WAD crash for wad_ssl_port_on_ocsp_notify.

587987

In case of TLS 1.3 with certificate inspection and a certificate with an empty CN name, WAD workers would locate a random size for CN name and then cause unexpected high memory usage in WAD workers.

592153

Potential memory leak that will be triggered by certificate inspection CIC connection in WAD.

593365

WAD crash due to user learned from proxy not purged from the kernel when user is deleted from proxy or zone with empty interface member.

594237

Slow download speed in proxy-based mode compared to flow-based mode.

594725

WAD memory leak detected on cert_hash in wad_ssl_cert.

596012

Receive SSL fatal alert with source IP 0.0.0.0.

REST API

Bug ID

Description

587470 REST API to support revision flag.

Routing

Bug ID

Description

371453

OSPF translated type 5 LSA not flushed according to RFC-3101.

524229

SD-WAN health-check keep records useless logs under some circumstances.

570686

FortiOS 6.2.1 introduces asymmetric return path on the hub in SD-WAN after the link change due to SLA on the spoke.

582078

ISDB ID is changed after restoring the configuration under the situation where the FortiGate has a previous ISDB version.

584095

SD-WAN option of set gateway enable/set default enable override available on connected routes.

584477

In transparent mode with asymmetric routing, packet in the reply direction does not use asymmetric route.

585027

There is no indication in proute if the SD-WAN service is default or not.

585325

IPv6 route cannot be inactive after link-monitor is down when link-monitor are set with ipv4 and ipv6.

587198

After failover/recovery of link, E2 route with non-zero forward address recurses to itself as a next hope.

587700

Routing monitor policy view cannot show source and destination data for SD-WAN route and wildcard destination.

587970

SD-WAN rules route-tag still used in service rule but not in diagnose sys virtual-wan-link route-tag-list.

589620

Link monitor with tunnel as srcintf cannot recover after remote server down/up.

592599

FortiGate sends malformed OSPFv3 LSAReq/LSAck packets on interfaces with MTU = 9k.

593375

OSPF NSSA with multiple ASBRs losing valid external OSPF routes in upstream neighbors as different ASBRs are power cycled.

593864

Routing table is not always updated when BGP gets an update with changed next hop.

594685

Unable to create the IPsec VPN directly in Network > SD-WAN.

595937

PPPoE interface bandwidth is mistakenly calculated as 0 in SD-WAN.

Security Fabric

Bug ID

Description

575495

FGCP dynamic objects are not populated in the secondary unit.

586587

Security Fabric widget keeps loading when FortiSwitches are in a loop, or the FortiSwitch is in MCLAG mode.

587758

Invalid CIDR format shows as valid by the Security Fabric threat feed.

589503

Threat Feeds show the URL is invalid if there is a special character in the URL.

591015

ACI SDN connector dynamic address cannot be resolved.

592344

CSF automation configuration cannot be synced to downstream from root.

SSL VPN

Bug ID

Description

525342

In some special cases, SSL VPN main state machine reads function pointer is empty that will cause SSL VPN daemon crash.

557806

Cannot fully load a website through SSL VPN bookmark.

570171

When accessing ACT application through SSL VPN web mode, the embedded calendar request gets wrong response and redirects to login page.

573787

SSL VPN web mode not displaying custom web application's JavaScript parts.

576288

FSSO groups set in rule with SSL VPN interface.

578908

Fails to load bookmark site over SSL VPN portal.

580377

Unable to access https://outlook.office365.com as bookmark in SSL VPN web mode.

583339

Support HSTS include SubDomains and preload option under SSL VPN settings.

584780

When the SSL VPN portal theme is set to red, the style is lost in the SSL VPN portal.

585754

A VPN SSL bookmark failed to load the Proxmox GUI interface.

586032

Unable to download report from an internal server via SSL VPN web mode connection.

586035

The policy "script-src 'self'" will block the SSL VPN proxy URL.

587075

SAML login is not stable for SSL VPN, it requires restarting sslvpnd to enable the function.

587117

SSL handshake failure with Server Architect in web mode.

588119

There is no OS support for the latest macOS Catalina version (10.15) when using SSL VPN tunnel mode.

588720

SSL VPN web portal bookmarks cannot resolve hostname.

589015

SSO does not correctly URL-encode POST-ed credentials.

590643

href rewrite has some issues with the customer's JS file.

591613

https://outlook.office365.com cannot be accessed in SSLVPN web portal.

592318

After sslvpn proxy, some Kurim JS files run with an error.

592935

sslvpnd crashed on FortiGate.

593082

SSL VPN bookmark does not load Google Maps on internal server.

593641

Cannot access HTTPS bookmark, get a blank page.

593850

SSL VPN logs out after some users click through the remote application.

594160

Screen shot feature is not working though SSL VPN portal.

594247

Cannot access https://cdn.i-ready.com through SSL VPN web portal.

595920

SSL VPN web mode goes to 99% on a specific bookmark.

596273

sslvpnd worker process crashes, causing a zombie tunnel session.

596843

Internal website not working in SSL VPN web mode.

597282

The latest FortiOS GUI does not render when accessing it by the SSL VPN portal.

Switch Controller

Bug ID

Description

581370

FortiSwitch managed by FortiGate not updating the RADIUS settings and user group in the FortiSwitch.

586299

Adding factory-reset device to HA fails with switch-controller.qos settings in root.

592111

FortiSwitch shows offline CAPWAP response packet getting dropped/failed after upgrading from 6.2.2.

System

Bug ID

Description

484749

TCP traffic with tcp_ecn tag cannot go through ipip ipv6 tunnel with NP6 offload enabled.

502387

X.509 certificate support required for FGFM portocol.

511790

Router info does not update after plugging out/plugging in USB modem.

528052

FortiGuard filtering services show as unavailable for read-only admin.

534806

FGR-30D cannot add ports SFP1 and SFP2 on a virtual hardware switch.

547712

HPE does not protect against DDoS attacks like flood on IKE and BGP destination ports.

556408

Aggregate link does not work for LACP mode active for FG-60E internal ports but works for wan1 and wan2 combination.

570759

RX/TX counters for VLAN interfaces based on LACP interface are 0.

572003

There was a hardware defect in an earlier revision of SSD used for FG-61E. When powering off then powering on in a very short time, the SSD may jump into ROM mode and cannot recover until a power circle.

573090

Making a change to a policy through inline editing is very slow with large table sizes.

573238

Session TTL expiry timer is not reset for VLAN traffic when offloading is enabled.

573973

ASIC offloading sessions sticking to interfaces after SD-WAN SLA interface selection.

576054

Missing mpsk-schedules option when restoring configuration via VDOM.

577423

FG-80D and FG-92D kernel error in CLI during FortiGate boot up.

578259

FG-3980E VLANs over LAG interface show no TX/RX statistics.

578608

High CPU usage due to dnsproxy process as high at 99%.

580038

Problems with cmdbsvr while handling a large number of FSSO address groups and security policies.

581496

FG-201E stops sending out packets and NP6lite is stuck.

581528

SSH/RDP sessions are terminated unexpectedly.

581998

Session clash event log found on FG-6500F when passing a lot of the same source IP ICMP traffic over load-balance VIP.

582520

Enabling offloading drops fragmented packets.

583199

fgfmsd crashed with signal 11 when some code accesses a VDOM that has been deleted, but does not check the return value from CMDB query.

583602

Script to purge and re-create a local-in-policy ran against the remote FortiGate directly (in the CLI) is causing auto-update issues.

585841

Console outputs unregister_netdevice error on UoM setup.

586042

NTPD does not requery the DNS server unless it restarts.

586301

GUI cannot show default Fortinet logo for replacement messages.

586551

When an SD-WAN member is disabled or VWL is disabled, snmpwalk shows "No Such Object available on this agent at this OID" message.

587498

FortiGate sends ICMP type 3 code 3 (port unreachable) for UDP 500 and UDP 520 against vulnerability scan.

587540

NetFlow traffic records sent with wrong interface index 0 (inputint = 0 and outputint = 0).

587952

get system inter transceiver reports error for some transceivers.

588035

Kernel crashes when sniffing packets on interfaces that are related to EMAC VLAN.

588202

FortiGate returns invalid configuration during FortiManager retrieving configuration.

589027

EMAC VLAN drops traffic when asymmetric roue enabled on internet VDOM.

589234

Local system DNS setting instead of DNS setting acquired from upstream DHCP server was assigned to client under management VDOM.

589517

Dedicated management CPU running on high CPU (soft IRQ).

589978

alertemail username length cannot go beyond 35 characters.

590295

OID for the IPsec VPN phase 2 selector only displays the first one on the list.

591466

Cannot change the mask for an existing secondary IP on interfaces.

592787

FortiGate got rebooted automatically due to kernel crash.

593606

diagnose hardware test suite all fails due to FortiLink loopback test.

594157

FortiGate accepts invalid configuration from FortiManager.

594499

Communication over PPPoE fails after installing PPPoE configuration from FortiManager.

595598

SOC4 devices may reboot by watchdog after upgrading to FortiOS 6.2.2 (build 6083).

Affected platforms: FG-60F, FG-61F, FG-100F, and FG-101F.

596180

Constant DHCPD crashes.

596421

FG-3400E/FG-3600E link is up on 25G ports only when the FEC is disabled on the Ixia tester.

Upgrade

Bug ID

Description

586793

Address objects have reference to old firewall policy after upgrading from 6.0.6 > 6.2.x NGFW policies.

User & Device

Bug ID

Description

567831

Local FSSO poller regularly missing logon events.

583745

Wrong categorization of OS from device detection.

586334

Brief connectivity loss on shared service when RDP session is logged in to from local device.

586394

Authentication list entry is not created/updated after changing the client PC with another user in FSSO polling mode.

587293

The session to the SQL database is closed as timeout when a new user logs in to terminal server.

587519

fnbamd takes high CPU usage and user not able to authenticate.

587666

Mobile token authentication does not work for SSL VPN on SOC3 platforms.

Affected models include: FG-60E, FG-60E-POE, FG-61E, FG-80E, FG-80E-POE, FG-81E, FG-81E-POE, FG-100E, FG-100EF, FG-101E, FG-140E, FWF-60E, FWF-61E.

592241

Gmail POP3 authentication fails with certificate error since version 6.0.5.

592253

RADIUS state attribute truncated in access request when using third-party MFA (ping ID).

593116

Client PC matching multiple authentication methods (firewall, FSSO, RSSO, WSSO) may not be matched to NGFW policies correctly.

597496

Guest user log in expires after first log in and no longer works; user is not removed from the firewall authentication list after the set time.

VM

Bug ID

Description

571212

Only one CPU core in AWS is being used for traffic processing.

577653

vMotion tasks cause connections to be dropped as sessions related to vMotion VMs do not appear on the destination VMX.

579708

Should replace GUI option to register to FortiCare from AWS PAYG with link to portal for registration.

582123

EIP does not failover if the primary FortiGate is rebooted or stopped from the Alibaba Cloud console.

586954

FGCP cluster member reboots in infinite loop and hatalk daemon dumps the core with segmentation fault.

588436

Azure SDN connector unable to connect to Azure Kubneretes integrated with AAD.

589445

VM deployed in ESX platform with VMXNET3 does not show the correct speed and duplex settings.

590140

FG-VM-LENC unable to validate new license.

590149

Azure FortiGate crashing frequently when MLX4 driver RX jumbo.

590253

VLAN not working on FortiGate in a Hyper-V deployment.

590555

Allow PAYG AWS VM to bootstrap the configuration first before acquiring FortiCare license.

590780

Azure FortiGate-VM (BYOL) unable to boot up when loading a lower vCPU license than the instance's vCPU.

591563

Azure autoscale not syncing after upgrading to 6.2.2.

592000

In Alibaba Cloud, multiple VPC route entries fail to switch when HA fails over.

592611

HA not fully failing over when using OCI.

593797

FG-VM64-AWS not responding to ICMP6 request when destination IPv6 address is in the neighbor cache entry.

596430

If central-management server is set to FortiManager IP address and FortiGuard update-server-location is set to usa, the FOS-VM is able to get web filter license and server list from FortiManager, but the GUI shows the service availability as down.

VoIP

Bug ID

Description

582271

Add support for Cisco IP Phone keepalive packet.

Web Filter

Bug ID

Description

560904

In NGFW mode, Security Profiles GUI is missing Web Rating Overrides page.

581523

Wrong web filter category when using flow-based inspection.

587120

Administrator logged in with web filter read/write privilege cannot create or edit web filter profiles in the GUI.

590599

In flow mode web filter, a certificate warning is triggered when a site redirects HTTP request to HTTPS and if ovrd-auth-https is enabled.

WiFi Controller

Bug ID

Description

520677

When editing a FortiAP profile on the FortiGate web UI, the previously selected SSID group(s) cannot be displayed.

555659

When FortiAP is managed with cross VDOM links, the WiFi client cannot join to SSID when auto-asic-offload is enabled.

566054

Errors pop up while creating or editing as SSID.

567011

WPA2-Enterprise SSID should support acct-all-servers setting in RADIUS to send accounting messages to all servers.

567933

FortiAP unable to connect to FortiGate via IPsec VPN tunnel with dtls-policy clear-text.

572350

FortiOS GUI cannot support FAP-U431F and FAP-U433F profiles.

580169

Captive portal (disclaimer) redirect not working for Android phones.

587586

cw_acd crashes multiple times (FG-6501F).

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

568788

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2007-6750

576090

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2019-17655

576941

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2019-15703

581663

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2019-9496

Resolved issues

Resolved issues

The following issues have been fixed in version 6.2.3. For inquires about a particular bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

590092

Cannot clear scanunit vdom-stats to reset the statistics on ATP widget.

Data Leak Prevention

Bug ID

Description

586689

Downloading a file with FTP client in EPSV mode will hang.

591676

Enable file filter password protected blocked for 7Z, RAR, PDF, MSOffice, and MSOfficeX.

DNS Filter

Bug ID

Description

561297

DNS filtering does not perform well on the zone transfer when a large DNS zone's AXFR response consists of one or more messages.

563441

7K DNS filter breaking DNS zone transfer.

574980

DNS translation is not working when request is checked against the local FortiGate.

583449

DNS filter explicit block all (wildcard FQDN) not working in 6.2 firmware.

586178

In domain threat feed, some URLs cannot be fetched due to SSL error.

586526

Unable to change DNS filter profile category action after upgrading from 6.0.5 to 6.2.0.

586834

With option error-allow DNS attempts fail when FortiGuard servers are unavailable.

Explicit Proxy

Bug ID

Description

504011

FortiGate does not generate traffic logs for SOCKS proxy.

588211

WAD cannot learn policy if multiple policies use the same FQDN address.

589065

FSSO-based NTLM sessions from explicit proxy do not respect timeout duration and type.

589811

urfilter process does not started when adding a category as dstaddr in a proxy policy with the deny action.

590942

AV does not forward reply when GET for FTP over HTTP is used.

Firewall

Bug ID

Description

508015

Editing a policy in the GUI changes the FSSO setting to disable.

558996

FortiGate sends type-3 code-1 IP unreachable for VIP.

583173

Policy push from FortiManager failed due to abandoned ISDB entry.

584451

NGFW default block page partially loads.

585073

Adding too many address objects to a local-in policy causes all blocking to fail.

585122

Should not be allowed to rename VIP or address with the same name as an existing VIP group or address group object.

590039

Samsung OEM internet browser cannot connect to FortiGate VS/VIP.

597110

When creating a firewall address with the associated-interface setting, CMD gets stuck if there is a large nested address group.

FortiView

Bug ID

Description

582341

On Policies page, consolidated policies are without names and tooltips; tooltips not working for security policies.

GUI

Bug ID

Description

282160

GUI does not show byte information for aggregate and VLAN interface.

303651

Should hide Override internal DNS option if vdom-dns is set to disable.

438298

When VDOM is enabled, the interface faceplate should only show data for interfaces managed by the admin.

451306

Add a tooltip for IPS Rate Based Signatures.

460698

There is no uptime information in the HA Status widget for the secondary unit's GUI.

467495

A message stating that all source interfaces have no members is erroneously displayed for the explicit proxy policy list when a user enables a policy immediately after pasting or inserting it into the list.

478472

Options 150, 15, and 51 for the DHCP server should not be shown after removing them and having no related configuration in the backend.

480731

Interface filter gets incorrect result (EMAC VLAN, VLAN ID, etc.) when entries are collapsed.

482437

SD-WAN member number is not correct in Interfaces page.

493527

Compliance events GUI page does not load when redirected from the advanced compliance page.

498892

GUI shows wrong relationship between VLAN and physical interface after adding them to a zone.

499658

Editing system interface in the GUI causes explicit-web-proxy to become disabled.

502962

Get "Fail to retrieve info" for default VDOM link on Network > Interfaces page.

505066

Not possible to select value for DN field in LDAP GUI browser.

510685

Hardware Switch row is shown indicating a number of interfaces but without any interfaces below.

514027

Cannot disable CORS setting on GUI.

519102

GUI navigation menu notification should match with issue in the dialog box.

525535

OK button greyed out when editing an interface that has DHCP option 224 in the list with FortiClient-On-Net Status enabled.

531376

Get "Internal Server Error" when editing an aggregate link that has a name with a space in it.

534853

Suggest GUI Interfaces list includes SIT tunnels.

536718

Cannot change MAC address setting when configuring a reserved DHCP client.

536843

LACP aggregate interface flaps when adding/removing a member interface (first position in member list).

537307

"Failed to retrieve info" message appears for ha-mgmt-interface in Network > Interfaces.

538125

Hovering mouse over FortiExtender virtual interface shows incorrect information.

540098

GUI does not display the status for VLAN and loopback in the Network > Interfaces > Status column.

542544

In Log & Report, filtering for blank values (None) always shows no results.

544442

Virtual IPs page should not show port range dialog box when the protocol is ICMP.

547409

Admin with netgrp privilege unable to get interface page and got pyfcgid crash (signal 11 (Segmentation fault)).

552811

Scripts pushed from FortiCloud do not show up in System > Advanced Settings when FortiCloud remote access is used.

553290

The tooltip for VLAN interfaces displays as "Failed to retrieve info".

555687

Network mask of a VPN interface is changed to 255.255.255.255 without an actual configuration change.

559866

When sending CSF proxied request, segfault happens (httpsd crashes) if FortiExplorer accesses root FortiGate via the management tunnel.

560206

Change/remove FortiCloud standalone reference.

563053

Warning messages for third-party transceivers were removed in 6.2.1 to prevent excessive RMA or support tickets. In 6.2.2, warnings were re-added for third-party transceivers.

565748

New interface pair consolidated policy added via CLI is not displayed on GUI policy page.

566414

Application Name field shows vuln_id for custom signature, not its application name in logs.

567369

Cannot save DHCP Relay configuration when the Relay IP address list is separated by a comma.

571909

SSL VPN Settings page shows undefined error.

573456

FortiGate without disk email alert settings page should remove Disk usage exceeds option.

573862

Signature name should be shown when VDOM admin has WAF read/write permission only.

574101

Empty firmware version in managed FortiSwitch from FortiGate GUI.

580168

Connected routes in the routing monitor are showing up with 1969/12/31 18:59:59 for Up Since times.

582658

Email filter page keeps loading and cannot create a new profile when the VDOM admin only has emailfilter permission.

582716

Filtering service availability check always fails once anycast is enabled and override server is set.

583049

Internal server error while trying to create a new interface.

584419

Issue with application and filter overrides.

584426

Add Selected button does not show up under FSSO Fabric Connector with custom admin profile.

584560

GUI does not have the option to disable the interface when creating a VLAN interface.

584949

When the link status is up, the aggregate interface status icon is incorrectly displayed in red.

586604

No matching IPS signatures are found when Severity or Target filter is applied.

586749

Enable/disable Disarm and Reconstruction in the GUI only affects the SMTP protocol in AV profiles.

587091

When logged in as administrator with web filter read/write only privilege, the Web Rating Overrides GUI page cannot load.

587673

The Interface Pair View option is always unavailable for the Proxy Policy list.

587686

Wrong warning message, All source interface(s) has no members, appears in Proxy Policy page.

588028

If the Endpoint Control feature is disabled, the exempt options for captive portal are not shown in the GUI.

588222

WAN Opt. Monitor displays Total Savings as negative integers during file transfers.

588665

Option to reset statistics from Monitor > WAN Opt. Monitor in GUI does not clear the counters.

589085

Web filter profile warning message when logged in with read/write admin on VDOM environment.

592244

VIPs dialog page should be able to create VIP with the same extip/extport but different source IP address.

593433

DHCP offset option 2 has to be removed before changing the address range for the DHCP server in the GUI.

594162

Interface hierarchy is not respected in the GUI when a LAG interface belongs to SD-WAN and its VLANs belong to a zone.

594565

Wrong Sub-Category appears in the Edit Web Rating Override page.

HA

Bug ID

Description

479780

Secondary unit fails to send and receive HA heartbeat when configuring cfg-revert setting on FG-2500E.

540632

In HA, management-ip that is set on a hardware switch interface does not respond to ping after executing reboot.

575020

HA failing config sync on VM01 with error (secondary and primary unit have different hdisk status) when primary unit is pre-configured.

581906

HA secondary unit sending out GARP packets in 16-20 seconds after HA monitored interface failed.

585348

default-gateway injected by dynamic-gateway on PPP interface deleted by other interface down.

585675

exe backup disk alllogs ftp command causes FortiGate to enter conserve mode.

586004

Moving VDOM via GUI between virtual clusters causes cluster to go out of sync and VDOM state work/standby does not change.

586835

HA secondary unit unable to get checksum from primary unit. HA sync in Z state.

590931

Multiple PPPoE connections on a single interface does not sync PPPoE dynamic assigned IP and cannot start re-negotiation.

Intrusion Prevention

Bug ID

Description

540718

Signal 14 alarm crashes were observed on DFA rebuild.

579018

IPS engine 5.030 signal 14 alarm clock crash at nturbo_on_event.

586608

The CPU consumption of ipsengine gets high with customer configuration file.

IPsec VPN

Bug ID

Description

577502

OCVPN cannot register—status "Undefined".

582251

IKEv2 with EAP peer ID authentication validation does not work.

582876

ADVPN connections from the hub disconnects one-by-one and IKE gets stuck.

584982

The customer is unable to log in to VPN with RADIUS intermittently.

Log & Report

Bug ID

Description

578057

Action field in traffic log cannot record security policy action—it shows the consolidated policy action.

580887

No traffic log after reducing miglogd child to 1.

586038

FortiOS 6.0.6 reports too long VPN tunnel durations in local report.

586854

FortiGate sends change notice for global REST APIs once a minute.

590598

Log viewer application control cannot show any logs (page is stuck loading).

590852

Log filter can return empty result when there are too many logs, but the filter result is small.

591152

IPS logs set srcintf(role)/dstinf(role) reversely at the time of IPS signature reverse pattern.

591523

When refreshing logs in GUI, some log_se processes are running extremely long and consuming CPU.

593907

Miglogd still uses the daylight savings time after the daylight savings end.

596278

sentdelta and rcvddelta showing 0 if syslog format is set to CSV.

596398

sentdelta and rcvddelta log fields appears as 0 in syslog CEF format.

599860

When logtraffic is set to all, existing sessions cannot change the egress interfaces when the routing table is updated with a new outgoing interface.

Proxy

Bug ID

Description

525328

External resource does not support no content length.

549660

WAD crash with signal 11.

573028

WAD crash causing traffic interruption.

579400

High CPU with authd process caused by WAD paring multiple line content-encoding error and IPC broken between wad and authd.

580592

Policy in proxy-based mode with AV and WAF profile denies access to Nginx with enabled gzip compression.

584719

WAD reads ftp over-limit multi-line response incorrectly.

587214

WAD crash for wad_ssl_port_on_ocsp_notify.

587987

In case of TLS 1.3 with certificate inspection and a certificate with an empty CN name, WAD workers would locate a random size for CN name and then cause unexpected high memory usage in WAD workers.

592153

Potential memory leak that will be triggered by certificate inspection CIC connection in WAD.

593365

WAD crash due to user learned from proxy not purged from the kernel when user is deleted from proxy or zone with empty interface member.

594237

Slow download speed in proxy-based mode compared to flow-based mode.

594725

WAD memory leak detected on cert_hash in wad_ssl_cert.

596012

Receive SSL fatal alert with source IP 0.0.0.0.

REST API

Bug ID

Description

587470 REST API to support revision flag.

Routing

Bug ID

Description

371453

OSPF translated type 5 LSA not flushed according to RFC-3101.

524229

SD-WAN health-check keep records useless logs under some circumstances.

570686

FortiOS 6.2.1 introduces asymmetric return path on the hub in SD-WAN after the link change due to SLA on the spoke.

582078

ISDB ID is changed after restoring the configuration under the situation where the FortiGate has a previous ISDB version.

584095

SD-WAN option of set gateway enable/set default enable override available on connected routes.

584477

In transparent mode with asymmetric routing, packet in the reply direction does not use asymmetric route.

585027

There is no indication in proute if the SD-WAN service is default or not.

585325

IPv6 route cannot be inactive after link-monitor is down when link-monitor are set with ipv4 and ipv6.

587198

After failover/recovery of link, E2 route with non-zero forward address recurses to itself as a next hope.

587700

Routing monitor policy view cannot show source and destination data for SD-WAN route and wildcard destination.

587970

SD-WAN rules route-tag still used in service rule but not in diagnose sys virtual-wan-link route-tag-list.

589620

Link monitor with tunnel as srcintf cannot recover after remote server down/up.

592599

FortiGate sends malformed OSPFv3 LSAReq/LSAck packets on interfaces with MTU = 9k.

593375

OSPF NSSA with multiple ASBRs losing valid external OSPF routes in upstream neighbors as different ASBRs are power cycled.

593864

Routing table is not always updated when BGP gets an update with changed next hop.

594685

Unable to create the IPsec VPN directly in Network > SD-WAN.

595937

PPPoE interface bandwidth is mistakenly calculated as 0 in SD-WAN.

Security Fabric

Bug ID

Description

575495

FGCP dynamic objects are not populated in the secondary unit.

586587

Security Fabric widget keeps loading when FortiSwitches are in a loop, or the FortiSwitch is in MCLAG mode.

587758

Invalid CIDR format shows as valid by the Security Fabric threat feed.

589503

Threat Feeds show the URL is invalid if there is a special character in the URL.

591015

ACI SDN connector dynamic address cannot be resolved.

592344

CSF automation configuration cannot be synced to downstream from root.

SSL VPN

Bug ID

Description

525342

In some special cases, SSL VPN main state machine reads function pointer is empty that will cause SSL VPN daemon crash.

557806

Cannot fully load a website through SSL VPN bookmark.

570171

When accessing ACT application through SSL VPN web mode, the embedded calendar request gets wrong response and redirects to login page.

573787

SSL VPN web mode not displaying custom web application's JavaScript parts.

576288

FSSO groups set in rule with SSL VPN interface.

578908

Fails to load bookmark site over SSL VPN portal.

580377

Unable to access https://outlook.office365.com as bookmark in SSL VPN web mode.

583339

Support HSTS include SubDomains and preload option under SSL VPN settings.

584780

When the SSL VPN portal theme is set to red, the style is lost in the SSL VPN portal.

585754

A VPN SSL bookmark failed to load the Proxmox GUI interface.

586032

Unable to download report from an internal server via SSL VPN web mode connection.

586035

The policy "script-src 'self'" will block the SSL VPN proxy URL.

587075

SAML login is not stable for SSL VPN, it requires restarting sslvpnd to enable the function.

587117

SSL handshake failure with Server Architect in web mode.

588119

There is no OS support for the latest macOS Catalina version (10.15) when using SSL VPN tunnel mode.

588720

SSL VPN web portal bookmarks cannot resolve hostname.

589015

SSO does not correctly URL-encode POST-ed credentials.

590643

href rewrite has some issues with the customer's JS file.

591613

https://outlook.office365.com cannot be accessed in SSLVPN web portal.

592318

After sslvpn proxy, some Kurim JS files run with an error.

592935

sslvpnd crashed on FortiGate.

593082

SSL VPN bookmark does not load Google Maps on internal server.

593641

Cannot access HTTPS bookmark, get a blank page.

593850

SSL VPN logs out after some users click through the remote application.

594160

Screen shot feature is not working though SSL VPN portal.

594247

Cannot access https://cdn.i-ready.com through SSL VPN web portal.

595920

SSL VPN web mode goes to 99% on a specific bookmark.

596273

sslvpnd worker process crashes, causing a zombie tunnel session.

596843

Internal website not working in SSL VPN web mode.

597282

The latest FortiOS GUI does not render when accessing it by the SSL VPN portal.

Switch Controller

Bug ID

Description

581370

FortiSwitch managed by FortiGate not updating the RADIUS settings and user group in the FortiSwitch.

586299

Adding factory-reset device to HA fails with switch-controller.qos settings in root.

592111

FortiSwitch shows offline CAPWAP response packet getting dropped/failed after upgrading from 6.2.2.

System

Bug ID

Description

484749

TCP traffic with tcp_ecn tag cannot go through ipip ipv6 tunnel with NP6 offload enabled.

502387

X.509 certificate support required for FGFM portocol.

511790

Router info does not update after plugging out/plugging in USB modem.

528052

FortiGuard filtering services show as unavailable for read-only admin.

534806

FGR-30D cannot add ports SFP1 and SFP2 on a virtual hardware switch.

547712

HPE does not protect against DDoS attacks like flood on IKE and BGP destination ports.

556408

Aggregate link does not work for LACP mode active for FG-60E internal ports but works for wan1 and wan2 combination.

570759

RX/TX counters for VLAN interfaces based on LACP interface are 0.

572003

There was a hardware defect in an earlier revision of SSD used for FG-61E. When powering off then powering on in a very short time, the SSD may jump into ROM mode and cannot recover until a power circle.

573090

Making a change to a policy through inline editing is very slow with large table sizes.

573238

Session TTL expiry timer is not reset for VLAN traffic when offloading is enabled.

573973

ASIC offloading sessions sticking to interfaces after SD-WAN SLA interface selection.

576054

Missing mpsk-schedules option when restoring configuration via VDOM.

577423

FG-80D and FG-92D kernel error in CLI during FortiGate boot up.

578259

FG-3980E VLANs over LAG interface show no TX/RX statistics.

578608

High CPU usage due to dnsproxy process as high at 99%.

580038

Problems with cmdbsvr while handling a large number of FSSO address groups and security policies.

581496

FG-201E stops sending out packets and NP6lite is stuck.

581528

SSH/RDP sessions are terminated unexpectedly.

581998

Session clash event log found on FG-6500F when passing a lot of the same source IP ICMP traffic over load-balance VIP.

582520

Enabling offloading drops fragmented packets.

583199

fgfmsd crashed with signal 11 when some code accesses a VDOM that has been deleted, but does not check the return value from CMDB query.

583602

Script to purge and re-create a local-in-policy ran against the remote FortiGate directly (in the CLI) is causing auto-update issues.

585841

Console outputs unregister_netdevice error on UoM setup.

586042

NTPD does not requery the DNS server unless it restarts.

586301

GUI cannot show default Fortinet logo for replacement messages.

586551

When an SD-WAN member is disabled or VWL is disabled, snmpwalk shows "No Such Object available on this agent at this OID" message.

587498

FortiGate sends ICMP type 3 code 3 (port unreachable) for UDP 500 and UDP 520 against vulnerability scan.

587540

NetFlow traffic records sent with wrong interface index 0 (inputint = 0 and outputint = 0).

587952

get system inter transceiver reports error for some transceivers.

588035

Kernel crashes when sniffing packets on interfaces that are related to EMAC VLAN.

588202

FortiGate returns invalid configuration during FortiManager retrieving configuration.

589027

EMAC VLAN drops traffic when asymmetric roue enabled on internet VDOM.

589234

Local system DNS setting instead of DNS setting acquired from upstream DHCP server was assigned to client under management VDOM.

589517

Dedicated management CPU running on high CPU (soft IRQ).

589978

alertemail username length cannot go beyond 35 characters.

590295

OID for the IPsec VPN phase 2 selector only displays the first one on the list.

591466

Cannot change the mask for an existing secondary IP on interfaces.

592787

FortiGate got rebooted automatically due to kernel crash.

593606

diagnose hardware test suite all fails due to FortiLink loopback test.

594157

FortiGate accepts invalid configuration from FortiManager.

594499

Communication over PPPoE fails after installing PPPoE configuration from FortiManager.

595598

SOC4 devices may reboot by watchdog after upgrading to FortiOS 6.2.2 (build 6083).

Affected platforms: FG-60F, FG-61F, FG-100F, and FG-101F.

596180

Constant DHCPD crashes.

596421

FG-3400E/FG-3600E link is up on 25G ports only when the FEC is disabled on the Ixia tester.

Upgrade

Bug ID

Description

586793

Address objects have reference to old firewall policy after upgrading from 6.0.6 > 6.2.x NGFW policies.

User & Device

Bug ID

Description

567831

Local FSSO poller regularly missing logon events.

583745

Wrong categorization of OS from device detection.

586334

Brief connectivity loss on shared service when RDP session is logged in to from local device.

586394

Authentication list entry is not created/updated after changing the client PC with another user in FSSO polling mode.

587293

The session to the SQL database is closed as timeout when a new user logs in to terminal server.

587519

fnbamd takes high CPU usage and user not able to authenticate.

587666

Mobile token authentication does not work for SSL VPN on SOC3 platforms.

Affected models include: FG-60E, FG-60E-POE, FG-61E, FG-80E, FG-80E-POE, FG-81E, FG-81E-POE, FG-100E, FG-100EF, FG-101E, FG-140E, FWF-60E, FWF-61E.

592241

Gmail POP3 authentication fails with certificate error since version 6.0.5.

592253

RADIUS state attribute truncated in access request when using third-party MFA (ping ID).

593116

Client PC matching multiple authentication methods (firewall, FSSO, RSSO, WSSO) may not be matched to NGFW policies correctly.

597496

Guest user log in expires after first log in and no longer works; user is not removed from the firewall authentication list after the set time.

VM

Bug ID

Description

571212

Only one CPU core in AWS is being used for traffic processing.

577653

vMotion tasks cause connections to be dropped as sessions related to vMotion VMs do not appear on the destination VMX.

579708

Should replace GUI option to register to FortiCare from AWS PAYG with link to portal for registration.

582123

EIP does not failover if the primary FortiGate is rebooted or stopped from the Alibaba Cloud console.

586954

FGCP cluster member reboots in infinite loop and hatalk daemon dumps the core with segmentation fault.

588436

Azure SDN connector unable to connect to Azure Kubneretes integrated with AAD.

589445

VM deployed in ESX platform with VMXNET3 does not show the correct speed and duplex settings.

590140

FG-VM-LENC unable to validate new license.

590149

Azure FortiGate crashing frequently when MLX4 driver RX jumbo.

590253

VLAN not working on FortiGate in a Hyper-V deployment.

590555

Allow PAYG AWS VM to bootstrap the configuration first before acquiring FortiCare license.

590780

Azure FortiGate-VM (BYOL) unable to boot up when loading a lower vCPU license than the instance's vCPU.

591563

Azure autoscale not syncing after upgrading to 6.2.2.

592000

In Alibaba Cloud, multiple VPC route entries fail to switch when HA fails over.

592611

HA not fully failing over when using OCI.

593797

FG-VM64-AWS not responding to ICMP6 request when destination IPv6 address is in the neighbor cache entry.

596430

If central-management server is set to FortiManager IP address and FortiGuard update-server-location is set to usa, the FOS-VM is able to get web filter license and server list from FortiManager, but the GUI shows the service availability as down.

VoIP

Bug ID

Description

582271

Add support for Cisco IP Phone keepalive packet.

Web Filter

Bug ID

Description

560904

In NGFW mode, Security Profiles GUI is missing Web Rating Overrides page.

581523

Wrong web filter category when using flow-based inspection.

587120

Administrator logged in with web filter read/write privilege cannot create or edit web filter profiles in the GUI.

590599

In flow mode web filter, a certificate warning is triggered when a site redirects HTTP request to HTTPS and if ovrd-auth-https is enabled.

WiFi Controller

Bug ID

Description

520677

When editing a FortiAP profile on the FortiGate web UI, the previously selected SSID group(s) cannot be displayed.

555659

When FortiAP is managed with cross VDOM links, the WiFi client cannot join to SSID when auto-asic-offload is enabled.

566054

Errors pop up while creating or editing as SSID.

567011

WPA2-Enterprise SSID should support acct-all-servers setting in RADIUS to send accounting messages to all servers.

567933

FortiAP unable to connect to FortiGate via IPsec VPN tunnel with dtls-policy clear-text.

572350

FortiOS GUI cannot support FAP-U431F and FAP-U433F profiles.

580169

Captive portal (disclaimer) redirect not working for Android phones.

587586

cw_acd crashes multiple times (FG-6501F).

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

568788

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2007-6750

576090

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2019-17655

576941

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2019-15703

581663

FortiOS 6.2.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2019-9496