Fortinet black logo

Known issues

Known issues

The following issues have been identified in version 6.2.4. For inquires about a particular bug or to report a bug, please contact Customer Service & Support.

Anti Spam

Bug ID

Description

497024

Flow mode banned word spam filter log is missing the banned word.

Anti Virus

Bug ID

Description

582368

URL threat detection version shows a large negative number after FortiGate reboots.

Application Control

Bug ID

Description

630075

After upgrading, FortiGate faced an internet access issue when IPS and AC profiles are enabled and the outgoing interface is an npu_vlink.

Data Leak Prevention

Bug ID

Description

582480

scanunit crashes with signal 11 in dlpscan_mailheader when AV scans files via IMAP.

DNS Filter

Bug ID

Description

582374

License shows expiry date of 0000-00-00.

Endpoint Control

Bug ID

Description

608301

EMS serial number format should be flexible.

Explicit Proxy

Bug ID

Description

540091

Cannot access explicit FTP proxy via VIP.

591012

WAD crashed at wad_disclaimer_get with signal 11 when disclaimer is enabled in proxy policy and the browser is Chrome.

610298

Compare and sync the VSD change in V5.6 to WAD VS.

650540

FortiGate sends traffic to an incorrect port using a wrong source NAT IP address.

Firewall

Bug ID

Description

596633

In NGFW mode, IPS engine drops RPC data channel when IPS profile is applied to a security policy.

603263

Increase the maximum limit for the optional parameters in SCTP INIT packet. After the fix, the maximum limit is 10 instead of 4 parameters.

615073

FTP session helper does not work when there is reflected (auxiliary) session.

FortiView

Bug ID

Description

573138

When the data source is FortiGate Cloud, there is no paging to load sessions; only entries 1-499 are rendered.

635309

When FortiAnalyzer logging is configured using an FQDN domain, the GUI displays a 500 error message on the FortiView Compromised Hosts page.

673225

FortiView Top Traffic Shaping widget does not show data for outbound traffic if the source interface's role is WAN. The data is displayed if the source interface's role is LAN, DMZ, or undefined.

GUI

Bug ID

Description

354464

AntiVirus archive logging enabled from the CLI will be disabled by editing the AntiVirus profile in the GUI, even if no changes are made.

514632

Inconsistent reference count when using ports in HA session-sync-dev.

529094

When creating an antispam block/allow list entry, Mark as Reject should be grayed out.

541042

Log viewer forwarded traffic does not support multiple filters for one field.

564849

HA warning message remains after primary device takes back control.

584915

OK button missing from many pages when viewed in Chrome on an Android device.

584939

VPN event logs are incorrectly filtered when there are two Action filters and one of them contains "-".

589709

Status icon in Tunnel column on IPsec Tunnels page should be removed.

594534

GUI shows Invalid LDAP server error while LDAP query successfully finished.

594702

When sorting the interface list by the Name column, the ports are not always in the correct order (port10 appears before port2).

601568

Interface status is not displayed on faceplate when viewing from the System > HA page.

601653

When deleting an AV profile in the GUI, there is no confirmation message prompt.

602102

Warning message is not displayed when a user configures an interface with a static IP address that is already in use.

604682

GUI takes two minutes to load VPN > IPsec Tunnels for 1483 tunnels.

620854

FG-101F GUI should not add speed to virtual switch member port.

621254

When creating or editing an IPv4 policy or address group, firewall address searching does not work if there is an empty wildcard address due to a configuration error.

624551

On POE devices, several sections of the GUI take over 15 seconds to fully load.

628373

Software switch members and their VLANs are not visible in the GUI interfaces list.

638277

Firewall address group object (including interface subnet) is invisible in Accessible Networks.

638752

FortiGates in an HA A-P configuration may lose GUI access to the HA secondary device after a period of 8 days of inactivity, when at least one static IPv6 address is configured on an interface.

639756

Monitor > SD-WAN Monitor keeps loading after disabling VPN member.

642402

LCP-1250RJ3SR-K transceiver shows a warning in the GUI even though it is certified.

654339

GUI search does not work in the interface list if DHCP client and range columns are present.

662640

Some GUI pages (dashboard, topology, policy list, interface list) are slow to load on low-end platforms when there are many concurrent HTTPSD requests.

664007

GUI incorrectly displays the warning, Botnet package update unavailable, AntiVirus subscription not found., when the antivirus entitlement is expiring within 30 days. The actual botnet package update still works within the active entitlement duration.

689605

On some browser versions, the GUI displays a blank dialog when creating custom application or IPS signatures. Affected browsers: Firefox 85.0, Microsoft Edge 88.0, and Chrome 88.0.

695163

When there are a lot of historical logs from FortiAnalyzer, the FortiGate GUI Forward Traffic log page can take time to load if there is no specific filter for the time range.

Workaround: provide a specific time range filter, or use the FortiAnalyzer GUI to view the logs.

HA

Bug ID

Description

623642

It takes up to 10 seconds to get NPU VDOM link up when rebooting primary unit.

637843

HA secondary device is reporting multiple events (DDNS update failed).

638287

private-data-encryption causes cluster to be periodically out of sync due to customer certificates.

645293

traceroute not working in asymmetric FGSP environment.

656099

mgmt interfaces are excluded for heartbeat interfaces (even if dedicate-mgmt is not enabled).

Intrusion Prevention

Bug ID

Description

565747

IPS engine 5.00027 has signal 11 crash.

586544

IPS intelligent mode not working when reflect sessions are created on different physical interfaces.

587668

IPS engine 5.00035 has signal 11 crash.

590087

When IPS pcap is enabled, traffic is intermittently disrupted after disk I/O reaches IOPS limit.

631381

RDP NLA authentication blocked by FortiGate when enabling IPS profile in the security group (central NAT).

IPsec VPN

Bug ID

Description

592361

Cannot pass traffic over ADVPN if: tunnel-search is set to nexthop, net-device disable, mode-cfg enable, and add-route disable.

606129

iked crash when proposal is AES-GCM.

610390

IKEv2 EAP certificate authentication failings after upgrading from to 6.2.1 to 6.2.3.

610558

ADVPN cannot establish after primary ISP has recovered from failure and traffic between spokes is dropped.

631968

IKE daemon signal 6 crash when phase1 add-gw-route is enabled.

634883

IKE crashes at ike_hasync__xauth.

635325

Static route for site-to site VPN remains active even when the tunnel is down.

Log & Report

Bug ID

Description

605405

IPS logs are recorded twice with TCP offloading on virtual server.

606533

User observes FGT internal error while trying to log in or activate FortiGate Cloud from the web UI.

608565

FortiGate sends incorrect long session logs to FortiGate Cloud.

616835

Logs from HA secondary unit cannot be uploaded to FortiCloud.

628358

Logs are not generated in GUI and CLI after checking the file system (after power cable disconnected).

635013

FortiOS gives wrong time stamp when querying FortiGate Cloud log view.

643840

vwlservice should log the SD-WAN rule and not an internet service; impacts FortiAnalyzer SD-WAN monitor widgets and reports.

Proxy

Bug ID

Description

582475

WAD is crashing with signal 6 in wad_fmem_free when processing SMB2/CIFS.

586909

When CIFS profile is loaded, using MacOS to access Windows Share causes WAD to crash.

612333

In FortiGate with squid configuration (proxy chain), get ERR_SSL_PROTOCOL_ERROR when using Google Chrome with certificate/deep inspection.

615791

Abbreviated handshake randomly receives fatal illegal_parameter against zendesk.com services/sites.

629504

SSH status in SSL profile changes to deep-inspection from disable after upgrading.

637389

The WAD process is crashing multiple times.

640427

Web proxy WAD crash under WAN Opt auto-active mode.

648831

WAD memory leak caused by Kerberos proxy authentication.

REST API

Bug ID

Description

584631 REST API administrator with token unable to configure HA setting (via login session works).

Routing

Bug ID

Description

537354

BFD/BGP dropping when outbandwidth is set on interface.

602826

BGP route is not added in to kernel during ADVPN test.

608106

BGP daemon crashes when TCP connection is broken by peer.

611539

Editing/adding any address object that is referenced in policy is generating false positive SD-WAN alert messages.

613716

Local-out TCP traffic changes output interface when irrelevant interface is flapping that causes disconnections.

619343

Cannot ping old VRIPs when adding new VRIPs.

625345

The single BGP update message contains the same prefix in withdrawn routes and NLRI (advertised route).

627951

NTP and FSSO not following SD-WAN rules.

629521

SD-WAN IPv6 default route cannot be redistributed into BGP using set default-originateroutemap6.

635716

FortiGuard web filter traffic also needs to follow SD-WAN service.

666829

Application bfdd crashes.

Security Fabric

Bug ID

Description

597139

Crash happens due to segfault in CSF.

649556

FortiNAC requests to FortiGate can timeout on low-end models when there are many concurrent requests.

SSL VPN

Bug ID

Description

505986

On IE 11, SSL VPN web portal displays blank page title {{::data.portal.heading}} after authentication.

595505

FortiGate does not send client IP address as a framed IP address to RADIUS server in RADIUS accounting request message.

606271

Double redirection through SSL web mode not working.

607687

RDP connection via SSL VPN web portal does not work with UserPrincipalName (UPN) and NLA security.

610579

Videos from live cameras via SSL VPN web mode not working.

620508

CLI command get vpn ssl monitor displays users from other VDOM.

622068

Adding FQDN routing address in split tunnel configuration injects single route in client for multiple A records.

622110

SSL VPN disconnected when importing or renaming CA certificates.

623231

Pages could not be shown after logging in to back-end application server.

623379

Memory corrupt in some DNS callback cases causes SSL VPN crash.

624145

An internal website via SSL VPN web portal failed to load an external resource.

624899

Log entry for tunnel stats shows wrong tunnel ID when using RDP bookmark.

625301

Riverbed SteelCentral AppResponse login form is not displaying in SSL VPN web mode.

628821

Internal aixws7test2 portal is not loading in SSL VPN web mode.

629190

After SSL VPN proxy, some JS files of hapi website could not work.

631130

Internal site http://vau***.com not completely loading through SSL VPN web mode bookmark.

633812

For guacd daemon generated for RDP session, it would sometimes be in an unknown state with 100% CPU and could not be released.

634991

Internal server error 500 while accessing contolavdip portal in SSL VPN web mode.

635307

Map could not be displayed correctly in SSL VPN web mode.

636984

Pro***.com not loading properly in SSL VPN web mode.

637018

After the upgrade to 6.0.10/6.2.4/6.4.0, SSL VPN portal mapping/remote authentication is matching user into the incorrect group.

638733

Internal website hosted in bookmark https://int***.cat is not loading completely in SSL VPN web mode.

648369

Some JS files of jira.***.vwg could not run in SSL VPN web mode.

649130

SSL VPN log entries display users from other VDOMs.

654534

SAML authentications occurring through SSL VPN web mode are not completing.

Switch Controller

Bug ID

Description

588584

GUI should add support to allow using switch VLAN interface under a tenant VDOM on a managed switch VDOM.

605864

If the firewall is downgraded from 6.2.3 to 6.2.2, the FortiLink interface looses its CAPWAP setting.

System

Bug ID

Description

464340

EHP drops for units with no NP service module.

503125

FG-100D traffic traversing port1-port16 only saturates CPU0.

567019

CP9 VPN queue tasklet unable to handle kernel NULL pointer dereference at 0000000000000120 and device reboots.

576323

SFP+ 1G speed should be supported on FG-1100E, FG-1800F, FG-2200E, and FG-3300E series.

578031

FortiManager Cloud cannot be removed once the FortiGate has trouble on contract.

594871

Potential memory leak triggered by FTP command in WAD.

600032

SNMP does not provide routing table for non-management VDOM.

604613

sentbyte of NTP on local traffic log shows as 0 bytes, even though NTP client receives the packet.

607357

High CPU usage issue caused by high depth expectation sessions in the same hash table slot.

608442

After a reboot of the PPPoE server, the FortiGate (PPPoE clients, 35 clients) keeps flapping (connection down and up) for a long time before connecting successfully.

611512

When a LAG is created between 10 GE SFP+ slots and 25 GE SFP28/10 GE SFP+ slots, only about 50% of the sessions can be created. Affected models: FG-110xE, FG-220xE, and FG-330xE.

612351

Many no session matched logs while managing FortiGate.

613017

ip6-extra-addr does not perform router advertisement after reboot in HA.

613136

Uninitialized variable that may potentially cause httpsd signal 6 and 11 crash issue.

615435

Crashes might happen due to CMDB query allocation fail that causes a segfault.

616022

Long delay and cmdbsvr at 100% CPU consumption when modifying address objects and address groups via GUI or REST API.

617134

Traffic not showing statistics for VLAN interfaces base on hardware switch.

617154

Fortinet_CA is missing in FG-3400E.

617409

The FG-800D HA LED is off when HA status is normal.

618762

Fail to detect transceiver on all SFP28/QSFP ports. Affected platforms: FG-3300E and FG-3301E.

620827

Over a period of time, FG-60E goes into memory conserve mode caused by resource leak of sepmd daemon.

623501

FG-80D may fail to boot due to a limitation in the size of the bootloader and kernel.

626371

Request to blocked signature with SSL mirrored traffic capture causes FG-500E to reboot.

632353

Virtual WAN link stops responding after 45 members.

632635

Frame size option in sniffer does not work.

633102

DHCPv6 client's DUID generated on two different FortiGates match.

634600

FWF-60E-DSL ADSL2+ connection provided by BT in the UK does not work after upgrading from 6.0.9 to 6.2.4.

636069

Unable to handle kernel NULL pointer dereference at 000000000000008f.

638041

SFP28 port group (ha1, ha2, port1 and port2) missing 1000full speed option. Affected platforms: FG-220xE, FG-330xE, FG-340xE, and FG-360xE.

641419

FG-40F LAN interfaces are down after upgrading to 6.2.4 (build 5632).

647718

VDOM with long name cannot be deleted.

648977

Sometimes when updating the FortiGate license, there is a certificate verification failure.

654159

NP6Xlite traffic not sent over the tunnel when NPU is enabled.

694202

stpforward does not work with LAG interfaces on a transparent VDOM.

Upgrade

Bug ID

Description

615972

After upgrading from 6.2.2 to 6.2.3, the description field in the table has disappeared under DHCP reservation.

635589

Upon upgrading to FortiOS 6.2.4, DoS policies configured on interfaces may drop traffic that is passing through the DoS policy configuration. Note that this can occur if the DoS policy is configured in drop or monitor mode.

Workaround: disable the DoS policy.

649948

Upon upgrading to an affected 6.2 or 6.4 firmware, IKE/IPsec SAs are not synced to the primary when HA uninterruptible-upgrade is enabled. As a result, IPsec traffic from a client may be detected as having an invalid SPI until the client starts a new negotiation.

User & Device

Bug ID

Description

591170

Sessions are removed from the session table when FSSO group order is changed.

591461

FortiGate does not send user IP to TACACS server during authentication.

595583

Device identification via LLDP on an aggregate interface does not work.

605838

Device identification scanner crashes on receipt of SSDP search.

621161

src-vis crashes on receipt of certain ONVIF packets.

626532

fnbamd is not sending Calling-Station-Id in Access-Request for L2TP/IPsec since 5.4.0.

VM

Bug ID

Description

587180

FG-VM64-KVM is unable to boot up properly when doing a hard reboot with the host.

587757

FG-VM image unable to be deployed on AWS with additional HDD(st1) disk type.

596742

Azure SDN connector replicates configuration from primary device to secondary device during configuration restore.

605511

FG-VM-GCP reboots a couple of times due to kernel panic.

606527

GUI and CLI interface dropdown lists are inconsistent.

608881

IPsec VPN tunnel not staying up after failing over with AWS A-P cross-AZ setup.

613730

Unable to update routing table for a resource group in a different subscription with FortiGate Azure SDN.

623376

Cross-zone HA breaks after upgrading to 6.4.0 because upgrade process does not add relevant items under vdom-exception.

624657

Azure changes FPGA for Accelerated Networking live and VM loses SR-IOV interfaces.

626705

By assigning port1 as the HA management port, the HA secondary unit node is now able to send system information to the Azure portal through waagent so that up-to-date information is displayed on the Azure dashboard.

If port1 is not used as the HA management port, the Azure display and Azure Security Center alerts will not reflect the correct state of the node, which may result in unnecessary alarms.

634499

AWS FortiGate NIC gets swapped between port2 and port3 after FortiGate reboots.

685782

HTTPS administrative interface responds over heartbeat port on Azure FortiGate despite allowaccess settings.

VoIP

Bug ID

Description

620742

RAS helper does not NAT the port 1720 in the callSignalAddress field of the RegistrationRequest packet sent from the endpoint.

630024

voipd crashes repeatedly.

Web Filter

Bug ID

Description

657466

local urlfilter configuration in a flow mode web filter does not work when the matched FortiGuard category is also enabled in the web filter profile.

WiFi Controller

Bug ID

Description

625326

FortiAP not coming online on FG-PPPoE interface.

641811

In FG-100F/101F with PPPoE interface, the FortiGate could not manage FortiAP.

Known issues

The following issues have been identified in version 6.2.4. For inquires about a particular bug or to report a bug, please contact Customer Service & Support.

Anti Spam

Bug ID

Description

497024

Flow mode banned word spam filter log is missing the banned word.

Anti Virus

Bug ID

Description

582368

URL threat detection version shows a large negative number after FortiGate reboots.

Application Control

Bug ID

Description

630075

After upgrading, FortiGate faced an internet access issue when IPS and AC profiles are enabled and the outgoing interface is an npu_vlink.

Data Leak Prevention

Bug ID

Description

582480

scanunit crashes with signal 11 in dlpscan_mailheader when AV scans files via IMAP.

DNS Filter

Bug ID

Description

582374

License shows expiry date of 0000-00-00.

Endpoint Control

Bug ID

Description

608301

EMS serial number format should be flexible.

Explicit Proxy

Bug ID

Description

540091

Cannot access explicit FTP proxy via VIP.

591012

WAD crashed at wad_disclaimer_get with signal 11 when disclaimer is enabled in proxy policy and the browser is Chrome.

610298

Compare and sync the VSD change in V5.6 to WAD VS.

650540

FortiGate sends traffic to an incorrect port using a wrong source NAT IP address.

Firewall

Bug ID

Description

596633

In NGFW mode, IPS engine drops RPC data channel when IPS profile is applied to a security policy.

603263

Increase the maximum limit for the optional parameters in SCTP INIT packet. After the fix, the maximum limit is 10 instead of 4 parameters.

615073

FTP session helper does not work when there is reflected (auxiliary) session.

FortiView

Bug ID

Description

573138

When the data source is FortiGate Cloud, there is no paging to load sessions; only entries 1-499 are rendered.

635309

When FortiAnalyzer logging is configured using an FQDN domain, the GUI displays a 500 error message on the FortiView Compromised Hosts page.

673225

FortiView Top Traffic Shaping widget does not show data for outbound traffic if the source interface's role is WAN. The data is displayed if the source interface's role is LAN, DMZ, or undefined.

GUI

Bug ID

Description

354464

AntiVirus archive logging enabled from the CLI will be disabled by editing the AntiVirus profile in the GUI, even if no changes are made.

514632

Inconsistent reference count when using ports in HA session-sync-dev.

529094

When creating an antispam block/allow list entry, Mark as Reject should be grayed out.

541042

Log viewer forwarded traffic does not support multiple filters for one field.

564849

HA warning message remains after primary device takes back control.

584915

OK button missing from many pages when viewed in Chrome on an Android device.

584939

VPN event logs are incorrectly filtered when there are two Action filters and one of them contains "-".

589709

Status icon in Tunnel column on IPsec Tunnels page should be removed.

594534

GUI shows Invalid LDAP server error while LDAP query successfully finished.

594702

When sorting the interface list by the Name column, the ports are not always in the correct order (port10 appears before port2).

601568

Interface status is not displayed on faceplate when viewing from the System > HA page.

601653

When deleting an AV profile in the GUI, there is no confirmation message prompt.

602102

Warning message is not displayed when a user configures an interface with a static IP address that is already in use.

604682

GUI takes two minutes to load VPN > IPsec Tunnels for 1483 tunnels.

620854

FG-101F GUI should not add speed to virtual switch member port.

621254

When creating or editing an IPv4 policy or address group, firewall address searching does not work if there is an empty wildcard address due to a configuration error.

624551

On POE devices, several sections of the GUI take over 15 seconds to fully load.

628373

Software switch members and their VLANs are not visible in the GUI interfaces list.

638277

Firewall address group object (including interface subnet) is invisible in Accessible Networks.

638752

FortiGates in an HA A-P configuration may lose GUI access to the HA secondary device after a period of 8 days of inactivity, when at least one static IPv6 address is configured on an interface.

639756

Monitor > SD-WAN Monitor keeps loading after disabling VPN member.

642402

LCP-1250RJ3SR-K transceiver shows a warning in the GUI even though it is certified.

654339

GUI search does not work in the interface list if DHCP client and range columns are present.

662640

Some GUI pages (dashboard, topology, policy list, interface list) are slow to load on low-end platforms when there are many concurrent HTTPSD requests.

664007

GUI incorrectly displays the warning, Botnet package update unavailable, AntiVirus subscription not found., when the antivirus entitlement is expiring within 30 days. The actual botnet package update still works within the active entitlement duration.

689605

On some browser versions, the GUI displays a blank dialog when creating custom application or IPS signatures. Affected browsers: Firefox 85.0, Microsoft Edge 88.0, and Chrome 88.0.

695163

When there are a lot of historical logs from FortiAnalyzer, the FortiGate GUI Forward Traffic log page can take time to load if there is no specific filter for the time range.

Workaround: provide a specific time range filter, or use the FortiAnalyzer GUI to view the logs.

HA

Bug ID

Description

623642

It takes up to 10 seconds to get NPU VDOM link up when rebooting primary unit.

637843

HA secondary device is reporting multiple events (DDNS update failed).

638287

private-data-encryption causes cluster to be periodically out of sync due to customer certificates.

645293

traceroute not working in asymmetric FGSP environment.

656099

mgmt interfaces are excluded for heartbeat interfaces (even if dedicate-mgmt is not enabled).

Intrusion Prevention

Bug ID

Description

565747

IPS engine 5.00027 has signal 11 crash.

586544

IPS intelligent mode not working when reflect sessions are created on different physical interfaces.

587668

IPS engine 5.00035 has signal 11 crash.

590087

When IPS pcap is enabled, traffic is intermittently disrupted after disk I/O reaches IOPS limit.

631381

RDP NLA authentication blocked by FortiGate when enabling IPS profile in the security group (central NAT).

IPsec VPN

Bug ID

Description

592361

Cannot pass traffic over ADVPN if: tunnel-search is set to nexthop, net-device disable, mode-cfg enable, and add-route disable.

606129

iked crash when proposal is AES-GCM.

610390

IKEv2 EAP certificate authentication failings after upgrading from to 6.2.1 to 6.2.3.

610558

ADVPN cannot establish after primary ISP has recovered from failure and traffic between spokes is dropped.

631968

IKE daemon signal 6 crash when phase1 add-gw-route is enabled.

634883

IKE crashes at ike_hasync__xauth.

635325

Static route for site-to site VPN remains active even when the tunnel is down.

Log & Report

Bug ID

Description

605405

IPS logs are recorded twice with TCP offloading on virtual server.

606533

User observes FGT internal error while trying to log in or activate FortiGate Cloud from the web UI.

608565

FortiGate sends incorrect long session logs to FortiGate Cloud.

616835

Logs from HA secondary unit cannot be uploaded to FortiCloud.

628358

Logs are not generated in GUI and CLI after checking the file system (after power cable disconnected).

635013

FortiOS gives wrong time stamp when querying FortiGate Cloud log view.

643840

vwlservice should log the SD-WAN rule and not an internet service; impacts FortiAnalyzer SD-WAN monitor widgets and reports.

Proxy

Bug ID

Description

582475

WAD is crashing with signal 6 in wad_fmem_free when processing SMB2/CIFS.

586909

When CIFS profile is loaded, using MacOS to access Windows Share causes WAD to crash.

612333

In FortiGate with squid configuration (proxy chain), get ERR_SSL_PROTOCOL_ERROR when using Google Chrome with certificate/deep inspection.

615791

Abbreviated handshake randomly receives fatal illegal_parameter against zendesk.com services/sites.

629504

SSH status in SSL profile changes to deep-inspection from disable after upgrading.

637389

The WAD process is crashing multiple times.

640427

Web proxy WAD crash under WAN Opt auto-active mode.

648831

WAD memory leak caused by Kerberos proxy authentication.

REST API

Bug ID

Description

584631 REST API administrator with token unable to configure HA setting (via login session works).

Routing

Bug ID

Description

537354

BFD/BGP dropping when outbandwidth is set on interface.

602826

BGP route is not added in to kernel during ADVPN test.

608106

BGP daemon crashes when TCP connection is broken by peer.

611539

Editing/adding any address object that is referenced in policy is generating false positive SD-WAN alert messages.

613716

Local-out TCP traffic changes output interface when irrelevant interface is flapping that causes disconnections.

619343

Cannot ping old VRIPs when adding new VRIPs.

625345

The single BGP update message contains the same prefix in withdrawn routes and NLRI (advertised route).

627951

NTP and FSSO not following SD-WAN rules.

629521

SD-WAN IPv6 default route cannot be redistributed into BGP using set default-originateroutemap6.

635716

FortiGuard web filter traffic also needs to follow SD-WAN service.

666829

Application bfdd crashes.

Security Fabric

Bug ID

Description

597139

Crash happens due to segfault in CSF.

649556

FortiNAC requests to FortiGate can timeout on low-end models when there are many concurrent requests.

SSL VPN

Bug ID

Description

505986

On IE 11, SSL VPN web portal displays blank page title {{::data.portal.heading}} after authentication.

595505

FortiGate does not send client IP address as a framed IP address to RADIUS server in RADIUS accounting request message.

606271

Double redirection through SSL web mode not working.

607687

RDP connection via SSL VPN web portal does not work with UserPrincipalName (UPN) and NLA security.

610579

Videos from live cameras via SSL VPN web mode not working.

620508

CLI command get vpn ssl monitor displays users from other VDOM.

622068

Adding FQDN routing address in split tunnel configuration injects single route in client for multiple A records.

622110

SSL VPN disconnected when importing or renaming CA certificates.

623231

Pages could not be shown after logging in to back-end application server.

623379

Memory corrupt in some DNS callback cases causes SSL VPN crash.

624145

An internal website via SSL VPN web portal failed to load an external resource.

624899

Log entry for tunnel stats shows wrong tunnel ID when using RDP bookmark.

625301

Riverbed SteelCentral AppResponse login form is not displaying in SSL VPN web mode.

628821

Internal aixws7test2 portal is not loading in SSL VPN web mode.

629190

After SSL VPN proxy, some JS files of hapi website could not work.

631130

Internal site http://vau***.com not completely loading through SSL VPN web mode bookmark.

633812

For guacd daemon generated for RDP session, it would sometimes be in an unknown state with 100% CPU and could not be released.

634991

Internal server error 500 while accessing contolavdip portal in SSL VPN web mode.

635307

Map could not be displayed correctly in SSL VPN web mode.

636984

Pro***.com not loading properly in SSL VPN web mode.

637018

After the upgrade to 6.0.10/6.2.4/6.4.0, SSL VPN portal mapping/remote authentication is matching user into the incorrect group.

638733

Internal website hosted in bookmark https://int***.cat is not loading completely in SSL VPN web mode.

648369

Some JS files of jira.***.vwg could not run in SSL VPN web mode.

649130

SSL VPN log entries display users from other VDOMs.

654534

SAML authentications occurring through SSL VPN web mode are not completing.

Switch Controller

Bug ID

Description

588584

GUI should add support to allow using switch VLAN interface under a tenant VDOM on a managed switch VDOM.

605864

If the firewall is downgraded from 6.2.3 to 6.2.2, the FortiLink interface looses its CAPWAP setting.

System

Bug ID

Description

464340

EHP drops for units with no NP service module.

503125

FG-100D traffic traversing port1-port16 only saturates CPU0.

567019

CP9 VPN queue tasklet unable to handle kernel NULL pointer dereference at 0000000000000120 and device reboots.

576323

SFP+ 1G speed should be supported on FG-1100E, FG-1800F, FG-2200E, and FG-3300E series.

578031

FortiManager Cloud cannot be removed once the FortiGate has trouble on contract.

594871

Potential memory leak triggered by FTP command in WAD.

600032

SNMP does not provide routing table for non-management VDOM.

604613

sentbyte of NTP on local traffic log shows as 0 bytes, even though NTP client receives the packet.

607357

High CPU usage issue caused by high depth expectation sessions in the same hash table slot.

608442

After a reboot of the PPPoE server, the FortiGate (PPPoE clients, 35 clients) keeps flapping (connection down and up) for a long time before connecting successfully.

611512

When a LAG is created between 10 GE SFP+ slots and 25 GE SFP28/10 GE SFP+ slots, only about 50% of the sessions can be created. Affected models: FG-110xE, FG-220xE, and FG-330xE.

612351

Many no session matched logs while managing FortiGate.

613017

ip6-extra-addr does not perform router advertisement after reboot in HA.

613136

Uninitialized variable that may potentially cause httpsd signal 6 and 11 crash issue.

615435

Crashes might happen due to CMDB query allocation fail that causes a segfault.

616022

Long delay and cmdbsvr at 100% CPU consumption when modifying address objects and address groups via GUI or REST API.

617134

Traffic not showing statistics for VLAN interfaces base on hardware switch.

617154

Fortinet_CA is missing in FG-3400E.

617409

The FG-800D HA LED is off when HA status is normal.

618762

Fail to detect transceiver on all SFP28/QSFP ports. Affected platforms: FG-3300E and FG-3301E.

620827

Over a period of time, FG-60E goes into memory conserve mode caused by resource leak of sepmd daemon.

623501

FG-80D may fail to boot due to a limitation in the size of the bootloader and kernel.

626371

Request to blocked signature with SSL mirrored traffic capture causes FG-500E to reboot.

632353

Virtual WAN link stops responding after 45 members.

632635

Frame size option in sniffer does not work.

633102

DHCPv6 client's DUID generated on two different FortiGates match.

634600

FWF-60E-DSL ADSL2+ connection provided by BT in the UK does not work after upgrading from 6.0.9 to 6.2.4.

636069

Unable to handle kernel NULL pointer dereference at 000000000000008f.

638041

SFP28 port group (ha1, ha2, port1 and port2) missing 1000full speed option. Affected platforms: FG-220xE, FG-330xE, FG-340xE, and FG-360xE.

641419

FG-40F LAN interfaces are down after upgrading to 6.2.4 (build 5632).

647718

VDOM with long name cannot be deleted.

648977

Sometimes when updating the FortiGate license, there is a certificate verification failure.

654159

NP6Xlite traffic not sent over the tunnel when NPU is enabled.

694202

stpforward does not work with LAG interfaces on a transparent VDOM.

Upgrade

Bug ID

Description

615972

After upgrading from 6.2.2 to 6.2.3, the description field in the table has disappeared under DHCP reservation.

635589

Upon upgrading to FortiOS 6.2.4, DoS policies configured on interfaces may drop traffic that is passing through the DoS policy configuration. Note that this can occur if the DoS policy is configured in drop or monitor mode.

Workaround: disable the DoS policy.

649948

Upon upgrading to an affected 6.2 or 6.4 firmware, IKE/IPsec SAs are not synced to the primary when HA uninterruptible-upgrade is enabled. As a result, IPsec traffic from a client may be detected as having an invalid SPI until the client starts a new negotiation.

User & Device

Bug ID

Description

591170

Sessions are removed from the session table when FSSO group order is changed.

591461

FortiGate does not send user IP to TACACS server during authentication.

595583

Device identification via LLDP on an aggregate interface does not work.

605838

Device identification scanner crashes on receipt of SSDP search.

621161

src-vis crashes on receipt of certain ONVIF packets.

626532

fnbamd is not sending Calling-Station-Id in Access-Request for L2TP/IPsec since 5.4.0.

VM

Bug ID

Description

587180

FG-VM64-KVM is unable to boot up properly when doing a hard reboot with the host.

587757

FG-VM image unable to be deployed on AWS with additional HDD(st1) disk type.

596742

Azure SDN connector replicates configuration from primary device to secondary device during configuration restore.

605511

FG-VM-GCP reboots a couple of times due to kernel panic.

606527

GUI and CLI interface dropdown lists are inconsistent.

608881

IPsec VPN tunnel not staying up after failing over with AWS A-P cross-AZ setup.

613730

Unable to update routing table for a resource group in a different subscription with FortiGate Azure SDN.

623376

Cross-zone HA breaks after upgrading to 6.4.0 because upgrade process does not add relevant items under vdom-exception.

624657

Azure changes FPGA for Accelerated Networking live and VM loses SR-IOV interfaces.

626705

By assigning port1 as the HA management port, the HA secondary unit node is now able to send system information to the Azure portal through waagent so that up-to-date information is displayed on the Azure dashboard.

If port1 is not used as the HA management port, the Azure display and Azure Security Center alerts will not reflect the correct state of the node, which may result in unnecessary alarms.

634499

AWS FortiGate NIC gets swapped between port2 and port3 after FortiGate reboots.

685782

HTTPS administrative interface responds over heartbeat port on Azure FortiGate despite allowaccess settings.

VoIP

Bug ID

Description

620742

RAS helper does not NAT the port 1720 in the callSignalAddress field of the RegistrationRequest packet sent from the endpoint.

630024

voipd crashes repeatedly.

Web Filter

Bug ID

Description

657466

local urlfilter configuration in a flow mode web filter does not work when the matched FortiGuard category is also enabled in the web filter profile.

WiFi Controller

Bug ID

Description

625326

FortiAP not coming online on FG-PPPoE interface.

641811

In FG-100F/101F with PPPoE interface, the FortiGate could not manage FortiAP.