Fortinet black logo

FortiGate-6000 and FortiGate-7000 Release Notes

Resolved issues

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 6.2.7 Build 1179. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 6.2.7 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.2.7 Build 1179.

Bug ID

Description

572435 700563 705117 718918

Resolved an issue that created duplicate backup routes after an HA failover. The same issue caused proto=20 routes to be deleted before route-ttl ends and sometimes caused excess memory usage. You can use the following command to clear proto=20 routes (also called backup routes): diagnose test application chlbd 15.

586808

The GUI no longer incorrectly includes the mgmt-vdom when calculating the number of VDOMs.

587437

Running a packet capture from the GUI now works as expected.

600486 601006 671653 709905

Resolved an issue that resulted in a FGCP HA cluster entering conserve mode because of low memory when the cluster is managing a large number of active RSSO or FSSO users. The issue would often happen when the secondary FortiGate-6000 or 7000 restarted.

678572

Resolved an issue that resulted in displaying inaccurate interface bandwidth usage information on the FortiGate-7000F GUI.

688572 715613

Improved FIB synchronization for the FortiGate-6000 management board or FortiGate-7000 FIMs. The management board or either FIM can now request to download the FIB from the primary FPC or FPM when incremental FIB synchronization is interrupted. This also helps resolve an issue with the management board or primary FIM being unable to accurately synchronize the system routing table with FortiManager.

689042

Resolved an issue that caused the fgfmsd process to crash when running configuration scripts.

693969

SNMP queries can now successfully capture FIM serial numbers.

698215

The diagnose sys npu-session list command now displays ICMP sessions.

698935

Resolved an issue that caused FortiGate-7000F load balancing to send fragmented and non-fragmented packets from the same session to different FPMs.

701302

Resolved an issue that can cause the hasync process to crash on one or more FPCs or FPMs when the system is managing a large number of users.

702915

Resolved an issue that could prevent incremental FIB synchronization updates from resuming after the FIB is downloaded from the primary FPC or FPM after an error condition.

703269 703296

Adjusted the logic used during system startup to record the status of FPCs and FPMs and the order in which VDOMs are created.

703640

Corrected overlapping MAC addresses found on two internal interfaces.

703855

Resolved an issue that caused proto=18 routes to get stuck on FPMs that are not the primary FPM during FIB delete synchronization events.

704235

Resolved an issue that prevented the FortiGate from recording the number of bytes received by a newly configured LAG or redundant interface.

705582

Resolved an issue that could sometimes prevent the FortiGate from deleting all VDOMs after a factory reset.

707028

Resolved a timer problem that kept IPv6 FTP pinhole sessions in NP7 processor session tables for too long.

707759

The diagnose ip route delete command can now be used to delete HA routes from FPCs or FPMs in a secondary FortiGate-6000 or 7000 in a FGCP HA configuration.

707785

Resolved an issue that caused BGP to stop working after an FIM failover or restart.

709848 716158

Fixed syntax errors in the FORTINET-CORE-MIB.mib FORTINET-FORTIGATE-MIB.mib files.

710627

On FortiGate-7000E system with QSFP28 interfaces, the 40G speed setting is now only available if the interface is configured using set qsfp28-40g-port <interface> option under config system global.

711212

Resolved an issue that caused flow rules based on the source interface to be ignored after a system restart.

712020

The expected options are now available when configuring the SLBC management interface from the CLI.

712200

Resolved an issue that could prevent syslog messages from being generated on an FPM when the system is processing a large number of sessions.

712327

MAC addresses set using the macaddr interface option now persist after the FortiGate-6000 or 7000 restarts.

712404

Resolved an issue that displayed the message NP7: None NP interface 1-mgmt1 is in a NP LAG interface on the CLI console while editing a management LAG.

712835

Resolved an issue that could sometimes prevented FortiOS from receiving accurate chassis information, such as the chassis serial number, from the SMM.

713577

Setting the SLBC management interface to a management LAG no longer causes an error message when the system starts up. After system startup, special managements ports work as expected.

713965

Proto_state is now set correctly for NP7 TCP sessions in the TIME_WAIT state.

715376

Improved the accuracy of the Dataplane and Interface Bandwidth dashboard wdgets.

716377

Resolved an issue that caused multiple HA failovers that would result all entries being removed from the FIB.

718394 Resolved an FGCP HA cluster issue that caused the cluster to incorrectly use the primary FortiGate's contract information instead of the contract information of the secondary FortiGate, which should have been used because the secondary FortiGate contract expired sooner.

719183

The CHLB_ROUTE_NOTIFY receive counter on FIMs no longer shows twice the actual number of messages received.

719290

Resolved an issue that could prevent Chromebook clients from communicating through L2TP IPsec tunnels.

719863

Resolved an issue that caused the hasync process to crash.

720710

Resolved an issue that caused Detected Tx Unit Hang messages to appear on the FortiGate-7000 CLI console.

720745

Resolved an issue with VLAN interfaces added to a LAG that blocked local in and passthrough traffic.

721262 Resolved an issue that resulted in proto=11 and proto=18 routes co-existing on the new primary FPC or FPM after an FPC or FPM failover.

721371

The config system global option miglog-affinity now works as expected.

721508

Resolved an issue that caused VRRP between an FGCP cluster and a router to stop working after the FGCP cluster experienced an FGCP HA failover.

721534

A message is added to the FortiGate-6000 crashlog if an FPC is shut down due to insufficient power.

722114

Resolved an issue that caused NP7 processors to block ICMP traffic from being accepted by firewall policies with IP pools.

723015

SNMP query for OID 1.3.6.1.4.1.12356.101.99.2.1.1.8 now works as expected.

723024

Resolved an issue that caused SNMP query timeouts and snmpd process crashes.

723258

Resolved an issue that could sometimes prevent the primary FortiGate in an FGCP HA cluster from sending checksum information to the secondary FortiGate.

723489

Resolved an issue related to SSH keys that could prevent a factory reset FPC or FPM from rejoining the SLBC cluster.

724866

Resolved an issue that could sometimes cause an interface to be created on an FPM with a duplicate MAC address.

725201

Both FIMs and FPMs now have the same range for the max-size option of the config log memory command.

725515 716531 716537 717136

VRRP state synchronization between FPCs and between FIMs and FPMs now works as expected.

726525

Resolved an issue that prevented synchronizing NP7 load balancing policies after the DP load distribution method is changed.

728220

Resolved an issue that delayed SNMP queries received by a LAG interface.

728934

Resolved an issue that could block traffic when first enabling Split-Task VDOM mode.

729134

Resolved an issue that could prevent OSPF from re-negotiating successfully after an FGCP HA failover.

Common vulnerabilities and exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

722850

FortiOS 6.2.7 for FortiGate-6000 and 7000 series is no longer vulnerable to the following CVE Reference:

  • CVE-2021-26110

713992

FortiOS 6.2.7 for FortiGate-6000 and 7000 series is no longer vulnerable to the following PSIRT incident number:

  • CVE-2021-26108

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 6.2.7 Build 1179. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 6.2.7 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.2.7 Build 1179.

Bug ID

Description

572435 700563 705117 718918

Resolved an issue that created duplicate backup routes after an HA failover. The same issue caused proto=20 routes to be deleted before route-ttl ends and sometimes caused excess memory usage. You can use the following command to clear proto=20 routes (also called backup routes): diagnose test application chlbd 15.

586808

The GUI no longer incorrectly includes the mgmt-vdom when calculating the number of VDOMs.

587437

Running a packet capture from the GUI now works as expected.

600486 601006 671653 709905

Resolved an issue that resulted in a FGCP HA cluster entering conserve mode because of low memory when the cluster is managing a large number of active RSSO or FSSO users. The issue would often happen when the secondary FortiGate-6000 or 7000 restarted.

678572

Resolved an issue that resulted in displaying inaccurate interface bandwidth usage information on the FortiGate-7000F GUI.

688572 715613

Improved FIB synchronization for the FortiGate-6000 management board or FortiGate-7000 FIMs. The management board or either FIM can now request to download the FIB from the primary FPC or FPM when incremental FIB synchronization is interrupted. This also helps resolve an issue with the management board or primary FIM being unable to accurately synchronize the system routing table with FortiManager.

689042

Resolved an issue that caused the fgfmsd process to crash when running configuration scripts.

693969

SNMP queries can now successfully capture FIM serial numbers.

698215

The diagnose sys npu-session list command now displays ICMP sessions.

698935

Resolved an issue that caused FortiGate-7000F load balancing to send fragmented and non-fragmented packets from the same session to different FPMs.

701302

Resolved an issue that can cause the hasync process to crash on one or more FPCs or FPMs when the system is managing a large number of users.

702915

Resolved an issue that could prevent incremental FIB synchronization updates from resuming after the FIB is downloaded from the primary FPC or FPM after an error condition.

703269 703296

Adjusted the logic used during system startup to record the status of FPCs and FPMs and the order in which VDOMs are created.

703640

Corrected overlapping MAC addresses found on two internal interfaces.

703855

Resolved an issue that caused proto=18 routes to get stuck on FPMs that are not the primary FPM during FIB delete synchronization events.

704235

Resolved an issue that prevented the FortiGate from recording the number of bytes received by a newly configured LAG or redundant interface.

705582

Resolved an issue that could sometimes prevent the FortiGate from deleting all VDOMs after a factory reset.

707028

Resolved a timer problem that kept IPv6 FTP pinhole sessions in NP7 processor session tables for too long.

707759

The diagnose ip route delete command can now be used to delete HA routes from FPCs or FPMs in a secondary FortiGate-6000 or 7000 in a FGCP HA configuration.

707785

Resolved an issue that caused BGP to stop working after an FIM failover or restart.

709848 716158

Fixed syntax errors in the FORTINET-CORE-MIB.mib FORTINET-FORTIGATE-MIB.mib files.

710627

On FortiGate-7000E system with QSFP28 interfaces, the 40G speed setting is now only available if the interface is configured using set qsfp28-40g-port <interface> option under config system global.

711212

Resolved an issue that caused flow rules based on the source interface to be ignored after a system restart.

712020

The expected options are now available when configuring the SLBC management interface from the CLI.

712200

Resolved an issue that could prevent syslog messages from being generated on an FPM when the system is processing a large number of sessions.

712327

MAC addresses set using the macaddr interface option now persist after the FortiGate-6000 or 7000 restarts.

712404

Resolved an issue that displayed the message NP7: None NP interface 1-mgmt1 is in a NP LAG interface on the CLI console while editing a management LAG.

712835

Resolved an issue that could sometimes prevented FortiOS from receiving accurate chassis information, such as the chassis serial number, from the SMM.

713577

Setting the SLBC management interface to a management LAG no longer causes an error message when the system starts up. After system startup, special managements ports work as expected.

713965

Proto_state is now set correctly for NP7 TCP sessions in the TIME_WAIT state.

715376

Improved the accuracy of the Dataplane and Interface Bandwidth dashboard wdgets.

716377

Resolved an issue that caused multiple HA failovers that would result all entries being removed from the FIB.

718394 Resolved an FGCP HA cluster issue that caused the cluster to incorrectly use the primary FortiGate's contract information instead of the contract information of the secondary FortiGate, which should have been used because the secondary FortiGate contract expired sooner.

719183

The CHLB_ROUTE_NOTIFY receive counter on FIMs no longer shows twice the actual number of messages received.

719290

Resolved an issue that could prevent Chromebook clients from communicating through L2TP IPsec tunnels.

719863

Resolved an issue that caused the hasync process to crash.

720710

Resolved an issue that caused Detected Tx Unit Hang messages to appear on the FortiGate-7000 CLI console.

720745

Resolved an issue with VLAN interfaces added to a LAG that blocked local in and passthrough traffic.

721262 Resolved an issue that resulted in proto=11 and proto=18 routes co-existing on the new primary FPC or FPM after an FPC or FPM failover.

721371

The config system global option miglog-affinity now works as expected.

721508

Resolved an issue that caused VRRP between an FGCP cluster and a router to stop working after the FGCP cluster experienced an FGCP HA failover.

721534

A message is added to the FortiGate-6000 crashlog if an FPC is shut down due to insufficient power.

722114

Resolved an issue that caused NP7 processors to block ICMP traffic from being accepted by firewall policies with IP pools.

723015

SNMP query for OID 1.3.6.1.4.1.12356.101.99.2.1.1.8 now works as expected.

723024

Resolved an issue that caused SNMP query timeouts and snmpd process crashes.

723258

Resolved an issue that could sometimes prevent the primary FortiGate in an FGCP HA cluster from sending checksum information to the secondary FortiGate.

723489

Resolved an issue related to SSH keys that could prevent a factory reset FPC or FPM from rejoining the SLBC cluster.

724866

Resolved an issue that could sometimes cause an interface to be created on an FPM with a duplicate MAC address.

725201

Both FIMs and FPMs now have the same range for the max-size option of the config log memory command.

725515 716531 716537 717136

VRRP state synchronization between FPCs and between FIMs and FPMs now works as expected.

726525

Resolved an issue that prevented synchronizing NP7 load balancing policies after the DP load distribution method is changed.

728220

Resolved an issue that delayed SNMP queries received by a LAG interface.

728934

Resolved an issue that could block traffic when first enabling Split-Task VDOM mode.

729134

Resolved an issue that could prevent OSPF from re-negotiating successfully after an FGCP HA failover.

Common vulnerabilities and exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

722850

FortiOS 6.2.7 for FortiGate-6000 and 7000 series is no longer vulnerable to the following CVE Reference:

  • CVE-2021-26110

713992

FortiOS 6.2.7 for FortiGate-6000 and 7000 series is no longer vulnerable to the following PSIRT incident number:

  • CVE-2021-26108