Fortinet black logo

FortiGate-6000 and FortiGate-7000 Release Notes

Resolved issues

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 6.4.12 Build 1920. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 6.4.12 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.4.12 Build 1920.

Bug ID

Description

714476 Resolved an issue that prevented console baud rate changes from being synchronized to all FPCs or FPMs if the baud rate change was made from a console session.

731789 860330

On a FortiGate-6000, when using the vd (VDOM) filter of the diagnose debug flow command from the management board CLI, the flow trace is now enabled on the management board and on the FPCs.

768931

The FortiGate-7000F GUI now correctly shows FPM-7620F P1 and P2 split interfaces.

787646 878934

Resolved an issue related to how FortiOS updates large routing configurations that could cause the fctrlproxyd process to periodically use excessive amounts of CPU time (up to 99%), usually as a result of routing configuration changes.

Restarting the fctrlproxyd process no longer causes interface flapping.

808667

The media option is now available when configuring FIM-7921F and FIM-7941F interfaces.

835847 Resolved an issue that prevented automation stitches from updating the password policy.
855340 Resolved an issue that prevented LDAP user authentication from timing out when LDAP users were configured with auth-timeout-type set to hard-timeout.

861177

Resolved an issue that could prevent the FortiGate-6000 management board for starting up, after displaying an error message similar to platform index is not found.

864629 Resolved an issue that caused excessive CPU usage when entering a command similar to dnsproxy-worker-count 48.
867049 Resolved an issue that could cause a kernel crash on a FortiGate-7000F FPM after enabling fragmented packet reassembly.
868372 Resolved an issue that caused FGSP to stop working if the FGSP configuration includes cluster synch entries that use different peer VDOMs.

871968

Fragmented packets are no longer blocked by EMAC VLAN interfaces.

871978 Resolved a FortiGate-6000 issue that could cause some interfaces to flap after manually disabling and re-enabling an interface.

874008 881503

Resolved an issue that caused a LAG interface that is operating normally to appear to be down if the min-links interface configuration option is set to 2.

874355

Resolved an issue that under some network conditions, could result in lost HA heartbeats , causing an HA failover for an FortiGate-6000 or 7000 FGCP HA cluster.

876074

The correct interface name now appears in the port statistics output of the diagnose load-balance dp show stats channel command.

879293

Administrators with read only access can now use the diagnose sniffer packet command.

886298

Resolved an issue that disabled the fctrlproxyd route after an FGCP HA failover.

891633

Resolved an issue that caused IPsec VPN tunnels to appear up on FortiGate-7000 FPMs but not processing data because tunnel setup and encryption data was not synchronized among all FPMs.

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 6.4.12 Build 1920. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 6.4.12 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.4.12 Build 1920.

Bug ID

Description

714476 Resolved an issue that prevented console baud rate changes from being synchronized to all FPCs or FPMs if the baud rate change was made from a console session.

731789 860330

On a FortiGate-6000, when using the vd (VDOM) filter of the diagnose debug flow command from the management board CLI, the flow trace is now enabled on the management board and on the FPCs.

768931

The FortiGate-7000F GUI now correctly shows FPM-7620F P1 and P2 split interfaces.

787646 878934

Resolved an issue related to how FortiOS updates large routing configurations that could cause the fctrlproxyd process to periodically use excessive amounts of CPU time (up to 99%), usually as a result of routing configuration changes.

Restarting the fctrlproxyd process no longer causes interface flapping.

808667

The media option is now available when configuring FIM-7921F and FIM-7941F interfaces.

835847 Resolved an issue that prevented automation stitches from updating the password policy.
855340 Resolved an issue that prevented LDAP user authentication from timing out when LDAP users were configured with auth-timeout-type set to hard-timeout.

861177

Resolved an issue that could prevent the FortiGate-6000 management board for starting up, after displaying an error message similar to platform index is not found.

864629 Resolved an issue that caused excessive CPU usage when entering a command similar to dnsproxy-worker-count 48.
867049 Resolved an issue that could cause a kernel crash on a FortiGate-7000F FPM after enabling fragmented packet reassembly.
868372 Resolved an issue that caused FGSP to stop working if the FGSP configuration includes cluster synch entries that use different peer VDOMs.

871968

Fragmented packets are no longer blocked by EMAC VLAN interfaces.

871978 Resolved a FortiGate-6000 issue that could cause some interfaces to flap after manually disabling and re-enabling an interface.

874008 881503

Resolved an issue that caused a LAG interface that is operating normally to appear to be down if the min-links interface configuration option is set to 2.

874355

Resolved an issue that under some network conditions, could result in lost HA heartbeats , causing an HA failover for an FortiGate-6000 or 7000 FGCP HA cluster.

876074

The correct interface name now appears in the port statistics output of the diagnose load-balance dp show stats channel command.

879293

Administrators with read only access can now use the diagnose sniffer packet command.

886298

Resolved an issue that disabled the fctrlproxyd route after an FGCP HA failover.

891633

Resolved an issue that caused IPsec VPN tunnels to appear up on FortiGate-7000 FPMs but not processing data because tunnel setup and encryption data was not synchronized among all FPMs.