Fortinet black logo

FortiGate-6000 and FortiGate-7000 Release Notes

Resolved issues

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 6.4.2 Build 1749. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 6.4.2 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.4.2 Build 1749.

Bug ID

Description

607772

Resolved an issue that caused FortiGate-6000 FPCs to enter kernel conserve mode when handling a high rate of LDAP user logins.

611666

Resolved issues that caused problems with displaying the FortiGate faceplate on the System > HA GUI page of the primary FortiGate of an operating cluster.

642920

The Network > Interfaces GUI page now correctly displays information about all supported transceivers.

643032

Corrected the path used by FPCs and FPMs in the secondary FortiGate-6000 or 7000 in an HA cluster to connect to FortiSandbox.

646660

To make sure that ICMP echo requests and reply packets always go to the same FPC or FPM, the FortiGate-6000 and 7000 now always send DP ICMP packets to the DP processor, regardless of the dp-load-distribution setting.

647259

Resolved an issue that caused the Cluster Status dashboard to stop updating.

650683

The command execute ha disconnect now works as expected.

653682

The command get system interface transceiver now works as expected.

660032

The FortiGate-6000 and 7000 startup process has been optimized to avoid data heartbeat failure during system startup.

660989

The command diagnose hardware ipmitool raw can now be used to factory reset the SMCs in a FortiGate-6000 or 7000.

663706

Resolved an issue that sometimes caused all FortiGate-6000 or 7000 interfaces to start flapping simultaneously on both chassis in an HA configuration.

665487

Resolved an issue the prevented a FortiGate-6000 or 7000 from initiating IPsec VPN tunnels when IPsec VPN load balancing is enabled.

669211

In an HA configuration, log handling allows the secondary FortiGate-6000 management board and FPCs, or FortiGate-7000 FIMs and FPMs to connect directly to remote syslog servers.

Common vulnerabilities and exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

645622

FortiOS 6.4.2 for FortiGate-6000 and 7000 series is no longer vulnerable to the following CVE Reference:

  • CVE-2021-26110

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 6.4.2 Build 1749. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 6.4.2 release notes also apply to FortiGate-6000 and 7000 FortiOS 6.4.2 Build 1749.

Bug ID

Description

607772

Resolved an issue that caused FortiGate-6000 FPCs to enter kernel conserve mode when handling a high rate of LDAP user logins.

611666

Resolved issues that caused problems with displaying the FortiGate faceplate on the System > HA GUI page of the primary FortiGate of an operating cluster.

642920

The Network > Interfaces GUI page now correctly displays information about all supported transceivers.

643032

Corrected the path used by FPCs and FPMs in the secondary FortiGate-6000 or 7000 in an HA cluster to connect to FortiSandbox.

646660

To make sure that ICMP echo requests and reply packets always go to the same FPC or FPM, the FortiGate-6000 and 7000 now always send DP ICMP packets to the DP processor, regardless of the dp-load-distribution setting.

647259

Resolved an issue that caused the Cluster Status dashboard to stop updating.

650683

The command execute ha disconnect now works as expected.

653682

The command get system interface transceiver now works as expected.

660032

The FortiGate-6000 and 7000 startup process has been optimized to avoid data heartbeat failure during system startup.

660989

The command diagnose hardware ipmitool raw can now be used to factory reset the SMCs in a FortiGate-6000 or 7000.

663706

Resolved an issue that sometimes caused all FortiGate-6000 or 7000 interfaces to start flapping simultaneously on both chassis in an HA configuration.

665487

Resolved an issue the prevented a FortiGate-6000 or 7000 from initiating IPsec VPN tunnels when IPsec VPN load balancing is enabled.

669211

In an HA configuration, log handling allows the secondary FortiGate-6000 management board and FPCs, or FortiGate-7000 FIMs and FPMs to connect directly to remote syslog servers.

Common vulnerabilities and exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

645622

FortiOS 6.4.2 for FortiGate-6000 and 7000 series is no longer vulnerable to the following CVE Reference:

  • CVE-2021-26110