Known issues
The following issues have been identified in version 7.2.3. To inquire about a particular bug or report a bug, please contact Customer Service & Support.
Anti Virus
Bug ID |
Description |
---|---|
800731 |
Flow AV sends HTML files to the FortiGate Cloud Sandbox every time when HTML is not configured in file list. |
Application Control
Bug ID |
Description |
---|---|
829458 |
Remove option to block QUIC by default. |
Firewall
Bug ID |
Description |
---|---|
728734 |
The VIP group hit count in the table (Policy & Objects > Virtual IPs) is not reflecting the correct sum of VIP members. |
824091 |
Promethean Screen Share (multicast) is not working on the member interfaces of a software switch. |
854107 |
NGFW VDOM incorrectly includes all interfaces belonging to the root VDOM on interface and policy related GUI pages. |
FortiView
Bug ID |
Description |
---|---|
838652 |
The FortiView Sessions monitor displays VDOM sessions from other VDOMs. |
GUI
Bug ID |
Description |
---|---|
440197 |
On the System > FortiGuard page, the override FortiGuard server for AntiVirus & IPS Updates shows an Unknown status, even if the server is working correctly. This is a display issue only; the override feature is working properly. |
677806 |
On the Network > Interfaces page when VDOM mode is enabled, the Global view incorrectly shows the status of IPsec tunnel interfaces from non-management VDOMs as up. The VDOM view shows the correct status. |
719476 |
FortiLink NAC matched device is displayed in the CLI but not in the GUI under WiFi & Switch Controller > NAC Policies > View Matched Devices. |
729406 |
New IPsec design |
749843 |
Bandwidth widget does not display traffic information for VLAN interfaces when a large number of VLAN interfaces are configured. |
780832 |
WiFi & Switch Controller > Managed FortiAPs list does not load if there is an invalid or unsupported FortiAP configured. |
794656 |
After rebooting, the Licenses widget shows an |
804584 |
On the policy dialog page, the Select Entries box for the Service field does not list all service objects if an IPv6 address is in the policy. |
807197 |
High |
819272 |
When a VLAN belongs to a zone, and the zone is used in a policy, editing the VLAN ID changes the policy's position in the table. |
820909 |
On the Policy & Objects > Schedules page, when the end date of a one-time schedule is set to the 31st of a month, it gets reset to the 1st of the same month. Workaround: use CLI to set schedules with an end date of 31st. |
829736 |
Incorrect information is being displayed for the HA role on the System > HA page. |
829773 |
Unable to load the Network > SD-WAN > SD-WAN Rules table sometimes due to a JavaScript error. |
831439 |
On the WiFi & Switch Controller > SSIDs page, multiple DHCP servers for the same range can be configured on an interface if the interface name contains a comma (,) character. |
831885 |
Unable to access GUI via HA management interface of secondary unit. |
833306 |
Intermittent error, Failed to retrieve FortiView data, appears on real-time FortiView Sources and FortiView Destination monitor pages. |
833774 |
GUI needs to allow the members of the software switch interface to be used in IPv4/IPv6 multicast policy. |
837836 |
The Network > Interfaces faceplate shows two SFP interfaces, which do not exist on that FortiGate model. |
840604 |
When upgrading the FortiGate firmware upgrade from FortiGuard, update the API description text for the file name. |
842079 |
On the System > HA page, a Failed to retrieve info caution message appears when hovering over the secondary unit's Hostname. The same issue is observed on the Dashboard > Status > Security Fabric widget. |
845513 |
On G-model profiles, changing the platform mode change from single 5G (dedicated scan enabled) to dual 5G is not taking effect. |
853352 |
On the View/Edit Entries slide-out pane (Policy & Objects > Internet Service Database dialog), users cannot scroll down to the end if there are over 100000 entries. |
854529 |
The local standalone mode in a VAP configuration is disabled when viewing or updating its settings in the GUI. |
HA
Bug ID |
Description |
---|---|
788702 |
Due to an HA port (Intel i40e) driver issue, not all SW sessions are synchronized to the secondary, so there is a difference. |
818432 |
When private data encryption is enabled, all passwords present in the configuration fail to load and may cause HA failures. |
829390 |
When the internet service name management checksum is changed, it is out-of-sync when the auto-update is disabled on FortiManager. |
832470 |
HA A-P clusters keeps getting out-of-sync due to local VPN certificate. |
840305 |
Static ARP entry is removed after reboot or HA failover. |
843837 |
HA A-P virtual cluster information is not correctly presented in the GUI and CLI. |
843907 |
Session load balancing is not working in HA A-A configuration for traffic flowing via the VLAN interface when the port1 link is down on platforms with a 4.19 kernel. |
854445 |
When adding or removing an HA monitor interface, the link failure value is not updated. |
Hyperscale
Bug ID |
Description |
---|---|
804742 |
After changing hyperscale firewall policies, it may take longer than expected for the policy changes to be applied to traffic. The delay occurs because the hyperscale firewall policy engine enhancements added to FortiOS may cause the FortiGate to take extra time to compile firewall policy changes and generate a new policy set that can be applied to traffic by NP7 processors. The delay is affected by hyperscale policy set complexity, the total number of established sessions to be re-evaluated, and the rate of receiving new sessions. |
810366 |
Unrelated background traffic gets impacted when changing a policy where a hyperscale license is used. |
824733 |
IPv6 traffic continues to pass through a multi-VDOM setup, even when the static route is deleted. |
829549 |
DSE entry is being created for ALG sessions, and EIF sessions pass through. |
835697 |
Interface routes under DHCP mode remain in LPMD after moving the interface to another VDOM. |
843197 |
Output of |
843305 |
Get |
Intrusion Prevention
Bug ID |
Description |
---|---|
848003 |
FG-200E memory is not released and enters conserve mode, even after the traffic stopped. |
856837 |
When flow mode AV is enabled, IPS engine memory usage is higher with a large number of flow mode AV requests. |
IPsec VPN
Bug ID |
Description |
---|---|
763205 |
IKE crashes after HA failover when the |
815253 |
NP7 offloaded egress ESP traffic that was not sent out of the FortiGate. |
836260 |
The IPsec aggregate interface does not appear in the Interface dropdown when configuring the Interface Bandwidth widget. |
Log & Report
Bug ID |
Description |
---|---|
814758 |
Get an intermittent error when running |
821359 |
FortiGate appears to have a limitation in the syslogd filter configuration. |
825318 |
Archived Data tab is missing from intrusion prevention and application control log Details pane once |
826483 |
The |
828211 |
Policy ID filter is not working as expected. |
829862 |
On the Log & Report > ZTNA Traffic page, the client's Device ID is shown as [object Object]. The Log Details pane show the correct ID information. |
836846 |
Packet captured by firewall policy cannot be downloaded. |
837116 |
FortiCloud log statistics chart on the Log Settings page shows incorrect data. |
838253 |
FortiAnalyzer log statistics chart on the Log Settings page shows incorrect data. |
839601 |
Unable to view logs longer than 500 lines by scrolling down or using the drag down function. |
847213 |
Unable to mouse over an IP address in FortiGate logs. |
856613 |
Older Forward Traffic logs are not visible on the FortiGate with 1 hour, 24 hours, and 7 days time period after upgrading. |
858589 |
Unable to download more than 500 logs from the FortiGate GUI. |
Proxy
Bug ID |
Description |
---|---|
799237 |
WAD crash occurs when TLS/SSL renegotiation encounters an error. |
813562, 823247, 823829, 829428 |
When an LDAP user is authenticated in a firewall policy, the WAD user-info process has a memory leak causing the FortiGate to enter conserve mode. |
827882 |
One WAD daemon is consistently using 99% CPU. |
835903 |
There is no replacement message for an IPS custom signature block in a proxy inspection mode firewall policy or proxy policy. |
837724 |
WAD crash occurs. |
855882 |
Increase in WAD process memory usage after upgrading. |
REST API
Bug ID |
Description |
---|---|
836760 |
The |
Routing
Bug ID |
Description |
---|---|
769330 |
Traffic does not fail over to alternate path upon interface being down (FGR-60F in transparent mode). |
830254 |
When changing interfaces from dense mode to sparse mode, and then back to dense mode, the interfaces did not show up under dense mode. |
830383 |
Unable to configure IPsec static route. |
833399 |
Static routes are incorrectly added to the routing table, even if the IPsec tunnel type is static. |
834497 |
Traffic behaves differently for connected routes and IGP routes in an ADVPN or SD-WAN environment. |
850862 |
GUI does not allow an AS path to be to configured with multiple similar AS numbers. |
862165 |
FortiGate does not add the route in the routing table when it changes for SD-WAN members. |
Security Fabric
Bug ID |
Description |
---|---|
809106 |
Security Fabric widget and Fabric Connectors page do not identify FortiGates properly in HA. |
814796 |
The threat level threshold in the compromised host trigger does not work. |
819192 |
After adding a Fabric device widget, the device widget does not appear in the dashboard. |
824433 |
After authorizing a downstream FortiGate, an empty name and offline status appear in the device registration wizard. |
835765 |
Automation stitch trigger is not working when the threshold based email alert is enabled in the configuration. |
843043 |
Only the first ACI SDN connector can be kept after upgrading from 6.4.8 if multiple ACI SDN connectors are configured. |
844412 |
Security rating failed for custom LLDP profiles. |
848822 |
Security Rating report incorrectly lists the latest AP and switch firmware as unknown. |
852340 |
Various places in the GUI do not show the secondary HA device. |
862532 |
Unable to load topology pages for a specific Security Fabric topology on the root and downstream FortiGates. |
SSL VPN
Bug ID |
Description |
---|---|
705880 |
Updated empty group with SAML user does not trigger an SSL VPN firewall policy refresh, which causes the SAML user detection to not be successful in later usage. |
777790 |
Unable to select |
795381 |
FortiClient Windows cannot be launched with SSL VPN web portal. |
808107 |
FortiGate is not sending Accounting-Request packet that contains the Interim-Update AVP when two-factor authentication is assigned to a user (defined on the FortiGate) while connecting using SSL VPN. |
819754 |
Multiple DNS suffixes cannot be set for the SSL VPN portal. |
848067 |
RDP over VPN SSL web mode stops work after upgrading. |
Switch Controller
Bug ID |
Description |
---|---|
836604 |
The |
853718 |
Layer 3 FortiLink does not come up after upgrading. |
858113 |
Unable to view the Diagnostics and Tools page for FortiSwitch with limited access permissions using an administrative profile created on the FortiGate. |
System
Bug ID |
Description |
---|---|
780315 |
Poor CPS performance with VLAN interfaces in firewall only mode (NP7 and NP6 platforms). |
798091 |
After upgrading from 6.4.9 to 7.0.5, the FG-110xE's 1000M SFP interface may fail to auto-negotiate and cannot be up due to the missed auto-negotiation. |
798303 |
The threshold for conserve mode is lowered. |
805122 |
In FIPS-CC mode, if |
809030 |
Traffic loss occurs when running SNAT PBA pool in a hyperscale VDOM. The NP7 hardware module PRP got stuck, which caused the NP7 to hang. |
824464 |
CMDB checksum is not updated when a certificate is renewed over CMP, causing a FortiManager failure to synchronize with the certificate. |
826254 |
Get disk error message after changing disk usage to |
827240 |
FortiGate in HA may freeze and reboot. Before the reboot, softIRQ may be seen as high. This leads to a kernel panic. |
827241 |
Unable to resolve sp***.saas.ap***.com on a specific VDOM. |
837730 |
Trusted hosts are not working correctly in FortiOS 7.2.1. |
841932 |
The GUI and API stopped working after loading many interfaces due to httpsd stuck in a D state (kernel I/O socket). |
847077 |
|
853144 |
Network device kernel null pointer is causing a kernel crash. |
853794 |
Issue with the |
856202 |
Random reboots and kernel panic on NP7 cluster when the FortiGate sends a TCP RST packet and IP options are missing in the header. |
Upgrade
Bug ID |
Description |
---|---|
803041 |
Link lights on the FG-1100E fail to come up and are inoperative after upgrading. |
822844 |
Observed |
850691 |
The Workaround: upgrade from FortiOS 6.4.x to 7.0.7 and then 7.0.8. If you have already upgraded to FortiOS 7.0.8, reboot the FortiGate to automatically set |
User & Authentication
Bug ID |
Description |
---|---|
825759 |
The Device detection option is missing in the GUI for redundant interfaces (CLI is OK). |
828212 |
RADIUS Access Request message needs to be sent when the client reconnects during firewall authentication session expiration. |
865166 |
A cid scan crash occurs when device detections happen in a certain order. |
VM
Bug ID |
Description |
---|---|
825464 |
Every time the FortiGate reboots, the certificate setting reverts to |
Web Filter
Bug ID |
Description |
---|---|
766126 |
Block replacement page is not pushed automatically to replace the video content when using a video filter. |
WiFi Controller
Bug ID |
Description |
---|---|
807713 |
FortiGate is not sending RADIUS accounting message consistently to RADIUS server for wireless SSO. |
809623 |
CAPWAP traffic is dropped when |
821320 |
FG-1800F drops wireless client traffic in L2 tunneled VLAN with |
824441 |
Suggest replacing the IP Address column with MAC Address in the Collected Email widget. |
846730 |
Dynamic VLAN assignment is disabled in the GUI when editing an SSID with |
856038 |
The |
858653 |
Invalid wireless MAC OUI detected for a valid client on the network. |
ZTNA
Bug ID |
Description |
---|---|
832508 |
The EMS tag name (defined in the EMS server's Zero Trust Tagging Rules) format changed in 7.2.1 from After upgrading from 7.2.0 to 7.2.1, the EMS tag format was converted properly in the CLI configuration, but the WAD daemon is unable to recognize this new format, so the ZTNA traffic will not match any ZTNA policies with EMS tag name checking enabled. Workaround: unset the |
845321 |
An offline FortiClient should be immediately rejected by ZTNA. |