Fortinet black logo

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:


Table of Contents

Known issues

The following issues have been identified in version 7.2.3. To inquire about a particular bug or report a bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

800731

Flow AV sends HTML files to the FortiGate Cloud Sandbox every time when HTML is not configured in file list.

Application Control

Bug ID

Description

829458

Remove option to block QUIC by default.

Firewall

Bug ID

Description

728734

The VIP group hit count in the table (Policy & Objects > Virtual IPs) is not reflecting the correct sum of VIP members.

824091

Promethean Screen Share (multicast) is not working on the member interfaces of a software switch.

854107

NGFW VDOM incorrectly includes all interfaces belonging to the root VDOM on interface and policy related GUI pages.

FortiView

Bug ID

Description

838652

The FortiView Sessions monitor displays VDOM sessions from other VDOMs.

GUI

Bug ID

Description

440197

On the System > FortiGuard page, the override FortiGuard server for AntiVirus & IPS Updates shows an Unknown status, even if the server is working correctly. This is a display issue only; the override feature is working properly.

677806

On the Network > Interfaces page when VDOM mode is enabled, the Global view incorrectly shows the status of IPsec tunnel interfaces from non-management VDOMs as up. The VDOM view shows the correct status.

719476

FortiLink NAC matched device is displayed in the CLI but not in the GUI under WiFi & Switch Controller > NAC Policies > View Matched Devices.

729406

New IPsec design tunnel-id still displays the gateway as an IP address, when it should be a tunnel ID.

749843

Bandwidth widget does not display traffic information for VLAN interfaces when a large number of VLAN interfaces are configured.

780832

WiFi & Switch Controller > Managed FortiAPs list does not load if there is an invalid or unsupported FortiAP configured.

794656

After rebooting, the Licenses widget shows an Unable to connect to FortiGuard servers message for ten minutes.

804584

On the policy dialog page, the Select Entries box for the Service field does not list all service objects if an IPv6 address is in the policy.

807197

High iowait CPU usage and memory consumption issues caused by report runner.

819272

When a VLAN belongs to a zone, and the zone is used in a policy, editing the VLAN ID changes the policy's position in the table.

820909

On the Policy & Objects > Schedules page, when the end date of a one-time schedule is set to the 31st of a month, it gets reset to the 1st of the same month.

Workaround: use CLI to set schedules with an end date of 31st.

829736

Incorrect information is being displayed for the HA role on the System > HA page.

829773

Unable to load the Network > SD-WAN > SD-WAN Rules table sometimes due to a JavaScript error.

831439

On the WiFi & Switch Controller > SSIDs page, multiple DHCP servers for the same range can be configured on an interface if the interface name contains a comma (,) character.

831885

Unable to access GUI via HA management interface of secondary unit.

833306

Intermittent error, Failed to retrieve FortiView data, appears on real-time FortiView Sources and FortiView Destination monitor pages.

833774

GUI needs to allow the members of the software switch interface to be used in IPv4/IPv6 multicast policy.

837836

The Network > Interfaces faceplate shows two SFP interfaces, which do not exist on that FortiGate model.

840604

When upgrading the FortiGate firmware upgrade from FortiGuard, update the API description text for the file name.

842079

On the System > HA page, a Failed to retrieve info caution message appears when hovering over the secondary unit's Hostname. The same issue is observed on the Dashboard > Status > Security Fabric widget.

845513

On G-model profiles, changing the platform mode change from single 5G (dedicated scan enabled) to dual 5G is not taking effect.

853352

On the View/Edit Entries slide-out pane (Policy & Objects > Internet Service Database dialog), users cannot scroll down to the end if there are over 100000 entries.

854529

The local standalone mode in a VAP configuration is disabled when viewing or updating its settings in the GUI.

HA

Bug ID

Description

788702

Due to an HA port (Intel i40e) driver issue, not all SW sessions are synchronized to the secondary, so there is a difference.

818432

When private data encryption is enabled, all passwords present in the configuration fail to load and may cause HA failures.

829390

When the internet service name management checksum is changed, it is out-of-sync when the auto-update is disabled on FortiManager.

832470

HA A-P clusters keeps getting out-of-sync due to local VPN certificate.

840305

Static ARP entry is removed after reboot or HA failover.

843837

HA A-P virtual cluster information is not correctly presented in the GUI and CLI.

843907

Session load balancing is not working in HA A-A configuration for traffic flowing via the VLAN interface when the port1 link is down on platforms with a 4.19 kernel.

854445

When adding or removing an HA monitor interface, the link failure value is not updated.

Hyperscale

Bug ID

Description

804742

After changing hyperscale firewall policies, it may take longer than expected for the policy changes to be applied to traffic. The delay occurs because the hyperscale firewall policy engine enhancements added to FortiOS may cause the FortiGate to take extra time to compile firewall policy changes and generate a new policy set that can be applied to traffic by NP7 processors. The delay is affected by hyperscale policy set complexity, the total number of established sessions to be re-evaluated, and the rate of receiving new sessions.

810366

Unrelated background traffic gets impacted when changing a policy where a hyperscale license is used.

824733

IPv6 traffic continues to pass through a multi-VDOM setup, even when the static route is deleted.

829549

DSE entry is being created for ALG sessions, and EIF sessions pass through.

835697

Interface routes under DHCP mode remain in LPMD after moving the interface to another VDOM.

843197

Output of diagnose sys npu-session list/list-full does not mention policy route information.

843305

Get PARSE SKIP ERROR=17 NPD ERR PBR ADDRESS console error log when system boots up.

Intrusion Prevention

Bug ID

Description

848003

FG-200E memory is not released and enters conserve mode, even after the traffic stopped.

856837

When flow mode AV is enabled, IPS engine memory usage is higher with a large number of flow mode AV requests.

IPsec VPN

Bug ID

Description

763205

IKE crashes after HA failover when the enforce-unique-id option is enabled.

815253

NP7 offloaded egress ESP traffic that was not sent out of the FortiGate.

836260

The IPsec aggregate interface does not appear in the Interface dropdown when configuring the Interface Bandwidth widget.

Log & Report

Bug ID

Description

814758

Get an intermittent error when running execute log fortianalyzer-cloud test-connectivity.

821359

FortiGate appears to have a limitation in the syslogd filter configuration.

825318

Archived Data tab is missing from intrusion prevention and application control log Details pane once log-packet is enabled.

826483

The dstname log field cannot store more than 66 characters.

828211

Policy ID filter is not working as expected.

829862

On the Log & Report > ZTNA Traffic page, the client's Device ID is shown as [object Object]. The Log Details pane show the correct ID information.

836846

Packet captured by firewall policy cannot be downloaded.

837116

FortiCloud log statistics chart on the Log Settings page shows incorrect data.

838253

FortiAnalyzer log statistics chart on the Log Settings page shows incorrect data.

839601

Unable to view logs longer than 500 lines by scrolling down or using the drag down function.

847213

Unable to mouse over an IP address in FortiGate logs.

856613

Older Forward Traffic logs are not visible on the FortiGate with 1 hour, 24 hours, and 7 days time period after upgrading.

858589

Unable to download more than 500 logs from the FortiGate GUI.

Proxy

Bug ID

Description

799237

WAD crash occurs when TLS/SSL renegotiation encounters an error.

813562, 823247,

823829, 829428

When an LDAP user is authenticated in a firewall policy, the WAD user-info process has a memory leak causing the FortiGate to enter conserve mode.

827882

One WAD daemon is consistently using 99% CPU.

835903

There is no replacement message for an IPS custom signature block in a proxy inspection mode firewall policy or proxy policy.

837724

WAD crash occurs.

855882

Increase in WAD process memory usage after upgrading.

REST API

Bug ID

Description

836760

The start parameter has no effect with the /api/v2/monitor/user/device/query API call.

Routing

Bug ID

Description

769330

Traffic does not fail over to alternate path upon interface being down (FGR-60F in transparent mode).

830254

When changing interfaces from dense mode to sparse mode, and then back to dense mode, the interfaces did not show up under dense mode.

830383

Unable to configure IPsec static route.

833399

Static routes are incorrectly added to the routing table, even if the IPsec tunnel type is static.

834497

Traffic behaves differently for connected routes and IGP routes in an ADVPN or SD-WAN environment.

850862

GUI does not allow an AS path to be to configured with multiple similar AS numbers.

862165

FortiGate does not add the route in the routing table when it changes for SD-WAN members.

Security Fabric

Bug ID

Description

809106

Security Fabric widget and Fabric Connectors page do not identify FortiGates properly in HA.

814796

The threat level threshold in the compromised host trigger does not work.

819192

After adding a Fabric device widget, the device widget does not appear in the dashboard.

824433

After authorizing a downstream FortiGate, an empty name and offline status appear in the device registration wizard.

835765

Automation stitch trigger is not working when the threshold based email alert is enabled in the configuration.

843043

Only the first ACI SDN connector can be kept after upgrading from 6.4.8 if multiple ACI SDN connectors are configured.

844412

Security rating failed for custom LLDP profiles.

848822

Security Rating report incorrectly lists the latest AP and switch firmware as unknown.

852340

Various places in the GUI do not show the secondary HA device.

862532

Unable to load topology pages for a specific Security Fabric topology on the root and downstream FortiGates.

SSL VPN

Bug ID

Description

705880

Updated empty group with SAML user does not trigger an SSL VPN firewall policy refresh, which causes the SAML user detection to not be successful in later usage.

777790

Unable to select vip64 in nat64 firewall policy in the CLI if the srcintf is an SSL VPN interface.

795381

FortiClient Windows cannot be launched with SSL VPN web portal.

808107

FortiGate is not sending Accounting-Request packet that contains the Interim-Update AVP when two-factor authentication is assigned to a user (defined on the FortiGate) while connecting using SSL VPN.

819754

Multiple DNS suffixes cannot be set for the SSL VPN portal.

848067

RDP over VPN SSL web mode stops work after upgrading.

Switch Controller

Bug ID

Description

836604

The 40000cr4 port speed is not available under the switch-controller managed-switch port speed settings.

853718

Layer 3 FortiLink does not come up after upgrading.

858113

Unable to view the Diagnostics and Tools page for FortiSwitch with limited access permissions using an administrative profile created on the FortiGate.

System

Bug ID

Description

780315

Poor CPS performance with VLAN interfaces in firewall only mode (NP7 and NP6 platforms).

798091

After upgrading from 6.4.9 to 7.0.5, the FG-110xE's 1000M SFP interface may fail to auto-negotiate and cannot be up due to the missed auto-negotiation.

798303

The threshold for conserve mode is lowered.

805122

In FIPS-CC mode, if cfg-save is set to revert, the system will halt a configuration change or certificate purge.

809030

Traffic loss occurs when running SNAT PBA pool in a hyperscale VDOM. The NP7 hardware module PRP got stuck, which caused the NP7 to hang.

824464

CMDB checksum is not updated when a certificate is renewed over CMP, causing a FortiManager failure to synchronize with the certificate.

826254

Get disk error message after changing disk usage to wanopt.

827240

FortiGate in HA may freeze and reboot. Before the reboot, softIRQ may be seen as high. This leads to a kernel panic.

827241

Unable to resolve sp***.saas.ap***.com on a specific VDOM.

837730

Trusted hosts are not working correctly in FortiOS 7.2.1.

841932

The GUI and API stopped working after loading many interfaces due to httpsd stuck in a D state (kernel I/O socket).

847077

Can't find xitem. Drop the response. error appears for DHCPOFFER packets in the DHCP relay debug.

853144

Network device kernel null pointer is causing a kernel crash.

853794

Issue with the server_host_key_algorithm compatibility when using SSH on SolarWinds.

856202

Random reboots and kernel panic on NP7 cluster when the FortiGate sends a TCP RST packet and IP options are missing in the header.

Upgrade

Bug ID

Description

803041

Link lights on the FG-1100E fail to come up and are inoperative after upgrading.

822844

Observed Node exiting due to unhandled rejection error messages in crash log after upgrading to 7.2.1.

850691

The endpoint-control fctems entry 0 is added after upgrading from 6.4 to 7.0.8 when the FortiGate does not have EMS server, which means the endpoint-control fctems feature was not enabled previously. This leads to a FortiManager installation failure.

Workaround: upgrade from FortiOS 6.4.x to 7.0.7 and then 7.0.8. If you have already upgraded to FortiOS 7.0.8, reboot the FortiGate to automatically set endpoint-control fctems to 1.

User & Authentication

Bug ID

Description

825759

The Device detection option is missing in the GUI for redundant interfaces (CLI is OK).

828212

RADIUS Access Request message needs to be sent when the client reconnects during firewall authentication session expiration.

865166

A cid scan crash occurs when device detections happen in a certain order.

VM

Bug ID

Description

825464

Every time the FortiGate reboots, the certificate setting reverts to self-sign under config system ftm-push.

Web Filter

Bug ID

Description

766126

Block replacement page is not pushed automatically to replace the video content when using a video filter.

WiFi Controller

Bug ID

Description

807713

FortiGate is not sending RADIUS accounting message consistently to RADIUS server for wireless SSO.

809623

CAPWAP traffic is dropped when capwap-offload is enabled.

821320

FG-1800F drops wireless client traffic in L2 tunneled VLAN with capwap-offload enabled.

824441

Suggest replacing the IP Address column with MAC Address in the Collected Email widget.

846730

Dynamic VLAN assignment is disabled in the GUI when editing an SSID with radius mac-auth and dynamic-vlan enabled.

856038

The voice-enterprise value changed after upgrading.

858653

Invalid wireless MAC OUI detected for a valid client on the network.

ZTNA

Bug ID

Description

832508

The EMS tag name (defined in the EMS server's Zero Trust Tagging Rules) format changed in 7.2.1 from FCTEMS<serial_number>_<tag_name> to EMS<id>_ZTNA_<tag_name>.

After upgrading from 7.2.0 to 7.2.1, the EMS tag format was converted properly in the CLI configuration, but the WAD daemon is unable to recognize this new format, so the ZTNA traffic will not match any ZTNA policies with EMS tag name checking enabled.

Workaround: unset the ztna-ems-tag in the ZTNA firewall proxy policy, and then set it again.

845321

An offline FortiClient should be immediately rejected by ZTNA.

Known issues

The following issues have been identified in version 7.2.3. To inquire about a particular bug or report a bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

800731

Flow AV sends HTML files to the FortiGate Cloud Sandbox every time when HTML is not configured in file list.

Application Control

Bug ID

Description

829458

Remove option to block QUIC by default.

Firewall

Bug ID

Description

728734

The VIP group hit count in the table (Policy & Objects > Virtual IPs) is not reflecting the correct sum of VIP members.

824091

Promethean Screen Share (multicast) is not working on the member interfaces of a software switch.

854107

NGFW VDOM incorrectly includes all interfaces belonging to the root VDOM on interface and policy related GUI pages.

FortiView

Bug ID

Description

838652

The FortiView Sessions monitor displays VDOM sessions from other VDOMs.

GUI

Bug ID

Description

440197

On the System > FortiGuard page, the override FortiGuard server for AntiVirus & IPS Updates shows an Unknown status, even if the server is working correctly. This is a display issue only; the override feature is working properly.

677806

On the Network > Interfaces page when VDOM mode is enabled, the Global view incorrectly shows the status of IPsec tunnel interfaces from non-management VDOMs as up. The VDOM view shows the correct status.

719476

FortiLink NAC matched device is displayed in the CLI but not in the GUI under WiFi & Switch Controller > NAC Policies > View Matched Devices.

729406

New IPsec design tunnel-id still displays the gateway as an IP address, when it should be a tunnel ID.

749843

Bandwidth widget does not display traffic information for VLAN interfaces when a large number of VLAN interfaces are configured.

780832

WiFi & Switch Controller > Managed FortiAPs list does not load if there is an invalid or unsupported FortiAP configured.

794656

After rebooting, the Licenses widget shows an Unable to connect to FortiGuard servers message for ten minutes.

804584

On the policy dialog page, the Select Entries box for the Service field does not list all service objects if an IPv6 address is in the policy.

807197

High iowait CPU usage and memory consumption issues caused by report runner.

819272

When a VLAN belongs to a zone, and the zone is used in a policy, editing the VLAN ID changes the policy's position in the table.

820909

On the Policy & Objects > Schedules page, when the end date of a one-time schedule is set to the 31st of a month, it gets reset to the 1st of the same month.

Workaround: use CLI to set schedules with an end date of 31st.

829736

Incorrect information is being displayed for the HA role on the System > HA page.

829773

Unable to load the Network > SD-WAN > SD-WAN Rules table sometimes due to a JavaScript error.

831439

On the WiFi & Switch Controller > SSIDs page, multiple DHCP servers for the same range can be configured on an interface if the interface name contains a comma (,) character.

831885

Unable to access GUI via HA management interface of secondary unit.

833306

Intermittent error, Failed to retrieve FortiView data, appears on real-time FortiView Sources and FortiView Destination monitor pages.

833774

GUI needs to allow the members of the software switch interface to be used in IPv4/IPv6 multicast policy.

837836

The Network > Interfaces faceplate shows two SFP interfaces, which do not exist on that FortiGate model.

840604

When upgrading the FortiGate firmware upgrade from FortiGuard, update the API description text for the file name.

842079

On the System > HA page, a Failed to retrieve info caution message appears when hovering over the secondary unit's Hostname. The same issue is observed on the Dashboard > Status > Security Fabric widget.

845513

On G-model profiles, changing the platform mode change from single 5G (dedicated scan enabled) to dual 5G is not taking effect.

853352

On the View/Edit Entries slide-out pane (Policy & Objects > Internet Service Database dialog), users cannot scroll down to the end if there are over 100000 entries.

854529

The local standalone mode in a VAP configuration is disabled when viewing or updating its settings in the GUI.

HA

Bug ID

Description

788702

Due to an HA port (Intel i40e) driver issue, not all SW sessions are synchronized to the secondary, so there is a difference.

818432

When private data encryption is enabled, all passwords present in the configuration fail to load and may cause HA failures.

829390

When the internet service name management checksum is changed, it is out-of-sync when the auto-update is disabled on FortiManager.

832470

HA A-P clusters keeps getting out-of-sync due to local VPN certificate.

840305

Static ARP entry is removed after reboot or HA failover.

843837

HA A-P virtual cluster information is not correctly presented in the GUI and CLI.

843907

Session load balancing is not working in HA A-A configuration for traffic flowing via the VLAN interface when the port1 link is down on platforms with a 4.19 kernel.

854445

When adding or removing an HA monitor interface, the link failure value is not updated.

Hyperscale

Bug ID

Description

804742

After changing hyperscale firewall policies, it may take longer than expected for the policy changes to be applied to traffic. The delay occurs because the hyperscale firewall policy engine enhancements added to FortiOS may cause the FortiGate to take extra time to compile firewall policy changes and generate a new policy set that can be applied to traffic by NP7 processors. The delay is affected by hyperscale policy set complexity, the total number of established sessions to be re-evaluated, and the rate of receiving new sessions.

810366

Unrelated background traffic gets impacted when changing a policy where a hyperscale license is used.

824733

IPv6 traffic continues to pass through a multi-VDOM setup, even when the static route is deleted.

829549

DSE entry is being created for ALG sessions, and EIF sessions pass through.

835697

Interface routes under DHCP mode remain in LPMD after moving the interface to another VDOM.

843197

Output of diagnose sys npu-session list/list-full does not mention policy route information.

843305

Get PARSE SKIP ERROR=17 NPD ERR PBR ADDRESS console error log when system boots up.

Intrusion Prevention

Bug ID

Description

848003

FG-200E memory is not released and enters conserve mode, even after the traffic stopped.

856837

When flow mode AV is enabled, IPS engine memory usage is higher with a large number of flow mode AV requests.

IPsec VPN

Bug ID

Description

763205

IKE crashes after HA failover when the enforce-unique-id option is enabled.

815253

NP7 offloaded egress ESP traffic that was not sent out of the FortiGate.

836260

The IPsec aggregate interface does not appear in the Interface dropdown when configuring the Interface Bandwidth widget.

Log & Report

Bug ID

Description

814758

Get an intermittent error when running execute log fortianalyzer-cloud test-connectivity.

821359

FortiGate appears to have a limitation in the syslogd filter configuration.

825318

Archived Data tab is missing from intrusion prevention and application control log Details pane once log-packet is enabled.

826483

The dstname log field cannot store more than 66 characters.

828211

Policy ID filter is not working as expected.

829862

On the Log & Report > ZTNA Traffic page, the client's Device ID is shown as [object Object]. The Log Details pane show the correct ID information.

836846

Packet captured by firewall policy cannot be downloaded.

837116

FortiCloud log statistics chart on the Log Settings page shows incorrect data.

838253

FortiAnalyzer log statistics chart on the Log Settings page shows incorrect data.

839601

Unable to view logs longer than 500 lines by scrolling down or using the drag down function.

847213

Unable to mouse over an IP address in FortiGate logs.

856613

Older Forward Traffic logs are not visible on the FortiGate with 1 hour, 24 hours, and 7 days time period after upgrading.

858589

Unable to download more than 500 logs from the FortiGate GUI.

Proxy

Bug ID

Description

799237

WAD crash occurs when TLS/SSL renegotiation encounters an error.

813562, 823247,

823829, 829428

When an LDAP user is authenticated in a firewall policy, the WAD user-info process has a memory leak causing the FortiGate to enter conserve mode.

827882

One WAD daemon is consistently using 99% CPU.

835903

There is no replacement message for an IPS custom signature block in a proxy inspection mode firewall policy or proxy policy.

837724

WAD crash occurs.

855882

Increase in WAD process memory usage after upgrading.

REST API

Bug ID

Description

836760

The start parameter has no effect with the /api/v2/monitor/user/device/query API call.

Routing

Bug ID

Description

769330

Traffic does not fail over to alternate path upon interface being down (FGR-60F in transparent mode).

830254

When changing interfaces from dense mode to sparse mode, and then back to dense mode, the interfaces did not show up under dense mode.

830383

Unable to configure IPsec static route.

833399

Static routes are incorrectly added to the routing table, even if the IPsec tunnel type is static.

834497

Traffic behaves differently for connected routes and IGP routes in an ADVPN or SD-WAN environment.

850862

GUI does not allow an AS path to be to configured with multiple similar AS numbers.

862165

FortiGate does not add the route in the routing table when it changes for SD-WAN members.

Security Fabric

Bug ID

Description

809106

Security Fabric widget and Fabric Connectors page do not identify FortiGates properly in HA.

814796

The threat level threshold in the compromised host trigger does not work.

819192

After adding a Fabric device widget, the device widget does not appear in the dashboard.

824433

After authorizing a downstream FortiGate, an empty name and offline status appear in the device registration wizard.

835765

Automation stitch trigger is not working when the threshold based email alert is enabled in the configuration.

843043

Only the first ACI SDN connector can be kept after upgrading from 6.4.8 if multiple ACI SDN connectors are configured.

844412

Security rating failed for custom LLDP profiles.

848822

Security Rating report incorrectly lists the latest AP and switch firmware as unknown.

852340

Various places in the GUI do not show the secondary HA device.

862532

Unable to load topology pages for a specific Security Fabric topology on the root and downstream FortiGates.

SSL VPN

Bug ID

Description

705880

Updated empty group with SAML user does not trigger an SSL VPN firewall policy refresh, which causes the SAML user detection to not be successful in later usage.

777790

Unable to select vip64 in nat64 firewall policy in the CLI if the srcintf is an SSL VPN interface.

795381

FortiClient Windows cannot be launched with SSL VPN web portal.

808107

FortiGate is not sending Accounting-Request packet that contains the Interim-Update AVP when two-factor authentication is assigned to a user (defined on the FortiGate) while connecting using SSL VPN.

819754

Multiple DNS suffixes cannot be set for the SSL VPN portal.

848067

RDP over VPN SSL web mode stops work after upgrading.

Switch Controller

Bug ID

Description

836604

The 40000cr4 port speed is not available under the switch-controller managed-switch port speed settings.

853718

Layer 3 FortiLink does not come up after upgrading.

858113

Unable to view the Diagnostics and Tools page for FortiSwitch with limited access permissions using an administrative profile created on the FortiGate.

System

Bug ID

Description

780315

Poor CPS performance with VLAN interfaces in firewall only mode (NP7 and NP6 platforms).

798091

After upgrading from 6.4.9 to 7.0.5, the FG-110xE's 1000M SFP interface may fail to auto-negotiate and cannot be up due to the missed auto-negotiation.

798303

The threshold for conserve mode is lowered.

805122

In FIPS-CC mode, if cfg-save is set to revert, the system will halt a configuration change or certificate purge.

809030

Traffic loss occurs when running SNAT PBA pool in a hyperscale VDOM. The NP7 hardware module PRP got stuck, which caused the NP7 to hang.

824464

CMDB checksum is not updated when a certificate is renewed over CMP, causing a FortiManager failure to synchronize with the certificate.

826254

Get disk error message after changing disk usage to wanopt.

827240

FortiGate in HA may freeze and reboot. Before the reboot, softIRQ may be seen as high. This leads to a kernel panic.

827241

Unable to resolve sp***.saas.ap***.com on a specific VDOM.

837730

Trusted hosts are not working correctly in FortiOS 7.2.1.

841932

The GUI and API stopped working after loading many interfaces due to httpsd stuck in a D state (kernel I/O socket).

847077

Can't find xitem. Drop the response. error appears for DHCPOFFER packets in the DHCP relay debug.

853144

Network device kernel null pointer is causing a kernel crash.

853794

Issue with the server_host_key_algorithm compatibility when using SSH on SolarWinds.

856202

Random reboots and kernel panic on NP7 cluster when the FortiGate sends a TCP RST packet and IP options are missing in the header.

Upgrade

Bug ID

Description

803041

Link lights on the FG-1100E fail to come up and are inoperative after upgrading.

822844

Observed Node exiting due to unhandled rejection error messages in crash log after upgrading to 7.2.1.

850691

The endpoint-control fctems entry 0 is added after upgrading from 6.4 to 7.0.8 when the FortiGate does not have EMS server, which means the endpoint-control fctems feature was not enabled previously. This leads to a FortiManager installation failure.

Workaround: upgrade from FortiOS 6.4.x to 7.0.7 and then 7.0.8. If you have already upgraded to FortiOS 7.0.8, reboot the FortiGate to automatically set endpoint-control fctems to 1.

User & Authentication

Bug ID

Description

825759

The Device detection option is missing in the GUI for redundant interfaces (CLI is OK).

828212

RADIUS Access Request message needs to be sent when the client reconnects during firewall authentication session expiration.

865166

A cid scan crash occurs when device detections happen in a certain order.

VM

Bug ID

Description

825464

Every time the FortiGate reboots, the certificate setting reverts to self-sign under config system ftm-push.

Web Filter

Bug ID

Description

766126

Block replacement page is not pushed automatically to replace the video content when using a video filter.

WiFi Controller

Bug ID

Description

807713

FortiGate is not sending RADIUS accounting message consistently to RADIUS server for wireless SSO.

809623

CAPWAP traffic is dropped when capwap-offload is enabled.

821320

FG-1800F drops wireless client traffic in L2 tunneled VLAN with capwap-offload enabled.

824441

Suggest replacing the IP Address column with MAC Address in the Collected Email widget.

846730

Dynamic VLAN assignment is disabled in the GUI when editing an SSID with radius mac-auth and dynamic-vlan enabled.

856038

The voice-enterprise value changed after upgrading.

858653

Invalid wireless MAC OUI detected for a valid client on the network.

ZTNA

Bug ID

Description

832508

The EMS tag name (defined in the EMS server's Zero Trust Tagging Rules) format changed in 7.2.1 from FCTEMS<serial_number>_<tag_name> to EMS<id>_ZTNA_<tag_name>.

After upgrading from 7.2.0 to 7.2.1, the EMS tag format was converted properly in the CLI configuration, but the WAD daemon is unable to recognize this new format, so the ZTNA traffic will not match any ZTNA policies with EMS tag name checking enabled.

Workaround: unset the ztna-ems-tag in the ZTNA firewall proxy policy, and then set it again.

845321

An offline FortiClient should be immediately rejected by ZTNA.