Resolved issues
The following issues have been fixed in version 7.6.0. To inquire about a particular bug, please contact Customer Service & Support.
Anti Virus
|
Bug ID |
Description |
|---|---|
|
948197 |
Large file downloads may intermittently stall when flow-based UTM and SSL deep inspection are enabled. |
|
977634 |
FortiOS High Security Alert block page reference URL is incorrect. |
|
981757 |
An error is displayed when downloading a file from a browser with FortiSandbox |
|
993785 |
When logged in as an administrator with Security Fabric access permissions set to none, trying to create a new antivirus profile on the Security Profiles > Antivirus page shows an error. |
|
1004576 |
Incorrect service and action values occur in AV logs when converting fields from bytes to strings. |
|
1028114 |
FortiGate cannot connect to FortiSandboxCloud when |
|
1031084 |
When FortiGate is in HA AA mode, the secondary unit does not connect to all FSA types for inline scanning. |
|
1042358 |
A memory usage issue in the WAD process prevents the AV Engine from loading properly. |
Application Control
|
Bug ID |
Description |
|---|---|
|
982147 |
Remote TACACS+ administrators cannot edit application control profiles using the GUI due to transaction failure. Workaround: TACACS+ administrators can make changes to the application control using the CLI or local administrators can make changes using the GUI. |
|
1015616 |
Packets may be dropped by anti-reply function due to it been partially offloaded. |
Data Loss Prevention
|
Bug ID |
Description |
|---|---|
|
980995 |
DLP Reference check slide window is empty on Global level. |
|
1007202 |
An upgrade issue may prevent the upload or download of large files using HTTP2. |
|
1012922 |
When a DLP policy is set to block the upload or download of test PDF documents, the policy does not function as expected. |
|
1036260 |
The DLP blocks all traffic with deep packet inspection and displays an error page. |
DNS Filter
|
Bug ID |
Description |
|---|---|
|
804790 |
DNS server latency increases by 15 seconds when a request times out. This increase may give a perception that this server is unreachable or has a latency value that doesn't reflect real-world conditions. |
|
1010464 |
When the DNS filter is enabled with |
|
1025233 |
Support Encrypted ClientHello (ECH) in flow mode. |
|
1026058 |
When IP is not resolved or does not exist, the DNS alters the response for the domain and results in a performance issue on the client device. |
|
1048289 |
DNS requests with uppercase characters in the domain name are not blocked when the policy is in flow mode with an external Domain threat feed. |
Endpoint Control
|
Bug ID |
Description |
|---|---|
|
987456 |
FortiOS experiences a CPU usage issue in the daemon when connecting to an EMS that has a large amount of EMS tags. |
|
1007809 |
On FortiGate, anonpages and active(anon) pages frequently use a high amount of memory, causing FortiGate to enter into conserve mode. |
Explicit Proxy
|
Bug ID |
Description |
|---|---|
|
775882 |
The WAD does not function as expected due to a memory allocation issue. |
|
830418 |
Website content does not load properly when using an explicit proxy. |
|
890776 |
The GUI-explicit-proxy setting on the System > Feature Visibility page is not retained after a FortiGate reboot or upgrade. |
|
893935 |
HTTP requests are forwarded to the server through a web proxy even when |
|
894557 |
In some cases, the explicit proxy policy list can take a long time to load due to a delay in retrieving the proxy statistics. This issue does not impact explicit proxy functionality. |
|
983897 |
Traffic that should not be matching a policy is incorrectly matching an allow policy or a deny policy. |
|
990643 |
FortiGate blocks pages when browsing websites though a transparent proxy-redirect policy on SD-WAN. |
|
991106 |
Traffic logs and security events cannot be viewed in the SASE portal caused by the WAD not functioning as expected. |
|
1001700 |
If explicit webproxy uses SAML authentication and the PAC file is enabled at the same time, the browser will report a too many redirects error when trying to visit any websites. |
|
1004634 |
Health check issues occur when forward server is configured in proxy mode firewall policy. |
|
1006362 |
Debug daemon may be blocked while handling client connection and increases the GUI load time. |
|
1011209 |
The proxy policy does not work as expected when the session-ttl value is greater than the global session-ttl value. |
|
1014477 |
Files do not get uploaded on webmail applications with antivirus, app control, or IPS enabled on an explicit proxy policy. |
|
1021643 |
The WAD may not forward HTTP requests through an explicit web proxy. |
|
1021710 |
The |
|
1025323 |
Traffic is blocked when enabling EMS with custom client certificate in secure web proxy policy. |
|
1025974 |
When FortiGate is configured as a downstream proxy with an FQDN type, browsing traffic may encounter a gateway timeout error. |
|
1026362 |
Web pages do not load when |
|
1042125 |
FortiGate generates a replacement error message when the |
|
1043326 |
Traffic is not blocked when HTTP request length exceeds the limit value set in |
|
1048194 |
FortiGate blocks traffic if a |
File Filter
|
Bug ID |
Description |
|---|---|
|
1004198 |
.exe files in ZIP archives are not blocked by file-filter profiles during CIFS file transfers. |
Firewall
|
Bug ID |
Description |
|---|---|
|
807191 |
On FortiGate, the |
|
815333 |
Local-in policy does not deny IKE UDP 500/4500. |
|
819274 |
On the Query > Routing Menu page in FortiManager, the routing table does not include the static or BGP types in |
|
837866 |
On the NP7 platform, traffic is blocked when |
|
892774 |
On FortiGate 7000 models, the hit counter on the FortiManager GUI does not display the correct values. |
|
951422 |
Corner case: failure to download file from web server with Proxy mode inspection and AV/IPS enabled. |
|
966466 |
On an FG-3001F NP7 device, packet loss occurs even on local-in traffic. |
| 975923 | SNAT issues occur when using NPTv6 mapping from RFC 6296. |
|
977097 |
Packet drop occurs when NP7 SCTP CRC check is enabled. |
| 983862 | Traffic disruption occurs when GTP-U dynamic source port is enabled. |
|
985419 |
On the Policy & Objects > Firewall Policy page, the Log violation traffic checkbox displays as being unchecked when the policy is configured and reopened for editing. This purely a GUI display issue and does impact system operation. |
|
991961 |
On the Policy & Objects > Addresses page, address objects are not sorted in alphabetical order for address group or firewall policies. |
|
992610 |
The source interface displays the name of the VDOM and local out traffic displays as forward traffic. |
| 994223 | Virtual-Servers failure occurs when upgrading from v7.2 to v7.4. |
|
996876 |
Adding IPv6 address group memberships to a policy using FortiGate REST API does not work as expected. |
|
998699 |
On the Policy & Objects > Firewall Policy page, the Firewall/Network options are missing in the GUI when enabling a security profile group in a policy. |
|
1002269 |
When a schedule is added to a firewall policy, the schedule is not activated at the time configured in the policy. |
|
1004267 |
On the Policy & Objects > Firewall Policy page, when searching for an address object with a comment keyword, no results are displayed. |
| 1008532 | Policy cloning failure occurs when attempting to clone an existing local-in-policy. |
|
1008680 |
On FortiOS, the Dashboard > FortiView Destination Interfaces, Dashboard > FortiView Source Interfaces pages, and Policy & Objects > Firewall Policy > Edit Policy page display incorrect bandwidth units. |
|
1008863 |
SNAT |
|
1010037 |
When editing object address on the Policy & Objects > Addresses page, the GUI does not function as expected if the address being edited contains a slash character. |
|
1010824 |
FortiGate creates dummy destination IP logs when pinging a FortiGate VIP. |
|
1011438 |
On the Policy & Objects > Firewall Policy List page, the Interface Pair View does not display policies alphanumerically and by interface alias. |
|
1012239 |
When creating a new policy using the GUI in TP mode, NAT is automatically enabled. |
|
1013488 |
On the Policy & Objects > Firewall Policy page, searching for service port numbers in the Firewall Policy list does not return any results. |
|
1014584 |
On the Policy & Objects > Firewall Policy page, firewall policies with FQDN show as unresolved in the table. |
|
1016893 |
On the Policy & Objects > Firewall Policy page, when hovering over addresses in the Source or Destination columns, the tooltip window does not scroll when there are a large number of addresses. |
|
1022116 |
After editing a policy on the Interface Pair View window on the Policy & Objects > Firewall Policy page, the display order changes. |
|
1025111 |
Registration issues occur when GTP tunnel timeout expires. |
| 1033926 |
Cannot set profile-group in firewall policy when inspection-mode is proxy. |
|
1034378 |
SMTP traffic does not egress from the same interface when a UTM profile is used in a proxy-based policy. |
FortiGate 6000 and 7000 platforms
|
Bug ID |
Description |
|---|---|
|
638799 |
The DHCPv6 client does not work with vcluster2. |
|
694958 |
On FortiGate 7000 models, the Power Supply status displays as Normal in the GUI when there is a logged power failure. |
|
819274 |
On the Query > Routing Menu page in FortiManager, the routing table does not include the static or BGP types in |
|
885205 |
IPv6 ECMP is not supported for the FortiGate 6000F and 7000E platforms. IPv6 ECMP is supported for the FortiGate 7000F platform. |
|
892774 |
On FortiGate 7000 models, the hit counter on the FortiManager GUI does not display the correct values. |
|
940541 |
A permanent MAC address is used instead of an HA virtual MAC address during automation. |
|
946399 |
On the Policy & Objects > Firewall Policy page, address entries cannot be edited using the Edit button from the tooltip pop-up window. |
|
983236 |
Under normal conditions, a FortiGate 6000 or 7000 may generate event log messages due to a known issue with a feature added to FortiOS 7.2 and 7.4. The feature is designed to create event log messages for certain DP channel traffic issues but also generates event log messages when the DP processor detects traffic anomalies that are part of normal traffic processing. This causes the event log messages to detect false positives that don't affect normal operation. For example, DP channel 15 RX drop detected! messages can be created when a routine problem is detected with a packet that would normally cause the DP processor to drop the packet. Similar discard message may also appear if the DP buffer is full. |
|
991173 |
High latency occurs when sending UDP fragments through FortiGate at high rates. |
|
1003820 |
DHCP response issues occur when traffic is tagged and sent via LAN extension method. |
|
1003879 |
Incorrect SLBC traffic-related statistics may be displayed on the FortiGate 6000 or FortiGate 7000 GUI (for example, in a dashboard widgets). This can occur if an FPC or FPM is not correctly registered for statistic collection during startup. This is purely a GUI display issue and does not impact system operation. |
|
1005227 |
Full-cone NAT support for 7KF. |
|
1013046 |
On FortiGate 6000 and 7000 models, interested traffic cannot trigger the IPsec tunnel. |
|
1018594 |
On FortiGate 7000, if |
|
1022499 |
IPv6 routes are not fully synchronized between HA primary and secondary units. |
|
1025926 |
After a firmware upgrade, the configuration does not synchronize because the SDN connector password is unmatched. |
|
1028313 |
On FortiGate 7000E and 7000F models in an HA cluster, FortiGate experiences a split brain scenario between the primary and secondary units when the primary unit is rebooted. |
|
1029415 |
On FortiGate 6000 models in an HA cluster, the secondary unit does not send out logs when an interface is configured. |
|
1030917 |
FortiGate displays an erroneous error for high/low warning alarms. SFP data transfer functions as expected. |
|
1033050 |
On FortiGate 6000 models in an HA cluster, the secondary unit does not send out automated stitch emails for certain events. |
|
1047553 |
HA remote access does not work as expected when |
FortiView
|
Bug ID |
Description |
|---|---|
|
941521 |
On the Dashboard > FortiView Websites page, the Category filter does not work in the Japanese GUI. |
|
945448 |
On the Asset Vulnerability Monitor page, filtering by FortiClient user does not show any results. |
GUI
|
Bug ID |
Description |
|---|---|
|
896008 |
On wide resolution screens, the GUI-based CLI console widget has text overlap display issues on very wide screens. |
| 941104 | Firmware installation failure occurs when upgrading multiple FortiAPs of the same model from FortiGuard. |
|
946521 |
On the System > Interfaces page, the set monitor-bandwidth setting is not automatically disabled set when the interface bandwidth monitor for a port is deleted. |
| 955457 | SD-WAN rules cannot be shown or configured from GUI when changing system.ha. |
|
957441 |
On the Firmware & Registration page, the GUI displays a Cannot determine mkey for cmdb source entry. error message. This is purely a GUI display issue and does not impact system function. |
|
964386 |
GUI dashboards show all the IPv6 sessions on every VDOM. |
|
970528 |
The |
| 971988 | The Add button for Phase2 selectors is missing when editing IPsec tunnels under non-root VDOMs. |
|
974988 |
FortiGate GUI should not show a license expired notification due to an expired device-level FortiManager Cloud license if it still has a valid account-level FortiManager Cloud license (function is not affected). |
|
978716 |
On the Security Profiles > Inline-CASB page, when a SaaS application is added to a CASB profile, the option is not grayed out and the SaaS application can be added again. |
|
981244 |
On the FortiGate GUI, IPsec or GRE configurations are missing when using |
|
983422 |
A GTP profile cannot be applied to policy using the GUI. |
|
992346 |
|
|
993890 |
The |
|
994915 |
The CLI GUI console is disconnected after creating a new VDOM. |
| 996547 | Improvements to policy tables caused by migrating Central SNAT, DoS, ACL, Multicast, Proxy policy MuTable pages to Angular with next-gen menu support. |
|
996845 |
When saving a packet capture, the file name saves as a generic file name with no identifiable information. |
|
998155 |
The |
|
1006079 |
When changing administrator account settings, the |
|
1006868 |
On the FortiGuard page, when setting a schedule using the Scheduled updates option on the GUI, the CLI displays the wrong value. |
|
1007934 |
FortiGate may experience a memory usage issue with the node daemon once a connection is closed. |
|
1013455 |
On the FortiGate GUI, inter-VDOM links are not available for packet capture. |
|
1013866 |
The category action change is not saved if the category number is the same as the existing entry ID. |
|
1017181 |
The |
| 1021642 | Authorization failure occurs when attempting to authorize a FEXT on the GUI. |
| 1031683 | Error occurs when adding interface bandwidth widget and maximum number of monitored interfaces is reached. |
| 1033012 | Trailing 0s are silently dropped when GUI BGP is set as number with asdot/asdot+ format. |
| 1033972 | An error condition occurs in the GUI when changing the LDAP server IP. |
| 1043099 | An error condition in httpsd occurs when csf downstream is configured without config change or GUI navigation. |
|
1044596 |
An error condition in httpsd occurs when accessing api_cmdb_is_cacheable on FortiGate-201E v7.6.0 |
| 1051778 | Access to managed switches fails when viewing FortiSwitch port page features. |
HA
|
Bug ID |
Description |
|---|---|
|
825380 |
When workspace configuration save mode is set to manual in the System > Settings, configuration changes made on the primary unit and then saved do not synchronize with the secondary unit when one of the cluster units are rebooted or shutdown after the change. |
|
962525 |
In HA mode, FortiGate uses |
|
985601 |
When configuring VDOMs in an HA cluster, the VDOM assigned to the VDOM link in vcluster2 active on the secondary unit is incorrect. |
|
985967 |
Session synced with FGSP does not allow immediate failover when UTM is enabled in flow mode. |
|
988944 |
The Fabric Management page displays inconsistent information when accessed through secondary HA units on some FortiGate models. |
|
992758 |
When uploading certificates, HA can go out of synchronization. |
|
993849 |
After restoring a VDOM configuration, the HA is not synchronized. |
|
995340 |
An issue with |
|
998004 |
When the HA management interface is set a LAG, it is not synchronized to newly joining secondary HA devices. |
|
1000001 |
A secondary HA unit may go into conserve mode when joining an HA cluster if the FortiGate's configuration is large. |
|
1000808 |
FortiGate in an HA setup has an unnecessary primary unit selection when a new member joins or reboots one member in the VC cluster when the VC has more than 2 units. |
|
1001239 |
HA-direct remains enabled when declining confirmation after setting HA-direct option. |
|
1002682 |
The VMware SDN connector does not respect the |
|
1004077 |
Error message occurs when configuring HA management interfaces from GUI at hyperscale system. |
|
1004215 |
Local out traffic from the primary HA unit uses the wrong interface when SNMP points to the secondary HA unit. |
|
1005596 |
Using RADIUS login on the secondary unit does not work as expected when trying to login to the primary and secondary units at the same time. |
|
1007395 |
When downgrading to a 7.2.x firmware version, an error message displays on the primary HA device and does not get removed when the device is rebooted. |
|
1007857 |
Both FGTs appear as primary in an HA virtual cluster during setup of two HA virtual clusters. |
|
1012115 |
Hitless failover issues occur when FortiGate is in WAN-extension CAPWAP mode. |
|
1013152 |
After a factory reset, the FortiGate HA cluster may remain out of synchronization between the primary and secondary units. |
|
1015950 |
When upgrading a FortiGate VM Analyzer, a CPU usage issue causes the auto scale cluster to go out of synchronization. |
|
1017177 |
A WAD processing issue causes the SNMP to not respond in an HA cluster. |
|
1018937 |
In a FortiGate HA configuration, the tunnel connection to FortiManager is disrupted due to a mismatched serial number and local certificate issue. |
|
1024535 |
In an FGSP cluster configuration running in TP mode, reply traffic in asymmetric flow is not offloaded to NP. |
|
1025585 |
Network traffic may be disrupted due to a linking issue with upstream routers. |
|
1027149 |
When creating a new VDOM in an HA configuration, FortiGate may not operate as expected due to an |
|
1029441 |
In an HA cluster on the SCO4 platform, the secondary unit enters a continuous rebooting cycle due to an interruption in the kernel after a firmware upgrade. |
|
1032415 |
On the System > HA page, all HA vcluster device roles display as Primary in the Role column. |
|
1033083 |
HA sessions are not synchronized properly causing a high number of sessions on the primary unit and the standby unit enters into conserve mode. |
|
1033626 |
During a firewall failover, the multicast traffic is not forwarded within an appropriate time frame. |
|
1034326 |
In a HA cluster using FGSP mode, the primary and secondary units cannot synchronize the lease agreements due to a synchronization issue with the DHCP server. |
|
1035988 |
SCTP session sync issue occurs when protocol state is in closing stage. |
|
1050410 |
An error condition in Newcli occurs when reading corrupted timestamp data in the history cluster file. |
Hyperscale
|
Bug ID |
Description |
|---|---|
|
961684 |
When DoS policies are used and the system is under stress conditions, BGP might go down. |
|
967017 |
TCP or UDP timer profiles configured using |
|
975220 |
The Gentree Compiler is enabled by default on all NP7 platforms for threat feed support. |
|
976972 |
New primary can get stuck on failover with HTTP CC sessions. |
|
993343 |
In a Hyperscale VDOM, an interruption in the kernel occurs with set nat46-generate-ipv6-fragment-header enabled. |
|
994019 |
Harpin traffic may not work due to a rare situation caused by a race condition. |
|
1013254 |
Resource usage issues caused by changing ippool for hyperscale case. |
|
1016478 |
When modifying existing policies with a BOA loaded configuration, NPD is not working as expected. |
|
1024274 |
When Hyperscale logging is enabled with multicast log, the log is not sent to servers that are configured to receive multicast logs. |
|
1024313 |
The template for the netflow v9 log packets is not included in the configuration. |
|
1024902 |
After FTP traffic passes, the |
|
1027251 |
Logs are not sent out from FGT with log2host setting when log-server becomes reachable, and it has correct dmac. |
|
1032471 |
When rebooting the secondary unit in an FGSP setup, the session information is not visible in the secondary unit. |
|
1034100 |
The NPD process is interrupted in a Hyperscale VDOM configuration after an upgrade and sessions are not setup on hardware. |
|
1034685 |
Log cache is not cleared and holding the wrong dmac for unreachable gateway. |
|
1042151 |
syslog over TCP not working. |
|
1223321 |
IP pools got stuck when session-ttl changes are made |
ICAP
|
Bug ID |
Description |
|---|---|
|
1022247 |
In an ICAP profile, the |
Intrusion Prevention
|
Bug ID |
Description |
|---|---|
|
810783 |
The number of IPS sessions is higher than kernel sessions, which causes the FortiGate to enter conserve mode. |
|
910267 |
In an FGSP setup running emix traffic, nTurbo values run in the negative. |
|
916175 |
In rare cases, the IPS engine may not handle buffer overflow. |
|
968464 |
nTurbo passes the wrong ID to the IPS engine when the |
|
979586 |
When applying an IPS profile with offloading enabled, WLAN authentication does not function as expected caused by EAP transaction timeouts. |
|
995997 |
ISDB is shown in 'diag test app ipsmonitor 1' output when IPS/AppCtrl feature are not enabled. |
|
1000223 |
HTTPS connections to a Virtual IP (VIP) on TCP port 8015 are incorrectly blocked by the firewall, displaying an IPS block page even when no packet from the outside to TCP port 8015 should reach the internal VIP address. |
|
1008064 |
The IPS DB is not preserved when upgrading to 7.2.5 or later. |
|
1008107 |
Because of how IPS handles long-lived nTurbo sessions, throughput capacity may be reduced after an FGCP HA failover. Once all failed-over nTurbo sessions have been completed, throughput will return to normal. |
|
1011702 |
FortiGate experiences a CPU usage issue which may lead to an interruption in the kernel when dos-policy is enabled. |
|
1013666 |
IPS engine attempts to use FortiGuard for vulnerability lookup even though FMG is configured as override server in a closed network, causing vulnerability lookup to fail. |
|
1026354 |
On FortiGate, the softirq experiences a CPU usage issue with the IPS engine when traffic hits a firewall policy without an IPS profile. |
IPsec VPN
|
Bug ID |
Description |
|---|---|
|
564920 |
IPsec VPN fails to connect if |
|
787673 |
IPsec VPN types are not saved to the configuration when edited using the GUI. |
|
942618 |
Traffic does not pass through an |
|
950445 |
After a third-party router failover, traffic traversing the IPsec tunnel is lost. |
|
966085 |
IKEv2 authorization with an invalid certificate can cause tunnel status mismatch. |
|
968055 |
After an upgrade, L2TP/IPsec connections using the RIP protocol do not function as expected. |
|
968376 |
Changes to the IPsec tunnel type from a static to dialup user on the GUI does not change the actual configuration. |
|
974648 |
Editing existing IPsec aggregate members does not update in the bundle list. |
|
978243 |
Unable to send all prefixes through FortiClient using dial-up IPsec VPN split tunnel to macOS devices. |
|
986756 |
VPN traffic does not pass between VDOMs through intervdom links. |
|
989570 |
On FortiGate, firewall address groups created using the VPN wizard cannot be edited. |
|
994115 |
When ASIC offload is enabled and packet size is larger than 1422, FortiGate does not generate an ICMP Type 3, Code 4 error message. |
|
996625 |
Unable to create a FortiClient dial-up VPN with certificate authentication because a peer CA certificate cannot be selected. |
|
998229 |
Traffic loss is experienced on inter-region ADVPN tunnels after phase 2 rekey. |
|
999619 |
A peername conflict error occurs when users configure static tunnels and then dynamic tunnels. There is no conflict when done in the reverse order. |
| 1000000 | IKE negotiation failure occurs when changing ike-tcp-port. |
|
1001602 |
Using IPSec over back to back EMAC VLAN interfaces does not work as expected with NPU offload enabled. |
|
1001996 |
The iked does not function as expected due to a misplaced object being created in the secondary HA during failover. |
|
1003830 |
IPsec VPN tunnel phase 2 instability after upgrading to 7.4.2 on the NP6xlite platform. |
| 1004090 | Intermittent traffic disruption caused by error condition in ipsengine during phase1 object deletion. |
|
1004272 |
On NP7 platforms that are used a hub in a hub and spoke configuration, traffic packets are dropped on IPsec tunnel spokes due to an anti-replay error. |
| 1006014 | IKE negotiation failure occurs when ike-port is set to a non-standard value. |
|
1006110 |
When an ipip tunnel over IPsec is configured, the configuration may cause running traffic to access the deleted SA. |
|
1007043 |
Iked may experience an interruption in operation resulting in all VPN tunnels going down. |
|
1009732 |
If there are more than 2000 dialup IPsec tunnel interfaces used in multiple FGT firewall polices, and IKE policy update may not able to complete before IKE watchdog timeout. |
|
1014026 |
On the VPN > IPsec Tunnels page, after creating an IPsec tunnel in phase 2, the Named Address field does not show any results. |
|
1019269 |
On the VPN > IPsec Tunnels page, when language setting on FortiOS is set to anything other than English, the Status column displays active (green up arrow) when the tunnel is inactive. |
|
1020250 |
A second IPsec tunnel cannot be added on different IP versions that use the same peerid. |
|
1025202 |
After a peer-side interface shutdown and reboot, the |
|
1029262 |
IPsec VPN traffic does not pass over the tunnel when the HA heartbeat cable is reconnected. |
|
1031985 |
IPSec VPN tunnel does not go down when the VPN peer route is removed from the routing table. |
|
1033154 |
FortiGate does not unregister the |
|
1036262 |
Tunnel traffic is encrypted as FortiGate-ESP packets when transport is UDP and FortiGate-ESP is enabled. |
|
1041019 |
When QKD dialup is enabled, IKE SA cannot establish a connection and generates an error. |
| 1044993 | IP assignment fails from external DHCP server when DHCP_LOCAL_SERVER socket binding is unsuccessful. |
|
1047148 |
FortiGate prematurely switches ports when IKE fragmented packets are not delivered from FortiClient to FortiOS. |
Log & Report
|
Bug ID |
Description |
|---|---|
|
872493 |
Disk logging files are cached in the kernel, causing high memory usage. |
|
925649 |
An interruption may occur in the daemon locallogd when the system is in memory conserve mode. |
|
957130 |
On the Log & Report > Forward Traffic page, when running version 7.2.3 of FortiGate, log retrieval speed from FortiAnalyzer is slow. |
|
960661 |
FortiAnalyzer report is not available to view for the secondary unit in the HA cluster on the Log & Report > Reports page. |
|
973673 |
The |
|
993476 |
On FortiGate, the locallogd process encounters a CPU usage issue for a few minutes after a reboot or a restart. |
|
998215 |
Frequent API queries to add and remove objects can result in a memory usage issue on FortiGate. |
|
1000600 |
When a log output is generated, the position of the rawdata field is not consistent, causing some information to be missing. |
|
1002502 |
Add log when duplicate IP detected. |
|
1005171 |
After upgrading to version 7.0.14, the system event log generates false positives for individual ports that are not used in any configuration. |
|
1006611 |
FortiOS may not function as expected when the miglogd application attempts to process logs. |
|
1008626 |
ReportD does not function as expected when event logs have message fields over 2000 bytes. |
|
1010074 |
The miglogd does not function as expected due to a CPU usage issue. |
|
1010244 |
When uploading the log file to the FTP server, some parts of the log files are not included in the upload. |
|
1010428 |
On the Log & Report > System Events page, the log displays an FortiGate has experienced an unexpected power off error message when an interruption occurs in the kernel. |
|
1011172 |
The miglogd does not forward log packages to FortiAnalyzer due to a memory usage issue. |
|
1012862 |
User equipment IP addresses are not visible in traffic logs. |
|
1018392 |
A memory usage issue in the fgtlogd daemon causes FortiGate to enter into conserve mode. |
|
1021195 |
The IPS engine sends a high frequency of IoT device queries even when the device identification is set to disabled. |
|
1022930 |
SD-WAN information is not logged in forward traffic logs for certain IPv6 traffic. |
|
1025797 |
The |
|
1027777 |
Traffic log fields for applications are missing when proxy-inline-IPS is enabled. |
|
1028167 |
A system log message is not generated when |
|
1028309 |
On FortiGate, a CPU usage issue occurs in the locallogd. |
|
1040678 |
The first character |
Proxy
|
Bug ID |
Description |
|---|---|
|
871273 |
When the kernel API tries to access the command buffer, the device enters D state due to a kernel interruption. |
|
900546 |
DNS proxy may resolve with an IPv4 address, even when |
|
918652 |
FortiGate experiences a CPU usage issue and halts traffic when there are a large amount of addresses and external resource is updated frequently. |
|
922093 |
CPU usage issue in WAD caused by source port exhaustion when using WAN optimization. |
|
933502 |
When a forward server with proxy authorization is configured with certain traffic, a memory usage issue in the WAD process interrupts to operation of FortiGate. |
|
949464 |
On FortiGate, a memory usage issue in the WAD may cause the unit to enter into conserve mode. |
|
956481 |
On FortiGate 6000 models, when an explicit proxy is configured, the TCP 3-way handshake does complete as expected. |
|
968303 |
TLS session blockage occurs when encrypted-client-hello extension is detected in ClientHello. |
|
979361 |
After an upgrade, FortiOS encounters an error condition in the application daemon wad caused by an SSL cache error. |
|
982553 |
After upgrading from version 6.4.13 to version 7.0.12 or 7.0.13, FortiGate experiences a memory usage issue. |
|
983997 |
Certificate validation fails on FortiGate/FortiProxy when using root CAs with identical subjects but distinct public keys and serial numbers. |
|
987483 |
On FortiGate, the WAD daemon does not work as expected due to a NULL pointer issue. |
|
987655 |
RPM files could not be blocked in HTTP downloading on Box Cloud website in proxy mode. |
|
988473 |
On FortiGate 61E and 81E models, a daemon WAD issue causes high memory usage. |
|
991168 |
An error condition in WAD occurs when executing vulnerability lookup responses on FortiGate-1101E |
|
994101 |
SSL Logs show certificate-probe-failed error when web profile is enabled. |
|
999118 |
TCP connections are not distributed properly when |
|
1000653 |
The proxy policy does not validate IP addresses in the XFF when an HTTP address is sent by AGW. |
|
1001598 |
When proxy-based policies are enabled, HTTP2 resources cannot be accessed. |
|
1003481 |
FortiGate may not work as expected due to an error condition in the daemon WAD. |
|
1008079 |
Memory usage increase for WAD process. |
|
1010718 |
The proxy inspection mode policy is deleted from the configuration without notification after an upgrade. |
|
1012965 |
Deep inspection and web filter for an explicit proxy policy do not work if |
|
1016970 |
High memory usage in WAD causes FortiGate to enter into conserve mode. |
|
1019230 |
On FortiGate, a memory usage issue in the WAD causes the unit to enter into conserve mode. |
|
1020067 |
Due to the removal of proxy-related options in devices with 2GB, within |
|
1020828 |
An HTTP2 stream issue causes an error condition in the WAD. |
|
1021346 |
Starting from version 7.4.4, FortiOS no longer supports proxy-related features for FortiGate models with 2 GB RAM or less. When upgrading from FOS 7.4.3 or earlier to later versions, the UTM profile feature set was not properly changed from proxy to flow. |
|
1021699 |
When some regex objects do not match the policy, it can result in all other objects in the same policy to not match. |
|
1028017 |
Change the default value of |
|
1033729 |
An IMAP connection to an external application email server is not established in a proxy mode policy with DPI enabled. |
|
1036201 |
A memory usage issue occurs in the WAD daemon process for |
|
1039006 |
Some websites cannot open subpages when the HTTP2 header value exceeds 16MB. |
|
1046568 |
An error condition in WAD occurs when configuring explicit web proxy with SSL deep inspection. |
REST API
|
Bug ID |
Description |
|---|---|
|
859680 |
In an HA setup with vCluster, a CMDB API request to the primary cluster does not synchronize the configuration to the secondary cluster. |
|
984499 |
REST API query |
|
985285 |
Packet capture issues occur when starting packet capture on an LAN extension interface. |
|
998932 |
Discrepancy in external resource handling occurs when making requests over the in-band management IP of passive units in HA AP clusters. |
|
1026195 |
When importing a certificate using API, it is not visible on FortiOS despite displaying that the import was successful. |
Routing
|
Bug ID |
Description |
|---|---|
|
779825 |
In SD-WAN with |
|
792512 |
The dashboard Session widget cannot display the correct IPv6 session count per VDOM. |
|
817562 |
lpmd fails to correctly handle different VRFs, treating all as vrf 0, causing improper route management and affecting network traffic isolation. |
|
923994 |
On the Network > Static Routes page, VRF information does not display in the VRF column. |
|
924693 |
On the Network > SD-WAN > SD-WAN Rules page, member interfaces that are down are incorrectly shown as up. The tooltip on the interface shows the correct status. |
|
966681 |
FortiGate cannot ping an IPv6 loopback address. |
|
978683 |
The |
|
987360 |
SD-WAN health checks are not deleted after all related references are removed when applied over ADVPN. |
|
989012 |
The |
|
990211 |
On the Network > BGP > Neighbor Groups page, an error message is shown under IPv4 Filtering for routes that are already have in and out routes configured in the GUI. |
|
993843 |
On FortiGate 1800F models, the VXLAN tunnel on a Loopback interface does not match SD-WAN rules. |
|
995972 |
When accessing the ZebOS in chroot, the ospfd does not work as expected. |
|
1000433 |
The IPv6 route with dynamic gateway enabled cannot be configured after an upgrade and reboot. |
|
1001556 |
VXLAN does not match SD-WAN rule when a service is specified. |
|
1002132 |
A BGP neighbor over GRE tunnel does not get established after upgrading due to anti-spoofing not functioning as expected. |
|
1002721 |
Existing |
|
1002851 |
BGP Stale routes do not function as expected in an HA configuration. |
|
1004249 |
FortiGate routes traffic to an interface with a physical status of DOWN. |
|
1006703 |
OSPF logs for neighbor status are not generated when using multiple VRFs. |
|
1006753 |
When renewing the LTE WWAN IP, some packets are sent using the old IP address causing traffic to drop. |
|
1007163 |
In a hub and spoke configuration, the spoke cannot resolve BGP routes to HUB when a shortcut is established. |
|
1008818 |
The default configuration of the Fabric Overlay Orchestrator causes concurrent disconnects with the BGP. |
|
1009907 |
The OSPF daemon does not function as expected causing routing to stop working after an HA cluster failover. |
|
1011263 |
FortiGate does not advertise default route to its EBGP neighbor when |
|
1012321 |
When modifying an address in VDOM DAF, the session is routed to the default static route instead of the policy routing. |
|
1012895 |
The |
|
1013773 |
FortiGate does not automatically add the set LTE dynamic route to the routing table. |
|
1013940 |
After an HA failover and the SD-WAN neighbor role is selected as the primary, the SD-WAN service with role set as primary is disabled. |
|
1017950 |
The OSPF process encounters a CPU usage issue when there are a high number of prefixes and |
|
1019166 |
On the Network > Routing Objects page, route map objects cannot be edited and saved. |
|
1020474 |
In a hub and spoke configuration, the IPsec SA MTU calculation does not match with the |
|
1021666 |
When adding a route using SD-WAN zone, there is no overlap check on existing gateway IP addresses which prevents routes from being added. |
|
1022665 |
When the SNAT does not match the outgoing interface during failover from the secondary to the primary, SD-WAN traffic does not failover back to the primary WAN. |
|
1023878 |
SD-WAN SLA shows intermittent disruptions of packet loss on all links simultaneously, even though there is no actual packet loss. |
|
1025201 |
FortiGate encounters a duplication issue in a hub and spoke configuration with |
|
1027001 |
IBGP routes are not accepted on the neighbor-group with remote-as-filter. |
|
1031394 |
On the Network > Routing Objects page, the Set AS path on the Edit Rule pane does not allow the use of the full range AS numbers. |
|
1042487 |
When setting a prefix using the set prefix option, the prefix entry is created using a default route instead of the desired configuration. |
|
1042848 |
BGP multipath routing does not work as expected in a BGP confederation setup. |
|
1044403 |
HTTPS/SSH traffic fails on the interface when policy routing is enabled due to incorrect ARP requests from cached routes. |
|
1050992 |
IKE-SAML reply traffic does not egress from the same interface as ingress traffic when the route is present in the routing table. |
SD-WAN
|
Bug ID |
Description |
|---|---|
|
982365 |
Egress shaping profile application issue occurs when using static tunnels on IPsec spoke |
| 1004054 | Route remains active when interface is physically down. |
|
1045558 |
Remote health-check on Hub remains alive when active health-check on spoke is dead. |
Security Fabric
|
Bug ID |
Description |
|---|---|
|
899585 |
When running a security rating check, the security rating endpoints do not use the latest endpoint data. |
|
907452 |
On FortiOS, GUI access can be prevented when requesting a security rating over CSF from FortiAnalyzer. |
|
948322 |
After deauthorizing a downstream FortiGate from the System > Firmware & Registration page, the page may appear to be stuck to loading. |
|
958429 |
On the Security Fabric > Automation page, the webhook request header does not contain |
|
968621 |
Erroneous memory allocation resulting in unexpected behavior in csfd after upgrading. |
|
972921 |
On the Security Fabric > External Connectors page, the comments are not working as expected in the threat feed list for the domain threat feed. |
|
984127 |
FortiGate shows the wrong notification to setup an upstream device that is not a FortiGate to the Security Fabric. |
|
987531 |
Threat Feed connectors in different VDOMs cannot use the source IP when using internal interfaces. |
|
989184 |
The Security Fabric root device takes longer than expected to synchronize with downstream secondary HA devices in an HA configuration. |
|
990703 |
In certain scenarios, dynamic addresses managed by the Azure SDN connector may be removed leading to potential network interruptions. |
|
994167 |
An issue with the csfd results in FortiGate being disconnected from the Security Fabric. |
|
1000880 |
When renaming an existing address name on a downstream FortiGate from the root FortiGate, a new address is created on the downstream FortiGate with the updated name. |
|
1003503 |
During a full fabric upgrade where a PoE powered device (PD) connected to a Power Sourcing Equipment (PSE) are upgraded, the upgrade of the PD may be interrupted if the PSE finishes upgrading first, causing a boot loop on the PD. This behavior is now avoided by performing upgrades on PDs first before upgrading PSEs and the FortiGate itself. |
|
1008901 |
STIX threat feeds cannot download properly due to a JSON parsing issue. |
|
1012476 |
Automation stitches are not synced to downstream FortiGate memory when using CSF external sync API. |
|
1014961 |
The SDN Connector for nutanix does not return all the entries. |
|
1018953 |
Configuration issue occurs when setting low-end FGT as CSF root. |
|
1023998 |
On the System > Firmware & Registration page, the firmware information for the secondary device is not shown when the Security Fabric is enabled in the GUI. |
|
1026700 |
Internal REST API requests are routed through the httpsd CSF proxy, leading to issues with chunked encoding for large responses and blocking behavior. |
|
1041855 |
kubed crashed with signal 6 (Aborted) when testing kubernetes sdn connector during robot auto test. |
|
1044054 |
Incorrect FortiGates field is displayed in GUI when automation-destination is configured. |
|
991462, 993279 |
When automation stitch is configured with the once schedule, the stitch is not synchronized to the downstream FortiGates. |
SSL VPN
|
Bug ID |
Description |
|---|---|
|
905050 |
Intermittent behavior in samld due to an absent crucial parameter in the SP login response may lead to SSL VPN users experiencing disconnections. |
|
947536 |
SSL VPN crashes on corporate FortiGate due to watchdog timeout when a single connection enters an infinite loop of read iterations and the worker process becomes unresponsive to new connections |
| 978939 | Performance issues occur when CMDB configuration is large. |
|
982705 |
When editing a security policy, the custom signature is removed from the policy. |
|
983513 |
The |
| 998311 | An error condition occurs when setting host-check-interval to 0 after changing it from the default value. |
|
999378 |
When the GUI tries to write a QR code for the SSL VPN configuration to the file system to send in an email, it tries to write it in a read-only folder. |
|
999661 |
When changing SSL VPN access in the Restrict Access field to Allow access from any host and enabling the Negate Source option on the VPN > SSL VPN page, the changes made in the GUI are not reflected in the CLI. |
|
1000674 |
When generating function backtrace in crash logs for ARM32, SSL VPN frequently crashes due to segmentation faults. |
|
1001272 |
The SAML DB Insert does not function as expected and causes a CPU usage issue. |
| 1002820 | Memory usage issues caused by SSL VPN on 2 GB RAM models. |
|
1003672 |
When RDP is accessed through SSL VPN web mode, keyboard strokes on-screen lag behind what is being typed by users. |
|
1004633 |
FortiGate does not respond to ARP packets related to SSL VPN client IP addresses. |
|
1006448 |
Security vulnerability occurs when SSL VPN performs early validation on incoming HTTP messages from clients. |
|
1012486 |
SSL VPN OS checklist does not include minor version numbers of macOS 13 and 14. |
|
1018928 |
A CPU usage issue occurs in the tvc daemon when the vpn server cannot be reached. |
|
1022439 |
SAMLD encounters a memory usage issue, preventing successful login attempts on SSL VPN. |
|
1024584 |
The SSL VPN IP pool may get exhausted when |
|
1024837 |
OneLogin SAML does not work with SSL VPN after upgrading to 7.0.15 or 7.4.3. |
|
1026102 |
SSL VPN encounters a CPU usage issue in the daemon after updating the language from the GUI. |
|
1027863 |
NAS-IP per SSL-VPN realm does not work as expected under the |
|
1031179 |
SSH and telnet service disruption occurs when hterm_all.js is incorrectly removed in SSL VPN web portal. |
|
1036542 |
When using an SSL VPN quick connection in web mode, web page images are distorted. |
|
1041202 |
SSL VPN does not work as expected if an LDAP user UPN exceeds 35 characters. |
|
1042164 |
Memory usage issues occur when user-peer is used and user login fails in SSL VPN. |
Switch Controller
|
Bug ID |
Description |
|---|---|
|
688724 |
A non-default LLDP profile with a configured |
| 848357 | Authentication order issues caused by enabling both 802.1x and MAB. |
|
899414 |
On the WiFi & Switch Controller > WiFi maps page Diagnostics and Tools panel, and on the WiFi & Switch Controller > FortiSwitch Clients page, the status of the LACP interface is incorrectly shown as down when it is up. This is a GUI issue that does not affect the operations of the LACP interface. To view the correct status of the LACP interface, go to the WiFi & Switch Controller > FortiSwitch Ports page, or use the CLI. |
|
944975 |
After configuring the |
|
960240 |
On the WiFi & Switch Controller > Managed FortiSwitches page, ISL links do not display as solid connections. |
|
984404 |
On the System > Firmware & Registration page, after upgrading the version 7.4.2, the FortiSwitch shows as not registered in the GUI. |
|
991855 |
The |
|
995518 |
On the WiFi & Switch Controller > Managed FortiSwitches > Upgrade page, the FortiGuard option is not available to upgrade when new firmware is available. |
| 997978 | Improvements to WAD to resolve an issue where unused values were handled during virtual switch configuration. |
|
1000663 |
The switch-controller managed-switch ports' configurations are getting removed after each reboot. |
|
1006398 |
DPP matching issues occur when multiple devices are connected to the same DPP port. |
|
1023888 |
On the WiFi & Switch Controller > FortiSwitch Ports page, changes made to the Allowed VLANs and Native VLAN columns are not saved when edited on the GUI. |
| 1028645 | Preconfig option issues occur when adding new FSW models. |
|
1032105 |
FortiGate in an HA configuration goes out of synchronization due to a split-port interface on FortiSwitch. |
|
1033874 |
FortiGate does not work as expected due an issue with a null variable in the |
| 1053043 | Free-style search failure occurs when searching with many FortiSwitches. |
| 1149978 |
CPU usage issues observed during flcfgd iteration over WAD user-device-store entries in FortiLink setup. |
| 1199780 |
Config status remains 'Wait' when FortiGate configuration changes are not reflected on FortiSwitches. |
System
|
Bug ID |
Description |
|---|---|
|
860534 |
VDOM settings are removed after rebooting FortiGate in TP mode with multiple VDOMs enabled. |
| 879876 | DSL connection issues occur when merging 80F_DSL platforms. |
|
880611 |
FortiGate enters into conserve mode due to a memory usage issue. |
|
901721 |
In a certain edge case, traffic directed towards a VLAN interface could cause an kernel interruption. |
|
910364 |
CPU usage issue in miglogd caused by constant updates to the ZTNA tags. |
|
916172 |
GRE traffic is still allowed to flow through when the GRE interface is disabled. |
|
917886 |
On FortiGate, fragmented packets with specific flow types are not forwarded to the correct ports on a LAG interface. |
|
925554 |
On the Network > Interfaces page, hardware and software switches show VLAN interfaces as down instead of up. The actual status of the VLAN interface can be verified using the command line. |
|
932002 |
Possible infinite loop can cause FortiOS to become unresponsive until the FortiGate goes through a power cycle. |
|
935158 |
The FortiGate console prints |
|
938475 |
A memory usage issue occurs when multiple threads try to access VLAN group. |
|
946393 |
On FortiGate, the software switch does not send an ARP reply from OIF. |
|
947398 |
When an EMAC VLAN interface is set up on top of a redundant interface, the kernel may encounter an error when rebooting. |
|
948875 |
The passthrough GRE keepalive packets are not offloaded on NP7 platforms. |
|
952284 |
A FortiGate with 2 GB of memory enters conserve mode when a node uses 20% of the memory. |
|
953547 |
SCTP traffic does not get forwarded by a connected hardware switch on FortiGate. |
|
956697 |
On NP7 platforms, the FortiGate maybe reboot twice when upgrading to 7.4.2 or restoring a configuration after a factory reset or burn image. This issue does not impact FortiOS functionality. |
|
959660 |
The |
|
964465 |
Administrators with read-write permission for WiFi and read permission for network configuration cannot create SSIDs on the System > Administrator Profiles page. |
|
964820 |
Traffic forwarding on Dialup VPN IPSec does not work as expected when |
|
966237 |
On NP7 platforms, egress shaping on a physical interface is not enforced on traffic according to the shaping profile definition. |
|
966384 |
On FortiGate 401F and 601F models, the CR mediatype option on x5-x8 ports is not available. |
|
967436 |
DAC cable between FortiGate and FortiSwitch stops working after upgrading from 7.2.6 to 7.2.7. |
|
968134 |
FortiGate 200F experiences a performance issue due to Marvell switch HOL mode. |
|
970053, 1006324 |
When a different transceiver type is added to FortiGate, the new transceiver information does not update in the GUI or CLI. |
|
972170 |
On FortiGate 80F models, the 100FULL speed option is not available for the SPF port. |
|
974740 |
FortiGate 2600F does not set 10G ports to 100G. |
|
975496 |
FortiGate 200F experiences slow download and upload speeds when traversing from a 1G to a 10G interface. |
|
975778, 1004883 |
VLAN traffic is stopped when created on LACP with |
|
976314 |
After upgrading FortiGate and not changing any configuration details, the output of |
|
978122 |
FortiGate experiences packet drop when |
|
979645 |
TCP traffic is classified as ip-frag and dropped when HPE entries are incorrectly configured in FortiOS versions prior to the fix. |
|
981433 |
The ipmcsensord does not work as expected when executing sensor-related commands before the high-end device sensor finishes booting up. |
|
986713 |
When restoring a FortiGate from a backup configuration, the device enters into system maintenance mode and is not accessible. |
|
986926 |
On the FortiGate 90xG models, the ULL interfaces for x5 - x8 are down after being set to 25G speed. |
|
988528 |
With NGFW mixed traffic, FortiGate experiences a CPU usage issue. |
|
989473 |
On FortiGate, the device may not work as expected due to a memory usage issue with the cmdbsvr. |
|
989629 |
FortiGate does not show additional speed options outside of auto on a WAN interface. |
|
990409 |
After an upgrade on FortiOS, the kernel operation is interrupted and reboots due to a switch command issue. |
|
991264 |
The locallogd process may cause a CPU usage issue on FortiGate. |
| 994043 | Unnecessary default timezones appear in backup files when config files are downloaded from FortiGate. |
|
995269 |
On FortiGate, the multicast session walker is rescheduled on the same CPU instead of the next CPU. |
|
995442 |
FortiGate may generate a Power Redundancy Alarm error when there is no power loss. The error also does not show up in the system log. |
| 995967 | Interface speed changes to 1000Full during upgrade from 7.2.6 to 7.4.2. |
|
996893 |
On FortiWiFi 81F-2R-3G4G-POE models, GPS service cannot be activated. |
| 997401 | System becomes unresponsive during upgrade to FortiOS 7.4.4 B2624. |
|
997563 |
SNMP ifSpeed OID show values as zero on VLAN interfaces in hardware switches. |
| 997617 | License restoration fails when uploading air-gap license. |
| 999899 | Config restoration occurs when private data encryption key is changed. |
|
1000194 |
FortiGate does not show QoS statistics in the |
|
1000658 |
After an integrity check, the dates on the hash files do not match causing a false positive error message. |
|
1001133 |
After an upgrade, FortiGate receives a |
|
1001498 |
On FortiGate, TCP and UDP traffic cannot pass through with |
|
1001601 |
A kernel interruption on FortiGate prevents it from rebooting after an upgrade with a specific configuration. |
|
1001722 |
VLAN/EMAC VLAN traffic is unexpectedly blocked under certain conditions. |
|
1001938 |
Support Kazakhstan time zone change to a single time zone, UTC+5. |
|
1002323 |
After restoring a configuration on FortiGate with the interface changed from aggregate to physical, the interface switches back to aggregate and cannot be changed back to physical. |
|
1002766 |
FortiGate prevents select interface |
|
1003026 |
On SoC3/SoC4 platforms, a kernel interruption may occur when running WAD monitoring scripts. |
|
1003349 |
CPU usage issue in WAD after upgrading from 7.4.1 to 7.4.3 when using address group member. |
|
1003925 |
After deleting a redundant port on FortiGate, the port does not register as being available and generates an error. |
|
1004804 |
FortiGate running firmware 7.2.7, the device encounters an error condition in the application daemon. |
| 1005020 | Firmware upgrade timeout occurs when upgrading LTE modem from FortiGuard. |
|
1005573 |
FortiGate incorrectly sends |
|
1006024 |
Administrator accounts using an admin profile with only FortiGuard Updates read-write permissions cannot open the FortiGuard page. |
|
1006979 |
FortiGate may encounter a memory usage issue on the flpold process, causing the primary and secondary units to go out of synchronization. |
|
1008049 |
The I2C bus becomes stuck during an upgrade due to an error in the |
|
1009278 |
Traffic does not hit a new policy created in the GUI or CLI due to an |
|
1009853 |
Outgoing traffic from EMAC-VLAN uses default cos tag when traffic is not offloaded. |
| 1009891 | Serial number setting issues occur when
using exec batch with set serial-number command. |
| 1010899 | Config loss occurs when restoring SNMP mib-views configuration. |
|
1011229 |
On FortiGate, a slab memory usage issue causes the device to enter into conserve mode. |
|
1011968 |
Jumbo frame packets do not pass through all split ports and may cause packets to drop. |
|
1012518 |
Some FortiGate models on NP6/NP6Lite/NP6xLite platforms experience unexpected behavior due to certain traffic conditions after upgrading to 7.2.8. Traffic may be interrupted momentarily. |
|
1013010 |
On some FortiGates, 25 GB transceivers are displayed as 10 GB transceivers in the |
|
1015169 |
On FortiGate, SNMP v3 cannot use |
|
1015736 |
On FortiWiFi 60/61F models, the STATUS LED light does not turn on after rebooting the device. |
|
1017446 |
Some TTL exceeded packets are not forwarded on their destination and an error message is not always generated. |
|
1018022 |
On FortiGate, VXLAN traffic is not offloaded properly resulting in some packets being dropped. |
|
1019749 |
On a VDOM, running |
|
1021355 |
FortiGate encounters a CPU usage issue when there are a high volume of traffic and scripts running on the device which could lead to an issue with performance. |
|
1021542 |
FortiGate reboots twice after a factory reset when |
|
1021632 |
FortiGate may experience intermittent traffic loss on an LACP interface in a virtual wire pair with |
|
1024737 |
On FortiGate, when |
| 1024746 | Performance issues occur when querying children objects with cmf query. |
| 1025442 | SNMPv3 polling issues occur when non-mgmt-vdom-query is disabled. |
|
1025503 |
On the Network > Diagnostics page, FortiGate shows that the packet capture capacity has been reached when there is no captured packet on the device. |
|
1025576 |
Passthrough GRE traffic using Transparent Ethernet Bridging packets as the protocol type are not offloaded on NP7 platforms. |
|
1025927 |
In an HA configuration, FortiGate cannot access the GUI after a firmware upgrade due to a certificate matching issue. |
|
1027335 |
Interface cannot ping out with dos-offloading enabled but no DoS policy. |
|
1029351 |
The OPC VM does not boot up when in native mode. |
|
1029874 |
FortiCron does not work as expected due to a memory usage issue in the daemon. |
|
1030529 |
Password change occurs when admin's password is unset after burn image |
|
1032018 |
The SFP+ port LED does not illuminate and displays a speed 10Mbps even though the link status up and speed is set to 1000Mbps. |
| 1033226 | An error condition occurs when restoring configuration with a large number of interfaces across multiple VDOMs. |
|
1034322 |
FortiGates using a SOC4 platform with a virtual switch configured may continuously reboot when upgrading due to an interruption in the kernel. |
| 1035834 | Support added for FortiExtender models FEX-511G and FEX-511G-wifi in FortiOS 7.4.5 and 7.6.0. |
|
1037075 |
On FortiGate, an interruption occurs in the kernel when running WAD process monitoring scripts. |
|
1037393 |
FortiGate reboots due to the maximum buffer length difference between nTurbo and NPU HW. |
| 1037480 | DHCP server configuration issues occur when setting role LAN under IPAM mode. |
|
1041457 |
The kernel 4.19 cannot concurrently reassemble IPv4 fragments for a source IP with more than 64 destination IP addresses. |
|
1041491 |
FortiGate encounters a memory usage issue in the |
|
1041669 |
FortiGate does not upgrade if |
|
1043979 |
An interruption occurs in the kernel resulting in intermittent power disruptions and rebooting of FortiGate. |
| 1044794 |
After installing a .deb image during bootup device shows "File - 1 seems to be corrupted" error and cannot boot up. |
|
1045701 |
FGT-80F-BP fails to boot up after burning image, showing error message "cli 161 die in an exception in line 300: end". |
|
1046171 |
System hang occurs when removing VDOMs after IPv6 connection through IP VDOM management. |
|
1048299 |
User names for some cloud-based services cannot be configured under |
|
1052004 |
FortiGate encounters a memory usage issue when there is no traffic running and the configuration is not fully loaded. |
| 1076964 | Status LED issue occurs when upgrading to B1703 v7.2.10 on FortiGate. |
Upgrade
|
Bug ID |
Description |
|---|---|
|
925567 |
When upgrading multiple firmware versions in the GUI, the Follow upgrade path option does not respect the recommended upgrade path. |
|
952828 |
The automatic patch upgrade feature overlooks patch release with the Feature label. Consequently, a FortiGate running 7.4.2 GA does not automatically upgrade to 7.4.3 GA. |
|
955810 |
Upgrading FortiOS is unsuccessful due to unmount shared data partition failed error. |
|
955835 |
When |
|
977281 |
After the FortiGate in an HA environment is upgraded using the Fabric upgrade feature, the GUI might incorrectly show the status Downgrade to 7.2.X shortly, even though the upgrade has completed. This is only a display issue; the Fabric upgrade will not recur unless it is manually scheduled. |
|
999324 |
FortiGate Pay-As-You-Go or On-demand VM versions cannot upload firmware using the System > Firmware & Registration > File Upload page. |
|
1013821 |
On FortiGate, an interruption occurs in the kernel in both HA FortiGates when an HA cluster's firmware is upgraded. |
|
1017519 |
Auto firmware-upgrade may run when a FortiGate is added to a FortiManager that is added behind a NAT. |
|
1019643 |
FGFM allowance removal occurs when central-mgmt is set to FMG during upgrade. |
|
1025687 |
After a firmware upgrade, the |
|
1027462 |
When restoring an FortiGate, the 7.4.1 config file with deprecated Inline CASB entries displays errors messages and causes the confsyncd to not function as expected. |
|
1031574 |
During a graceful upgrade, the confsync daemon and updated daemon encounter a memory usage issue, causing a race condition. |
|
1050162 |
The |
|
1053795 |
On FortiOS, passwords cannot be changed using the GUI with |
|
1055486 |
On the Firmware and Registration page, when performing a Fabric Upgrade using the GUI for the whole Fabric topology that includes managed FortiAPs and FortiSwitches, the root FortiGate may use an incorrect recommended image for FortiAP and FortiSwitch due to a parsing issue. |
User & Authentication
|
Bug ID |
Description |
|---|---|
|
910678, 946191 |
CPU usage issue in WAD caused by a high number of devices being detected by the device detection feature. |
|
974298 |
When using the local-in firewall authentication with SAML method, SAML users cannot get access using the authentication portal. |
|
976790 |
WiFi clients are not authenticated when using the Use my windows user account option for LDAP authentication. |
|
988958 |
When rsso user groups are updated, the session table is not cleared of old sessions and traffic still hits the old policy. |
|
989760 |
On the System > Certificates page, error Unable to create certificate displays when uploading certificates using the PKCS12 (.pfx) format. The certificates are still uploaded. |
|
1001026 |
Users are unable to use passwords that contain the ñ character for authentication. |
|
1004585 |
Intermittent traffic disruption occurs when SAML is configured in IPsec tunnel. |
|
1009213 |
After upgrading firmware on FortiGate, an interruption occurs in the fnbamd resulting in auto-connect not working as expected. |
|
1016112 |
SSL VPN access is prevented when the LDAP server includes a two-factor authentication filter. |
|
1017280 |
The default certificate bundle in FortiOS is updated to CRDB 1.50. |
|
1018846 |
When SCEP is used with SSL connections, some TLS connections are missing the SNI extension on FortiGate. |
|
1021157 |
Users are unable to use passwords that contain Polish characters ńżźćłśąó for RADIUS authentication. |
|
1023605 |
Multiple errors observed in the IOTD debug log caused by connection timeouts. |
|
1034898 |
After a firmware upgrade, FortiToken does not work as expected when using the GUI. |
|
1036265 |
The |
|
1039004 |
The |
|
1039490 |
FortiGate does not use a policy with deep inspection enabled on SSL profiles for SWG user access. |
VM
|
Bug ID |
Description |
|---|---|
|
891809 |
MTU issues occur when underlying interface MTU exceeds 1500. |
|
996389 |
AWS SDN Connector stops processing caused by the IAM external account role missing the |
|
998208 |
The FortiGate-VM system stops after sending an image to the HA secondary during an firmware upgrade due to different Flex-VM CPU license. |
|
999599 |
On FortiGate AWS, the IPsec configuration goes missing after an upgrade due to an inconsistent table-size. |
|
1001940 |
A newly created FGT-VM64 could not configure the vapp options settings. |
|
1006570 |
VPN tunnels go down due to IKE authentication loss after a firmware upgrade on the VM. |
|
1007382 |
Error condition in WAD occurs when handling large traffic bursts with DPDK |
|
1013122 |
Password reset issues occur when using Azure portal to reset FortiGate admin username/password. |
|
1016327 |
After rebooting, DPDK mode is disabled on a VLAN interface and traffic stops. |
|
1019467 |
When the underlying interface is removed, the IPsec tunnel interface will still hold a dst reference. |
|
1024011 |
The SDN connector does not update the correct IP addresses for either the upscale or downscale VMSS. |
|
1025604 |
The SDN connector does not update the correct IP addresses when using Flexible VMSS. |
|
1030534 |
On FortiGate, an HA failover does not work as expected when using an OCI environment. |
|
1036917 |
When a intended policy is configured for interesting traffic subnets, traffic flow hits the implicit deny rule instead of the configured policy. |
|
1040088 |
In an HA configuration, the secondary unit heartbeat port is accessible even though access to the interface is not allowed on that unit. |
VoIP
|
Bug ID |
Description |
|---|---|
|
1004894 |
VOIPD experiences high memory usage and enters into conserve mode. |
WAN Optimization
|
Bug ID |
Description |
|---|---|
|
642875 |
Memory usage issues caused by an error condition in WanOpt. |
|
899377 |
On FortiGate, an interruption occurs in the WAD causing traffic to stop and large files cannot be downloaded. |
Web Filter
|
Bug ID |
Description |
|---|---|
|
634781 |
Unable to customize replacement message for FortiGuard category in web filter profile. |
|
925801 |
Custom Images are not seen on Web Filter block replacement page for HTTP traffic in flow mode. |
|
975115 |
FortiGate prevents adding a regex string to a static URL filter table. |
|
1002266 |
Web filtering does not update rating servers if there is a FortiGuard DNS change. |
|
1004985 |
The webfilter cookie override trigger process had no issue observed and an override entry was created in the FortiGate, but client access was kept blocked by the old profile and the client received a replacement message with an override link just like the initial access to trigger the override. |
WiFi Controller
|
Bug ID |
Description |
|---|---|
|
908282 |
On FortiGate, an interruption occurs with the |
|
915715 |
On a secondary FortiGate in an HA cluster, |
|
949682 |
Intermittent traffic disruption observed in cw_acd caused by a rare error condition. |
|
950379 |
The diagnostics of online FortiAPs shows Link Down in the trunk port Connected Via field when the FortiAP has an LACP connection to a FortiSwitch. |
|
954277 |
Image download failure occurs when upgrading multiple FAP models through FortiGuard. |
|
989929 |
A kernel interruption occurs on FWF-40F/60F models when WiFi stations connect to SSID on the local radio. |
|
994752 |
A memory issue on the secondary firewall causes FortiGate to enter into conserve mode. |
|
1001104 |
FortiAP units repeated joining and leaving FortiGate HA cluster when the secondary FortiGate has stored FortiAP images. |
|
1001672 |
FortiWiFi reboots or becomes unresponsive when connecting to SSID after upgrading to 7.0.14. |
|
1003070 |
On FortiGate, the sta count is not accurate when some wireless clients connect to APs managed by FortiGate. |
|
1008333 |
Wi-Fi client disconnection occurs in FGT HA setup as the authentication state is not synchronized. |
|
1012433 |
Guest WiFi clients cannot be removed using RADIUS CoA after FortiGate reboots. |
|
1015163 |
Country codes BB, BZ, CO, DO, GD, GY, HN, FM, and PA moved from region N to A in FortiWiFi platforms. |
|
1017238 |
On the WiFi & Switch Controller > SSIDs page, new SSIDs cannot be created with captive portal enabled and a Portal Type of Disclaimer Only or Email Collect. |
|
1018107 |
Unable to manage FortiAP from FortiGate. |
|
1019680 |
FortiWiFi cannot access internal FAP consoles due to a login prompt issue in |
|
1035621 |
Accounting messages are not sent to all accounting servers when |
ZTNA
|
Bug ID |
Description |
|---|---|
|
944772 |
FortiGate does not use data from FortiClient to send the VPN snapshot to EMS. |
|
998172 |
When first connecting to the ZTNA server, the EMS websocket can become stuck and an error displays ZTNA Access Denied - Policy restriction!. |
|
1008632 |
When visiting SaaS application web pages using ZTNA, web pages can stall or return an ERR_CERT_COMMON_NAME_INVALID error. |
|
1012317 |
ZTNA intermittently does not match the firewall policy due to missing information in the policy. |
|
1016265 |
An interruption occurs in the WAD when trying to access the ZTNA server due to map matchers not being present. |
|
1018303 |
ZTNA does not allow tcp-forwarding SSH traffic to pass through. |
|
1020084 |
Health check on the ZTNA realserver does not work as expected if a blackhole route is added to the realserver address. |
|
1026930 |
An interruption occurs in the WAD process causing TCP connections to stop for ZTNA proxy policies. |
|
1037749 |
An error occurs when changing user SAML SP login/logout URL in ZTNA access. |
Common Vulnerabilities and Exposures
Visit https://fortiguard.com/psirt for more information.
|
Bug ID |
CVE references |
|---|---|
| 980300 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
997189 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
998718 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
998719 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
999253 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1001599 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1001731 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1002468 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1003801 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1020319 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1029403 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1045435 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1052254 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|
|
1071464 |
FortiOS 7.6.0 is no longer vulnerable to the following CVE Reference:
|