Resolved issues
The following issues have been fixed in version 7.6.3. To inquire about a particular bug, please contact Customer Service & Support.
Agentless VPN (formerly SSL VPN web mode)
See also SSL VPN tunnel mode replaced with IPsec VPN.
|
Bug ID |
Description |
|---|---|
|
947536 |
SSLVPN crashes on corporate FortiGate due to watchdog timeout when a single connection enters an infinite loop of read iterations and the worker process becomes unresponsive to new connections. |
|
1017304 |
SSL VPN web mode missing several security headers in the HTTP response. |
|
1036557, 1091173 |
Performance degradation occurs in SSL-VPN due to connection/session timeout management issues. |
|
1058211 |
Traffic could not go though SSL VPN tunnel when DTLS is enabled with a loopback interface as source address. |
|
1077157 |
FortiGate sends out expired server certificate for a given SSL VPN realm, even when the certificate configured in |
|
1083262 |
FNBAMD session hangs after a massive authorization request. |
|
1093580 |
SSL VPN authentication is triggered even with EMS SN check enabled. |
|
1099492 |
Permission error occurs when local user enters new password that does not comply with password policy. |
|
1101837 |
Insufficient session expiration in SSL VPN using SAML authentication. |
|
1102362 |
SSL VPN web mode missing HTTP response headers. |
|
1102515 |
Login failure occurs when 'warn days' are enabled in password policy for SSL VPN tunnel mode. |
|
1107663 |
FortiClient 7.2.6 GA Azure auto login cannot connect after upgrade. |
|
1111135 |
Log additional debug information to aid troubleshooting. |
|
1115510 |
SAML metadata fails to generate when haproxy binds to the reserved SSL VPN source port 8900, preventing SAML authentication. |
|
1124359 |
Error condition in sslvpnd occurs when generating a local signal handler within a chroot jail |
|
1126825 |
SSL VPN stops functioning when ssl.root interface is added to a zone used by at least one policy. |
Anti Virus
|
Bug ID |
Description |
|---|---|
|
1054835 |
Large file downloads take longer than expected due to a WAD process issue. |
|
1100819 |
SMB traffic fails when the file server uses AES-256-GCM/CCM encryption with FortiOS. |
|
1104189 |
In TP VDOM, the WAD creates the expectation session for FTP data connection if the firewall is in the proxy mode. This session does not have the outdev info. |
|
1111973 |
Security Profiles > Antivirus: Creating a new antivirus profile on 2G models displays error notification Cannot read properties of undefined (reading 'entries') and fails. |
|
1115628 |
Slowness and inaccessible internal resources when Antivirus profile is enabled in proxy mode. |
Application Control
|
Bug ID |
Description |
|---|---|
|
1064413 |
Traffic fails to follow SD-WAN rules when SNAT is enabled and "snat-route-change" is activated due to session drops caused by SNAT check failures after route changes. |
|
1102636 |
After the first DB update, only signatures in the built-in DB are loaded, preventing new categories and updated signatures from appearing correctly. |
DNS Filter
|
Bug ID |
Description |
|---|---|
|
1025233 |
Support Encrypted Client Hello (ECH) in flow mode. |
|
1080773 |
License expiration issue occurs when FortiGate has a valid FURL contract and connects to the StateRAMP SDNS server. |
|
1096380 |
FortiGate in proxy mode sends the cached DNS response when it receives a DNS registration request. |
|
1100282 |
When using FortiGate DNS servers, some clients cannot handle large UDP DNS responses exceeding 512B received from the FortiGate. |
Endpoint Control
|
Bug ID |
Description |
|---|---|
|
1066250 |
Verification of EMS and upgrade of FGT with verified EMS should promote CA to fabric-ca. |
|
1090981 |
Non-web ZTNA application configurations fail to sync with EMS after initial setup when FortiGate is connected to multiple EMS connectors. |
|
1093786 |
Expired 'FCEM' contracts are loaded in FGVM when multiple account-level licenses exist under the same tag due to selection based on entry order rather than expiration date. |
|
1098350 |
Sometimes the GUI >Asset FortiClient cannot display |
Explicit Proxy
|
Bug ID |
Description |
|---|---|
|
924740 |
Verbose wad diag filter on source IP occurs when filtering with src/src6 filter. |
|
1103272 |
SSL certificates are misapplied when FortiGate processes requests with deny actions in proxy policies. |
|
1107762 |
Overflow occurs in WAD daemon when oversize-limit exceeds 4096 MiB during byte conversion. |
|
1114438 |
Policy Test feature fails to function correctly when testing HTTP(S) server configurations due to missing source port initialization. |
|
1115137 |
Expand the |
|
1116555 |
Deep scanning occurs when accessing subcategories of websites with category-based proxy policies despite disabling subcategory checks. |
|
1134310 |
SSL exemption not working on proxy policy when partial match occurs. |
Firewall
|
Bug ID |
Description |
|---|---|
|
723186 |
Policy & Objects > Multicast Policy: Mac type addresses are not listed in the Src/dst omniselect on the GUI. |
|
946762 |
Policy & Objects > Firewall Policy: The column filter for Secondary security posture Tag does not filter matching results when multiple tags are present on a policy. |
|
993138 |
Misleading logs with subtype="ztna" appear when only virtual-server in a firewall policy. |
|
994986 |
The By Sequence view in the Firewall policy list may incorrectly show a duplicate implicit deny policy in the middle of the list. This is purely a GUI display issue and does not impact policy operation. The Interface Pair View and Sequence Grouping View do not have this issue. |
|
1025078, 1086315 |
Some customers observed memory usage increase and client session not disconnecting issues using virtual server |
|
1025969 |
Policy enforcement fails for wildcard FQDN hosts as destination targets because the address records are not added to the wildcard entry when processing a server response for an FQDN's domain name. |
|
1038650 |
Policy list refreshes entirely when right-clicking on hitcount or bytes columns to update statistics or clear counters. |
|
1050906 |
Under heavy network traffic, the Netflow session cache for sampled traffic quickly reaches the hardcoded RAM limit, causing the sFlow daemon to shut down. |
|
1055898 |
HTTP/2 post without content-length is not supported in half-ssl virtual server. |
|
1066136 |
Denied sessions were bidirectional and caused all traffic to be blocked. |
|
1078662 |
If an interface on an NP7 platform has the
|
|
1081542 |
Packet drops occur when high traffic causes nTurbo buffers to be reused without proper initialization under CPU-intensive conditions with ASIC offloading enabled. |
|
1088507 |
ICMP Echo replies sent through local-in-policy with virtual-patch enabled are routed through incorrect interfaces during traffic handling. |
|
1097628 |
Firewall policy filter does not work well on source and destination columns for "all" and "ems" addresses. |
|
1098208 |
After FortiGate exits conserve mode, some policies failed to install into the kernel at the same time. |
|
1101865 |
Trailing stray characters appear in Netflow App Info reports, causing warnings in analysis programs. |
|
1102471 |
Unexpected traffic hit policy in forward traffic log. |
|
1103748, 111268 |
Threat feeds used as source or destination addresses in security policies may not match correctly. |
|
1104208 |
NAT is incorrectly applied to traffic when a single SYN packet is sent to a VIP without an acknowledgment or reset. |
|
1106112 |
Shared memory files on entry-level platforms can't be removed upon restart due to being stored in a persistent directory instead of a temporary one. |
|
1107003 |
Policy & Objects: local-in policy, central-snat map, DoS Policy, and multicast policy have SD-WAN member in omniselect list of interface, and choosing the member interface results in an error. Central-snat map, DoS Policy, and multicast policy do not list the SD-WAN zone in omniselect list of interfaces. |
|
1108540 |
Search in the Address group dialog box using a partial word match takes more than a minute. |
|
1108832 |
Traffic shaping statistic issues caused by QTM when using NP7. |
|
1110135 |
Policy & Objects > Firewall Policy: Policy lookup for UDP protocol with FQDN does not work. Workaround: Use the command line for policy lookup. |
|
1111263 |
|
|
1116161 |
Traffic shaping statistics are not provided when using QTM on NP7. |
|
1117165 |
Leaving the To configure GTP APN traffic shaping: config gtp apn-shaper
edit <policy-id>
set apn [<apn-name> <apngrp-name> ...]
set rate-limit <limit>
set action {drop | reject}
set back-off-time <time>
next
end
|
|
1120749 |
If session is in SYN_SENT or SYN_RECV state, and FortiGate receives a second SYN with different ISN, it will drop the second SYN. |
|
1121944 |
A firewall policy allows traffic from client to server, but no policy exists for server to client. When traffic is not matched from server to client, a block session forms that blocks traffic in both directions. |
|
1127977 |
Traffic fails to pass FortiGate when firewall policies are applied in TP VDOM due to flag checks treating packets as local instead of forwarding them. |
|
1130932 |
An error condition occurs when disabling the outbound shaping-profile on the interface edit page. |
|
1136058 |
Policies are deleted and replaced with "implicit" when exporting CSV from the Interface Pair View in Firewall Policy GUI. |
|
1136163 |
The local-in-policy session TTL does not follow the service session-ttl. |
|
1139282 |
VIP with |
|
1139282 |
Incorrect SNI is sent during HTTP2/HTTP3 requests using "http-host" load balancing because WAD uses the proxy's SNI instead of the request's hostname. |
FortiGate 6000 and 7000 platforms
|
Bug ID |
Description |
|---|---|
|
790464 |
After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond. |
|
976521 |
High CPU usage by the node process occurs when loading 7000 policies due to fetching all statistics in one request. |
|
998615 |
When doing a GUI-packet capture on FortiGate, the through-traffic packets are not captured. |
|
1037220 |
GTP-U traffic fails when offloaded to NP7 with monitor-mode enabled. |
|
1062080 |
SNMP query returns an error when there is a large number of BGP routes. |
|
1078334, 1103739 |
High cmdbsvr CPU usage and FTP hang issues occur during scheduled automation backup executions due to automated backups appending device serial numbers to file names. |
|
1095936 |
Fewer sensor entries appear when executing 'chassis-sensor list' after system bootup due to delayed sensor initialization on SMM. |
|
1096156 |
GUI unreachable due to certificates and private keys mismatches in a HA setup. |
|
1097428 |
The Security Profile menu does not appear in the GUI for Global VDOM on FortiGate 6K/7K devices despite being accessible through CLI. |
|
1102413 |
Session count for VDOMs incorrect in FortiGate 6K/7K devices. |
|
1102481 |
Local-in remote access issues due to incorrect destination address. |
|
1104569 |
FortiGate FPM hangs after upgrade when confsynchbd fails to release a lock due to file permission issue. |
|
1105009 |
The command |
|
1108181 |
Unexpected behavior observed in the confsyncd daemon due to an erroneous memory allocation. |
|
1109415 |
New SNMP MIB table for chassis sensor. |
|
1109601 |
Graceful upgrades fail when hatalk daemon restarts, disrupting slbha state synchronization during FortiOS version transitions. |
|
1109963 |
SFF-8472 diagnostic support was not recognized on SFP transceivers in FG-7941F systems. |
|
1112581 |
On the FortiGate 7000F platform, after upgrading from FortiOS 7.4.7 to 7.6.2, cmdbsvr CPU usage can be at 99% on one or more FPMs for several minutes. During high CPU usage, FortiGuard packets cannot be synchronized to the affected FPM(s). |
|
1115656 |
FG-6K session filter by source interface doesn't set correct interface index. |
|
1116862 |
Graceful upgrade of a FortiGate 7000E chassis to FortiOS 7.6.2 may fail for some configurations. |
|
1118004 |
On a FortiGate 7000E FGCP cluster, after using the execute ha disconnect command to disconnect a chassis from the cluster, you can't use the special management ports to connect to the FIM in slot 2 or to any of the FPMs of either chassis. You can still connect to the FIM in slot 1. |
|
1121918 |
Confsyncd crashes occur when syncing ha-mgmt-intf to a newly joined HA slave due to invalid pointer attributes. |
|
1124603 |
Traffic drop occurs on 7KF-FGT devices when traffic shaping is enabled during or after migration, causing intermittent internet connectivity loss. |
|
1130218 |
Policies fail when Security Posture Tags are configured on SLBC platforms due to dynamic address sync issues outside HA mode. |
|
1139867 |
In a 7121F chassis HA system with 7000F image, the secondary chassis GTP-C tunnels were not synced with the primary chassis GTP-C tunnels. |
|
1149405 |
The image upgrade fails when performing a non-graceful update due to an ISIZE mismatch during verification. |
FortiView
|
Bug ID |
Description |
|---|---|
|
1125124 |
When running more than 1 million concurrent HTTP sessions across the firewall, and trying to access session list on FortiView in the GUI, packet loss and loss of a session are observed. |
GUI
|
Bug ID |
Description |
|---|---|
|
919473 |
Network > Interfaces: When an IPsec tunnel is bound to an interface, the "Interface Integrate" option for the interface fails. |
|
1047963 |
High Node.js memory usage when building FortiManager in Report Runner fails. Occurs when FortiManager has a slow connection, is unreachable from the FortiGate (because FMG is behind NAT), or the IP is incorrect. |
|
1054026 |
Offline license file cannot be uploaded to FGT by GUI. |
|
1055197 |
On FortiGate G series with dual WAN links, Interface bandwidth widget may show incorrect incoming and outgoing bandwidth count, where the actual traffic does not match the display numbers. |
|
1055354 |
Inappropriate Security Rating Insights items occur when registering to EMS and syncing tags. |
|
1055865 |
NodeJS errors when event log socket is closed. |
|
1092489 |
The |
|
1097405 |
Patch schedule minutes are ignored when set through the GUI for automatic upgrades. |
|
1099309 |
The FortiOS GUI fails to load topology-related pages when temporary files generated during Security Rating operations are mistakenly read by the REST API. |
|
1101932 |
IPsec monitor widget: IPsec phase2 tunnel details are not displayed in the tooltip when hovering over the phase2 selector. |
|
1102404 |
VDOM search function does not work properly if VDOM has uppercase letters. |
|
1104519 |
Interface faceplate appending occurs when switching between fabric devices. |
|
1110382 |
Admin can log in to GUI (HTTPS) with password, even when admin-https-pki-required is enabled. |
|
1110827 |
GUI shows LAN interfaces that have an IP address in the network ranges 172.31.0.0/16 or 192.168.0.0/16 to be managed by IPAM, even though the feature is globally disabled. |
|
1111113 |
When launching the GUI console using Jet Stream theme, the character spacing appears wider than usual. |
|
1111967 |
SD-WAN zone is not selectable as an interface in GUI for certain policies. |
|
1112716 |
No log output when running debug flow on GUI. |
|
1114658 |
Duplicated logs occur during Node.js health-check operations when internal communication between daemons is exposed through HTTP requests, as the traffic is captured in logs and packet captures. |
|
1115684 |
System > FortiGuard: FortiCare elite contract is not displayed accurately under Licensing information. |
|
1118810 |
Asset Identity Center: Tooltip on IoT/OT Vulnerabilities says OT license is inactive even with full license. |
|
1128730 |
An error condition occurs during upgrade to FortiOS 7.6.3 B3485. |
|
1133808 |
An error occurs when accessing FortiSandbox connector configuration via GUI. |
HA
|
Bug ID |
Description |
|---|---|
|
982081 |
After changing the status to down on the ha1 and ha2 ports, setting the status back to up does not bring up the ports. |
|
999440 |
Console prints error message when delete vdom in HA setup. |
|
999440 |
Console prints error message when delete vdom in HA setup |
|
1068674 |
PBA logs missing during HA failover. |
|
1073514 |
In HA cluster, when a FortiToken is aggregated or revoked from a local.user, cluster is out of SYNC. |
|
1085314, 1095879 |
Firewall policy page takes a long time to load on the HA Primary unit due to a loop condition between BGP and NSM when other protocols' same route is redistributed to BGP. |
|
1086511 |
Firmware upgrade/downgrade is stuck at "Preparing for upload" with "*.js results in a network error" for FetchEvent when using Selenium auto test under Chrome Incognito window. |
|
1087924 |
HA secondary unit experiences high CPU usage when frequent changes are made to CMDB on the HA primary unit. |
|
1088956, 1101490 |
Duplicated logs occur in FAZ during sniffer mode operation in HA active-passive setups because both active and passive FortiGates forward L2 packets to the IPS engine, causing duplicate entries. |
|
1091189 |
Switches observe MAC address flapping in HA A-A setups when both FortiGates use identical virtual MACs on their primary VLANs. |
|
1091657 |
SDN connector limits the API traffic flow through root VDOM or HA management VDOM. |
|
1095786 |
Traffic interruption occurs when performing a manual HA failback after an initial failover in VWP setups. |
|
1098192 |
Joining a FortiGate with RAID enabled in an existing cluster causes the primary to shut down due to differing RAID statuses. |
|
1099346 |
Connection issues occur when FortiGate secondary uses primary's certificate to connect to FMG instead of its own. |
|
1100177 |
In an FGSP setup, on asymmetric TCP flow during SYN/ACK packet on the other member, the TCP MSS value is not adjusted according to the firewall policy. |
|
1101456 |
In a HA setup, the aggregate interface status remains up after configuring 'status down' in FortiOS due to a race condition. |
|
1101879 |
Multiple SCTP expectation sessions are created during resynchronization due to a flag allowing duplication. |
|
1104892 |
Duplicate IP detected messages are seen from the Secondary Fortigate in a cluster. |
|
1105422 |
"Detected Tx Unit Hang" error occurrs on the HA secondary, causing it to become out-of-sync. |
|
1107137 |
The secondary FortiGate with an HA Reserved Management Interface cannot be accessed using HTTPS after upgrading from version 7.4.3. |
|
1108895 |
In an FGSP cluster, enabling and disabling |
|
1108895 |
In an FGSP cluster, enabling and disabling |
|
1109919 |
Cluster experiences split-brain when EMAC interfaces are disabled within a zone. |
|
1110498 |
Add IPv6 destination support under HA management interface configuration. |
|
1112525 |
Admin socket creation error occurs when upgrading FortiOS in an HA A-P cluster. |
|
1113842 |
New LACP interface is not shown under |
|
1115190 |
The SNMP value of fgVWLHealthCheckLinkState on the secondary unit should always be set to dead(1). |
|
1117725 |
HA synchronization fails due to checksum mismatches on CA certificates across all VDOMs when adding or modifying certificates sourced from a bundle. |
|
1121117 |
When two HA clusters are on the same subnet, the L2 session-sync packets could be received by each other, even if they are from two different HA clusters. |
|
1122341 |
Unexpected behavior occurs when ippool PBA index is out of range. |
|
1129088 |
The sessionsync daemon experiences high CPU usage when syncing expectation sessions under heavy SCTP traffic and FGSP enablement due to inefficiencies in the dump API. |
|
1135866 |
HA second unit cannot sync firewall ZTNA dynamic address with HA primary unit after primary disables EMS server. |
|
1137565 |
vSN support added in 7.2.9, 7.4.6, and 7.6.1. FG-100F/101F do not yet support vSN and logical-sn. |
|
1138763 |
IKE hasync loop and high memory consumption when peer address/port changes. |
Hyperscale
| Bug ID | Description |
|---|---|
|
1013892 |
Unexpected behavior observed in NPD when the threat feed object attempted to update manually in the HA pair. |
|
1055443 |
Add |
| 1058477 | sentb and rcvdb show -ve value for end session syslog message. |
|
1074547 |
SNAT session drops occur when kernel sessions become dirty in hyperscale VDOM environments due to inconsistent NAT resource allocation between software and hardware sessions. |
| 1091244 | hypersale hw-session-sync-dev should print properly error message when set members over 8. |
| 1091815 | hw session doesn't sync when one of multiple interface hw-session-sync-dev is down. |
|
1093287 |
Using fixed-allocation IP Pools may cause NP7 NSS/PRP modules to become stuck, potentially disrupting traffic. Other PBA IP pools do not have this issue. |
|
1094162 |
The |
| 1101562 | hyperscale hw-session-sync-dev LAG members can exceed 2*number of NP. |
|
1108263 |
HA configurations are lost if |
|
1114113 |
The |
|
1115761 |
When handling very high traffic loads (150M 250M concurrent sessions), the system sometimes fails to free up memory, even after all sessions have been cleared and traffic has stopped. |
| 1119021 | Sessionsync daemon makes hw-session-sync dev up even it's physically down, no such issue with sw session sync dev. |
| 1119031 | HW sessions are not synced to slave when one of the hw-session-sync-dev members is down. |
|
1121524 |
Client could not get DHCP IP address with policy-offload-level set to full-offload. |
| 1128155 | FGT-1801F log-transport TCP should be hidden for log servers under L2host and Netflow on CLI. |
| 1135433 | IPv6 entries appear in the output of pba list after reaching max PBA limit for ippool. |
| 1138823 | FGT-1801F non-hyperscale VDOM shows incorrect output of "diag firewall ippool get-pub/priv" commands. |
| 1140493 | Config should be blocked when user tries to set same interface as hw-session-sync-dev andmonitor. |
Intrusion Prevention
|
Bug ID |
Description |
|---|---|
|
1040783 |
FortiGate encounters CPU usage issue due to IPSEngine utilization when using an |
|
1074732 |
Traffic is dropped silently when IPv6 traffic is sent with UTM and nTurbo enabled on FortiGate-121G. |
|
1090616 |
IPS does not pass channel ID/category ID from the first video in a YouTube playlist to WAD. |
|
1093788 |
Sniffer logs are not generated when using VLANs. |
|
1101633 |
Child process that loads IPS database does not have CMDB permission to write to IPS table. |
|
1113473 |
When IPS generates traffic log for tunnel traffic, traffic log should include outer packet details. |
|
1121953 |
IPSengine processes consume memory and can lead to the conserve mode. |
IPsec VPN
|
Bug ID |
Description |
|---|---|
|
1002325 |
When spoke re-authauthorization is enabled, shortcut tunnel rekey fails and goes down when SA expires. Shortcut tunnel flaps while it re-establishes again. |
|
1042465 |
Packet drops occur when FortiOS CPUs are overwhelmed by high traffic bursts while IPsec acceleration is enabled, leading to CP queue overflows despite prior optimizations. |
|
1049015 |
IPsec performance issue on Intel-based platforms occurs due to FortiOS not enabling all available IPsec drivers. |
| 1051144 | IPsec dialup VPN connection issues occur when TCP port 4500 is blocked. |
|
1054440 |
Incrementing TX and RX errors on VPN interface occur when NPU offload is disabled, busy CPU cores, or high burst traffic cause packet drops due to full queues on SoC3/Soc4 platforms. |
|
1057558 |
Dialup and |
|
1059778 |
IPsec does not work as expected when the traffic path is from spoke dial-up to hub1, and then from hub1 to another site through a site-to-site tunnel. |
|
1060048 |
Throughput is limited in Site to Site VPN connections between the FW1kF and the FWVM Google Cloud platform. |
|
1064078 |
Egress shaper fails to enforce bandwidth limits on VPN ID with IPIP encapsulation IPsec interfaces due to incorrect handling of traffic forwarding across multiple network processing units. |
|
1071769 |
L2TP/IPsec connections fail due to interface changes from break-before-make rekeys and Windows rejecting selectors during FGT-initiated QM rekeys. |
|
1073670 |
Unexpected behavior observed in the IKED during HA split-brain events when IPsec tunnels are configured to use DHCP. |
|
1087651 |
Authentication fails when using FortiClient with IPsec IKEv2 after waiting more than 60 seconds to enter the 2FA token, caused by a fixed 60-second RADIUS timeout. |
|
1090200 |
transport-mode IPsec phase2 cannot set non-zero protocol successfully. |
|
1090200 |
IPsec phase2 interface with encapsulation set to transport-mode cannot successfully set non-zero protocol. |
|
1094028 |
Unexpected behavior observed in the IKED after configuration changes when the phase1 monitor feature is used. |
|
1102528 |
NP7 tunnel offloading failure recovery issue may cause use-after-free memory corruption when there are many concurrent IPSec tunnels, which leads to high CPU usage and kernel panic. |
|
1102584 |
Kernel crash caused by memory corruption due to a use-after-free issue, resulting in a system hang. This issue occurs with a large number of IPsec tunnels. |
|
1103594 |
ADVPN IPsec traffic over shortcuts drops during IPsec tunnel rekey. |
|
1103754 |
Failed HTTP sessions occur when passing through nTurbo due to improper handling of fragmented packets. |
|
1107198 |
Transparent mode, policy-based IPsec VPN, local-out traffic automatically enters VPN. |
|
1109028 |
With |
|
1109627 |
IPsec VPN match-security-posture-tag feature won't work when FortiClient is behind NAT. |
|
1110093 |
IPsec SA offloading stops on some FortiGate models when handling more than 50,000 concurrent secure associations. |
|
1112665 |
Static routes are marked inactive when an old IPSec tunnel is deleted during an INITIAL-CONTACT message in IKEv1, mistakenly deactivating the new tunnel's status in the kernel. |
|
1113354 |
Group list is truncated because of fixed-size buffers. |
|
1116825 |
Juniper device unable to establish IKEv1 tunnel with FGT. |
|
1117758 |
FGT fails to negotiate encryption algorithm CHACHA20_POLY1305 against third- party client. |
|
1117910 |
iked spikes to 99.9% if client sends FIN after ike tcp session is established. |
|
1120003 |
FortiGate presents certificate information when accessed using IPsec VPN listening interface. |
| 1120517 | IPsec tunnel failure occurs when using aggressive mode with PSK authentication. |
|
1125487 |
Gateway switching fails during IKE session resumption when moving from a FortiGate model without Azure AD auto-connect enabled to one with it due to missing mode communication. |
|
1127444 |
For ADVPN 2.0 shortcut negotiation, UDP hole punching for spoke behind NAT uses source port 500 instead of 4500. |
|
1127782 |
Traffic is dropped by anti-spoof check when passing traffic through phase2 transport mode with GRE encap. |
| 1134841 | IPv6 split tunnel option issue occurs when configuring remote access tunnel through VPN Wizard or Tunnel dialog. |
| 1135445 | An error condition in SSL VPN occurs when upgrading to FortiOS from v7.4.7 to v7.6.2. |
| 1136309 | IKE negotiation failure occurs when iked is restarted with signature authentication. |
|
1136536 |
VPN authentication fails on FortiSASE when a large number of RADIUS groups are configured. |
| 1138631 | Traffic distribution issues occur when configuring multiple IPsec tunnels between two FortiGates. |
Log & Report
|
Bug ID |
Description |
|---|---|
|
864002 |
Unauthenticated User mismatch with User in logs. |
|
1004103 |
Log & Report > Reports: When reports are renamed, the scheduled reports page does not load and the unable to fetch reports error notification is displayed. |
|
1009584 |
FGT-VM64 has no crash log record and event logs for license status change from Valid to Warning. |
|
1074460 |
Erroneous memory allocation results in intermittent HTTPSD disruption caused by a corrupted traffic log file. |
|
1084934 |
Firewall logs show Object Object in GUI and |
|
1087534 |
Page loading issues occur when loading a high number of logs. |
|
1091064 |
Missing poluuid and policyname fields occur in Forward Traffic logs when HA failover happens in FGCP clusters. |
|
1100883 |
Forward Traffic log fetched from FortiGate Cloud takes a long time to load on GUI. |
|
1107571 |
Some WiFi Log descriptions are inaccurate. |
|
1116428 |
Observed Device vulnerability lookup on FortiGuard in high frequency under the system event log. |
|
1118089 |
Temporary log files persist in /var/log after successful FTP uploads, leading to increased disk usage. |
|
1119147 |
Secondary device fails to generate reports at the set time. |
|
1121505 |
Log & report > Forward Traffic: The Security tab for security event logs does not load. |
|
1122938 |
Syslog traffic uses the correct exit interface after a change in source interface but fails to update the source IP. |
|
1129448 |
The body is partially missing from emails sent by alert mail. |
|
1130821 |
Incomplete log entries occur when attack context logging is enabled for attacks involving long user-agent strings. |
Proxy
|
Bug ID |
Description |
|---|---|
|
958200 |
Packets captured by IPS indicates HTTP/1.1 in case of HTTP/2 request. |
|
988473 |
On FortiGate 61E and 81E models, a daemon WAD issue causes high memory usage. |
|
1014014 |
Proxyd always selects the first certificate in the list when multiple server certificates are configured, regardless of SNI. |
|
1023054 |
After an upgrade on a 2GB FortiGate device, the firewall policy does not switch from Proxy-based to Flow-based in the Inspection mode field. |
|
1051875 |
Strict SNI certificate checks skip IP destination validation under strict mode. |
|
1054835 |
HTTP/2 large file transfers are slow when IPS, APP, or SSL inspect-all is enabled due to excessive buffering during traffic forwarding. |
|
1066113 |
Accessing certain websites through HTTPS fails when using inspect-all deep-inspection in proxy mode firewall policy. |
|
1096728 |
An error case observed in the WAD, affecting some VIP traffic, caused by erroneous memory allocation. |
|
1107205 |
FortiGate encounters a WAD memory usage issue when using a secure explicit web proxy with WAD user authentication to visit some websites. |
|
1116771 |
Add a limit on the memory used by user-device-store as a percentage of the total system memory |
|
1120964 |
An error condition in WAD occurs during shutdown after factory-reset on 32-bit ARM platforms. |
|
1121171 |
Large file downloads through proxy HTTP2 are slow when IPS/APP/SSL inspect-all enabled. |
|
1126253 |
When VDOM configuration file is restored, it changes the no-inspection profile under ssl-ssh-profile to deep-inspection. |
|
1126385 |
WAD fails to handle deep-inspection traffic under FIPS mode. |
|
1245569 |
Empty response occurs when pageSize exceeds 105 in FortiGate HTTPS Virtual Server |
REST API
|
Bug ID |
Description |
|---|---|
| 943756 |
When creating a VPN remote certificate with the API, the "remote" key fails to be set, resulting in incomplete configuration. |
|
1019750 |
The available interfaces list is slow in configurations with many IPsec tunnel connections. |
| 1026547 | Sensor information through REST API on a FG-81F returns 404 error. |
| 1071799 | Failed to rename switch-controller managed-switch entries through the CMDB REST API. |
|
1077192 |
External Account Binding support occurs when using ACME RFC8555. |
|
1107698 |
Adding ipv6-trusthost under api-user will override ipv4-trusthost setting and allow all IPv4 source IP addresses. |
|
1110811 |
HTTPSD crash due to a memory leak in the libjson-c library when the monitor/virtual-wan/health-check API returns an error and response is not free correctly. |
Routing
|
Bug ID |
Description |
|---|---|
|
897308 |
The system fib version does not match VDOM fib version in 1801F when queried due to a misalignment in how genid is reported by the Linux kernel to user space. |
|
1008434 |
The speed-test result files are not deleted after test runs. The new test ID may collide with a previous result. In this case, the GUI may read a previously failed result and report errors. |
|
1058283 |
Routing monitor: The Routing widget becomes unresponsive when using route lookup on a configuration that has a large number of routes. |
|
1058700 |
The load-balance mode in SD-WAN rules only considers up to 8 paths as active when more than 8 are configured. |
|
1072311, 1075911 |
BGP flaps occur when high L2P TPE drops are detected under heavy IPsec traffic conditions. |
|
1080449 |
IPv6 prefix delegation does not add IPv6 route automatically. |
|
1082842 |
The loopback interface does not appear as an outgoing option for BGP peer connections when configuring through the GUI. |
|
1084851 |
When adding new static route and prefix-list using CLI, |
|
1084907 |
Inactive IPv6 routes occur when dual stack BFD is configured without assigning the correct interface for IPv6, causing it to default to an IPv4 interface instead. |
|
1086944 |
The BGP router-id fails to reset after editing the neighbor group settings because the dialog doesn't properly handle the reset functionality. |
|
1093215 |
Users can create a BGP neighbor without configuring remote-as using CLI, and after completing BGP neighbor configuration, neighbor will remain in admin down state. |
|
1095307 |
Network > SD-WAN > SD-WAN Rules: Filtering on members with alias names does not display matching results. |
|
1099554 |
FortiGate uses link-local IPv6 address as nexthop in VLAN network, instead of global address. |
|
1100529 |
BGP Stale route not working as expected. |
|
1103034 |
Application "cmdbsvr" crashes when processing a configuration from OaaS controller. This issue occurs when adding another ISP to the test spokes and applying the change. |
|
1103212 |
Network > Routing Objects: BGP AS number with asdot/asdot+ format will drop the trailing 0s on "set set-aspath" router-map config. |
|
1105064 |
IPv6 traffic can't match the correct firewall policy in certain SD-WAN cases. |
|
1106035 |
CPU usage issues observed during auto BMRK operations. |
|
1108192 |
Restore image from FTP server failed using SD-WAN. |
|
1108874 |
SD-WAN Default_DNS performance SLA shows all participants of Default_DNS are down. |
|
1109286 |
Incorrect priorities are applied during remote health-checks when iked restarts because lnkmtd retains stale tunnel cache entries. |
|
1111233 |
|
|
1113929 |
Incorrect SDWAN rule is matched. fib-best-match is configured under zone. |
|
1114687 |
The snmpd cache update takes longer when querying SD-WAN health-check data due to delays in retrieving bandwidth statistics. |
|
1116924 |
In SD-WAN, when detect mode Prefer Passive is used, routing table is not updated in time |
|
1118891 |
ADVPN shortcut is established between different transport-groups. |
|
1119119 |
Inadvertent behavior observed in BGPD due to erroneous memory freeing when applying route-maps. |
|
1122021 |
FortiGate disregards SD-WAN members for path selection even when they are in SLA. |
|
1128032 |
Traffic fails with Fabric Overlay Orchestrator using automatic policy creation with system zones. |
|
1129698 |
When FortiAnalyzer setting |
|
1133796 |
IPv6 routes are stuck on kernel routing table. |
|
1134485 |
Failed to sniffer the VNE tunnel interface. |
|
1134763 |
Session marked dirty by mistake when unrelated route changes in different VRF. |
|
1138483 |
The link-monitor daemon truncates hostnames exceeding 63 characters when used in SDWAN health-check configurations, causing DNS resolution failures and impacting service availability. |
|
1145668 |
FortiGate encounters PIMD daemon issue, which hinders multicast traffic. |
SD-WAN
|
Bug ID |
Description |
|---|---|
|
1094449 |
Traffic routing issues occur when |
| 1110156 | Speedtest failure occurs when using PPPoE mode on a physical interface without a valid IP. |
| 1115208 | Probe-timeout value is reset to 60000 when detect-mode is remote. |
|
1116619 |
An error condition in vwl occurs when changing IPsec phase1-interface settings |
|
1118705 |
Speed test failure occurs when using BGP over loopback design |
|
1127506 |
ADVPN shortcut establishment issues occur when responder replies are delayed due to heavy load. |
|
1139728 |
Link-monitor issues occur when a large number of ADVPN shortcuts are established. |
|
1139734 |
High latency occurs when a large number of established and monitored shortcuts are present on the FortiGate. |
Security Fabric
|
Bug ID |
Description |
|---|---|
|
903922 |
Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation. |
|
1006397 |
In case of failure during a federated upgrade process, the system does not report granular failure details for individual devices. |
|
1011833 |
FortiGate experiences a CPU usage issue in the |
|
1019844 |
In an HA configuration, when the primary FortiGate unit fails over to a downstream unit, the previous primary unit displays as being permanently disconnected. |
|
1021684 |
In some cases, the Security Fabric topology cannot load properly and displays a Failed to load Topology Results error. |
|
1090401 |
Error messages from netxd API calls are not displayed when running as a daemon because they are printed to stderr instead of the CLI. |
|
1098787 |
Azure SDN Connector failure occurs when service tags API returns empty results with Resource Group scope permissions. |
|
1099235 |
Scheduled triggers do not include eventtime in log entries, causing automation scripts using %%log.eventtime%% to fail and generate filenames with missing or incorrect timestamps. |
|
1101806 |
Failed to trigger Security Rating Summary event automation stitch due to issue with log field ID. |
|
1111619 |
The |
|
1113463 |
FortiGate Azure connector fails to retrieve AKS information on AKS 1.29.5. |
|
1119616 |
Externally maintained threat feed contains both resource FQDNs and IP address ranges/subnets. Entry such as <addr>/0x1 then matches half of all possible IPv4 address and causes network disruption. |
|
1120652 |
Fabric topology with two devices on different VDOMs but behind the same router shows wrong VDOM data on tooltip. |
|
1134970 |
Inconsistent DNS TTL behavior in Kubernetes API through SDN-Connector. |
Switch Controller
|
Bug ID |
Description |
|---|---|
|
1015992 |
WiFi & Switch Controller > FortiLink Interface: When a FortiLink interface is down and the Lockdown ISL toggle is set to 'disable' on the GUI, the setting is not retained. |
|
1016034 |
In an HA environment with FortiSwitches connected, the lockdown ISL setting on FortiLink gets enabled during HA failover. |
|
1087254 |
Device fails to get IP address when moved between NAC ports on the same switch. |
|
1108965 |
Sync errors occur when incomplete transaction flags related to dhcp-snooping-static-client replay past configuration changes during sync attempts. |
|
1113465 |
VLAN configurations intermittently fail to assign on FSW ports when devices matching DPP policy come online, which is caused by a race condition during FSW initialization. |
|
1124356 |
DPP mac classification issue occurs when DPP policy with vlan-policy and 802.1x is configured together. |
|
1130242 |
Only the last SNMP community configuration is pushed from FGT to FSW during bulk processing. |
|
1138333 |
Increase efficiency of FortiLink configuration daemon memory usage. |
System
|
Bug ID |
Description |
|---|---|
|
814119 |
|
| 898182 | High CPU usage occurs when FortiGate is attacked by 4K PPS ARP requests. |
|
932077 |
Connection issue between SOC4 platform and third-party switches, for example Hirschmann GRS 105 or Cisco switch, since SOC4 doesn't support certain carrier extension signals. |
|
976722 |
Invalid YAML files are generated when exporting configurations containing multi-value attributes or long strings with newline characters. |
|
992323, 1056133, 1075607, 1082413, 1084898 |
Traffic interrupt when traffic shaping is enabled on 9xG and 12xG |
|
1017941 |
GUI interface bandwidth shows Tetrabyte spike for Gigabyte interface. Affected platforms: FGT-220xE and FGT-330xE |
| 1021838 | Memory usage issues caused by updated daemon redesign in forticldd. |
|
1030529 |
Password change occurs when admin's password is unset after burn image |
| 1039980 | Unexpected behavior in system occurs when out of memory during emergency restart. |
|
1040137 |
NPD skips config parsing when policy-offload-level set to disable. |
|
1040489 |
Traffic using VXLAN VTEP with a loopback over an IPsec VPN is dropped when VXLAN and IPsec are configured in different VDOMs due to incorrect tunnel creation success indicators. |
| 1044472 | Traffic drop occurs when VXLAN is a member of software switch in implicit mode. |
|
1046484 |
After shutting down a SOC4 FortiGate (FGT-40F/FGT-61F/FGT-81F/FGT-100F) using the "execute shutdown" command, the system automatically boots up again. |
|
1067448 |
VLAN switch is not working on 120G/121G. |
|
1068756 |
After updating to the latest unsigned version of an object, update daemon will not download a new signed version of that object if the versions are the same. |
|
1069208 |
If the DHCP offer contains padding when DHCP relay is used, the DHCP relay deletes the padding before relaying the packet. |
|
1075279 |
Member interfaces of VWP appear in packet capture creation dialog despite being ineligible. |
| 1076795 | Private data encryption key generation issues caused by manual entry of 32-digit hexadecimal keys. |
|
1076883 |
When the top application bandwidth feature is disabled, the GUI process still performs the initial check for application bandwidth, which may cause FortiCron to experience high CPU usage. |
|
1077562 |
Hardware egress shaping doesn't work on SOC5 when NPU offload is enabled. |
|
1078119 |
Traffic is intermittently interrupted on virtual-vlan-switch on Soc5 based platforms when a multicast or broadcast packet is received. |
|
1078568 |
When FortiManager adds FortiGate via serial number and is behind NAT, FortiGate cannot initiate requests to FortiManager, causing the GUI to fail in retrieving the certificate CN/SAN and resulting in an error. |
|
1079850 |
HA1/HA2 ports remain down after setting status to up. Rebooting fixes the issue. |
|
1085407 |
FortiGate unresponsive when |
|
1086268 |
VXLAN interface cannot be created if its underlying interface is DHCP. |
|
1087160 |
NP drops traffic when VXLAN is a member of software switch in implicit mode. |
|
1087270 |
Unexpected traffic increase over the FortiGate 6000 base backplane. |
|
1089143 |
The time change in FOS is restored after reboot. The RTC node is not created correctly so the time change can't be kept in RTC. |
|
1089272 |
The inability to view or click the "+" sign occurs when a user is assigned an admin profile with only read access, restricting actions that require write privileges. |
|
1090372 |
Access profile entries exceed global limit when built-in profiles consume table size slots. |
|
1091175 |
VLAN statistics on LAGs are not displayed correctly when asic-offload is enabled due to incorrect OID usage. |
|
1091551 |
Hardware limitation on the NP7 platform causes the following QTM related issues:
|
|
1094404 |
State of peer ports of FGT ports(negotiated speed, 1G) is down after upgrade on specific FGT |
|
1095834 |
When FortiGate is managed by FortiManager, which has a slow connection or is unreachable, memory consumption of node process keeps increasing. |
|
1096409 |
EXPIRE dates cannot be displayed properly when displaying the output of |
|
1096878 |
DNS cache flushing occurs too frequently due to unnecessary interface-reload events triggered by DHCP6 packets and SLAAC updates. |
|
1099770 |
NP7 drops encrypted GRE packets that have checksum bit set (1) due to invalid checksum. |
|
1101392 |
Administrators can execute the command |
|
1101647 |
FortiGate encounters a CPU usage issue for cmdbsvr process |
|
1102416 |
Cannot push |
|
1102919 |
GTP tunnels are deleted even if there are still associated requests. The problem occurred when multiple Create Session Request from different source IPs create the same GTP tunnel, and the first Create Session Response with an authentication failed cause leads to the deletion of the half-open tunnel and all associated requests. |
|
1103146 |
Duplicated RADIUS packets are captured by the sniffer when performing firewall authentication with a RADIUS server. |
|
1103966 |
FG901G gen1/2 boxes "diag hardw test asic" got FAILED |
|
1104173 |
Kernel panic occurs when pushing 'Device Setting' from FortiManager to NP7 platforms with Broadcom switch, causing the device to become unresponsive and requiring a reboot. |
|
1104410 |
The FortiGate-120G SFP ports fail to establish connectivity when configured with |
|
1104966 |
SNMP fgDiskCount.0 OID not returning disk count value |
|
1105989 |
System global configuration lost due to port collision. |
|
1105995 |
The switch MTU doesn't set correctly on 100m speed. |
|
1109633 |
When visiting the GUI login page, FortiGate prompts user for certificate when no PKI admin is set. |
|
1110527 |
FortiGate did not update password-expire time on the start or end of daylight savings time. |
|
1111601 |
Fortiguard sends IP addresses to proxy instead of FQDNs |
|
1112376 |
Unexpected behavior observed in the newcli daemon due to inconsistencies in node registration between cmdbsvr and other daemons. |
|
1113720 |
Packets not forwarded due to improper handling of specific flags in the bridging code, which incorrectly treats them as local instead of resolving their destination MAC address and forwarding. |
| 1114873 | CPU usage issues observed during cmdbsrv process execution after reboot. |
|
1115486 |
Virtual switch interface drops LLDP packets. |
|
1116220 |
FortiGate 3601E 25Gauto link not coming up using DAC cables. |
|
1116922 |
FortiGate encounters a memory usage issue if too many ports have LLDP reception enabled. |
|
1117435 |
Add SNMP new OIDs |
|
1117527 |
VXLAN interface should be brought down when underlay interface is down. |
|
1119595 |
URLfilter fails to track DNS TTLs and update the IPs of FQDN addresses after they have been changed. |
|
1120467 |
No SNMP trap at power failure for DC PSU. |
|
1120907 |
High traffic load on a particular interface causes packet loss on other interfaces of the FortiGate. |
|
1122306 |
Typo in log-controller-update request. |
|
1123149 |
Unexpected behavior occurs in FEXT201E when cfg-revert is triggered |
|
1123727 |
Incorrect traffic class (TC) settings and shaper class ID handling cause improper Quality of Service (QoS) application and session offloading failures for VLANs configured over Link Aggregation Groups (LAG) and hardware switches on FortiOS devices using SOC5 hardware. |
|
1124024 |
When |
|
1125301 |
FortiGate encounters parsing errors and potential system halts when configuration strings contain un-escaped single quotation marks, especially in password fields. |
|
1125947 |
FortiGate encounters a memory usage issue due to usage by HTTSD |
|
1126100 |
Expired user passwords are stored as plaintext in configuration files when password history is enabled. |
|
1126327 |
The SNMP query for |
|
1127534 |
Update built-in CRDB bundle to version 1.56. |
|
1127700 |
Packets are dropped during VLAN over VXLAN traffic due to incorrect handling of VLAN tags and session keys. |
|
1128087 |
In new version of RDP client, FortiGate drops some RDP sessions due to IPv6 extended headers. |
|
1133159 |
Inbandwidth settings are not enforced for traffic with multiple class IDs in a FortiOS shaping profile, resulting in reduced available bandwidth beyond 12 classes. |
|
1133842 |
Packet dropped with 'DCE_IVS_IGR_DIR_DROP' over hardware switch. |
|
1140422 |
SNMP query failure occurs when rpc aggregation is enabled for slave blades on FortiGate 6000F. |
| 1140696 | An error condition in Forticron occurs when log-single-cpu-high is enabled. |
|
1142013 |
Policing improvement for QTM by limiting buffer size or switching to TPE ( |
|
1144091 |
An error condition in dhcprd occurs when handling IPsec messages. |
Upgrade
|
Bug ID |
Description |
|---|---|
|
1043815 |
Upgrading the firmware for a large number (100+) of FortiSwitch or FortiAP devices at the same time may cause performance issues with the GUI and some devices may not upgrade. |
|
1097503 |
Fabric upgrade from 7.2.9 to 7.4.5 failed. |
|
1102990 |
SLBC FortiGate 5001E primary blade failed to install image, even though graceful-upgrade was disabled. |
|
1104649 |
In 7.6.1 and 7.6.2, if a local-in policy, local-in-policy6, DoS policy, interface policy, multicast policy, TTL policy, or central SNAT map is used in an interface in version 7.4.5, 7.6.0, or any previous GA version that was part of the SD-WAN zone, these policies will be deleted or show empty values after upgrading to version 7.6.1 or 7.6.2. See Policies that use an interface show missing or empty values after an upgrade for more information. |
|
1105771 |
Upgrade from 7.4.6 GA to 7.6.1 GA results in an incomplete WAD device memory list table and triggers WAD error. |
|
1106072 |
The image file transfer between FortiManager and FortiGate may not work as expected when transferred by the FGFM tunnel. |
|
1110809 |
Egress-shaping-profile setting lost on interface after upgrade. |
|
1114232 |
When upgrading FortiGate from earlier than 7.4.1 to 7.4.1 or later, system.replacemsg.webproxy configuration is lost. |
|
1123954 |
FortiGuard updates are automatically enabled during upgrades from versions where they were previously disabled, bypassing user acknowledgment. |
|
1130861 |
FG-4401F enters a reboot loop after upgrading from 7.2.9 GA to 7.4.6 GA with a large config file (more than 10K policies). |
User & Authentication
|
Bug ID |
Description |
|---|---|
|
1017348 |
Memory usage by fsso_ldap daemon increases continuously when the LDAP server responds with "LDAP_UNWILLING_TO_PERFORM" due to an unhandled memory allocation issue. |
|
1020808 |
Use new keys for certificate renewal through EST server. |
|
1025260 |
Wildcard admin remote authorization password change in system GUI does not work. |
|
1043189 |
Low-end FortiGate models with 2GB memory can enter conserve mode when processing large amounts (over 5000 user records) of stored user store data, when each record has a large amount of IoT vulnerability data. For example, the Users and Devices page or FortiNAC request can trigger the following API call that causes httpsd process to spike in CPU and memory: GET request /api/v2/monitor/user/device/query |
|
1054818 |
Password encryption changes occur when editing |
|
1075207 |
Errors may occur in the FNBAMD due to the presence of two wildcard-enabled remote administrators in separate VDOMs. |
|
1077636 |
No SNMP trap available to detect FSSO external connected status change. |
|
1091483 |
When importing local certificate, GUI displays an error, even when certificate is correctly imported. |
|
1093538 |
In SAML config, after enabling "AD FS claim" (Active Directory Federated Services and rebooting, the "Attribute used to identify users" and "Attribute used to identify groups" fields are blank. |
|
1093542 |
FortiGate admin user authentication with token+RADIUS fails when wildcard user is configured. |
|
1093654 |
FGT uses global DNS when attempting to provision a certificate through SCEP or EST. |
|
1099831 |
An error condition in fnbamd occurs during stress testing with certificate parsing. |
|
1105305 |
Guest users are not removed after their configured expiry time on certain FortiGate models. |
|
1119143 |
Unable to view local certificate in GUI or CLI after certificate import. |
|
1121503 |
Source-ip setting issue occurs when configuring scep enroll settings per VDOM in non-management VDOM. |
|
1121987 |
Firewall user widget: Tooltip for FSSO users on the 'user group' column displays overlapping text. This is cosmetic and does not affect functionality. |
|
1136244 |
RSSO not working on 7.6.x with Cisco Meraki MX. |
VM
|
Bug ID |
Description |
|---|---|
|
999842 |
Azure fails to honor seamless live migration. In most cases, the public IP to private IP NAT fails to forward traffic from/to SD-WAN. |
|
1012000 |
When unicast HA setup has a large number of interfaces, FGT Hyper-V takes a long time to boot up. |
|
1094600 |
The virtual-wire pair fails to create during FortiOS initialization on cloud platforms when the underlying interface uses DHCP and hasn't acquired an IP address yet, preventing VXLAN configuration from completing successfully. |
|
1101264 |
HA failover actions are triggered even when the Azure SDN connector is in a "disabled" state, causing increased downtime during failover. |
|
1102434 |
Configuring VRF on hbdev causes FGT VM HA not to sync. |
|
1107007 |
samld stops working when certificate set to Fortinet_Factory in user SAML. |
|
1107933 |
The FortiGate device uses a single CPU core for GRE decapsulation tasks when running on AWS with ena NIC drivers because L4 hash functionality is not enabled, preventing RPS from distributing traffic efficiently. |
|
1107962 |
Dynamic addresses are removed/added every few seconds when the OCI SDN connector fetches only the first page of API results. |
|
1109724 |
Azd daemon on Azure NVA keeps consuming memory until FortiGate enters conserve mode. |
|
1113362 |
FGT-VM64-AZURE cannot establish connection with other FGTs in the Security Fabric tree. |
|
1121521 |
Azure SDN connector does not properly catch AKS cluster state. |
|
1121974 |
Due to continuous disk logging, slab memory for dentry continuously increases in FortiGate VM. |
|
1128351 |
Configuration fails to fully apply during bootstrap when the reboot function does not trigger an immediate reboot, causing cloudinit to re-run with insufficient tablespace. |
|
1128988 |
License validation issues occur when connecting to FDS via a web proxy. |
|
1143866 |
License status warning occurs when FortiGate-VM64 is upgraded |
Web Filter
|
Bug ID |
Description |
|---|---|
|
874516, 1100819 |
SMB traffic fails when the file server uses AES-256-GCM/CCM encryption with FortiOS. |
|
906603 |
Security Profiles > Webfilter: When a new webfilter is created and the action on the FortiGuard category-based filter is set to 'allow' and saved, the action is saved as 'monitor' on commit. |
|
1099818 |
Output of |
|
1107456 |
FG-120G webfilter.profile tablesize is incorrect. |
|
1110668 |
Add an option to control webfilter.urlfilter simple-type entries match subdomains. |
|
1110850 |
The value for x-forwarded-for is not properly displayed in the log on AWS environment. |
|
1118132, 1122036, 1127984 |
Webfilter local category override not working after reboot in flow mode. |
WiFi Controller
|
Bug ID |
Description |
|---|---|
|
823387 |
Email addresses collected through captive portal fail to display under WiFi clients when using guest SSID configurations. |
|
921080 |
The FortiGate Hostapd does not support IPv6 address of RADIUS server. |
|
987030 |
Unexpected behavior observed in the CAPWAP daemon when managing multiple APs and clients through dynamic VAP changes. |
|
1013892 |
On FortiGate's in an HA pair, the npd process do not work as expected when trying to manually update the threat feed. |
|
1030197 |
Client traffic is blocked after a failure when connecting through SSID using radius-mac-auth and radius-mac-auth-usergroup because the secondary FortiGate in HA does not receive necessary client details during failover. |
|
1039985 |
Erroneous memory allocation observed in the CAPWAP function on NP6 and NP6XLite platforms due to a rare error case. |
|
1080094 |
High memory usage may occur due to offline station entries not being automatically cleaned up over time. |
|
1083395 |
In an HA environment with FortiAPs managed by primary FortiGate, the secondary FortiGate GUI Managed FortiAP page may show the FortiAP status as offline if the FortiAP traffic is not routed through the secondary FortiGate. This is only a GUI issue and does not impact FortiAP operation. |
|
1086128 |
An error condition in CAPWAP occurred due to a rare case. |
|
1089999 |
FAPs remain offline post-upgrade when using image stored on FortiGate. |
|
1094415 |
VLAN pooling assigns incorrect VLAN IDs when FortiOS is upgraded, causing clients on AP groups to receive IPs from the optional VLAN instead of the pool. |
|
1096961 |
The "AP image receive success" log (id 43618) does not generate when upgrading FAP from FMG. |
|
1098727 |
Enable 5GHz channels 52-64, 108, 116-128 for FAP-231G-P, 431G-P Uzbekistan. (Uzbekistan has no DFS certification process.) |
|
1100220 |
COA disconnect is not functional for MPSK profiles when using external FortiGuest. |
|
1101583 |
FortiAP go offline when the cw_acd process becomes stuck at 99% CPU usage. This issue is caused by the FortiAP sending corrupt data in certain scenarios, leading to the process hanging. |
|
1102808 |
When the configuration contains a large number of vlan-pool entries, deleting or adding a few entries can cause the cw_acd crash. |
|
1108726 |
FortiAPs periodically lose connectivity with FortiGate (acting as WLC) due to an error case. |
|
1114144 |
WSSO firewall authentication sessions fail to establish when FortiGate processes multiple group attributes with the initial group missing. |
|
1114311 |
Packets are incorrectly routed when FAP management interface uses clear-text dtls-policy in a software switch with explicit intra-switch-policy. |
|
1123829 |
Support legal firewall policy when SD-WAN/zone member interface manages FAP with |
|
1128272 |
Management connection fails for FAP-231F when using PPPoE interface on FGT-120G. |
|
1130750 |
WiFi & Switch controller > Managed FortiAPs: When a channel override on a 5GHz channel is enabled is edited on a managed AP, the channel selection is unset. |
|
1133829 |
The FAP remains offline after the FortiGate reboots or wireless-controller restart-acd due to the controller sending an empty country string to the access point. |
|
1139749 |
FortiGate does not honor source IP for MPSK RADIUS requests. |
ZTNA
|
Bug ID |
Description |
|---|---|
|
1101022 |
FortiClient gets a blank page when doing SAML authentication due to the use of a stale user node. |
|
1107986 |
Should be unable to select geography object in ZTNA proxy-policy. |
|
1111112 |
Unable to configure more than eight mapped ports for access proxy realservers when the limit is 16. |
|
1114976 |
ZTNA policy matching failed due to an accidental deletion of firewall.policy with ZTNA tags when the firewall.policy is updated. |
|
1115153 |
Authentication loops occur during ZTNA connections requiring SAML when FortiClient uses multiple sessions with inconsistent cookies. |
|
1118540 |
Browser timeout occurs when accessing ZTNA web bookmark with IP address. |
Common Vulnerabilities and Exposures
Visit https://fortiguard.com/psirt for more information.
|
Bug ID |
CVE references |
|---|---|
|
1085628 |
FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:
|
|
1103790 |
FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:
|
|
1108301 |
FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:
|
|
1137151 |
FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:
|