Fortinet white logo
Fortinet white logo

FortiOS Release Notes

Resolved issues

Resolved issues

The following issues have been fixed in version 7.6.3. To inquire about a particular bug, please contact Customer Service & Support.

Agentless VPN (formerly SSL VPN web mode)

See also SSL VPN tunnel mode replaced with IPsec VPN.

Bug ID

Description

947536

SSLVPN crashes on corporate FortiGate due to watchdog timeout when a single connection enters an infinite loop of read iterations and the worker process becomes unresponsive to new connections.

1017304

SSL VPN web mode missing several security headers in the HTTP response.

1036557, 1091173

Performance degradation occurs in SSL-VPN due to connection/session timeout management issues.

1058211

Traffic could not go though SSL VPN tunnel when DTLS is enabled with a loopback interface as source address.

1077157

FortiGate sends out expired server certificate for a given SSL VPN realm, even when the certificate configured in virtual-host-server-cert has been updated.

1083262

FNBAMD session hangs after a massive authorization request.

1093580

SSL VPN authentication is triggered even with EMS SN check enabled.

1099492

Permission error occurs when local user enters new password that does not comply with password policy.

1101837

Insufficient session expiration in SSL VPN using SAML authentication.

1102362

SSL VPN web mode missing HTTP response headers.

1102515

Login failure occurs when 'warn days' are enabled in password policy for SSL VPN tunnel mode.

1107663

FortiClient 7.2.6 GA Azure auto login cannot connect after upgrade.

1111135

Log additional debug information to aid troubleshooting.

1115510

SAML metadata fails to generate when haproxy binds to the reserved SSL VPN source port 8900, preventing SAML authentication.

1124359

Error condition in sslvpnd occurs when generating a local signal handler within a chroot jail

1126825

SSL VPN stops functioning when ssl.root interface is added to a zone used by at least one policy.

Anti Virus

Bug ID

Description

1054835

Large file downloads take longer than expected due to a WAD process issue.

1100819

SMB traffic fails when the file server uses AES-256-GCM/CCM encryption with FortiOS.

1104189

In TP VDOM, the WAD creates the expectation session for FTP data connection if the firewall is in the proxy mode. This session does not have the outdev info.

1111973

Security Profiles > Antivirus: Creating a new antivirus profile on 2G models displays error notification Cannot read properties of undefined (reading 'entries') and fails.

1115628

Slowness and inaccessible internal resources when Antivirus profile is enabled in proxy mode.

Application Control

Bug ID

Description

1064413

Traffic fails to follow SD-WAN rules when SNAT is enabled and "snat-route-change" is activated due to session drops caused by SNAT check failures after route changes.

1102636

After the first DB update, only signatures in the built-in DB are loaded, preventing new categories and updated signatures from appearing correctly.

DNS Filter

Bug ID

Description

1025233

Support Encrypted Client Hello (ECH) in flow mode.

1080773

License expiration issue occurs when FortiGate has a valid FURL contract and connects to the StateRAMP SDNS server.

1096380

FortiGate in proxy mode sends the cached DNS response when it receives a DNS registration request.

1100282

When using FortiGate DNS servers, some clients cannot handle large UDP DNS responses exceeding 512B received from the FortiGate.

Endpoint Control

Bug ID

Description

1066250

Verification of EMS and upgrade of FGT with verified EMS should promote CA to fabric-ca.

1090981

Non-web ZTNA application configurations fail to sync with EMS after initial setup when FortiGate is connected to multiple EMS connectors.

1093786

Expired 'FCEM' contracts are loaded in FGVM when multiple account-level licenses exist under the same tag due to selection based on entry order rather than expiration date.

1098350

Sometimes the GUI >Asset FortiClient cannot display ems-tag for VPN user which make "Matched Endpoints" page missed those user.

Explicit Proxy

Bug ID

Description

924740

Verbose wad diag filter on source IP occurs when filtering with src/src6 filter.

1103272

SSL certificates are misapplied when FortiGate processes requests with deny actions in proxy policies.

1107762

Overflow occurs in WAD daemon when oversize-limit exceeds 4096 MiB during byte conversion.

1114438

Policy Test feature fails to function correctly when testing HTTP(S) server configurations due to missing source port initialization.

1115137

Expand the proxy-auth-timeout maximum value.

1116555

Deep scanning occurs when accessing subcategories of websites with category-based proxy policies despite disabling subcategory checks.

1134310

SSL exemption not working on proxy policy when partial match occurs.

Firewall

Bug ID

Description

723186

Policy & Objects > Multicast Policy: Mac type addresses are not listed in the Src/dst omniselect on the GUI.

946762

Policy & Objects > Firewall Policy: The column filter for Secondary security posture Tag does not filter matching results when multiple tags are present on a policy.

993138

Misleading logs with subtype="ztna" appear when only virtual-server in a firewall policy.

994986

The By Sequence view in the Firewall policy list may incorrectly show a duplicate implicit deny policy in the middle of the list. This is purely a GUI display issue and does not impact policy operation.

The Interface Pair View and Sequence Grouping View do not have this issue.

1025078, 1086315

Some customers observed memory usage increase and client session not disconnecting issues using virtual server

1025969

Policy enforcement fails for wildcard FQDN hosts as destination targets because the address records are not added to the wildcard entry when processing a server response for an FQDN's domain name.

1038650

Policy list refreshes entirely when right-clicking on hitcount or bytes columns to update statistics or clear counters.

1050906

Under heavy network traffic, the Netflow session cache for sampled traffic quickly reaches the hardcoded RAM limit, causing the sFlow daemon to shut down.

1055898

HTTP/2 post without content-length is not supported in half-ssl virtual server.

1066136

Denied sessions were bidirectional and caused all traffic to be blocked.

1078662

If an interface on an NP7 platform has the set inbandwidth XXX, set outbandwidth XXX, and set egress-shaping-profile XX settings, the following issues may occur:

  • Fragment packet checksum is incorrect.

  • MTU is not honored when sending packets out.

  • QTM hangs and blocks traffic when packet size is larger than 6000 bytes.

1081542

Packet drops occur when high traffic causes nTurbo buffers to be reused without proper initialization under CPU-intensive conditions with ASIC offloading enabled.

1088507

ICMP Echo replies sent through local-in-policy with virtual-patch enabled are routed through incorrect interfaces during traffic handling.

1097628

Firewall policy filter does not work well on source and destination columns for "all" and "ems" addresses.

1098208

After FortiGate exits conserve mode, some policies failed to install into the kernel at the same time.

1101865

Trailing stray characters appear in Netflow App Info reports, causing warnings in analysis programs.

1102471

Unexpected traffic hit policy in forward traffic log.

1103748, 111268

Threat feeds used as source or destination addresses in security policies may not match correctly.

1104208

NAT is incorrectly applied to traffic when a single SYN packet is sent to a VIP without an acknowledgment or reset.

1106112

Shared memory files on entry-level platforms can't be removed upon restart due to being stored in a persistent directory instead of a temporary one.

1107003

Policy & Objects: local-in policy, central-snat map, DoS Policy, and multicast policy have SD-WAN member in omniselect list of interface, and choosing the member interface results in an error.

Central-snat map, DoS Policy, and multicast policy do not list the SD-WAN zone in omniselect list of interfaces.

1108540

Search in the Address group dialog box using a partial word match takes more than a minute.

1108832

Traffic shaping statistic issues caused by QTM when using NP7.

1110135

Policy & Objects > Firewall Policy: Policy lookup for UDP protocol with FQDN does not work.

Workaround: Use the command line for policy lookup.

1111263

tcpsock command missing PID/process name for sessions in established state.

1116161

Traffic shaping statistics are not provided when using QTM on NP7.

1117165

Leaving the apn field empty in a GTP APN traffic shaping policy means that the policy will not match any traffic. Consequently, APN traffic shaping can only be applied to specific APNs.

To configure GTP APN traffic shaping:

config gtp apn-shaper
    edit <policy-id>
        set apn [<apn-name> <apngrp-name> ...]
        set rate-limit <limit>
        set action {drop | reject}
        set back-off-time <time>
    next
end

1120749

If session is in SYN_SENT or SYN_RECV state, and FortiGate receives a second SYN with different ISN, it will drop the second SYN.

1121944

A firewall policy allows traffic from client to server, but no policy exists for server to client. When traffic is not matched from server to client, a block session forms that blocks traffic in both directions.

1127977

Traffic fails to pass FortiGate when firewall policies are applied in TP VDOM due to flag checks treating packets as local instead of forwarding them.

1130932

An error condition occurs when disabling the outbound shaping-profile on the interface edit page.

1136058

Policies are deleted and replaced with "implicit" when exporting CSV from the Interface Pair View in Firewall Policy GUI.

1136163

The local-in-policy session TTL does not follow the service session-ttl.

1139282

VIP with set ldb-method http-host sends incorrect FQDN in ClientHello to second realserver when using HTTP2.

1139282

Incorrect SNI is sent during HTTP2/HTTP3 requests using "http-host" load balancing because WAD uses the proxy's SNI instead of the request's hostname.

FortiGate 6000 and 7000 platforms

Bug ID

Description

790464

After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond.

976521

High CPU usage by the node process occurs when loading 7000 policies due to fetching all statistics in one request.

998615

When doing a GUI-packet capture on FortiGate, the through-traffic packets are not captured.

1037220

GTP-U traffic fails when offloaded to NP7 with monitor-mode enabled.

1062080

SNMP query returns an error when there is a large number of BGP routes.

1078334, 1103739

High cmdbsvr CPU usage and FTP hang issues occur during scheduled automation backup executions due to automated backups appending device serial numbers to file names.

1095936

Fewer sensor entries appear when executing 'chassis-sensor list' after system bootup due to delayed sensor initialization on SMM.

1096156

GUI unreachable due to certificates and private keys mismatches in a HA setup.

1097428

The Security Profile menu does not appear in the GUI for Global VDOM on FortiGate 6K/7K devices despite being accessible through CLI.

1102413

Session count for VDOMs incorrect in FortiGate 6K/7K devices.

1102481

Local-in remote access issues due to incorrect destination address.

1104569

FortiGate FPM hangs after upgrade when confsynchbd fails to release a lock due to file permission issue.

1105009

The command execute load-balance slot manage X fails on FortiGate 6K/7K devices when admin-telnet is disabled and then re-enabled.

1108181

Unexpected behavior observed in the confsyncd daemon due to an erroneous memory allocation.

1109415

New SNMP MIB table for chassis sensor.

1109601

Graceful upgrades fail when hatalk daemon restarts, disrupting slbha state synchronization during FortiOS version transitions.

1109963

SFF-8472 diagnostic support was not recognized on SFP transceivers in FG-7941F systems.

1112581

On the FortiGate 7000F platform, after upgrading from FortiOS 7.4.7 to 7.6.2, cmdbsvr CPU usage can be at 99% on one or more FPMs for several minutes. During high CPU usage, FortiGuard packets cannot be synchronized to the affected FPM(s).

1115656

FG-6K session filter by source interface doesn't set correct interface index.

1116862

Graceful upgrade of a FortiGate 7000E chassis to FortiOS 7.6.2 may fail for some configurations.

1118004

On a FortiGate 7000E FGCP cluster, after using the execute ha disconnect command to disconnect a chassis from the cluster, you can't use the special management ports to connect to the FIM in slot 2 or to any of the FPMs of either chassis. You can still connect to the FIM in slot 1.

1121918

Confsyncd crashes occur when syncing ha-mgmt-intf to a newly joined HA slave due to invalid pointer attributes.

1124603

Traffic drop occurs on 7KF-FGT devices when traffic shaping is enabled during or after migration, causing intermittent internet connectivity loss.

1130218

Policies fail when Security Posture Tags are configured on SLBC platforms due to dynamic address sync issues outside HA mode.

1139867

In a 7121F chassis HA system with 7000F image, the secondary chassis GTP-C tunnels were not synced with the primary chassis GTP-C tunnels.

1149405

The image upgrade fails when performing a non-graceful update due to an ISIZE mismatch during verification.

FortiView

Bug ID

Description

1125124

When running more than 1 million concurrent HTTP sessions across the firewall, and trying to access session list on FortiView in the GUI, packet loss and loss of a session are observed.

GUI

Bug ID

Description

919473

Network > Interfaces: When an IPsec tunnel is bound to an interface, the "Interface Integrate" option for the interface fails.

1047963

High Node.js memory usage when building FortiManager in Report Runner fails. Occurs when FortiManager has a slow connection, is unreachable from the FortiGate (because FMG is behind NAT), or the IP is incorrect.

1054026

Offline license file cannot be uploaded to FGT by GUI.

1055197

On FortiGate G series with dual WAN links, Interface bandwidth widget may show incorrect incoming and outgoing bandwidth count, where the actual traffic does not match the display numbers.

1055354

Inappropriate Security Rating Insights items occur when registering to EMS and syncing tags.

1055865

NodeJS errors when event log socket is closed.

1092489

The config system fortiguard > fortiguard-anycast setting was changed to automatically disable when the FortiGuard page is shown on GUI.

1097405

Patch schedule minutes are ignored when set through the GUI for automatic upgrades.

1099309

The FortiOS GUI fails to load topology-related pages when temporary files generated during Security Rating operations are mistakenly read by the REST API.

1101932

IPsec monitor widget: IPsec phase2 tunnel details are not displayed in the tooltip when hovering over the phase2 selector.

1102404

VDOM search function does not work properly if VDOM has uppercase letters.

1104519

Interface faceplate appending occurs when switching between fabric devices.

1110382

Admin can log in to GUI (HTTPS) with password, even when admin-https-pki-required is enabled.

1110827

GUI shows LAN interfaces that have an IP address in the network ranges 172.31.0.0/16 or 192.168.0.0/16 to be managed by IPAM, even though the feature is globally disabled.

1111113

When launching the GUI console using Jet Stream theme, the character spacing appears wider than usual.

1111967

SD-WAN zone is not selectable as an interface in GUI for certain policies.

1112716

No log output when running debug flow on GUI.

1114658

Duplicated logs occur during Node.js health-check operations when internal communication between daemons is exposed through HTTP requests, as the traffic is captured in logs and packet captures.

1115684

System > FortiGuard: FortiCare elite contract is not displayed accurately under Licensing information.

1118810

Asset Identity Center: Tooltip on IoT/OT Vulnerabilities says OT license is inactive even with full license.

1128730

An error condition occurs during upgrade to FortiOS 7.6.3 B3485.

1133808

An error occurs when accessing FortiSandbox connector configuration via GUI.

HA

Bug ID

Description

982081

After changing the status to down on the ha1 and ha2 ports, setting the status back to up does not bring up the ports.

999440

Console prints error message when delete vdom in HA setup.

999440

Console prints error message when delete vdom in HA setup

1068674

PBA logs missing during HA failover.

1073514

In HA cluster, when a FortiToken is aggregated or revoked from a local.user, cluster is out of SYNC.

1085314, 1095879

Firewall policy page takes a long time to load on the HA Primary unit due to a loop condition between BGP and NSM when other protocols' same route is redistributed to BGP.

1086511

Firmware upgrade/downgrade is stuck at "Preparing for upload" with "*.js results in a network error" for FetchEvent when using Selenium auto test under Chrome Incognito window.

1087924

HA secondary unit experiences high CPU usage when frequent changes are made to CMDB on the HA primary unit.

1088956, 1101490

Duplicated logs occur in FAZ during sniffer mode operation in HA active-passive setups because both active and passive FortiGates forward L2 packets to the IPS engine, causing duplicate entries.

1091189

Switches observe MAC address flapping in HA A-A setups when both FortiGates use identical virtual MACs on their primary VLANs.

1091657

SDN connector limits the API traffic flow through root VDOM or HA management VDOM.

1095786

Traffic interruption occurs when performing a manual HA failback after an initial failover in VWP setups.

1098192

Joining a FortiGate with RAID enabled in an existing cluster causes the primary to shut down due to differing RAID statuses.

1099346

Connection issues occur when FortiGate secondary uses primary's certificate to connect to FMG instead of its own.

1100177

In an FGSP setup, on asymmetric TCP flow during SYN/ACK packet on the other member, the TCP MSS value is not adjusted according to the firewall policy.

1101456

In a HA setup, the aggregate interface status remains up after configuring 'status down' in FortiOS due to a race condition.

1101879

Multiple SCTP expectation sessions are created during resynchronization due to a flag allowing duplication.

1104892

Duplicate IP detected messages are seen from the Secondary Fortigate in a cluster.

1105422

"Detected Tx Unit Hang" error occurrs on the HA secondary, causing it to become out-of-sync.

1107137

The secondary FortiGate with an HA Reserved Management Interface cannot be accessed using HTTPS after upgrading from version 7.4.3.

1108895

In an FGSP cluster, enabling and disabling standalone-config-sync results in the local dev_base being deleted and synchronized with the peer, which leads to the absence of the dev_base.

1108895

In an FGSP cluster, enabling and disabling standalone-config-sync results in the local dev_base being deleted and synchronized with the peer, which leads to the absence of the dev_base.

1109919

Cluster experiences split-brain when EMAC interfaces are disabled within a zone.

1110498

Add IPv6 destination support under HA management interface configuration.

1112525

Admin socket creation error occurs when upgrading FortiOS in an HA A-P cluster.

1113842

New LACP interface is not shown under diagnose sys ha standalone-peers on both FGSP members.

1115190

The SNMP value of fgVWLHealthCheckLinkState on the secondary unit should always be set to dead(1).

1117725

HA synchronization fails due to checksum mismatches on CA certificates across all VDOMs when adding or modifying certificates sourced from a bundle.

1121117

When two HA clusters are on the same subnet, the L2 session-sync packets could be received by each other, even if they are from two different HA clusters.

1122341

Unexpected behavior occurs when ippool PBA index is out of range.

1129088

The sessionsync daemon experiences high CPU usage when syncing expectation sessions under heavy SCTP traffic and FGSP enablement due to inefficiencies in the dump API.

1135866

HA second unit cannot sync firewall ZTNA dynamic address with HA primary unit after primary disables EMS server.

1137565

vSN support added in 7.2.9, 7.4.6, and 7.6.1. FG-100F/101F do not yet support vSN and logical-sn.

1138763

IKE hasync loop and high memory consumption when peer address/port changes.

Hyperscale

Bug ID Description

1013892

Unexpected behavior observed in NPD when the threat feed object attempted to update manually in the HA pair.

1055443

Add ipv4/v6-session-quota back for software sessions in hyperscale VDOM.

1058477 sentb and rcvdb show -ve value for end session syslog message.

1074547

SNAT session drops occur when kernel sessions become dirty in hyperscale VDOM environments due to inconsistent NAT resource allocation between software and hardware sessions.

1091244 hypersale hw-session-sync-dev should print properly error message when set members over 8.
1091815 hw session doesn't sync when one of multiple interface hw-session-sync-dev is down.

1093287

Using fixed-allocation IP Pools may cause NP7 NSS/PRP modules to become stuck, potentially disrupting traffic. Other PBA IP pools do not have this issue.

1094162

The diag sys npu-session list-brief command now includes additional values for timeout, duration, and policy-id and an improved filter that includes EIF sessions to enhance its functionality and filtering capabilities.

1101562 hyperscale hw-session-sync-dev LAG members can exceed 2*number of NP.

1108263

HA configurations are lost if hw-sess-sync-dev is configured with more interfaces than expected. (The expectation is two times the number of NP7 chips.)

1114113

The get sys ha status command does not offer detailed interface statistics for hardware session sync devices.

1115761

When handling very high traffic loads (150M 250M concurrent sessions), the system sometimes fails to free up memory, even after all sessions have been cleared and traffic has stopped.

1119021 Sessionsync daemon makes hw-session-sync dev up even it's physically down, no such issue with sw session sync dev.
1119031 HW sessions are not synced to slave when one of the hw-session-sync-dev members is down.

1121524

Client could not get DHCP IP address with policy-offload-level set to full-offload.

1128155 FGT-1801F log-transport TCP should be hidden for log servers under L2host and Netflow on CLI.
1135433 IPv6 entries appear in the output of pba list after reaching max PBA limit for ippool.
1138823 FGT-1801F non-hyperscale VDOM shows incorrect output of "diag firewall ippool get-pub/priv" commands.
1140493 Config should be blocked when user tries to set same interface as hw-session-sync-dev andmonitor.

Intrusion Prevention

Bug ID

Description

1040783

FortiGate encounters CPU usage issue due to IPSEngine utilization when using an app-ctrl utm profile.

1074732

Traffic is dropped silently when IPv6 traffic is sent with UTM and nTurbo enabled on FortiGate-121G.

1090616

IPS does not pass channel ID/category ID from the first video in a YouTube playlist to WAD.

1093788

Sniffer logs are not generated when using VLANs.

1101633

Child process that loads IPS database does not have CMDB permission to write to IPS table.

1113473

When IPS generates traffic log for tunnel traffic, traffic log should include outer packet details.

1121953

IPSengine processes consume memory and can lead to the conserve mode.

IPsec VPN

Bug ID

Description

1002325

When spoke re-authauthorization is enabled, shortcut tunnel rekey fails and goes down when SA expires. Shortcut tunnel flaps while it re-establishes again.

1042465

Packet drops occur when FortiOS CPUs are overwhelmed by high traffic bursts while IPsec acceleration is enabled, leading to CP queue overflows despite prior optimizations.

1049015

IPsec performance issue on Intel-based platforms occurs due to FortiOS not enabling all available IPsec drivers.

1051144 IPsec dialup VPN connection issues occur when TCP port 4500 is blocked.

1054440

Incrementing TX and RX errors on VPN interface occur when NPU offload is disabled, busy CPU cores, or high burst traffic cause packet drops due to full queues on SoC3/Soc4 platforms.

1057558

Dialup and loopback-asymroute disable with multiple paths for IKE/IPsec traffic are configured. When the incoming ESP traffic changes path because of a routing change, reply traffic still egresses on the old interface, and traffic is dropped.

1059778

IPsec does not work as expected when the traffic path is from spoke dial-up to hub1, and then from hub1 to another site through a site-to-site tunnel.

1060048

Throughput is limited in Site to Site VPN connections between the FW1kF and the FWVM Google Cloud platform.

1064078

Egress shaper fails to enforce bandwidth limits on VPN ID with IPIP encapsulation IPsec interfaces due to incorrect handling of traffic forwarding across multiple network processing units.

1071769

L2TP/IPsec connections fail due to interface changes from break-before-make rekeys and Windows rejecting selectors during FGT-initiated QM rekeys.

1073670

Unexpected behavior observed in the IKED during HA split-brain events when IPsec tunnels are configured to use DHCP.

1087651

Authentication fails when using FortiClient with IPsec IKEv2 after waiting more than 60 seconds to enter the 2FA token, caused by a fixed 60-second RADIUS timeout.

1090200

transport-mode IPsec phase2 cannot set non-zero protocol successfully.

1090200

IPsec phase2 interface with encapsulation set to transport-mode cannot successfully set non-zero protocol.

1094028

Unexpected behavior observed in the IKED after configuration changes when the phase1 monitor feature is used.

1102528

NP7 tunnel offloading failure recovery issue may cause use-after-free memory corruption when there are many concurrent IPSec tunnels, which leads to high CPU usage and kernel panic.

1102584

Kernel crash caused by memory corruption due to a use-after-free issue, resulting in a system hang. This issue occurs with a large number of IPsec tunnels.

1103594

ADVPN IPsec traffic over shortcuts drops during IPsec tunnel rekey.

1103754

Failed HTTP sessions occur when passing through nTurbo due to improper handling of fragmented packets.

1107198

Transparent mode, policy-based IPsec VPN, local-out traffic automatically enters VPN.

1109028

With set peertype one, the FortiGate will not accept ID_IPV4_Address as peer ID for dynamic IPsec IKEv2.

1109627

IPsec VPN match-security-posture-tag feature won't work when FortiClient is behind NAT.

1110093

IPsec SA offloading stops on some FortiGate models when handling more than 50,000 concurrent secure associations.

1112665

Static routes are marked inactive when an old IPSec tunnel is deleted during an INITIAL-CONTACT message in IKEv1, mistakenly deactivating the new tunnel's status in the kernel.

1113354

Group list is truncated because of fixed-size buffers.

1116825

Juniper device unable to establish IKEv1 tunnel with FGT.

1117758

FGT fails to negotiate encryption algorithm CHACHA20_POLY1305 against third- party client.

1117910

iked spikes to 99.9% if client sends FIN after ike tcp session is established.

1120003

FortiGate presents certificate information when accessed using IPsec VPN listening interface.

1120517 IPsec tunnel failure occurs when using aggressive mode with PSK authentication.

1125487

Gateway switching fails during IKE session resumption when moving from a FortiGate model without Azure AD auto-connect enabled to one with it due to missing mode communication.

1127444

For ADVPN 2.0 shortcut negotiation, UDP hole punching for spoke behind NAT uses source port 500 instead of 4500.

1127782

Traffic is dropped by anti-spoof check when passing traffic through phase2 transport mode with GRE encap.

1134841 IPv6 split tunnel option issue occurs when configuring remote access tunnel through VPN Wizard or Tunnel dialog.
1135445 An error condition in SSL VPN occurs when upgrading to FortiOS from v7.4.7 to v7.6.2.
1136309 IKE negotiation failure occurs when iked is restarted with signature authentication.

1136536

VPN authentication fails on FortiSASE when a large number of RADIUS groups are configured.

1138631 Traffic distribution issues occur when configuring multiple IPsec tunnels between two FortiGates.

Log & Report

Bug ID

Description

864002

Unauthenticated User mismatch with User in logs.

1004103

Log & Report > Reports: When reports are renamed, the scheduled reports page does not load and the unable to fetch reports error notification is displayed.

1009584

FGT-VM64 has no crash log record and event logs for license status change from Valid to Warning.

1074460

Erroneous memory allocation results in intermittent HTTPSD disruption caused by a corrupted traffic log file.

1084934

Firewall logs show Object Object in GUI and dstintf="unknown-0" in raw logs.

1087534

Page loading issues occur when loading a high number of logs.

1091064

Missing poluuid and policyname fields occur in Forward Traffic logs when HA failover happens in FGCP clusters.

1100883

Forward Traffic log fetched from FortiGate Cloud takes a long time to load on GUI.

1107571

Some WiFi Log descriptions are inaccurate.

1116428

Observed Device vulnerability lookup on FortiGuard in high frequency under the system event log.

1118089

Temporary log files persist in /var/log after successful FTP uploads, leading to increased disk usage.

1119147

Secondary device fails to generate reports at the set time.

1121505

Log & report > Forward Traffic: The Security tab for security event logs does not load.

1122938

Syslog traffic uses the correct exit interface after a change in source interface but fails to update the source IP.

1129448

The body is partially missing from emails sent by alert mail.

1130821

Incomplete log entries occur when attack context logging is enabled for attacks involving long user-agent strings.

Proxy

Bug ID

Description

958200

Packets captured by IPS indicates HTTP/1.1 in case of HTTP/2 request.

988473

On FortiGate 61E and 81E models, a daemon WAD issue causes high memory usage.

1014014

Proxyd always selects the first certificate in the list when multiple server certificates are configured, regardless of SNI.

1023054

After an upgrade on a 2GB FortiGate device, the firewall policy does not switch from Proxy-based to Flow-based in the Inspection mode field.

1051875

Strict SNI certificate checks skip IP destination validation under strict mode.

1054835

HTTP/2 large file transfers are slow when IPS, APP, or SSL inspect-all is enabled due to excessive buffering during traffic forwarding.

1066113

Accessing certain websites through HTTPS fails when using inspect-all deep-inspection in proxy mode firewall policy.

1096728

An error case observed in the WAD, affecting some VIP traffic, caused by erroneous memory allocation.

1107205

FortiGate encounters a WAD memory usage issue when using a secure explicit web proxy with WAD user authentication to visit some websites.

1116771

Add a limit on the memory used by user-device-store as a percentage of the total system memory

1120964

An error condition in WAD occurs during shutdown after factory-reset on 32-bit ARM platforms.

1121171

Large file downloads through proxy HTTP2 are slow when IPS/APP/SSL inspect-all enabled.

1126253

When VDOM configuration file is restored, it changes the no-inspection profile under ssl-ssh-profile to deep-inspection.

1126385

WAD fails to handle deep-inspection traffic under FIPS mode.

1245569

Empty response occurs when pageSize exceeds 105 in FortiGate HTTPS Virtual Server

REST API

Bug ID

Description

943756

When creating a VPN remote certificate with the API, the "remote" key fails to be set, resulting in incomplete configuration.

1019750

The available interfaces list is slow in configurations with many IPsec tunnel connections.

1026547 Sensor information through REST API on a FG-81F returns 404 error.
1071799 Failed to rename switch-controller managed-switch entries through the CMDB REST API.

1077192

External Account Binding support occurs when using ACME RFC8555.

1107698

Adding ipv6-trusthost under api-user will override ipv4-trusthost setting and allow all IPv4 source IP addresses.

1110811

HTTPSD crash due to a memory leak in the libjson-c library when the monitor/virtual-wan/health-check API returns an error and response is not free correctly.

Routing

Bug ID

Description

897308

The system fib version does not match VDOM fib version in 1801F when queried due to a misalignment in how genid is reported by the Linux kernel to user space.

1008434

The speed-test result files are not deleted after test runs. The new test ID may collide with a previous result. In this case, the GUI may read a previously failed result and report errors.

1058283

Routing monitor: The Routing widget becomes unresponsive when using route lookup on a configuration that has a large number of routes.

1058700

The load-balance mode in SD-WAN rules only considers up to 8 paths as active when more than 8 are configured.

1072311, 1075911

BGP flaps occur when high L2P TPE drops are detected under heavy IPsec traffic conditions.

1080449

IPv6 prefix delegation does not add IPv6 route automatically.

1082842

The loopback interface does not appear as an outgoing option for BGP peer connections when configuring through the GUI.

1084851

When adding new static route and prefix-list using CLI, 0.0.0.0/0 takes effect, in spite of invalid format of dst and prefix.

1084907

Inactive IPv6 routes occur when dual stack BFD is configured without assigning the correct interface for IPv6, causing it to default to an IPv4 interface instead.

1086944

The BGP router-id fails to reset after editing the neighbor group settings because the dialog doesn't properly handle the reset functionality.

1093215

Users can create a BGP neighbor without configuring remote-as using CLI, and after completing BGP neighbor configuration, neighbor will remain in admin down state.

1095307

Network > SD-WAN > SD-WAN Rules: Filtering on members with alias names does not display matching results.

1099554

FortiGate uses link-local IPv6 address as nexthop in VLAN network, instead of global address.

1100529

BGP Stale route not working as expected.

1103034

Application "cmdbsvr" crashes when processing a configuration from OaaS controller. This issue occurs when adding another ISP to the test spokes and applying the change.

1103212

Network > Routing Objects: BGP AS number with asdot/asdot+ format will drop the trailing 0s on "set set-aspath" router-map config.

1105064

IPv6 traffic can't match the correct firewall policy in certain SD-WAN cases.

1106035

CPU usage issues observed during auto BMRK operations.

1108192

Restore image from FTP server failed using SD-WAN.

1108874

SD-WAN Default_DNS performance SLA shows all participants of Default_DNS are down.

1109286

Incorrect priorities are applied during remote health-checks when iked restarts because lnkmtd retains stale tunnel cache entries.

1111233

auto-asic-offload disabled under vne-interface after upgrading from 7.4.6 to 7.6.1.

1113929

Incorrect SDWAN rule is matched. fib-best-match is configured under zone.

1114687

The snmpd cache update takes longer when querying SD-WAN health-check data due to delays in retrieving bandwidth statistics.

1116924

In SD-WAN, when detect mode Prefer Passive is used, routing table is not updated in time

1118891

ADVPN shortcut is established between different transport-groups.

1119119

Inadvertent behavior observed in BGPD due to erroneous memory freeing when applying route-maps.

1122021

FortiGate disregards SD-WAN members for path selection even when they are in SLA.

1128032

Traffic fails with Fabric Overlay Orchestrator using automatic policy creation with system zones.

1129698

When FortiAnalyzer setting interface-select-method is sdwan, FortiAnalyzer connection is closed and restarted, even though SD-WAN interface doesn't change.

1133796

IPv6 routes are stuck on kernel routing table.

1134485

Failed to sniffer the VNE tunnel interface.

1134763

Session marked dirty by mistake when unrelated route changes in different VRF.

1138483

The link-monitor daemon truncates hostnames exceeding 63 characters when used in SDWAN health-check configurations, causing DNS resolution failures and impacting service availability.

1145668

FortiGate encounters PIMD daemon issue, which hinders multicast traffic.

SD-WAN

Bug ID

Description

1094449

Traffic routing issues occur when service-sla-tie-break is set to fib-best-match.

1110156 Speedtest failure occurs when using PPPoE mode on a physical interface without a valid IP.
1115208 Probe-timeout value is reset to 60000 when detect-mode is remote.

1116619

An error condition in vwl occurs when changing IPsec phase1-interface settings

1118705

Speed test failure occurs when using BGP over loopback design

1127506

ADVPN shortcut establishment issues occur when responder replies are delayed due to heavy load.

1139728

Link-monitor issues occur when a large number of ADVPN shortcuts are established.

1139734

High latency occurs when a large number of established and monitored shortcuts are present on the FortiGate.

Security Fabric

Bug ID

Description

903922

Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation.

1006397

In case of failure during a federated upgrade process, the system does not report granular failure details for individual devices.

1011833

FortiGate experiences a CPU usage issue in the Node.js daemon when there multiple administrator sessions running simultaneously.

1019844

In an HA configuration, when the primary FortiGate unit fails over to a downstream unit, the previous primary unit displays as being permanently disconnected.

1021684

In some cases, the Security Fabric topology cannot load properly and displays a Failed to load Topology Results error.

1090401

Error messages from netxd API calls are not displayed when running as a daemon because they are printed to stderr instead of the CLI.

1098787

Azure SDN Connector failure occurs when service tags API returns empty results with Resource Group scope permissions.

1099235

Scheduled triggers do not include eventtime in log entries, causing automation scripts using %%log.eventtime%% to fail and generate filenames with missing or incorrect timestamps.

1101806

Failed to trigger Security Rating Summary event automation stitch due to issue with log field ID.

1111619

The replacemsg-group in automation-action gets unset when system reboots.

1113463

FortiGate Azure connector fails to retrieve AKS information on AKS 1.29.5.

1119616

Externally maintained threat feed contains both resource FQDNs and IP address ranges/subnets. Entry such as <addr>/0x1 then matches half of all possible IPv4 address and causes network disruption.

1120652

Fabric topology with two devices on different VDOMs but behind the same router shows wrong VDOM data on tooltip.

1134970

Inconsistent DNS TTL behavior in Kubernetes API through SDN-Connector.

Switch Controller

Bug ID

Description

1015992

WiFi & Switch Controller > FortiLink Interface: When a FortiLink interface is down and the Lockdown ISL toggle is set to 'disable' on the GUI, the setting is not retained.

1016034

In an HA environment with FortiSwitches connected, the lockdown ISL setting on FortiLink gets enabled during HA failover.

1087254

Device fails to get IP address when moved between NAC ports on the same switch.

1108965

Sync errors occur when incomplete transaction flags related to dhcp-snooping-static-client replay past configuration changes during sync attempts.

1113465

VLAN configurations intermittently fail to assign on FSW ports when devices matching DPP policy come online, which is caused by a race condition during FSW initialization.

1124356

DPP mac classification issue occurs when DPP policy with vlan-policy and 802.1x is configured together.

1130242

Only the last SNMP community configuration is pushed from FGT to FSW during bulk processing.

1138333

Increase efficiency of FortiLink configuration daemon memory usage.

System

Bug ID

Description

814119

drop-overlapped-fragment {enable | disable} does not work on NP7 platforms.

898182 High CPU usage occurs when FortiGate is attacked by 4K PPS ARP requests.

932077

Connection issue between SOC4 platform and third-party switches, for example Hirschmann GRS 105 or Cisco switch, since SOC4 doesn't support certain carrier extension signals.

976722

Invalid YAML files are generated when exporting configurations containing multi-value attributes or long strings with newline characters.

992323, 1056133, 1075607, 1082413, 1084898

Traffic interrupt when traffic shaping is enabled on 9xG and 12xG

1017941

GUI interface bandwidth shows Tetrabyte spike for Gigabyte interface.

Affected platforms: FGT-220xE and FGT-330xE

1021838 Memory usage issues caused by updated daemon redesign in forticldd.

1030529

Password change occurs when admin's password is unset after burn image

1039980 Unexpected behavior in system occurs when out of memory during emergency restart.

1040137

NPD skips config parsing when policy-offload-level set to disable.

1040489

Traffic using VXLAN VTEP with a loopback over an IPsec VPN is dropped when VXLAN and IPsec are configured in different VDOMs due to incorrect tunnel creation success indicators.

1044472 Traffic drop occurs when VXLAN is a member of software switch in implicit mode.

1046484

After shutting down a SOC4 FortiGate (FGT-40F/FGT-61F/FGT-81F/FGT-100F) using the "execute shutdown" command, the system automatically boots up again.

1067448

VLAN switch is not working on 120G/121G.

1068756

After updating to the latest unsigned version of an object, update daemon will not download a new signed version of that object if the versions are the same.

1069208

If the DHCP offer contains padding when DHCP relay is used, the DHCP relay deletes the padding before relaying the packet.

1075279

Member interfaces of VWP appear in packet capture creation dialog despite being ineligible.

1076795 Private data encryption key generation issues caused by manual entry of 32-digit hexadecimal keys.

1076883

When the top application bandwidth feature is disabled, the GUI process still performs the initial check for application bandwidth, which may cause FortiCron to experience high CPU usage.

1077562

Hardware egress shaping doesn't work on SOC5 when NPU offload is enabled.

1078119

Traffic is intermittently interrupted on virtual-vlan-switch on Soc5 based platforms when a multicast or broadcast packet is received.

1078568

When FortiManager adds FortiGate via serial number and is behind NAT, FortiGate cannot initiate requests to FortiManager, causing the GUI to fail in retrieving the certificate CN/SAN and resulting in an error.

1079850

HA1/HA2 ports remain down after setting status to up. Rebooting fixes the issue.

1085407

FortiGate unresponsive when default-qos-type is set to shaping.

1086268

VXLAN interface cannot be created if its underlying interface is DHCP.

1087160

NP drops traffic when VXLAN is a member of software switch in implicit mode.

1087270

Unexpected traffic increase over the FortiGate 6000 base backplane.

1089143

The time change in FOS is restored after reboot. The RTC node is not created correctly so the time change can't be kept in RTC.

1089272

The inability to view or click the "+" sign occurs when a user is assigned an admin profile with only read access, restricting actions that require write privileges.

1090372

Access profile entries exceed global limit when built-in profiles consume table size slots.

1091175

VLAN statistics on LAGs are not displayed correctly when asic-offload is enabled due to incorrect OID usage.

1091551

Hardware limitation on the NP7 platform causes the following QTM related issues:

  • Incorrect checksum for fragments after QTM.

  • Packets longer than 6000 bytes cause QTM unresponsiveness.

  • Refresh issue causes QTM unresponsiveness.

  • MTU is not honored after QTM, so packets are not fragmented.

1094404

State of peer ports of FGT ports(negotiated speed, 1G) is down after upgrade on specific FGT

1095834

When FortiGate is managed by FortiManager, which has a slow connection or is unreachable, memory consumption of node process keeps increasing.

1096409

EXPIRE dates cannot be displayed properly when displaying the output of get sys fortiguard-service status.

1096878

DNS cache flushing occurs too frequently due to unnecessary interface-reload events triggered by DHCP6 packets and SLAAC updates.

1099770

NP7 drops encrypted GRE packets that have checksum bit set (1) due to invalid checksum.

1101392

Administrators can execute the command diagnose sys ha reset-uptime when the permissions of Admin Profile is set to Read.

1101647

FortiGate encounters a CPU usage issue for cmdbsvr process

1102416

Cannot push config sfp-dsl enable and vectoring under interface.

1102919

GTP tunnels are deleted even if there are still associated requests.

The problem occurred when multiple Create Session Request from different source IPs create the same GTP tunnel, and the first Create Session Response with an authentication failed cause leads to the deletion of the half-open tunnel and all associated requests.

1103146

Duplicated RADIUS packets are captured by the sniffer when performing firewall authentication with a RADIUS server.

1103966

FG901G gen1/2 boxes "diag hardw test asic" got FAILED

1104173

Kernel panic occurs when pushing 'Device Setting' from FortiManager to NP7 platforms with Broadcom switch, causing the device to become unresponsive and requiring a reboot.

1104410

The FortiGate-120G SFP ports fail to establish connectivity when configured with set speed 1000full due to improper auto-negotiation handling.

1104966

SNMP fgDiskCount.0 OID not returning disk count value

1105989

System global configuration lost due to port collision.

1105995

The switch MTU doesn't set correctly on 100m speed.

1109633

When visiting the GUI login page, FortiGate prompts user for certificate when no PKI admin is set.

1110527

FortiGate did not update password-expire time on the start or end of daylight savings time.

1111601

Fortiguard sends IP addresses to proxy instead of FQDNs

1112376

Unexpected behavior observed in the newcli daemon due to inconsistencies in node registration between cmdbsvr and other daemons.

1113720

Packets not forwarded due to improper handling of specific flags in the bridging code, which incorrectly treats them as local instead of resolving their destination MAC address and forwarding.

1114873 CPU usage issues observed during cmdbsrv process execution after reboot.

1115486

Virtual switch interface drops LLDP packets.

1116220

FortiGate 3601E 25Gauto link not coming up using DAC cables.

1116922

FortiGate encounters a memory usage issue if too many ports have LLDP reception enabled.

1117435

Add SNMP new OIDs fgAdminLoggedInTable for get sys admin list.

1117527

VXLAN interface should be brought down when underlay interface is down.

1119595

URLfilter fails to track DNS TTLs and update the IPs of FQDN addresses after they have been changed.

1120467

No SNMP trap at power failure for DC PSU.

1120907

High traffic load on a particular interface causes packet loss on other interfaces of the FortiGate.

1122306

Typo in log-controller-update request.

1123149

Unexpected behavior occurs in FEXT201E when cfg-revert is triggered

1123727

Incorrect traffic class (TC) settings and shaper class ID handling cause improper Quality of Service (QoS) application and session offloading failures for VLANs configured over Link Aggregation Groups (LAG) and hardware switches on FortiOS devices using SOC5 hardware.

1124024

When set append-index disable in system.snmp.sysinfo, querying per-VDOM BGPPeerTable might get incorrect results because of no updates.

1125301

FortiGate encounters parsing errors and potential system halts when configuration strings contain un-escaped single quotation marks, especially in password fields.

1125947

FortiGate encounters a memory usage issue due to usage by HTTSD

1126100

Expired user passwords are stored as plaintext in configuration files when password history is enabled.

1126327

The SNMP query for fgSwPortSwitchSerialNum gives switch name as the output instead of SN.

1127534

Update built-in CRDB bundle to version 1.56.

1127700

Packets are dropped during VLAN over VXLAN traffic due to incorrect handling of VLAN tags and session keys.

1128087

In new version of RDP client, FortiGate drops some RDP sessions due to IPv6 extended headers.

1133159

Inbandwidth settings are not enforced for traffic with multiple class IDs in a FortiOS shaping profile, resulting in reduced available bandwidth beyond 12 classes.

1133842

Packet dropped with 'DCE_IVS_IGR_DIR_DROP' over hardware switch.

1140422

SNMP query failure occurs when rpc aggregation is enabled for slave blades on FortiGate 6000F.

1140696 An error condition in Forticron occurs when log-single-cpu-high is enabled.

1142013

Policing improvement for QTM by limiting buffer size or switching to TPE (shaping-profile mode of config).

1144091

An error condition in dhcprd occurs when handling IPsec messages.

Upgrade

Bug ID

Description

1043815

Upgrading the firmware for a large number (100+) of FortiSwitch or FortiAP devices at the same time may cause performance issues with the GUI and some devices may not upgrade.

1097503

Fabric upgrade from 7.2.9 to 7.4.5 failed.

1102990

SLBC FortiGate 5001E primary blade failed to install image, even though graceful-upgrade was disabled.

1104649

In 7.6.1 and 7.6.2, if a local-in policy, local-in-policy6, DoS policy, interface policy, multicast policy, TTL policy, or central SNAT map is used in an interface in version 7.4.5, 7.6.0, or any previous GA version that was part of the SD-WAN zone, these policies will be deleted or show empty values after upgrading to version 7.6.1 or 7.6.2.

See Policies that use an interface show missing or empty values after an upgrade for more information.

1105771

Upgrade from 7.4.6 GA to 7.6.1 GA results in an incomplete WAD device memory list table and triggers WAD error.

1106072

The image file transfer between FortiManager and FortiGate may not work as expected when transferred by the FGFM tunnel.

1110809

Egress-shaping-profile setting lost on interface after upgrade.

1114232

When upgrading FortiGate from earlier than 7.4.1 to 7.4.1 or later, system.replacemsg.webproxy configuration is lost.

1123954

FortiGuard updates are automatically enabled during upgrades from versions where they were previously disabled, bypassing user acknowledgment.

1130861

FG-4401F enters a reboot loop after upgrading from 7.2.9 GA to 7.4.6 GA with a large config file (more than 10K policies).

User & Authentication

Bug ID

Description

1017348

Memory usage by fsso_ldap daemon increases continuously when the LDAP server responds with "LDAP_UNWILLING_TO_PERFORM" due to an unhandled memory allocation issue.

1020808

Use new keys for certificate renewal through EST server.

1025260

Wildcard admin remote authorization password change in system GUI does not work.

1043189

Low-end FortiGate models with 2GB memory can enter conserve mode when processing large amounts (over 5000 user records) of stored user store data, when each record has a large amount of IoT vulnerability data. For example, the Users and Devices page or FortiNAC request can trigger the following API call that causes httpsd process to spike in CPU and memory:

GET request /api/v2/monitor/user/device/query

1054818

Password encryption changes occur when editing config vpn certificate local without actual certificate changes.

1075207

Errors may occur in the FNBAMD due to the presence of two wildcard-enabled remote administrators in separate VDOMs.

1077636

No SNMP trap available to detect FSSO external connected status change.

1091483

When importing local certificate, GUI displays an error, even when certificate is correctly imported.

1093538

In SAML config, after enabling "AD FS claim" (Active Directory Federated Services and rebooting, the "Attribute used to identify users" and "Attribute used to identify groups" fields are blank.

1093542

FortiGate admin user authentication with token+RADIUS fails when wildcard user is configured.

1093654

FGT uses global DNS when attempting to provision a certificate through SCEP or EST.

1099831

An error condition in fnbamd occurs during stress testing with certificate parsing.

1105305

Guest users are not removed after their configured expiry time on certain FortiGate models.

1119143

Unable to view local certificate in GUI or CLI after certificate import.

1121503

Source-ip setting issue occurs when configuring scep enroll settings per VDOM in non-management VDOM.

1121987

Firewall user widget: Tooltip for FSSO users on the 'user group' column displays overlapping text.

This is cosmetic and does not affect functionality.

1136244

RSSO not working on 7.6.x with Cisco Meraki MX.

VM

Bug ID

Description

999842

Azure fails to honor seamless live migration.

In most cases, the public IP to private IP NAT fails to forward traffic from/to SD-WAN.

1012000

When unicast HA setup has a large number of interfaces, FGT Hyper-V takes a long time to boot up.

1094600

The virtual-wire pair fails to create during FortiOS initialization on cloud platforms when the underlying interface uses DHCP and hasn't acquired an IP address yet, preventing VXLAN configuration from completing successfully.

1101264

HA failover actions are triggered even when the Azure SDN connector is in a "disabled" state, causing increased downtime during failover.

1102434

Configuring VRF on hbdev causes FGT VM HA not to sync.

1107007

samld stops working when certificate set to Fortinet_Factory in user SAML.

1107933

The FortiGate device uses a single CPU core for GRE decapsulation tasks when running on AWS with ena NIC drivers because L4 hash functionality is not enabled, preventing RPS from distributing traffic efficiently.

1107962

Dynamic addresses are removed/added every few seconds when the OCI SDN connector fetches only the first page of API results.

1109724

Azd daemon on Azure NVA keeps consuming memory until FortiGate enters conserve mode.

1113362

FGT-VM64-AZURE cannot establish connection with other FGTs in the Security Fabric tree.

1121521

Azure SDN connector does not properly catch AKS cluster state.

1121974

Due to continuous disk logging, slab memory for dentry continuously increases in FortiGate VM.

1128351

Configuration fails to fully apply during bootstrap when the reboot function does not trigger an immediate reboot, causing cloudinit to re-run with insufficient tablespace.

1128988

License validation issues occur when connecting to FDS via a web proxy.

1143866

License status warning occurs when FortiGate-VM64 is upgraded

Web Filter

Bug ID

Description

874516, 1100819

SMB traffic fails when the file server uses AES-256-GCM/CCM encryption with FortiOS.

906603

Security Profiles > Webfilter: When a new webfilter is created and the action on the FortiGuard category-based filter is set to 'allow' and saved, the action is saved as 'monitor' on commit.

1099818

Output of diagnose webfilter fortiguard cache dump command shows the message "Cache is not enabled".

1107456

FG-120G webfilter.profile tablesize is incorrect.

1110668

Add an option to control webfilter.urlfilter simple-type entries match subdomains.

1110850

The value for x-forwarded-for is not properly displayed in the log on AWS environment.

1118132, 1122036, 1127984

Webfilter local category override not working after reboot in flow mode.

WiFi Controller

Bug ID

Description

823387

Email addresses collected through captive portal fail to display under WiFi clients when using guest SSID configurations.

921080

The FortiGate Hostapd does not support IPv6 address of RADIUS server.

987030

Unexpected behavior observed in the CAPWAP daemon when managing multiple APs and clients through dynamic VAP changes.

1013892

On FortiGate's in an HA pair, the npd process do not work as expected when trying to manually update the threat feed.

1030197

Client traffic is blocked after a failure when connecting through SSID using radius-mac-auth and radius-mac-auth-usergroup because the secondary FortiGate in HA does not receive necessary client details during failover.

1039985

Erroneous memory allocation observed in the CAPWAP function on NP6 and NP6XLite platforms due to a rare error case.

1080094

High memory usage may occur due to offline station entries not being automatically cleaned up over time.

1083395

In an HA environment with FortiAPs managed by primary FortiGate, the secondary FortiGate GUI Managed FortiAP page may show the FortiAP status as offline if the FortiAP traffic is not routed through the secondary FortiGate.

This is only a GUI issue and does not impact FortiAP operation.

1086128

An error condition in CAPWAP occurred due to a rare case.

1089999

FAPs remain offline post-upgrade when using image stored on FortiGate.

1094415

VLAN pooling assigns incorrect VLAN IDs when FortiOS is upgraded, causing clients on AP groups to receive IPs from the optional VLAN instead of the pool.

1096961

The "AP image receive success" log (id 43618) does not generate when upgrading FAP from FMG.

1098727

Enable 5GHz channels 52-64, 108, 116-128 for FAP-231G-P, 431G-P Uzbekistan. (Uzbekistan has no DFS certification process.)

1100220

COA disconnect is not functional for MPSK profiles when using external FortiGuest.

1101583

FortiAP go offline when the cw_acd process becomes stuck at 99% CPU usage. This issue is caused by the FortiAP sending corrupt data in certain scenarios, leading to the process hanging.

1102808

When the configuration contains a large number of vlan-pool entries, deleting or adding a few entries can cause the cw_acd crash.

1108726

FortiAPs periodically lose connectivity with FortiGate (acting as WLC) due to an error case.

1114144

WSSO firewall authentication sessions fail to establish when FortiGate processes multiple group attributes with the initial group missing.

1114311

Packets are incorrectly routed when FAP management interface uses clear-text dtls-policy in a software switch with explicit intra-switch-policy.

1123829

Support legal firewall policy when SD-WAN/zone member interface manages FAP with dtls-policy set to ipsec-vpn.

1128272

Management connection fails for FAP-231F when using PPPoE interface on FGT-120G.

1130750

WiFi & Switch controller > Managed FortiAPs: When a channel override on a 5GHz channel is enabled is edited on a managed AP, the channel selection is unset.

1133829

The FAP remains offline after the FortiGate reboots or wireless-controller restart-acd due to the controller sending an empty country string to the access point.

1139749

FortiGate does not honor source IP for MPSK RADIUS requests.

ZTNA

Bug ID

Description

1101022

FortiClient gets a blank page when doing SAML authentication due to the use of a stale user node.

1107986

Should be unable to select geography object in ZTNA proxy-policy.

1111112

Unable to configure more than eight mapped ports for access proxy realservers when the limit is 16.

1114976

ZTNA policy matching failed due to an accidental deletion of firewall.policy with ZTNA tags when the firewall.policy is updated.

1115153

Authentication loops occur during ZTNA connections requiring SAML when FortiClient uses multiple sessions with inconsistent cookies.

1118540

Browser timeout occurs when accessing ZTNA web bookmark with IP address.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

1085628

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-24471

1103790

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-25248

1108301

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-22254

1137151

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-53744

Resolved issues

Resolved issues

The following issues have been fixed in version 7.6.3. To inquire about a particular bug, please contact Customer Service & Support.

Agentless VPN (formerly SSL VPN web mode)

See also SSL VPN tunnel mode replaced with IPsec VPN.

Bug ID

Description

947536

SSLVPN crashes on corporate FortiGate due to watchdog timeout when a single connection enters an infinite loop of read iterations and the worker process becomes unresponsive to new connections.

1017304

SSL VPN web mode missing several security headers in the HTTP response.

1036557, 1091173

Performance degradation occurs in SSL-VPN due to connection/session timeout management issues.

1058211

Traffic could not go though SSL VPN tunnel when DTLS is enabled with a loopback interface as source address.

1077157

FortiGate sends out expired server certificate for a given SSL VPN realm, even when the certificate configured in virtual-host-server-cert has been updated.

1083262

FNBAMD session hangs after a massive authorization request.

1093580

SSL VPN authentication is triggered even with EMS SN check enabled.

1099492

Permission error occurs when local user enters new password that does not comply with password policy.

1101837

Insufficient session expiration in SSL VPN using SAML authentication.

1102362

SSL VPN web mode missing HTTP response headers.

1102515

Login failure occurs when 'warn days' are enabled in password policy for SSL VPN tunnel mode.

1107663

FortiClient 7.2.6 GA Azure auto login cannot connect after upgrade.

1111135

Log additional debug information to aid troubleshooting.

1115510

SAML metadata fails to generate when haproxy binds to the reserved SSL VPN source port 8900, preventing SAML authentication.

1124359

Error condition in sslvpnd occurs when generating a local signal handler within a chroot jail

1126825

SSL VPN stops functioning when ssl.root interface is added to a zone used by at least one policy.

Anti Virus

Bug ID

Description

1054835

Large file downloads take longer than expected due to a WAD process issue.

1100819

SMB traffic fails when the file server uses AES-256-GCM/CCM encryption with FortiOS.

1104189

In TP VDOM, the WAD creates the expectation session for FTP data connection if the firewall is in the proxy mode. This session does not have the outdev info.

1111973

Security Profiles > Antivirus: Creating a new antivirus profile on 2G models displays error notification Cannot read properties of undefined (reading 'entries') and fails.

1115628

Slowness and inaccessible internal resources when Antivirus profile is enabled in proxy mode.

Application Control

Bug ID

Description

1064413

Traffic fails to follow SD-WAN rules when SNAT is enabled and "snat-route-change" is activated due to session drops caused by SNAT check failures after route changes.

1102636

After the first DB update, only signatures in the built-in DB are loaded, preventing new categories and updated signatures from appearing correctly.

DNS Filter

Bug ID

Description

1025233

Support Encrypted Client Hello (ECH) in flow mode.

1080773

License expiration issue occurs when FortiGate has a valid FURL contract and connects to the StateRAMP SDNS server.

1096380

FortiGate in proxy mode sends the cached DNS response when it receives a DNS registration request.

1100282

When using FortiGate DNS servers, some clients cannot handle large UDP DNS responses exceeding 512B received from the FortiGate.

Endpoint Control

Bug ID

Description

1066250

Verification of EMS and upgrade of FGT with verified EMS should promote CA to fabric-ca.

1090981

Non-web ZTNA application configurations fail to sync with EMS after initial setup when FortiGate is connected to multiple EMS connectors.

1093786

Expired 'FCEM' contracts are loaded in FGVM when multiple account-level licenses exist under the same tag due to selection based on entry order rather than expiration date.

1098350

Sometimes the GUI >Asset FortiClient cannot display ems-tag for VPN user which make "Matched Endpoints" page missed those user.

Explicit Proxy

Bug ID

Description

924740

Verbose wad diag filter on source IP occurs when filtering with src/src6 filter.

1103272

SSL certificates are misapplied when FortiGate processes requests with deny actions in proxy policies.

1107762

Overflow occurs in WAD daemon when oversize-limit exceeds 4096 MiB during byte conversion.

1114438

Policy Test feature fails to function correctly when testing HTTP(S) server configurations due to missing source port initialization.

1115137

Expand the proxy-auth-timeout maximum value.

1116555

Deep scanning occurs when accessing subcategories of websites with category-based proxy policies despite disabling subcategory checks.

1134310

SSL exemption not working on proxy policy when partial match occurs.

Firewall

Bug ID

Description

723186

Policy & Objects > Multicast Policy: Mac type addresses are not listed in the Src/dst omniselect on the GUI.

946762

Policy & Objects > Firewall Policy: The column filter for Secondary security posture Tag does not filter matching results when multiple tags are present on a policy.

993138

Misleading logs with subtype="ztna" appear when only virtual-server in a firewall policy.

994986

The By Sequence view in the Firewall policy list may incorrectly show a duplicate implicit deny policy in the middle of the list. This is purely a GUI display issue and does not impact policy operation.

The Interface Pair View and Sequence Grouping View do not have this issue.

1025078, 1086315

Some customers observed memory usage increase and client session not disconnecting issues using virtual server

1025969

Policy enforcement fails for wildcard FQDN hosts as destination targets because the address records are not added to the wildcard entry when processing a server response for an FQDN's domain name.

1038650

Policy list refreshes entirely when right-clicking on hitcount or bytes columns to update statistics or clear counters.

1050906

Under heavy network traffic, the Netflow session cache for sampled traffic quickly reaches the hardcoded RAM limit, causing the sFlow daemon to shut down.

1055898

HTTP/2 post without content-length is not supported in half-ssl virtual server.

1066136

Denied sessions were bidirectional and caused all traffic to be blocked.

1078662

If an interface on an NP7 platform has the set inbandwidth XXX, set outbandwidth XXX, and set egress-shaping-profile XX settings, the following issues may occur:

  • Fragment packet checksum is incorrect.

  • MTU is not honored when sending packets out.

  • QTM hangs and blocks traffic when packet size is larger than 6000 bytes.

1081542

Packet drops occur when high traffic causes nTurbo buffers to be reused without proper initialization under CPU-intensive conditions with ASIC offloading enabled.

1088507

ICMP Echo replies sent through local-in-policy with virtual-patch enabled are routed through incorrect interfaces during traffic handling.

1097628

Firewall policy filter does not work well on source and destination columns for "all" and "ems" addresses.

1098208

After FortiGate exits conserve mode, some policies failed to install into the kernel at the same time.

1101865

Trailing stray characters appear in Netflow App Info reports, causing warnings in analysis programs.

1102471

Unexpected traffic hit policy in forward traffic log.

1103748, 111268

Threat feeds used as source or destination addresses in security policies may not match correctly.

1104208

NAT is incorrectly applied to traffic when a single SYN packet is sent to a VIP without an acknowledgment or reset.

1106112

Shared memory files on entry-level platforms can't be removed upon restart due to being stored in a persistent directory instead of a temporary one.

1107003

Policy & Objects: local-in policy, central-snat map, DoS Policy, and multicast policy have SD-WAN member in omniselect list of interface, and choosing the member interface results in an error.

Central-snat map, DoS Policy, and multicast policy do not list the SD-WAN zone in omniselect list of interfaces.

1108540

Search in the Address group dialog box using a partial word match takes more than a minute.

1108832

Traffic shaping statistic issues caused by QTM when using NP7.

1110135

Policy & Objects > Firewall Policy: Policy lookup for UDP protocol with FQDN does not work.

Workaround: Use the command line for policy lookup.

1111263

tcpsock command missing PID/process name for sessions in established state.

1116161

Traffic shaping statistics are not provided when using QTM on NP7.

1117165

Leaving the apn field empty in a GTP APN traffic shaping policy means that the policy will not match any traffic. Consequently, APN traffic shaping can only be applied to specific APNs.

To configure GTP APN traffic shaping:

config gtp apn-shaper
    edit <policy-id>
        set apn [<apn-name> <apngrp-name> ...]
        set rate-limit <limit>
        set action {drop | reject}
        set back-off-time <time>
    next
end

1120749

If session is in SYN_SENT or SYN_RECV state, and FortiGate receives a second SYN with different ISN, it will drop the second SYN.

1121944

A firewall policy allows traffic from client to server, but no policy exists for server to client. When traffic is not matched from server to client, a block session forms that blocks traffic in both directions.

1127977

Traffic fails to pass FortiGate when firewall policies are applied in TP VDOM due to flag checks treating packets as local instead of forwarding them.

1130932

An error condition occurs when disabling the outbound shaping-profile on the interface edit page.

1136058

Policies are deleted and replaced with "implicit" when exporting CSV from the Interface Pair View in Firewall Policy GUI.

1136163

The local-in-policy session TTL does not follow the service session-ttl.

1139282

VIP with set ldb-method http-host sends incorrect FQDN in ClientHello to second realserver when using HTTP2.

1139282

Incorrect SNI is sent during HTTP2/HTTP3 requests using "http-host" load balancing because WAD uses the proxy's SNI instead of the request's hostname.

FortiGate 6000 and 7000 platforms

Bug ID

Description

790464

After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond.

976521

High CPU usage by the node process occurs when loading 7000 policies due to fetching all statistics in one request.

998615

When doing a GUI-packet capture on FortiGate, the through-traffic packets are not captured.

1037220

GTP-U traffic fails when offloaded to NP7 with monitor-mode enabled.

1062080

SNMP query returns an error when there is a large number of BGP routes.

1078334, 1103739

High cmdbsvr CPU usage and FTP hang issues occur during scheduled automation backup executions due to automated backups appending device serial numbers to file names.

1095936

Fewer sensor entries appear when executing 'chassis-sensor list' after system bootup due to delayed sensor initialization on SMM.

1096156

GUI unreachable due to certificates and private keys mismatches in a HA setup.

1097428

The Security Profile menu does not appear in the GUI for Global VDOM on FortiGate 6K/7K devices despite being accessible through CLI.

1102413

Session count for VDOMs incorrect in FortiGate 6K/7K devices.

1102481

Local-in remote access issues due to incorrect destination address.

1104569

FortiGate FPM hangs after upgrade when confsynchbd fails to release a lock due to file permission issue.

1105009

The command execute load-balance slot manage X fails on FortiGate 6K/7K devices when admin-telnet is disabled and then re-enabled.

1108181

Unexpected behavior observed in the confsyncd daemon due to an erroneous memory allocation.

1109415

New SNMP MIB table for chassis sensor.

1109601

Graceful upgrades fail when hatalk daemon restarts, disrupting slbha state synchronization during FortiOS version transitions.

1109963

SFF-8472 diagnostic support was not recognized on SFP transceivers in FG-7941F systems.

1112581

On the FortiGate 7000F platform, after upgrading from FortiOS 7.4.7 to 7.6.2, cmdbsvr CPU usage can be at 99% on one or more FPMs for several minutes. During high CPU usage, FortiGuard packets cannot be synchronized to the affected FPM(s).

1115656

FG-6K session filter by source interface doesn't set correct interface index.

1116862

Graceful upgrade of a FortiGate 7000E chassis to FortiOS 7.6.2 may fail for some configurations.

1118004

On a FortiGate 7000E FGCP cluster, after using the execute ha disconnect command to disconnect a chassis from the cluster, you can't use the special management ports to connect to the FIM in slot 2 or to any of the FPMs of either chassis. You can still connect to the FIM in slot 1.

1121918

Confsyncd crashes occur when syncing ha-mgmt-intf to a newly joined HA slave due to invalid pointer attributes.

1124603

Traffic drop occurs on 7KF-FGT devices when traffic shaping is enabled during or after migration, causing intermittent internet connectivity loss.

1130218

Policies fail when Security Posture Tags are configured on SLBC platforms due to dynamic address sync issues outside HA mode.

1139867

In a 7121F chassis HA system with 7000F image, the secondary chassis GTP-C tunnels were not synced with the primary chassis GTP-C tunnels.

1149405

The image upgrade fails when performing a non-graceful update due to an ISIZE mismatch during verification.

FortiView

Bug ID

Description

1125124

When running more than 1 million concurrent HTTP sessions across the firewall, and trying to access session list on FortiView in the GUI, packet loss and loss of a session are observed.

GUI

Bug ID

Description

919473

Network > Interfaces: When an IPsec tunnel is bound to an interface, the "Interface Integrate" option for the interface fails.

1047963

High Node.js memory usage when building FortiManager in Report Runner fails. Occurs when FortiManager has a slow connection, is unreachable from the FortiGate (because FMG is behind NAT), or the IP is incorrect.

1054026

Offline license file cannot be uploaded to FGT by GUI.

1055197

On FortiGate G series with dual WAN links, Interface bandwidth widget may show incorrect incoming and outgoing bandwidth count, where the actual traffic does not match the display numbers.

1055354

Inappropriate Security Rating Insights items occur when registering to EMS and syncing tags.

1055865

NodeJS errors when event log socket is closed.

1092489

The config system fortiguard > fortiguard-anycast setting was changed to automatically disable when the FortiGuard page is shown on GUI.

1097405

Patch schedule minutes are ignored when set through the GUI for automatic upgrades.

1099309

The FortiOS GUI fails to load topology-related pages when temporary files generated during Security Rating operations are mistakenly read by the REST API.

1101932

IPsec monitor widget: IPsec phase2 tunnel details are not displayed in the tooltip when hovering over the phase2 selector.

1102404

VDOM search function does not work properly if VDOM has uppercase letters.

1104519

Interface faceplate appending occurs when switching between fabric devices.

1110382

Admin can log in to GUI (HTTPS) with password, even when admin-https-pki-required is enabled.

1110827

GUI shows LAN interfaces that have an IP address in the network ranges 172.31.0.0/16 or 192.168.0.0/16 to be managed by IPAM, even though the feature is globally disabled.

1111113

When launching the GUI console using Jet Stream theme, the character spacing appears wider than usual.

1111967

SD-WAN zone is not selectable as an interface in GUI for certain policies.

1112716

No log output when running debug flow on GUI.

1114658

Duplicated logs occur during Node.js health-check operations when internal communication between daemons is exposed through HTTP requests, as the traffic is captured in logs and packet captures.

1115684

System > FortiGuard: FortiCare elite contract is not displayed accurately under Licensing information.

1118810

Asset Identity Center: Tooltip on IoT/OT Vulnerabilities says OT license is inactive even with full license.

1128730

An error condition occurs during upgrade to FortiOS 7.6.3 B3485.

1133808

An error occurs when accessing FortiSandbox connector configuration via GUI.

HA

Bug ID

Description

982081

After changing the status to down on the ha1 and ha2 ports, setting the status back to up does not bring up the ports.

999440

Console prints error message when delete vdom in HA setup.

999440

Console prints error message when delete vdom in HA setup

1068674

PBA logs missing during HA failover.

1073514

In HA cluster, when a FortiToken is aggregated or revoked from a local.user, cluster is out of SYNC.

1085314, 1095879

Firewall policy page takes a long time to load on the HA Primary unit due to a loop condition between BGP and NSM when other protocols' same route is redistributed to BGP.

1086511

Firmware upgrade/downgrade is stuck at "Preparing for upload" with "*.js results in a network error" for FetchEvent when using Selenium auto test under Chrome Incognito window.

1087924

HA secondary unit experiences high CPU usage when frequent changes are made to CMDB on the HA primary unit.

1088956, 1101490

Duplicated logs occur in FAZ during sniffer mode operation in HA active-passive setups because both active and passive FortiGates forward L2 packets to the IPS engine, causing duplicate entries.

1091189

Switches observe MAC address flapping in HA A-A setups when both FortiGates use identical virtual MACs on their primary VLANs.

1091657

SDN connector limits the API traffic flow through root VDOM or HA management VDOM.

1095786

Traffic interruption occurs when performing a manual HA failback after an initial failover in VWP setups.

1098192

Joining a FortiGate with RAID enabled in an existing cluster causes the primary to shut down due to differing RAID statuses.

1099346

Connection issues occur when FortiGate secondary uses primary's certificate to connect to FMG instead of its own.

1100177

In an FGSP setup, on asymmetric TCP flow during SYN/ACK packet on the other member, the TCP MSS value is not adjusted according to the firewall policy.

1101456

In a HA setup, the aggregate interface status remains up after configuring 'status down' in FortiOS due to a race condition.

1101879

Multiple SCTP expectation sessions are created during resynchronization due to a flag allowing duplication.

1104892

Duplicate IP detected messages are seen from the Secondary Fortigate in a cluster.

1105422

"Detected Tx Unit Hang" error occurrs on the HA secondary, causing it to become out-of-sync.

1107137

The secondary FortiGate with an HA Reserved Management Interface cannot be accessed using HTTPS after upgrading from version 7.4.3.

1108895

In an FGSP cluster, enabling and disabling standalone-config-sync results in the local dev_base being deleted and synchronized with the peer, which leads to the absence of the dev_base.

1108895

In an FGSP cluster, enabling and disabling standalone-config-sync results in the local dev_base being deleted and synchronized with the peer, which leads to the absence of the dev_base.

1109919

Cluster experiences split-brain when EMAC interfaces are disabled within a zone.

1110498

Add IPv6 destination support under HA management interface configuration.

1112525

Admin socket creation error occurs when upgrading FortiOS in an HA A-P cluster.

1113842

New LACP interface is not shown under diagnose sys ha standalone-peers on both FGSP members.

1115190

The SNMP value of fgVWLHealthCheckLinkState on the secondary unit should always be set to dead(1).

1117725

HA synchronization fails due to checksum mismatches on CA certificates across all VDOMs when adding or modifying certificates sourced from a bundle.

1121117

When two HA clusters are on the same subnet, the L2 session-sync packets could be received by each other, even if they are from two different HA clusters.

1122341

Unexpected behavior occurs when ippool PBA index is out of range.

1129088

The sessionsync daemon experiences high CPU usage when syncing expectation sessions under heavy SCTP traffic and FGSP enablement due to inefficiencies in the dump API.

1135866

HA second unit cannot sync firewall ZTNA dynamic address with HA primary unit after primary disables EMS server.

1137565

vSN support added in 7.2.9, 7.4.6, and 7.6.1. FG-100F/101F do not yet support vSN and logical-sn.

1138763

IKE hasync loop and high memory consumption when peer address/port changes.

Hyperscale

Bug ID Description

1013892

Unexpected behavior observed in NPD when the threat feed object attempted to update manually in the HA pair.

1055443

Add ipv4/v6-session-quota back for software sessions in hyperscale VDOM.

1058477 sentb and rcvdb show -ve value for end session syslog message.

1074547

SNAT session drops occur when kernel sessions become dirty in hyperscale VDOM environments due to inconsistent NAT resource allocation between software and hardware sessions.

1091244 hypersale hw-session-sync-dev should print properly error message when set members over 8.
1091815 hw session doesn't sync when one of multiple interface hw-session-sync-dev is down.

1093287

Using fixed-allocation IP Pools may cause NP7 NSS/PRP modules to become stuck, potentially disrupting traffic. Other PBA IP pools do not have this issue.

1094162

The diag sys npu-session list-brief command now includes additional values for timeout, duration, and policy-id and an improved filter that includes EIF sessions to enhance its functionality and filtering capabilities.

1101562 hyperscale hw-session-sync-dev LAG members can exceed 2*number of NP.

1108263

HA configurations are lost if hw-sess-sync-dev is configured with more interfaces than expected. (The expectation is two times the number of NP7 chips.)

1114113

The get sys ha status command does not offer detailed interface statistics for hardware session sync devices.

1115761

When handling very high traffic loads (150M 250M concurrent sessions), the system sometimes fails to free up memory, even after all sessions have been cleared and traffic has stopped.

1119021 Sessionsync daemon makes hw-session-sync dev up even it's physically down, no such issue with sw session sync dev.
1119031 HW sessions are not synced to slave when one of the hw-session-sync-dev members is down.

1121524

Client could not get DHCP IP address with policy-offload-level set to full-offload.

1128155 FGT-1801F log-transport TCP should be hidden for log servers under L2host and Netflow on CLI.
1135433 IPv6 entries appear in the output of pba list after reaching max PBA limit for ippool.
1138823 FGT-1801F non-hyperscale VDOM shows incorrect output of "diag firewall ippool get-pub/priv" commands.
1140493 Config should be blocked when user tries to set same interface as hw-session-sync-dev andmonitor.

Intrusion Prevention

Bug ID

Description

1040783

FortiGate encounters CPU usage issue due to IPSEngine utilization when using an app-ctrl utm profile.

1074732

Traffic is dropped silently when IPv6 traffic is sent with UTM and nTurbo enabled on FortiGate-121G.

1090616

IPS does not pass channel ID/category ID from the first video in a YouTube playlist to WAD.

1093788

Sniffer logs are not generated when using VLANs.

1101633

Child process that loads IPS database does not have CMDB permission to write to IPS table.

1113473

When IPS generates traffic log for tunnel traffic, traffic log should include outer packet details.

1121953

IPSengine processes consume memory and can lead to the conserve mode.

IPsec VPN

Bug ID

Description

1002325

When spoke re-authauthorization is enabled, shortcut tunnel rekey fails and goes down when SA expires. Shortcut tunnel flaps while it re-establishes again.

1042465

Packet drops occur when FortiOS CPUs are overwhelmed by high traffic bursts while IPsec acceleration is enabled, leading to CP queue overflows despite prior optimizations.

1049015

IPsec performance issue on Intel-based platforms occurs due to FortiOS not enabling all available IPsec drivers.

1051144 IPsec dialup VPN connection issues occur when TCP port 4500 is blocked.

1054440

Incrementing TX and RX errors on VPN interface occur when NPU offload is disabled, busy CPU cores, or high burst traffic cause packet drops due to full queues on SoC3/Soc4 platforms.

1057558

Dialup and loopback-asymroute disable with multiple paths for IKE/IPsec traffic are configured. When the incoming ESP traffic changes path because of a routing change, reply traffic still egresses on the old interface, and traffic is dropped.

1059778

IPsec does not work as expected when the traffic path is from spoke dial-up to hub1, and then from hub1 to another site through a site-to-site tunnel.

1060048

Throughput is limited in Site to Site VPN connections between the FW1kF and the FWVM Google Cloud platform.

1064078

Egress shaper fails to enforce bandwidth limits on VPN ID with IPIP encapsulation IPsec interfaces due to incorrect handling of traffic forwarding across multiple network processing units.

1071769

L2TP/IPsec connections fail due to interface changes from break-before-make rekeys and Windows rejecting selectors during FGT-initiated QM rekeys.

1073670

Unexpected behavior observed in the IKED during HA split-brain events when IPsec tunnels are configured to use DHCP.

1087651

Authentication fails when using FortiClient with IPsec IKEv2 after waiting more than 60 seconds to enter the 2FA token, caused by a fixed 60-second RADIUS timeout.

1090200

transport-mode IPsec phase2 cannot set non-zero protocol successfully.

1090200

IPsec phase2 interface with encapsulation set to transport-mode cannot successfully set non-zero protocol.

1094028

Unexpected behavior observed in the IKED after configuration changes when the phase1 monitor feature is used.

1102528

NP7 tunnel offloading failure recovery issue may cause use-after-free memory corruption when there are many concurrent IPSec tunnels, which leads to high CPU usage and kernel panic.

1102584

Kernel crash caused by memory corruption due to a use-after-free issue, resulting in a system hang. This issue occurs with a large number of IPsec tunnels.

1103594

ADVPN IPsec traffic over shortcuts drops during IPsec tunnel rekey.

1103754

Failed HTTP sessions occur when passing through nTurbo due to improper handling of fragmented packets.

1107198

Transparent mode, policy-based IPsec VPN, local-out traffic automatically enters VPN.

1109028

With set peertype one, the FortiGate will not accept ID_IPV4_Address as peer ID for dynamic IPsec IKEv2.

1109627

IPsec VPN match-security-posture-tag feature won't work when FortiClient is behind NAT.

1110093

IPsec SA offloading stops on some FortiGate models when handling more than 50,000 concurrent secure associations.

1112665

Static routes are marked inactive when an old IPSec tunnel is deleted during an INITIAL-CONTACT message in IKEv1, mistakenly deactivating the new tunnel's status in the kernel.

1113354

Group list is truncated because of fixed-size buffers.

1116825

Juniper device unable to establish IKEv1 tunnel with FGT.

1117758

FGT fails to negotiate encryption algorithm CHACHA20_POLY1305 against third- party client.

1117910

iked spikes to 99.9% if client sends FIN after ike tcp session is established.

1120003

FortiGate presents certificate information when accessed using IPsec VPN listening interface.

1120517 IPsec tunnel failure occurs when using aggressive mode with PSK authentication.

1125487

Gateway switching fails during IKE session resumption when moving from a FortiGate model without Azure AD auto-connect enabled to one with it due to missing mode communication.

1127444

For ADVPN 2.0 shortcut negotiation, UDP hole punching for spoke behind NAT uses source port 500 instead of 4500.

1127782

Traffic is dropped by anti-spoof check when passing traffic through phase2 transport mode with GRE encap.

1134841 IPv6 split tunnel option issue occurs when configuring remote access tunnel through VPN Wizard or Tunnel dialog.
1135445 An error condition in SSL VPN occurs when upgrading to FortiOS from v7.4.7 to v7.6.2.
1136309 IKE negotiation failure occurs when iked is restarted with signature authentication.

1136536

VPN authentication fails on FortiSASE when a large number of RADIUS groups are configured.

1138631 Traffic distribution issues occur when configuring multiple IPsec tunnels between two FortiGates.

Log & Report

Bug ID

Description

864002

Unauthenticated User mismatch with User in logs.

1004103

Log & Report > Reports: When reports are renamed, the scheduled reports page does not load and the unable to fetch reports error notification is displayed.

1009584

FGT-VM64 has no crash log record and event logs for license status change from Valid to Warning.

1074460

Erroneous memory allocation results in intermittent HTTPSD disruption caused by a corrupted traffic log file.

1084934

Firewall logs show Object Object in GUI and dstintf="unknown-0" in raw logs.

1087534

Page loading issues occur when loading a high number of logs.

1091064

Missing poluuid and policyname fields occur in Forward Traffic logs when HA failover happens in FGCP clusters.

1100883

Forward Traffic log fetched from FortiGate Cloud takes a long time to load on GUI.

1107571

Some WiFi Log descriptions are inaccurate.

1116428

Observed Device vulnerability lookup on FortiGuard in high frequency under the system event log.

1118089

Temporary log files persist in /var/log after successful FTP uploads, leading to increased disk usage.

1119147

Secondary device fails to generate reports at the set time.

1121505

Log & report > Forward Traffic: The Security tab for security event logs does not load.

1122938

Syslog traffic uses the correct exit interface after a change in source interface but fails to update the source IP.

1129448

The body is partially missing from emails sent by alert mail.

1130821

Incomplete log entries occur when attack context logging is enabled for attacks involving long user-agent strings.

Proxy

Bug ID

Description

958200

Packets captured by IPS indicates HTTP/1.1 in case of HTTP/2 request.

988473

On FortiGate 61E and 81E models, a daemon WAD issue causes high memory usage.

1014014

Proxyd always selects the first certificate in the list when multiple server certificates are configured, regardless of SNI.

1023054

After an upgrade on a 2GB FortiGate device, the firewall policy does not switch from Proxy-based to Flow-based in the Inspection mode field.

1051875

Strict SNI certificate checks skip IP destination validation under strict mode.

1054835

HTTP/2 large file transfers are slow when IPS, APP, or SSL inspect-all is enabled due to excessive buffering during traffic forwarding.

1066113

Accessing certain websites through HTTPS fails when using inspect-all deep-inspection in proxy mode firewall policy.

1096728

An error case observed in the WAD, affecting some VIP traffic, caused by erroneous memory allocation.

1107205

FortiGate encounters a WAD memory usage issue when using a secure explicit web proxy with WAD user authentication to visit some websites.

1116771

Add a limit on the memory used by user-device-store as a percentage of the total system memory

1120964

An error condition in WAD occurs during shutdown after factory-reset on 32-bit ARM platforms.

1121171

Large file downloads through proxy HTTP2 are slow when IPS/APP/SSL inspect-all enabled.

1126253

When VDOM configuration file is restored, it changes the no-inspection profile under ssl-ssh-profile to deep-inspection.

1126385

WAD fails to handle deep-inspection traffic under FIPS mode.

1245569

Empty response occurs when pageSize exceeds 105 in FortiGate HTTPS Virtual Server

REST API

Bug ID

Description

943756

When creating a VPN remote certificate with the API, the "remote" key fails to be set, resulting in incomplete configuration.

1019750

The available interfaces list is slow in configurations with many IPsec tunnel connections.

1026547 Sensor information through REST API on a FG-81F returns 404 error.
1071799 Failed to rename switch-controller managed-switch entries through the CMDB REST API.

1077192

External Account Binding support occurs when using ACME RFC8555.

1107698

Adding ipv6-trusthost under api-user will override ipv4-trusthost setting and allow all IPv4 source IP addresses.

1110811

HTTPSD crash due to a memory leak in the libjson-c library when the monitor/virtual-wan/health-check API returns an error and response is not free correctly.

Routing

Bug ID

Description

897308

The system fib version does not match VDOM fib version in 1801F when queried due to a misalignment in how genid is reported by the Linux kernel to user space.

1008434

The speed-test result files are not deleted after test runs. The new test ID may collide with a previous result. In this case, the GUI may read a previously failed result and report errors.

1058283

Routing monitor: The Routing widget becomes unresponsive when using route lookup on a configuration that has a large number of routes.

1058700

The load-balance mode in SD-WAN rules only considers up to 8 paths as active when more than 8 are configured.

1072311, 1075911

BGP flaps occur when high L2P TPE drops are detected under heavy IPsec traffic conditions.

1080449

IPv6 prefix delegation does not add IPv6 route automatically.

1082842

The loopback interface does not appear as an outgoing option for BGP peer connections when configuring through the GUI.

1084851

When adding new static route and prefix-list using CLI, 0.0.0.0/0 takes effect, in spite of invalid format of dst and prefix.

1084907

Inactive IPv6 routes occur when dual stack BFD is configured without assigning the correct interface for IPv6, causing it to default to an IPv4 interface instead.

1086944

The BGP router-id fails to reset after editing the neighbor group settings because the dialog doesn't properly handle the reset functionality.

1093215

Users can create a BGP neighbor without configuring remote-as using CLI, and after completing BGP neighbor configuration, neighbor will remain in admin down state.

1095307

Network > SD-WAN > SD-WAN Rules: Filtering on members with alias names does not display matching results.

1099554

FortiGate uses link-local IPv6 address as nexthop in VLAN network, instead of global address.

1100529

BGP Stale route not working as expected.

1103034

Application "cmdbsvr" crashes when processing a configuration from OaaS controller. This issue occurs when adding another ISP to the test spokes and applying the change.

1103212

Network > Routing Objects: BGP AS number with asdot/asdot+ format will drop the trailing 0s on "set set-aspath" router-map config.

1105064

IPv6 traffic can't match the correct firewall policy in certain SD-WAN cases.

1106035

CPU usage issues observed during auto BMRK operations.

1108192

Restore image from FTP server failed using SD-WAN.

1108874

SD-WAN Default_DNS performance SLA shows all participants of Default_DNS are down.

1109286

Incorrect priorities are applied during remote health-checks when iked restarts because lnkmtd retains stale tunnel cache entries.

1111233

auto-asic-offload disabled under vne-interface after upgrading from 7.4.6 to 7.6.1.

1113929

Incorrect SDWAN rule is matched. fib-best-match is configured under zone.

1114687

The snmpd cache update takes longer when querying SD-WAN health-check data due to delays in retrieving bandwidth statistics.

1116924

In SD-WAN, when detect mode Prefer Passive is used, routing table is not updated in time

1118891

ADVPN shortcut is established between different transport-groups.

1119119

Inadvertent behavior observed in BGPD due to erroneous memory freeing when applying route-maps.

1122021

FortiGate disregards SD-WAN members for path selection even when they are in SLA.

1128032

Traffic fails with Fabric Overlay Orchestrator using automatic policy creation with system zones.

1129698

When FortiAnalyzer setting interface-select-method is sdwan, FortiAnalyzer connection is closed and restarted, even though SD-WAN interface doesn't change.

1133796

IPv6 routes are stuck on kernel routing table.

1134485

Failed to sniffer the VNE tunnel interface.

1134763

Session marked dirty by mistake when unrelated route changes in different VRF.

1138483

The link-monitor daemon truncates hostnames exceeding 63 characters when used in SDWAN health-check configurations, causing DNS resolution failures and impacting service availability.

1145668

FortiGate encounters PIMD daemon issue, which hinders multicast traffic.

SD-WAN

Bug ID

Description

1094449

Traffic routing issues occur when service-sla-tie-break is set to fib-best-match.

1110156 Speedtest failure occurs when using PPPoE mode on a physical interface without a valid IP.
1115208 Probe-timeout value is reset to 60000 when detect-mode is remote.

1116619

An error condition in vwl occurs when changing IPsec phase1-interface settings

1118705

Speed test failure occurs when using BGP over loopback design

1127506

ADVPN shortcut establishment issues occur when responder replies are delayed due to heavy load.

1139728

Link-monitor issues occur when a large number of ADVPN shortcuts are established.

1139734

High latency occurs when a large number of established and monitored shortcuts are present on the FortiGate.

Security Fabric

Bug ID

Description

903922

Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation.

1006397

In case of failure during a federated upgrade process, the system does not report granular failure details for individual devices.

1011833

FortiGate experiences a CPU usage issue in the Node.js daemon when there multiple administrator sessions running simultaneously.

1019844

In an HA configuration, when the primary FortiGate unit fails over to a downstream unit, the previous primary unit displays as being permanently disconnected.

1021684

In some cases, the Security Fabric topology cannot load properly and displays a Failed to load Topology Results error.

1090401

Error messages from netxd API calls are not displayed when running as a daemon because they are printed to stderr instead of the CLI.

1098787

Azure SDN Connector failure occurs when service tags API returns empty results with Resource Group scope permissions.

1099235

Scheduled triggers do not include eventtime in log entries, causing automation scripts using %%log.eventtime%% to fail and generate filenames with missing or incorrect timestamps.

1101806

Failed to trigger Security Rating Summary event automation stitch due to issue with log field ID.

1111619

The replacemsg-group in automation-action gets unset when system reboots.

1113463

FortiGate Azure connector fails to retrieve AKS information on AKS 1.29.5.

1119616

Externally maintained threat feed contains both resource FQDNs and IP address ranges/subnets. Entry such as <addr>/0x1 then matches half of all possible IPv4 address and causes network disruption.

1120652

Fabric topology with two devices on different VDOMs but behind the same router shows wrong VDOM data on tooltip.

1134970

Inconsistent DNS TTL behavior in Kubernetes API through SDN-Connector.

Switch Controller

Bug ID

Description

1015992

WiFi & Switch Controller > FortiLink Interface: When a FortiLink interface is down and the Lockdown ISL toggle is set to 'disable' on the GUI, the setting is not retained.

1016034

In an HA environment with FortiSwitches connected, the lockdown ISL setting on FortiLink gets enabled during HA failover.

1087254

Device fails to get IP address when moved between NAC ports on the same switch.

1108965

Sync errors occur when incomplete transaction flags related to dhcp-snooping-static-client replay past configuration changes during sync attempts.

1113465

VLAN configurations intermittently fail to assign on FSW ports when devices matching DPP policy come online, which is caused by a race condition during FSW initialization.

1124356

DPP mac classification issue occurs when DPP policy with vlan-policy and 802.1x is configured together.

1130242

Only the last SNMP community configuration is pushed from FGT to FSW during bulk processing.

1138333

Increase efficiency of FortiLink configuration daemon memory usage.

System

Bug ID

Description

814119

drop-overlapped-fragment {enable | disable} does not work on NP7 platforms.

898182 High CPU usage occurs when FortiGate is attacked by 4K PPS ARP requests.

932077

Connection issue between SOC4 platform and third-party switches, for example Hirschmann GRS 105 or Cisco switch, since SOC4 doesn't support certain carrier extension signals.

976722

Invalid YAML files are generated when exporting configurations containing multi-value attributes or long strings with newline characters.

992323, 1056133, 1075607, 1082413, 1084898

Traffic interrupt when traffic shaping is enabled on 9xG and 12xG

1017941

GUI interface bandwidth shows Tetrabyte spike for Gigabyte interface.

Affected platforms: FGT-220xE and FGT-330xE

1021838 Memory usage issues caused by updated daemon redesign in forticldd.

1030529

Password change occurs when admin's password is unset after burn image

1039980 Unexpected behavior in system occurs when out of memory during emergency restart.

1040137

NPD skips config parsing when policy-offload-level set to disable.

1040489

Traffic using VXLAN VTEP with a loopback over an IPsec VPN is dropped when VXLAN and IPsec are configured in different VDOMs due to incorrect tunnel creation success indicators.

1044472 Traffic drop occurs when VXLAN is a member of software switch in implicit mode.

1046484

After shutting down a SOC4 FortiGate (FGT-40F/FGT-61F/FGT-81F/FGT-100F) using the "execute shutdown" command, the system automatically boots up again.

1067448

VLAN switch is not working on 120G/121G.

1068756

After updating to the latest unsigned version of an object, update daemon will not download a new signed version of that object if the versions are the same.

1069208

If the DHCP offer contains padding when DHCP relay is used, the DHCP relay deletes the padding before relaying the packet.

1075279

Member interfaces of VWP appear in packet capture creation dialog despite being ineligible.

1076795 Private data encryption key generation issues caused by manual entry of 32-digit hexadecimal keys.

1076883

When the top application bandwidth feature is disabled, the GUI process still performs the initial check for application bandwidth, which may cause FortiCron to experience high CPU usage.

1077562

Hardware egress shaping doesn't work on SOC5 when NPU offload is enabled.

1078119

Traffic is intermittently interrupted on virtual-vlan-switch on Soc5 based platforms when a multicast or broadcast packet is received.

1078568

When FortiManager adds FortiGate via serial number and is behind NAT, FortiGate cannot initiate requests to FortiManager, causing the GUI to fail in retrieving the certificate CN/SAN and resulting in an error.

1079850

HA1/HA2 ports remain down after setting status to up. Rebooting fixes the issue.

1085407

FortiGate unresponsive when default-qos-type is set to shaping.

1086268

VXLAN interface cannot be created if its underlying interface is DHCP.

1087160

NP drops traffic when VXLAN is a member of software switch in implicit mode.

1087270

Unexpected traffic increase over the FortiGate 6000 base backplane.

1089143

The time change in FOS is restored after reboot. The RTC node is not created correctly so the time change can't be kept in RTC.

1089272

The inability to view or click the "+" sign occurs when a user is assigned an admin profile with only read access, restricting actions that require write privileges.

1090372

Access profile entries exceed global limit when built-in profiles consume table size slots.

1091175

VLAN statistics on LAGs are not displayed correctly when asic-offload is enabled due to incorrect OID usage.

1091551

Hardware limitation on the NP7 platform causes the following QTM related issues:

  • Incorrect checksum for fragments after QTM.

  • Packets longer than 6000 bytes cause QTM unresponsiveness.

  • Refresh issue causes QTM unresponsiveness.

  • MTU is not honored after QTM, so packets are not fragmented.

1094404

State of peer ports of FGT ports(negotiated speed, 1G) is down after upgrade on specific FGT

1095834

When FortiGate is managed by FortiManager, which has a slow connection or is unreachable, memory consumption of node process keeps increasing.

1096409

EXPIRE dates cannot be displayed properly when displaying the output of get sys fortiguard-service status.

1096878

DNS cache flushing occurs too frequently due to unnecessary interface-reload events triggered by DHCP6 packets and SLAAC updates.

1099770

NP7 drops encrypted GRE packets that have checksum bit set (1) due to invalid checksum.

1101392

Administrators can execute the command diagnose sys ha reset-uptime when the permissions of Admin Profile is set to Read.

1101647

FortiGate encounters a CPU usage issue for cmdbsvr process

1102416

Cannot push config sfp-dsl enable and vectoring under interface.

1102919

GTP tunnels are deleted even if there are still associated requests.

The problem occurred when multiple Create Session Request from different source IPs create the same GTP tunnel, and the first Create Session Response with an authentication failed cause leads to the deletion of the half-open tunnel and all associated requests.

1103146

Duplicated RADIUS packets are captured by the sniffer when performing firewall authentication with a RADIUS server.

1103966

FG901G gen1/2 boxes "diag hardw test asic" got FAILED

1104173

Kernel panic occurs when pushing 'Device Setting' from FortiManager to NP7 platforms with Broadcom switch, causing the device to become unresponsive and requiring a reboot.

1104410

The FortiGate-120G SFP ports fail to establish connectivity when configured with set speed 1000full due to improper auto-negotiation handling.

1104966

SNMP fgDiskCount.0 OID not returning disk count value

1105989

System global configuration lost due to port collision.

1105995

The switch MTU doesn't set correctly on 100m speed.

1109633

When visiting the GUI login page, FortiGate prompts user for certificate when no PKI admin is set.

1110527

FortiGate did not update password-expire time on the start or end of daylight savings time.

1111601

Fortiguard sends IP addresses to proxy instead of FQDNs

1112376

Unexpected behavior observed in the newcli daemon due to inconsistencies in node registration between cmdbsvr and other daemons.

1113720

Packets not forwarded due to improper handling of specific flags in the bridging code, which incorrectly treats them as local instead of resolving their destination MAC address and forwarding.

1114873 CPU usage issues observed during cmdbsrv process execution after reboot.

1115486

Virtual switch interface drops LLDP packets.

1116220

FortiGate 3601E 25Gauto link not coming up using DAC cables.

1116922

FortiGate encounters a memory usage issue if too many ports have LLDP reception enabled.

1117435

Add SNMP new OIDs fgAdminLoggedInTable for get sys admin list.

1117527

VXLAN interface should be brought down when underlay interface is down.

1119595

URLfilter fails to track DNS TTLs and update the IPs of FQDN addresses after they have been changed.

1120467

No SNMP trap at power failure for DC PSU.

1120907

High traffic load on a particular interface causes packet loss on other interfaces of the FortiGate.

1122306

Typo in log-controller-update request.

1123149

Unexpected behavior occurs in FEXT201E when cfg-revert is triggered

1123727

Incorrect traffic class (TC) settings and shaper class ID handling cause improper Quality of Service (QoS) application and session offloading failures for VLANs configured over Link Aggregation Groups (LAG) and hardware switches on FortiOS devices using SOC5 hardware.

1124024

When set append-index disable in system.snmp.sysinfo, querying per-VDOM BGPPeerTable might get incorrect results because of no updates.

1125301

FortiGate encounters parsing errors and potential system halts when configuration strings contain un-escaped single quotation marks, especially in password fields.

1125947

FortiGate encounters a memory usage issue due to usage by HTTSD

1126100

Expired user passwords are stored as plaintext in configuration files when password history is enabled.

1126327

The SNMP query for fgSwPortSwitchSerialNum gives switch name as the output instead of SN.

1127534

Update built-in CRDB bundle to version 1.56.

1127700

Packets are dropped during VLAN over VXLAN traffic due to incorrect handling of VLAN tags and session keys.

1128087

In new version of RDP client, FortiGate drops some RDP sessions due to IPv6 extended headers.

1133159

Inbandwidth settings are not enforced for traffic with multiple class IDs in a FortiOS shaping profile, resulting in reduced available bandwidth beyond 12 classes.

1133842

Packet dropped with 'DCE_IVS_IGR_DIR_DROP' over hardware switch.

1140422

SNMP query failure occurs when rpc aggregation is enabled for slave blades on FortiGate 6000F.

1140696 An error condition in Forticron occurs when log-single-cpu-high is enabled.

1142013

Policing improvement for QTM by limiting buffer size or switching to TPE (shaping-profile mode of config).

1144091

An error condition in dhcprd occurs when handling IPsec messages.

Upgrade

Bug ID

Description

1043815

Upgrading the firmware for a large number (100+) of FortiSwitch or FortiAP devices at the same time may cause performance issues with the GUI and some devices may not upgrade.

1097503

Fabric upgrade from 7.2.9 to 7.4.5 failed.

1102990

SLBC FortiGate 5001E primary blade failed to install image, even though graceful-upgrade was disabled.

1104649

In 7.6.1 and 7.6.2, if a local-in policy, local-in-policy6, DoS policy, interface policy, multicast policy, TTL policy, or central SNAT map is used in an interface in version 7.4.5, 7.6.0, or any previous GA version that was part of the SD-WAN zone, these policies will be deleted or show empty values after upgrading to version 7.6.1 or 7.6.2.

See Policies that use an interface show missing or empty values after an upgrade for more information.

1105771

Upgrade from 7.4.6 GA to 7.6.1 GA results in an incomplete WAD device memory list table and triggers WAD error.

1106072

The image file transfer between FortiManager and FortiGate may not work as expected when transferred by the FGFM tunnel.

1110809

Egress-shaping-profile setting lost on interface after upgrade.

1114232

When upgrading FortiGate from earlier than 7.4.1 to 7.4.1 or later, system.replacemsg.webproxy configuration is lost.

1123954

FortiGuard updates are automatically enabled during upgrades from versions where they were previously disabled, bypassing user acknowledgment.

1130861

FG-4401F enters a reboot loop after upgrading from 7.2.9 GA to 7.4.6 GA with a large config file (more than 10K policies).

User & Authentication

Bug ID

Description

1017348

Memory usage by fsso_ldap daemon increases continuously when the LDAP server responds with "LDAP_UNWILLING_TO_PERFORM" due to an unhandled memory allocation issue.

1020808

Use new keys for certificate renewal through EST server.

1025260

Wildcard admin remote authorization password change in system GUI does not work.

1043189

Low-end FortiGate models with 2GB memory can enter conserve mode when processing large amounts (over 5000 user records) of stored user store data, when each record has a large amount of IoT vulnerability data. For example, the Users and Devices page or FortiNAC request can trigger the following API call that causes httpsd process to spike in CPU and memory:

GET request /api/v2/monitor/user/device/query

1054818

Password encryption changes occur when editing config vpn certificate local without actual certificate changes.

1075207

Errors may occur in the FNBAMD due to the presence of two wildcard-enabled remote administrators in separate VDOMs.

1077636

No SNMP trap available to detect FSSO external connected status change.

1091483

When importing local certificate, GUI displays an error, even when certificate is correctly imported.

1093538

In SAML config, after enabling "AD FS claim" (Active Directory Federated Services and rebooting, the "Attribute used to identify users" and "Attribute used to identify groups" fields are blank.

1093542

FortiGate admin user authentication with token+RADIUS fails when wildcard user is configured.

1093654

FGT uses global DNS when attempting to provision a certificate through SCEP or EST.

1099831

An error condition in fnbamd occurs during stress testing with certificate parsing.

1105305

Guest users are not removed after their configured expiry time on certain FortiGate models.

1119143

Unable to view local certificate in GUI or CLI after certificate import.

1121503

Source-ip setting issue occurs when configuring scep enroll settings per VDOM in non-management VDOM.

1121987

Firewall user widget: Tooltip for FSSO users on the 'user group' column displays overlapping text.

This is cosmetic and does not affect functionality.

1136244

RSSO not working on 7.6.x with Cisco Meraki MX.

VM

Bug ID

Description

999842

Azure fails to honor seamless live migration.

In most cases, the public IP to private IP NAT fails to forward traffic from/to SD-WAN.

1012000

When unicast HA setup has a large number of interfaces, FGT Hyper-V takes a long time to boot up.

1094600

The virtual-wire pair fails to create during FortiOS initialization on cloud platforms when the underlying interface uses DHCP and hasn't acquired an IP address yet, preventing VXLAN configuration from completing successfully.

1101264

HA failover actions are triggered even when the Azure SDN connector is in a "disabled" state, causing increased downtime during failover.

1102434

Configuring VRF on hbdev causes FGT VM HA not to sync.

1107007

samld stops working when certificate set to Fortinet_Factory in user SAML.

1107933

The FortiGate device uses a single CPU core for GRE decapsulation tasks when running on AWS with ena NIC drivers because L4 hash functionality is not enabled, preventing RPS from distributing traffic efficiently.

1107962

Dynamic addresses are removed/added every few seconds when the OCI SDN connector fetches only the first page of API results.

1109724

Azd daemon on Azure NVA keeps consuming memory until FortiGate enters conserve mode.

1113362

FGT-VM64-AZURE cannot establish connection with other FGTs in the Security Fabric tree.

1121521

Azure SDN connector does not properly catch AKS cluster state.

1121974

Due to continuous disk logging, slab memory for dentry continuously increases in FortiGate VM.

1128351

Configuration fails to fully apply during bootstrap when the reboot function does not trigger an immediate reboot, causing cloudinit to re-run with insufficient tablespace.

1128988

License validation issues occur when connecting to FDS via a web proxy.

1143866

License status warning occurs when FortiGate-VM64 is upgraded

Web Filter

Bug ID

Description

874516, 1100819

SMB traffic fails when the file server uses AES-256-GCM/CCM encryption with FortiOS.

906603

Security Profiles > Webfilter: When a new webfilter is created and the action on the FortiGuard category-based filter is set to 'allow' and saved, the action is saved as 'monitor' on commit.

1099818

Output of diagnose webfilter fortiguard cache dump command shows the message "Cache is not enabled".

1107456

FG-120G webfilter.profile tablesize is incorrect.

1110668

Add an option to control webfilter.urlfilter simple-type entries match subdomains.

1110850

The value for x-forwarded-for is not properly displayed in the log on AWS environment.

1118132, 1122036, 1127984

Webfilter local category override not working after reboot in flow mode.

WiFi Controller

Bug ID

Description

823387

Email addresses collected through captive portal fail to display under WiFi clients when using guest SSID configurations.

921080

The FortiGate Hostapd does not support IPv6 address of RADIUS server.

987030

Unexpected behavior observed in the CAPWAP daemon when managing multiple APs and clients through dynamic VAP changes.

1013892

On FortiGate's in an HA pair, the npd process do not work as expected when trying to manually update the threat feed.

1030197

Client traffic is blocked after a failure when connecting through SSID using radius-mac-auth and radius-mac-auth-usergroup because the secondary FortiGate in HA does not receive necessary client details during failover.

1039985

Erroneous memory allocation observed in the CAPWAP function on NP6 and NP6XLite platforms due to a rare error case.

1080094

High memory usage may occur due to offline station entries not being automatically cleaned up over time.

1083395

In an HA environment with FortiAPs managed by primary FortiGate, the secondary FortiGate GUI Managed FortiAP page may show the FortiAP status as offline if the FortiAP traffic is not routed through the secondary FortiGate.

This is only a GUI issue and does not impact FortiAP operation.

1086128

An error condition in CAPWAP occurred due to a rare case.

1089999

FAPs remain offline post-upgrade when using image stored on FortiGate.

1094415

VLAN pooling assigns incorrect VLAN IDs when FortiOS is upgraded, causing clients on AP groups to receive IPs from the optional VLAN instead of the pool.

1096961

The "AP image receive success" log (id 43618) does not generate when upgrading FAP from FMG.

1098727

Enable 5GHz channels 52-64, 108, 116-128 for FAP-231G-P, 431G-P Uzbekistan. (Uzbekistan has no DFS certification process.)

1100220

COA disconnect is not functional for MPSK profiles when using external FortiGuest.

1101583

FortiAP go offline when the cw_acd process becomes stuck at 99% CPU usage. This issue is caused by the FortiAP sending corrupt data in certain scenarios, leading to the process hanging.

1102808

When the configuration contains a large number of vlan-pool entries, deleting or adding a few entries can cause the cw_acd crash.

1108726

FortiAPs periodically lose connectivity with FortiGate (acting as WLC) due to an error case.

1114144

WSSO firewall authentication sessions fail to establish when FortiGate processes multiple group attributes with the initial group missing.

1114311

Packets are incorrectly routed when FAP management interface uses clear-text dtls-policy in a software switch with explicit intra-switch-policy.

1123829

Support legal firewall policy when SD-WAN/zone member interface manages FAP with dtls-policy set to ipsec-vpn.

1128272

Management connection fails for FAP-231F when using PPPoE interface on FGT-120G.

1130750

WiFi & Switch controller > Managed FortiAPs: When a channel override on a 5GHz channel is enabled is edited on a managed AP, the channel selection is unset.

1133829

The FAP remains offline after the FortiGate reboots or wireless-controller restart-acd due to the controller sending an empty country string to the access point.

1139749

FortiGate does not honor source IP for MPSK RADIUS requests.

ZTNA

Bug ID

Description

1101022

FortiClient gets a blank page when doing SAML authentication due to the use of a stale user node.

1107986

Should be unable to select geography object in ZTNA proxy-policy.

1111112

Unable to configure more than eight mapped ports for access proxy realservers when the limit is 16.

1114976

ZTNA policy matching failed due to an accidental deletion of firewall.policy with ZTNA tags when the firewall.policy is updated.

1115153

Authentication loops occur during ZTNA connections requiring SAML when FortiClient uses multiple sessions with inconsistent cookies.

1118540

Browser timeout occurs when accessing ZTNA web bookmark with IP address.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

1085628

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-24471

1103790

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-25248

1108301

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-22254

1137151

FortiOS 7.6.3 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-53744