Fortinet white logo
Fortinet white logo

FortiOS Release Notes

Resolved issues

Resolved issues

The following issues have been fixed in version 7.6.4. To inquire about a particular bug, please contact Customer Service & Support.

Agentless VPN (formerly SSL VPN web mode)

See also SSL VPN tunnel mode replaced with IPsec VPN.

Bug ID

Description

978939

Performance issues occur when CMDB configuration is large.

1115577

Add customization support for the SSL-VPN header replacement message.

1124222

Intermittent connection disruption occurs when using SSL VPN web mode to SSH to Cisco routers with authentication banners.

1134189

Connection refused occurs when using custom landing page in agentless VPN portal on FortiGate.

1143541

An error condition occurs in sslvpn after receiving FortiClient UUID with an empty value.

Anti Spam

Bug ID

Description

1098623

A closing character ">" of HTML tag is missing in replacement message of antispam URL spam submission text when FortiGate processes spam emails.

Anti Virus

Bug ID

Description

1080003

FGT memory gradually increases when FGT Flow AV Profile is inspecting TCP 6200 traffic with outbreak prevention enabled.

Application Control

Bug ID

Description

1118703

Web traffic designated as blocked is allowed due to the config entry priority in the application control profile.

1136103

App categories fail to display in NGFW mode due to undefined object causing JavaScript TypeError during app category data access.

1144469

No security events logged for custom Application Control profiles in Monitor mode when applied to policies configured to log all sessions.

DNS Filter

Bug ID

Description

1134108

The IPS engine memory usage increases rapidly when a flow-based policy uses an external Threat Feed with over 1M domain entries, causing device unresponsiveness.

1144986

DNS service disruption occurs when FortiGate is deployed as a DNS proxy with DNS filtering enabled and an unreachable SDNS server is preferred.

1150842

Dynamic DNS updates are not forwarded to the DNS server according to transparent-dns-database when using a conditional DNS forwarder for the non-authoritative zone.

1159583

DNS Filter Rating Servers license not reflected in CLI for 71F when using Single FortiGuard HA license in HA cluster with logical-sn setting.

Endpoint Control

Bug ID

Description

1086668

FortiGate does not connect to EMS cloud when EMS cloud license is expired on the global FortiCare account, even when the access keys are valid in other VDOMs.

1113593

EMS connector is getting disconnected when using a third-party certificate for verification, resulting in loss of tags and denied traffic.

1142301

ZTNA tag in "View matched endpoint" on GUI might not match backend data.

Explicit Proxy

Bug ID

Description

1034891

Web application using SAML IDP authentication in POST method via SWG on FortiGate gets a 303 response and the payload in the post request gets discarded.

1066091

Traffic issue occurs when FortiGate authenticates machine account in the format of HOSTNAME$ using NTLM.

1096263

Intermittent 504 errors occur when an IPv6 HTTP request followed by an IPv4 request in the same pipeline goes through explicit proxy with outgoing-ip.

1116834

Authentication pop-up does not appear when accessing HTTPS websites through FortiGate with Explicit Proxy when authentication rules, webproxy-forward-server, and certificate-inspection are configured in proxy-policy.

1136596

Incorrect status display occurs when editing proxy policies for hard/software switches on some FortiGate models.

1139784

Machine account is treated as NULL user in Kerberos and fails to authenticate via Kerberos.

1144818

Download failure occurs when accessing https://7-zip.de for domain objects.githubusercontent.com.

1149811

An error condition in WAD occurs when auth rules are changed during policy matching in explicit proxy policies

1157551

Memory usage issue caused by improper internal state handling when using WebProxy.

1163040

An error condition in WAD is triggered by an edge case which causes the process to enter an error-handling path

1166344

WAD session freeze when using explicit proxy with HTTP2 enabled in VDOM UKT-Proxy.

1177548

A 400 Bad Request error occurs when accessing CP addresses during SAML authentication in session mode.

1178564

Intermittent policy-denied issue occurs when explicit proxy policy is configured with SD-WAN zones in outgoing interface.

Firewall

Bug ID

Description

1004263

Session counters are not being updated when ASIC offload is enabled on firewall policy. FortiGate GUI is displaying incorrect information in the "Bytes" and "Last Used" columns.

1057080

On the Firewall Policy page, search results do not display in an expanded format.

1108236

Incorrect logs are displayed when viewing matching logs for an implicit deny policy due to an invalid filter operator.

1114635

In the GUI, cannot filter Address objects correctly when using CIDR notation.

1131860

A two to three minute delay occurs when enforcing policy changes to existing or new traffic due to linear duplicate address checks during iprope updates.

1136543

Traffic block occurs when creating 802.1ad type VLAN based on redundant interface

1138259

Traffic carrying VLAN info encounters forwarding mismatch after deleting a VLAN interface built upon an NPU VDOM link

1140803

With interface policy configured with IPS enabled, UDP port 4500 traffic is not offloaded due to incorrect session flag f02 after ICMP unreachable packet is received.

1141922

Internet service custom limit increase occurs when per VDOM limit is set to 512

1142813

Filtering by comments fails when quick-editing firewall policies in the Firewall Policy page.

1144475

Intermittent DCE/RPC session blocks occur when two session-sync-dev are connected to the same switch without VLAN separation.

1145106

Multicast traffic drops occur when sending large packets to remote tunnels over the x5 interface on FortiGate 400F.

1145129

Port-preserve option changes to disable when disabling NAT in policy.

1148161

Erroneous MAC address is used on SOC4 platforms when traffic offloads EMAC-VLAN to VLAN traffic to NPU

1148166

Source port translation was not permitted with traffic to UDP port 7001.

1154620

Traffic is blocked by DoS policy when npu offload is disabled under IPsec phase1-interface and DoS policy is configured with parent interface.

1155687

DNAT incorrectly in later FTP data packets and FTP data session gets reset when FTP server responds with public IP in PASV mode

1156810

Traffic is logged as accepted in Forward Traffic Log when FortiGate is configured as a DNS server and implicit deny policy is enabled.

1157283

High priority traffic drops when bursty traffic is present on low priority queues.

1158137

Traffic is blocked when UTM and Nturbo are enabled in firewall policy for np7lite platforms.

1158391

Inconsistent address group configuration occurs when using CLI's 'append' command with 'all' value.

1159576

Traffic shaping fails when type is set to queuing in the shaping-profile.

1160083

Expected session using its parent session's policy ID in the session list is confusing and makes policy match look wrong.

1162875

IPv6 traffic is blocked without sending RST packets when send-deny-packet is enabled for 4.19 kernel.

1163826

When non-TCP/UDP traffic passes through the Hyperscale VDOM, the selected SNAT IPPool can be wrong in NAT Source function call.

1169439

GTP tunnel deletion occurs when mobility handover happens with same PDN connections information.

1171392

No response occurs when FortiGate receives a packet with low TTL and a deny-all policy is set.

1178125

Packet loss occurs when traffic shaping rule is enabled with no limits on per-ip-shaper and the pre-defined max limit is overflow

1178157

IPv6 packets are dropped when block-land-attack is disabled and source and destination addresses are the same.

1179233

Geo IPs are only installed into the kernel if the country is used, which makes the option geoip-anycast in firewall policy not work very well

FortiGate 6000 and 7000 platforms

Bug ID

Description

1014826

SLBC does not function as expected with IPsec over TCP enabled.

1060864

Ports fail to establish or exhibit CRC/input errors when 100G QSFP28 LR transceivers are used with FIM-7920E and Cisco ASR in specific setups.

1083246

Intermittent traffic disruption occurs when using Fortinet_Factory on FortiGate-200G.

1103810

100G SFPs are experiencing compatibility issues with the 7060E at Turkcell.

1104967

Intermittent interface disruption occurs after power cycle.

1108405

VLAN interface accounting issue occurs when vlif reaches its maximum.

1113805

Firewall policy statistics reset after reboot on FGT-6k devices caused by improper persistence of aggregated data.

1117663

Unexpected behavior in the bcm.user process after a factory reset can sometimes prevent the FPMs from booting up.

1131541

SSL VPN load balance settings remain active in FortiOS configurations where SSL VPN tunnel mode has been removed.

1135891

The PSU status incorrectly shows as "Critically High" on the GUI dashboard widget.

1136261

Traffic blockage occurs when creating VLAN over redundant interface on SOC5 platform.

1146580

Traffic stats aggregation issue occurs when using M ports in FGSP setup.

1147340

Duplicated interface entries occur in FortiGate HA configuration merges when the same interface is processed across multiple cycles without successful resolution, causing persistent sync failures and redundant log entries.

1149342

BGP flapping occurs when concurrent IP address management causes unexpected source IP usage on outbound connections during FortiGate VDOM migrations.

1153360

Counter values fail to match totals and may overflow during continuous clearing in certain FortiGate models.

1154348

CLI allows assigning VLAN interface of M port LAG interface to data VDOMs when configuring VLAN interface on top of M port LAG

1159714

Unexpected behavior observed on certain FortiGate models when configuration changes follow enabling "cfg-save revert" due to unresolved netdevice references in the np7 driver.

1161584

An error condition occurs in the APACER NVME controller during hardware testing on FortiGate-201G.

1170088

RADIUS authentication fails when connecting to Secondary Chassis Slot 2 to 4.

1170524

SSH login attempts via special ports fail for VDOM admin users with access to 'mgmt-vdom' on SLBC FortiController models.

1171521

In some cases, after a FortiGate 7000F chassis restart, an FPM may hang while logging in, resulting in the FPM being out of synch with the chassis. This happens because confsynchbd becomes stuck after receiving a management heartbeat from the primary FIM.

The issue can occur any time the chassis restarts, including after a firmware upgrade.

1172378

Blades go to dead status when upgrading due to a cross FIM issue.

1172922

SDN dynamic address synchronization flaps or fails when SDN connectors are frequently enabled and disabled.

1173230

Traffic loss occurs when FIM on standby unit is rebooted in HA A-P setup on 7KE model.

1174680

CPU usage issues observed during IPsec tunnel formation over PPPoE interfaces.

1178954

ICMP packet offload failure occurs when passing through VPN over aggregate interface.

1183735

Graceful upgrades lead to unintended primary claiming by FortiGate units during HA resynchronization.

FortiView

Bug ID

Description

1133164

Subnet filtering fails for firewall users due to partial API support.

1138980

Read-only profile admin user tries to change FortiView source time range , and it is logged as edit by system admin in system events.

1139219

The Quarantine widget experiences delays when loading the complete IP list.

1141357

Session counts beyond a certain limit are not displayed on FortiView, device icons are missing from FortiView pages, and quarantine actions do not reflect in the Log Viewer.

GUI

Bug ID

Description

264694

When a firewall user logs in via the GUI using RADIUS with FortiToken, no accounting request is generated.

853352

When viewing entries in slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100K entries.

919473

Network > Interfaces: When there is an IPsec tunnel bound to an interface, Interface Integrate for that interface fails.

1051993

Incorrect 'Cancel Fabric Upgrade' button display occurs when full fabric upgrade failed or complete.

1053139

Login failure messages appear in the GUI when administrators log in within an air-gap environment.

1110950

An error condition in httpsd occurs when using JSON array sort compare.

1119321

Authentication enhancements and optimizations using HTTP Admin Auth Daemon

1126162

Hostname pop-up window shows "failed to retrieve info" error in System > HA page.

1126975

Timezone offsets are displayed in UTC when a timezone is set.

1129254

Unexpected behavior occurs when attempting to save L2TP dialup tunnel configurations using SD-WAN members on some FortiGate models.

1130636

The FortiConverter window reappears after closing even when Don't show again is selected.

1131500

Some bandwidth interface widget not show historical information.

1137821

Failed to open CLI console from downstream FGT GUI with error "Connection lost." with SAML SSO admin login.

1138359

Can't open CLI console when logging in with SSO account.

1139922

Cannot rename authorized FortiSwitch.

1140317

FAP/FSW registration status appears vacant on Firmware & Registration page.

1143611

User/groups objects disappear after editing firewall policy.

1145475

Multicast traffic dropped when add/remove interface bandwidth widget on dashboard.

1146621

When editing an SSL VPN policy in the GUI after creating the policy in the CLI, user/group is not requested.

1146967

Failed to update prompt occurs when moving interface using Interface Integrate feature.

1148930

Exported FSW ports to tenant VDOM are not displayed on the GUI when the tenant VDOM has a FortiLink, causing virtual switches to be filtered out due to the lack of a fsw-wan1-peer attribute.

1148959

An error condition in httpsd occurs when fetching data from cmdbsvr fails.

1150591

Node.js encounters an error when attempting to read the property from a null value, causing unintended behavior on some FortiGate models.

1151118

Default Super Admin creation notification is not triggered when logging in through the GUI with accprofile-override enabled

1151414

Unable to connect to FortiSwitch CLI via Diagnostics and Tools.

1152464

The DHCP reservation widget incorrectly validates based on the subnet instead of individual IP addresses.

1152580

FEXT dataplan display issues occur in FortiGate GUI when controlled by FEXT-101G

1152737

When device-identification is enabled, an incorrect IP address is observed when a device gets updated with no IP address

1152849

Connection loss occurs when accessing FortiGate Cloud remote access.

1153294

Custom HTML content does not render correctly on login pages when configured through the FortiGate web interface or CLI.

1154487

GUI page times out when never timeout option is enabled for the admin profile.

1156109

Console prints error when logging in to the GUI with dns ssl-certificate set to Fortinet_Factory.

1162818

Proxy policy GUI page keeps loading when using user.certificate in ZTNA proxy-policy.

1163464

Read permission occurs when logging in with read-write accprofile if FortiGate is managed by FortiManager.

1165306

FortiSwitches not showing in alphabetical order in GUI occurs when viewing FortiSwitch Ports.

1165693

An error condition occurs in the GUI sniffer when using advanced syntax.

1166936

Failed to load value occurs when viewing PoE devices on FortiOS GUI.

1169584

An error condition in Apache occurs when the ACME renewal thread interacts with the main thread.

1170203

GUI access issues occur when upgrading from B3561.

1172647

Filtering services become unavailable when Anycast is enabled.

1175241

After performing a search in the policy list, sections cannot be collapsed, causing delays in operations.

1178020

Administrative-access option FMG-Access is not available on the GUI when FIPS-CC mode is enabledj.

1179698

GUI error when editing the IPsec tunnel when the VPN name contains "/"

HA

Bug ID

Description

794395

The secondary unit in an HA cluster would display messages indicating that external resources were not in sync, despite the resources being correctly synchronized.

984306

Session synchronization fails when encryption is enabled in FGSP with IPsec VPN setup.

1017177

A WAD processing issue causes the SNMP to not respond in a HA cluster.

1080655

HA synchronization fails after configuration changes on FortiGate devices due to improper handling of a hasync flag in the fgfmd daemon.

1115004

An error condition in the daemon occurs when upgrading an HA cluster with standalone-mgmt-vdom enabled.

1126274

VDOM is created unexpectedly when changing VRRP priorities on multiple interfaces if standalone-config-sync is enabled.

1133589

HA cluster fails to form when FIPS-CC is enabled.

1135008

When link monitor fail, initial HA cluster failover doesn't happen immediately until pingserver-flip-timeout expires.

1136097

HA state may become out of sync due to a race condition caused by missing local-in ipropes.

1141528

High CPU usage occurs when FortiGate secondary unit is started in Azure vWAN SD-WAN NGFW with Dynamic rerouting.

1142161

Federated upgrade failure occurs when upgrading in an HA cluster

1143361

Downtime occurs when upgrading HA cluster with HA encryption or authentication enabled due to HA communication being sent through IKE tunnel when tunnel is not ready

1143791

The heartbeat interface default route is lost and HA fails to sync when changing the interface mtu-override option.

1148845

LDAP authentication fails when ha-direct is enabled due to confusing logic between which interface takes priority when interface-selection is also used

1151668

Interface bandwidth widget doesn't display HB and Managed port.

1154466

Traffic forwarding issues occur when FGSP failover happens.

1160292

FFDB version sync issue occurs when updating on-demand ffdb in HA environment.

1162432

Split brain occurs when renaming IPsec phase1-interface in a HA cluster with a lot of VDOMs.

1165798

An error condition in FortiMQ occurs when HA AA is configured and malware-stream scan is enabled on primary FortiGate.

1168328

Mgmt interface is lost when joining a device to a cluster with system dedicated-mgmt enabled.

1170763

Device synchronization issues occur when removing a device from FortiManager

1171987

HA not synced after modifying onetime schedule when cfg-save is manual.

1172590

An error condition occurs in FortiGate when running the diag sys ha nonhaconf command on the secondary node in an HA cluster.

1178208

VLAN HB link monitor stops working when HA Group-ID is set above 255.

1179351

FortiGate failed to load the private keys for factory certificates to fgfmd due to incorrect classification

1179821

Intermittent connectivity loss occurs to HA secondary management IP after upgrade to v7.4.8.

1180636

Session filter issues occur when adding custom service filters with different port ranges under cluster-peer session sync.

Hyperscale

Bug ID

Description

1089281

With FG-480xF/FFW-480xF using npu-group other than "0" with log2host with around ~1M CPS could result in NP chip getting stuck.

1141632

After HA failover, syslog packets not sent out from new HA master when using NAT46/NAT64 policies.

1143144

Both HW log(ps) rate and log(pm) rate show in dia sys npu-session stat when set log-mode per-nat-mapping is enabled.

1150073

For previous versions of hyperscale FortiOS, FGCP HA clustering with hardware session synchronization with config vcluster-status disabled allowed you to monitor hw-session-sync-dev interfaces. FortiOS 7.6.3 changed this behavior, and you can no longer monitor hw-session-sync-dev interfaces.

When upgrading to FortiOS 7.6.3 if your HA configuration includes monitoring hw-session-sync-dev interfaces, the upgrade will fail.

1150863

Unintended session deletion may occur after FGSP failover due to a dirty Rsession.

1155548

With host logging (log2host) enabled, session counts may begin to rise after a few days of operation. This rise in session count can reduce throughput and CPS performance.

1159964

Incorrect duration of hardware sessions occurs when the system is up for a long time.

Intrusion Prevention

Bug ID

Description

1110788

Memory usage issues caused by configuration changes or rule loading.

1117043

Fatal errors occur when the IPS engine sends requests with zero-length data segments to IPSA.

This issue only affects physical FortiGate models with the following IPS engine versions:

  • IPS Engine version: 7.550 - 7.567

  • IPS Engine version: 7.1019 - 7.1039

To determine the IPS Engine versions, use the command:

get sys fortiguard-service status | grep 'IPS/FlowAV Engine'

1122188

Internal diagnostic commands fail or delay when ipsmonitor processes each request sequentially due to sequential forwarding to IPS daemon processes.

1149760

Inline-IPS fails to match sensor locations for the "Web.Server.Password.File.Access" signature because it incorrectly reverses traffic direction definitions.

1158024

Packet drops and lower CPU utilization on FPC blades when using IPv6 traffic with np-accel-mode enabled and auto-asic-offload.

1158524

Unexpected behavior observed in the IPSEngine when a DNS packet matches a policy with DNSFilter and Safe Search enabled.

IPsec VPN

Bug ID

Description

842821

Accounting information is not sent to RADIUS when EAP and 2FA authentication are enabled.

979591

Changes to IPsec phase1 fragmentation settings do not take effect immediately when made on dynamic configurations.

995912

VPN tunnels exhibit instability following an upgrade, with processes stuck during NP7 debugging due to improper prioritization of certain packets.

1045098

IPv6 traffic is blocked on new configured IPsec VPN over loopback interface, need reboot to fix it.

1063528

Incorrect MTU settings prevent fragmented packets from being properly offloaded in IPsec tunnels, causing high CPU usage on FortiGate models.

1063737

High CPU usage occurs when using IPsec tunnel with fragmented packets and UDP frame size of 1600B.

1068626

SOC4 platform IPSec traffic may stop in specific corner cases due to the IPSec outbound process becoming unresponsive.

1101897

Abnormal spikes in VPN traffic sent bytes occur when counters roll back due to race conditions.

1116128

Traffic disruption occurs when IPSec engine is offloaded.

1128662

BGP peering fails to establish when a race condition occurs between FortiGate OS and NPU driver during IPsec SA updates for dynamic hub-to-static spoke VPNs.

1133207

Tunnel establishment fails for multiple FortiGate clients when using DHCP-over-IPSec dial-up VPNs during high concurrent connection attempts.

1135490

Static route towards remote side of IPsec tunnel becomes inactive when tunnel IP address is configured.

1140823

IPsec tunnels become stuck on spoke np6xlite, causing ESP packet drops after extended operation due to improper vifid formation during multiple rekey operations.

1141865

Decrypt counters do not update when SA is offloaded.

1145219

IPsec tunnels drop unexpectedly during rekeying when using certificate authentication with multiple dialup gateways and peer-initiated SA_INIT requests.

1145391

IPsec VPN tunnel fails to establish when QKD is required due to failure to complete SSL handshake with the QKD server

1145411

Changing the ip-fragmentation setting on dynamic IPsec phase1 does not take effect immediately after modification due to an issue with the change handler function in certain FortiOS builds.

1147023

VPN traffic halts unexpectedly on the spoke when FEC is disabled during connection cleanup after failed phase 1 negotiations, affecting dynamic tunnel handling.

1149340

Fragmented packets are not sent out on vpn-id-ipip IPsec tunnel when npu-offloading is enabled.

1152486

Unable to select policy-based IPsec tunnel in the firewall policy for SD-WAN member while configuring in GUI.

1153363

Intermittent disruption occurs on ipv6 route lookup when configuring IPsec with FIPS-CC enabled.

1153984

Authentication error occurs when IPSEC-IKEv2 tunnel is configured with FortiToken Cloud.

1156722

DNS suffix search issues occur when using IKEv2 phase1 dialup gateways with mode-cfg enabled.

1157885

Shaping parameter is not shared during ADVPN spoke to spoke negotiation.

1162270

Secondary IPsec tunnel cannot come up after primary tunnel is down and config change when "set monitor" is configured under phase1.

1162563

An error condition in the system occurs when creating more than 75 VPN tunnels with Egress Traffic shaping enabled.

1162740

Multicast traffic above 1350 bytes does not flow through the IPsec aggregate tunnel when using pre-encapsulation.

1163234

IPsec negotiations fail when auth-keepalive is enabled with SAML authentication.

1165581

Certificate validation issues occur when mandatory-ca-verify is disabled in IPsec VPN configuration.

1167952

Packets with payload larger than 10K and smaller than 15K are dropped when using IPsec tunnel as egress interface with nTurbo enabled.

1168556

IPv6 routing entries remain after iked restarts.

1169860

L2TP connections fail when L2TPD experiences internal errors while attempting to create tunnels for clients.

1170094

An error condition in IKE occurs when using TCP transport.

1172040

Returning packets take a different path when TCP transport is used with multiple default routes in the routing table.

1173228

During modeconfig setup, an IPSec IKEv2 dialup tunnel may install a default route when no IP address can be allocated from the pool.

1179347

Intermittent IPSec tunnel disruption occurs when upgrading to FortiOS 7.4.8 with FIPS enabled in HA mode.

1181552

An error condition in IKE occurs when using TCP.

Log & Report

Bug ID

Description

611460

On FortiOS, the Log & Report > Forward Traffic page does not completely load the entire log when the log exceeds 200MB.

1005223

Unmatched custom service name appears in traffic log when source port range is defined in custom service.

1087235

Only last 24 hours of Forward traffic log are been downloaded while trying to download logs from the last 7 days.

1087534

Page loading issues occur when loading a high number of logs.

1100945

The "Resolve Unknown Applications" feature in the GUI Log Viewer is not functioning as intended.

1113588

FortiGate prompts error "Fetching data from Disk is taking longer than expected. Suggest trying a different log source or check the availability of Disk." when viewing logs for the last 7 days from disk or FortiAnalyzer.

1116108

Intra-zone Local logs are missing when intrazone allow is enabled.

1125032

Export option fails when 500+ logs are present

1127636

Unnecessary log generated when disabling an interface.

1128940

Security Rating summary log displays incorrect counts when triggering a security rating check.

1141436

FortiGate device enabled with FIPS-CC mode sends an incorrect build number (0523) to FortiGate Cloud.

1141733

Traffic interruptions occur when revisiting the forward traffic log page during searches with applied filters.

1142836

Broadcast traffic is no longer logged when local-in-deny-broadcast setting is disabled.

1146443

Inaccurate Netflow reports occur when ICMP long live sessions exceed the active timeout value.

1148101

Logs fail to appear in FortiAnalyzer, and FortiView sources are missing from the Dashboard.

1151300

Logs are not displayed in FortiGate CLI when using free-style filter with timestamp and FortiAnalyzer as data source.

1168738

Syslog packets are not sent when log server IP is not configured.

1184366

Incorrect logs are displayed when applying a destination filter in Log Viewer for remote log sources FAZ and FGT-cloud until a hard refresh is performed.

Proxy

Bug ID

Description

859182

WAD encounters an error condition when configuration changes affect certificate verification processes with Crypto KXP enabled.

1015721

An error condition occurs in WAD during stress testing.

1019504

An error condition occurs in WAD during high HTTP traffic.

1107594

Slow website loading occurs when using certificate inspection with proxy inspection-mode in HA active-active mode.

1118701

Connection issues for Kentik application using http2 gRPC occur with proxy and deep inspection.

1124557

An error condition occurs in WAD when wad-restart-mode is set to time and wad-restart-start-time / wad-restart-end-time are configured.

1125531

Timeout occurs when server certificate is expired.

1133100

Memory usage issues caused by WAD leaking SMB2 session objects when clients close connections with a Kerberos status of KRB_AP_ERR_MODIFIED.

1141948

Certificate inspection profiles differ across VDOMs when importing policy packages from FMG, caused by inconsistent default values for unsupported-ssl-version in certificate-inspection profiles between different FOS releases.

1144571

TLS handshake fails when Client Hello is split across two packets in proxy-mode, and the packet length is less than 256 bytes.

1146601

With proxy inline-ips, a memory leak occurs on the WAD daemon, leading to conserve mode.

1155170

Memory usage increases unexpectedly during high load when processing WAD-related tasks.

1155858

RD Gateway fails behind HTTPS Virtual Server when using WebSocket upgrade.

1159963

Expired server certificates are issued when Deep Inspection is enabled due to improper handling of certificate cache renewals.

1161940

An error condition in proxyd occurs when migrating from 500E to 901G.

1173291

Memory usage issues caused by missing certificate memory free operations during stress testing.

1177929

Memory usage issues occur in WAD when handling a large number of sessions.

REST API

Bug ID

Description

1159460

Current bandwidth value is not sent to FMG for shaping graph when using FortiOS API.

Routing

Bug ID

Description

1036123

BFD for BGP takes interface BFD config instead of multi-hop config when BFD is enabled on both OSPF and BGP.

1097855

IPv6 traffic may be sent to the wrong destination interface or route, causing connectivity issues.

1097939

Console print out "/bin/cmdbsvr...node=system.health-check-fortiguard.name" error messages when restore a config.

1142290

An error message appears in FortiGate when attempting to add the ssl.root interface to a route-map via the GUI.

1142955

High CPU usage occurs when link monitor daemon fetches session counts on every interface during REST API calls.

1147497

Slow performance and network issues when surfing to Internet from GRE tunnels.

1150878

The IPoE tunnel interface cannot be selected in the Interface Bandwidth widget.

1152976

Spokes using remote-as-filter with 4-byte ASN cannot establish BGP neighborship.

1156431

PIM error when receiving PIM Assert with SSM enabled during HA failover.

1164316

IPv6 route issues occur when set delegated-prefix-route enable.

1165424

The behaviour of the command diagnose ip router bgp <module> <enable | disable> is incorrect. Turning on debugging for one of the modules turns on debugging for all modules.

1166008

VRRP version 2 failure occurs when adv-interval is configured in milliseconds Workaround: Configure the adv-interval at 1025.

1171689

Incorrect route selection occurs during BGP redistribution with route maps due to improper handling of parent protocol distances.

SD-WAN

Bug ID

Description

1130683

Shortcut can't be triggered in certain cases due to the error "found duplicate in ike_check_update_addr_key".

1147720

Traffic forwards to the unexpected egress interface when duplicate SD-WAN rules exist in the proute list in the case that priority-zone in sdwan service has only one sdwan member

1147727

Encapsulated traffic of GRE tunnel interface over VNE tunnel egressed wrong interface after reboot

1153992

Event log used wrong reason that packetloss over the threshold when SLA fails due to consecutive probes failed

1155927

SD-WAN Service events are not logged in SD-WAN Events when using SD-WAN rules in standalone mode.

1159877

Hash-mode remains visible when SD-WAN service mode is changed to priority.

1027225

New shortcuts fail to trigger when existing shortcuts experience high packet loss in priority mode.

1142171

Health check status change behavior occurs when recovery time is set to 240 and interval is set to 500ms.

1153432

Downtime occurs when using OSPF with LAN during shortcut establishment and tunnel failover.

1164937

Incorrect outbandwidth calculation occurs when IPsec tunnel interfaces are used in SDWAN configuration.

1167276

All participants of SLA name become unavailable when the check interval is set to 15 seconds.

1181497

Incorrect data type occurs when using OID fgVWLHealthCheckLinkBandwidthBi.

1187007

GUI issues occur when accessing SDWAN rules and Performance SLA menus.

Security Fabric

Bug ID

Description

1085248

FortiGate encounters CPU and memory usage issue when loading 20 large external threat feeds (100K entries each).

1110643

Security Fabric issues occur when running FortiOS 7.4 or 7.6 with 200G.

1117104

Scheduled automation incorrectly triggers reschedule after reboot when using specific time zones and NTP configurations.

1118086

An error condition occurs when enabling CSF root on 50G series devices.

1145138

Automation stitch fails to shut down a specific port on the secondary FortiGate during HA failover due to incorrect script environment settings.

1149817

Security Fabric > Physical Topology: FortiLink Tier 2 switch shows directly connected to FortiGate on Security Fabric > Physical Topology page.

The correct topology can be seen on the WiFi & Switch Controller > Managed FortiSwitches > Topology view.

1150382

Security profile names containing two forward slashes (//) cause the webpage to become unresponsive when attempting to edit.

1165624

Topology page load failure occurs when CSF is disabled.

1166189

When using the OCI SDN connector, dynamic IP addresses are not fetched correctly if the target compartment contains more than 100 VNICs.

1180555

Threat feed connections fail during SSL handshakes when server-identity-check is enabled for HTTPS downloads in FortiOS.

1210303

APIC device overload occurs when FortiGate logs in multiple times without proper logout.

Switch Controller

Bug ID

Description

961142

An interface in FortiLink is flapping with an MCLAG FortiSwitch using DAC on an OPSFPP-T-05-PAB transceiver.

1075365

Upgrade or restart of FSW fails when FortiLink is in HTTPS mode

1105000

Aggregate FortiLink went down, need to manually down/up the interface.

1114032

The GUI becomes slow or unresponsive when transceiver-related API requests fail.

1134306

VLAN configuration mismatch occurs when configuring LAN Extension and VLANs locally on FEX.

1135460

Health status becomes unknown after renaming a switch in the switch controller on some FortiGate models.

1137075

In the WiFi & Switch Controller > Managed FortiSwitches page, the Topology view shows the link between FortiSwitch units with a dotted line instead of a solid line.

1137213

Extension device registration fails through GUI when FortiCare agreement acknowledgment flag is reset after updates.

1138263

FortiSwitch port configurations fail to update and GUI display issues occur when user-info process overloads system resources with excessive connections.

1138430

Increase managed-switch.switch-id to more than 16 characters

1144076 High CPU usage occurs in cmdbsvr when FortiLink is enabled and FortiLink interfaces are connected to the firewall.

1153868

Sync errors occur when renaming a FortiLink switch with special characters.

1155546 Duplicate entries occur in the switch-controller managed-switch list when renaming a managed-switch.

1164685

Local MAC addresses are filtered out from being added to user device list when mab-entry-as dynamic mode is enabled on Fortiswitch.

1174647 Fortilink connections may not display correctly in the FortiGate GUI Topology view when using MCLAG aggregation.

1183135

Filtering by allowed VLANs fails to display expected results when using certain FOS versions.

System

Bug ID

Description

900936

The fnbamd service may terminate unexpectedly due to erroneous memory handling during certificate authentication, if DNS responses include both IPv4 and IPv6 addresses and one (for example, IPv6) is unreachable.

908309

LLDP packets not received on management interface when LLDP is enabled on certain FortiGate models.

973034

LACPDU packet drops occur when FortiGate fails to reliably send required packets due to incorrect npu_tc assignment for hi-priority traffic.

992323, 1056133, 1075607, 1082413, 1084898, 0992323

Traffic interrupted when traffic shaping is enabled on 9xG and 12xG.

996863

Automatic firmware update email alerts triggered after each reboot on FortiGate.

1029459

sflowd error condition occurs when sflow sampling is enabled without a collector configured.

1048684

The FortiGate Internet Service Database (ISDB) update mechanism fails on a 100E FortiGate model due to insufficient memory allocation.

1057094

Disabling GRE auto-asic-offload on a FortiGate model causes traffic to be dropped due to unrecognized GRE tunnels, likely because the kernel fails to process them without proper configuration post-disabling.

1065869

SCTP CRC check option is not available on NP7lite platform like 91G/121G.

1071229

Ping reply packets are dropped after two successful requests when using VXLAN over IPsec on FortiGate.

1075340

Aggregate link down occurs when speed is set to 10000auto after upgrade to v7.4.5.

1082891

FortiGate reboots immediately after changing ull-port-mode to 25G without a confirmation prompt.

1095801

Error "Fail to del default npu-vlink setup" is shown when changing the hostname.

1096384

Warn user when restoring config from a different firmware version.

1096537

High CPU usage occurs when making configuration changes with a large number of policies.

1099770

NP7 drops encrypted GRE packets that have Checksum bit set (1) due to invalid checksum.

1107270

Communication over VXLAN is lost after upgrade on NP7 platform.

1113436

Packets are dropped when using auto-asic-offload with 802.1AD over LACP on FortiGate due to missing MAC address assignment on QinQ lag interfaces.

1113651

An error condition occurs in the simulator during stress testing.

1114298

FortiGate Cloud remote login triggers 2 admin login events (1 successful and 1 unsuccessful for PKI admin).

1117005

CPU spikes and management access issues occur on certain FortiGate models post-upgrade when IPsec Phase 1 NPU-offload is enabled during maintenance.

1121522

Memory leak in slab causes the system to enter memory conserve mode. The issue occurs due to out-of-order log packets and incomplete session scrubbing, resulting in residual entries in the log2host table.

1121548

Enabling "device-identification" also gets endpoint information even though intermediate router exists on FG and endpoints.

1122741

Two duplicate FGFM sessions could be triggered when connecting to FortiGate cloud. And the first FGFM session that enters in GET_IP state kills the other FGFM session which will schedule a FGFM session restart two minutes later.

1130803

Port13-20 speed setting changes to 1000full after FortiGate 10xF reboot.

1131516

CRC error count reset issue occurs when using the diag netlink interface clear command.

1132414

When connecting port5-14 on 3201F with third-party switches using optical transceivers, the 1gig link is down.

1133575

The 100M speed option is not available for wan1 and wan2 interfaces during configuration in certain FortiGate models.

1135440

Unexpected behavior occurs when changing interface mode or static route through an IPSEC-Tunnel when emac vlan interface based on npu-vlink is used

1137218

VXLAN traffic uses primary IP address instead of secondary IP address when configured vxlan remote-ip with secondary IP.

1138155

DNS (TCP853) fails until idle timeout when link monitor failover occurs in dual internet connection.

1140755

When attempting to delete a software switch interface, it becomes permanently hidden due to an unreverted temporary flag.

1141832

Interface inbound/outbound information is not displayed on the bandwidth widget and CLI when using VLAN interfaces with NP6 platform.

1141907

Unexpected behavior occurs when deleting IPv6 reflect session.

1142591

Unexpected behavior occurs when high load IP fragment traffic is sent through an IPsec tunnel with vpn-id-ipip encapsulation and offloading enabled.

1142782

GRE tunnel traffic is limited when sessions share same local/remote IPs, causing them to be assigned to single CPU core.

1142785

False SNMP alerts occur when a non-installed power supply unit is detected

1142805

Cannot set source IP for FortiGuard when a non-root VDOM is set.

1146354

The network interface settings page fails to load on certain FortiGate models when the admin profile does not have the System > Configuration > Read/Write permission.

1148843

Unstable LTE 4G connection occurs when using IPv6.

1149508

WAN interface goes down when share-port medium type changes to 'copper' after upgrading FortiGate-80F-DSL

1149814

An error condition in WAD occurs when executing log messages with invalid node pointers.

1151313

On NP7 models, gtp tunnel list counters don't increase when restoring configuration file with "gtp-enhanced-mode enable".

1152059

Device information is not detected when device-detection is enabled in ARM based models

1152638

FGT still sends reset packet when drops TCP SYN packets with ident-accept enable on wwan interface after reboot.

1153004

APN profile not updating when configuring Verizon APN.

1153442

Concurrent sessions drop significantly when low-end FortiGate models have low free memory.

1153983

Registration status remains unknown when re-adding Fortimanager IP after it was lost.

1154158

DHCP issue occurs when configuring hardware switch interface in A-P HA mode.

1155410

High memory consumption occurs when Node.js encounters catastrophic failures and creates excessive logs.

1156561

NP7lite platforms might encounter high softirq issue and stop processing traffic after running for one month.

1156785

Device recognition issues occur when device-detection is enabled for some Apple devices.

1157490

Temperature is out of range with unreasonably high value.

1158975

FortiGate does not establish VNE tunnel caused by a failure to commit DNS servers to the CMDB after receiving a DHCPv6 information request.

1159425

Unused power supply log appears in diagnose alertconsole list when a redundant power supply is not used

1160215

An error condition occurs in snmpd on FortiGate-VM64-AZURE approximately every 1.5 hours.

1162489

The SFP WAN1 and WAN2 ports on the FGT-80F device remain down after a reboot when the speed is set to 100M.

1163292

VDOM expansion issues occur when upgrading license on FortiGate-201G.

1163814

Memory usage issues occur when newcli processes are not deleted after their parent sshd process died.

1164174

Configuration loss on FGT-60F when FortiGate enters extreme conserve mode

1164761

SFP+ direct attach cables are shown as "compliance is unspecified" by the "get system interface transceiver" command.

1165059

Unexpected behavior in system occurs when executing factory reset on FortiGate-70F.

1165172

CPU usage issues caused by receipt of packets longer than 65535 octets.

1166455

TCP packet drop occurs when sending traffic over VLAN+redundant port

1167234

Unexpected behavior occurs when loading build B3553 on FortiGate-101F.

1167426

High CPU usage occurs in the linkmtd daemon when large traffic is present.

1168786

100G ports turn up after reboot when administratively down on platforms with Marvell switch, such as FortiGate 480xF.

1168792

Network detection issues occur when the LED is on during diagnose hardware tests.

1170291

WWAN interface fails to get IP address when 'auto-connect' feature is enabled.

1170464

Memory usage issues caused by low memory availability on FortiGate-51G

1172295

FortiGate does not autoupdate router objects in full such as key-chain, route-map, and prefix list, causing FMG to purge the config during installation.

1175384

"Partition ImageEXT4-fs (sda2): couldn't mount as ext3 due to feature incompatibilities" when running "diagnose sys flash list"

1177037

System events are not generated when FortiGate acts as a DHCP client.

1178017

10G Copper interface fails to come up when directly connected after a fresh setup

1178199

SNMPD access issues occur when increasing VM memory.

1178583

DHCP relay strips DHCP END Option (255) when relaying DHCP packets.

1185286

An error condition in Newcli occurs when executing the get system fortiguard-service status command.

1187981

DDOS policy not properly installed in kernel on FortiGate 120G and 121G.

1190222

Incompatibility occurs when using 8G eMMC on 3XG/5XG/7XG/9XG models

1190245

Memory usage issues caused by renaming VPN IPsec phase1-interface during config change.

1193889

Certificate error occurs when connecting to FAZ via SSH

Upgrade

Bug ID

Description

1130034

Obsolete system.autoupdate.tunneling is removed when configuring system fortiguard.

1130655

License validation issues occur when system.autoupdate.tunneling is not migrated to system.fortiguard after upgrading.

1158947

Manual patch upgrade not allowed when system has invalid upgrade license

1160916

Password history settings are lost during upgrade from 2731 to 2794.

1171564

System halt occurs when upgrading from v7.4.8 GA b2795 to v7.6.4 b3563

1172979

Upgrade failure occurs when upgrading from v7.6.4 to v8.0.0 due to CMDB request issue.

User & Authentication

Bug ID

Description

1112301

CPU usage issues observed during certificate authentication with multiple DNS replies.

1118212

Captive portal authentication fails after FortiToken push notification approval during radius authentication with FAC for remote groups.

1122979

Custom NAS-ID not sent to RADIUS server when testing connectivity via GUI.

1124183

Guest user sessions persist in the FortiGate authentication list despite manual expiry, enabling continued network access.

1134368

LDAP server becoming unreachable 'set mfa-mode subject-identity' is configured under the user peer settings, or ha-direct enabled with source-ip.

1137727

Delays in SSH login verification occur on some FortiGate models when hashing passwords, and immediate failure messages are returned for invalid usernames.

1146635

Fnbamd issue during certificate authentication when multiple DNS replies contain both IPv4 and IPv6 parts.

1147049

Device hostname is not displayed when device identification is enabled and mDNS includes the device UUID.

1156903

CLI authentication test fails when RADIUS server has require-message-authenticator setting disabled.

1160080

User deletion occurs when upgrading with invalid password-history characters.

1163152

RADIUS stops working on secondary unit when HA secondary connects to a RADIUS server using UDP.

1193697

Emails with FortiToken codes are not sent due to an SSL error when using SMTPS port 465.

VM

Bug ID

Description

1125437

The "set distance" option under interface configured as DHCP client doesn't work on VM.

1146370

AWS bootstrap is unable to parse IAM role profile properly due to the length.

1146634

IfLinkUpDown SNMP trap is not triggered on FGT_VM64_KVM using the virtio driver when an interface is brought up or down.

1157674

Incorrect system time occurs when FortiGate-VM64-GCP boots up on GCP.

1161380

License becomes invalid when system time is incorrect on FortiGate VM64-GCP devices.

1172050

Packet-rate information is missing for some interfaces when running the diagnose netlink interface packet-rate command on FortiGate-ARM64-AWS.

WAN Optimization

Bug ID

Description

1160444

Global config wanopt content-delivery-network-rule is deleted when restoring VDOM config.

Web Filter

Bug ID

Description

1145481

URL filter exemption fails when adding regex entries to URL filter if newly added regex entry contains invalid perl style regex.

1150232

Threat feed URLs are not blocked since Sandbox block list file version check always fails and aborts loading other types of URL lists, including external-resource category URL list.

1156789

Web filter settings category name, block screen category name, and log category name are translated into different Japanese when using web filter profile on FortiGate.

1177015

Webfilter logs are not generated when https-replacement-message is disabled in proxy-policy with DPI.

WiFi Controller

Bug ID

Description

1001211

Add optional antenna support for K-series models 443K and 243K.

1018895

Clients on local-bridging SSIDs appear offline despite having active traffic when acd-process-count is 2, caused by the AP failing to report client IPs to the controller.

1063976

Empty SN values occur in AP DTLS session timeout messages.

1126824

When WiFi client enables VPN endpoint, VPN traffic cannot pass through NP6Xlite FGT models.

1131094

The iPhone 16 fails to connect to a WPA3-SAE SSID on FWF-61F due to incorrect ordering of RSN and RSNXE parameters during the authentication handshake.

1145326

In non-root VDOM, device fails to authenticate when MPSK is used with an external RADIUS server.

1147416

Connection fails for Samsung S22 devices when using WPA3-SAE from local-radio on certain FortiGate models.

1151713

FortiAPs may go offline when memory pool of WiFi daemon cw_acd is fully occupied and not released properly. cw_acd debug constantly show ERR: NO MEM for USER_LOCAL_MSG

1161023

Groups of Wi-Fi clients are lost after roaming to a different AP, causing unintended behavior in network policies.

1174782

The client fails to authenticate and gets disconnected from the access point when initiating Fast BSS transition (FT) roaming with MAC authentication enabled.

1177859

When FWF local radio is in non-root vdom, wifi users encounter connectivity issues.

ZTNA

Bug ID

Description

1089157

An error condition in WAD occurs when adding a ztna-ems-tag to a proxy policy with an active ZTNA session

1102925

Memory usage issues caused by accessing multiple websites through WAD

1118878

Traffic bottleneck occurs when syncing 120K FCT endpoints from EMS to FortiGate.

1134649

WAD cannot re-verify new ems-tag after an ems-tag update for HTTPS access proxy, causing existing sessions to remain active despite matching a deny policy.

1135441

CLI error occurs when configuring SAML server in api-gateway with access-proxy6 and vip6 configured.

1139201

Internal resources are inaccessible via IP or FQDN when using agentless ZTNA Access proxy-portal with apptype web on FortiGate.

1159018

ZTNA agentless not working on FG-90G devices.

1172396

The Certificate Information field in the replacement message shows incorrect information when ZTNA access proxy is configured to accept empty cert.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

1112620

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-25255

1126271

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-25249

1132094

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-31514

1172008

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-58413

1173156

FortiOS 7.6.4 is no longer vulnerable to the following CVE:

  • CVE-2025-25249

1174215

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-53843

1177284

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-53844

1179021

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-54821

1184468

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-59718

1188853

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-58903

Resolved issues

Resolved issues

The following issues have been fixed in version 7.6.4. To inquire about a particular bug, please contact Customer Service & Support.

Agentless VPN (formerly SSL VPN web mode)

See also SSL VPN tunnel mode replaced with IPsec VPN.

Bug ID

Description

978939

Performance issues occur when CMDB configuration is large.

1115577

Add customization support for the SSL-VPN header replacement message.

1124222

Intermittent connection disruption occurs when using SSL VPN web mode to SSH to Cisco routers with authentication banners.

1134189

Connection refused occurs when using custom landing page in agentless VPN portal on FortiGate.

1143541

An error condition occurs in sslvpn after receiving FortiClient UUID with an empty value.

Anti Spam

Bug ID

Description

1098623

A closing character ">" of HTML tag is missing in replacement message of antispam URL spam submission text when FortiGate processes spam emails.

Anti Virus

Bug ID

Description

1080003

FGT memory gradually increases when FGT Flow AV Profile is inspecting TCP 6200 traffic with outbreak prevention enabled.

Application Control

Bug ID

Description

1118703

Web traffic designated as blocked is allowed due to the config entry priority in the application control profile.

1136103

App categories fail to display in NGFW mode due to undefined object causing JavaScript TypeError during app category data access.

1144469

No security events logged for custom Application Control profiles in Monitor mode when applied to policies configured to log all sessions.

DNS Filter

Bug ID

Description

1134108

The IPS engine memory usage increases rapidly when a flow-based policy uses an external Threat Feed with over 1M domain entries, causing device unresponsiveness.

1144986

DNS service disruption occurs when FortiGate is deployed as a DNS proxy with DNS filtering enabled and an unreachable SDNS server is preferred.

1150842

Dynamic DNS updates are not forwarded to the DNS server according to transparent-dns-database when using a conditional DNS forwarder for the non-authoritative zone.

1159583

DNS Filter Rating Servers license not reflected in CLI for 71F when using Single FortiGuard HA license in HA cluster with logical-sn setting.

Endpoint Control

Bug ID

Description

1086668

FortiGate does not connect to EMS cloud when EMS cloud license is expired on the global FortiCare account, even when the access keys are valid in other VDOMs.

1113593

EMS connector is getting disconnected when using a third-party certificate for verification, resulting in loss of tags and denied traffic.

1142301

ZTNA tag in "View matched endpoint" on GUI might not match backend data.

Explicit Proxy

Bug ID

Description

1034891

Web application using SAML IDP authentication in POST method via SWG on FortiGate gets a 303 response and the payload in the post request gets discarded.

1066091

Traffic issue occurs when FortiGate authenticates machine account in the format of HOSTNAME$ using NTLM.

1096263

Intermittent 504 errors occur when an IPv6 HTTP request followed by an IPv4 request in the same pipeline goes through explicit proxy with outgoing-ip.

1116834

Authentication pop-up does not appear when accessing HTTPS websites through FortiGate with Explicit Proxy when authentication rules, webproxy-forward-server, and certificate-inspection are configured in proxy-policy.

1136596

Incorrect status display occurs when editing proxy policies for hard/software switches on some FortiGate models.

1139784

Machine account is treated as NULL user in Kerberos and fails to authenticate via Kerberos.

1144818

Download failure occurs when accessing https://7-zip.de for domain objects.githubusercontent.com.

1149811

An error condition in WAD occurs when auth rules are changed during policy matching in explicit proxy policies

1157551

Memory usage issue caused by improper internal state handling when using WebProxy.

1163040

An error condition in WAD is triggered by an edge case which causes the process to enter an error-handling path

1166344

WAD session freeze when using explicit proxy with HTTP2 enabled in VDOM UKT-Proxy.

1177548

A 400 Bad Request error occurs when accessing CP addresses during SAML authentication in session mode.

1178564

Intermittent policy-denied issue occurs when explicit proxy policy is configured with SD-WAN zones in outgoing interface.

Firewall

Bug ID

Description

1004263

Session counters are not being updated when ASIC offload is enabled on firewall policy. FortiGate GUI is displaying incorrect information in the "Bytes" and "Last Used" columns.

1057080

On the Firewall Policy page, search results do not display in an expanded format.

1108236

Incorrect logs are displayed when viewing matching logs for an implicit deny policy due to an invalid filter operator.

1114635

In the GUI, cannot filter Address objects correctly when using CIDR notation.

1131860

A two to three minute delay occurs when enforcing policy changes to existing or new traffic due to linear duplicate address checks during iprope updates.

1136543

Traffic block occurs when creating 802.1ad type VLAN based on redundant interface

1138259

Traffic carrying VLAN info encounters forwarding mismatch after deleting a VLAN interface built upon an NPU VDOM link

1140803

With interface policy configured with IPS enabled, UDP port 4500 traffic is not offloaded due to incorrect session flag f02 after ICMP unreachable packet is received.

1141922

Internet service custom limit increase occurs when per VDOM limit is set to 512

1142813

Filtering by comments fails when quick-editing firewall policies in the Firewall Policy page.

1144475

Intermittent DCE/RPC session blocks occur when two session-sync-dev are connected to the same switch without VLAN separation.

1145106

Multicast traffic drops occur when sending large packets to remote tunnels over the x5 interface on FortiGate 400F.

1145129

Port-preserve option changes to disable when disabling NAT in policy.

1148161

Erroneous MAC address is used on SOC4 platforms when traffic offloads EMAC-VLAN to VLAN traffic to NPU

1148166

Source port translation was not permitted with traffic to UDP port 7001.

1154620

Traffic is blocked by DoS policy when npu offload is disabled under IPsec phase1-interface and DoS policy is configured with parent interface.

1155687

DNAT incorrectly in later FTP data packets and FTP data session gets reset when FTP server responds with public IP in PASV mode

1156810

Traffic is logged as accepted in Forward Traffic Log when FortiGate is configured as a DNS server and implicit deny policy is enabled.

1157283

High priority traffic drops when bursty traffic is present on low priority queues.

1158137

Traffic is blocked when UTM and Nturbo are enabled in firewall policy for np7lite platforms.

1158391

Inconsistent address group configuration occurs when using CLI's 'append' command with 'all' value.

1159576

Traffic shaping fails when type is set to queuing in the shaping-profile.

1160083

Expected session using its parent session's policy ID in the session list is confusing and makes policy match look wrong.

1162875

IPv6 traffic is blocked without sending RST packets when send-deny-packet is enabled for 4.19 kernel.

1163826

When non-TCP/UDP traffic passes through the Hyperscale VDOM, the selected SNAT IPPool can be wrong in NAT Source function call.

1169439

GTP tunnel deletion occurs when mobility handover happens with same PDN connections information.

1171392

No response occurs when FortiGate receives a packet with low TTL and a deny-all policy is set.

1178125

Packet loss occurs when traffic shaping rule is enabled with no limits on per-ip-shaper and the pre-defined max limit is overflow

1178157

IPv6 packets are dropped when block-land-attack is disabled and source and destination addresses are the same.

1179233

Geo IPs are only installed into the kernel if the country is used, which makes the option geoip-anycast in firewall policy not work very well

FortiGate 6000 and 7000 platforms

Bug ID

Description

1014826

SLBC does not function as expected with IPsec over TCP enabled.

1060864

Ports fail to establish or exhibit CRC/input errors when 100G QSFP28 LR transceivers are used with FIM-7920E and Cisco ASR in specific setups.

1083246

Intermittent traffic disruption occurs when using Fortinet_Factory on FortiGate-200G.

1103810

100G SFPs are experiencing compatibility issues with the 7060E at Turkcell.

1104967

Intermittent interface disruption occurs after power cycle.

1108405

VLAN interface accounting issue occurs when vlif reaches its maximum.

1113805

Firewall policy statistics reset after reboot on FGT-6k devices caused by improper persistence of aggregated data.

1117663

Unexpected behavior in the bcm.user process after a factory reset can sometimes prevent the FPMs from booting up.

1131541

SSL VPN load balance settings remain active in FortiOS configurations where SSL VPN tunnel mode has been removed.

1135891

The PSU status incorrectly shows as "Critically High" on the GUI dashboard widget.

1136261

Traffic blockage occurs when creating VLAN over redundant interface on SOC5 platform.

1146580

Traffic stats aggregation issue occurs when using M ports in FGSP setup.

1147340

Duplicated interface entries occur in FortiGate HA configuration merges when the same interface is processed across multiple cycles without successful resolution, causing persistent sync failures and redundant log entries.

1149342

BGP flapping occurs when concurrent IP address management causes unexpected source IP usage on outbound connections during FortiGate VDOM migrations.

1153360

Counter values fail to match totals and may overflow during continuous clearing in certain FortiGate models.

1154348

CLI allows assigning VLAN interface of M port LAG interface to data VDOMs when configuring VLAN interface on top of M port LAG

1159714

Unexpected behavior observed on certain FortiGate models when configuration changes follow enabling "cfg-save revert" due to unresolved netdevice references in the np7 driver.

1161584

An error condition occurs in the APACER NVME controller during hardware testing on FortiGate-201G.

1170088

RADIUS authentication fails when connecting to Secondary Chassis Slot 2 to 4.

1170524

SSH login attempts via special ports fail for VDOM admin users with access to 'mgmt-vdom' on SLBC FortiController models.

1171521

In some cases, after a FortiGate 7000F chassis restart, an FPM may hang while logging in, resulting in the FPM being out of synch with the chassis. This happens because confsynchbd becomes stuck after receiving a management heartbeat from the primary FIM.

The issue can occur any time the chassis restarts, including after a firmware upgrade.

1172378

Blades go to dead status when upgrading due to a cross FIM issue.

1172922

SDN dynamic address synchronization flaps or fails when SDN connectors are frequently enabled and disabled.

1173230

Traffic loss occurs when FIM on standby unit is rebooted in HA A-P setup on 7KE model.

1174680

CPU usage issues observed during IPsec tunnel formation over PPPoE interfaces.

1178954

ICMP packet offload failure occurs when passing through VPN over aggregate interface.

1183735

Graceful upgrades lead to unintended primary claiming by FortiGate units during HA resynchronization.

FortiView

Bug ID

Description

1133164

Subnet filtering fails for firewall users due to partial API support.

1138980

Read-only profile admin user tries to change FortiView source time range , and it is logged as edit by system admin in system events.

1139219

The Quarantine widget experiences delays when loading the complete IP list.

1141357

Session counts beyond a certain limit are not displayed on FortiView, device icons are missing from FortiView pages, and quarantine actions do not reflect in the Log Viewer.

GUI

Bug ID

Description

264694

When a firewall user logs in via the GUI using RADIUS with FortiToken, no accounting request is generated.

853352

When viewing entries in slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100K entries.

919473

Network > Interfaces: When there is an IPsec tunnel bound to an interface, Interface Integrate for that interface fails.

1051993

Incorrect 'Cancel Fabric Upgrade' button display occurs when full fabric upgrade failed or complete.

1053139

Login failure messages appear in the GUI when administrators log in within an air-gap environment.

1110950

An error condition in httpsd occurs when using JSON array sort compare.

1119321

Authentication enhancements and optimizations using HTTP Admin Auth Daemon

1126162

Hostname pop-up window shows "failed to retrieve info" error in System > HA page.

1126975

Timezone offsets are displayed in UTC when a timezone is set.

1129254

Unexpected behavior occurs when attempting to save L2TP dialup tunnel configurations using SD-WAN members on some FortiGate models.

1130636

The FortiConverter window reappears after closing even when Don't show again is selected.

1131500

Some bandwidth interface widget not show historical information.

1137821

Failed to open CLI console from downstream FGT GUI with error "Connection lost." with SAML SSO admin login.

1138359

Can't open CLI console when logging in with SSO account.

1139922

Cannot rename authorized FortiSwitch.

1140317

FAP/FSW registration status appears vacant on Firmware & Registration page.

1143611

User/groups objects disappear after editing firewall policy.

1145475

Multicast traffic dropped when add/remove interface bandwidth widget on dashboard.

1146621

When editing an SSL VPN policy in the GUI after creating the policy in the CLI, user/group is not requested.

1146967

Failed to update prompt occurs when moving interface using Interface Integrate feature.

1148930

Exported FSW ports to tenant VDOM are not displayed on the GUI when the tenant VDOM has a FortiLink, causing virtual switches to be filtered out due to the lack of a fsw-wan1-peer attribute.

1148959

An error condition in httpsd occurs when fetching data from cmdbsvr fails.

1150591

Node.js encounters an error when attempting to read the property from a null value, causing unintended behavior on some FortiGate models.

1151118

Default Super Admin creation notification is not triggered when logging in through the GUI with accprofile-override enabled

1151414

Unable to connect to FortiSwitch CLI via Diagnostics and Tools.

1152464

The DHCP reservation widget incorrectly validates based on the subnet instead of individual IP addresses.

1152580

FEXT dataplan display issues occur in FortiGate GUI when controlled by FEXT-101G

1152737

When device-identification is enabled, an incorrect IP address is observed when a device gets updated with no IP address

1152849

Connection loss occurs when accessing FortiGate Cloud remote access.

1153294

Custom HTML content does not render correctly on login pages when configured through the FortiGate web interface or CLI.

1154487

GUI page times out when never timeout option is enabled for the admin profile.

1156109

Console prints error when logging in to the GUI with dns ssl-certificate set to Fortinet_Factory.

1162818

Proxy policy GUI page keeps loading when using user.certificate in ZTNA proxy-policy.

1163464

Read permission occurs when logging in with read-write accprofile if FortiGate is managed by FortiManager.

1165306

FortiSwitches not showing in alphabetical order in GUI occurs when viewing FortiSwitch Ports.

1165693

An error condition occurs in the GUI sniffer when using advanced syntax.

1166936

Failed to load value occurs when viewing PoE devices on FortiOS GUI.

1169584

An error condition in Apache occurs when the ACME renewal thread interacts with the main thread.

1170203

GUI access issues occur when upgrading from B3561.

1172647

Filtering services become unavailable when Anycast is enabled.

1175241

After performing a search in the policy list, sections cannot be collapsed, causing delays in operations.

1178020

Administrative-access option FMG-Access is not available on the GUI when FIPS-CC mode is enabledj.

1179698

GUI error when editing the IPsec tunnel when the VPN name contains "/"

HA

Bug ID

Description

794395

The secondary unit in an HA cluster would display messages indicating that external resources were not in sync, despite the resources being correctly synchronized.

984306

Session synchronization fails when encryption is enabled in FGSP with IPsec VPN setup.

1017177

A WAD processing issue causes the SNMP to not respond in a HA cluster.

1080655

HA synchronization fails after configuration changes on FortiGate devices due to improper handling of a hasync flag in the fgfmd daemon.

1115004

An error condition in the daemon occurs when upgrading an HA cluster with standalone-mgmt-vdom enabled.

1126274

VDOM is created unexpectedly when changing VRRP priorities on multiple interfaces if standalone-config-sync is enabled.

1133589

HA cluster fails to form when FIPS-CC is enabled.

1135008

When link monitor fail, initial HA cluster failover doesn't happen immediately until pingserver-flip-timeout expires.

1136097

HA state may become out of sync due to a race condition caused by missing local-in ipropes.

1141528

High CPU usage occurs when FortiGate secondary unit is started in Azure vWAN SD-WAN NGFW with Dynamic rerouting.

1142161

Federated upgrade failure occurs when upgrading in an HA cluster

1143361

Downtime occurs when upgrading HA cluster with HA encryption or authentication enabled due to HA communication being sent through IKE tunnel when tunnel is not ready

1143791

The heartbeat interface default route is lost and HA fails to sync when changing the interface mtu-override option.

1148845

LDAP authentication fails when ha-direct is enabled due to confusing logic between which interface takes priority when interface-selection is also used

1151668

Interface bandwidth widget doesn't display HB and Managed port.

1154466

Traffic forwarding issues occur when FGSP failover happens.

1160292

FFDB version sync issue occurs when updating on-demand ffdb in HA environment.

1162432

Split brain occurs when renaming IPsec phase1-interface in a HA cluster with a lot of VDOMs.

1165798

An error condition in FortiMQ occurs when HA AA is configured and malware-stream scan is enabled on primary FortiGate.

1168328

Mgmt interface is lost when joining a device to a cluster with system dedicated-mgmt enabled.

1170763

Device synchronization issues occur when removing a device from FortiManager

1171987

HA not synced after modifying onetime schedule when cfg-save is manual.

1172590

An error condition occurs in FortiGate when running the diag sys ha nonhaconf command on the secondary node in an HA cluster.

1178208

VLAN HB link monitor stops working when HA Group-ID is set above 255.

1179351

FortiGate failed to load the private keys for factory certificates to fgfmd due to incorrect classification

1179821

Intermittent connectivity loss occurs to HA secondary management IP after upgrade to v7.4.8.

1180636

Session filter issues occur when adding custom service filters with different port ranges under cluster-peer session sync.

Hyperscale

Bug ID

Description

1089281

With FG-480xF/FFW-480xF using npu-group other than "0" with log2host with around ~1M CPS could result in NP chip getting stuck.

1141632

After HA failover, syslog packets not sent out from new HA master when using NAT46/NAT64 policies.

1143144

Both HW log(ps) rate and log(pm) rate show in dia sys npu-session stat when set log-mode per-nat-mapping is enabled.

1150073

For previous versions of hyperscale FortiOS, FGCP HA clustering with hardware session synchronization with config vcluster-status disabled allowed you to monitor hw-session-sync-dev interfaces. FortiOS 7.6.3 changed this behavior, and you can no longer monitor hw-session-sync-dev interfaces.

When upgrading to FortiOS 7.6.3 if your HA configuration includes monitoring hw-session-sync-dev interfaces, the upgrade will fail.

1150863

Unintended session deletion may occur after FGSP failover due to a dirty Rsession.

1155548

With host logging (log2host) enabled, session counts may begin to rise after a few days of operation. This rise in session count can reduce throughput and CPS performance.

1159964

Incorrect duration of hardware sessions occurs when the system is up for a long time.

Intrusion Prevention

Bug ID

Description

1110788

Memory usage issues caused by configuration changes or rule loading.

1117043

Fatal errors occur when the IPS engine sends requests with zero-length data segments to IPSA.

This issue only affects physical FortiGate models with the following IPS engine versions:

  • IPS Engine version: 7.550 - 7.567

  • IPS Engine version: 7.1019 - 7.1039

To determine the IPS Engine versions, use the command:

get sys fortiguard-service status | grep 'IPS/FlowAV Engine'

1122188

Internal diagnostic commands fail or delay when ipsmonitor processes each request sequentially due to sequential forwarding to IPS daemon processes.

1149760

Inline-IPS fails to match sensor locations for the "Web.Server.Password.File.Access" signature because it incorrectly reverses traffic direction definitions.

1158024

Packet drops and lower CPU utilization on FPC blades when using IPv6 traffic with np-accel-mode enabled and auto-asic-offload.

1158524

Unexpected behavior observed in the IPSEngine when a DNS packet matches a policy with DNSFilter and Safe Search enabled.

IPsec VPN

Bug ID

Description

842821

Accounting information is not sent to RADIUS when EAP and 2FA authentication are enabled.

979591

Changes to IPsec phase1 fragmentation settings do not take effect immediately when made on dynamic configurations.

995912

VPN tunnels exhibit instability following an upgrade, with processes stuck during NP7 debugging due to improper prioritization of certain packets.

1045098

IPv6 traffic is blocked on new configured IPsec VPN over loopback interface, need reboot to fix it.

1063528

Incorrect MTU settings prevent fragmented packets from being properly offloaded in IPsec tunnels, causing high CPU usage on FortiGate models.

1063737

High CPU usage occurs when using IPsec tunnel with fragmented packets and UDP frame size of 1600B.

1068626

SOC4 platform IPSec traffic may stop in specific corner cases due to the IPSec outbound process becoming unresponsive.

1101897

Abnormal spikes in VPN traffic sent bytes occur when counters roll back due to race conditions.

1116128

Traffic disruption occurs when IPSec engine is offloaded.

1128662

BGP peering fails to establish when a race condition occurs between FortiGate OS and NPU driver during IPsec SA updates for dynamic hub-to-static spoke VPNs.

1133207

Tunnel establishment fails for multiple FortiGate clients when using DHCP-over-IPSec dial-up VPNs during high concurrent connection attempts.

1135490

Static route towards remote side of IPsec tunnel becomes inactive when tunnel IP address is configured.

1140823

IPsec tunnels become stuck on spoke np6xlite, causing ESP packet drops after extended operation due to improper vifid formation during multiple rekey operations.

1141865

Decrypt counters do not update when SA is offloaded.

1145219

IPsec tunnels drop unexpectedly during rekeying when using certificate authentication with multiple dialup gateways and peer-initiated SA_INIT requests.

1145391

IPsec VPN tunnel fails to establish when QKD is required due to failure to complete SSL handshake with the QKD server

1145411

Changing the ip-fragmentation setting on dynamic IPsec phase1 does not take effect immediately after modification due to an issue with the change handler function in certain FortiOS builds.

1147023

VPN traffic halts unexpectedly on the spoke when FEC is disabled during connection cleanup after failed phase 1 negotiations, affecting dynamic tunnel handling.

1149340

Fragmented packets are not sent out on vpn-id-ipip IPsec tunnel when npu-offloading is enabled.

1152486

Unable to select policy-based IPsec tunnel in the firewall policy for SD-WAN member while configuring in GUI.

1153363

Intermittent disruption occurs on ipv6 route lookup when configuring IPsec with FIPS-CC enabled.

1153984

Authentication error occurs when IPSEC-IKEv2 tunnel is configured with FortiToken Cloud.

1156722

DNS suffix search issues occur when using IKEv2 phase1 dialup gateways with mode-cfg enabled.

1157885

Shaping parameter is not shared during ADVPN spoke to spoke negotiation.

1162270

Secondary IPsec tunnel cannot come up after primary tunnel is down and config change when "set monitor" is configured under phase1.

1162563

An error condition in the system occurs when creating more than 75 VPN tunnels with Egress Traffic shaping enabled.

1162740

Multicast traffic above 1350 bytes does not flow through the IPsec aggregate tunnel when using pre-encapsulation.

1163234

IPsec negotiations fail when auth-keepalive is enabled with SAML authentication.

1165581

Certificate validation issues occur when mandatory-ca-verify is disabled in IPsec VPN configuration.

1167952

Packets with payload larger than 10K and smaller than 15K are dropped when using IPsec tunnel as egress interface with nTurbo enabled.

1168556

IPv6 routing entries remain after iked restarts.

1169860

L2TP connections fail when L2TPD experiences internal errors while attempting to create tunnels for clients.

1170094

An error condition in IKE occurs when using TCP transport.

1172040

Returning packets take a different path when TCP transport is used with multiple default routes in the routing table.

1173228

During modeconfig setup, an IPSec IKEv2 dialup tunnel may install a default route when no IP address can be allocated from the pool.

1179347

Intermittent IPSec tunnel disruption occurs when upgrading to FortiOS 7.4.8 with FIPS enabled in HA mode.

1181552

An error condition in IKE occurs when using TCP.

Log & Report

Bug ID

Description

611460

On FortiOS, the Log & Report > Forward Traffic page does not completely load the entire log when the log exceeds 200MB.

1005223

Unmatched custom service name appears in traffic log when source port range is defined in custom service.

1087235

Only last 24 hours of Forward traffic log are been downloaded while trying to download logs from the last 7 days.

1087534

Page loading issues occur when loading a high number of logs.

1100945

The "Resolve Unknown Applications" feature in the GUI Log Viewer is not functioning as intended.

1113588

FortiGate prompts error "Fetching data from Disk is taking longer than expected. Suggest trying a different log source or check the availability of Disk." when viewing logs for the last 7 days from disk or FortiAnalyzer.

1116108

Intra-zone Local logs are missing when intrazone allow is enabled.

1125032

Export option fails when 500+ logs are present

1127636

Unnecessary log generated when disabling an interface.

1128940

Security Rating summary log displays incorrect counts when triggering a security rating check.

1141436

FortiGate device enabled with FIPS-CC mode sends an incorrect build number (0523) to FortiGate Cloud.

1141733

Traffic interruptions occur when revisiting the forward traffic log page during searches with applied filters.

1142836

Broadcast traffic is no longer logged when local-in-deny-broadcast setting is disabled.

1146443

Inaccurate Netflow reports occur when ICMP long live sessions exceed the active timeout value.

1148101

Logs fail to appear in FortiAnalyzer, and FortiView sources are missing from the Dashboard.

1151300

Logs are not displayed in FortiGate CLI when using free-style filter with timestamp and FortiAnalyzer as data source.

1168738

Syslog packets are not sent when log server IP is not configured.

1184366

Incorrect logs are displayed when applying a destination filter in Log Viewer for remote log sources FAZ and FGT-cloud until a hard refresh is performed.

Proxy

Bug ID

Description

859182

WAD encounters an error condition when configuration changes affect certificate verification processes with Crypto KXP enabled.

1015721

An error condition occurs in WAD during stress testing.

1019504

An error condition occurs in WAD during high HTTP traffic.

1107594

Slow website loading occurs when using certificate inspection with proxy inspection-mode in HA active-active mode.

1118701

Connection issues for Kentik application using http2 gRPC occur with proxy and deep inspection.

1124557

An error condition occurs in WAD when wad-restart-mode is set to time and wad-restart-start-time / wad-restart-end-time are configured.

1125531

Timeout occurs when server certificate is expired.

1133100

Memory usage issues caused by WAD leaking SMB2 session objects when clients close connections with a Kerberos status of KRB_AP_ERR_MODIFIED.

1141948

Certificate inspection profiles differ across VDOMs when importing policy packages from FMG, caused by inconsistent default values for unsupported-ssl-version in certificate-inspection profiles between different FOS releases.

1144571

TLS handshake fails when Client Hello is split across two packets in proxy-mode, and the packet length is less than 256 bytes.

1146601

With proxy inline-ips, a memory leak occurs on the WAD daemon, leading to conserve mode.

1155170

Memory usage increases unexpectedly during high load when processing WAD-related tasks.

1155858

RD Gateway fails behind HTTPS Virtual Server when using WebSocket upgrade.

1159963

Expired server certificates are issued when Deep Inspection is enabled due to improper handling of certificate cache renewals.

1161940

An error condition in proxyd occurs when migrating from 500E to 901G.

1173291

Memory usage issues caused by missing certificate memory free operations during stress testing.

1177929

Memory usage issues occur in WAD when handling a large number of sessions.

REST API

Bug ID

Description

1159460

Current bandwidth value is not sent to FMG for shaping graph when using FortiOS API.

Routing

Bug ID

Description

1036123

BFD for BGP takes interface BFD config instead of multi-hop config when BFD is enabled on both OSPF and BGP.

1097855

IPv6 traffic may be sent to the wrong destination interface or route, causing connectivity issues.

1097939

Console print out "/bin/cmdbsvr...node=system.health-check-fortiguard.name" error messages when restore a config.

1142290

An error message appears in FortiGate when attempting to add the ssl.root interface to a route-map via the GUI.

1142955

High CPU usage occurs when link monitor daemon fetches session counts on every interface during REST API calls.

1147497

Slow performance and network issues when surfing to Internet from GRE tunnels.

1150878

The IPoE tunnel interface cannot be selected in the Interface Bandwidth widget.

1152976

Spokes using remote-as-filter with 4-byte ASN cannot establish BGP neighborship.

1156431

PIM error when receiving PIM Assert with SSM enabled during HA failover.

1164316

IPv6 route issues occur when set delegated-prefix-route enable.

1165424

The behaviour of the command diagnose ip router bgp <module> <enable | disable> is incorrect. Turning on debugging for one of the modules turns on debugging for all modules.

1166008

VRRP version 2 failure occurs when adv-interval is configured in milliseconds Workaround: Configure the adv-interval at 1025.

1171689

Incorrect route selection occurs during BGP redistribution with route maps due to improper handling of parent protocol distances.

SD-WAN

Bug ID

Description

1130683

Shortcut can't be triggered in certain cases due to the error "found duplicate in ike_check_update_addr_key".

1147720

Traffic forwards to the unexpected egress interface when duplicate SD-WAN rules exist in the proute list in the case that priority-zone in sdwan service has only one sdwan member

1147727

Encapsulated traffic of GRE tunnel interface over VNE tunnel egressed wrong interface after reboot

1153992

Event log used wrong reason that packetloss over the threshold when SLA fails due to consecutive probes failed

1155927

SD-WAN Service events are not logged in SD-WAN Events when using SD-WAN rules in standalone mode.

1159877

Hash-mode remains visible when SD-WAN service mode is changed to priority.

1027225

New shortcuts fail to trigger when existing shortcuts experience high packet loss in priority mode.

1142171

Health check status change behavior occurs when recovery time is set to 240 and interval is set to 500ms.

1153432

Downtime occurs when using OSPF with LAN during shortcut establishment and tunnel failover.

1164937

Incorrect outbandwidth calculation occurs when IPsec tunnel interfaces are used in SDWAN configuration.

1167276

All participants of SLA name become unavailable when the check interval is set to 15 seconds.

1181497

Incorrect data type occurs when using OID fgVWLHealthCheckLinkBandwidthBi.

1187007

GUI issues occur when accessing SDWAN rules and Performance SLA menus.

Security Fabric

Bug ID

Description

1085248

FortiGate encounters CPU and memory usage issue when loading 20 large external threat feeds (100K entries each).

1110643

Security Fabric issues occur when running FortiOS 7.4 or 7.6 with 200G.

1117104

Scheduled automation incorrectly triggers reschedule after reboot when using specific time zones and NTP configurations.

1118086

An error condition occurs when enabling CSF root on 50G series devices.

1145138

Automation stitch fails to shut down a specific port on the secondary FortiGate during HA failover due to incorrect script environment settings.

1149817

Security Fabric > Physical Topology: FortiLink Tier 2 switch shows directly connected to FortiGate on Security Fabric > Physical Topology page.

The correct topology can be seen on the WiFi & Switch Controller > Managed FortiSwitches > Topology view.

1150382

Security profile names containing two forward slashes (//) cause the webpage to become unresponsive when attempting to edit.

1165624

Topology page load failure occurs when CSF is disabled.

1166189

When using the OCI SDN connector, dynamic IP addresses are not fetched correctly if the target compartment contains more than 100 VNICs.

1180555

Threat feed connections fail during SSL handshakes when server-identity-check is enabled for HTTPS downloads in FortiOS.

1210303

APIC device overload occurs when FortiGate logs in multiple times without proper logout.

Switch Controller

Bug ID

Description

961142

An interface in FortiLink is flapping with an MCLAG FortiSwitch using DAC on an OPSFPP-T-05-PAB transceiver.

1075365

Upgrade or restart of FSW fails when FortiLink is in HTTPS mode

1105000

Aggregate FortiLink went down, need to manually down/up the interface.

1114032

The GUI becomes slow or unresponsive when transceiver-related API requests fail.

1134306

VLAN configuration mismatch occurs when configuring LAN Extension and VLANs locally on FEX.

1135460

Health status becomes unknown after renaming a switch in the switch controller on some FortiGate models.

1137075

In the WiFi & Switch Controller > Managed FortiSwitches page, the Topology view shows the link between FortiSwitch units with a dotted line instead of a solid line.

1137213

Extension device registration fails through GUI when FortiCare agreement acknowledgment flag is reset after updates.

1138263

FortiSwitch port configurations fail to update and GUI display issues occur when user-info process overloads system resources with excessive connections.

1138430

Increase managed-switch.switch-id to more than 16 characters

1144076 High CPU usage occurs in cmdbsvr when FortiLink is enabled and FortiLink interfaces are connected to the firewall.

1153868

Sync errors occur when renaming a FortiLink switch with special characters.

1155546 Duplicate entries occur in the switch-controller managed-switch list when renaming a managed-switch.

1164685

Local MAC addresses are filtered out from being added to user device list when mab-entry-as dynamic mode is enabled on Fortiswitch.

1174647 Fortilink connections may not display correctly in the FortiGate GUI Topology view when using MCLAG aggregation.

1183135

Filtering by allowed VLANs fails to display expected results when using certain FOS versions.

System

Bug ID

Description

900936

The fnbamd service may terminate unexpectedly due to erroneous memory handling during certificate authentication, if DNS responses include both IPv4 and IPv6 addresses and one (for example, IPv6) is unreachable.

908309

LLDP packets not received on management interface when LLDP is enabled on certain FortiGate models.

973034

LACPDU packet drops occur when FortiGate fails to reliably send required packets due to incorrect npu_tc assignment for hi-priority traffic.

992323, 1056133, 1075607, 1082413, 1084898, 0992323

Traffic interrupted when traffic shaping is enabled on 9xG and 12xG.

996863

Automatic firmware update email alerts triggered after each reboot on FortiGate.

1029459

sflowd error condition occurs when sflow sampling is enabled without a collector configured.

1048684

The FortiGate Internet Service Database (ISDB) update mechanism fails on a 100E FortiGate model due to insufficient memory allocation.

1057094

Disabling GRE auto-asic-offload on a FortiGate model causes traffic to be dropped due to unrecognized GRE tunnels, likely because the kernel fails to process them without proper configuration post-disabling.

1065869

SCTP CRC check option is not available on NP7lite platform like 91G/121G.

1071229

Ping reply packets are dropped after two successful requests when using VXLAN over IPsec on FortiGate.

1075340

Aggregate link down occurs when speed is set to 10000auto after upgrade to v7.4.5.

1082891

FortiGate reboots immediately after changing ull-port-mode to 25G without a confirmation prompt.

1095801

Error "Fail to del default npu-vlink setup" is shown when changing the hostname.

1096384

Warn user when restoring config from a different firmware version.

1096537

High CPU usage occurs when making configuration changes with a large number of policies.

1099770

NP7 drops encrypted GRE packets that have Checksum bit set (1) due to invalid checksum.

1107270

Communication over VXLAN is lost after upgrade on NP7 platform.

1113436

Packets are dropped when using auto-asic-offload with 802.1AD over LACP on FortiGate due to missing MAC address assignment on QinQ lag interfaces.

1113651

An error condition occurs in the simulator during stress testing.

1114298

FortiGate Cloud remote login triggers 2 admin login events (1 successful and 1 unsuccessful for PKI admin).

1117005

CPU spikes and management access issues occur on certain FortiGate models post-upgrade when IPsec Phase 1 NPU-offload is enabled during maintenance.

1121522

Memory leak in slab causes the system to enter memory conserve mode. The issue occurs due to out-of-order log packets and incomplete session scrubbing, resulting in residual entries in the log2host table.

1121548

Enabling "device-identification" also gets endpoint information even though intermediate router exists on FG and endpoints.

1122741

Two duplicate FGFM sessions could be triggered when connecting to FortiGate cloud. And the first FGFM session that enters in GET_IP state kills the other FGFM session which will schedule a FGFM session restart two minutes later.

1130803

Port13-20 speed setting changes to 1000full after FortiGate 10xF reboot.

1131516

CRC error count reset issue occurs when using the diag netlink interface clear command.

1132414

When connecting port5-14 on 3201F with third-party switches using optical transceivers, the 1gig link is down.

1133575

The 100M speed option is not available for wan1 and wan2 interfaces during configuration in certain FortiGate models.

1135440

Unexpected behavior occurs when changing interface mode or static route through an IPSEC-Tunnel when emac vlan interface based on npu-vlink is used

1137218

VXLAN traffic uses primary IP address instead of secondary IP address when configured vxlan remote-ip with secondary IP.

1138155

DNS (TCP853) fails until idle timeout when link monitor failover occurs in dual internet connection.

1140755

When attempting to delete a software switch interface, it becomes permanently hidden due to an unreverted temporary flag.

1141832

Interface inbound/outbound information is not displayed on the bandwidth widget and CLI when using VLAN interfaces with NP6 platform.

1141907

Unexpected behavior occurs when deleting IPv6 reflect session.

1142591

Unexpected behavior occurs when high load IP fragment traffic is sent through an IPsec tunnel with vpn-id-ipip encapsulation and offloading enabled.

1142782

GRE tunnel traffic is limited when sessions share same local/remote IPs, causing them to be assigned to single CPU core.

1142785

False SNMP alerts occur when a non-installed power supply unit is detected

1142805

Cannot set source IP for FortiGuard when a non-root VDOM is set.

1146354

The network interface settings page fails to load on certain FortiGate models when the admin profile does not have the System > Configuration > Read/Write permission.

1148843

Unstable LTE 4G connection occurs when using IPv6.

1149508

WAN interface goes down when share-port medium type changes to 'copper' after upgrading FortiGate-80F-DSL

1149814

An error condition in WAD occurs when executing log messages with invalid node pointers.

1151313

On NP7 models, gtp tunnel list counters don't increase when restoring configuration file with "gtp-enhanced-mode enable".

1152059

Device information is not detected when device-detection is enabled in ARM based models

1152638

FGT still sends reset packet when drops TCP SYN packets with ident-accept enable on wwan interface after reboot.

1153004

APN profile not updating when configuring Verizon APN.

1153442

Concurrent sessions drop significantly when low-end FortiGate models have low free memory.

1153983

Registration status remains unknown when re-adding Fortimanager IP after it was lost.

1154158

DHCP issue occurs when configuring hardware switch interface in A-P HA mode.

1155410

High memory consumption occurs when Node.js encounters catastrophic failures and creates excessive logs.

1156561

NP7lite platforms might encounter high softirq issue and stop processing traffic after running for one month.

1156785

Device recognition issues occur when device-detection is enabled for some Apple devices.

1157490

Temperature is out of range with unreasonably high value.

1158975

FortiGate does not establish VNE tunnel caused by a failure to commit DNS servers to the CMDB after receiving a DHCPv6 information request.

1159425

Unused power supply log appears in diagnose alertconsole list when a redundant power supply is not used

1160215

An error condition occurs in snmpd on FortiGate-VM64-AZURE approximately every 1.5 hours.

1162489

The SFP WAN1 and WAN2 ports on the FGT-80F device remain down after a reboot when the speed is set to 100M.

1163292

VDOM expansion issues occur when upgrading license on FortiGate-201G.

1163814

Memory usage issues occur when newcli processes are not deleted after their parent sshd process died.

1164174

Configuration loss on FGT-60F when FortiGate enters extreme conserve mode

1164761

SFP+ direct attach cables are shown as "compliance is unspecified" by the "get system interface transceiver" command.

1165059

Unexpected behavior in system occurs when executing factory reset on FortiGate-70F.

1165172

CPU usage issues caused by receipt of packets longer than 65535 octets.

1166455

TCP packet drop occurs when sending traffic over VLAN+redundant port

1167234

Unexpected behavior occurs when loading build B3553 on FortiGate-101F.

1167426

High CPU usage occurs in the linkmtd daemon when large traffic is present.

1168786

100G ports turn up after reboot when administratively down on platforms with Marvell switch, such as FortiGate 480xF.

1168792

Network detection issues occur when the LED is on during diagnose hardware tests.

1170291

WWAN interface fails to get IP address when 'auto-connect' feature is enabled.

1170464

Memory usage issues caused by low memory availability on FortiGate-51G

1172295

FortiGate does not autoupdate router objects in full such as key-chain, route-map, and prefix list, causing FMG to purge the config during installation.

1175384

"Partition ImageEXT4-fs (sda2): couldn't mount as ext3 due to feature incompatibilities" when running "diagnose sys flash list"

1177037

System events are not generated when FortiGate acts as a DHCP client.

1178017

10G Copper interface fails to come up when directly connected after a fresh setup

1178199

SNMPD access issues occur when increasing VM memory.

1178583

DHCP relay strips DHCP END Option (255) when relaying DHCP packets.

1185286

An error condition in Newcli occurs when executing the get system fortiguard-service status command.

1187981

DDOS policy not properly installed in kernel on FortiGate 120G and 121G.

1190222

Incompatibility occurs when using 8G eMMC on 3XG/5XG/7XG/9XG models

1190245

Memory usage issues caused by renaming VPN IPsec phase1-interface during config change.

1193889

Certificate error occurs when connecting to FAZ via SSH

Upgrade

Bug ID

Description

1130034

Obsolete system.autoupdate.tunneling is removed when configuring system fortiguard.

1130655

License validation issues occur when system.autoupdate.tunneling is not migrated to system.fortiguard after upgrading.

1158947

Manual patch upgrade not allowed when system has invalid upgrade license

1160916

Password history settings are lost during upgrade from 2731 to 2794.

1171564

System halt occurs when upgrading from v7.4.8 GA b2795 to v7.6.4 b3563

1172979

Upgrade failure occurs when upgrading from v7.6.4 to v8.0.0 due to CMDB request issue.

User & Authentication

Bug ID

Description

1112301

CPU usage issues observed during certificate authentication with multiple DNS replies.

1118212

Captive portal authentication fails after FortiToken push notification approval during radius authentication with FAC for remote groups.

1122979

Custom NAS-ID not sent to RADIUS server when testing connectivity via GUI.

1124183

Guest user sessions persist in the FortiGate authentication list despite manual expiry, enabling continued network access.

1134368

LDAP server becoming unreachable 'set mfa-mode subject-identity' is configured under the user peer settings, or ha-direct enabled with source-ip.

1137727

Delays in SSH login verification occur on some FortiGate models when hashing passwords, and immediate failure messages are returned for invalid usernames.

1146635

Fnbamd issue during certificate authentication when multiple DNS replies contain both IPv4 and IPv6 parts.

1147049

Device hostname is not displayed when device identification is enabled and mDNS includes the device UUID.

1156903

CLI authentication test fails when RADIUS server has require-message-authenticator setting disabled.

1160080

User deletion occurs when upgrading with invalid password-history characters.

1163152

RADIUS stops working on secondary unit when HA secondary connects to a RADIUS server using UDP.

1193697

Emails with FortiToken codes are not sent due to an SSL error when using SMTPS port 465.

VM

Bug ID

Description

1125437

The "set distance" option under interface configured as DHCP client doesn't work on VM.

1146370

AWS bootstrap is unable to parse IAM role profile properly due to the length.

1146634

IfLinkUpDown SNMP trap is not triggered on FGT_VM64_KVM using the virtio driver when an interface is brought up or down.

1157674

Incorrect system time occurs when FortiGate-VM64-GCP boots up on GCP.

1161380

License becomes invalid when system time is incorrect on FortiGate VM64-GCP devices.

1172050

Packet-rate information is missing for some interfaces when running the diagnose netlink interface packet-rate command on FortiGate-ARM64-AWS.

WAN Optimization

Bug ID

Description

1160444

Global config wanopt content-delivery-network-rule is deleted when restoring VDOM config.

Web Filter

Bug ID

Description

1145481

URL filter exemption fails when adding regex entries to URL filter if newly added regex entry contains invalid perl style regex.

1150232

Threat feed URLs are not blocked since Sandbox block list file version check always fails and aborts loading other types of URL lists, including external-resource category URL list.

1156789

Web filter settings category name, block screen category name, and log category name are translated into different Japanese when using web filter profile on FortiGate.

1177015

Webfilter logs are not generated when https-replacement-message is disabled in proxy-policy with DPI.

WiFi Controller

Bug ID

Description

1001211

Add optional antenna support for K-series models 443K and 243K.

1018895

Clients on local-bridging SSIDs appear offline despite having active traffic when acd-process-count is 2, caused by the AP failing to report client IPs to the controller.

1063976

Empty SN values occur in AP DTLS session timeout messages.

1126824

When WiFi client enables VPN endpoint, VPN traffic cannot pass through NP6Xlite FGT models.

1131094

The iPhone 16 fails to connect to a WPA3-SAE SSID on FWF-61F due to incorrect ordering of RSN and RSNXE parameters during the authentication handshake.

1145326

In non-root VDOM, device fails to authenticate when MPSK is used with an external RADIUS server.

1147416

Connection fails for Samsung S22 devices when using WPA3-SAE from local-radio on certain FortiGate models.

1151713

FortiAPs may go offline when memory pool of WiFi daemon cw_acd is fully occupied and not released properly. cw_acd debug constantly show ERR: NO MEM for USER_LOCAL_MSG

1161023

Groups of Wi-Fi clients are lost after roaming to a different AP, causing unintended behavior in network policies.

1174782

The client fails to authenticate and gets disconnected from the access point when initiating Fast BSS transition (FT) roaming with MAC authentication enabled.

1177859

When FWF local radio is in non-root vdom, wifi users encounter connectivity issues.

ZTNA

Bug ID

Description

1089157

An error condition in WAD occurs when adding a ztna-ems-tag to a proxy policy with an active ZTNA session

1102925

Memory usage issues caused by accessing multiple websites through WAD

1118878

Traffic bottleneck occurs when syncing 120K FCT endpoints from EMS to FortiGate.

1134649

WAD cannot re-verify new ems-tag after an ems-tag update for HTTPS access proxy, causing existing sessions to remain active despite matching a deny policy.

1135441

CLI error occurs when configuring SAML server in api-gateway with access-proxy6 and vip6 configured.

1139201

Internal resources are inaccessible via IP or FQDN when using agentless ZTNA Access proxy-portal with apptype web on FortiGate.

1159018

ZTNA agentless not working on FG-90G devices.

1172396

The Certificate Information field in the replacement message shows incorrect information when ZTNA access proxy is configured to accept empty cert.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

1112620

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-25255

1126271

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-25249

1132094

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-31514

1172008

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-58413

1173156

FortiOS 7.6.4 is no longer vulnerable to the following CVE:

  • CVE-2025-25249

1174215

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-53843

1177284

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-53844

1179021

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-54821

1184468

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-59718

1188853

FortiOS 7.6.4 is no longer vulnerable to the following CVE Reference:

  • CVE-2025-58903