Known issues
Known issues are organized into the following categories:
To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.
New known issues
There are no new issues identified in 7.2.8.
Existing known issues
The following issues have been identified in a previous version of FortiManager and remain in FortiManager 7.2.8.
AP Manager
|
Bug ID |
Description |
|---|---|
| 1010632 | Floor Map shows wrong AP status and does not show the rest of APs when adding a new AP. |
|
1040365 |
FortiManager is generating false vulnerability reports for certain FortiAPs:
|
| 1076200 |
Policy install fails due to FortiManager installs unexpected changes related to "<wifi_intf> address". Workaround: Create a CLI template with all subnet addresses and assign to device. |
Device Manager
|
Bug ID |
Description |
|---|---|
| 894948 | FortiManager fails to push the FortiAnalyzer override settings to the FortiGate. |
| 973365 |
FortiManager does not display the IP addresses of FortiGate interfaces configured with DHCP addressing mode. Workaround: Disable Addressing Mode from DHCP to Manual in FortiManager Device DB, then Retrieve from FortiGate and IP will be updated successfully. |
| 980362 | The Firmware Version column in Device Manager incorrectly shows "Upgrading FortiGate from V1 to V2" even after a successful upgrade has been completed. |
| 1004220 | The SD-WAN Overlay template creates route-map names that exceed the 35-character limit. |
| 1030685 | Unable to export metadata variables if the metadata's per-device-mapping value is empty. |
| 1062545 | When using the backslash "\" in the preshared key of IPSEC settings, the install may fail. |
|
1063635 |
FortiManager does not support the "FortiWiFi-80F-2R-3G4G-DSL". |
| 1063835 | FortiManager ZTP installation to FortiGate versions 7.2.8
and lower may fail due to differing default "ssh-kex-algo" settings
between FortiManager and FortiGate. |
|
1070943 |
Unable to upgrade the devices via Device Group Upgrade Firmware feature. Workaround: Upgrade devices individually by using the "Device Firmware Upgrade" feature or Create New Firmware Template for single devices or device groups and use the "Assign to Devices/Groups" feature. |
Others
|
Bug ID |
Description |
|---|---|
| 703585 | FortiManager may return 'Connection aborted' error with JSON API request. |
| 777831 | When FortiAnalyzer is added as a managed device to FortiManager, "Incidents & Events" tile will be displayed instead of the "FortiSoC". |
| 1003711 |
During the FortiGate HA upgrade, both the primary and secondary FortiGates may reboot simultaneously, which can disrupt the network. This issue is more likely to occur in FortiGates that require disk checks, leading to longer boot times. Workaround: Disabling the disk check on fmupdate before the upgrade using the following command: config fmupdate fwm-setting set check-fgt-disk disable end |
| 1019261 |
Unable to upgrade ADOM from 7.0 to 7.2, due to the error "Do not support urlfilter-table for global scope webfilter profile". Workaround: Run the following script against the ADOM DB: config webfilter profile edit "g-default" config web unset urlfilter-table end next end |
| 1029677 |
Unable to upgrade ADOM from v6.4 to v7.0 due to global scope error in webfilter profile. Workaround: Rename the "g-default" to "g-test" > save. It can be deleted after that. Once ADOM upgraded, new g-default is created. |
| 1078947 |
Repeatedly testing the URL rating on FortiManager ( |
Policy & Objects
|
Bug ID |
Description |
|---|---|
| 845022 | SDN Connector failed to import objects from VMWare VSphere. |
| 967271 | Installation failed when trying to remove firewall internet-service-name objects. |
| 971065 | When the number of Custom Internet Services exceeds 256, installation fails due to this limitation. |
| 1004929 |
FortiManager removes the Web Filter Profile from the Profile Group for Policy-Based FortiGates. Workaround: Use individual profiles in the policy instead of the profile group. |
| 1005161 |
The policy package status changes for all devices even when an address object is opened and saved without any modifications. This issue is particularly observed in objects utilizing the per-device mapping feature. |
| 1029921 | Under the "Web Application Firewall" security profiles,users are unable to disable the signatures via GUI. |
| 1030914 | Copy and paste function in GUI removes name of the policy rule and adds unwanted default security profiles (SSL-SSH no-inspection and default PROTOCOL OPTIONS). |
| 1037861 | ADOM versions (7.0 & 7.2) do nothave "ie-allow-list" option available to create GTP object. |
| 1076659 |
When policy package configured with policy block, installation to multiple devices may have copy fail errors if combined length of the Policy Block name and Policy name is greater than 35 characters and if the total number of such policies exceeds 1000. |
Script
|
Bug ID |
Description |
|---|---|
| 931088 |
Unable to delete VDOMs using the FortiManager script. Interfaces remain in the device database, causing the installation to fail. |
VPN Manager
|
Bug ID |
Description |
|---|---|
| 784385 |
If policy changes are made directly on the FortiGates, the subsequent policy package import creates faulty dynamic mappings for VPN Manager. Workaround: It is strongly recommended to create a fresh backup of the FortiManager's configuration prior to the workaround. Perform the following command to check & repair the FortiManager's configuration database. diagnose cdb check policy-packages <adom> After running this command, FortiManager will remove the invalid mappings of vpnmgr interfaces. |
| 1042701 | The traffic view page for the full mesh does not display the FortiGate and the external gateway. |