Known Issues
The following issues have been identified in 7.4.3. To inquire about a particular bug or to report a bug, please contact Customer Service & Support.
AP Manager
|
Bug ID |
Description |
|---|---|
| 1028657 | The captive-portal SSID and its configurations cannot be configured via GUI. |
|
1032319 |
Importing AP profiles for FortiWiFi models will cause "Unable to assign template" error. |
| 1032762 | Since FortiOS 7.4.4 now supports the selection of multiple 802.11 protocols and has trimmed the band options, importing FortiOS 7.4.3 AP profiles may result in some bands and channels being un-matched or unset. |
| 1033105 | When importing the CSV file in the Switch & AP manager, all columns show a green checkmark, but clicking "Next" to import is not possible. |
| 1034334 | Channels are not reflected properly for bands in AP Manager and there are missing bands in ADOM 7.4. |
| 1035299 | "Channel 1" under the "Radio-1" is not supported for ADOM 7.0 and 7.2. |
| 1036210 |
AP Manager does not display all supported bands for the FortiAP platform. Hence, FortiAP Bands can't be set on AP Profiles. Workaround: Set the required 2.4 Ghz or 5 Ghz band config from Policy & Objects > Advanced > CLI Configurations > edit the profile and set the band, and then Install. |
|
1040365 |
FortiManager is generating false vulnerability reports for certain FortiAPs:
|
|
1062154 |
Due to a syntax mismatch between FortiGates and FortiManager for FortiAPs, installation may fail. Currently, FortiManager v7.4.3 with ADOM 7.4 only supports the FortiAP syntax of the latest FortiGate version 7.4.4. |
Device Manager
|
Bug ID |
Description |
|---|---|
| 895994 | When using the "where used" feature in Phase 2 quick mode selector, objects do not appear and they can be removed. |
| 960538 |
FortiZTP AutoLink Device Discoverymay get stuck at 10% during the autoLink process (updating device) and subsequently fail. Workaround: Change the discover-timeout by using the following command: config system dm set discover-timeout 15 end |
| 963025 | When using the static route template, the "SD-WAN Zone" does not appear under the Interface column. |
|
980659 |
When adding FortiGates (FWF-80F, FWF-80F-2R-3G4G-DSL,FWF-81F-2R-3G4G-DSL) as model devices, FortiManager may attempt to create a duplicate DHCP server. Consequently, this installation fails due to the duplicate configuration. |
|
1000101 |
FortiManager fails to retrieve certificates that were directly imported into the FortiGate. As a result, FortiManager repeatedly attempts to push a CSR, leading to installation status conflicts. |
| 1000686 | HA autolink failure occurs when LAN interfaces do not exist. |
| 1003899 | FortiManager generates a VPN certificate that is not accepted by the FIPS-enabled FortiGate devices. |
| 1004220 | The SD-WAN Overlay template creates route-map names that exceed the 35-character limit. |
| 1019886 | The columns under Network and VPN may become distorted and unreadable after being created. |
| 1021693 | Incorrect time displays on the SDWAN monitor health check status. |
| 1024581 | Unable to create/remove the "DHCP Reservation" widget for managed FortiGates with a configured DHCP server setting. |
| 1026955 | Configuring BGP communities encounters errors due to improper format on the FortiManager. |
| 1029689 | When configuring/modifying BGP settings in the Provisioning Templates, an error message is displayed. |
| 1029746 | There are "carriage return characters" in the downloaded config files from the Device Manager. |
|
1033653 |
FortiManager is trying to install and configure " Affected FortiGates: Some low-end FortiGates have encountered this issue.
|
| 1034355 | When assigning a provisioning template with Admin Settings configuration, FortiManager changes the hostname of the device. |
|
1038133 |
Prefix list under BGP template does not allow to add "Greater than" or "Less than" value. |
| 1039014 |
The following error has been observed while doing configuration changes in the FortiGate Global system settings. This issue has been reported after upgrading the FortiManager from 7.2.5 to 7.4.3. "Error : datasrc invalid. object: firewall ssh setting.:caname. detail: Fortinet_SSH_CA. solution: datasrc invalid" This issue is mostly observed when the multi-vdom feature is enabled on the FortiGates. Workaround: Change system settings from CLI Configurations instead. |
| 1041440 |
Some FortiGate platforms (FGT-40F and
FGT-60F) do not support the " Workaround:
Use a script on device database on FortiManager to unset
" |
| 1063835 | FortiManager ZTP installation to FortiGate versions 7.2.8 and lower may fail due to differing default "ssh-kex-algo" settings between FortiManager and FortiGate. |
FortiSwitch Manager
|
Bug ID |
Description |
|---|---|
|
1040428 |
FortiSwitch diagnostics tools do not display the cable test diagnose results, device information on Ports, and update Registration status. |
|
1053220 |
Unable to delete FortiSwitches when central management is enabled for FortiSwitch. Workaround: Removing the FortiSwitch on FortiGate and retrieve on the FortiManager. |
Global ADOM
|
Bug ID |
Description |
|---|---|
| 999500 | Unable to configure EMS settings in the Global ADOM. |
| 1005177 | When creating a script to rename the policies on global db policy block by taking their IDs, the error "[Policy id space out of range]" can be seen. |
Others
|
Bug ID |
Description |
|---|---|
| 894219 | The log filter does not function correctly when filtering by FortiGate HA cluster ID instead of the device ID for individual FortiGate units. |
| 968647 |
On the Log View (when FortiAnalyzer is added to FortiManager) changing time filters, first request always fails but second one is successful. Workaround: Use FortiAnalyzer's Log View to view logs. |
| 983359 | The "40F-3G-4G LTE" modem is not listed on the FortiManager's Extender Manager. |
|
988422 |
The installation fails to FortiProxys when FortiManager attempts to set the firewall address object with the associated-interface value of "any". FortiProxy does not support the "any" value key. |
| 988477 | There is not detail output
information when executing "diagnose cdb check policy-packages". |
| 993924 | "Application fmgd" keeps crashing when accessing SDWAN monitor page. |
| 995459 | Not able to fix and delete the
"duplicate ADOM root node" objects after running the "cdb
upgrade" command. |
| 1001748 |
FortiManager does not display data usage for the FortiExtenders under the Extender Manager. |
| 1015890 | Unable to upgrade ADOM from v6.4 to v7.0 due to "switch-controller traffic-policy" error. |
| 1019261 |
Unable to upgrade ADOM from 7.0 to 7.2, due to the error "Do not support urlfilter-table for global scope webfilter profile". Workaround: Run the following script against the ADOM DB: config webfilter profile edit "g-default" config web unset urlfilter-table end next end |
| 1020787 | ZTP Enforce firmware Version doesn't upgrade the secondary cluster member. |
|
1032350 |
FortiManager fails to download Install preview log because the button is greyed out (for both policy package and device setting & device setting only installations). Workaround: Copy the content of the preview. |
|
1034511 |
Unable to upgrade ADOM from v7.2 to v7.4 due to a crash occurring with the assigned FortiSwitch template. Workaround: Unassign all FortiSwitch templates and upgrade the ADOM then create a new model switch. |
|
1035552 |
FortiManager's GUI may crash when users are navigating through DHCP Monitor (Device Manager > Managed Fortigate > Dashboard: Network Monitors). |
| 1036901 | The "Export" button does not function when attempting to export the Security Rating Report under Fabric View. |
|
1047184 |
When the "Allow FortiToken Mobile push notification" policy is enabled in the FortiAuthenticator, the "Token Code" field is not displayed on the FortiManager's GUI login page for manual insertion of the token. It should be noted, the token is received on the phone, and the login completes successfully. |
| 1049457 | When FortiAnalyzer is added as a managed device, users may encounter an issue in the FortiManager GUI when expanding the log details. |
| 1050556 | Unable to fix "adom-integrity" error using "diagnose cdb
upgrade" command. |
| 1055036 | Using Firmware Templates for scheduled upgrades may cause the "fwmsvrd" application daemon to crash. |
| 1055417 | Unable to upgrade the firmware version of the FortiGates in HA cluster by using the firmware template when HA is in-sync status. The failure to upgrade FortiGate HA cluster firmware is caused by a crash in "dmserver" daemon. |
|
1062128 |
After upgrading to the latest available build, the FortiManager GUI displays the warning message: "A new firmware version is available". |
|
1254367 |
FortiManager instances deployed on Azure may lose all data—including configuration, logs, and reports—if the VM is deallocated and subsequently reallocated. This may occur during Azure-level operations such as VM stop (deallocate) or SKU/size changes. Please refer to the Special Notices for more information. |
Policy & Objects
|
Bug ID |
Description |
|---|---|
| 845022 | SDN Connector failed to import objects from VMware VSphere. |
| 897470 | When running the "Policy Check", FortiManager occasionally incorrectly marks policies as shadowed. |
| 970056 | The policy installation fails when FortiManager attempts to apply changes related to the "management address" on the interface of the FortiGates. |
|
971610 |
FortiManager does not able to import the Central SNAT, DNAT, DOS, local-in and traffic shaping policies. |
|
981694 |
When "NAC Policy" rules are created and the "Install On" option is set to specific FortiGates, the rules are still pushed to all FortiGates listed under "Installation Targets". This results in policy installation failures on other devices, as some FortiGates might not support NAC Policy settings. |
| 998850 |
Modification to Policy with install target does not update the policy package status. Workaround: Remove the Installation Target and re-add to the policy which will trigger Policy Package Modification and the install preview will also show the changes made. |
| 1004056 |
The installation may encounter an error related to Syntax support for the " |
| 1004929 |
FortiManager removes the Web Filter Profile from the Profile Group for Policy-based FortiGates. Workaround: Use individual profiles in the policy instead of the profile group. |
|
1005161 |
The policy package status changes for all devices even when an address object is opened and saved without any modifications. This issue is particularly observed in objects utilizing the per-device mapping feature. |
| 1013434 | Unable to add VIP/VIP group in the destination address field of policies, as they are not visible when trying to add them in ADOM 6.4. |
| 1013948 | After upgrading to FortiManager versions 7.2.5 or 7.4.3, the installation preview may hang. However, the installation process itself can be completed successfully. |
| 1013990 | There are no commands available for installing source or destination interfaces when adding them to a firewall policy or SNAT rule. |
| 1014035 | Video filter profile config is not getting pushed completely from FortiManager to FortiGate. |
| 1029787 | The Firewall Policy pane in the FortiManager GUI may occasionally display both "Standard Security Profiles" (SSL no-inspection and protocol default profiles) and "Security Profile Groups" simultaneously. |
| 1033126 |
When
" Workaround:
To disable the " |
|
1034754 |
Policy installation might fail for v7.4.4 FortiGates when the " Workaround:
|
| 1037357 | FortiManager displays error when viewing policy consistency check results. |
| 1040107 |
Unable to install the Type of Service (ToS) and ToS-mask configuration from FortiManager to FortiGates. Workaround: Apply the ToS and ToS-mask configurations directly on the FortiGates. Alternatively, run a CLI script "Remote FortiGate Directly" with tos and tos-mask from FortiManager. |
|
1040160 |
When installing policy to a FortiGate that uses FortiSandbox inline scanning on an AV profile, FortiManager unsets the configuration on install. |
| 1068736 | Best Quality SDWAN rules installation may fail with the following error message: "Commit failed: Bad health check name". |
Revision History
|
Bug ID |
Description |
|---|---|
| 801614 |
FortiManager might display an error message "Failed to create a new revision." for some FortiGates, when retrieving their configurations. |
System Settings
|
Bug ID |
Description |
|---|---|
| 1005098 |
Verification of the LDAP Server via LDAP Browser may display an "Operation Error" message. Workaround: If an "Operation Error" occurs during LDAP Server Browser verification, re-enter the password and attempt the verification process again. |
|
1027547 |
In certain cases (currently under investigation), the License Status on FortiManager may be incorrectly displayed as "Expired" despite the license being active in the account. Workaround: Restart the FortiManager when feasible. |
|
1034021 |
FortiManager does not redirect to SSO login page when "Default Login Page" in SAML SSO is set to "Single-Sign-On". |
|
1034076 |
Admin Profile with no access to provisioning template can view provisioning templates by using direct URLs. |
| 1036112 | The "Time Used", "Start Time", and "End Time" data displayed in the Task Monitor do not match. |
|
1040130 |
GMT+6 is not visible on the System Settings. |
VPN Manager
|
Bug ID |
Description |
|---|---|
| 1042701 |
The traffic view page for the full mesh does not display the FortiGate and the external gateway. |