Known issues
Known issues are organized into the following categories:
To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.
New known issues
The following issues have been identified in version 7.6.0.
AP Manager
|
Bug ID |
Description |
|---|---|
| 1060238 |
FortiManager is attempting to unset the FortiAP's name. |
FortiSwitch Manager
|
Bug ID |
Description |
|---|---|
| 1060242 |
Unable to change the FortiSwitch name from the FortiSwitch Manager. |
Others
|
Bug ID |
Description |
|---|---|
| 1053830 |
MEAs cannot be enabled from FortiManager's GUI. Workaround:
Use the following CLI command to enable them (in this example, config system docker set status enable set universalconnector enable end |
|
1058585 |
When enabling Fabric Management, the "csfd" process might not start immediately. Workaround: Reboot the Supervisor or Member FortiManager to initiate the "csfd" process. |
|
1060337 |
The log insertion might be interrupted if FortiManager is upgraded directly from version (7.4.0/7.4.1) to 7.6.0. This will only occur if FortiAnalyzer Features are enabled on FortiManager. Workaround: To avoid this issue, upgrade the FortiManager to 7.4.2/7.4.3 first and then to 7.6.0. For more details see Special Notices |
|
1066132 |
After enabling the FortiAnalyzer features on FortiManager, a server error message might appear under "FortiView > System > Resource Usage". |
Policy & Objects
|
Bug ID |
Description |
|---|---|
|
1025012 |
Configuring the SSL/SSH inspection profile may result in the following error: "The server certificate replacement mode cannot support category exemptions." Workaroud:
|
| 1066617 |
Unable to create the IP address object type wildcard, the following error message is displayed: "Invalid IP netmask". Workaround: Create CLI script and run it on ADOM DB or use Metadata variables. |
System Settings
|
Bug ID |
Description |
|---|---|
| 1060943 |
FGFM Tunnel does not automatically come back online after disabling the "Offline Mode". Workaround: Reboot the FortiManager after disabling offline mode. |
Existing known issues
The following issues have been identified in a previous version of FortiManager and remain in FortiManager 7.6.0.
AP Manager
|
Bug ID |
Description |
|---|---|
| 955558 | FortiManager unsets the Protected Management Frame (PMF) setting when the SSID security mode is configured to OWE-enabled in the AP Manager. |
| 1040365 |
FortiManager is generating false vulnerability reports for certain FortiAPs:
|
| 1050466 |
The 802.11ax-5g AP profile is missing for all FortiAPs that support WiFi 6. This issue has been observed in FortiManager 7.6.0 and ADOM 7.6. |
| 1076200 |
Policy install fails due to FortiManager installs unexpected changes related to "<wifi_intf> address". Workaround: Create a CLI template with all subnet addresses and assign to device. |
Device Manager
|
Bug ID |
Description |
|---|---|
| 796842 |
Failed to reload the configuration due to the "datasrc invalid" error message. |
| 952422 | IPsec templates created by SDWAN Overlay does not create tunnels for all the underlay interfaces. |
| 963025 | When using the static route template, the "SD-WAN Zone" does not appear under the Interface column. |
| 1003899 | FortiManager generates a VPN certificate that is not accepted by the FIPS-enabled FortiGate devices. |
| 1020257 |
Packet Capture feature for managed FortiGates does not work; it starts but immediately stops. |
| 1034355 | When assigning a provisioning template with Admin Settings configuration, FortiManager changes the hostname of the device. |
| 1050126 |
Setting up a FortiGate-HA with ZTP fails because the FortiLink is not deleted during the "HA config pushed to FGT" process. |
| 1053194 |
If the " |
| 1063835 |
FortiManager ZTP installation to FortiGate versions 7.2.8 and lower may fail due to differing default "ssh-kex-algo" settings between FortiManager and FortiGate. |
| 1070943 |
Unable to upgrade the devices using the Device Group Upgrade Firmware feature. Workaround: Upgrade devices individually by using the "Device Firmware Upgrade" feature or Create New Firmware Template for single devices or device groups and use the "Assign to Devices/Groups feature. |
| 1074717 | An error might be observed when the SD-WAN template health check name contains a space, displaying the following message: "Bad health check name...". |
| 1075281 |
Unable to add FortiAnalyzer to FortiManager, when " Workaround:
Set the " |
|
1075747 |
SD-WAN Monitor does not display the members under the SD-WAN Rules (Map View or Table View). This issue is most likely to occur when "priority-zone" is configured. |
FortiSwitch Manager
|
Bug ID |
Description |
|---|---|
|
1040428 |
FortiSwitch diagnostics tools do not display the cable test diagnose results, device information on Ports, and update Registration status. |
| 1053220 |
Unable to delete FortiSwitches when central management is enabled for FortiSwitch. Workaround: Remove the FortiSwitch on FortiGate and retrieve on the FortiManager. |
Others
|
Bug ID |
Description |
|---|---|
|
998198 |
When upgrading ADOM, the upgrade process fails with the following error: "invalid value - can not find import template 'XYZ' ". Workaround: Locate the scripts, delete them, upgrade the ADOM and then import the scripts. |
| 1015890 | Unable to upgrade ADOM from v6.4
to v7.0 due to "switch-controller traffic-policy" error. |
|
1019261 |
Unable to upgrade ADOM from 7.0 to 7.2, due to the error "Do not support urlfilter-table for global scope webfilter profile". Workaround Run the following script against the ADOM DB: config webfilter profile edit "g-default" config web unset urlfilter-table end next end |
| 1049457 | When FortiAnalyzer is added as a managed device, users may encounter an issue in the FortiManager GUI when expanding the log details. |
| 1055417 |
Unable to upgrade the firmware version of the FortiGates in HA cluster by using the firmware template when HA is in-sync status. The failure to upgrade FortiGate HA cluster firmware is caused by a crash in "dmserver" daemon. |
| 1062128 |
After upgrading to the latest available build, the FortiManager GUI displays the warning message: "A new firmware version is available". |
|
1254367 |
FortiManager instances deployed on Azure may lose all data—including configuration, logs, and reports—if the VM is deallocated and subsequently reallocated. This may occur during Azure-level operations such as VM stop (deallocate) or SKU/size changes. Please refer to the Special Notices for more information. |
Policy & Objects
|
Bug ID |
Description |
|---|---|
|
843716 |
FortiManager tries to unset |
| 963536 | The policy package feature Export to Excel is not functioning. |
|
971610 |
FortiManager is not able to import the Central SNAT, DNAT, DOS, local-in and traffic shaping policies. |
| 991720 |
FortiManager still has an option to enable the "match-vip" through the policy package for "allow" policies. However, this is not supported anymore on the FortiGates. Workaround: Disable the option under advance option in Firewall Rule. |
| 1004056 | The installation may encounter
an error related to Syntax support for the "ssh-enc-algo" command. |
|
1005161 |
The policy package status changes for all devices even when an address object is opened and saved without any modifications. This issue is particularly observed in objects utilizing the per-device mapping feature. |
| 1013948 | After upgrading to FortiManager versions 7.2.5 or 7.4.3, the installation preview may hang. However, the installation process itself can be completed successfully. |
| 1014035 | Video filter profile config is not getting pushed completely from FortiManager to FortiGate. |
| 1029921 |
Under the "Web Application Firewall" security profiles, users are unable to disable the signatures through the GUI. |
| 1039766 |
The Firewall Policy Lookup feature does not display the list of source interfaces for FortiGates. |
| 1040160 | When installing policy to a FortiGate that uses FortiSandbox inline scanning on an AV profile, FortiManager unsets the configuration on install. |
| 1068736 | Best Quality SDWAN rules installation may fail with the following error message: "Commit failed: Bad health check name". |
| 1070800 |
FortiManager is attempting to install the
" |
| 1079678 |
FortiManager does not provide any warning when there is a "deny all" policy in the middle of a Policy Package. This can be still seen on the "task monitor". |
Script
|
Bug ID |
Description |
|---|---|
| 931088 | Unable to delete VDOMs using the FortiManager script. Interfaces remain in the device database, causing the installation to fail. |
System Settings
|
Bug ID |
Description |
|---|---|
| 1005098 |
Verification of the LDAP Server through the LDAP Browser may display an "Operation Error" message. Workaround: If an "Operation Error" occurs during LDAP Server Browser verification, re-enter the password and attempt the verification process again. |
|
1027547 |
In certain cases (currently under investigation), the License Status on FortiManager may be incorrectly displayed as "Expired" despite the license being active in the account. Workaround: Restart the FortiManager when feasible. |
| 1040377 |
Despite unchecking the backup strategy option and receiving the "Setup Complete" message, the "Setup Wizard" continues to display during future logins on the Secondary members. |
|
1047252 |
Incorrect warning message displayed in FortiManager GUI during upgrade from Feature build to Mature build. |