Fortinet white logo
Fortinet white logo

Known issues

Known issues

Known issues are organized into the following categories:

To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

New known issues

No new issues have been identified in version 7.6.1.

Existing known issues

The following issues have been identified in a previous version of FortiManager and remain in FortiManager 7.6.1.

AP Manager

Bug ID

Description

955558

FortiManager unsets the Protected Management Frame (PMF) setting when the SSID security mode is configured to OWE-enabled in the AP Manager.

1040365

FortiManager is generating false vulnerability reports for certain FortiAPs:

  • U431F

  • U231F

1050466

The 802.11ax-5g AP profile is missing for all FortiAPs that support WiFi 6. This issue has been observed in FortiManager 7.6.0 and ADOM 7.6.

1060238

FortiManager is attempting to unset the FortiAP's name.

1076200

Policy install fails due to FortiManager installs unexpected changes related to "<wifi_intf> address".

Workaround:

Create a CLI template with all subnet addresses and assign to device.

Device Manager

Bug ID

Description

796842

Failed to reload the configuration due to the "datasrc invalid" error message.

952422

IPsec templates created by SDWAN Overlay does not create tunnels for all the underlay interfaces.

963025

When using the static route template, the "SD-WAN Zone" does not appear under the Interface column.

1003899

FortiManager generates a VPN certificate that is not accepted by the FIPS-enabled FortiGate devices.

1020257

Packet Capture feature for managed FortiGates does not work; it starts but immediately stops.

1034355

When assigning a provisioning template with Admin Settings configuration, FortiManager changes the hostname of the device.

1050126

Setting up a FortiGate-HA with ZTP fails because the FortiLink is not deleted during the "HA config pushed to FGT" process.

1053194

If the "system interface speed" attribute is changed from the FortiManager, it may potentially cause an installation failure. Modifying the "system interface speed" is not currently supported on the FortiManager and must be done on the FortiGate side.

1063635

FortiManager does not support the "FortiWiFi-80F-2R-3G4G-DSL".

1063835

FortiManager ZTP installation to FortiGate versions 7.2.8 and lower may fail due to differing default "ssh-kex-algo" settings between FortiManager and FortiGate.

1063850

FortiManager is attempting to install a "PRIVATE KEY" with every installation, even after retrieving the config.

1070943

Unable to upgrade the devices using the Device Group Upgrade Firmware feature.

Workaround:

Upgrade devices individually by using the "Device Firmware Upgrade" feature or Create New Firmware Template for single devices or device groups and use the "Assign to Devices/Groups feature.

1074717

An error might be observed when the SD-WAN template health check name contains a space, displaying the following message: "Bad health check name...".

1075052

Occasionally, installations may fail on FortiGates in HA mode due to a "Serial number does NOT match" error. This can happen if the HA device's serial number on FortiManager does not immediately update after a failover.

1075281

Unable to add FortiAnalyzer to FortiManager, when "fgfm-peercert-withoutsn" is enabled.

Workaround:

Set the "fgfm-peercert-withoutsn" to disable and then add FortiAnalyzer to FortiManager.

1075747

SD-WAN Monitor does not display the members under the SD-WAN Rules (Map View or Table View). This issue is most likely to occur when "priority-zone" is configured.

1081105

The "system interface speed" attribute is incorrectly configured on the FortiManager, which may cause the installation to the FortiGate to fail.

Workaround:

Change the interface speed using CLI script and run directly on the FortiGate using the syntax "set speed auto".

1091441 Managed FortiAnalyzer is not available in dropdown menu in System Template in Log Settings.

FortiSwitch Manager

Bug ID

Description

1040428

FortiSwitch diagnostics tools do not display thecable test diagnose results, device information on Ports, and update Registration status.

1053220

Unable to delete FortiSwitches when central management is enabled for FortiSwitch.

Workaround:

Remove the FortiSwitch on FortiGate and retrieve on the FortiManager.

1060242

Unable to change the FortiSwitch name from the FortiSwitch Manager.

1075021

Users with the "admin profile" rights cannot access the FortiSwitch Manager.

Others

Bug ID

Description

998198

When upgrading ADOM, the upgrade process fails with the following error: "invalid value - can not find import template 'XYZ'".

Workaround:

Locate the scripts, delete them, upgrade the ADOM and then import the scripts.

1003711

During the FortiGate HA upgrade, both the primary and secondary FortiGates may reboot simultaneously, which can disrupt the network. This issue is more likely to occur in FortiGates that require disk checks, leading to longer boot times.

Workaround:

Disabling the disk check on fmupdate before the upgrade using the following command:

config fmupdate fwm-setting

set check-fgt-disk disable

end

1015890

Unable to upgrade ADOM from v6.4 to v7.0 due to "switch-controller traffic-policy" error.

1053830

MEAs cannot be enabled from FortiManager's GUI.

Workaround:

Use the following CLI command to enable them (in this example, universalconnector):

config system docker

set status enable

set universalconnector enable

end

1055417

Unable to upgrade the firmware version of the FortiGates in HA cluster by using the firmware template when HA is in-sync status. The failure to upgrade FortiGate HA cluster firmware is caused by a crash in "dmserver" daemon.

1058185

FortiProxy policies not imported if the policies have either internet service or IPv6 used in the source or destination.

1058585

When enabling Fabric Management, the "csfd" process might not start immediately.

Workaround:

Reboot the Supervisor or Member FortiManagers to initiate the "csfd" process.

1060337

The log insertion might be interrupted if FortiManager is upgraded directly from version (7.4.0/7.4.1) to 7.6.0/7.6.1. This will only occur if FortiAnalyzer Features are enabled on FortiManager.

Workaround:

To avoid this issue, upgrade the FortiManager to 7.4.2/7.4.3 first and then to 7.6.0/7.6.1.

For more details see Special Notices.

1062128

After upgrading to the latest available build, the FortiManager GUI displays the warning message: "A new firmware version is available".

1066132 When enabling the FortiAnalyzer features on FortiManager, a server error message might appear under "FortiView > System > Resource Usage".

1071064

Unable to upgrade the ADOMs.

1254367

FortiManager instances deployed on Azure may lose all data—including configuration, logs, and reports—if the VM is deallocated and subsequently reallocated.

This may occur during Azure-level operations such as VM stop (deallocate) or SKU/size changes. Please refer to the Special Notices for more information.

Policy & Objects

Bug ID

Description

843716

FortiManager tries to unset url-map for TCP forwarding ZTNA virtual server.

963536

The policy package feature "Export to Excel" is not functioning.

969923

The "View Mode" button, which is used to check the interface in Pair View, is missing in the Firewall Policy under Policy Packages.

971610

FortiManager does not able to import the Central SNAT, DNAT, DOS, local-in, and traffic shaping policies.

991720

FortiManager still has an option to enable the "match-vip" through the policy package for "allow" policies. However, this is not supported anymore on the FortiGates.

Workaround:

Disable the option under advance option in Firewall Rule.

1004056

The installation may encounter an error related to Syntax support for the "ssh-enc-algo" command.

Workaround:

Please try manually retrieving the configurations.

1005161

The policy package status changes for all devices even when an address object is opened and saved without any modifications. This issue is particularly observed in objects utilizing the per-device mapping feature.

1013948

After upgrading to FortiManager versions 7.2.5 or 7.4.3, the installation preview may hang. However, the installation process itself can be completed successfully.

1014035

Video filter profile config is not getting pushed completely from FortiManager to FortiGate.

1025012

Configuring the SSL/SSH inspection profile may result in the following error: "The server certificate replacement mode cannot support category exemptions."

Workaroud:

  1. Modify the SSL/SSH inspection profiles.

  2. Toggle from Protecting SSL Server to Multiple Clients Connecting to multiple Servers.

  3. Remove the categories from the Exempt from SSL inspection list.

  4. Toggle back to Protecting SSL Server and click OK.

  5. Install.

1029787

The Firewall Policy pane in the FortiManager GUI may occasionally display both "Standard Security Profiles" (SSL no-inspection and protocol default profiles) and "Security Profile Groups" simultaneously.

1029921

Under the "Web Application Firewall" security profiles, users are unable to disable the signatures through the GUI.

1039766

The Firewall Policy Lookup feature does not display the list of source interfaces for FortiGates.

1040160

When installing policy to a FortiGate that uses FortiSandbox inline scanning on an AV profile, FortiManager unsets the configuration on install.

1055795

During device import via multiple CSV files at same time, some devices were imported successfully, while others encountered errors and had missing metadata variables. Additionally, FortiManager forced the admin to log out. When attempting to log back in, the following error message appeared: "ADOM not found".

1066617

Unable to create the IP address object type wildcard, the following error message is displayed: "Invalid IP netmask".

Workaround:

Create CLI script and run it on ADOM DB or use Metadata variables.

1066638

In 7.4 ADOM, installation to 7.6 FortiGates may unset firewall service tcp-portrange (if a firewall policy references a firewall service).

1068736

Best Quality SDWAN rules installation may fail with the following error message: "Commit failed: Bad health check name".

1070800

FortiManager is attempting to install the "cli-cmd-audit" command on a FortiGate running version 7.2.8, which does not support this command, leading to an installation error.

1072354

FortiManager may attempt to install "ssl-ssh-profile" settings to "quic" objects. However, this syntax might not be supported on smaller FortiGate hardware platforms, particularly those with 2GB of RAM, such as the 60F/61F models.

1079128

ZTNA Server Per-Device Mapping may display a copy error failure if a new per-device mapping is created without specifying the object interface.

1079678

FortiManager does not provide any warning when there is a "deny all" policy in the middle of a Policy Package. This can be still seen on the "task monitor".

1086603

Unable to create local-in policy with ISDB objects.

Script

Bug ID

Description

931088 Unable to delete VDOMs using the FortiManager script. Interfaces remain in the device database, causing the installation to fail.

System Settings

Bug ID

Description

1005098

Verification of the LDAP Server through the LDAP Browser may display an "Operation Error" message.

Workaround:

If an "Operation Error" occurs during LDAP Server Browser verification, re-enter the password and attempt the verification process again.

1027547

In certain cases (currently under investigation), the License Status on FortiManager may be incorrectly displayed as "Expired" despite the license being active in the account.

Workaround:

Restart the FortiManager when feasible.

1040377

Despite unchecking the backup strategy option and receiving the "Setup Complete" message, the "Setup Wizard" continues to display during future logins on the Secondary members.

1047252

Incorrect warning message displayed in FortiManager GUI during upgrade from Feature build to Mature build.

1060943

FGFM Tunnel does not automatically come back online after disabling the "Offline Mode".

Workaround:

Reboot the FortiManager after disabling the offline mode.

1063040

Unable to import a local certificate into FortiManager. This issue may occur if the certificate is encrypted with a newer OpenSSL version that FortiManager does not yet support.

Workaround:

Convert the latest certificate to the legacy format before uploading it to FortiManager.

Known issues

Known issues

Known issues are organized into the following categories:

To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

New known issues

No new issues have been identified in version 7.6.1.

Existing known issues

The following issues have been identified in a previous version of FortiManager and remain in FortiManager 7.6.1.

AP Manager

Bug ID

Description

955558

FortiManager unsets the Protected Management Frame (PMF) setting when the SSID security mode is configured to OWE-enabled in the AP Manager.

1040365

FortiManager is generating false vulnerability reports for certain FortiAPs:

  • U431F

  • U231F

1050466

The 802.11ax-5g AP profile is missing for all FortiAPs that support WiFi 6. This issue has been observed in FortiManager 7.6.0 and ADOM 7.6.

1060238

FortiManager is attempting to unset the FortiAP's name.

1076200

Policy install fails due to FortiManager installs unexpected changes related to "<wifi_intf> address".

Workaround:

Create a CLI template with all subnet addresses and assign to device.

Device Manager

Bug ID

Description

796842

Failed to reload the configuration due to the "datasrc invalid" error message.

952422

IPsec templates created by SDWAN Overlay does not create tunnels for all the underlay interfaces.

963025

When using the static route template, the "SD-WAN Zone" does not appear under the Interface column.

1003899

FortiManager generates a VPN certificate that is not accepted by the FIPS-enabled FortiGate devices.

1020257

Packet Capture feature for managed FortiGates does not work; it starts but immediately stops.

1034355

When assigning a provisioning template with Admin Settings configuration, FortiManager changes the hostname of the device.

1050126

Setting up a FortiGate-HA with ZTP fails because the FortiLink is not deleted during the "HA config pushed to FGT" process.

1053194

If the "system interface speed" attribute is changed from the FortiManager, it may potentially cause an installation failure. Modifying the "system interface speed" is not currently supported on the FortiManager and must be done on the FortiGate side.

1063635

FortiManager does not support the "FortiWiFi-80F-2R-3G4G-DSL".

1063835

FortiManager ZTP installation to FortiGate versions 7.2.8 and lower may fail due to differing default "ssh-kex-algo" settings between FortiManager and FortiGate.

1063850

FortiManager is attempting to install a "PRIVATE KEY" with every installation, even after retrieving the config.

1070943

Unable to upgrade the devices using the Device Group Upgrade Firmware feature.

Workaround:

Upgrade devices individually by using the "Device Firmware Upgrade" feature or Create New Firmware Template for single devices or device groups and use the "Assign to Devices/Groups feature.

1074717

An error might be observed when the SD-WAN template health check name contains a space, displaying the following message: "Bad health check name...".

1075052

Occasionally, installations may fail on FortiGates in HA mode due to a "Serial number does NOT match" error. This can happen if the HA device's serial number on FortiManager does not immediately update after a failover.

1075281

Unable to add FortiAnalyzer to FortiManager, when "fgfm-peercert-withoutsn" is enabled.

Workaround:

Set the "fgfm-peercert-withoutsn" to disable and then add FortiAnalyzer to FortiManager.

1075747

SD-WAN Monitor does not display the members under the SD-WAN Rules (Map View or Table View). This issue is most likely to occur when "priority-zone" is configured.

1081105

The "system interface speed" attribute is incorrectly configured on the FortiManager, which may cause the installation to the FortiGate to fail.

Workaround:

Change the interface speed using CLI script and run directly on the FortiGate using the syntax "set speed auto".

1091441 Managed FortiAnalyzer is not available in dropdown menu in System Template in Log Settings.

FortiSwitch Manager

Bug ID

Description

1040428

FortiSwitch diagnostics tools do not display thecable test diagnose results, device information on Ports, and update Registration status.

1053220

Unable to delete FortiSwitches when central management is enabled for FortiSwitch.

Workaround:

Remove the FortiSwitch on FortiGate and retrieve on the FortiManager.

1060242

Unable to change the FortiSwitch name from the FortiSwitch Manager.

1075021

Users with the "admin profile" rights cannot access the FortiSwitch Manager.

Others

Bug ID

Description

998198

When upgrading ADOM, the upgrade process fails with the following error: "invalid value - can not find import template 'XYZ'".

Workaround:

Locate the scripts, delete them, upgrade the ADOM and then import the scripts.

1003711

During the FortiGate HA upgrade, both the primary and secondary FortiGates may reboot simultaneously, which can disrupt the network. This issue is more likely to occur in FortiGates that require disk checks, leading to longer boot times.

Workaround:

Disabling the disk check on fmupdate before the upgrade using the following command:

config fmupdate fwm-setting

set check-fgt-disk disable

end

1015890

Unable to upgrade ADOM from v6.4 to v7.0 due to "switch-controller traffic-policy" error.

1053830

MEAs cannot be enabled from FortiManager's GUI.

Workaround:

Use the following CLI command to enable them (in this example, universalconnector):

config system docker

set status enable

set universalconnector enable

end

1055417

Unable to upgrade the firmware version of the FortiGates in HA cluster by using the firmware template when HA is in-sync status. The failure to upgrade FortiGate HA cluster firmware is caused by a crash in "dmserver" daemon.

1058185

FortiProxy policies not imported if the policies have either internet service or IPv6 used in the source or destination.

1058585

When enabling Fabric Management, the "csfd" process might not start immediately.

Workaround:

Reboot the Supervisor or Member FortiManagers to initiate the "csfd" process.

1060337

The log insertion might be interrupted if FortiManager is upgraded directly from version (7.4.0/7.4.1) to 7.6.0/7.6.1. This will only occur if FortiAnalyzer Features are enabled on FortiManager.

Workaround:

To avoid this issue, upgrade the FortiManager to 7.4.2/7.4.3 first and then to 7.6.0/7.6.1.

For more details see Special Notices.

1062128

After upgrading to the latest available build, the FortiManager GUI displays the warning message: "A new firmware version is available".

1066132 When enabling the FortiAnalyzer features on FortiManager, a server error message might appear under "FortiView > System > Resource Usage".

1071064

Unable to upgrade the ADOMs.

1254367

FortiManager instances deployed on Azure may lose all data—including configuration, logs, and reports—if the VM is deallocated and subsequently reallocated.

This may occur during Azure-level operations such as VM stop (deallocate) or SKU/size changes. Please refer to the Special Notices for more information.

Policy & Objects

Bug ID

Description

843716

FortiManager tries to unset url-map for TCP forwarding ZTNA virtual server.

963536

The policy package feature "Export to Excel" is not functioning.

969923

The "View Mode" button, which is used to check the interface in Pair View, is missing in the Firewall Policy under Policy Packages.

971610

FortiManager does not able to import the Central SNAT, DNAT, DOS, local-in, and traffic shaping policies.

991720

FortiManager still has an option to enable the "match-vip" through the policy package for "allow" policies. However, this is not supported anymore on the FortiGates.

Workaround:

Disable the option under advance option in Firewall Rule.

1004056

The installation may encounter an error related to Syntax support for the "ssh-enc-algo" command.

Workaround:

Please try manually retrieving the configurations.

1005161

The policy package status changes for all devices even when an address object is opened and saved without any modifications. This issue is particularly observed in objects utilizing the per-device mapping feature.

1013948

After upgrading to FortiManager versions 7.2.5 or 7.4.3, the installation preview may hang. However, the installation process itself can be completed successfully.

1014035

Video filter profile config is not getting pushed completely from FortiManager to FortiGate.

1025012

Configuring the SSL/SSH inspection profile may result in the following error: "The server certificate replacement mode cannot support category exemptions."

Workaroud:

  1. Modify the SSL/SSH inspection profiles.

  2. Toggle from Protecting SSL Server to Multiple Clients Connecting to multiple Servers.

  3. Remove the categories from the Exempt from SSL inspection list.

  4. Toggle back to Protecting SSL Server and click OK.

  5. Install.

1029787

The Firewall Policy pane in the FortiManager GUI may occasionally display both "Standard Security Profiles" (SSL no-inspection and protocol default profiles) and "Security Profile Groups" simultaneously.

1029921

Under the "Web Application Firewall" security profiles, users are unable to disable the signatures through the GUI.

1039766

The Firewall Policy Lookup feature does not display the list of source interfaces for FortiGates.

1040160

When installing policy to a FortiGate that uses FortiSandbox inline scanning on an AV profile, FortiManager unsets the configuration on install.

1055795

During device import via multiple CSV files at same time, some devices were imported successfully, while others encountered errors and had missing metadata variables. Additionally, FortiManager forced the admin to log out. When attempting to log back in, the following error message appeared: "ADOM not found".

1066617

Unable to create the IP address object type wildcard, the following error message is displayed: "Invalid IP netmask".

Workaround:

Create CLI script and run it on ADOM DB or use Metadata variables.

1066638

In 7.4 ADOM, installation to 7.6 FortiGates may unset firewall service tcp-portrange (if a firewall policy references a firewall service).

1068736

Best Quality SDWAN rules installation may fail with the following error message: "Commit failed: Bad health check name".

1070800

FortiManager is attempting to install the "cli-cmd-audit" command on a FortiGate running version 7.2.8, which does not support this command, leading to an installation error.

1072354

FortiManager may attempt to install "ssl-ssh-profile" settings to "quic" objects. However, this syntax might not be supported on smaller FortiGate hardware platforms, particularly those with 2GB of RAM, such as the 60F/61F models.

1079128

ZTNA Server Per-Device Mapping may display a copy error failure if a new per-device mapping is created without specifying the object interface.

1079678

FortiManager does not provide any warning when there is a "deny all" policy in the middle of a Policy Package. This can be still seen on the "task monitor".

1086603

Unable to create local-in policy with ISDB objects.

Script

Bug ID

Description

931088 Unable to delete VDOMs using the FortiManager script. Interfaces remain in the device database, causing the installation to fail.

System Settings

Bug ID

Description

1005098

Verification of the LDAP Server through the LDAP Browser may display an "Operation Error" message.

Workaround:

If an "Operation Error" occurs during LDAP Server Browser verification, re-enter the password and attempt the verification process again.

1027547

In certain cases (currently under investigation), the License Status on FortiManager may be incorrectly displayed as "Expired" despite the license being active in the account.

Workaround:

Restart the FortiManager when feasible.

1040377

Despite unchecking the backup strategy option and receiving the "Setup Complete" message, the "Setup Wizard" continues to display during future logins on the Secondary members.

1047252

Incorrect warning message displayed in FortiManager GUI during upgrade from Feature build to Mature build.

1060943

FGFM Tunnel does not automatically come back online after disabling the "Offline Mode".

Workaround:

Reboot the FortiManager after disabling the offline mode.

1063040

Unable to import a local certificate into FortiManager. This issue may occur if the certificate is encrypted with a newer OpenSSL version that FortiManager does not yet support.

Workaround:

Convert the latest certificate to the legacy format before uploading it to FortiManager.