Known issues
Known issues are organized into the following categories:
To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.
New known issues
No new issues have been identified in version 7.6.1.
Existing known issues
The following issues have been identified in a previous version of FortiManager and remain in FortiManager 7.6.1.
AP Manager
|
Bug ID |
Description |
|---|---|
| 955558 |
FortiManager unsets the Protected Management Frame (PMF) setting when the SSID security mode is configured to OWE-enabled in the AP Manager. |
| 1040365 |
FortiManager is generating false vulnerability reports for certain FortiAPs:
|
| 1050466 |
The 802.11ax-5g AP profile is missing for all FortiAPs that support WiFi 6. This issue has been observed in FortiManager 7.6.0 and ADOM 7.6. |
| 1060238 |
FortiManager is attempting to unset the FortiAP's name. |
| 1076200 |
Policy install fails due to FortiManager installs unexpected changes related to "<wifi_intf> address". Workaround: Create a CLI template with all subnet addresses and assign to device. |
Device Manager
|
Bug ID |
Description |
|---|---|
| 796842 |
Failed to reload the configuration due to the "datasrc invalid" error message. |
| 952422 |
IPsec templates created by SDWAN Overlay does not create tunnels for all the underlay interfaces. |
| 963025 |
When using the static route template, the "SD-WAN Zone" does not appear under the Interface column. |
| 1003899 |
FortiManager generates a VPN certificate that is not accepted by the FIPS-enabled FortiGate devices. |
| 1020257 |
Packet Capture feature for managed FortiGates does not work; it starts but immediately stops. |
| 1034355 |
When assigning a provisioning template with Admin Settings configuration, FortiManager changes the hostname of the device. |
| 1050126 |
Setting up a FortiGate-HA with ZTP fails because the FortiLink is not deleted during the "HA config pushed to FGT" process. |
| 1053194 |
If the " |
|
1063635 |
FortiManager does not support the "FortiWiFi-80F-2R-3G4G-DSL". |
| 1063835 |
FortiManager ZTP installation to FortiGate versions 7.2.8 and lower may fail due to
differing default " |
|
1063850 |
FortiManager is attempting to install a "PRIVATE KEY" with every installation, even after retrieving the config. |
| 1070943 |
Unable to upgrade the devices using the Device Group Upgrade Firmware feature. Workaround: Upgrade devices individually by using the "Device Firmware Upgrade" feature or Create New Firmware Template for single devices or device groups and use the "Assign to Devices/Groups feature. |
| 1074717 |
An error might be observed when the SD-WAN template health check name contains a space, displaying the following message: "Bad health check name...". |
|
1075052 |
Occasionally, installations may fail on FortiGates in HA mode due to a "Serial number does NOT match" error. This can happen if the HA device's serial number on FortiManager does not immediately update after a failover. |
| 1075281 |
Unable to add FortiAnalyzer to FortiManager, when " Workaround:
Set the " |
|
1075747 |
SD-WAN Monitor does not display the members under the SD-WAN Rules (Map View or Table View). This issue is most likely to occur when "priority-zone" is configured. |
|
1081105 |
The " Workaround: Change the interface speed using CLI script and run directly on the FortiGate using the syntax " |
| 1091441 | Managed FortiAnalyzer is not available in dropdown menu in System Template in Log Settings. |
FortiSwitch Manager
|
Bug ID |
Description |
|---|---|
| 1040428 |
FortiSwitch diagnostics tools do not display thecable test diagnose results, device information on Ports, and update Registration status. |
| 1053220 |
Unable to delete FortiSwitches when central management is enabled for FortiSwitch. Workaround: Remove the FortiSwitch on FortiGate and retrieve on the FortiManager. |
| 1060242 |
Unable to change the FortiSwitch name from the FortiSwitch Manager. |
|
1075021 |
Users with the "admin profile" rights cannot access the FortiSwitch Manager. |
Others
|
Bug ID |
Description |
|---|---|
| 998198 |
When upgrading ADOM, the upgrade process fails with the following error: "invalid value - can not find import template 'XYZ'". Workaround: Locate the scripts, delete them, upgrade the ADOM and then import the scripts. |
| 1003711 |
During the FortiGate HA upgrade, both the primary and secondary FortiGates may reboot simultaneously, which can disrupt the network. This issue is more likely to occur in FortiGates that require disk checks, leading to longer boot times. Workaround: Disabling the disk check on fmupdate before the upgrade using the following command: config fmupdate fwm-setting set check-fgt-disk disable end |
| 1015890 |
Unable to upgrade ADOM from v6.4 to v7.0 due to "switch-controller traffic-policy" error. |
| 1053830 |
MEAs cannot be enabled from FortiManager's GUI. Workaround:
Use the following CLI command to
enable them (in this example, config system docker set status enable set universalconnector enable end |
| 1055417 |
Unable to upgrade the firmware version of the FortiGates in HA cluster by using the firmware template when HA is in-sync status. The failure to upgrade FortiGate HA cluster firmware is caused by a crash in "dmserver" daemon. |
|
1058185 |
FortiProxy policies not imported if the policies have either internet service or IPv6 used in the source or destination. |
| 1058585 |
When enabling Fabric Management, the "csfd" process might not start immediately. Workaround: Reboot the Supervisor or Member FortiManagers to initiate the "csfd" process. |
|
1060337 |
The log insertion might be interrupted if FortiManager is upgraded directly from version (7.4.0/7.4.1) to 7.6.0/7.6.1. This will only occur if FortiAnalyzer Features are enabled on FortiManager. Workaround: To avoid this issue, upgrade the FortiManager to 7.4.2/7.4.3 first and then to 7.6.0/7.6.1. For more details see Special Notices. |
| 1062128 |
After upgrading to the latest available build, the FortiManager GUI displays the warning message: "A new firmware version is available". |
| 1066132 | When enabling the FortiAnalyzer features on FortiManager, a server error message might appear under "FortiView > System > Resource Usage". |
|
1071064 |
Unable to upgrade the ADOMs. |
|
1254367 |
FortiManager instances deployed on Azure may lose all data—including configuration, logs, and reports—if the VM is deallocated and subsequently reallocated. This may occur during Azure-level operations such as VM stop (deallocate) or SKU/size changes. Please refer to the Special Notices for more information. |
Policy & Objects
|
Bug ID |
Description |
|---|---|
| 843716 |
FortiManager tries to unset url-map for TCP forwarding ZTNA virtual server. |
| 963536 |
The policy package feature "Export to Excel" is not functioning. |
|
969923 |
The "View Mode" button, which is used to check the interface in Pair View, is missing in the Firewall Policy under Policy Packages. |
| 971610 |
FortiManager does not able to import the Central SNAT, DNAT, DOS, local-in, and traffic shaping policies. |
| 991720 |
FortiManager still has an option to enable the "match-vip" through the policy package for "allow" policies. However, this is not supported anymore on the FortiGates. Workaround: Disable the option under advance option in Firewall Rule. |
| 1004056 |
The installation may encounter an error related to Syntax support for the "ssh-enc-algo" command. Workaround: Please try manually retrieving the configurations. |
| 1005161 |
The policy package status changes for all devices even when an address object is opened and saved without any modifications. This issue is particularly observed in objects utilizing the per-device mapping feature. |
| 1013948 |
After upgrading to FortiManager versions 7.2.5 or 7.4.3, the installation preview may hang. However, the installation process itself can be completed successfully. |
| 1014035 |
Video filter profile config is not getting pushed completely from FortiManager to FortiGate. |
|
1025012 |
Configuring the SSL/SSH inspection profile may result in the following error: "The server certificate replacement mode cannot support category exemptions." Workaroud:
|
| 1029787 |
The Firewall Policy pane in the FortiManager GUI may occasionally display both "Standard Security Profiles" (SSL no-inspection and protocol default profiles) and "Security Profile Groups" simultaneously. |
| 1029921 |
Under the "Web Application Firewall" security profiles, users are unable to disable the signatures through the GUI. |
| 1039766 |
The Firewall Policy Lookup feature does not display the list of source interfaces for FortiGates. |
| 1040160 |
When installing policy to a FortiGate that uses FortiSandbox inline scanning on an AV profile, FortiManager unsets the configuration on install. |
|
1055795 |
During device import via multiple CSV files at same time, some devices were imported successfully, while others encountered errors and had missing metadata variables. Additionally, FortiManager forced the admin to log out. When attempting to log back in, the following error message appeared: "ADOM not found". |
| 1066617 |
Unable to create the IP address object type wildcard, the following error message is displayed: "Invalid IP netmask". Workaround: Create CLI script and run it on ADOM DB or use Metadata variables. |
|
1066638 |
In 7.4 ADOM, installation to 7.6 FortiGates may |
| 1068736 |
Best Quality SDWAN rules installation may fail with the following error message: "Commit failed: Bad health check name". |
| 1070800 |
FortiManager is attempting to install the "cli-cmd-audit" command on a FortiGate running version 7.2.8, which does not support this command, leading to an installation error. |
|
1072354 |
FortiManager may attempt to install "ssl-ssh-profile" settings to "quic" objects. However, this syntax might not be supported on smaller FortiGate hardware platforms, particularly those with 2GB of RAM, such as the 60F/61F models. |
|
1079128 |
ZTNA Server Per-Device Mapping may display a copy error failure if a new per-device mapping is created without specifying the object interface. |
| 1079678 |
FortiManager does not provide any warning when there is a "deny all" policy in the middle of a Policy Package. This can be still seen on the "task monitor". |
|
1086603 |
Unable to create local-in policy with ISDB objects. |
Script
|
Bug ID |
Description |
|---|---|
| 931088 | Unable to delete VDOMs using the FortiManager script. Interfaces remain in the device database, causing the installation to fail. |
System Settings
|
Bug ID |
Description |
|---|---|
| 1005098 |
Verification of the LDAP Server through the LDAP Browser may display an "Operation Error" message. Workaround: If an "Operation Error" occurs during LDAP Server Browser verification, re-enter the password and attempt the verification process again. |
|
1027547 |
In certain cases (currently under investigation), the License Status on FortiManager may be incorrectly displayed as "Expired" despite the license being active in the account. Workaround: Restart the FortiManager when feasible. |
| 1040377 |
Despite unchecking the backup strategy option and receiving the "Setup Complete" message, the "Setup Wizard" continues to display during future logins on the Secondary members. |
|
1047252 |
Incorrect warning message displayed in FortiManager GUI during upgrade from Feature build to Mature build. |
| 1060943 |
FGFM Tunnel does not automatically come back online after disabling the "Offline Mode". Workaround: Reboot the FortiManager after disabling the offline mode. |
|
1063040 |
Unable to import a local certificate into FortiManager. This issue may occur if the certificate is encrypted with a newer OpenSSL version that FortiManager does not yet support. Workaround: Convert the latest certificate to the legacy format before uploading it to FortiManager. |