Fortinet black logo

Version 8.8.3

Version 8.8.3

Ticket #

Description (8.8.3)

574107 Access Points managed by wireless controllers do not import properly due to database object cache getting out of sync.
605783 Voice VLAN value does not save after entering under Model Configuration.
607448 Portal Role hidden field not taking effect when registered from alternative device, such as registering a gaming device or other device that does not support a browser.
617422 Port mode on Alcatel ports is changed when resync interfaces
617426 Not clearing port mode when set to RADMAC on Alcatel
622037 Long portal page loading times when connecting via VPN
644702 Interfaces disappearing from port groups
658512 SNMP link traps ignored from Huawei switch for a PC behind IP Phone
658846 Wireless Access Point SSID models set to Auto Register using 802.1x get Rogue Host Inactivity aging
659006 Motorola WiNG 7+ firmware requires different MAC format
659071 Admin Profile, Profiled Devices, Selected Rules not loading correctly
659882 Added support for API changes introduced in FortiClient EMS server version 6.4. Previously, FortiNAC displayed error "Failure: Failed to read Fortinet EMS devices" when attempting to connect.
665459 FGT VPN authentication fails when using RADIUS backend with legacy RADIUS server.
665658 Ability for pods to pull weekly Auto-Definition updates from NCM (Control Manager Proxy).
667326 Host Applications removed when Host is updated.
668628 nac.service status shows "failed" even though it successfully starts
668926 Support for Fortigate SNMP V1 Device Awareness SNMP Trap
669780 Added Operating System update proxy Configuration to UI (System > Settings > System Communication > Proxy Settings)
670093 Not properly discovering API version with newer versions of Citrix XenMobile MDM.
671107 Upgrade fails if configured for L2 HA and shared IP
671742 NCM dashboard can take 15 mins to load
671753 Enable Proxy support for FDN and Iot Service
671754 Potential NullPointerException in HostServer.updateConnectedContainer()
672066 Reading FNAC system IPs fails causing various system-wide functions to fail
672073 Adding a leading "." to a domain in the allowed domains list causes named-chroot service to fail
672456

Support for Citrix XenMobile MDM versions 10.10 or greater.

Important: Customers with 10.x XenMobile integrations must ensure XenMobile is running 10.10 or higher before upgrading FortiNAC. As of this version, FortiNAC no longer supports earlier 10.x XenMobile versions due to changes in API schema. This change does not affect 9.x versions of XenMobile.

672476 FGT VPN fails to process VPN session due to failure to parse VPN config.
672827 Security Fabric integration does not work with FNAC 8.8.1 and FGT versions less than 6.4.2
673012 Dell port enable shows failed in UI even though it really succeeded
673083 Cli Configuration no displaying on HP 5130 Switch in model config
673576 BufferOverflowException in SSOManager.buildFSSORecord() caused by IPv6 addresses
673577 Missing definition for Fortinet FSSO related event FORTINET2_COMMUNICATION_LOST
673579 Permissions on /usr/lib/systemd/system/analytics_agent.service are incorrect
673937 Hide unnecessary error message that is filling up the output.mom log file
674051 If a FortiGate read time out on an L2 poll occurs, clients connected to FortiSwitches in link mode show as offline (even though they are connected).
674604 DN checking during LDAP sync detects unexpected mismatch, doesnt sync groups for users.
674612

Added field in Administration UI to enable ability for FortiNAC to join winbind domain when hostname is greater than 15 characters.

System > Settings > Authentication > Local RADIUS Server

Field: Local NetBIOS Name

Description: Hostname (short name) of the FortiNAC server.

Example: FortiNAC FQDN = hostname.corp.example.com, Local NetBIOS Name = "HOSTNAME"

Enables FortiNAC to join winbind domain when FortiNAC hostname is greater than 15 characters.

675247 New DHCP fingerprint for iOS
675536 Airwatch polling stops before all records are returned
675547 Cert-check scan may fail when multiple certs are detected by agent.
675861 When removing "Custom Attribute" from the Local RADIUS configuration "radiusd" service fails to start
675919 CLI credential check on FGT fails for non-super_admin users.
676046 Added the following categories to Device Profiler FortiGuard IoT Method: Engineering - Arduino, Circuit Board, Processing Unit, Raspberry, RFID Tag Industry - Automotive, Energy, Industrial Device Smart Home - Fitness, Pool, Security System
676065 No internet access when installing / starting 8.8 will cause lengthy / infinite hang during install/startup
676142 No means to delete a Global Container on an NCM
676179 Local radius with FGT/FSW in FLink mode fails to identify FSW port from request.
676327 Primary FNAC responds with RADIUS reject if primary is down
676390 When using multiple DPC rules with Persisent Agent method only first method gets applied
676508 LDAP password erased after upgrade to 8.8.3.1457 due to race condition
677507 FSSO tags not sent to devices with ForceSSO attribute set.
677621 Config Wizard text still contains Network Sentry
677634 Reading dot1qPvid for vlans on Cisco SG350 switches does not work
677981 FGT VPN unable to determine correct tags to apply to sessions.
678148 Modify Device Profiling Rule-SSH-Delete Command-Incorrect message in dialog
678152 HTTP Status 500 when uploading new Certificate with non-string SAN
678178 Missing interface mapping in bsc-rename-ethers for New Dell R440 appliance (600C)
678490 Output.mom fills up with NameNotFoundException: Name SnmpV1 not found
678498 NumberFormatException in NCMServersTileActions.jsp
678806 Unable to sync objects from the NCM
679247 Support for enable password for H3C switches
680587 Device type change in properties not properly imported
680784 L2 data obtained from FGT should include only online entries.
681030 Device profiler not matching Apple iOS from FortiGate sessions
681083 Null Pointer Exception with device DEBUG attribute.
681096 Portal Policies using LDAP groups dont apply when connected via VPN.
681366 FNAC is associating the VPN clients with the wrong VPN interface.

682236

684038

Unable to add granularity to VPN User/Host Profiles, VPN w/ No existing User in FNAC, DA reports Login Failed but otherwise works.
682406 When If table changes on Cisco switch, FortiNAC does not update cache used for mapping SNMP traps to a port
682737 grab-log-snapshot now provides compression options for output: tar.gz, zip, or tar.xz
683320 FNAC does not create FNAC Events or Alarms for FortiGate API polling
683377 ARP data from a FortiGate can show inaccurate IPs
683429 DirectorySync not working if existing model name is null, affects groups
684136 RADIUS Attribute Group Editor does not render when launched from VDOM panel in UI
684139 Devices added directly to the "L2 Network Devices" group are automatically removed
684144 Remove admin access to vi from sudoers
684153 CLI/API Credentials are not always saved when initially modeling a FortiGate
684207 Error messages running install-winbind and install-radiusd in output.master
684312 FNAC experiences API failures periodically when accessing data.
684475 Not able to update BitDefender from isolation network

639548

520340

VPN with DA requires login, policy matching with vpn is inconsistent.

639548

652141

520340

VPNClient filter does not behave as expected

Includes agent 5.2.5.61

Version 8.8.3

Ticket #

Description (8.8.3)

574107 Access Points managed by wireless controllers do not import properly due to database object cache getting out of sync.
605783 Voice VLAN value does not save after entering under Model Configuration.
607448 Portal Role hidden field not taking effect when registered from alternative device, such as registering a gaming device or other device that does not support a browser.
617422 Port mode on Alcatel ports is changed when resync interfaces
617426 Not clearing port mode when set to RADMAC on Alcatel
622037 Long portal page loading times when connecting via VPN
644702 Interfaces disappearing from port groups
658512 SNMP link traps ignored from Huawei switch for a PC behind IP Phone
658846 Wireless Access Point SSID models set to Auto Register using 802.1x get Rogue Host Inactivity aging
659006 Motorola WiNG 7+ firmware requires different MAC format
659071 Admin Profile, Profiled Devices, Selected Rules not loading correctly
659882 Added support for API changes introduced in FortiClient EMS server version 6.4. Previously, FortiNAC displayed error "Failure: Failed to read Fortinet EMS devices" when attempting to connect.
665459 FGT VPN authentication fails when using RADIUS backend with legacy RADIUS server.
665658 Ability for pods to pull weekly Auto-Definition updates from NCM (Control Manager Proxy).
667326 Host Applications removed when Host is updated.
668628 nac.service status shows "failed" even though it successfully starts
668926 Support for Fortigate SNMP V1 Device Awareness SNMP Trap
669780 Added Operating System update proxy Configuration to UI (System > Settings > System Communication > Proxy Settings)
670093 Not properly discovering API version with newer versions of Citrix XenMobile MDM.
671107 Upgrade fails if configured for L2 HA and shared IP
671742 NCM dashboard can take 15 mins to load
671753 Enable Proxy support for FDN and Iot Service
671754 Potential NullPointerException in HostServer.updateConnectedContainer()
672066 Reading FNAC system IPs fails causing various system-wide functions to fail
672073 Adding a leading "." to a domain in the allowed domains list causes named-chroot service to fail
672456

Support for Citrix XenMobile MDM versions 10.10 or greater.

Important: Customers with 10.x XenMobile integrations must ensure XenMobile is running 10.10 or higher before upgrading FortiNAC. As of this version, FortiNAC no longer supports earlier 10.x XenMobile versions due to changes in API schema. This change does not affect 9.x versions of XenMobile.

672476 FGT VPN fails to process VPN session due to failure to parse VPN config.
672827 Security Fabric integration does not work with FNAC 8.8.1 and FGT versions less than 6.4.2
673012 Dell port enable shows failed in UI even though it really succeeded
673083 Cli Configuration no displaying on HP 5130 Switch in model config
673576 BufferOverflowException in SSOManager.buildFSSORecord() caused by IPv6 addresses
673577 Missing definition for Fortinet FSSO related event FORTINET2_COMMUNICATION_LOST
673579 Permissions on /usr/lib/systemd/system/analytics_agent.service are incorrect
673937 Hide unnecessary error message that is filling up the output.mom log file
674051 If a FortiGate read time out on an L2 poll occurs, clients connected to FortiSwitches in link mode show as offline (even though they are connected).
674604 DN checking during LDAP sync detects unexpected mismatch, doesnt sync groups for users.
674612

Added field in Administration UI to enable ability for FortiNAC to join winbind domain when hostname is greater than 15 characters.

System > Settings > Authentication > Local RADIUS Server

Field: Local NetBIOS Name

Description: Hostname (short name) of the FortiNAC server.

Example: FortiNAC FQDN = hostname.corp.example.com, Local NetBIOS Name = "HOSTNAME"

Enables FortiNAC to join winbind domain when FortiNAC hostname is greater than 15 characters.

675247 New DHCP fingerprint for iOS
675536 Airwatch polling stops before all records are returned
675547 Cert-check scan may fail when multiple certs are detected by agent.
675861 When removing "Custom Attribute" from the Local RADIUS configuration "radiusd" service fails to start
675919 CLI credential check on FGT fails for non-super_admin users.
676046 Added the following categories to Device Profiler FortiGuard IoT Method: Engineering - Arduino, Circuit Board, Processing Unit, Raspberry, RFID Tag Industry - Automotive, Energy, Industrial Device Smart Home - Fitness, Pool, Security System
676065 No internet access when installing / starting 8.8 will cause lengthy / infinite hang during install/startup
676142 No means to delete a Global Container on an NCM
676179 Local radius with FGT/FSW in FLink mode fails to identify FSW port from request.
676327 Primary FNAC responds with RADIUS reject if primary is down
676390 When using multiple DPC rules with Persisent Agent method only first method gets applied
676508 LDAP password erased after upgrade to 8.8.3.1457 due to race condition
677507 FSSO tags not sent to devices with ForceSSO attribute set.
677621 Config Wizard text still contains Network Sentry
677634 Reading dot1qPvid for vlans on Cisco SG350 switches does not work
677981 FGT VPN unable to determine correct tags to apply to sessions.
678148 Modify Device Profiling Rule-SSH-Delete Command-Incorrect message in dialog
678152 HTTP Status 500 when uploading new Certificate with non-string SAN
678178 Missing interface mapping in bsc-rename-ethers for New Dell R440 appliance (600C)
678490 Output.mom fills up with NameNotFoundException: Name SnmpV1 not found
678498 NumberFormatException in NCMServersTileActions.jsp
678806 Unable to sync objects from the NCM
679247 Support for enable password for H3C switches
680587 Device type change in properties not properly imported
680784 L2 data obtained from FGT should include only online entries.
681030 Device profiler not matching Apple iOS from FortiGate sessions
681083 Null Pointer Exception with device DEBUG attribute.
681096 Portal Policies using LDAP groups dont apply when connected via VPN.
681366 FNAC is associating the VPN clients with the wrong VPN interface.

682236

684038

Unable to add granularity to VPN User/Host Profiles, VPN w/ No existing User in FNAC, DA reports Login Failed but otherwise works.
682406 When If table changes on Cisco switch, FortiNAC does not update cache used for mapping SNMP traps to a port
682737 grab-log-snapshot now provides compression options for output: tar.gz, zip, or tar.xz
683320 FNAC does not create FNAC Events or Alarms for FortiGate API polling
683377 ARP data from a FortiGate can show inaccurate IPs
683429 DirectorySync not working if existing model name is null, affects groups
684136 RADIUS Attribute Group Editor does not render when launched from VDOM panel in UI
684139 Devices added directly to the "L2 Network Devices" group are automatically removed
684144 Remove admin access to vi from sudoers
684153 CLI/API Credentials are not always saved when initially modeling a FortiGate
684207 Error messages running install-winbind and install-radiusd in output.master
684312 FNAC experiences API failures periodically when accessing data.
684475 Not able to update BitDefender from isolation network

639548

520340

VPN with DA requires login, policy matching with vpn is inconsistent.

639548

652141

520340

VPNClient filter does not behave as expected

Includes agent 5.2.5.61