Fortinet black logo

Version 8.8.9

Version 8.8.9

Ticket #

Description (8.8.9.1745)

598844 Modifying a RADIUS server unnecessarily requires re-typing secret
650216 Unable to set firewall tags for PaloAlto model
666660 If a shared filter contains an exclamation point (!), a delete or edit silently fails
676232 Host with a disabled logged on user is not moved to dead end.
684657

Improved the communication method between Control Manager (NCM) and pods by using REST API and certificate client authentication over HTTP

Requirements:

  • Manager must be installed with License key containing certificates (not required for pods). For more information see related KB article FD52784

  • Firewalls allow TCP port 8443 between Manager and pods

If the above requirements are not met, the Manager will use original communication methods

709965 Server List panel in Control Manager Dashboard takes several minutes to build
713259 Meraki Ports/Interface creation issue when the Group Policy name is assigned to Production Logical Networks
723563 Event Alarm Mapping not adding host or event information to Email Action
724383 Intermittent failure polling clients connected to FortiSwitch in Link mode
725360 Fix potential ClassCastException in MibObject
725604 Hosts are automatically approved by the system when "Registrations Require Approval" is configured under "Standard User Registration Approval" in the Captive Portal
725746 Communication issues between Control Manager (NCM) and POD can cause Endpoint Compliance scan failures
725751 "Sync initiated" event added. Generated when a synchronization of servers by Control Manager has been triggered. Provides server IP, the user who triggered the sync and status.
725757 Scheduler Modify dialog, Next Scheduled Time validator doesn't accept new time format
725969 "System Error" balloon pop-up when creating roles
726099 FSSO processing performance enhancements
726458 DPC rule does not revalidate upon connect for RADIUS clients ("Confirm Device Rule on Connect")
726678 Added custom Network Devices Admin Profile permission set to view/hide the device model Credentials tab
727066 Error dialog when setting device mapping to Generic SNMP using set device mapping option
727336 When collecting ARP information from ArubaOS WLC, the user table that contains the correct ARP entries is not being queried
728677 Local RADIUS Server fails to disconnect clients from Ruckus Virtual SmartZone (SZ) controller due to missing RADIUS attributes
728823 Fortigate models with OID 1.3.6.1.4.1.12356.101.1.845 are mapped incorrectly (Device Icon, Resync Interfaces, SSID tab and other views are missing)
729007 NullPointerException during V3 device creation via API when no v1 community strings provided
729585 Cisco ASA VPN clients not moved to the unrestricted group due to multiple values returned when reading object-group
730236 Failure to read SSID on Ubiquiti causes all SSID models to be removed
730601 Changing Endpoint Complaince scan causes agents to be rescanned even when monitors were not changed
730789 When wired clients are authenticated by the Local RADIUS Server, the default VLAN is returned. Network Access Policy look-up is skipped.
730823 Multiple calls to edit a User Host Profile via the API results in failure after the first attempt
730892 VPN solution L2 polling process excessively long.
730908 Errors with secrets with special characters like %
730990 UI rendering for Authentication Policies/Configs tied to wrong permissions
731215 Added support to read L3 tables on Dell OS10 switches with VRFs configured
731633 SQL Exception is thrown during FortiNAC server startup
732265 Aruba Controller model configuration view is not showing supported RADIUS controls
732580 Added "sar" output in grab-log-snapshot
732965 Local RADIUS Server functionality not working properly upon failover or recovery in High Availability configuration
733232 Unable to save private filters
734792 API communication issues with FortiGate
735444 All RuggedCom switch models are shown as RSG2300 in the Model Configuration views
735880 Versa switch property files not loaded correctly
736110 Excessive exceptions for DatabaseObjectAlreadyExistsException seen in logs
736465 MAC address label is hidden if the IP address field is disabled in the Game Register portal configuration
736501 Cisco ASA VPN users are not always unrestricted after connecting.
738093 ISO build missing bc package
738257 Improved user look-up method to handle the different userID formats when matching Network Access Policies based on user record criteria. Previously, this was seen to cause delays in responding to RADIUS Accepts in some environments.
738375 RADIUS processing performance issues when RadiusManager debug is enabled
739465 Removed Local RADIUS requirement that request must contain Service-Type=10(Call-check)
739674 Local RADIUS MAB & CHAP fixes
740012 FSSO tags are not sent properly
740034 Exception in RadiusManager with logging enabled.

733892

733914

LicenseTool APPLIANCE shows EFFECTIVE count/level/certs if both are requested.
741811 Update of Adapter IPs causes empty replaces of DYNAMIC table
714641 Ajax response can return before fortiGuardCB is initialized
739674 Local RADIUS post-auth failing - NPE attempting to auth on generic/unknown devices (Moxa)
739380 AirWatch does not retrieve all MAC addresses for enrolled devices
740723 Devices with VDOMs that specify local radius server/secret and use the mgmt IP - on restart the nas DB tbl entry is removed
741382 Excessive log messages being printed.
735553 CLI and Vlan switching not functioning for Allied and Rugged devices
739131 Need to replace mysql-connector
740749 Local RADIUS can only handle secrets of 60 characters or less
734895 Unable to parse L2 table on Dell OS10 Switches

Version 8.8.9

Ticket #

Description (8.8.9.1745)

598844 Modifying a RADIUS server unnecessarily requires re-typing secret
650216 Unable to set firewall tags for PaloAlto model
666660 If a shared filter contains an exclamation point (!), a delete or edit silently fails
676232 Host with a disabled logged on user is not moved to dead end.
684657

Improved the communication method between Control Manager (NCM) and pods by using REST API and certificate client authentication over HTTP

Requirements:

  • Manager must be installed with License key containing certificates (not required for pods). For more information see related KB article FD52784

  • Firewalls allow TCP port 8443 between Manager and pods

If the above requirements are not met, the Manager will use original communication methods

709965 Server List panel in Control Manager Dashboard takes several minutes to build
713259 Meraki Ports/Interface creation issue when the Group Policy name is assigned to Production Logical Networks
723563 Event Alarm Mapping not adding host or event information to Email Action
724383 Intermittent failure polling clients connected to FortiSwitch in Link mode
725360 Fix potential ClassCastException in MibObject
725604 Hosts are automatically approved by the system when "Registrations Require Approval" is configured under "Standard User Registration Approval" in the Captive Portal
725746 Communication issues between Control Manager (NCM) and POD can cause Endpoint Compliance scan failures
725751 "Sync initiated" event added. Generated when a synchronization of servers by Control Manager has been triggered. Provides server IP, the user who triggered the sync and status.
725757 Scheduler Modify dialog, Next Scheduled Time validator doesn't accept new time format
725969 "System Error" balloon pop-up when creating roles
726099 FSSO processing performance enhancements
726458 DPC rule does not revalidate upon connect for RADIUS clients ("Confirm Device Rule on Connect")
726678 Added custom Network Devices Admin Profile permission set to view/hide the device model Credentials tab
727066 Error dialog when setting device mapping to Generic SNMP using set device mapping option
727336 When collecting ARP information from ArubaOS WLC, the user table that contains the correct ARP entries is not being queried
728677 Local RADIUS Server fails to disconnect clients from Ruckus Virtual SmartZone (SZ) controller due to missing RADIUS attributes
728823 Fortigate models with OID 1.3.6.1.4.1.12356.101.1.845 are mapped incorrectly (Device Icon, Resync Interfaces, SSID tab and other views are missing)
729007 NullPointerException during V3 device creation via API when no v1 community strings provided
729585 Cisco ASA VPN clients not moved to the unrestricted group due to multiple values returned when reading object-group
730236 Failure to read SSID on Ubiquiti causes all SSID models to be removed
730601 Changing Endpoint Complaince scan causes agents to be rescanned even when monitors were not changed
730789 When wired clients are authenticated by the Local RADIUS Server, the default VLAN is returned. Network Access Policy look-up is skipped.
730823 Multiple calls to edit a User Host Profile via the API results in failure after the first attempt
730892 VPN solution L2 polling process excessively long.
730908 Errors with secrets with special characters like %
730990 UI rendering for Authentication Policies/Configs tied to wrong permissions
731215 Added support to read L3 tables on Dell OS10 switches with VRFs configured
731633 SQL Exception is thrown during FortiNAC server startup
732265 Aruba Controller model configuration view is not showing supported RADIUS controls
732580 Added "sar" output in grab-log-snapshot
732965 Local RADIUS Server functionality not working properly upon failover or recovery in High Availability configuration
733232 Unable to save private filters
734792 API communication issues with FortiGate
735444 All RuggedCom switch models are shown as RSG2300 in the Model Configuration views
735880 Versa switch property files not loaded correctly
736110 Excessive exceptions for DatabaseObjectAlreadyExistsException seen in logs
736465 MAC address label is hidden if the IP address field is disabled in the Game Register portal configuration
736501 Cisco ASA VPN users are not always unrestricted after connecting.
738093 ISO build missing bc package
738257 Improved user look-up method to handle the different userID formats when matching Network Access Policies based on user record criteria. Previously, this was seen to cause delays in responding to RADIUS Accepts in some environments.
738375 RADIUS processing performance issues when RadiusManager debug is enabled
739465 Removed Local RADIUS requirement that request must contain Service-Type=10(Call-check)
739674 Local RADIUS MAB & CHAP fixes
740012 FSSO tags are not sent properly
740034 Exception in RadiusManager with logging enabled.

733892

733914

LicenseTool APPLIANCE shows EFFECTIVE count/level/certs if both are requested.
741811 Update of Adapter IPs causes empty replaces of DYNAMIC table
714641 Ajax response can return before fortiGuardCB is initialized
739674 Local RADIUS post-auth failing - NPE attempting to auth on generic/unknown devices (Moxa)
739380 AirWatch does not retrieve all MAC addresses for enrolled devices
740723 Devices with VDOMs that specify local radius server/secret and use the mgmt IP - on restart the nas DB tbl entry is removed
741382 Excessive log messages being printed.
735553 CLI and Vlan switching not functioning for Allied and Rugged devices
739131 Need to replace mysql-connector
740749 Local RADIUS can only handle secrets of 60 characters or less
734895 Unable to parse L2 table on Dell OS10 Switches