Fortinet black logo

Version 9.2.3

Version 9.2.3

Ticket #

Description (9.2.3.0435)

769558 NullPointerException registering a rogue host from the Hosts View.
640841 SSH connection to some AlaxalA switches fail.
741373 Support for Mobile Iron V2 API
746585 Cisco Mac Move Notification Trap support.
750248 Unable to access the secondary server's Configuration Wizard in a High Availability configuration.
752792 Device Profiling Rule registration not setting user/group membership.
753937 "Run NMAP" is now an option under Users & Hosts >Endpoint Fingerprints in the UI.
754279 Host record marked "At Risk" due tothe generation of the "Persistent Agent Not Communicating" alarm fail to be marked "Safe" after "Communication Resumed" is generated.
754605 Added Tripp Lite DHCP fingerprints
758009 Added support to change VLANs via CLI on Allied Telesyn 8000S.
759018 Admin user with admin user profile permissions to Access, Add/Modify and delete "Users" is unable to create a new regular user.
761276 User/Host Profile with Location does not use Portal defined in Portal Configuration.
762071 Radius Auth/EAP Type columns empty in Network > Device > Ports > Adapters table.
762081 bsc-rename-ethers service fails on virtual machines.
762702 Improved FortiClient EMS polling.Previously, not all hosts were retrieved upon a poll, causing some hosts not to register.
765477 FortiClient EMS test connect still fails after correcting a credential mistake.
765483 Fortinet EMS Version parsing is broken for EMS 7.0.
765899 EMS integration does not take into account theignoredAdapters.txt list.Can cause Adapter/Host record generation with Fortinet virtual adapters.
766600 L3 polling support for Inhand IR915L Router
767209 Aerohive VLAN interfaces do not update on resynchronization after VLAN ID or Profile ID change.
767942 Incorrect serial number used for CSF protocol used for SSO.
768329 Fail to determine port type for Cisco SG Switches with latest Cisco firmware.
768673 OS name for OS X devices between DHCP and Fortiguard fingerprints do not match.
768785 The GUI value "Registered Host" now displays as "Registered Host With Owner".
768793 Race condition causing StaleStateException in FirewallSessionManager.
768822 FortiSwitch does not respond to Change of Auth (COA) packet due to FortiNAC not sending the correct secret.
769851 Accounting Stop Message is discarded from Link Mode FortiSwitches when using Local Radius.
770034 FGT 1800F labeled as 1500D
770192 Device Profiling rules stop processing as expected if HTTP method is used and HTTP is timing out.
770208 Juniper switches fail to change VLAN on ports that are RADIUS enabled.
770548 Operating System custom attribute does not save in Device Profiling Rule.
770562 Device Profiler is performing all scans before checking for matches.
770695 Local RADIUS fails to find correct port on Extreme Summit X, preventing proper VLAN assignment.
770730 Local RADIUS service goes down & does not restart when FortiNAC processes are restarted.
770738 Ruckus API version detection not working for login API
770830 Device Rule Confirmation Failure event is not generated for some methods.
770930 High L3 Polling frequency in environments with no SSO management configured.
771038 Port state actions without clear actions cannot be saved in the Event to Alarm mapping.
771149 "Confirm Device Rule on Connect" does not work properly when "Confirm Device Rule on Interval" is also enabled within the same Device Profiling rule.
771157 MobileIron Cloud application poll can fail if licenseID is too long.
771422 RFC 3576 (CoA/RADIUS Disconnect) support for Extreme switches.
771506 Erroneous creation of redundant unique keys could overfill Group table key limits.
771685 Apresia integration RADIUS 802.1x support incomplete.
771705 Change Inhand mib file to not use WRITE_HIDDEN in 9.1. and 9.2.
771743 FSSO tags not sent to FortiGate with multi-VDOM Fabric Connections.
771939 Automatically detect MAC format for RADIUS CoA requests for Juniper switches.
772010 Wireless clients are not correctly processed on FortinetAPs when using some multi-vdom configurations.
773053 RADIUS not mapping to correct AD server when Kerberos and NetBIOS names differ.
773828 Not polling L2 information from PNetworks switches with latest firmware.
773841 Meraki Switch VLAN read/set fails when the ifIndex does not match the dot1d index.
774202 Adjusted timestamp in syslog CEF message format.Previous formatting prevented some systems from properly processing syslog from FortiNAC.
774724 Unable to filter Hosts and Adapters by status through API.
775973 Option to prevent auto-logging on users during authentication is absent during L2 polling.
776123 Unable to add/modify groups starting with "!" (bang).
777124 A higher ranked policy more general than a lower ranked policy is still honored if disabled.Lower ranked policy displays with a strike-through and is ignored.
777126 Invalid MAC address doesn't skip non-matching OUI Method.
777400 Syncing "Role Based Access" group on the Control manager (NCM) may delete sub-groups on the synchronized POD.
777479 Control Manager (NCM) Dashboard tile is very slow to load.
777511 RADIUS support for HP 2910 and 2920 switches.
777778 Unable to switch VLANs on Juniper switch via 802.1x RADIUS in Proxy mode.
778108 Windows domain check Device Profiling method fails if there is no domain user logged on.
778112 Performance issue when performing group membership lookups.Symptoms include usually high CPU utilization.
778157 L2 Polling issues with Cisco 9800 WLC firmware 17.3.
778520 Added SQL query for GroupManager.getGroupsMembershipIDs() when determining group membership in order to improve performance.
779873 FortiNAC processes taking unusually long to startup due to delays resuming FirewallSessionMgr.
779901 Vulnerabilties in mysql versions less than 5.6.42.
780282 FortiNAC Events using old vendor name "Bradford Networks".
780626 Huawei Wireless controller imports nameless APs.
780790 CLI Failing to Alcatel Omni 6860-P48.
782374 L2 polling not parsing correctly for Motorola 7.X devices.
782740 Unable to read default and current vlans for Ruijie switches.
782744 Script install-winbind-virtual contains spaces around = assignments - invalid
783227 Operating System updates from the UI fail when freeradius gpg key is not present.
783544 Fortigate FG-200F improperly labeled as FG-201E.
783552 nac.service / ProcessManager not running at startup when no IP on box, leads to processes down.
783621 Host import related Memory issues.
783944 Exception reading VLANs or SSIDs on Meru 4100 with firmware 5.1-93.
784601 Group membership lookup causing high CPU utilization.
784957 Not polling L2 information from Cisco ME-3400E-24TS-M router.
786401 Remote Scan -> Linux x86_64 -> 500 Error
786434 Allow changing CLI Passwords from Secondary and Application Servers.
786751 Added Distinguished Name (DN) field in Users View table.DN can now be used as a filter.
787562 Devices registered with incorrect icon type in MDM integration.
787563 NullPointerException (NPE) during L2 poll of Meraki.
787585 DHCP fingerprints are not matching DHCP message type.
788089 RADIUS service will not start after upgrade to 9.2 if winbind is not fully configured.
788825

DHCP fingerprint additions, changes or improvements.

Added: "Camera","D-Link"; "Camera","TRENDnet"; "HVAC","Honeywell"

Updated: "Mobile","Samsung SmartWatch"; "Gaming","Nintendo"; "Network","Router/Netgear"; "Network","Router/D-Link"; "Network","Router/Trendnet"

Changed Device Type: "Network","Apple TV" -> "internet_tv","Apple TV"; "Network","Amazon Fire TV" -> "internet_tv","Amazon Fire TV"; "Network","Chromecast" -> "internet_tv","Chromecast"; "Network","DIRECTV" -> "internet_tv","DIRECTV"; "Network","DVR/TiVo" -> "internet_tv","DVR/TiVo";

"Network","Roku Media Player" -> "internet_tv","Roku Media Player"

790403 ClassCastException in AirespaceSwitch during WAP read.
790747 FortiGate interface with VLANs does not show device connections to VLAN sub interfaces for device detection traps.
0784737 0785526 Location and IPRange method match failure prevent matching lower rank rules.
788729 RADIUS 802.1x proxy intermittently stops working.
791342 Manually Registered IP Phones get incorrect device type assigned.
758009 SSH access fails to Allied Tellesys AT8000S.
782433 Fix Integration for D-Link DGS-3130-30TS.
790854 Failure to properly read Cisco trunk ports results in undesired VLAN switching.
791304 Selecting "Uncheck All"in an Admin Profile removes General permissions.
791401 By Day grouping is incorrect under Dashboard > Scans.
794362 System Update not reliably trusting fnac-updates.fortinet.net
791276 Clicking EULA Link When Logging In As New User Goes To Broken Link.
793920 Default Admin Profiles Have No Permissions
782760 Huawei S7706 switch does not correctly reflect the interface port number in Label column.

796105

Device Type incorrectly changing for registered devices.

Version 9.2.3

Ticket #

Description (9.2.3.0435)

769558 NullPointerException registering a rogue host from the Hosts View.
640841 SSH connection to some AlaxalA switches fail.
741373 Support for Mobile Iron V2 API
746585 Cisco Mac Move Notification Trap support.
750248 Unable to access the secondary server's Configuration Wizard in a High Availability configuration.
752792 Device Profiling Rule registration not setting user/group membership.
753937 "Run NMAP" is now an option under Users & Hosts >Endpoint Fingerprints in the UI.
754279 Host record marked "At Risk" due tothe generation of the "Persistent Agent Not Communicating" alarm fail to be marked "Safe" after "Communication Resumed" is generated.
754605 Added Tripp Lite DHCP fingerprints
758009 Added support to change VLANs via CLI on Allied Telesyn 8000S.
759018 Admin user with admin user profile permissions to Access, Add/Modify and delete "Users" is unable to create a new regular user.
761276 User/Host Profile with Location does not use Portal defined in Portal Configuration.
762071 Radius Auth/EAP Type columns empty in Network > Device > Ports > Adapters table.
762081 bsc-rename-ethers service fails on virtual machines.
762702 Improved FortiClient EMS polling.Previously, not all hosts were retrieved upon a poll, causing some hosts not to register.
765477 FortiClient EMS test connect still fails after correcting a credential mistake.
765483 Fortinet EMS Version parsing is broken for EMS 7.0.
765899 EMS integration does not take into account theignoredAdapters.txt list.Can cause Adapter/Host record generation with Fortinet virtual adapters.
766600 L3 polling support for Inhand IR915L Router
767209 Aerohive VLAN interfaces do not update on resynchronization after VLAN ID or Profile ID change.
767942 Incorrect serial number used for CSF protocol used for SSO.
768329 Fail to determine port type for Cisco SG Switches with latest Cisco firmware.
768673 OS name for OS X devices between DHCP and Fortiguard fingerprints do not match.
768785 The GUI value "Registered Host" now displays as "Registered Host With Owner".
768793 Race condition causing StaleStateException in FirewallSessionManager.
768822 FortiSwitch does not respond to Change of Auth (COA) packet due to FortiNAC not sending the correct secret.
769851 Accounting Stop Message is discarded from Link Mode FortiSwitches when using Local Radius.
770034 FGT 1800F labeled as 1500D
770192 Device Profiling rules stop processing as expected if HTTP method is used and HTTP is timing out.
770208 Juniper switches fail to change VLAN on ports that are RADIUS enabled.
770548 Operating System custom attribute does not save in Device Profiling Rule.
770562 Device Profiler is performing all scans before checking for matches.
770695 Local RADIUS fails to find correct port on Extreme Summit X, preventing proper VLAN assignment.
770730 Local RADIUS service goes down & does not restart when FortiNAC processes are restarted.
770738 Ruckus API version detection not working for login API
770830 Device Rule Confirmation Failure event is not generated for some methods.
770930 High L3 Polling frequency in environments with no SSO management configured.
771038 Port state actions without clear actions cannot be saved in the Event to Alarm mapping.
771149 "Confirm Device Rule on Connect" does not work properly when "Confirm Device Rule on Interval" is also enabled within the same Device Profiling rule.
771157 MobileIron Cloud application poll can fail if licenseID is too long.
771422 RFC 3576 (CoA/RADIUS Disconnect) support for Extreme switches.
771506 Erroneous creation of redundant unique keys could overfill Group table key limits.
771685 Apresia integration RADIUS 802.1x support incomplete.
771705 Change Inhand mib file to not use WRITE_HIDDEN in 9.1. and 9.2.
771743 FSSO tags not sent to FortiGate with multi-VDOM Fabric Connections.
771939 Automatically detect MAC format for RADIUS CoA requests for Juniper switches.
772010 Wireless clients are not correctly processed on FortinetAPs when using some multi-vdom configurations.
773053 RADIUS not mapping to correct AD server when Kerberos and NetBIOS names differ.
773828 Not polling L2 information from PNetworks switches with latest firmware.
773841 Meraki Switch VLAN read/set fails when the ifIndex does not match the dot1d index.
774202 Adjusted timestamp in syslog CEF message format.Previous formatting prevented some systems from properly processing syslog from FortiNAC.
774724 Unable to filter Hosts and Adapters by status through API.
775973 Option to prevent auto-logging on users during authentication is absent during L2 polling.
776123 Unable to add/modify groups starting with "!" (bang).
777124 A higher ranked policy more general than a lower ranked policy is still honored if disabled.Lower ranked policy displays with a strike-through and is ignored.
777126 Invalid MAC address doesn't skip non-matching OUI Method.
777400 Syncing "Role Based Access" group on the Control manager (NCM) may delete sub-groups on the synchronized POD.
777479 Control Manager (NCM) Dashboard tile is very slow to load.
777511 RADIUS support for HP 2910 and 2920 switches.
777778 Unable to switch VLANs on Juniper switch via 802.1x RADIUS in Proxy mode.
778108 Windows domain check Device Profiling method fails if there is no domain user logged on.
778112 Performance issue when performing group membership lookups.Symptoms include usually high CPU utilization.
778157 L2 Polling issues with Cisco 9800 WLC firmware 17.3.
778520 Added SQL query for GroupManager.getGroupsMembershipIDs() when determining group membership in order to improve performance.
779873 FortiNAC processes taking unusually long to startup due to delays resuming FirewallSessionMgr.
779901 Vulnerabilties in mysql versions less than 5.6.42.
780282 FortiNAC Events using old vendor name "Bradford Networks".
780626 Huawei Wireless controller imports nameless APs.
780790 CLI Failing to Alcatel Omni 6860-P48.
782374 L2 polling not parsing correctly for Motorola 7.X devices.
782740 Unable to read default and current vlans for Ruijie switches.
782744 Script install-winbind-virtual contains spaces around = assignments - invalid
783227 Operating System updates from the UI fail when freeradius gpg key is not present.
783544 Fortigate FG-200F improperly labeled as FG-201E.
783552 nac.service / ProcessManager not running at startup when no IP on box, leads to processes down.
783621 Host import related Memory issues.
783944 Exception reading VLANs or SSIDs on Meru 4100 with firmware 5.1-93.
784601 Group membership lookup causing high CPU utilization.
784957 Not polling L2 information from Cisco ME-3400E-24TS-M router.
786401 Remote Scan -> Linux x86_64 -> 500 Error
786434 Allow changing CLI Passwords from Secondary and Application Servers.
786751 Added Distinguished Name (DN) field in Users View table.DN can now be used as a filter.
787562 Devices registered with incorrect icon type in MDM integration.
787563 NullPointerException (NPE) during L2 poll of Meraki.
787585 DHCP fingerprints are not matching DHCP message type.
788089 RADIUS service will not start after upgrade to 9.2 if winbind is not fully configured.
788825

DHCP fingerprint additions, changes or improvements.

Added: "Camera","D-Link"; "Camera","TRENDnet"; "HVAC","Honeywell"

Updated: "Mobile","Samsung SmartWatch"; "Gaming","Nintendo"; "Network","Router/Netgear"; "Network","Router/D-Link"; "Network","Router/Trendnet"

Changed Device Type: "Network","Apple TV" -> "internet_tv","Apple TV"; "Network","Amazon Fire TV" -> "internet_tv","Amazon Fire TV"; "Network","Chromecast" -> "internet_tv","Chromecast"; "Network","DIRECTV" -> "internet_tv","DIRECTV"; "Network","DVR/TiVo" -> "internet_tv","DVR/TiVo";

"Network","Roku Media Player" -> "internet_tv","Roku Media Player"

790403 ClassCastException in AirespaceSwitch during WAP read.
790747 FortiGate interface with VLANs does not show device connections to VLAN sub interfaces for device detection traps.
0784737 0785526 Location and IPRange method match failure prevent matching lower rank rules.
788729 RADIUS 802.1x proxy intermittently stops working.
791342 Manually Registered IP Phones get incorrect device type assigned.
758009 SSH access fails to Allied Tellesys AT8000S.
782433 Fix Integration for D-Link DGS-3130-30TS.
790854 Failure to properly read Cisco trunk ports results in undesired VLAN switching.
791304 Selecting "Uncheck All"in an Admin Profile removes General permissions.
791401 By Day grouping is incorrect under Dashboard > Scans.
794362 System Update not reliably trusting fnac-updates.fortinet.net
791276 Clicking EULA Link When Logging In As New User Goes To Broken Link.
793920 Default Admin Profiles Have No Permissions
782760 Huawei S7706 switch does not correctly reflect the interface port number in Label column.

796105

Device Type incorrectly changing for registered devices.