Fortinet white logo
Fortinet white logo

Known Issues Version 9.4.5

Known Issues Version 9.4.5

Ticket #

Description

1022276

NCM standalone and HA CA license entitlement is correctly reflected, but accessing the portal on Primary CA throws "You do not have permission to access this page" and accessing any menu under Policy & Objects throws “Server Error”.

1030210

Need to prevent dir sync from running multiple processes at once.

999354

Delay in Agent reporting external network connectors causing host to remain isolated.

1010097

Re-scanning a host at risk causes false positives having Required Critical Updates applied on endpoint compliance scan.

972925

OS information on device/adapter is not always accurate.

1003792

Hosts not registering correctly when using Auto Registration function in model configuration for some Cisco switches.

1002475

Unable to scan using Dissolvable Agent with spaces in scan name.

998758

Captive Portal Authentication Failure message "Custom text" not taking effect when customized via Portal Configuration.

998736

Syslog format changed in FortiGate Firmware 7.4.2 causing FortiNAC to not be able to parse MAC Add, Delete, and Move messages.

996006

API Calls failing to remove or update user records.

996381

Applications view is not able to display hosts with specific applications.

993873

Host Search with wildcard provides unexpected results.

977249 Host removed from GUI when L2-Poll with NEC-QX Switch.
927754 Custom Registration failed with the error "Anonymous Guest Access is not Enabled".
982255 Unable to Parse L3 HPE 5130-24G-SFP-4SFP+ EI Switch 1.3.6.1.4.1.25506.11.1.185
956436 FortiNAC does not function properly as a RADIUS proxy when integrated with a NEC-QX switch.
827283 The Roaming Guest Logical Network is missing from the Model Configuration of FortiGate and possibly from other vendors.
955985 Extreme switch with 'description-string' in switchport config won't display connected adapters in GUI device model.
974270 Non fabric root FortiGate do not have dynamic tags after firmware update.

986049

FortiSwitch MAC Trap Notifications not mapping to correct port.

978586

L2 poll of Palo Alto firewall brings VPN clients offline.

969655

LAG ports on FortiGate are not shown in Inventory > ports view.

950004

Bearer Token Authentication is currently not supported for Jamf MDM integrations. Basic Authentication must be used.

932546 In [9.4.4] on NCM, 'Server Responses' appear duplicated when distributing firmware.

928827

Host aging is not applied to IP Phone device type.

924474

Unable to select SSIDs when creating/modifying a port group under System > Groups. Workaround: Under SSID tab, right click SSID, select Group Membership & select the desired group.

800326

Cisco chassis switch with a Cisco WLC connected via port channel shows as a rogue.

887470 Domain with single character between dots in multiple dot domains results in error when adding to allowed domains.
863826 License Management view in the UI always displays "Base" for the License Name when using subscription licenses. Workaround: Use the License Information Dashboard Widget.
861201 Windows 11 Domain Check.
852670 AP showing up as learned uplink not WAP Uplink.
852560 Custom Guest Account Password e-mail template is not used for Self Registration Self Registered Guest.
827283 Roaming Guest Logical Network missing from FortiGate Model Configuration and possibly other vendors.
826653 FortiNAC supplied Dynamic Addresses on the FortiGate can become orphaned in FortiNAC High Availability environments. This can cause unintended network access.
824088 Unable to update existing Registered Host records using Legacy View > Hosts > Import.
810574 "Unable to scan" message when using Dissolvable agent if scan configuration label contains non US-ASCII characters.
795411 Not able to click the "In Use" number of Concurrent Licenses Widget.
776077 Local Radius to Winbind connection cannot be secured at this time.
767548 Register Game system with Host Inventory success page is not working.
752538 When in the Users & Hosts > Applications view, selecting an application and clicking the Show Hosts option displays a page that does not provide accurately filtered results. Workaround: Navigate Users & Hosts > Hosts and create a custom filter to list hosts associated to an application.
710583 L2 Polling Mist APs can result in more API requests than Mist allows per hour.
708936 FortiNAC will log off SSO for sessions that remain connected to a managed FortiGate IPSec VPN tunnel after 12 hours.
682438 Page Unresponsive' error when exporting hosts. For details and workaround see related KB article https://community.fortinet.com/t5/FortiNAC/Technical-Note-Page-Unresponsive-error-when-exporting-hosts/ta-p/193878.
Not all models of all network devices can be configured to perform Physical MAC Address Filtering even though the Admin UI indicates that the configuration can be set. Resolution: Hosts can be disabled by implementing a Dead-end VLAN.
For Portal v2 configurations, web pages that are stored in the site directory to be used for Scan Configurations will not be included when you do an Export of the Portal v2 configuration. Resolution: The files in the site directory are backed up with the Remote Backup feature, but otherwise keep a copy of these files in a safe place.
Removing a device from the L2 Wired Devices or L2 Wireless Devices Group does not disable L2 (Hosts) Polling under the Polling tab in Topology.
The "Set all hosts 'Risk State' to 'Safe'" button changes the status of all hosts marked At-Risk to Safe. However, the status of the individual scans for each host remain unchanged.
In a Layer 3 High Availability (HA) environment, configWizard must have a DHCP scope defined. Running configWizard without a DHCP scope can cause a failover.
On FortiNAC appliances with CentOS 7, duplicate log messages may appear in dhcpd.log for each sub interface (eth1, eth1:1, eth1:2, etc).
System > Settings > Updates > Operating System will only record and display dates of OS updates that are completed through the Administrative UI. If Operating System updates are run via command line using the "yum" tool, the update is not recorded. Resolution: Execute Operating System Updates through the Administrative UI in order to maintain update history.
Only English versions of AV/AS and their corresponding definitions are supported.
Anti-Virus product Iolo technologies System Mechanic Professional is currently not supported.

Known Issues Version 9.4.5

Known Issues Version 9.4.5

Ticket #

Description

1022276

NCM standalone and HA CA license entitlement is correctly reflected, but accessing the portal on Primary CA throws "You do not have permission to access this page" and accessing any menu under Policy & Objects throws “Server Error”.

1030210

Need to prevent dir sync from running multiple processes at once.

999354

Delay in Agent reporting external network connectors causing host to remain isolated.

1010097

Re-scanning a host at risk causes false positives having Required Critical Updates applied on endpoint compliance scan.

972925

OS information on device/adapter is not always accurate.

1003792

Hosts not registering correctly when using Auto Registration function in model configuration for some Cisco switches.

1002475

Unable to scan using Dissolvable Agent with spaces in scan name.

998758

Captive Portal Authentication Failure message "Custom text" not taking effect when customized via Portal Configuration.

998736

Syslog format changed in FortiGate Firmware 7.4.2 causing FortiNAC to not be able to parse MAC Add, Delete, and Move messages.

996006

API Calls failing to remove or update user records.

996381

Applications view is not able to display hosts with specific applications.

993873

Host Search with wildcard provides unexpected results.

977249 Host removed from GUI when L2-Poll with NEC-QX Switch.
927754 Custom Registration failed with the error "Anonymous Guest Access is not Enabled".
982255 Unable to Parse L3 HPE 5130-24G-SFP-4SFP+ EI Switch 1.3.6.1.4.1.25506.11.1.185
956436 FortiNAC does not function properly as a RADIUS proxy when integrated with a NEC-QX switch.
827283 The Roaming Guest Logical Network is missing from the Model Configuration of FortiGate and possibly from other vendors.
955985 Extreme switch with 'description-string' in switchport config won't display connected adapters in GUI device model.
974270 Non fabric root FortiGate do not have dynamic tags after firmware update.

986049

FortiSwitch MAC Trap Notifications not mapping to correct port.

978586

L2 poll of Palo Alto firewall brings VPN clients offline.

969655

LAG ports on FortiGate are not shown in Inventory > ports view.

950004

Bearer Token Authentication is currently not supported for Jamf MDM integrations. Basic Authentication must be used.

932546 In [9.4.4] on NCM, 'Server Responses' appear duplicated when distributing firmware.

928827

Host aging is not applied to IP Phone device type.

924474

Unable to select SSIDs when creating/modifying a port group under System > Groups. Workaround: Under SSID tab, right click SSID, select Group Membership & select the desired group.

800326

Cisco chassis switch with a Cisco WLC connected via port channel shows as a rogue.

887470 Domain with single character between dots in multiple dot domains results in error when adding to allowed domains.
863826 License Management view in the UI always displays "Base" for the License Name when using subscription licenses. Workaround: Use the License Information Dashboard Widget.
861201 Windows 11 Domain Check.
852670 AP showing up as learned uplink not WAP Uplink.
852560 Custom Guest Account Password e-mail template is not used for Self Registration Self Registered Guest.
827283 Roaming Guest Logical Network missing from FortiGate Model Configuration and possibly other vendors.
826653 FortiNAC supplied Dynamic Addresses on the FortiGate can become orphaned in FortiNAC High Availability environments. This can cause unintended network access.
824088 Unable to update existing Registered Host records using Legacy View > Hosts > Import.
810574 "Unable to scan" message when using Dissolvable agent if scan configuration label contains non US-ASCII characters.
795411 Not able to click the "In Use" number of Concurrent Licenses Widget.
776077 Local Radius to Winbind connection cannot be secured at this time.
767548 Register Game system with Host Inventory success page is not working.
752538 When in the Users & Hosts > Applications view, selecting an application and clicking the Show Hosts option displays a page that does not provide accurately filtered results. Workaround: Navigate Users & Hosts > Hosts and create a custom filter to list hosts associated to an application.
710583 L2 Polling Mist APs can result in more API requests than Mist allows per hour.
708936 FortiNAC will log off SSO for sessions that remain connected to a managed FortiGate IPSec VPN tunnel after 12 hours.
682438 Page Unresponsive' error when exporting hosts. For details and workaround see related KB article https://community.fortinet.com/t5/FortiNAC/Technical-Note-Page-Unresponsive-error-when-exporting-hosts/ta-p/193878.
Not all models of all network devices can be configured to perform Physical MAC Address Filtering even though the Admin UI indicates that the configuration can be set. Resolution: Hosts can be disabled by implementing a Dead-end VLAN.
For Portal v2 configurations, web pages that are stored in the site directory to be used for Scan Configurations will not be included when you do an Export of the Portal v2 configuration. Resolution: The files in the site directory are backed up with the Remote Backup feature, but otherwise keep a copy of these files in a safe place.
Removing a device from the L2 Wired Devices or L2 Wireless Devices Group does not disable L2 (Hosts) Polling under the Polling tab in Topology.
The "Set all hosts 'Risk State' to 'Safe'" button changes the status of all hosts marked At-Risk to Safe. However, the status of the individual scans for each host remain unchanged.
In a Layer 3 High Availability (HA) environment, configWizard must have a DHCP scope defined. Running configWizard without a DHCP scope can cause a failover.
On FortiNAC appliances with CentOS 7, duplicate log messages may appear in dhcpd.log for each sub interface (eth1, eth1:1, eth1:2, etc).
System > Settings > Updates > Operating System will only record and display dates of OS updates that are completed through the Administrative UI. If Operating System updates are run via command line using the "yum" tool, the update is not recorded. Resolution: Execute Operating System Updates through the Administrative UI in order to maintain update history.
Only English versions of AV/AS and their corresponding definitions are supported.
Anti-Virus product Iolo technologies System Mechanic Professional is currently not supported.