Fortinet black logo

Version 9.4.4

Version 9.4.4

Ticket #

Description

924690 Using a single dot as the Scan name should be restricted by the API, as it causes filesystem issues.
833088 Deleting a switch removes all port nesting's removing all ports from FortiNAC System Port Group.
834025 Allied Telesys devices using standard SNMP for L2 polling fails if there are entries in the dot1qTpFdb table with a port index of 0.
835149 When an endpoint is registered as a device in Host AND Inventory/Topology, it is not possible to edit the host role. The option is available, but changes do not apply.
858184 Custom Subject line for Self Registration Request sent to sponsor does not reflect custom text.
860595 FortiNAC unable to change admin state on FortiGate firewall physical ports.
866343 Proxy RADIUS support added for Arista switches (802.1x and MAB).
867183 CLI communication can fail due to invalid SSH key when devices using a Virtual IP (VIP) fail over.A new device attribute (MultiKnownHostEntries) has been added to address.For details see Model configuration in the 9.4 Administration Guide.
868451 L3 support for Forcepoint firewalls.
868712 In some instances, Administration UI is inaccessible after running the Configuration Wizard during a new deployment.Clicking Config Wizard results in "No User"error.
869052 Meraki MX doesn't pass CLI credentials validation.
869097 Prioritize the IP -> MAC value provided by RadiusServer for managed wireless clients.
869316 Excessive "Authentication Failure" events after L2 poll.
869605 CLI credentials are removed from the Ubiquiti AP device model after applying changes.
869961 Added Aruba CX series switch Port Channel support.
874812 Private VLANs not switching on Cisco switches.
875287 Added User/Host Profile and Policy Configuration ID validation for API POSTs to Authentication, Endpoint Compliance, Portal, Supplicant, and Access policies.
875588 Unable to remove users from the All Administrators group.
875720 REST API v2 query for Scan Results returns no results.
876003 Incorrect license information displayed in License Management GUI view after upgrade to 9.4.2. License Key Details list features as "Disabled". Correct entitlements displayed in Dashboard and CLI.
876116 Upgrade to 9.4.2 > ManagedElementInterface causing issues with startup and device credentials.
877934 LDAP communication failure if Primary AD is reachable but Secondary is not.
877942 Performance issues related to Firewall Session table growing to large.
877980 Navigating to Logs > Audit Logs generates console error "Missing Type: LOGICAL_NETWORK" when in Legacy View.
878080 Aruba CX Switch Incorrect VLAN Management Syntax.
878836 Intune MDM Integration 'Invalid Audience' when using an App registration in the Azure Government cloud.
879773 Cannot Change "Perform proactive "Active" method profiling" setting in Device Profiler.
880761 IP->MAC resolution doesn't update the adapter's IP after a proactive L3 polling when VLAN change occurs.
880796 API - AccessConfiguration - Access configurations should not require a Logical Network.
882265 FortiNAC is not sending the correct serial number field to FortiAnalyzer (FAZ).
882782 Fix NullPointerException in MessagingGatewayPlugin.sendSMS().
883046 Fortinac not sending Radius Disconnect/CoA to Aruba IAP when there is a status change/policy match.
883068 SMTP SMS Gateway service connector: Country code prefix is incorrectly prepended to outgoing SMS messages.
883080 Local Radius attempts to look up mac addresses in the directory for mac-auth auth requests.
883129 Mist L2 polling may not function properly due to how Mist devices are modeled in FortiNAC.
883146 Secondary may restart repeatedly.
883221 FortiNAC now processes static MAC address entries by default for Arista switches.
883680 404 response to HTTPS GET when polling Firewall Sessions on FortiGate running FOS 7.2+.
884329 Base license, User/Host profiles and Network Access Policies throw permissions errors.
884345 Improved error messaging when creating a new device using REST API.
887915 Endpoint Compliance Custom scans improperly state "in-use" by deleted scans and cannot be deleted.
888179 Updated integer fields in the FirewallSession table to accomodate bigger values.
888212 High Availability configuration: Endpoint Compliance Scans are not replicated to secondary.
889103 Test Device Profiling Rule option in Network > Inventory Adapters view is not matching properly.
889132 Global Custom Scans are not fully removed after deleting from Manager.Consequently, scan cannot be edited or deleted on the managed FortiNAC server.
890009 Unable to read VLANs on Ruijie S5310 switch.
890015 Unexpected error encountered when attempting to modify or create a Syslog file under System > Settings > System communication > Syslog Files.
890929 Unable to restart server after uploading new license key through UI (Setup Progress > Enter License Key).
891332 HTTP 500 error when installing license key using Modify License button in License Management view.
892486 Secondary server in a High Availability configuration does not reflect the correct concurrent count in License Management.
892856 Communication between FortiNAC Manager and managed FortiNAC servers enhanced for security. Important: Requires additional configuration. See Upgrade Requirements for details.
893582 Changing default credentials in Config Wizard logs an error.
894157 Guest > View > Send SMS button returns error.
895085 RADIUS Performance problems on rogue host record creation.
896471 Licensetool not correctly displaying the subscription level from the FortiNAC Manager.
0896100 , 0896556 Error adding/removing Switch Ports to Port Group from Groups view.
883378, 882567 HA>UI hangs when re-running config HA when connected to the shared address.
884322, 855084 Type column would not render correctly for Device Profiling Rule.
888616, 893561 System > Scheduler GUI error encountered after upgrade from an older FortiNAC version.
897851 FortiNAC not supporting QX series Mac-notification trap.
905865 Cannot enable "Enable Quarantine VLAN Switching" option in GUI.
871758 Parse IPv6 addresses from the ipNetToPhysical table correctly.
904541 FirmwareVersion attribute missing from Meraki APs on upgrade.
904755 Several log messages related to SSO addressing initialization were always being printed which filled the logs with unnecessary info.
904052 Policy & Objects - Endpoint Compliance - Scans - Fixed rendering of escaped characters in both editors and tables.
833305 Guest account password is unmasked on badge when user does not have password viewing permissions.
903869 Improve error message if NCM add server fails.
901925 Disable revoking admin permissions when all mappings are removed.
899075 NPE in readarp function caused an incomplete ARP table for Sonicwall appliance.
902072 Replace Hashtable with ConcurrentHashMap for DatabaseServer.savedObjects.
900284 Issue in TelnetServer that causes the Juniper logout sequence to pause for the entirety of the current Telnet/SSH timeout.
899047 Replace: systemd-run -M VIRT_WINBIND_INST systemctl is-enabled winbindWith: systemctl is-enabled -M VIRT_WINBIND_INST winbind
897921 Removed hostname column from Firewall Sessions view.
872900 Typo in Guided Installation informational dialog.
888213 Validate credentials of FS results in severe removeLogicalNetworkConfigurations passed null or transient ManagedElement.
885306 WLC Extreme VX9000 MAC table cannot be parsed.
884077 Gracefully handle guest account passwords permissions issue.
874363 SSLVPN user loses and receives TAG periodically.
871340 Entering XSS causes exception and blank page.
876504 Fixed username formatting.
876818 Download Logs from UI should have longer timeout.
906953 Check if the device supports the UCD-SNMP-MIB, if so, model as a Ubiquiti switch.
907844 Add missing RADIUS properties to Arista switches.
897921 Allow hostname collection from firewall with a global option.
883989 Update default Phone attribute for AD LDAP.
901236 Fix RADIUS Access-Reject when Direct Configuration Network Access Policy is in use.
895097 Only return the custom device type if it is a system created device type or if the type starts with cust_.
894165 Fix to ensure DPC rules with multiple adjacent spaces run correctly.
907854 VLAN change commands fail for Cisco SG-250.
897921 This allows the hostnames to show up in the firewall session table, but does not update the host record unless the global option is enabled.
879697 Sync Global Objects and EPC Scans via REST RPC.
911439 Incorrect OID in device properties file - Device support for MICROSENS G6 Switch.
900281 Reverse proxy via FortiPoC causes incorrect URLs in Config Wizard.
890988 Fixed handle of Inventory > Network.
910216 Unable to upload G Suite Credential JSON file on NacOS.
907328 Fixed Guest & Contractor table null reporting total when empty.
902533 Fixed char escaping in Port and Adapter Props.
901257 HTML is not supported in the "Guest Account details".
904624 Host summary panel does not show accurate total host count.
908861 Custom filter is not applied in host or adapter view.
879814 879814 - Users & Hosts - Guests & Contractors - View Accounts - Guest Account - Max Attendees should not show any number at all because it is not a conference.
903055 Hosts - Filters - IP Phone - Fixed lack of selection for in the Host->Device Type dropdown.
906398 Fixed validation error preventing log receiver modification; modifications were rejected as duplicates based on matching existing ip and port.
896002 Error creating guest accounts with duration greater than 20 days.
907523 Fixed Guest & Contractors table filter function, also fixed option menu layout issue.
911132 Container status check is now failing due to changes to the NAC sudoers file.
885306 Fixed StringIndexOutOfBoundsException regarding the WLC Extreme VX9000 MAC table parsing.
897921 Added code to retrieve the hostname field from the response.
885306 Fixed an issue with regex regarding the WLC Extreme VX9000 MAC table parsing.
881650 HP J9776A 2530-24G Switch - uplink ports are not properly displayed in Ports view.
912128 Disconnect requests are not sent for Meraki switches.
917032 MICROSENS G6 Switch and hide Macs on link feature.
915532 Adding a DHCP scope with invalid label prevents ConfigWizard from applying any further DHCP scope changes.
919423 API endpoint /host/scan returns status code 405 (Method Not Allowed) to POST request.
927355 User is unable to edit the current VLAN value in the port properties dialog on a FortiSwitch modeled in the QA FortiNAC system.
924250 PaloAlto fails validation for CLI testing SSH when REST API is supposed to be used.
922911 Add missing radius options to the various NEC-QX switch Model Configuration views.
925117 Fix retrieval of MibId value and add session logout to Ruijie.mib file.
899075 NPE in readarp function causes an incomplete ARP table for Sonicwall appliance.
909839 SSO messages are being logged on and off repeatedly.
910706 Cannot create Guest account with REST v2 results in errors 400 and 500.
922274 Custom fields not loading Security Incidents.
912115 Guest Self Registration Error "The input is required".
908302 FortiNAC Icons are squeezed in the host status.
889986 Issues while enabling and adding subnets in Require Connected Adapter.
932578 Unable to L2 poll FortiLink switches on FOS 7.4.

Version 9.4.4

Ticket #

Description

924690 Using a single dot as the Scan name should be restricted by the API, as it causes filesystem issues.
833088 Deleting a switch removes all port nesting's removing all ports from FortiNAC System Port Group.
834025 Allied Telesys devices using standard SNMP for L2 polling fails if there are entries in the dot1qTpFdb table with a port index of 0.
835149 When an endpoint is registered as a device in Host AND Inventory/Topology, it is not possible to edit the host role. The option is available, but changes do not apply.
858184 Custom Subject line for Self Registration Request sent to sponsor does not reflect custom text.
860595 FortiNAC unable to change admin state on FortiGate firewall physical ports.
866343 Proxy RADIUS support added for Arista switches (802.1x and MAB).
867183 CLI communication can fail due to invalid SSH key when devices using a Virtual IP (VIP) fail over.A new device attribute (MultiKnownHostEntries) has been added to address.For details see Model configuration in the 9.4 Administration Guide.
868451 L3 support for Forcepoint firewalls.
868712 In some instances, Administration UI is inaccessible after running the Configuration Wizard during a new deployment.Clicking Config Wizard results in "No User"error.
869052 Meraki MX doesn't pass CLI credentials validation.
869097 Prioritize the IP -> MAC value provided by RadiusServer for managed wireless clients.
869316 Excessive "Authentication Failure" events after L2 poll.
869605 CLI credentials are removed from the Ubiquiti AP device model after applying changes.
869961 Added Aruba CX series switch Port Channel support.
874812 Private VLANs not switching on Cisco switches.
875287 Added User/Host Profile and Policy Configuration ID validation for API POSTs to Authentication, Endpoint Compliance, Portal, Supplicant, and Access policies.
875588 Unable to remove users from the All Administrators group.
875720 REST API v2 query for Scan Results returns no results.
876003 Incorrect license information displayed in License Management GUI view after upgrade to 9.4.2. License Key Details list features as "Disabled". Correct entitlements displayed in Dashboard and CLI.
876116 Upgrade to 9.4.2 > ManagedElementInterface causing issues with startup and device credentials.
877934 LDAP communication failure if Primary AD is reachable but Secondary is not.
877942 Performance issues related to Firewall Session table growing to large.
877980 Navigating to Logs > Audit Logs generates console error "Missing Type: LOGICAL_NETWORK" when in Legacy View.
878080 Aruba CX Switch Incorrect VLAN Management Syntax.
878836 Intune MDM Integration 'Invalid Audience' when using an App registration in the Azure Government cloud.
879773 Cannot Change "Perform proactive "Active" method profiling" setting in Device Profiler.
880761 IP->MAC resolution doesn't update the adapter's IP after a proactive L3 polling when VLAN change occurs.
880796 API - AccessConfiguration - Access configurations should not require a Logical Network.
882265 FortiNAC is not sending the correct serial number field to FortiAnalyzer (FAZ).
882782 Fix NullPointerException in MessagingGatewayPlugin.sendSMS().
883046 Fortinac not sending Radius Disconnect/CoA to Aruba IAP when there is a status change/policy match.
883068 SMTP SMS Gateway service connector: Country code prefix is incorrectly prepended to outgoing SMS messages.
883080 Local Radius attempts to look up mac addresses in the directory for mac-auth auth requests.
883129 Mist L2 polling may not function properly due to how Mist devices are modeled in FortiNAC.
883146 Secondary may restart repeatedly.
883221 FortiNAC now processes static MAC address entries by default for Arista switches.
883680 404 response to HTTPS GET when polling Firewall Sessions on FortiGate running FOS 7.2+.
884329 Base license, User/Host profiles and Network Access Policies throw permissions errors.
884345 Improved error messaging when creating a new device using REST API.
887915 Endpoint Compliance Custom scans improperly state "in-use" by deleted scans and cannot be deleted.
888179 Updated integer fields in the FirewallSession table to accomodate bigger values.
888212 High Availability configuration: Endpoint Compliance Scans are not replicated to secondary.
889103 Test Device Profiling Rule option in Network > Inventory Adapters view is not matching properly.
889132 Global Custom Scans are not fully removed after deleting from Manager.Consequently, scan cannot be edited or deleted on the managed FortiNAC server.
890009 Unable to read VLANs on Ruijie S5310 switch.
890015 Unexpected error encountered when attempting to modify or create a Syslog file under System > Settings > System communication > Syslog Files.
890929 Unable to restart server after uploading new license key through UI (Setup Progress > Enter License Key).
891332 HTTP 500 error when installing license key using Modify License button in License Management view.
892486 Secondary server in a High Availability configuration does not reflect the correct concurrent count in License Management.
892856 Communication between FortiNAC Manager and managed FortiNAC servers enhanced for security. Important: Requires additional configuration. See Upgrade Requirements for details.
893582 Changing default credentials in Config Wizard logs an error.
894157 Guest > View > Send SMS button returns error.
895085 RADIUS Performance problems on rogue host record creation.
896471 Licensetool not correctly displaying the subscription level from the FortiNAC Manager.
0896100 , 0896556 Error adding/removing Switch Ports to Port Group from Groups view.
883378, 882567 HA>UI hangs when re-running config HA when connected to the shared address.
884322, 855084 Type column would not render correctly for Device Profiling Rule.
888616, 893561 System > Scheduler GUI error encountered after upgrade from an older FortiNAC version.
897851 FortiNAC not supporting QX series Mac-notification trap.
905865 Cannot enable "Enable Quarantine VLAN Switching" option in GUI.
871758 Parse IPv6 addresses from the ipNetToPhysical table correctly.
904541 FirmwareVersion attribute missing from Meraki APs on upgrade.
904755 Several log messages related to SSO addressing initialization were always being printed which filled the logs with unnecessary info.
904052 Policy & Objects - Endpoint Compliance - Scans - Fixed rendering of escaped characters in both editors and tables.
833305 Guest account password is unmasked on badge when user does not have password viewing permissions.
903869 Improve error message if NCM add server fails.
901925 Disable revoking admin permissions when all mappings are removed.
899075 NPE in readarp function caused an incomplete ARP table for Sonicwall appliance.
902072 Replace Hashtable with ConcurrentHashMap for DatabaseServer.savedObjects.
900284 Issue in TelnetServer that causes the Juniper logout sequence to pause for the entirety of the current Telnet/SSH timeout.
899047 Replace: systemd-run -M VIRT_WINBIND_INST systemctl is-enabled winbindWith: systemctl is-enabled -M VIRT_WINBIND_INST winbind
897921 Removed hostname column from Firewall Sessions view.
872900 Typo in Guided Installation informational dialog.
888213 Validate credentials of FS results in severe removeLogicalNetworkConfigurations passed null or transient ManagedElement.
885306 WLC Extreme VX9000 MAC table cannot be parsed.
884077 Gracefully handle guest account passwords permissions issue.
874363 SSLVPN user loses and receives TAG periodically.
871340 Entering XSS causes exception and blank page.
876504 Fixed username formatting.
876818 Download Logs from UI should have longer timeout.
906953 Check if the device supports the UCD-SNMP-MIB, if so, model as a Ubiquiti switch.
907844 Add missing RADIUS properties to Arista switches.
897921 Allow hostname collection from firewall with a global option.
883989 Update default Phone attribute for AD LDAP.
901236 Fix RADIUS Access-Reject when Direct Configuration Network Access Policy is in use.
895097 Only return the custom device type if it is a system created device type or if the type starts with cust_.
894165 Fix to ensure DPC rules with multiple adjacent spaces run correctly.
907854 VLAN change commands fail for Cisco SG-250.
897921 This allows the hostnames to show up in the firewall session table, but does not update the host record unless the global option is enabled.
879697 Sync Global Objects and EPC Scans via REST RPC.
911439 Incorrect OID in device properties file - Device support for MICROSENS G6 Switch.
900281 Reverse proxy via FortiPoC causes incorrect URLs in Config Wizard.
890988 Fixed handle of Inventory > Network.
910216 Unable to upload G Suite Credential JSON file on NacOS.
907328 Fixed Guest & Contractor table null reporting total when empty.
902533 Fixed char escaping in Port and Adapter Props.
901257 HTML is not supported in the "Guest Account details".
904624 Host summary panel does not show accurate total host count.
908861 Custom filter is not applied in host or adapter view.
879814 879814 - Users & Hosts - Guests & Contractors - View Accounts - Guest Account - Max Attendees should not show any number at all because it is not a conference.
903055 Hosts - Filters - IP Phone - Fixed lack of selection for in the Host->Device Type dropdown.
906398 Fixed validation error preventing log receiver modification; modifications were rejected as duplicates based on matching existing ip and port.
896002 Error creating guest accounts with duration greater than 20 days.
907523 Fixed Guest & Contractors table filter function, also fixed option menu layout issue.
911132 Container status check is now failing due to changes to the NAC sudoers file.
885306 Fixed StringIndexOutOfBoundsException regarding the WLC Extreme VX9000 MAC table parsing.
897921 Added code to retrieve the hostname field from the response.
885306 Fixed an issue with regex regarding the WLC Extreme VX9000 MAC table parsing.
881650 HP J9776A 2530-24G Switch - uplink ports are not properly displayed in Ports view.
912128 Disconnect requests are not sent for Meraki switches.
917032 MICROSENS G6 Switch and hide Macs on link feature.
915532 Adding a DHCP scope with invalid label prevents ConfigWizard from applying any further DHCP scope changes.
919423 API endpoint /host/scan returns status code 405 (Method Not Allowed) to POST request.
927355 User is unable to edit the current VLAN value in the port properties dialog on a FortiSwitch modeled in the QA FortiNAC system.
924250 PaloAlto fails validation for CLI testing SSH when REST API is supposed to be used.
922911 Add missing radius options to the various NEC-QX switch Model Configuration views.
925117 Fix retrieval of MibId value and add session logout to Ruijie.mib file.
899075 NPE in readarp function causes an incomplete ARP table for Sonicwall appliance.
909839 SSO messages are being logged on and off repeatedly.
910706 Cannot create Guest account with REST v2 results in errors 400 and 500.
922274 Custom fields not loading Security Incidents.
912115 Guest Self Registration Error "The input is required".
908302 FortiNAC Icons are squeezed in the host status.
889986 Issues while enabling and adding subnets in Require Connected Adapter.
932578 Unable to L2 poll FortiLink switches on FOS 7.4.