Fortinet white logo
Fortinet white logo

Known Issues Version 9.4.7

Known Issues Version 9.4.7

Ticket # Description

1093080

Failover occurs on High Availability pair configured with a shared IP (VIP). Caused by the system check failing on the primary server. For details and workaround see KB article 354324.

https://community.fortinet.com/t5/FortiNAC/Technical-Tip-After-upgrading-FortiNAC-to-9-4-7-on-an-HA-pair/ta-p/354324

1070325

Making changes in the older Model Configuration views (right-click model > Model Configuration) can override custom SSH port settings in the Credentials tab. Workaround: Make all changes using the newer Model Configuration and Credentials tabs at the top of the Inventory view.

1030210 Need to prevent dir sync from running multiple processes at once.
1030103 Model Configuration > 500 error if there are no CLI configurations.
1022559 FortiNAC has no ability to support weak SSH ciphers.
1022276 NCM standalone and HA CA license entitlement is correctly reflected, but accessing the portal on Primary CA throws "You do not have permission to access this page" and accessing any menu under Policy & Objects throws “Server Error”.
1016576 FortiNAC sometimes creates duplicate virtual interfaces.
1014123 Mist AP's do not discover properly if Hostname is not configured.
1010097 Re-scanning a host at risk causes false positives having Required Critical Updates applied on endpoint compliance scan.
1002475 Unable to scan using Dissolvable Agent with spaces in scan name.
974270 Non fabric root FortiGate do not have dynamic tags after firmware update.
932546 In [9.4.4] on NCM, 'Server Responses' appear duplicated when distributing firmware.
928827 Host aging is not applied to IP Phone device type.
924474 Unable to select SSIDs when creating/modifying a port group under System > Groups. Workaround: Under SSID tab, right click SSID, select Group Membership & select the desired group.
863826 License Management view in the UI always displays "Base" for the License Name when using subscription licenses. Workaround: Use the License Information Dashboard Widget.
861201 Windows 11 Domain Check.
827283 Roaming Guest Logical Network missing from FortiGate Model Configuration and possibly other vendors.
826653 FortiNAC supplied Dynamic Addresses on the FortiGate can become orphaned in FortiNAC High Availability environments. This can cause unintended network access.
824088 Unable to update existing Registered Host records using Legacy View > Hosts > Import.
800326 Cisco chassis switch with a Cisco WLC connected via port channel shows as a rogue.
776077 Local Radius to Winbind connection cannot be secured at this time.
767548 Register Game system with Host Inventory success page is not working.
710583 L2 Polling Mist APs can result in more API requests than Mist allows per hour.
708936 FortiNAC will log off SSO for sessions that remain connected to a managed FortiGate IPSec VPN tunnel after 12 hours.
Not all models of all network devices can be configured to perform Physical MAC Address Filtering even though the Admin UI indicates that the configuration can be set. Resolution: Hosts can be disabled by implementing a Dead-end VLAN.
For Portal v2 configurations, web pages that are stored in the site directory to be used for Scan Configurations will not be included when you do an Export of the Portal v2 configuration. Resolution: The files in the site directory are backed up with the Remote Backup feature, but otherwise keep a copy of these files in a safe place.
Removing a device from the L2 Wired Devices or L2 Wireless Devices Group does not disable L2 (Hosts) Polling under the Polling tab in Topology.
The "Set all hosts 'Risk State' to 'Safe'" button changes the status of all hosts marked At-Risk to Safe. However, the status of the individual scans for each host remain unchanged.
In a Layer 3 High Availability (HA) environment, configWizard must have a DHCP scope defined. Running configWizard without a DHCP scope can cause a failover.
On FortiNAC appliances with CentOS 7, duplicate log messages may appear in dhcpd.log for each sub interface (eth1, eth1:1, eth1:2, etc).
System > Settings > Updates > Operating System will only record and display dates of OS updates that are completed through the Administrative UI. If Operating System updates are run via command line using the "yum" tool, the update is not recorded. Resolution: Execute Operating System Updates through the Administrative UI in order to maintain update history.
Only English versions of AV/AS and their corresponding definitions are supported.
Anti-Virus product Iolo technologies System Mechanic Professional is currently not supported.

Known Issues Version 9.4.7

Known Issues Version 9.4.7

Ticket # Description

1093080

Failover occurs on High Availability pair configured with a shared IP (VIP). Caused by the system check failing on the primary server. For details and workaround see KB article 354324.

https://community.fortinet.com/t5/FortiNAC/Technical-Tip-After-upgrading-FortiNAC-to-9-4-7-on-an-HA-pair/ta-p/354324

1070325

Making changes in the older Model Configuration views (right-click model > Model Configuration) can override custom SSH port settings in the Credentials tab. Workaround: Make all changes using the newer Model Configuration and Credentials tabs at the top of the Inventory view.

1030210 Need to prevent dir sync from running multiple processes at once.
1030103 Model Configuration > 500 error if there are no CLI configurations.
1022559 FortiNAC has no ability to support weak SSH ciphers.
1022276 NCM standalone and HA CA license entitlement is correctly reflected, but accessing the portal on Primary CA throws "You do not have permission to access this page" and accessing any menu under Policy & Objects throws “Server Error”.
1016576 FortiNAC sometimes creates duplicate virtual interfaces.
1014123 Mist AP's do not discover properly if Hostname is not configured.
1010097 Re-scanning a host at risk causes false positives having Required Critical Updates applied on endpoint compliance scan.
1002475 Unable to scan using Dissolvable Agent with spaces in scan name.
974270 Non fabric root FortiGate do not have dynamic tags after firmware update.
932546 In [9.4.4] on NCM, 'Server Responses' appear duplicated when distributing firmware.
928827 Host aging is not applied to IP Phone device type.
924474 Unable to select SSIDs when creating/modifying a port group under System > Groups. Workaround: Under SSID tab, right click SSID, select Group Membership & select the desired group.
863826 License Management view in the UI always displays "Base" for the License Name when using subscription licenses. Workaround: Use the License Information Dashboard Widget.
861201 Windows 11 Domain Check.
827283 Roaming Guest Logical Network missing from FortiGate Model Configuration and possibly other vendors.
826653 FortiNAC supplied Dynamic Addresses on the FortiGate can become orphaned in FortiNAC High Availability environments. This can cause unintended network access.
824088 Unable to update existing Registered Host records using Legacy View > Hosts > Import.
800326 Cisco chassis switch with a Cisco WLC connected via port channel shows as a rogue.
776077 Local Radius to Winbind connection cannot be secured at this time.
767548 Register Game system with Host Inventory success page is not working.
710583 L2 Polling Mist APs can result in more API requests than Mist allows per hour.
708936 FortiNAC will log off SSO for sessions that remain connected to a managed FortiGate IPSec VPN tunnel after 12 hours.
Not all models of all network devices can be configured to perform Physical MAC Address Filtering even though the Admin UI indicates that the configuration can be set. Resolution: Hosts can be disabled by implementing a Dead-end VLAN.
For Portal v2 configurations, web pages that are stored in the site directory to be used for Scan Configurations will not be included when you do an Export of the Portal v2 configuration. Resolution: The files in the site directory are backed up with the Remote Backup feature, but otherwise keep a copy of these files in a safe place.
Removing a device from the L2 Wired Devices or L2 Wireless Devices Group does not disable L2 (Hosts) Polling under the Polling tab in Topology.
The "Set all hosts 'Risk State' to 'Safe'" button changes the status of all hosts marked At-Risk to Safe. However, the status of the individual scans for each host remain unchanged.
In a Layer 3 High Availability (HA) environment, configWizard must have a DHCP scope defined. Running configWizard without a DHCP scope can cause a failover.
On FortiNAC appliances with CentOS 7, duplicate log messages may appear in dhcpd.log for each sub interface (eth1, eth1:1, eth1:2, etc).
System > Settings > Updates > Operating System will only record and display dates of OS updates that are completed through the Administrative UI. If Operating System updates are run via command line using the "yum" tool, the update is not recorded. Resolution: Execute Operating System Updates through the Administrative UI in order to maintain update history.
Only English versions of AV/AS and their corresponding definitions are supported.
Anti-Virus product Iolo technologies System Mechanic Professional is currently not supported.