Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.2.0. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

604172

Webfilter cannot communicate with FortiGuard through proxy.

728311

FortiProxy bypassed FTP MODE command when protocol option configuration was set to block.

734909

ICAP error messages use the correct replacement messages rather than the existing, hard-coded 502 response.

764817, 786194, 789150, 796489, 796574, 800013, 802841, 806595, 807653, 808091, 808203, 808454, 817881, 817995, 827721, 829497, 829543, 830074, 832716, 833174, 835163, 835638, 836141, 836142, 837089, 840519, 840525, 842519

Fix GUI issues.

752001

Ensure route entry removal whenever system.ha.unicast-gateway updates.

763951

Speed up policy learning by using a delta config.

766102

Change name from FortiAI to FortiNDR.

768980, 770178, 773671, 777370, 777718, 788697, 789520, 789600, 789982

Implicitly enforce deepscan when HTTP CONNECT request or TLS SNI partially matches to a policy.

776989

Fixed overflow when adding VDOM.

777032, 803217

Improve url-rating by FortiGuard URL rating raw-flag, fix isolate does not work.

778766, 783072, 783811

Port bug fix from FOS: wad forward-server monitor doesn't work.

780182

WAD crash at wad_http_fwd_msg_body.

781891

Add upgrade code to handle lost LDAP search filter option value.

781943

Disable default firewall policy action for explicit proxy on ZTNA rules.

783201

Memory usage tunning for webcache.

783837

Primary FortiProxy license status is changing from "Valid" to "Warning" after a successfull upgrade under an HA cluster fix.

784337

OVF contains wrong VMDK for HW15 and FortiGate-label fix.

784338

OVF files contain FortiGate-VM references fix.

784797

Fix SSH over HTTP policy matching issue and ICAP server failures.

784891

Fix UTM features list is missing on policy page of type ssh/ssh-tunnel/wanopt/ftp.

785232

Comment out unwanted references to SD-WAN.

785912

Some fields (e.g. utm features) are not valid or missing according to the policy type fix.

787027

Fix antivirus profile content disarm options are not rendered correctly.

787496

Fix WAD memory leak on matching shaping policy.

787895

Fix potential memory corruption in wad_stats.

787977, 805228

Fix several issues related to dedicated-to option.

788822

Update kernel to v5.10.109.

789422

Fix missing ICAP request for CONNECT.

791235

Fix ssl exempt check condition for nontp policy.

791668

Traffic Shaping match fix

792065

DLP block an email with multi attachments via MAPI, but the log cannot show all the blocked files.

792579

Fix implicit deny policy logs and HTTP transaction logs not working.

793251

Unable to add IPv6 address group objects to policies fix.

793687

The source port range is not changed in kernel according to the CLI configuration fix.

794165, 803452

Fix fast match generation update after config change.

794753

Fix the issue authz header line is removed for HTTP basic authentication request.

795159

Add traffic log.action as 'pending' for not full matched policy.

795621

Fix data corruption on SSL traffic.

795970

As long as the ICAP function is turned on, the website front will be abnormal.

796019

Access issue with Application Control or IPS.

796152

Fix key_share leak on HRR.

796664

Fix domain-fronting conflict with HTTP2 connection coalescing.

797270

Fix ha-mgmt interface binding.

797609

IPv6 gateway route is not installed fix.

797809

Fix super_admin is not prompted to select between RO and RW access.

798027

Rollback multiple session-base users check under ip-base authenticate and rollback userquery logic at http-get-user.

798054

Fix SSL layer data flow-control.

798118

WAD process crashes at wad_async_queue_time_out.

798745

Fix delayed CRLF 204 handling in ICAP.

799171

Fix shaping policy match crash by pol_ctx double free.

799214

Follow-up enforce deepscan when HTTP CONNECT: enforce fwdsvr, except host-cate not match.

799278

Transparent mode "set dedicated-to management" not working as expected fix.

799718

When to-pol with auth(group/user) is set to action isolate, request fails to be redirected to WAD.

800243

Dedicated to management interfaces allow incoming connections on extra ports.

800262

Access of NULL pointer in sslvpnd fix.

800921

HTTPS request via tp-policy + fw server and authentication, crashes @__wad_http_policy_category_notify.

801174

Add multiple HTTP request headers and extract .tar.gz file for external resource.

801492

If the icap remote server is abnormal, the service connected through FortiProxy will be abnormal.

802222

FSSO traffic log has group info but no user information. Add save guard when calling af->make().

802303

ICAP - correct ICAP server max_conn and health check server IP leak issue.

802333

Add sec_profile when matched implicit policy on HTTP traffic.

802866

Fix certificate ha sync related issues.

803159

FortiProxy blocks uncompressed oversize file, the AV UTM log does not cache the correct information.

803217

Fix policy matching with multiple category type proxy-address.

803380, 807332

WAD does not forward 302 HTTP redirect to end-client. WAD memory leak when convert explicit proxy to captive portal.

803794

Custom upgrade code to handle the loss of local certificate data during upgrade.

804689

ICAP "respmod-forward-rules" should AND "header-group" entries.

804853

Fix SSL traffic occasionally fail.

805210

Fix NTLM agentless authenticate fail due to user-restriction after FSSO service down.

805819

FortiProxy as explicit web proxy did not block file transfer via ftp-over-http which has same hash value from ems-threat-feed.

806066

Avoid Syncing Outgoing-ip in webproxy.global.

806130

Fix proxy-address with host-regex match for IP URL.

806224

Execute ha manage does not work in FortiProxy cluster when trusted host is configured fix.

806595

Add License Sharing Information Widget on GUI.

807090

Upgrade IA Engine to Version 8.

807280

Fix proxy the certificate error when no policy matched.

808040

Kerberos authentication failed when upgrade FortiProxy.

808043

Fix disclaimer page is redirecting to incorrect URL.

808074

Allow content-encoding: UTF-8 passthrough.

808598, 809201, 809341

Local-ICAP Server Response does not contain Virus Response Header names and values, like X-Virus-ID or X-Infection-Found.

808769

Prevent HA Syncing of gui-dashboard and ems-tag to fix ICAP local server sync issue.

809813

Prefetch URLs report crawl for http://www.<whatever>.com failed (error: 255).

809832

Adding local-in rules for NTD server.

810570, 811995

Fixed several WebCache issues.

810571

Fix SSL exempt check condition for non-transparent policy.

811259

Fix WAD leak on IPS session objects.

813261

With learn-client-ip enable policy able to control based on the learn-client-ip but logs not reflecting.

813317

In transparent mode, implement srcaddr-negate, dstaddr-negate, and service-negate.

813348

Failure to access HTTPS virtual server after the flow control in SSL port improved.

813693

Event type of "infected" instead of "ems-threat-feed" logged when cached ems-threat-feed scan result used in FTP download.

813769

Fix WAD memory leak after enable ICAP profile 'respmod-forward-rules'.

814199

Change FortiGate reference to FortiProxy in "update-server-location" of "config sys fortiguard".

814266

Fix TP Policy displaying explicit proxy service list and vice-versa.

814569

Physical FortiProxy keeps killing usbmuxd.

815203

Traffic forwarded to fw-server is always rebind with outgoing interface/ip despite of the masquerade configuration.

815313

Fix WAD crash on wad_ssl_cert_check_auth_status().

816205

Fix uninitialized ses_ctx usr_addr.

817056

The inactivity timer is 30 minutes, and renewed any time it is given out by the pool for ICAP traffic, or when any traffic flows through the connection in either direction.

817173

Fix an issue where dst-addr iptables rules are incorrect.

817722

Second try to a URL using prefetch failed.

817750

Fix WAD crash when web-proxy.forward-server-group does not have server-list.

817770

Change default source port range to 1024-65001.

817979

Explicit-outgoing-ip is not learned when config changes fix.

818406

Client got 304 response if a cached object with vary headers and got expired.

819700

Fix traffic shaping on VLAN interface.

820084

Fetch IPsec tunnel status from strongSwan and display it in the GUI.

821242

ICAP bypassing yields to web traffic corrupted upon ICAP_server failure to response.

822015

Add support for ACI dynamic address in WAD.

823247, 823829

WAD user_info process memory leak.

824259

Too many redirections error with session based authenthication and web-auth-cookie.

825349

WAD crashed at wad_http_req_finished with signal 11.

826088

Agent-based NTLM authentication resulted in blank user entry and allowed traffic.

826385

Add missing file.

826441

Fix WAD firewall schedule config change does not take effect.

827900

Fix empty FortiView monitor pages.

830907

WAD can crash when building a proxy policy if an address group has no member.

831428

Corrupted forward-server caused WAD crash.

832041

Filter wad log messages by process type or process ID.

832905

Crash when trying to access uninitialized array member.

833372

WAD crash due to long line reponse from server and SSH filter vulnerability.

833798

CID bug FORWARD_NULL in user info inventory.

834684

Configuring SNMP wiped kernel SNAT settings.

835180

Fix traffic shaping on newly configured VLAN interface.

835623, 837608

Embed base64 string images instead of URLs for WAD blocking page.

835625

Add kernel flow messages to help with kernel debugging.

835739

Website will not reply if Connection uses the wrong letter case

836286

ICAP infection headers could not show the correct file name.

836464

The mac address type removed from firewall addresses, as it is not supported.

836723

HTTP/HTTPS requests that match a policy with an L7 address are not forward to the isolate server.

836915

DNS queries fail with dnsfilter applied.

837598

cloudinitd crash when deploying FortiProxy on AWS.

837729

Bypass interface kernel driver reset after rebooting.

838888

Fix HA sequential upgrade.

838910

WAD crashes on attaching history traffic stats to NULL tcp_port from session.

840189

Rare case in HA configuration caused kernel panic.

840680

Fix SSLVPN connection issue.

841632

Add bypass URLs to HTTP isolator check .

842338, 842826

Fix VPN widgets in the GUI.

842469

ZTNA access stuck when going through TCP-fwd towards HTTPS with a deep-inspection profile.

842840

Fix kernel panic when form HA A/P mode.

842926

Failure to perform SNAT when creating an FTP PASSIVE mode data channel.

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.2.0. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

604172

Webfilter cannot communicate with FortiGuard through proxy.

728311

FortiProxy bypassed FTP MODE command when protocol option configuration was set to block.

734909

ICAP error messages use the correct replacement messages rather than the existing, hard-coded 502 response.

764817, 786194, 789150, 796489, 796574, 800013, 802841, 806595, 807653, 808091, 808203, 808454, 817881, 817995, 827721, 829497, 829543, 830074, 832716, 833174, 835163, 835638, 836141, 836142, 837089, 840519, 840525, 842519

Fix GUI issues.

752001

Ensure route entry removal whenever system.ha.unicast-gateway updates.

763951

Speed up policy learning by using a delta config.

766102

Change name from FortiAI to FortiNDR.

768980, 770178, 773671, 777370, 777718, 788697, 789520, 789600, 789982

Implicitly enforce deepscan when HTTP CONNECT request or TLS SNI partially matches to a policy.

776989

Fixed overflow when adding VDOM.

777032, 803217

Improve url-rating by FortiGuard URL rating raw-flag, fix isolate does not work.

778766, 783072, 783811

Port bug fix from FOS: wad forward-server monitor doesn't work.

780182

WAD crash at wad_http_fwd_msg_body.

781891

Add upgrade code to handle lost LDAP search filter option value.

781943

Disable default firewall policy action for explicit proxy on ZTNA rules.

783201

Memory usage tunning for webcache.

783837

Primary FortiProxy license status is changing from "Valid" to "Warning" after a successfull upgrade under an HA cluster fix.

784337

OVF contains wrong VMDK for HW15 and FortiGate-label fix.

784338

OVF files contain FortiGate-VM references fix.

784797

Fix SSH over HTTP policy matching issue and ICAP server failures.

784891

Fix UTM features list is missing on policy page of type ssh/ssh-tunnel/wanopt/ftp.

785232

Comment out unwanted references to SD-WAN.

785912

Some fields (e.g. utm features) are not valid or missing according to the policy type fix.

787027

Fix antivirus profile content disarm options are not rendered correctly.

787496

Fix WAD memory leak on matching shaping policy.

787895

Fix potential memory corruption in wad_stats.

787977, 805228

Fix several issues related to dedicated-to option.

788822

Update kernel to v5.10.109.

789422

Fix missing ICAP request for CONNECT.

791235

Fix ssl exempt check condition for nontp policy.

791668

Traffic Shaping match fix

792065

DLP block an email with multi attachments via MAPI, but the log cannot show all the blocked files.

792579

Fix implicit deny policy logs and HTTP transaction logs not working.

793251

Unable to add IPv6 address group objects to policies fix.

793687

The source port range is not changed in kernel according to the CLI configuration fix.

794165, 803452

Fix fast match generation update after config change.

794753

Fix the issue authz header line is removed for HTTP basic authentication request.

795159

Add traffic log.action as 'pending' for not full matched policy.

795621

Fix data corruption on SSL traffic.

795970

As long as the ICAP function is turned on, the website front will be abnormal.

796019

Access issue with Application Control or IPS.

796152

Fix key_share leak on HRR.

796664

Fix domain-fronting conflict with HTTP2 connection coalescing.

797270

Fix ha-mgmt interface binding.

797609

IPv6 gateway route is not installed fix.

797809

Fix super_admin is not prompted to select between RO and RW access.

798027

Rollback multiple session-base users check under ip-base authenticate and rollback userquery logic at http-get-user.

798054

Fix SSL layer data flow-control.

798118

WAD process crashes at wad_async_queue_time_out.

798745

Fix delayed CRLF 204 handling in ICAP.

799171

Fix shaping policy match crash by pol_ctx double free.

799214

Follow-up enforce deepscan when HTTP CONNECT: enforce fwdsvr, except host-cate not match.

799278

Transparent mode "set dedicated-to management" not working as expected fix.

799718

When to-pol with auth(group/user) is set to action isolate, request fails to be redirected to WAD.

800243

Dedicated to management interfaces allow incoming connections on extra ports.

800262

Access of NULL pointer in sslvpnd fix.

800921

HTTPS request via tp-policy + fw server and authentication, crashes @__wad_http_policy_category_notify.

801174

Add multiple HTTP request headers and extract .tar.gz file for external resource.

801492

If the icap remote server is abnormal, the service connected through FortiProxy will be abnormal.

802222

FSSO traffic log has group info but no user information. Add save guard when calling af->make().

802303

ICAP - correct ICAP server max_conn and health check server IP leak issue.

802333

Add sec_profile when matched implicit policy on HTTP traffic.

802866

Fix certificate ha sync related issues.

803159

FortiProxy blocks uncompressed oversize file, the AV UTM log does not cache the correct information.

803217

Fix policy matching with multiple category type proxy-address.

803380, 807332

WAD does not forward 302 HTTP redirect to end-client. WAD memory leak when convert explicit proxy to captive portal.

803794

Custom upgrade code to handle the loss of local certificate data during upgrade.

804689

ICAP "respmod-forward-rules" should AND "header-group" entries.

804853

Fix SSL traffic occasionally fail.

805210

Fix NTLM agentless authenticate fail due to user-restriction after FSSO service down.

805819

FortiProxy as explicit web proxy did not block file transfer via ftp-over-http which has same hash value from ems-threat-feed.

806066

Avoid Syncing Outgoing-ip in webproxy.global.

806130

Fix proxy-address with host-regex match for IP URL.

806224

Execute ha manage does not work in FortiProxy cluster when trusted host is configured fix.

806595

Add License Sharing Information Widget on GUI.

807090

Upgrade IA Engine to Version 8.

807280

Fix proxy the certificate error when no policy matched.

808040

Kerberos authentication failed when upgrade FortiProxy.

808043

Fix disclaimer page is redirecting to incorrect URL.

808074

Allow content-encoding: UTF-8 passthrough.

808598, 809201, 809341

Local-ICAP Server Response does not contain Virus Response Header names and values, like X-Virus-ID or X-Infection-Found.

808769

Prevent HA Syncing of gui-dashboard and ems-tag to fix ICAP local server sync issue.

809813

Prefetch URLs report crawl for http://www.<whatever>.com failed (error: 255).

809832

Adding local-in rules for NTD server.

810570, 811995

Fixed several WebCache issues.

810571

Fix SSL exempt check condition for non-transparent policy.

811259

Fix WAD leak on IPS session objects.

813261

With learn-client-ip enable policy able to control based on the learn-client-ip but logs not reflecting.

813317

In transparent mode, implement srcaddr-negate, dstaddr-negate, and service-negate.

813348

Failure to access HTTPS virtual server after the flow control in SSL port improved.

813693

Event type of "infected" instead of "ems-threat-feed" logged when cached ems-threat-feed scan result used in FTP download.

813769

Fix WAD memory leak after enable ICAP profile 'respmod-forward-rules'.

814199

Change FortiGate reference to FortiProxy in "update-server-location" of "config sys fortiguard".

814266

Fix TP Policy displaying explicit proxy service list and vice-versa.

814569

Physical FortiProxy keeps killing usbmuxd.

815203

Traffic forwarded to fw-server is always rebind with outgoing interface/ip despite of the masquerade configuration.

815313

Fix WAD crash on wad_ssl_cert_check_auth_status().

816205

Fix uninitialized ses_ctx usr_addr.

817056

The inactivity timer is 30 minutes, and renewed any time it is given out by the pool for ICAP traffic, or when any traffic flows through the connection in either direction.

817173

Fix an issue where dst-addr iptables rules are incorrect.

817722

Second try to a URL using prefetch failed.

817750

Fix WAD crash when web-proxy.forward-server-group does not have server-list.

817770

Change default source port range to 1024-65001.

817979

Explicit-outgoing-ip is not learned when config changes fix.

818406

Client got 304 response if a cached object with vary headers and got expired.

819700

Fix traffic shaping on VLAN interface.

820084

Fetch IPsec tunnel status from strongSwan and display it in the GUI.

821242

ICAP bypassing yields to web traffic corrupted upon ICAP_server failure to response.

822015

Add support for ACI dynamic address in WAD.

823247, 823829

WAD user_info process memory leak.

824259

Too many redirections error with session based authenthication and web-auth-cookie.

825349

WAD crashed at wad_http_req_finished with signal 11.

826088

Agent-based NTLM authentication resulted in blank user entry and allowed traffic.

826385

Add missing file.

826441

Fix WAD firewall schedule config change does not take effect.

827900

Fix empty FortiView monitor pages.

830907

WAD can crash when building a proxy policy if an address group has no member.

831428

Corrupted forward-server caused WAD crash.

832041

Filter wad log messages by process type or process ID.

832905

Crash when trying to access uninitialized array member.

833372

WAD crash due to long line reponse from server and SSH filter vulnerability.

833798

CID bug FORWARD_NULL in user info inventory.

834684

Configuring SNMP wiped kernel SNAT settings.

835180

Fix traffic shaping on newly configured VLAN interface.

835623, 837608

Embed base64 string images instead of URLs for WAD blocking page.

835625

Add kernel flow messages to help with kernel debugging.

835739

Website will not reply if Connection uses the wrong letter case

836286

ICAP infection headers could not show the correct file name.

836464

The mac address type removed from firewall addresses, as it is not supported.

836723

HTTP/HTTPS requests that match a policy with an L7 address are not forward to the isolate server.

836915

DNS queries fail with dnsfilter applied.

837598

cloudinitd crash when deploying FortiProxy on AWS.

837729

Bypass interface kernel driver reset after rebooting.

838888

Fix HA sequential upgrade.

838910

WAD crashes on attaching history traffic stats to NULL tcp_port from session.

840189

Rare case in HA configuration caused kernel panic.

840680

Fix SSLVPN connection issue.

841632

Add bypass URLs to HTTP isolator check .

842338, 842826

Fix VPN widgets in the GUI.

842469

ZTNA access stuck when going through TCP-fwd towards HTTPS with a deep-inspection profile.

842840

Fix kernel panic when form HA A/P mode.

842926

Failure to perform SNAT when creating an FTP PASSIVE mode data channel.