Resolved issues
The following issues have been fixed in FortiProxy 7.2.0. For inquiries about a particular bug, please contact Customer Service & Support.
Bug ID |
Description |
---|---|
604172 |
Webfilter cannot communicate with FortiGuard through proxy. |
728311 |
FortiProxy bypassed FTP MODE command when protocol option configuration was set to block. |
734909 |
ICAP error messages use the correct replacement messages rather than the existing, hard-coded 502 response. |
764817, 786194, 789150, 796489, 796574, 800013, 802841, 806595, 807653, 808091, 808203, 808454, 817881, 817995, 827721, 829497, 829543, 830074, 832716, 833174, 835163, 835638, 836141, 836142, 837089, 840519, 840525, 842519 |
Fix GUI issues. |
752001 |
Ensure route entry removal whenever system.ha.unicast-gateway updates. |
763951 |
Speed up policy learning by using a delta config. |
766102 |
Change name from FortiAI to FortiNDR. |
768980, 770178, 773671, 777370, 777718, 788697, 789520, 789600, 789982 |
Implicitly enforce deepscan when HTTP CONNECT request or TLS SNI partially matches to a policy. |
776989 |
Fixed overflow when adding VDOM. |
777032, 803217 |
Improve url-rating by FortiGuard URL rating raw-flag, fix isolate does not work. |
778766, 783072, 783811 |
Port bug fix from FOS: wad forward-server monitor doesn't work. |
780182 |
WAD crash at wad_http_fwd_msg_body. |
781891 |
Add upgrade code to handle lost LDAP search filter option value. |
781943 |
Disable default firewall policy action for explicit proxy on ZTNA rules. |
783201 |
Memory usage tunning for webcache. |
783837 |
Primary FortiProxy license status is changing from "Valid" to "Warning" after a successfull upgrade under an HA cluster fix. |
784337 |
OVF contains wrong VMDK for HW15 and FortiGate-label fix. |
784338 |
OVF files contain FortiGate-VM references fix. |
784797 |
Fix SSH over HTTP policy matching issue and ICAP server failures. |
784891 |
Fix UTM features list is missing on policy page of type ssh/ssh-tunnel/wanopt/ftp. |
785232 |
Comment out unwanted references to SD-WAN. |
785912 |
Some fields (e.g. utm features) are not valid or missing according to the policy type fix. |
787027 |
Fix antivirus profile content disarm options are not rendered correctly. |
787496 |
Fix WAD memory leak on matching shaping policy. |
787895 |
Fix potential memory corruption in wad_stats. |
787977, 805228 |
Fix several issues related to dedicated-to option. |
788822 |
Update kernel to v5.10.109. |
789422 |
Fix missing ICAP request for CONNECT. |
791235 |
Fix ssl exempt check condition for nontp policy. |
791668 |
Traffic Shaping match fix |
792065 |
DLP block an email with multi attachments via MAPI, but the log cannot show all the blocked files. |
792579 |
Fix implicit deny policy logs and HTTP transaction logs not working. |
793251 |
Unable to add IPv6 address group objects to policies fix. |
793687 |
The source port range is not changed in kernel according to the CLI configuration fix. |
794165, 803452 |
Fix fast match generation update after config change. |
794753 |
Fix the issue authz header line is removed for HTTP basic authentication request. |
795159 |
Add traffic log.action as 'pending' for not full matched policy. |
795621 |
Fix data corruption on SSL traffic. |
795970 |
As long as the ICAP function is turned on, the website front will be abnormal. |
796019 |
Access issue with Application Control or IPS. |
796152 |
Fix key_share leak on HRR. |
796664 |
Fix domain-fronting conflict with HTTP2 connection coalescing. |
797270 |
Fix ha-mgmt interface binding. |
797609 |
IPv6 gateway route is not installed fix. |
797809 |
Fix super_admin is not prompted to select between RO and RW access. |
798027 |
Rollback multiple session-base users check under ip-base authenticate and rollback userquery logic at http-get-user. |
798054 |
Fix SSL layer data flow-control. |
798118 |
WAD process crashes at wad_async_queue_time_out. |
798745 |
Fix delayed CRLF 204 handling in ICAP. |
799171 |
Fix shaping policy match crash by pol_ctx double free. |
799214 |
Follow-up enforce deepscan when HTTP CONNECT: enforce fwdsvr, except host-cate not match. |
799278 |
Transparent mode "set dedicated-to management" not working as expected fix. |
799718 |
When to-pol with auth(group/user) is set to action isolate, request fails to be redirected to WAD. |
800243 |
Dedicated to management interfaces allow incoming connections on extra ports. |
800262 |
Access of NULL pointer in sslvpnd fix. |
800921 |
HTTPS request via tp-policy + fw server and authentication, crashes @__wad_http_policy_category_notify. |
801174 |
Add multiple HTTP request headers and extract .tar.gz file for external resource. |
801492 |
If the icap remote server is abnormal, the service connected through FortiProxy will be abnormal. |
802222 |
FSSO traffic log has group info but no user information. Add save guard when calling af->make(). |
802303 |
ICAP - correct ICAP server max_conn and health check server IP leak issue. |
802333 |
Add sec_profile when matched implicit policy on HTTP traffic. |
802866 |
Fix certificate ha sync related issues. |
803159 |
FortiProxy blocks uncompressed oversize file, the AV UTM log does not cache the correct information. |
803217 |
Fix policy matching with multiple category type proxy-address. |
803380, 807332 |
WAD does not forward 302 HTTP redirect to end-client. WAD memory leak when convert explicit proxy to captive portal. |
803794 |
Custom upgrade code to handle the loss of local certificate data during upgrade. |
804689 |
ICAP "respmod-forward-rules" should AND "header-group" entries. |
804853 |
Fix SSL traffic occasionally fail. |
805210 |
Fix NTLM agentless authenticate fail due to user-restriction after FSSO service down. |
805819 |
FortiProxy as explicit web proxy did not block file transfer via ftp-over-http which has same hash value from ems-threat-feed. |
806066 |
Avoid Syncing Outgoing-ip in webproxy.global. |
806130 |
Fix proxy-address with host-regex match for IP URL. |
806224 |
Execute ha manage does not work in FortiProxy cluster when trusted host is configured fix. |
806595 |
Add License Sharing Information Widget on GUI. |
807090 |
Upgrade IA Engine to Version 8. |
807280 |
Fix proxy the certificate error when no policy matched. |
808040 |
Kerberos authentication failed when upgrade FortiProxy. |
808043 |
Fix disclaimer page is redirecting to incorrect URL. |
808074 |
Allow content-encoding: UTF-8 passthrough. |
808598, 809201, 809341 |
Local-ICAP Server Response does not contain Virus Response Header names and values, like X-Virus-ID or X-Infection-Found. |
808769 |
Prevent HA Syncing of gui-dashboard and ems-tag to fix ICAP local server sync issue. |
809813 |
Prefetch URLs report crawl for http://www.<whatever>.com failed (error: 255). |
809832 |
Adding local-in rules for NTD server. |
810570, 811995 |
Fixed several WebCache issues. |
810571 |
Fix SSL exempt check condition for non-transparent policy. |
811259 |
Fix WAD leak on IPS session objects. |
813261 |
With learn-client-ip enable policy able to control based on the learn-client-ip but logs not reflecting. |
813317 |
In transparent mode, implement srcaddr-negate, dstaddr-negate, and service-negate. |
813348 |
Failure to access HTTPS virtual server after the flow control in SSL port improved. |
813693 |
Event type of "infected" instead of "ems-threat-feed" logged when cached ems-threat-feed scan result used in FTP download. |
813769 |
Fix WAD memory leak after enable ICAP profile 'respmod-forward-rules'. |
814199 |
Change FortiGate reference to FortiProxy in "update-server-location" of "config sys fortiguard". |
814266 |
Fix TP Policy displaying explicit proxy service list and vice-versa. |
814569 |
Physical FortiProxy keeps killing usbmuxd. |
815203 |
Traffic forwarded to fw-server is always rebind with outgoing interface/ip despite of the masquerade configuration. |
815313 |
Fix WAD crash on wad_ssl_cert_check_auth_status(). |
816205 |
Fix uninitialized ses_ctx usr_addr. |
817056 |
The inactivity timer is 30 minutes, and renewed any time it is given out by the pool for ICAP traffic, or when any traffic flows through the connection in either direction. |
817173 |
Fix an issue where dst-addr iptables rules are incorrect. |
817722 |
Second try to a URL using prefetch failed. |
817750 |
Fix WAD crash when web-proxy.forward-server-group does not have server-list. |
817770 |
Change default source port range to 1024-65001. |
817979 |
Explicit-outgoing-ip is not learned when config changes fix. |
818406 |
Client got 304 response if a cached object with vary headers and got expired. |
819700 |
Fix traffic shaping on VLAN interface. |
820084 |
Fetch IPsec tunnel status from strongSwan and display it in the GUI. |
821242 |
ICAP bypassing yields to web traffic corrupted upon ICAP_server failure to response. |
822015 |
Add support for ACI dynamic address in WAD. |
823247, 823829 |
WAD user_info process memory leak. |
824259 |
Too many redirections error with session based authenthication and web-auth-cookie. |
825349 |
WAD crashed at wad_http_req_finished with signal 11. |
826088 |
Agent-based NTLM authentication resulted in blank user entry and allowed traffic. |
826385 |
Add missing file. |
826441 |
Fix WAD firewall schedule config change does not take effect. |
827900 |
Fix empty FortiView monitor pages. |
830907 |
WAD can crash when building a proxy policy if an address group has no member. |
831428 |
Corrupted forward-server caused WAD crash. |
832041 |
Filter wad log messages by process type or process ID. |
832905 |
Crash when trying to access uninitialized array member. |
833372 |
WAD crash due to long line reponse from server and SSH filter vulnerability. |
833798 |
CID bug FORWARD_NULL in user info inventory. |
834684 |
Configuring SNMP wiped kernel SNAT settings. |
835180 |
Fix traffic shaping on newly configured VLAN interface. |
835623, 837608 |
Embed base64 string images instead of URLs for WAD blocking page. |
835625 |
Add kernel flow messages to help with kernel debugging. |
835739 |
Website will not reply if |
836286 |
ICAP infection headers could not show the correct file name. |
836464 |
The mac address type removed from firewall addresses, as it is not supported. |
836723 |
HTTP/HTTPS requests that match a policy with an L7 address are not forward to the isolate server. |
836915 |
DNS queries fail with dnsfilter applied. |
837598 |
cloudinitd crash when deploying FortiProxy on AWS. |
837729 |
Bypass interface kernel driver reset after rebooting. |
838888 |
Fix HA sequential upgrade. |
838910 |
WAD crashes on attaching history traffic stats to NULL tcp_port from session. |
840189 |
Rare case in HA configuration caused kernel panic. |
840680 |
Fix SSLVPN connection issue. |
841632 |
Add bypass URLs to HTTP isolator check . |
842338, 842826 |
Fix VPN widgets in the GUI. |
842469 |
ZTNA access stuck when going through TCP-fwd towards HTTPS with a deep-inspection profile. |
842840 |
Fix kernel panic when form HA A/P mode. |
842926 |
Failure to perform SNAT when creating an FTP PASSIVE mode data channel. |