Resolved issues
The following issues have been fixed in FortiProxy 7.4.5. For inquiries about a particular bug, please contact Customer Service & Support.
Description |
Bug ID |
---|---|
1003762 |
Loss of connection with no internet access and multiple crashes for the application WAD. |
1027833 |
Proxy forwarding no longer works after firmware upgrade. |
1028626, 1028633 |
Sync issue due to casb.saas-application matching error. |
1026753 |
No alert email for license-related logs when alertmail setting.fpx-license-logs is enabled. |
1029833 |
WAD crash at wad_http_avscan_scan_cache_find. |
1029347 |
ICAP profile should not be counted towards SWG license seats. |
987003 |
Internet service and customer service groups do not work in proxy policies. |
1008421, 1029603 |
IP threat feed configured in global VDOM does not work when used as a destination address in a policy in a VDOM and the destination address is treated as having no addresses. |
1034036 |
FortiManager access is lost after upgrade when central-management type is fortimanager. |
1007411 |
Incorrect CLI version description in FortiProxy Hyper-V platforms. |
1025657 |
After upgrading, some websites are inaccessible when web cache is enabled. |
1017054 |
Traffic redirected through proxyd is blocked when the FortiProxy is in bridge mode. |
1036668 |
IPS default-action filter values do not match in GUI and CLI. |
1036823 |
Session-based authentication with form-based method cannot be configured in GUI when web-auth-cookie is not enabled. |
1037465 |
DNS filter profile search does not work for non-root VDOM. |
1038836 |
User, group, and URL category information missing in HTTP transaction log for cert-inspect HTTPS traffic. |
1020788 |
No log is generated when a user is redirected to SAML authentication. |
1029938 |
"exec ha manage" returns the "Bad vrf ' 32'" error. |
1003723 |
Cannot configure heartbeat interface IP or set up unicast HA in transparent mode. |
1042226 |
Potential crash in wsm_read_string(). |
1039033 |
FortiProxy sends a request to FortiGuard every 30 minutes and causes out-of-sync for a few minutes. |
1036145, 1036156, 1039217, 1045083, 1052888, 1052914 |
Integer overflow issues. |
1038447 |
FortiAnalyzer traffic is directed to the dedicated-to management interface even if the dedicated-to interface is down. |
998940,1032955 |
Duplicate file-filter logs. |
1037448 |
Passive FTP over SOCKS proxy does not send RETR command. |
1038453 |
Crash when sending HTTPS request with unexpected path to Captive-portal-ssl port. |
1045085 |
Overlapping buffer in memory copy may cause undefined behavior. |
1032454, 1047782, 1048529, 994780, 1045147, 1042239, 1042382 |
GUI issues. |
1046944 |
Transparent policy does not support interface-subnet firewall address type. |
1031971 |
Memory leak for multipart boundary in http/2. |
1047934 |
Disable ssh-rsa from SSH server host-key algorithm. |
1045459 |
The "munmap" function is called with an incorrect argument, which can result in buffer overflow. |
1043778 |
FortiProxy cannot detect the VFIO network inteface type in OCI. |
1041560 |
FortiProxy crashes after cache peer setting change. |
1046470 |
High CPU and WAD crashes on FPX-4000E. |
1045223 |
Cannot change log disk size after Azure template deployment. |
1043427 |
FortiProxy does not use the correct certificate configured for secure-proxy when multiple web-proxy entries exist. |
1043659 |
Some pages such as policy, address, dashboard cannot be loaded for FortiProxy secondary units after upgrading from 7.4.3 to 7.4.4. |
1043602 |
Error when creating HA with ha-mgmt interface. |
983358, 1001700 |
Memory leak when using SAML authentication. |
1020961 |
FortiProxy does not attempt to authenticate using the secondary Radius server when the primary is down. |
991626 |
The GUI option for selecting a wildcard FQDN destination for IPv6 SNAT does not work properly. |
1042442 |
SDN dynamic address does not work. |
997868, 1041622 |
Explicit FTPS does not work over SOCKS proxy. |
1041167 |
File Filter Profile is unavailable on the WebUI when policy type is FTP. |
990366, 1029049 |
Device freezes and randomly reboots. Kernel panic observed. |
1025061 |
Intermittent file uploading failure using SFTP on Winscp client after upgrade. |
1041490 |
Transparent policy schedule one-time match does not match system time. |
1049835 |
Inline CASB DB version rolls back to built-in version upon FortiProxy reboot or upgrade. |
1050348 |
DHCP relay does not work in FortiProxy. |
1050855 |
NTLM Agentless authentication does not work when LDAP cache is enabled. |
849814 |
Internet is not accessible through Android Emulator. |
1039006 |
Increase the maximum http2 header value length from 16 KB to 32KB to accommodate websites with a bigger header value. |
1042957 |
Traffic logs do not show transparent policy UUID and the Packets column always shows 0. |
1018996, 1019013, 1022461, 1038577, 1040368, 1042741 |
Optimize Inline CASB matching logic. |
1042975 |
High CPU load through ips-engine and WAD keeps crashing when the isolator profile has an empty entry. |
1047542 |
WAD fails to forward HTTP request with header 'accept-encoding: zstd' when strip-encoding is enabled. |
1048856 |
No status information for hardware sensor. |
1037299 |
Cache resolving issue in HA. |
1025553, 1052378 |
Inline IPS deep control crashes. |
1008556 |
Webcache cannot correctly handle content-encoding conversion for Brotli and zstd. |
1045438 |
FTP connection fails through wanopt profile with FTP. |
948034 |
VDOM still works after being disabled on GUI. |
1050156 |
WAD crash due to accessing uninitialized wad_fwd_srv list when process algo is closing. |
1049243 |
Access issue after changing captive portal type. |
1052991 |
Crash when getting eicar file with webfilter in transparent policy. |
1035614 |
Unpacked variables do not match the pack layout. |
1036201 |
WAD daemon for wad-config-notify has memory leak. |
967250 |
WAD removes whole path and not forward request to server when you set to delete specific url path with CASB customized UA. |
1060261 |
Uninitialized user group member. |
1024570 |
SSH deep-inspection with unsupported-version is bypassed. |
1052516 |
FortiProxy authentication rule misses some authentication schemes. |
1047758 |
Website encounters slowness and stuck issue due to http2. |
1044961 |
Scanunit internal error due to http data failing zlib data check during content decode. |
1052421 |
IPSet allows duplicate internet service entries in a single IP set. |
1003729 |
Unable to configure ha-mgmt-intf ip for FortiProxy in transparent mode. |
1036782 |
IPS sensor configuration does not filter out what is not supported. |
1054641 |
Error saying "Failed to enforce FortiOS Security Enforce mode" at FPX-400G startup. |
1030106 |
VIP configured in a transparent policy affects the behavior of FTP proxy. |
1049032 |
Unexpected logged kernel warnings. |
1052294 |
WAD crashes frequently with "signal 11 (Segmentation fault) received" and "signal 6 (Aborted) received". |
1052333 |
Some categories are missing under System > Replacement Messages in GUI. |
1006164 |
WAD crash log at wad_ips_hs.c. |
1054908, 1056282, 1056600 |
Refactor and improve WAD vd module management. |
1057454 |
Explicit proxy traffic is blocked by shaping policy and traffic log shows "Shaping policy internal error". |
1058198, 1060782 |
Traffic loop caused by HA in transparent mode. |
1060705 |
Crash at wad_sstr_upd at /code/daemon/wad/wad_str.h:96. |
1054591 |
GIF, TIFF, and PNG files can be uploaded as replacement images but do now show up in replacement message. |
1053432 |
Buffer security violation in wad_str2ip. |
1059374 |
Traffic cannot be forward to isolator after changing the name of the isolator in FortiProxy. |
1060351 |
Cannot visit Gmail and other websites after enabling Strict-Web-Check. |
FortiNBI
The following issues have been fixed in FortiNBI. For inquiries about a particular bug, please contact Customer Service & Support.
Bug ID | Description |
---|---|
1032886, 1034982 | Crash during FortiNBI exit. |
1053344 |
The "last modified" time for FortiNBI installer packages are not updated during upload. |
1019850 |
No result feedback message when FNBI download from cloud is complete. |