Known issues
The following issues have been identified in version 6.2.4. For inquires about a particular bug or to report a bug, please contact Customer Service & Support.
Anti Spam
Bug ID |
Description |
---|---|
497024 |
Flow mode banned word spam filter log is missing the banned word. |
Anti Virus
Bug ID |
Description |
---|---|
582368 |
URL threat detection version shows a large negative number after FortiGate reboots. |
Application Control
Bug ID |
Description |
---|---|
630075 |
After upgrading, FortiGate faced an internet access issue when IPS and AC profiles are enabled and the outgoing interface is an npu_vlink. |
Data Leak Prevention
Bug ID |
Description |
---|---|
582480 |
scanunit crashes with signal 11 in dlpscan_mailheader when AV scans files via IMAP. |
DNS Filter
Bug ID |
Description |
---|---|
582374 |
License shows expiry date of 0000-00-00 . |
Endpoint Control
Bug ID |
Description |
---|---|
608301 |
EMS serial number format should be flexible. |
Explicit Proxy
Bug ID |
Description |
---|---|
540091 |
Cannot access explicit FTP proxy via VIP. |
591012 |
WAD crashed at wad_disclaimer_get with signal 11 when disclaimer is enabled in proxy policy and the browser is Chrome. |
610298 |
Compare and sync the VSD change in V5.6 to WAD VS. |
650540 |
FortiGate sends traffic to an incorrect port using a wrong source NAT IP address. |
Firewall
Bug ID |
Description |
---|---|
596633 |
In NGFW mode, IPS engine drops RPC data channel when IPS profile is applied to a security policy. |
603263 |
Increase the maximum limit for the optional parameters in SCTP INIT packet. After the fix, the maximum limit is 10 instead of 4 parameters. |
615073 |
FTP session helper does not work when there is reflected (auxiliary) session. |
FortiView
Bug ID |
Description |
---|---|
573138 |
When the data source is FortiGate Cloud, there is no paging to load sessions; only entries 1-499 are rendered. |
635309 |
When FortiAnalyzer logging is configured using an FQDN domain, the GUI displays a 500 error message on the FortiView Compromised Hosts page. |
673225 |
FortiView Top Traffic Shaping widget does not show data for outbound traffic if the source interface's role is WAN. The data is displayed if the source interface's role is LAN, DMZ, or undefined. |
GUI
Bug ID |
Description |
---|---|
354464 |
AntiVirus archive logging enabled from the CLI will be disabled by editing the AntiVirus profile in the GUI, even if no changes are made. |
514632 |
Inconsistent reference count when using ports in HA |
529094 |
When creating an antispam block/allow list entry, Mark as Reject should be grayed out. |
541042 |
Log viewer forwarded traffic does not support multiple filters for one field. |
564849 |
HA warning message remains after primary device takes back control. |
584915 |
OK button missing from many pages when viewed in Chrome on an Android device. |
584939 |
VPN event logs are incorrectly filtered when there are two Action filters and one of them contains "-". |
589709 |
Status icon in Tunnel column on IPsec Tunnels page should be removed. |
594534 |
GUI shows Invalid LDAP server error while LDAP query successfully finished. |
594702 |
When sorting the interface list by the Name column, the ports are not always in the correct order (port10 appears before port2). |
601568 |
Interface status is not displayed on faceplate when viewing from the System > HA page. |
601653 |
When deleting an AV profile in the GUI, there is no confirmation message prompt. |
602102 |
Warning message is not displayed when a user configures an interface with a static IP address that is already in use. |
604682 |
GUI takes two minutes to load VPN > IPsec Tunnels for 1483 tunnels. |
620854 |
FG-101F GUI should not add speed to virtual switch member port. |
621254 |
When creating or editing an IPv4 policy or address group, firewall address searching does not work if there is an empty wildcard address due to a configuration error. |
624551 |
On POE devices, several sections of the GUI take over 15 seconds to fully load. |
628373 |
Software switch members and their VLANs are not visible in the GUI interfaces list. |
638277 |
Firewall address group object (including interface subnet) is invisible in Accessible Networks. |
638752 |
FortiGates in an HA A-P configuration may lose GUI access to the HA secondary device after a period of 8 days of inactivity, when at least one static IPv6 address is configured on an interface. |
639756 |
Monitor > SD-WAN Monitor keeps loading after disabling VPN member. |
642402 |
LCP-1250RJ3SR-K transceiver shows a warning in the GUI even though it is certified. |
654339 |
GUI search does not work in the interface list if DHCP client and range columns are present. |
662640 |
Some GUI pages (dashboard, topology, policy list, interface list) are slow to load on low-end platforms when there are many concurrent HTTPSD requests. |
664007 |
GUI incorrectly displays the warning, Botnet package update unavailable, AntiVirus subscription not found., when the antivirus entitlement is expiring within 30 days. The actual botnet package update still works within the active entitlement duration. |
689605 |
On some browser versions, the GUI displays a blank dialog when creating custom application or IPS signatures. Affected browsers: Firefox 85.0, Microsoft Edge 88.0, and Chrome 88.0. |
695163 |
When there are a lot of historical logs from FortiAnalyzer, the FortiGate GUI Forward Traffic log page can take time to load if there is no specific filter for the time range. Workaround: provide a specific time range filter, or use the FortiAnalyzer GUI to view the logs. |
HA
Bug ID |
Description |
---|---|
623642 |
It takes up to 10 seconds to get NPU VDOM link up when rebooting primary unit. |
637843 |
HA secondary device is reporting multiple events (DDNS update failed). |
638287 |
|
645293 |
|
656099 |
mgmt interfaces are excluded for heartbeat interfaces (even if |
Intrusion Prevention
Bug ID |
Description |
---|---|
565747 |
IPS engine 5.00027 has signal 11 crash. |
586544 |
IPS intelligent mode not working when reflect sessions are created on different physical interfaces. |
587668 |
IPS engine 5.00035 has signal 11 crash. |
590087 |
When IPS pcap is enabled, traffic is intermittently disrupted after disk I/O reaches IOPS limit. |
631381 |
RDP NLA authentication blocked by FortiGate when enabling IPS profile in the security group (central NAT). |
IPsec VPN
Bug ID |
Description |
---|---|
592361 |
Cannot pass traffic over ADVPN if: |
606129 |
|
610390 |
IKEv2 EAP certificate authentication failings after upgrading from to 6.2.1 to 6.2.3. |
610558 |
ADVPN cannot establish after primary ISP has recovered from failure and traffic between spokes is dropped. |
631968 |
IKE daemon signal 6 crash when |
634883 |
IKE crashes at |
635325 |
Static route for site-to site VPN remains active even when the tunnel is down. |
Log & Report
Bug ID |
Description |
---|---|
605405 |
IPS logs are recorded twice with TCP offloading on virtual server. |
606533 |
User observes |
608565 |
FortiGate sends incorrect long session logs to FortiGate Cloud. |
616835 |
Logs from HA secondary unit cannot be uploaded to FortiCloud. |
628358 |
Logs are not generated in GUI and CLI after checking the file system (after power cable disconnected). |
635013 |
FortiOS gives wrong time stamp when querying FortiGate Cloud log view. |
643840 |
|
Proxy
Bug ID |
Description |
---|---|
582475 |
WAD is crashing with signal 6 in |
586909 |
When CIFS profile is loaded, using MacOS to access Windows Share causes WAD to crash. |
612333 |
In FortiGate with squid configuration (proxy chain), get ERR_SSL_PROTOCOL_ERROR when using Google Chrome with certificate/deep inspection. |
615791 |
Abbreviated handshake randomly receives fatal illegal_parameter against zendesk.com services/sites. |
629504 |
SSH status in SSL profile changes to |
637389 |
The WAD process is crashing multiple times. |
640427 |
Web proxy WAD crash under WAN Opt auto-active mode. |
648831 |
WAD memory leak caused by Kerberos proxy authentication. |
REST API
Bug ID |
Description |
---|---|
584631 | REST API administrator with token unable to configure HA setting (via login session works). |
Routing
Bug ID |
Description |
---|---|
537354 |
BFD/BGP dropping when |
602826 |
BGP route is not added in to kernel during ADVPN test. |
608106 |
BGP daemon crashes when TCP connection is broken by peer. |
611539 |
Editing/adding any address object that is referenced in policy is generating false positive SD-WAN alert messages. |
613716 |
Local-out TCP traffic changes output interface when irrelevant interface is flapping that causes disconnections. |
619343 |
Cannot ping old VRIPs when adding new VRIPs. |
625345 |
The single BGP update message contains the same prefix in withdrawn routes and NLRI (advertised route). |
627951 |
NTP and FSSO not following SD-WAN rules. |
629521 |
SD-WAN IPv6 default route cannot be redistributed into BGP using |
635716 |
FortiGuard web filter traffic also needs to follow SD-WAN service. |
666829 |
Application bfdd crashes. |
Security Fabric
Bug ID |
Description |
---|---|
597139 |
Crash happens due to segfault in CSF. |
649556 |
FortiNAC requests to FortiGate can timeout on low-end models when there are many concurrent requests. |
SSL VPN
Bug ID |
Description |
---|---|
505986 |
On IE 11, SSL VPN web portal displays blank page title {{::data.portal.heading}} after authentication. |
595505 |
FortiGate does not send client IP address as a framed IP address to RADIUS server in RADIUS accounting request message. |
606271 |
Double redirection through SSL web mode not working. |
607687 |
RDP connection via SSL VPN web portal does not work with UserPrincipalName (UPN) and NLA security. |
610579 |
Videos from live cameras via SSL VPN web mode not working. |
620508 |
CLI command |
622068 |
Adding FQDN routing address in split tunnel configuration injects single route in client for multiple A records. |
622110 |
SSL VPN disconnected when importing or renaming CA certificates. |
623231 |
Pages could not be shown after logging in to back-end application server. |
623379 |
Memory corrupt in some DNS callback cases causes SSL VPN crash. |
624145 |
An internal website via SSL VPN web portal failed to load an external resource. |
624899 |
Log entry for tunnel stats shows wrong tunnel ID when using RDP bookmark. |
625301 |
Riverbed SteelCentral AppResponse login form is not displaying in SSL VPN web mode. |
628821 |
Internal aixws7test2 portal is not loading in SSL VPN web mode. |
629190 |
After SSL VPN proxy, some JS files of hapi website could not work. |
631130 |
Internal site http://vau***.com not completely loading through SSL VPN web mode bookmark. |
633812 |
For guacd daemon generated for RDP session, it would sometimes be in an unknown state with 100% CPU and could not be released. |
634991 |
Internal server error 500 while accessing contolavdip portal in SSL VPN web mode. |
635307 |
Map could not be displayed correctly in SSL VPN web mode. |
636984 |
Pro***.com not loading properly in SSL VPN web mode. |
637018 |
After the upgrade to 6.0.10/6.2.4/6.4.0, SSL VPN portal mapping/remote authentication is matching user into the incorrect group. |
638733 |
Internal website hosted in bookmark https://int***.cat is not loading completely in SSL VPN web mode. |
648369 |
Some JS files of jira.***.vwg could not run in SSL VPN web mode. |
649130 |
SSL VPN log entries display users from other VDOMs. |
654534 |
SAML authentications occurring through SSL VPN web mode are not completing. |
Switch Controller
Bug ID |
Description |
---|---|
588584 |
GUI should add support to allow using switch VLAN interface under a tenant VDOM on a managed switch VDOM. |
605864 |
If the firewall is downgraded from 6.2.3 to 6.2.2, the FortiLink interface looses its CAPWAP setting. |
System
Bug ID |
Description |
---|---|
464340 |
EHP drops for units with no NP service module. |
503125 |
FG-100D traffic traversing port1-port16 only saturates CPU0. |
567019 |
CP9 VPN queue tasklet unable to handle kernel NULL pointer dereference at 0000000000000120 and device reboots. |
576323 |
SFP+ 1G speed should be supported on FG-1100E, FG-1800F, FG-2200E, and FG-3300E series. |
578031 |
FortiManager Cloud cannot be removed once the FortiGate has trouble on contract. |
594871 |
Potential memory leak triggered by FTP command in WAD. |
600032 |
SNMP does not provide routing table for non-management VDOM. |
604613 |
|
607357 |
High CPU usage issue caused by high depth expectation sessions in the same hash table slot. |
608442 |
After a reboot of the PPPoE server, the FortiGate (PPPoE clients, 35 clients) keeps flapping (connection down and up) for a long time before connecting successfully. |
611512 |
When a LAG is created between 10 GE SFP+ slots and 25 GE SFP28/10 GE SFP+ slots, only about 50% of the sessions can be created. Affected models: FG-110xE, FG-220xE, and FG-330xE. |
612351 |
Many |
613017 |
|
613136 |
Uninitialized variable that may potentially cause httpsd signal 6 and 11 crash issue. |
615435 |
Crashes might happen due to CMDB query allocation fail that causes a segfault. |
616022 |
Long delay and cmdbsvr at 100% CPU consumption when modifying address objects and address groups via GUI or REST API. |
617134 |
Traffic not showing statistics for VLAN interfaces base on hardware switch. |
617154 |
Fortinet_CA is missing in FG-3400E. |
617409 |
The FG-800D HA LED is off when HA status is normal. |
618762 |
Fail to detect transceiver on all SFP28/QSFP ports. Affected platforms: FG-3300E and FG-3301E. |
620827 |
Over a period of time, FG-60E goes into memory conserve mode caused by resource leak of sepmd daemon. |
623501 |
FG-80D may fail to boot due to a limitation in the size of the bootloader and kernel. |
626371 |
Request to blocked signature with SSL mirrored traffic capture causes FG-500E to reboot. |
632353 |
Virtual WAN link stops responding after 45 members. |
632635 |
Frame size option in sniffer does not work. |
633102 |
DHCPv6 client's DUID generated on two different FortiGates match. |
634600 |
FWF-60E-DSL ADSL2+ connection provided by BT in the UK does not work after upgrading from 6.0.9 to 6.2.4. |
636069 |
Unable to handle kernel NULL pointer dereference at 000000000000008f. |
638041 |
SFP28 port group (ha1, ha2, port1 and port2) missing |
641419 |
FG-40F LAN interfaces are down after upgrading to 6.2.4 (build 5632). |
647718 |
VDOM with long name cannot be deleted. |
648977 |
Sometimes when updating the FortiGate license, there is a certificate verification failure. |
654159 |
NP6Xlite traffic not sent over the tunnel when NPU is enabled. |
694202 |
|
Upgrade
Bug ID |
Description |
---|---|
615972 |
After upgrading from 6.2.2 to 6.2.3, the description field in the table has disappeared under DHCP reservation. |
635589 |
Upon upgrading to FortiOS 6.2.4, DoS policies configured on interfaces may drop traffic that is passing through the DoS policy configuration. Note that this can occur if the DoS policy is configured in drop or monitor mode. Workaround: disable the DoS policy. |
649948 |
Upon upgrading to an affected 6.2 or 6.4 firmware, IKE/IPsec SAs are not synced to the primary when HA |
User & Device
Bug ID |
Description |
---|---|
591170 |
Sessions are removed from the session table when FSSO group order is changed. |
591461 |
FortiGate does not send user IP to TACACS server during authentication. |
595583 |
Device identification via LLDP on an aggregate interface does not work. |
605838 |
Device identification scanner crashes on receipt of SSDP search. |
621161 |
|
626532 |
fnbamd is not sending |
VM
Bug ID |
Description |
---|---|
587180 |
FG-VM64-KVM is unable to boot up properly when doing a hard reboot with the host. |
587757 |
FG-VM image unable to be deployed on AWS with additional HDD(st1) disk type. |
596742 |
Azure SDN connector replicates configuration from primary device to secondary device during configuration restore. |
605511 |
FG-VM-GCP reboots a couple of times due to kernel panic. |
606527 |
GUI and CLI interface dropdown lists are inconsistent. |
608881 |
IPsec VPN tunnel not staying up after failing over with AWS A-P cross-AZ setup. |
613730 |
Unable to update routing table for a resource group in a different subscription with FortiGate Azure SDN. |
623376 |
Cross-zone HA breaks after upgrading to 6.4.0 because upgrade process does not add relevant items under |
624657 |
Azure changes FPGA for Accelerated Networking live and VM loses SR-IOV interfaces. |
626705 |
By assigning port1 as the HA management port, the HA secondary unit node is now able to send system information to the Azure portal through waagent so that up-to-date information is displayed on the Azure dashboard. If port1 is not used as the HA management port, the Azure display and Azure Security Center alerts will not reflect the correct state of the node, which may result in unnecessary alarms. |
634499 |
AWS FortiGate NIC gets swapped between port2 and port3 after FortiGate reboots. |
685782 |
HTTPS administrative interface responds over heartbeat port on Azure FortiGate despite |
VoIP
Bug ID |
Description |
---|---|
620742 |
RAS helper does not NAT the port 1720 in the |
630024 |
voipd crashes repeatedly. |
Web Filter
Bug ID |
Description |
---|---|
657466 |
|
WiFi Controller
Bug ID |
Description |
---|---|
625326 |
FortiAP not coming online on FG-PPPoE interface. |
641811 |
In FG-100F/101F with PPPoE interface, the FortiGate could not manage FortiAP. |