Resolved issues
The following issues have been fixed in version 6.4.5. To inquire about a particular bug, please contact Customer Service & Support.
Anti Virus
Bug ID |
Description |
---|---|
524571 |
Quarantined files cannot be fetched in the AV log page if the file was already quarantined under another protocol. |
Application Control
Bug ID |
Description |
---|---|
576727 |
Unknown Applications category is not present in NGFW policy-based mode. |
DNS Filter
Bug ID |
Description |
---|---|
674302 |
Do not send FortiGate generated DNS response if no server response was received and redirect DNS queries time out. |
Explicit Proxy
Bug ID |
Description |
---|---|
642196 |
Web proxy forwarding server health check does not send user name and password. |
664380 |
When configuring explicit proxy with forward server, if |
Firewall
Bug ID |
Description |
---|---|
661014 |
FortiCarrier has GTP dropped packet log after configuring GTP allow list. |
663062 |
Sessions are marked dirty when IPsec dialup client connects/disconnects and policy routes are used. |
665964 |
In NAT64 scenario, ICMPv6 |
667772 |
When NGFW mode is set to policy mode and a security policy is configured, the Quard daemon should start when either an anti-virus, web filter, application, IPS, or DLP profile is enabled. |
675353 |
Security policy (NGFW mode) flow-based UTM logs are still generated when policy traffic log is disabled. |
675772 |
Virtual wire pair of mirror traffic on FortiOS 6.4 cannot detect IPS attacks because of failed anti-replay checks. |
675823 |
In NGFW mode, traffic is not passing through zone members when intra-zone traffic is allowed. |
678813 |
Cannot change the order of IPv4 access control list entries from FortiOS after upgrading from 6.4.1. to 6.4.3. |
682956 |
ISDB is empty/crashes after upgrading from 6.2.4/6.2.5 to 6.2.6. |
683604 |
When changing a policy and creating a firewall sniffer concurrently, there is traffic that is unrelated to the policy that is being changed and matching the implicit deny policy. Some IPv4 firewall policies were missing after the change. |
FortiView
Bug ID |
Description |
---|---|
628225 |
FortiView Compromised Hosts dashboard cannot show data if FortiAnalyzer is configured using the FQDN address in the log setting. FortiAnalyzer configured with an IP address does not have this issue. |
673225 |
FortiView Top Traffic Shaping widget does not show data for outbound traffic if the source interface's role is WAN. Data is displayed if the source interface's role is LAN, DMZ, or undefined. |
673478 |
Some FortiView graphs and drilldown views show empty data due to filtering issue. Affected graphs/views: Top System Events, Top Authentication Failures, Policy View, and Compromised Host View. |
683413 |
Some FortiView pages/widgets fail to query data from FortiAnalyzer Cloud if the local FortiAnalyzer is not enabled. Affected pages/widgets: Compromised Hosts, FortiView Cloud Applications, FortiView VPN, FortiView Web Categories, Top Admin Logins, Top Endpoint Vulnerabilities, Top Failed Authentication, Top System Events, Top Threats, Top Threats - WAN, and Top Vulnerable Endpoint Devices. |
GUI
Bug ID |
Description |
---|---|
561420 |
On Traffic Shaping Policy list page, right-click option to show matching logs does not work. |
589749 |
Incorrect error message on log settings page, Connectivity issue, 0 logs queued, for FortiAnalyzer connection when the VDOM is in transparent mode with log setting override enabled. |
592854 |
An address created by the VPN wizard cannot save changes due to an incorrect validation check for parentheses, (), in the Comments field. |
602102 |
Warning message is not displayed when a user configures an interface with a static IP address that is already in use. |
636208 |
On SD-WAN Rules page, the GUI does not indicate which outgoing interface is active. This is due to auto-discovery VPN routing changes. |
652522 |
When performed from the primary FortiGate, using the GUI to change a firewall policy action from accept to deny does not disable the IP pool setting, causing the HA cluster to be out of sync. Updating the policy via the CLI does not have this issue. |
654705 |
Aggregated IPsec VPN interface shows as down when each member tunnel has phase 1 and phase 2 names that differ from each other. |
656668 |
On the System > HA page, GUI tooltip for the reserved management interface incorrectly shows the connecting IP address instead of the configured IP address. |
659490 |
A remote certificate in VDOM mode that has no references cannot be deleted from the GUI. Removal is possible using the CLI. |
662705 |
REST API, |
664007 |
GUI incorrectly displays the warning, Botnet package update unavailable, AntiVirus subscription not found., when the antivirus entitlement is expiring within 30 days. The actual Botnet package update still works within the active entitlement duration. |
665111 |
There is no way to add a line break when using the GUI to edit the replacement message for pre_admin-disclaimer-text. One must use the CLI with the |
665712 |
When multiple favorite menus are configured, the new features video pops up after each GUI login, even though user previously selected Don't show again. |
666999 |
When editing the Poll Active Directory Server page, the configured LDAP server saved in FSSO polling is not displayed. Users must use the CLI to modify the setting. |
668470 |
FortiGuard DDNS setting incorrectly displays truncated unique location and empty server selection after saving changes. |
670026 |
When editing a DoS policy, users were able to click OK twice as there was a small delay until the dialog was saved and closed. Clicking twice would cause unwanted changes to the policy. This has been corrected as Submit buttons are now disabled while a dialog is submitting. This fix covers all policy dialogs. |
672599 |
After performing a search on firewall Addresses, the matched count over total count displayed for each address type shows an incorrect total count number. The search functionality still works correctly. |
673496 |
When editing phase 2 configurations, clicking Complete Section results in a red highlight around the phase 2 configuration GUI box, and users cannot click OK to save configuration changes. |
676165 |
Script pushed from FortiManager 6.4.2 to FortiOS 6.4.2 to add address objects and an address group only pushes the address group. |
680805 |
The list of firewall schedules displays time based on the browser time, even though the global time preference is set to use the FortiGate system time. The Edit Schedule page does not have this issue. |
682008 |
On the SSL-VPN Settings page, the option to send an SSL VPN configuration to a user for FortiClient provisioning does not support showing domain name for VPN gateway. |
682077 |
Log viewer should use relative timestamps for dates less than seven days old. |
682440 |
On Firewall Policy list, the tooltip for IP Pool incorrectly shows Port Block Allocation as being exhausted if there are expiring PBAs available to be reallocated. |
684076 |
Erroneous duplication error displayed when creating a phase 2 with Named IPv6 Address set to all if there is already a phase 2 entry defined with Named IPv4 Address set to all. The CLI must be used for this configuration. |
684904 |
When a FortiGate with VDOM and explicit proxy enabled has an access profile with packet capture set to none, administrators with this access profile are not able to create an explicit proxy policy. |
688076 |
The Firewall Address and Service pages cannot load on a downstream FortiGate if Fabric Synchronization is enabled, but the downstream FortiGate cannot reach the root FortiGate. |
688994 |
The Edit Web Filter Profile page incorrectly shows that a URL filter is configured (even though it is not) if the URL filter entry has the same name as the web filter profile in the CLI. |
689605 |
On some browser versions, the GUI displays a blank dialog when creating custom application or IPS signatures. Affected browsers: Firefox 85.0, Microsoft Edge 88.0, and Chrome 88.0. |
HA
Bug ID |
Description |
---|---|
540600 |
The HA |
670331 |
Management access not working in transparent mode cluster after upgrade. |
675781 |
HA cluster goes out of sync with new custom DDNS entry, and changes with respect to the |
678309 |
Cluster is out of sync because of |
684051 |
IPv6 link local address is not generated in FGCP. |
Intrusion Prevention
Bug ID |
Description |
---|---|
654307 |
Incorrect direction and banned location by quarantine action for |
668631 |
IPS is constantly crashing, and ipshelper has high CPU when IPS extended database has too many rules (more than 256) sharing the same pattern. Affected models: SoC3-based FortiGates. |
IPsec VPN
Bug ID |
Description |
---|---|
642543 |
IPsec did not rekey when keylife expired after back-to-back HA failover. |
652774 |
OCVPN spoke-to-spoke communication intermittently fails with mixed topology where some spokes have two ISPs and some have one, but the hubs have two. |
655895 |
Unable to route traffic to a spoke VPN site from the hub FortiGate when the dialup IPsec VPN interface is dual stacked (IPv4/IPv6). |
670025 |
IKEv2 |
675838 |
iked ignores phase 1 configuration changes due to frequent FortiExtender cmdb changes. |
678166 |
TFTP upload not working when application control and ASIC offload are enabled. |
678800 |
Kernel may crash on link event update with |
687749 |
iked HA sync crashed on secondary with authenticated user group in firewall policy. Affected models: all except NP7 platforms (FG-180xF, FG-260xF, FG-420xF, FG-440xF). |
Log & Report
Bug ID |
Description |
---|---|
650886 |
No log entry is generated for SSL VPN login attempts where two factor authentication challenge times out. |
654363 |
Traffic log shows Policy violation for traffic hitting the allow policy in NGFW policy mode. |
667274 |
FortiGate does not have log disk auto scan failure status log. |
667950 |
IPS UTM log is missing |
675347 |
When searching for some rarely-found logs within a large volume of logs, there is a long period of time before the results are returned. During the waiting period, if any new requests arrive, the old search session cannot be cleared. There is then a risk that multiple processes exist together, which may cause performance issues. |
682374 |
Traffic logs not forwarded correctly to syslog server in CEF format. |
Proxy
Bug ID |
Description |
---|---|
640488, 669736, 675480 |
When URLs for block/allow/external resource are processed, the system might enter conserve mode when external resources are very big. |
658257 |
StartTLS-SMTP traffic gets blocked by the firewall when certificate inspection (proxy mode) and the IPS sensor are enabled in a policy. |
664737 |
WAD crash with signal 11 ( |
675343 |
WAD crashes with transparent web proxy when connecting to a forward server. |
675525 |
No WAD sessions displayed when running |
680651 |
Memory leak when retrieving the thumbnailPhoto information from the LDAP server. |
681134 |
Proxy-based SSL certification inspection session hangs if the outbound probe connection has no routes. |
682002 |
An incorrect teardown logic on the WAD SSL port causes memory leak. |
688006 |
WAD user information daemon crashes on purging extra interfaces that exist in multiple VDOMs. |
692462 |
Transparent proxy implicit deny policy is not blocking access. |
REST API
Bug ID |
Description |
---|---|
597707 |
REST API |
658206 |
New REST API |
663441 |
REST API unable to change status of interface when VDOMs are enabled. |
Routing
Bug ID |
Description |
---|---|
672061 |
In IPsec topology with hub and ~1000 spokes, hundreds of spoke tunnels are flapping, causing BGP instability for other spokes. |
677928 |
SD-WAN with |
680365 |
BGP is choosing local route that should have been removed from the BGP network table. |
687034 |
bgpd memory leak if running BGP on 6.2.7 and 6.4.4. |
692241 |
BGP daemon consumes high CPU in ADVPN setup when disconnecting after socket writing error. |
Security Fabric
Bug ID |
Description |
---|---|
650724 |
Invalid license data supplied by FortiGuard/FortiCare causes invalid warning in the Security Rating report. |
673560 |
Compromised host automation stitch with IP ban action in multi-VDOM setup always bans the IP in the root VDOM. |
SSL VPN
Bug ID |
Description |
---|---|
598614 |
When a group and a |
623379 |
Memory corruption in some DNS callback cases causes SSL VPN crash. |
630068 |
When sslvpn SSH times-out, a crash is observed when the SSH client is empty. |
656557 |
The map on the http://www.op***.org website could not be shown in SSL VPN web mode. |
663723 |
SSL VPN with user certificate and credential verification allows a user to connect with a certificate signed by a trusted CA that does not match the certificate chain of the configured CA in the user peer configuration. |
666513 |
An internal web site via SSL VPN web mode, https://***.46.19.****:10443, is unable to open. |
666855 |
FortiOS supports verifying client certificates with RSA-PSS series of signature algorithms, which causes problems with certain clients. |
669506 |
SSL VPN web mode cannot load web page https://jira.ca.ob***.com properly based on Jira application. |
669900 |
SSL VPN crash when updating the existing connection at the authentication stage. |
673320 |
Pop-up window does not load correctly when accessing internal application at https://re***.wo***.nl using SSL VPN web mode. |
674279 |
Customer cannot access SAP web GUI with SSL VPN bookmark. |
675196 |
RTA login webpage is not displaying in SSL VPN web mode. |
675901 |
Internal website https://po***.we***.ac.uk is not loading correctly with SSL VPN bookmark. |
677256 |
Custom languages do not work in SSL VPN web portals. |
677550 |
GUI issues on the internal Atlassian Jira web portal in SSL VPN web mode. |
678130 |
Customer internal website, https://va***.do***.com:21108/mne, cannot be displayed correctly in SSL VPN web mode. |
678132 |
SSL VPN web portal SSO credentials for alternative option are not working. |
678450 |
Unable to view the management GUI of PaloAlto running on 8.1.16 in SSL VPN web mode. |
681626 |
Internal Gridbees portal does not display in SSL VPN web mode. |
684012 |
SSL VPN crashed with signal 11 (segmentation fault) |
685269 |
SSL VPN web mode is not working properly for aw***.co***.com website. |
685854 |
After SSL VPN proxy rewrite, some Salto JS files could not run. |
Switch Controller
Bug ID |
Description |
---|---|
686031 |
LLDP updates from FortiSwitch can cause flcfgd to leak memory. |
System
Bug ID |
Description |
---|---|
598464 |
Rebooting FG-1500D in 5.6.x during upgrade causes an L2 loop on the heartbeat interface and VLAN is disabled on the switch side. |
628642 |
Issue when packets from the same session are forwarded to each LACP member when NPx offloading is enabled. |
648083 |
cmdbsvr may crash with signal 11 (segmentation fault) when frequently changing firewall policies. |
649937 |
The |
651103 |
FG-101F crashed and rebooted when adding |
654131 |
No statistics for TX and RX counters for VLAN interfaces. |
665332 |
When VDOM has large number of VIPs and policies, any firewall policy change causes cmdbsvr to be too busy and consume high CPU. |
665550 |
Fragmented UDP traffic does not assemble on the FortiGate and does not forward out. |
667722 |
VLAN interface created on top of a 10 GB interface is not showing the actual TX/RX counters. |
667962 |
httpsd crashed and |
669914 |
No statistics for TX and RX counters for VLAN interfaces. |
669951 |
confsyncd may crash when there is an error parsing through the internet service database, but no error is returned. |
670897 |
Update GTP code to be compatible with newer versions (GTPv1 and GTPv2). |
670962 |
Packet loss occurs when traffic flow between VLAN interfaces is created under 10G LACP link. |
671643 |
NTurbo does not work when enabled in IPsec tunnel or with session helper. |
673609 |
The auto-join FortiCloud re-try timer 600 second value is too large. |
675171 |
L2TP with status set to enable should be configured before EIP and SIP. |
675508 |
When provisioning a FortiGate and FortiSwitch with enforced firmware version 6.4.2 in FortiManager, the physical port for FortiLink is down and cannot connect to FortiSwitch. |
679114 |
DHCP discover request is wrongly forwarded to all IPsec VPN interfaces when tunnel flipping occurs. |
687519 |
Bulk changes through the CLI are very slow with 24000 existing policies. |
695252 |
FortiExtender VLAN interface cannot get updated LTE IP. |
User & Authentication
Bug ID |
Description |
---|---|
658228 |
The authd and foauthd processes may crash due to crypto functions being set twice. |
666857 |
LDAP connectivity delays in transparent mode VDOM. |
667025 |
FortiGate does not send LLDP PDU when it receives LLDP packets from VoIP phones. |
664123 |
Log enrichment for source and destination IP with RSSO user information in logs not properly working for IPv4 with framed route attribute in RADIUS accounting. |
675226 |
The |
675539 |
FSSO collector status is down, despite that it is reported as connected by authd in a multi-VDOM environment. |
682966 |
FortiGate is unable to parse IPv6 RADIUS accounting packet ( |
VM
Bug ID |
Description |
---|---|
620654 |
Spoke dialup IPsec VPN does not initiate connection to hub after FG-VM HA failover in Azure. |
646161 |
FG-VM8 does not recognize all memory allocated in Hyper-V. |
669722 |
Unable to import more than 50 groups from NSX-T SDN connector. |
672509 |
OCI HA unable to handle cross-compartment failover. |
682260 |
After enabling DPDK, the FG-VM license becomes invalid. After rebooting, the license becomes valid again. |
682420 |
Dialup IPsec tunnel from Azure may not be re-established after HA failover. |
682561 |
|
689307 |
HA secondary VMSL license is invalid after reboot. |
690863 |
EIP is not updating properly with |
Web Filter
Bug ID |
Description |
---|---|
668325 |
A hanging FortiGuard connection is not torn down in some situations. |
669018 |
Change URL re-evaluation link on web filter block pages to HTTPS. |
675436 |
YouTube channel home page on blocklist is not blocked when directed from a YouTube search result. |
676403 |
Replacement message pictures (FortiGuard web filter) are not displayed in Chrome. |
678467 |
Safe search URL option is not working while the original query in Google Images has the same parameter name. |
WiFi Controller
Bug ID |
Description |
---|---|
620764 |
AP country and region settings are not updating as expected. |
625630 |
FWF-60E hangs with looping kernel panic at WiFi driver. |
672136 |
Log severity for wireless events in FortiWiFi and FortiAP should be reconsidered for CAPWAP teardown. |
676640 |
cw_acd crash with |