Resolved issues
The following issues have been fixed in version 7.0.11. To inquire about a particular bug, please contact Customer Service & Support.
Anti Virus
Bug ID |
Description |
---|---|
818092 |
CDR archived files are deleted at random times and not retained. |
845960 |
Flow mode opens port 8008 over the AV profile that does not have HTTP scan enabled. |
849020 |
FortiGate may enter conserve mode while performing Content Disarm and Reconstruction (CDR) parsing on certain MS Office documents with a .tmp extension. |
Data Leak Prevention
Bug ID |
Description |
---|---|
873608 |
DLP blocking of SMB traffic gives unreliable results. |
Endpoint Control
Bug ID |
Description |
---|---|
730767 |
The new HA primary FortiGate cannot get EMS Cloud information when HA switches over. |
834168 |
FortiGates get deauthorized on EMS. |
Explicit Proxy
Bug ID |
Description |
---|---|
823319 |
Authentication hard timeout is not respected for firewall users synchronized from WAD user. |
842016 |
Client gets 304 response if a cached object has varying headers and is expired. |
849794 |
Random websites are not accessible with proxy policy after upgrading to 6.4.10. |
865135 |
Multipart boundary parsing failed with CRLF before the end of boundary 1. |
Firewall
Bug ID |
Description |
---|---|
728734 |
The VIP group hit count in the table (Policy & Objects > Virtual IPs) is not reflecting the correct sum of VIP members. |
794901 |
Unable to create a |
816493 |
The |
835413 |
Inaccurate sFlow interface data reported to PRTG after upgrading to 7.0. |
840689 |
Virtual server aborts connection when |
847086 |
Unable to add additional MAC address objects in an address group that already has 152 MAC address objects. |
852714 |
Making a full HTTP session is sometimes bypassed if |
854901 |
Full cone NAT ( |
856187 |
Explicit FTPS stops working with IP pool after upgrading. |
860480 |
FG-3000D cluster kernel panic occurs when upgrading from 7.0.5 to 7.0.6 and later. |
861990 |
Increased CPU usage in softIRQ after upgrading from 7.0.5 to 7.0.6. |
865661 |
Standard and full ISDB sizes are not configurable on FG-101F. |
875565 |
The policy or other cache lists are sometimes not freed in time. This may cause unexpected policies to be stored in the cache list. |
FortiView
Bug ID |
Description |
---|---|
804177 |
When setting the time period to the now filter, the table cannot be filtered by policy type. |
GUI
Bug ID |
Description |
---|---|
722358 |
When a FortiGate local administrator is assigned to more than two VDOMs and tries logging in to the GUI console, they get a command parse error when entering VDOM configuration mode. |
753328 |
Incorrect shortcut name shown on the Network > SD-WAN > Performance SLAs page. |
773258 |
FortiAP icon cannot be moved once placed on the WiFi map. |
833306 |
Intermittent error, Failed to retrieve FortiView data, appears on real-time FortiView Sources and FortiView Destination monitor pages. |
837836 |
The Network > Interfaces faceplate shows two SFP interfaces, which do not exist on that FortiGate model. |
845513 |
On G-model profiles, changing the platform mode change from single 5G (dedicated scan enabled) to dual 5G is not taking effect. |
853414 |
Policy and dashboard widgets do not load when the FortiGate manages a FortiSwitch with tenant ports (exported from root to other VDOM). |
867589 |
Local VDOM administrator randomly sees a blank white page after logging in with the interface that belongs to the VDOM. |
869138 |
Unable to select addresses in FortiView monitors. |
870675 |
CLI console in GUI reports Connection lost. when the administrator has more than 100 VDOMs assigned. |
872064 |
Creating a monitor from a dashboard widget in a non-root VDOM incorrectly uses the root VDOM. |
HA
Bug ID |
Description |
---|---|
662978 |
Long lasting sessions are expired on HA secondary device with a 10G interface. |
777394 |
Long-lasting sessions expire on the HA secondary in large session synchronization scenarios. |
810175 |
|
813207 |
Virtual MAC address is sent inside GARP by the secondary unit after a reboot. |
830879 |
Running |
835331 |
Communication is disrupted when HA switching is performed in an environment where the VDOM is split to accommodate two IPoE lines. |
837888 |
CLI deployment of a configuration to the secondary unit results in an unresponsive aggregate interface. |
840305 |
Static ARP entry is removed after reboot or HA failover. |
853900 |
The administrator |
854445 |
When adding or removing an HA monitor interface, the link failure value is not updated. |
856004 |
Telnet connection running ping fails during FGSP failover for virtual wire pair with VLAN traffic. |
856643 |
FG-500E interface stops sending IPv6 RAs after upgrading from 7.0.5 to 7.0.7. |
859242 |
Unable to synchronize IPsec SA between FGCP members after upgrading. |
860497 |
Output of |
864226 |
FG-2600F kernel panic occurs after a failover on both members of the cluster. |
874823 |
FGSP |
885844 |
HA shows as being out-of-sync after upgrading due to a checksum mismatch for |
Hyperscale
Bug ID |
Description |
---|---|
807476 |
After packets go through host interface TX/RX queues, some packet buffers can still hold references to a VDOM when the host queues are idle. This causes a VDOM delete error with |
824733 |
IPv6 traffic continues to pass through a multi-VDOM setup, even when the static route is deleted. |
877696 |
Get KTRIE invalid node related error and kernel panic on standby after adding a second device into A-P mode HA cluster. |
Intrusion Prevention
Bug ID |
Description |
---|---|
845944 |
Firewall policy change causes high CPU spike with IPS engine. |
IPsec VPN
Bug ID |
Description |
---|---|
726326, 745331 |
IPsec server with NP offloading drops packets with an invalid SPI during rekey. |
765174 |
Certain packets are causing IPsec tunnel drops on NP6XLite platforms after HA failover because the packet is not checked properly. |
798045 |
FortiGate is unable to install SA ( |
810833 |
IPsec static router gateway IP is set to the gateway of the tunnel interface when it is not specified. |
822651 |
NP dropping packet in the incoming direction for SoC4 models. |
842571 |
If |
848014 |
ESP tunnel traffic hopping from VRF. |
855772 |
FortiGate IPsec tunnel role could be incorrect after rebooting or upgrading, and causes negotiation to be stuck when it comes up. |
858715 |
IPsec phase 2 fails when both HA cluster members reboot at the same time. |
869166 |
IPsec tunnel does not coming up after the upgrading firmware on the branch FortiGate (FG-61E). |
873097 |
Phase 2 not initiating the rekey at soft limit timeout on new kernel platforms. |
876795 |
RADIUS server will reject new authentication if a previous session is missing ACCT-STOP to terminate the session, which causes the VPN connection to fail. |
Log & Report
Bug ID |
Description |
---|---|
838357 |
A deny policy with log traffic disabled is generating logs. |
860264 |
The miglogd process may send empty logs to other logging devices. |
873987 |
High memory usage from miglogd processes even without traffic. |
850519 |
Log & Report > Forward Traffic logs do not return matching results when filtered with !<application name>. |
Proxy
Bug ID |
Description |
---|---|
746587 |
Error condition in WAD occurs during traffic scans in proxy mode. |
769955 |
WAD process crashes (signal 11) with disclaimer and user authentication being applied to the web proxy. |
781613 |
Intermittent traffic disruption caused by race condition in WAD. |
818371 |
An error condition occurs in WAD while parsing certain URIs. |
823078 |
Improvements to WAD to optimize CPU usage when using user groups. |
825977 |
An error condition occurs in WAD during an AV scan submission. |
834387 |
In a firewall proxy policy, the SD-WAN zone assigned to interface is not checked. |
835745 |
An error condition occurs in WAD when the |
855853 |
Improvements to WAD to optimize CPU usage when using user groups. |
855882 |
Improvements to WAD to resolve a memory usage issue when user-info updates the FortiAP information. |
856235 |
The WAD process memory usage gradually increases over a few days, causing the FortiGate to enter into conserve mode. |
857368 |
WAD crashed while parsing a Huffman-encoded HTTP header. |
Routing
Bug ID |
Description |
---|---|
618684 |
When HA failover is performed to the other cluster member that is not able to reach the BFD neighbor, the BFD session is down as expected but the static route is present in the routing table. |
708904 |
|
809321 |
IS-IS LSP packets do not include the checksum and the authentication key ( |
816582 |
Connected subnet in VRF other than VRF 0, gets RPF failure after HA failover |
846107 |
IPv6 VRRP backup is sending RA, which causes routing issues. |
847037 |
When the policy route has a set gateway, the FortiGate is not following the policy route to forward traffic and sends unreasonable ARP requests. |
848270 |
Reply traffic from the DNS proxy (DNS database) is choosing the wrong interface. |
848310 |
IPsec traffic sourced from a loopback interface does not follow the policy route or SD-WAN rules. |
850862 |
When creating a new rule on the Network > Routing Objects page, the user cannot create a route map with a rule that has multiple similar or different AS paths in the GUI. |
852525 |
When enabled, FEC is not effectively reducing packet loss when behind NAT. |
860075 |
Traffic session is processed by a different SD-WAN rule and randomly times out. |
862165 |
FortiGate does not add the route in the routing table when it changes for SD-WAN members. |
862418 |
Application VWL crash occurs after FortiManager configuration push causes an SD-WAN related outage. |
862573 |
SD-WAN GUI does not load, and the lnkmtd process crashes frequently. |
865914 |
When BSM carries multiple CRPs, PIM might use the incorrect prefix to update the mroute's RP information. |
Security Fabric
Bug ID |
Description |
---|---|
798795 |
API that registers appliances to the Fabric stopped working. |
801048 |
During the FortiOS initialization process, there is a small chance that other services using UDP take the specific port that caused csfd initialization to fail. |
814674 |
Failed to retrieve upgrade progress message appears when upgrading a FortiAP or FortiSwitch that is connected to a downstream FortiGate. |
835765 |
Automation stitch trigger is not working when the threshold based email alert is enabled in the configuration. |
839258 |
Unable to add another FortiGate to the Security Fabric after updating to the latest patch. |
870527 |
FortiGate cannot display more than 500 VMs in a GCP dynamic address. |
SSL VPN
Bug ID |
Description |
---|---|
746230 |
SSL VPN web mode cannot display certain websites that are internal bookmarks. |
748085 |
Authentication request of SSL VPN realm can now only be sent to user group, local user, and remote group that is mapped to that realm in the SSL VPN settings. The authentication request will not be applied to the user group and remote group of non-realm or other realms. |
783167 |
Unable to load GitLab through SSL VPN web portal. |
803576 |
Comments in front of |
808107 |
FortiGate is not sending Accounting-Request packet that contains the Interim-Update AVP when two-factor authentication is assigned to a user (defined on the FortiGate) while connecting using SSL VPN. |
810239 |
Unable to view PDF files in SSL VPN web mode. |
819754 |
Multiple DNS suffixes cannot be set for the SSL VPN portal. |
825750 |
VMware vCenter bookmark in not working after logging in to SSL VPN web mode. |
825810 |
SSL VPN web mode is unable to access EMS server. |
828194 |
SSL VPN stops passing traffic after some time. |
831069 |
A blank page displayed after logging in to the back-end server in SSL VPN web mode. |
848067 |
RDP over VPN SSL web mode stops work after upgrading. |
850898 |
OS checklist for the SSL VPN in FortiOS does not include macOS Ventura (13). |
852566 |
User peer feature for one group to match to multiple user peers in the authentication rules is broken. |
854143 |
Unable to access Synology NAS server through SSL VPN web mode. |
854642 |
Internal website with JavaScript is proxying some functions in SSL VPN web mode, which breaks them. |
863860 |
RDP over SSL VPN web mode to a Windows Server changes the time zone to GMT. |
864096 |
EcoStruxure Building Operations 2022 does not render using SSL VPN bookmark. |
864417 |
In the second authentication of RADIUS two-factor authentication, the |
876683 |
SSL VPN web mode has issue accessing specific URL, https://gt***.si***.fr. |
877896 |
When accessing the VDOM's GUI in SSL VPN web mode, policies are only shown for a specific VDOM instead of all VDOMs. |
Switch Controller
Bug ID |
Description |
---|---|
762615, 765283 |
FortiSwitches managed by FortiGate go offline intermittently and require a FortiGate reboot to recover. |
857778 |
Switch controller managed switch port configuration changes do not take effect on the FortiSwitch. |
876021 |
FortiLink virtually managed switch port status is not getting pushed after the FortiGate reboots. |
System
Bug ID |
Description |
---|---|
550701 |
Inadvertent traffic disruption caused by WAD due to deadlock. |
649729 |
HA synchronization packets are hashed to a single queue when |
700621 |
The forticron daemon is constantly being restarted. |
722273 |
SA is freed while its timer is still pending, which leads to a kernel crash. |
757482 |
When |
778794 |
Incorrect values in NP7/hyperscale DoS policy anomaly logs. For packet rate-based meter log, the repeated numbers do not reflect the amount of dropped packets for a specific anomaly/attack; for the session counter meter log, the |
784169 |
When a virtual switch member port is set to be an alternate by STP, it should not reply with ARP; otherwise, the connected device will learn the MAC address from the alternate port and send subsequent packets to the alternate port. |
795104 |
A member of an LAG interface is not coming up due to a different actor key. |
799487 |
The debug zone uses over 400 MB of RAM. |
799570 |
High memory usage occurs on FG-200F. |
807629 |
NP7 |
810137 |
Scheduled speed test crash is caused by adding the same object to a list twice. |
813162 |
Kernel panic occurs after traffic goes through IPsec VPN tunnel and EMAC VLAN interface. |
813607 |
LACP interfaces are flapping after upgrading to 6.4.9. |
815937 |
FCLF8522P2BTLFTN transceiver is not working after upgrade. |
818452 |
The |
819667 |
1G copper SFP port is always up on FG-260xF. |
819724 |
LTE fails to connect after the firewall reboots. Multiple reboots are required to bring back connectivity. |
824543 |
The |
826490 |
NP7 platforms may reboot unexpectedly when unable to handle kernel null pointer de-reference. |
827240 |
FortiGate may not provide detailed information during a watchdog-initiated reboot. |
827241 |
Unable to resolve sp***.saas.ap***.com on a specific VDOM. |
833062 |
FortiGate becomes unresponsive, and there are many WAD and forticron crashes. |
840960 |
When kernel debug level is set to |
841932 |
The GUI and API stopped working after loading many interfaces due to httpsd stuck in a D state (kernel I/O socket). |
845736 |
After rebooting the FortiGate, the MTU value on the VXLAN interface was changed. |
845781 |
Kernel panic and regular reboots occur on NP7 platforms, which are caused by FortiOS trying to offload a receiving ESP packet from the EMAC VLAN interface and convert to an IPv6 destination address with NAT46 NPU offloaded sessions. |
847077 |
|
847314 |
NP7 platforms may encounter random kernel crash after reboot or factory reset. |
849186 |
Unexpected console error appears: |
850683 |
Console keeps displaying |
850688 |
FG-20xF system halts if setting |
853144 |
Network device kernel null pointer is causing a kernel crash. |
853794 |
Issue with the |
853811 |
Fortinet 10 GB transceiver LACP flapping when shut/no shut was performed on the interface from the switch side. |
854388 |
Configuring |
855573 |
False alarm of the PSU2 occurs with only one installed. |
856202 |
Random reboots and kernel panic on NP7 cluster when the FortiGate sends a TCP RST packet and IP options are missing in the header. |
858633 |
When any 10 Gigabit (SFP+) port is connected a switch, all configurations related to the 10 Gigabit ports is removed (trunks) when traffic is flowing upon boot. Affected platforms: FG-40xF, FG-60xF, FG-300xF. |
859717 |
The FortiGate is only offering the |
860385 |
IPv6 BGP session drops when passing through a FortiGate configured with VRF. |
861144 |
|
868225 |
After a cold reboot (such as a power outage), traffic interfaces may not come up with a possible loss of VLAN configurations. |
869599 |
Forticron memory is leaking. |
870381 |
Memory corruption or incorrect memory access when processing a bad WQE. |
873805 |
CPSS usage goes to 99% and causes initiation issues when traffic is flowing upon boot. Affected platforms: FG-40xF, FG-60xF, FG-300xF. |
877154 |
FortiGate with new kernel crashes when starting debug flow. |
877240 |
Get |
880290 |
NP7 is not configured properly when the ULL ports are added to LAG interface, which causes accounting on the LAG to not work. |
Upgrade
Bug ID |
Description |
---|---|
850691 |
The |
854550 |
After upgrading to 7.0.8, |
User & Authentication
Bug ID |
Description |
---|---|
751763 |
When MAC-based authentication is enabled, multiple RADIUS authentication requests may be sent at the same time. This results in duplicate sessions for the same device. |
835859 |
Incorrect source MAC address is used in LLDP TX packet when the interface has |
839801 |
FortiToken purge in a VDOM clears all FortiToken statuses in the system. |
842517 |
Adding a local user to a group containing many users causes a delay in GUI and CLI due to cmdbsvr (high CPU). |
843528 |
RADIUS MAC authentication using ClearPass is intermittently using old credentials. |
851233 |
FortiToken activation emails should include HTTPS links to documentation instead of HTTP. |
853793 |
FG-81F 802.1X MAC authentication bypass (MAB) failed to authenticate Cisco AP. |
872051 |
When the LDAP server has a huge amount of LDAP groups configured, it might return |
VM
Bug ID |
Description |
---|---|
740796 |
IPv6 traffic triggers |
764392 |
Incorrect VMDK file size in the OVF file for hw13 and hw15. |
856645 |
Session is not crated over NSX imported object when traffic starts to flow. |
859165 |
Unable to enable FIPS cipher mode on FG-VM-ARM64-AWS. |
860096 |
CPU spike observed on all the cores in a GCP firewall VM. |
868698 |
During a same zone AWS HA failover, moving the secondary IP will cause the EIP to be in a disassociated state. |
869359 |
Azure auto-scale HA shows certificate error for secondary VM. |
885829 |
Azure SDN connector stopped processing when Azure returned |
VoIP
Bug ID |
Description |
---|---|
757477 |
PRACK will cause voipd crashes when the following conditions are met: |
Web Filter
Bug ID |
Description |
---|---|
856793 |
In flow mode, URL filter configuration changes cause a spike in CPU usage of the IPS engine process. |
WiFi Controller
Bug ID |
Description |
---|---|
807605 |
FortiOS exhibits segmentation fault on hostapd on the secondary controller configured in HA. |
828901 |
Connectivity loss occurs due to switch and FortiAPs (hostapd crash). |
831736 |
Application hostapd crash found on FG-101F. |
834644 |
A hostapd process crash is shown in device crash logs. |
856830 |
HA FortiGate encounters multiple hostapd crashes. |
857084 |
Hostapd segmentation fault signal 6 occurs upon HA failover. |
857140 |
Hostapd segmentation fault signal 11 occurs upon RF chamber setup. |
858653 |
Invalid wireless MAC OUI detected for a valid client on the network. |
865260 |
Incorrect source IP in the self-originating traffic to RADIUS server. |
868022 |
Wi-Fi clients on a RADIUS MAC MPSK SSID get prematurely de-authenticated by the secondary FortiGate in the HA cluster. |
882551 |
FortiWiFi fails to act as the root mesh AP, and leaf AP does not come online. |
ZTNA
Bug ID |
Description |
---|---|
832508 |
The EMS tag name (defined in the EMS server's Zero Trust Tagging Rules) format changed in 7.0.8 from After upgrading, the EMS tag format was converted properly in the CLI configuration, but the WAD daemon is unable to recognize this new format, so the ZTNA traffic will not match any ZTNA policies with EMS tag name checking enabled. |
863057 |
ZTNA real server address group gets unset once the FortiGate restarts. |
865316 |
Adding an EMS tag on the Policy & Objects > Firewall Policy edit page for a normal firewall policy forces NAT to be enabled. |
Common Vulnerabilities and Exposures
Visit https://fortiguard.com/psirt for more information.
Bug ID |
CVE references |
---|---|
841788 |
FortiOS 7.0.11 is no longer vulnerable to the following CVE Reference:
|
843318 |
FortiOS 7.0.11 is no longer vulnerable to the following CVE Reference:
|
857368 |
FortiOS 7.0.11 is no longer vulnerable to the following CVE Reference:
|
858793 |
FortiOS 7.0.11 is no longer vulnerable to the following CVE Reference:
|
860282 |
FortiOS 7.0.11 is no longer vulnerable to the following CVE Reference:
|
863856 |
FortiOS 7.0.11 is no longer vulnerable to the following CVE Reference:
|
887734 |
FortiOS 7.0.11 is no longer vulnerable to the following CVE Reference:
|