Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 7.0.16 Build 0282. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 7.0.16 release notes also apply to FortiGate-6000 and 7000 FortiOS 7.0.16 Build 0282.

Bug ID

Description

901075 ICMPv6 ping now works as expected when using the execute ping6 command after setting the ping data size to send packets large enough to be fragmented.
930019 Resolved an issue that could cause a load balancing flow rule to stop working after changing the interface members of a LAG included in the flow rule.

979422 1069633

Resolved an issue that caused the output of the diagnose autoupdate versions command to show incorrect date information in the attack definitions section.

997611 995888

Resolved a FortiGate 7000F issue that caused the cmdbsvr process to sometimes crash on each FPM.

998372 Resolved an issue that could cause a kernel panic after upgrading to a new firmware version.
1006415 Resolved an issue that could cause FortiGate 6000F FPCs to fail to synchronize after changing the configuration an IP pool.

1048235

Improvements to how the FortiGate 6000 and 7000 platforms behave if the log disks in the two chassis in an HA cluster have different log disk RAID configurations. Now if the log disk RAID configurations are different, the secondary chassis is shut down and the primary chassis operates normally.

1056262

With a FortiGate configured with a root-vdom and a mgmt-vdom, when an automation stitch is configured for a compromised host with IP-Ban action, the IP is no longer banned from the mgmt-vdom.

1059621

Resolved an issue that could cause traffic destined for a regular FQDN to be matched by two different firewall policies. This was occurring because one of the policies used an FQDN firewall address as the source address and the FQDN had expired on some FPCs or FPMs. To resolve the problem the following commands were added:

config system dns

set fqdn-cache-ttl <seconds>

set fqdn-min-refresh <seconds>

end

For more information, see New timers for FQDNs.

1062698

Resolved an issue that caused high DNSproxy CPU usage.

1073536

Resolved a session synchronization issue that could cause the secondary chassis in a FortiGate 6000 or 7000 FGCP HA cluster to have up to three times more sessions than the primary chassis.

1076538

Found and blocked some access paths to internal switch shells.

Resolved issues

Resolved issues

The following issues have been fixed in FortiGate-6000 and FortiGate-7000 FortiOS 7.0.16 Build 0282. For inquires about a particular bug, please contact Customer Service & Support. The Resolved issues described in the FortiOS 7.0.16 release notes also apply to FortiGate-6000 and 7000 FortiOS 7.0.16 Build 0282.

Bug ID

Description

901075 ICMPv6 ping now works as expected when using the execute ping6 command after setting the ping data size to send packets large enough to be fragmented.
930019 Resolved an issue that could cause a load balancing flow rule to stop working after changing the interface members of a LAG included in the flow rule.

979422 1069633

Resolved an issue that caused the output of the diagnose autoupdate versions command to show incorrect date information in the attack definitions section.

997611 995888

Resolved a FortiGate 7000F issue that caused the cmdbsvr process to sometimes crash on each FPM.

998372 Resolved an issue that could cause a kernel panic after upgrading to a new firmware version.
1006415 Resolved an issue that could cause FortiGate 6000F FPCs to fail to synchronize after changing the configuration an IP pool.

1048235

Improvements to how the FortiGate 6000 and 7000 platforms behave if the log disks in the two chassis in an HA cluster have different log disk RAID configurations. Now if the log disk RAID configurations are different, the secondary chassis is shut down and the primary chassis operates normally.

1056262

With a FortiGate configured with a root-vdom and a mgmt-vdom, when an automation stitch is configured for a compromised host with IP-Ban action, the IP is no longer banned from the mgmt-vdom.

1059621

Resolved an issue that could cause traffic destined for a regular FQDN to be matched by two different firewall policies. This was occurring because one of the policies used an FQDN firewall address as the source address and the FQDN had expired on some FPCs or FPMs. To resolve the problem the following commands were added:

config system dns

set fqdn-cache-ttl <seconds>

set fqdn-min-refresh <seconds>

end

For more information, see New timers for FQDNs.

1062698

Resolved an issue that caused high DNSproxy CPU usage.

1073536

Resolved a session synchronization issue that could cause the secondary chassis in a FortiGate 6000 or 7000 FGCP HA cluster to have up to three times more sessions than the primary chassis.

1076538

Found and blocked some access paths to internal switch shells.