Known issues
The following issues have been identified in version 7.0.7. To inquire about a particular bug or report a bug, please contact Customer Service & Support.
Endpoint Control
Bug ID |
Description |
---|---|
730767 |
The new HA primary FortiGate cannot get EMS Cloud information when HA switches over. Workaround: delete the EMS Cloud entry then add it back. |
Explicit Proxy
Bug ID |
Description |
---|---|
803228 |
When converting an explicit proxy session to SSL redirect, traffic may be interrupted inadvertently in some situations. |
Firewall
Bug ID |
Description |
---|---|
808264 |
Stress test shows packet loss when testing with flow inspection mode and application control. |
860480 |
FG-3000D cluster kernel panic occurs when upgrading from 7.0.5 to 7.0.6 and later. |
861990 |
Increased CPU usage in softirq after upgrading from 7.0.5 to 7.0.6. |
GUI
Bug ID |
Description |
---|---|
440197 |
On the System > FortiGuard page, the override FortiGuard server for AntiVirus & IPS Updates shows an Unknown status, even if the server is working correctly. This is a display issue only; the override feature is working properly. |
677806 |
On the Network > Interfaces page when VDOM mode is enabled, the Global view incorrectly shows the status of IPsec tunnel interfaces from non-management VDOMs as up. The VDOM view shows the correct status. |
685431 |
On the Policy & Objects > Firewall Policy page, the policy list can take around 30 seconds or more to load when there is a large number (over 20 thousand) of policies. Workaround: use the CLI to configure policies. |
707589 |
System > Certificates list sometimes shows an incorrect reference count for a certificate, and incorrectly allows a user to delete a referenced certificate. The deletion will fail even though a success message is shown. Users should be able to delete the certificate after all references are removed. |
708005 |
When using the SSL VPN web portal in the Firefox, users cannot paste text into the SSH terminal emulator. Workaround: use Chrome, Edge, or Safari as the browser. |
719476 |
FortiLink NAC matched device is displayed in the CLI but not in the GUI under WiFi & Switch Controller > NAC Policies > View Matched Devices. |
729406 |
New IPsec design |
755177 |
When upgrade firmware from 7.0.1 to 7.0.2, the GUI incorrectly displays a warning saying this is not a valid upgrade path. |
777145 |
Managed FortiSwitches page incorrectly shows a warning about an unregistered FortiSwitch even though it is registered. This only impacts transferred or RMAed FortiSwitches. This is only a display issue with no impact on the FortiSwitch's operation. Workaround: confirm the FortiSwitch registration status in the FortiCare portal. |
810225 |
An undefined error is displayed when changing an administrator password for the first time. Affected models: NP7 platforms. |
831885 |
Unable to access GUI via HA management interface of secondary unit. |
853352 |
When viewing entries in the slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100000 entries. |
HA
Bug ID |
Description |
---|---|
818432 |
When private data encryption is enabled, all passwords present in the configuration fail to load and may cause HA failures. |
819872 |
HA split brain scenario occurs after upgrading from 6.4.6 to 7.0.6, and HA heartbeats are lost followed by a kernel panic. Affected platforms: NP7 models. |
823687 |
A cluster is repeatedly out-of sync due to external files (SSLVPN_AUTH_GROUPS) when there are frequent user logins and logouts. |
830463 |
After shutting down the HA primary unit and then restarting it, the uptime for both nodes is zero, and it fails back to the former primary unit. |
Hyperscale
Bug ID |
Description |
---|---|
782674 |
A few tasks are hung on issuing |
804742 |
After changing hyperscale firewall policies, it may take longer than expected for the policy changes to be applied to traffic. The delay occurs because the hyperscale firewall policy engine enhancements added to FortiOS 7.0.6 may cause the FortiGate to take extra time to compile firewall policy changes and generate a new policy set that can be applied to traffic by NP7 processors. The delay is affected by hyperscale policy set complexity, the total number of established sessions to be re-evaluated, and the rate of receiving new sessions. |
805846 |
In the FortiOS MIB files, the trap fields |
807476 |
After packets go through host interface TX/RX queues, some packet buffers can still hold references to a VDOM when the host queues are idle. This causes a VDOM delete error with |
810025 |
Using EIF to support hairpinning does not work for NAT64 sessions. |
810379 |
Creating an access control list (ACL) policy on a FortiGate with NP7 processors causes the npd process to crash. |
811109 |
FortiGate 4200F, 4201F, 4400F, and 4401F HA1, HA2, AUX1, and AUX2 interfaces cannot be added to an LAG. |
812833 |
FortiGate still holds |
836474 |
Changes in the zone configuration are not updated by the NPD on hyperscale. |
836976 |
Sessions being processed by hyperscale firewall policies with hardware logging may be dropped when dynamically changing the |
838654 |
Hit count not ticking for implicit deny policy for hardware session in case of NAT46 and NAT64 traffic. |
839958 |
|
842659 |
|
843197 |
Output of |
843266 |
Diagnose command should be available to show |
843305 |
Get |
844421 |
The |
846520 |
NPD/LPMD process killed by out of memory killer after running mixed sessions and HA failover. |
IPsec VPN
Bug ID |
Description |
---|---|
761754 |
IPsec aggregate static route is not marked inactive if the IPsec aggregate is down. |
763205 |
IKE crashes after HA failover when the |
778243 |
When |
810833 |
IPsec static router gateway IP is set to the gateway of the tunnel interface when it is not specified. |
822651 |
NP dropping packet in the incoming direction for SoC4 models. |
Proxy
Bug ID |
Description |
---|---|
727629 |
An error case occurs in WAD while handling the HTTP requests for an explicit proxy policy. |
799237 |
WAD crash occurs when TLS/SSL renegotiation encounters an error. |
Security Fabric
Bug ID |
Description |
---|---|
614691 |
Slow GUI performance in large Fabric topology with over 50 downstream devices. |
794703 |
Security Rating report for Rogue AP Detection and FortiCare Support checks show incorrect results. |
825291 |
Security rating test for FortiAnalyzer fails when connected to FortiAnalyzer Cloud. |
SSL VPN
Bug ID |
Description |
---|---|
819754 |
Multiple DNS suffixes cannot be set for the SSL VPN portal. |
852566 |
User peer feature for one group to match to multiple user peers in the authentication rules is broken. |
System
Bug ID |
Description |
---|---|
724085 |
Traffic passing through an EMAC VLAN interface when the parent interface is in another VDOM is blocked if NP7 offloading is enabled. Workaround: set the |
751715 |
Random LTE modem disconnections due to certain carriers getting unstable due to WWAN modem USB speed under super-speed. |
798091 |
After upgrading from 6.4.9 to 7.0.5, the FG-110xE's 1000M SFP interface may fail to auto-negotiate and cannot be up due to the missed auto-negotiation. |
798303 |
The threshold for conserve mode is lowered. |
799570 |
High memory usage occurs on FG-200F. |
810879 |
DoS policy ID cannot be moved in GUI and CLI when enabling multiple DoS policies. |
812957 |
When setting the |
815360 |
NP7 platforms may encounter a kernel panic when deleting more than two hardware switches at the same time. |
830415 |
FEX-40D-NAM model support was removed after upgrading to 7.0.6 or 7.0.7. |
847077 |
|
850430 |
DHCP relay does not work properly with two DHCP relay servers configured. |
882187 |
FortiGate might enter conserve mode if disk logging is enabled and |
883071 |
Kernel panic occurs due to null pointer dereference. |
1041457 |
On FortiGate, kernel 4.19 does not work as expected when concurrently reassembling fragmented packets that have more than 64 destination IPv4 addresses. |
Upgrade
Bug ID |
Description |
---|---|
925567 |
When upgrading multiple firmware versions in the GUI, the Follow upgrade path option does not respect the recommended upgrade path. |
User & Authentication
Bug ID |
Description |
---|---|
754725 |
After updating the FSSO DC agent to version 5.0.0301, the DC agent keeps crashing on Windows 2012 R2 and 2016, which causes lsass.exe to reboot. |
825505 |
After a few days, some devices are not displayed in the Users & Devices > Device Inventory widget and WiFi & Switch Controller > FortiSwitch Ports page's Device Information column due to a mismatch in the device count between the following commands.
Workaround: restart the WAD process or reboot the FortiGate to recover the device count for the user device store list. |
Web Filter
Bug ID |
Description |
---|---|
766126 |
Block replacement page is not pushed automatically to replace the video content when using a video filter. |