Resolved issues
The following issues have been fixed in version 7.6.1. To inquire about a particular bug, please contact Customer Service & Support.
Anti Spam
Bug ID |
Description |
---|---|
1050805 | When spam mail is received from the server, POP connection times out. |
Anti Virus
Bug ID |
Description |
---|---|
1044961 | On FortiGate, the Scanunit does not work as expected due to zlib data check issue. |
1054835 |
Large file downloads take longer than expected due to a WAD process issue. |
1055609 |
Files sent between FortiGate and FortiSandbox are dropped due to a connection issue. |
1058701 |
On FortiGate, the |
1062753 |
The incorrect percentage is displayed in the Files Uploaded Today widget to Sandbox. |
1068321 |
MMDB and AVAI DBs are unsigned after upgrading from version 7.0.15 to version 7.2.9. |
1070864, 1082877 |
The scanunit shows error messages that do not provide enough detail when corrupt AV engine or DB events occur. |
1073326 |
Entry-level FortiGate's with 2GB of memory encounter a memory usage issue and do not operate as expected caused by the scanunit initiating an AV engine restart. |
1078882 |
Scanunit tries to scan with no payload, resulting in an error message from FortiNDR and generating an error on FortiGate. |
Application Control
Bug ID |
Description |
---|---|
951150 | The Zoom meeting remote control feature is not blocked during meetings. |
990540 |
FortiGate does not generate traffic logs for established or denied TCP sessions that lack application data. |
1060562 |
The application control profile is missing on the GUI for FortiGate models with 2GB of memory. |
1064413 |
When using SD-WAN load balancing, some sites are slow or inaccessible when the Application Control action is set to Allow. |
1066078 |
Application control cannot detect Facebook as Social Media when certificate-inspection is used. |
1066567 |
Tencent.Meeting application is not blocked by the inline IPS when using HTTP or Socks5 proxy. |
Data Loss Prevention
Bug ID |
Description |
---|---|
908279 |
The DLP incorrectly detects a .pdf file as a .mpeg file and blocks the download. |
984784 |
When a DLP profile is set to MAPI, there is a slow connection between Outlook and the Exchange server. |
1049719 | The DLP dictionary with a regex configuration does not deny an accent mark on FortiGate. |
DNS Filter
Bug ID |
Description |
---|---|
1058866 | DNS translation does not work as expected when a resolved IP matches the external block list entry. |
1086355 |
DNS query logs are not visible on FortiGate when traffic uses VIP for DNS traffic. |
Explicit Proxy
Bug ID |
Description |
---|---|
900911 | When secure-web-proxy is enabled, if the client disconnects without sending any data as soon as the TCP connection with FortiGate is established, a WAD process signal 11 error occurs. |
1056600 |
FortiGate experiences a WAD process issue and produces a wad_find_fwdsvr_by_key error. |
1076642 |
Unable to load pages with cloudflare protected websites with auth enabled, if Auth scheme is set to Form-Based in explicit proxy. |
File Filter
Bug ID |
Description |
---|---|
1011320 | Adding File Filter to a firewall policy will impact performance. |
1095866 |
Filefilter block corrupts file on NetApp Files share instead of completely blocking it. |
Firewall
Bug ID |
Description |
---|---|
996622 |
On FortiGate, the IPv6 real server shown as DOWN by the health check but it is considered UP in the kernel. |
1007029 | On FortiGate, connections are disrupted between client email exchange servers and a virtual server when HTTP2 support is enabled. |
1007566 |
When the FortiGate has thousands of addresses and hundreds address groups, the GUI can take a few minutes to search for a specific address inside the address group dialog. |
1028356 |
Reordering the DNAT policies in the central NAT causes a false hit count. |
1030516 |
An internet interface with egress/outbound shaping encounters a performance issue with sla after rebooting. |
1036676 | When a loopback interface has an IP that matches a VIP's extip with an extintf "any" , FortiGate will match the VIP but the oif loopback causes an unintended policy 0 match and drops. |
1047208 | The FortiGate virtual server does not setup an http2 connection with a WebSocket server due to a WAD process issue. |
1050864 |
No route is found when the FTP server connects back to FTP client in FTP active mode. |
1051891 |
The SNMP fgIpsAnomalyDetections counter does not increase if the DoS policy is configured in a no management VDOM. |
1055733 |
The F5 HTTP/S monitors for the web server in FortiGate do not function as expected due to HTTP 0.9 traffic. |
1057080 |
On the Firewall Policy page, search results do not display in an expanded format. |
1058494 | When snat-hairpin-traffic is enabled, SNAT is not automatically applied to hairpin traffic, causing a SNAT mismatch in strict-dirty-session-check . |
1059989 |
Modifying the shaping profile, whether it is assigned to an interface or not, results in IPsec tunnels going down. |
1060452 |
FortiGate in policy-based mode showing the incorrect policy ID in forward traffic logs. |
1062333 | FortiGate does not reply to an ARP request when VIP is disabled due to an iplist reference issue. |
1064748 |
When a VIP load balancer is configured to use an IPPool and has |
1068393 |
Incorrect matching of zones and SD-WAN zones occurs where interfaces do not exist. |
1078662 |
Incorrect checksum for fragments after QTM. |
1079590 |
Intermittent reply traffic is not sent out of FortiGate. |
1081542 |
On FortiGate, packets are dropped when ASIC offloading is enabled. |
1052334 |
The firewall policy name length validation does not work with Korean characters. |
1088905 |
The Virtual Server HTTP |
FortiGate 6000 and 7000 platforms
Bug ID |
Description |
---|---|
986845 |
On FortiOS, the Security Fabric widget does not display information on blade status. |
997161 |
On FortiGate 6000 FPCs and FortiGate 7000 FPMs the node process may consume large amounts of CPU resources, possibly affecting FPC or FPM performance. (You can run the |
1016439 | Enabling or disabling a vcluster causes some backup routes (proto = 20) to be lost when a routing table has a significant amount of routes (over 10000 routes). |
1032573 |
In an HA configuration, FortiGate does not respond to SNMP queries causing the device to display as being DOWN. |
1035601 | An SNMP query for policy statistics returns 0 on MBD. |
1037965 |
When applying a script to a configuration, the updated configuration is applied to the FIM but is not fully synchronized on the FPCs. |
1048808 | If the secondary reboots, after it rejoins the cluster SIP sessions are not resynchronized. |
1056894 |
On FortiGate, IPv6 VRF routing tables appear under the new and old FPC primary units when the primary FPC slot is changed. |
1057499 | FIM interfaces are DOWN after restoring the root VDOM configuration due to a speed issue. |
1060619 | CSF is not working as expected. |
1081015, 1086953 |
The secondary 7K slot 3 (FPM) has no ISDB database and will not update. |
1086889 |
FIM encounters a split-brain scenario after rebooting. |
1088402 |
On FortiGate 6K/7K FGSP clusters, the configuration does not synchronize properly with |
FortiView
Bug ID |
Description |
---|---|
1009287 |
On the Dashboard > FortiView Sessions page, closing a large number of FortiView sessions (+100) can take longer than expected and result in a CPU usage issue. |
1029254 |
When trying to filter by device using the 1 week filter option, the User device store query error (error code: -1) error message is displayed. |
1077555 |
On FortiGate, the Top Threat - WAN does not show the correct information for the IPS Logs. |
GUI
Bug ID |
Description |
---|---|
885427 |
On the Network > Interfaces page, the SFP port is grayed out on the faceplate diagram even though the port is working. This is purely a GUI display issue and does not affect system operation. Workaround: View the SFP port information and status using the |
989512 | When the number of users in the Firewall User monitor exceeds 2000, the search bar, column filters, and graphs are no longer displayed due to results being lazily loaded. |
991573 | In the Assets widget preview window of the Asset & Identities widget, clicking the Refresh button does not update the data. |
1009143 | On FortiOS, the time displayed in the CLI and in the GUI do not match. |
1018682 | When creating a firewall policy, applications groups with custom application signatures cannot be saved using the GUI. |
1035356 |
The WAN interface is accessible in the GUI under certain interface configurations even though it is not allowed in the configuration file. |
1044745 | On the Dashboard > User & Devices page on a VDOM, the Address column shows multiple devices with the FortiGate VLAN gateway instead of the Client IP. |
1050865 | When updating an administrator password in the GUI, the password expiration date does not update when the new password is created. |
1052040 |
The IP/Netmask column of HA management port hangs in the GUI. |
1056800 |
On FortiOS, IPSec localid cannot be deleted using the GUI. |
1057628 |
Catch WebSocket errors from PerMessageDeflate occur when the client abruptly closes the connection. |
1058473 | Expired licenses are still displayed in the GUI after 30 days. |
1058608 |
FortiGate Cloud still shows as Activated in the GUI, even when logged out. |
1068202 |
On low end models, the service list is empty when selecting members for a Service Group. |
1071907 |
In the GUI, there is no setting for the type option for the npu_vlink interface. |
1092475 |
GTP-profile do not display in the GUI when Central SNAT is enabled. |
HA
Bug ID |
Description |
---|---|
824651 | Certificate upload causes HA checksum mismatch. |
965217 | In an HA configuration, FortiGate may experience intermittent heartbeat loss causing unexpected failover to the secondary unit. |
1007516 |
Rx_dropped is observed on |
1009939 |
When bandwidth is low, the tftp backup command on the secondary unit does not work as expected when it should be able to reach the server. |
1026794 |
The HA secondary FortiGate logical topology page shows the FAZ connected interface as FortiAnalyzer. |
1036139 |
FortiGate encounters a memory usage issue caused by cmdbsvr and hasync. |
1047094 | The HA Secondary unit cannot communicate with FortiGate Cloud when it uses standalone-mgmt-vdom using the HA Primary unit. |
1052320 |
In a vCluster configuration, traffic stops after a VDOM failover. |
1054041 |
On FortiGate's in an HA environment, DHCP clients can not get an IPv4 address from the server with vcluster. |
1055336 | Using the Test User Credentials button from the Radius Server in the GUI does not honor the custom nas-id-type . |
1056138 | On FortiGate 120G and 121G models in an HA cluster, if the ha or mgmt interface is used as the heartbeat interface, the HA cluster may not synchronize and the GUI HA page may not load. |
1056651 |
Static routes configured under the secondary unit's |
1060006 |
The |
1060023 |
FortiGate in an HA environment encounter a CPU uasge issue in hte softriq on FGSP cluster members with more than 200000 session running. |
1061492 |
The HA secondary device sends GARP with the wrong MAC address after the vcluster is removed. |
1064728 |
More sessions on a FGCP secondary unit than the primary unit. |
1067274 |
Reply packets are misdirected in an asymmetric L3 FGSP configuration. |
1070745 | Sessions may not fail back to the original FGSP peer that owns the session if either the interface name for the monitor-interface or pingsvr-monitor-interface is 7 characters or longer. |
1070901 |
The |
1084662 |
FFDB signatures keep flapping on all blades except the master FIM of the primary chassis. |
1085371 |
SNMP v3 times out in FortiGate Azure/AWS in HA setup. |
1092547 |
FortiGate in an HA configuration keeps rebooting continuously during a firmware upgrade. |
Hyperscale
Bug ID |
Description |
---|---|
1042512 | On FortiGate, the CGN Resource Quota field allows an invalid value to be set. |
1047362 |
The sw session and log2host netflow logs cannot be seen even though template is present. Data packet displays an error saying template not found. |
1075915 |
The NP can get stuck after many hours of traffic with |
ICAP
Bug ID |
Description |
---|---|
1072282 | ICAP may encounter a 400 Bad Request error with certain websites due to an absent reason-phrase when converting from HTTP/2 to HTTP/1. |
Intrusion Prevention
Bug ID |
Description |
---|---|
891295 |
FortiGate experiences a performance issue with geography-type addresses matching in NGFW policy mode. |
1001860 | On the Security Profiles > Intrusion Prevention page, when a new IPS filter is created with no filter selected, the Details column of the IPS Signatures and Filters table is blank instead of All Attributes. |
1016531 |
FortiGate encounters a memory usage issue in the IPSengine when |
1040783 | FortiGate encounters CPU usage issue due to IPSEngine utilization when using an app-ctrl utm profile. |
1066151 |
Forticron runs |
1086789 |
FortiGate encounters a CPU usage issue caused by the IPS engine. |
IPsec VPN
Bug ID |
Description |
---|---|
1002345 | IKE daemon randomly does not operate as expected during phase1 rekeying depending on soft rekey margin, timing, and packet ordering. |
1018749 |
IPsec inserted SA's are not deleted successfully after flushing all tunnels. |
1020690 | The IPsec Aggregate interface displays as DOWN on the Network > Interfaces and the Policy & Objects > Firewall Policy pages when the member including the Dialup VPN is actually UP. This is purely a GUI display issue and does affect system operation. The correct status is shown on the VPN > IPsec Tunnels page. |
1023871 | IPSec IKEv2 with SAML cannot match the Entra ID group during EAP due to a buffer size issue. |
1024558 | IPsec interfaces created on 802.1ad + 802.3ad interfaces with NP offloading enable do not work as expected after a firmware upgrade. |
1027537 | On the SOC4 platform, L2TP & ETHERIP traffic does not traverse through an IPSec tunnel with NP offload enabled. |
1031963 | The firewall hit and bytes counts display values of 0 in a policy-based VPN. |
1039988 | When performing a SAML authentication, authd gets stuck in a loop due to a CPU usage issue. |
1041019 |
When QKD dialup is enabled, IKE SA cannot establish a connection and generates an error. |
1042324 | The Phase1 monitor BGP remains active when the tunnel is DOWN. |
1049015 |
FortiOS does not enable all available IPsec drivers. |
1050646 | FortiGate does not always send the full Server Certificate Chain causing disconnections with IKEv2 VPN using the native Windows client. |
1054953 |
If IKEv2 is selected during the VPN FortiClient Remote Access wizard setup in the GUI, the Extensible Authentication Protocol (EAP) configuration cannot be selected using the GUI. |
1057165 | The IPsec tunnel with QKD experiences flapping each time a DHCP configuration/interface update occurs. |
1058691 |
The IPsec VPN tunnel on the branch unit does not terminate even when the remote gateway IP address becomes unavailable. |
1059778 |
IPsec does not work as expected when the traffic path is |
1060048 |
Throughput is limited in Site to Site VPN connections between the FW1kF and the FWVM Google Cloud platform. |
1061925 |
IPsec tunnels are flushed when unrelated changes are made in the system. |
1073995 |
Authentication for native iOS IPsec VPN user with FortiToken 2FA does not work as expected. |
1075112 |
FortiGate enters into conserve mode due to IKED encountering a memory usage issue. |
1076636 |
Unexpected behavior in IKED occurs when a peer attempts to negotiate with two different gateway profiles simultaneously. |
1077122 |
The Phase2 SA is present in the kernel but there is no IKE Phase1 SA after an HA upgrade. |
1080164 |
The |
1080420 |
The IPsec tunnel with FlexVPN Cisco (ASR1006 Cisco IOS XE Software, Version 17.09.05a) is down after 1 minute. |
1081951 |
FortiGate encounters a steadily increasing IKED memory usage issue after upgrading to version 7.4.5. |
1082624 |
EAP doe snot work as expected for local users inherited from the policy. RADIUS users can authenticate and the tunnel can be established. |
Log & Report
Bug ID |
Description |
---|---|
979200 |
In a Policy-Based NGFW, if there is no rule hit in |
1001583 |
The GUI experiences a performance issue and reverts to the last input when multiple ports are added to a filter for destination ports. |
1024570 |
The SSH deep-inspection with |
1024990 |
Some traffic logs show local-out traffic with the vdom-name. |
1031342 |
On the Security Traffic Log > Security tab, the Details page displays data with a 1/500 log fetched prompt. |
1034824 | On the Log & Report > Forward Traffic page, application icons may not display in the Application Name column. |
1044092 |
When filtering forward traffic logs using FortiAnalyzer as a source, data takes longer than expected to load and generates a memory error message. |
1045253 |
FortiGate logs are not transferred into FortiGate Cloud Log server. |
1050071 | The unset pac-file-data from pac-policy does not generate a system event log and the pac-file-data is deleted. |
1053334 |
The |
1053412 |
Alert email displays an error for FDS-license-expiring. |
1060204 | When the threat feed download times out, a system event log is not generated. |
1060316 |
Event logs are generated with CLEAR TEXT PASSWORD when using the |
1074236 |
FortiGate cannot connect to FortiAnalyzer due to a hostname resolution issue. |
1083537 |
The FortiAnalyzer serial number disappears from the FortiGate configuration when the OFTP session disconnects. |
1086191 |
An error condition is observed in the |
1087067 |
On the Log Viewer page, the UTM log Matching log page keeps loading under the Log Details > Security tab. |
1088385 |
FortiGate intermittently loses the FortiAnalyzer serial number and is required to verify again the FortiAnalyzer serial number and certificate. |
1091064 |
Forward traffic does not contain the |
Proxy
Bug ID |
Description |
---|---|
916178 |
FortiGate encounters an issue with the WAD daemon when deep inspection and SSL exemption are enabled while visiting a server with an expired certificate. |
979502 |
On FortiGate, when the |
1018780 |
FortiGate encounters a memory usage issue caused by the WAD process after an upgrade. |
1020828 |
An HTTP2 stream issue causes an error condition in the WAD. |
1042055 |
On FortiGate, an interruption occurs in the WAD process when in proxy-mode causing the unit to go into memory conserve mode. |
1043423 |
Unexpected behavior is observed in the WAD user info history daemon with no data in messages, caused by erroneous memory allocation. |
1047441 |
On FortiGate, the WAD process may not work as expected with H2 traffic when creating UTM logs. |
1048296 | FortiGate experiences an HTTP2 framing error when accessing websites using proxy mode with deep inspection configured due to a frame sizing issue in the WAD process. |
1051875 |
The IP SNI check for |
1054052 |
The WAD process does not load a self-sign certificate when |
1056127 |
An error condition occurs in the WAD process due to a rare error case during the SSL handshake. |
1057442 |
On FortiGate, erroneous memory allocation is observed in the WAD process. |
1057488 |
On FortiGate, unexpected behavior is observed in the WAD process during the HTTP session freeing. |
1060812 |
When Proxy-mode inline IPS scanning is enabled, the botnet check within the IPS profile does not work as expected when the IPS profile is applied to a proxy-based inspection policy using certificate inspection. |
1062516 | The WAD process does not work as expected when FortiGate is configured as a HTTP load balancer with an HTTP session and changes are made to the virtual server live. |
1064758 |
The Protocol option tcp window size in a proxy policy does not work as expected. |
1067014 | All wad-workers encounter a gradual memory usage issue, /proc/pid/maps shows increasing symbolic links to /tmp/casb_shm . |
1067942 |
An error occurs in the WAD process when DoH traffic is sent to a transparent proxy after enabling HTTP policy redirect, and without having a transparent proxy configured. |
1069896 |
A wad-worker experiences a memory usage issue increase over several days. |
1078385 |
FortiGate experiences a memory usage issue in the WAD process when sending AVDBs updates from the config daemon to workers. |
REST API
Bug ID |
Description |
---|---|
1014694 | The count and start API request attributes that required for some API endpoints are skipped, causing the REST API to not function as expected. |
1057999 | REST API returns an HTTP 500 error when ssl-static-key-ciphers is enabled under global system settings . |
1060135 |
The API Swagger doc cannot be generated due to incorrect attributes. |
1074529 |
FortiGate is unable to rename the |
Routing
Bug ID |
Description |
---|---|
969992 |
On FortiGate, SCTP traffic does not follow the routing table. |
981876 |
The VRRP primary randomly stops sending VRRP advertisement messages for a few seconds. |
1003756 |
When creating a rule on the Network > Routing Objects page, the Prefix-list is set to 0.0.0.0 0.0.0.0 when an incorrect format is entered in the Prefix field. |
1006753 | When renewing the LTE WWAN IP, some packets are sent using the old IP address causing traffic to drop. |
1011816 |
The BGP neighbor range with a space in the name is ignored. |
1023109 |
The vlan interface and IPSec tunnel interface are not displayed in the GUI after an upgrade. |
1027847 |
FortiGate does not include the |
1029460 |
Creating a BGP IPv4 network prefix or neighbor in the GUI unintentionally creates an empty IPv6 network prefix. |
1041812 |
In a hub and spoke HA configuration, SD-WAN pages take longer than expected to load in the GUI when there are a large number of spokes (~350) configured. |
1042909 |
When creating a new static route on the Network > Static Routes page, the Priority field still displays when the Destination is switched from Subnet to Internet Service. |
1046169 | On FortiGate, outgoing traffic goes through the wrong interface for local-in traffic coming on an SDWAN interface. |
1048338 |
On FortiGate in an HA setup the secondary HA passive device generates unexpected logs. |
1049721 | When BGP enables local-as-replace-as and there is a network loop condition, the NLRI's as-path is increased indefinitely. |
1051709 |
On FortiOS, the Routes widget does not list out IPv6 routes with non-zero VRF's. |
1057135 | The gateway/offload value of offloaded one-way UDP sessions is reset when unrelated routing changes are made. |
1057474 |
FortiGate does not generate a PIM register after stopping and starting a multicast stream. |
1057504 |
FortiGate encounters a multicast routing issue in a VRRP environment. |
1058616 |
On FortiOS, the secondary HA device does not display the SD-WAN Rules tab on the Network > SD-WAN page. |
1060456 | When hovering over a vlan interface on the SD-WAN Rules tab on the Network > SD-WAN page, the interface shows as disabled in the SD-WAN rule even though it is active. |
1061899 |
Packet are duplicated if the latency between SD-WAN channels differs by more than 250ms. |
1069060 |
Routes are not displayed correctly when the BGP configuration is in a specific order. |
1071662 |
Shortcuts are not created for ADVPN2.0 and BGP on loopback for segregated transports. |
1078608 |
The SD-WAN |
1085271 |
An IGMP membership report with a |
1085897 |
During a graceful restart towards Cisco Nexus causes BGP VPNv4 routes not to enter FIB. |
1086828 |
SD-WAN logs show the parent interface instead of the shortcut interface. |
1091628 |
The secondary IP of an interface is removed from the routing table of other VDOMs when a new VDOM is created. |
Security Fabric
Bug ID |
Description |
---|---|
873222 |
The automation email does not show the output of some commands. |
948322 |
After deauthorizing a downstream FortiGate from the System > Firmware & Registration page, the page may appear to be stuck to loading. Workaround: perform a full page refresh to allow the page to load again. |
987531 |
Threat Feed connectors in different VDOMs cannot use the source IP when using internal interfaces. |
1007607 |
When creating a new IPv6 address, SDN connectors cannot be added for dynamic addresses. |
1019284 |
When optimizing a security rating, resolving an alert for one rating causes another alert to appear for another rating and the alerts cycle between both ratings continuously. |
1040700 |
The external connector only allows users to specify the interface in the root vdom and not the vdom it is configured in. |
1042972 |
Cannot test an automation stitch that uses the Schedule trigger from the GUI. |
1054407 |
The Security Rating report does not show test results for downstream FortiGates when the All FortiGates view is selected. |
1055616 |
The Threat feed loaded does not run immediately after restarting FortiGate. |
1056262 |
With a FortiGate configured with a |
1057862 |
FortiGate models with 2GB of memory that manage many extension devices (FortiSwitches and FortiAPs) may enter conserve mode due to the GUI process experiencing a memory usage issue over time. |
1058589 | Webhook requests use the same Content-Type: application/json in HTTP headers for all requests, even if it has a custom header. |
1075080 |
The Duplicate Firewall Objects security rating does not work as expected, even it should be passed. |
1082980 |
The AZURE type dynamic firewall address takes longer than normal to resolve itself, even with the correct filter value in the robot test bed. |
1088000 |
The |
SSL VPN
Bug ID |
Description |
---|---|
943971 | On the VPN > SSL-VPN Settings page, when renaming a selected Restrict Access Host object, the object is deselected. |
998219 |
Internet services cannot be used (IPv4 and IPv6) as destination in SSL VPN policies with dual stack enabled. |
1042457 | Duplicate log entries are created for SSL VPN when the tunnel is up or down. |
1046374 |
An unauthenticated user mismatch occurs with the user. |
1047705 |
SAML login from a Windows FortiClient is blocked when |
1061165 | SSL VPN encounters a signal 11 interruption and does not work as expected due to a word-length heap memory issue. |
1066564 |
SSL VPN SMB is inaccessible when using Web Mode. |
1078149 |
Internal resources cannot be accessed using FortiClient after a network disruption. |
1079185 |
Incorrect maximum values present in CLI schema files. |
1082427 |
The OS checklist for SSL VPN in FortiOS does not include macOS Sequoia 15.0. |
1094825 |
Unexpected behavior caused by SSL VPN when multiple routes are configured with the same address. |
Switch Controller
Bug ID |
Description |
---|---|
1035823 |
When trying to start and stop the FortiSwitch LED blink using the Security Fabric, the GUI shows a Failed to send command error. |
1038646 |
The FortiSwitch registration status changes from Not registered to Failed to fetch status when it is deauthorized and then authorized. |
1042390 |
On the WiFi & Switch Controller > SSID page, NAC policies using a Wildcard MAC Address cannot be saved using the GUI. Workaround: use the CLI to perform the operation. |
1044150 |
Upgrading FortiSwitch from the FortiGate GUI does not work as expected when strict and moderate tunnel modes are configured. |
1052908 | When the name of the FortiSwitch does not match its serial number, it shows up as not registered on the System > Firmware & Registration and Security Fabric > Fabric Connectors pages. |
1054445 |
When editing a dynamic port policy, saved changes are not shown in the GUI. |
1055052 |
On FortiOS, NAC policies disappear from the GUI. |
1069164 |
The incorrect timezone is shown for the managed switch. |
1071594 |
The interface dialog takes longer than expected to load the FortiLink interface page when there are a large number of FortiSwitch VMs (300+). |
1073340 |
On the Firmware page, the Registration Status shows a Failed to fetch status error for an online FortiSwitch. The CLI shows that its registered. |
1074981 |
The FortiGate switch port configuration GUI does not allow the de-selection of all values for Allowed VLANs, Security Policy, or QOS Policy. |
1077496 |
FortiGate encounters a CPU usage issue caused in the |
1092043 |
The dynamic VLAN is not visible in the GUI. |
System
Bug ID |
Description |
---|---|
776290 |
VLAN sub interface event logs for interface status changes are inaccurate. |
894966 |
ACME certificates cannot be renewed manually before their expiration date. |
901621 |
On the NP7 platform, setting the interface configuration using |
907752 | On FortiGate 1000D models, the SFP 1G port randomly experiences flapping during operation. |
920320 | FortiGate encounters increasing Rx_CRC_Errors on SFP ports on the NP6 platform when an Ethernet frame contains carrier extension symbols to Cisco devices. |
952104 |
FortiGate experiences packet loss when using an internal hardware switch. |
960707 | Egress shaping does not work on NP when applied on the WAN interface. |
976314 | After upgrading FortiGate and not changing any configuration details, the output of s_duplex in get hardware nic port command displays Half instead of Full . This is purely a display issue and does not affect system operation. |
978290 |
FortiGate cannot communicate with ACME client and cannot generate certificate. |
983467 |
FortiGate 60F and 61F models may experience a memory usage issue during a FortiGuard update due to the ips-helper process. This can cause the FortiGate to go into conserve mode if there is not enough free memory. |
999816 | FortiGate 100 models may become unresponsive and prevent access to the GUI, requiring a reboot to regain access due to an issue with the SOC3. |
1006685 |
FortiGate enters a loop cycle and generates a large number of LCAP packets when FortiGate does not receive LCAP packets from a peer device. |
1008022 |
After a restarting FortiGate from the GUI, the |
1011696 |
When a SIM card is ejected from a FortiGate using dual SIM cards, the log message does not indicate the slot number FortiOS is switching to. |
1015347 |
After changing the admin profile scope to global, the vdom configuration in the admin user is not consistent with the GUI. |
1018843 | When FortiGate experiences a memory usage issue and enters into conserve mode, the system file integrity check may not work as expected and cause the device to shutdown. |
1020602 |
After configuring a virtual wire pair (VWP) setting, it is not present in FortiGate after a reboot. |
1020921 | When configuring an SNMP trusted host that matches the management Admin trusted host subnet, the GUI may give an incorrect warning that the current SNMP trusted host does not match. This is purely a GUI display issue and does not impact the actual SNMP traffic. |
1022935 |
FortiGate experiences a CPU usage issue when |
1025114 | Insufficient free memory on entry-level Fortigate devices with 2 GB RAM may cause unexpected behavior in the IPS engine. |
1029353 |
The SNMP trap is not sent out when a virus is detected on the antivirus scanner. |
1029447 | FortiGate encounters increasing Rx_CRC_Errors on SFP ports on the NP6 platform when an Ethernet frame contains carrier extension symbols to Cisco devices. |
1032018 | The SFP+ port LED does not illuminate and displays a speed 10Mbps even though the link status up and speed is set to 1000Mbps. |
1032602 |
FortiGate encounters a memory usage issue on DNS proxy, resulting in FortiGate going into conserve mode. |
1034286 |
FortiGate does not auto negotiate to |
1034821 |
On FortiGate, NP7 offloaded traffic does not use the updated MAC address from the ARP table to forward traffic using a GRE tunnel. |
1039264 |
The DNS proxy does not forward the response after upgrading FortiGate. |
1039564 |
When the configuration changes using the SSH, a backup failed alert is generated. |
1044178 |
FortiGate does not return an ICMP message with type unreachable and code |
1045301 |
Configuration revisions are missing multiple parts of the configuration. |
1047996 |
FortiGate 4800F model split ports do not work as expected causing issues with LACP and MRU on split ports. |
1048496 |
On FortiGate, the |
1049119 |
FortiGate encounters an interruption in the kernel due to a NULL pointer issue. |
1050883 |
Backing up a configuration using SFTP with the domain username does not work when characters @ and |
1050908 |
In some scenarios, when FortiGate as a DHCP client sends out |
1051961 |
On FortiGate, IP addresses cannot be assigned within a configured IP range due to a DHCP server issue. |
1053536 |
On FortiGate, the console displays error messages when adding Pre and Post-login banners due to a rare error condition. |
1054294 |
FortiGate reboots after a connected HA heartbeat cable is connected, or running the |
1055029 |
FortiGate cannot get updates from the public FortiGuard servers in FIPS-CC mode. |
1055392 |
The traffic shaper does not take effect on the firewall policy when traffic is offloaded to NP7 due to a traffic management issue. |
1055805 |
Duplicate SNMP traps are sent to |
1056166 |
In the GUI, Can not create query, check_create_cmf_query, firewall, and ippool_grp errors are displayed. |
1056174 |
FortiOS processes packets on a non-active port of a redundant link. |
1056578 |
The DNS server does not operate as expected with |
1057131 |
A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate. |
1057625 |
FortiGate does not work as expected due to an interruption in the kernel. |
1058397 |
On FortiGate 900 models, when the baudrate is configured, the changes are not applied and is set to 9600. |
1059398 |
The |
1061155 |
Error messages are printed when assigning a transparent vdom to a vdom link interface. |
1061334 |
FortiGate returns a string with a % sign for the OID 1.3.6.1.4.1.12356.101.4.8.2.1.8 (fgLinkMonitorPacketLoss). |
1061413 |
|
1061796 |
Inaccurate inbound and outbound traffic values on the Bandwidth widget for the EMAC VLAN interface. |
1065047 |
An error is observed in the dnsproxy caused by the use of secondary dns-database zones. |
1065553 |
FortiGate 80F-DSL models display the incorrect connected route. |
1065969 |
FortiGate does not boot up after restoring a configuration file containing an invalid string format. |
1066622 |
The source IP is not replaced as per the |
1066655 |
FortiGate 60F and 40F models become stuck after entering conserve mode and hbdev and console access is lost. |
1068150 |
The DHCP relay uses the wrong interface to send DHCP offer packets to the client. |
1069554 |
Upgrading directly from 7.2.4 or earlier versions to 7.2.9, or directly from 7.0.11 or earlier to 7.2.9 is not supported. Users must upgrade following the recommended upgrade path to avoid system hanging. |
1071749 |
Write permission violation log observed in FortiGate in a rare case caused by the host check plugin used in FortiClient/browser side. |
1072320 |
On FortiGate 400E models, the Link/Activity LED for the MGMT & HA port does not go out even after an |
1072437 |
FortiWiFi 61F models experience a memory usage issue caused by the WAD daemon. |
1072787 |
When accessing an IPv6 test site using the IPoE from an iPhone, the IPv6 connection does not work as expected. |
1075032 |
On FortiGate, NP7 offloaded traffic does not use the MAC address of a new default gateway to forward traffic using the EMAC-VLAN interface. |
1075585 |
Shared copper WAN1 and WAN2 ports remain down when the interface speed is set to |
1079021 |
A CPU usage issue in the Softirq space on 40/160 CPU cores causes packets to drop. |
1085736 |
FortiGate cannot restore the configuration file in the following sequence.
|
1087109 |
After a reboot, FortiGate shows the wrong date if the date was set manually prior to the reboot. |
1092021 |
FortiGate logs out when deleting the secondary IP configured on an interface in work space mode. |
1093042 |
FortiGate encounters a memory usage issue caused by the snmpd daemon. |
Upgrade
Bug ID |
Description |
---|---|
1056126 |
FortiGate does not boot up properly after an upgrade when it has a large number (500+) of VDOMs configured. |
User & Authentication
Bug ID |
Description |
---|---|
1003373 |
FortiGate experiences a gradual memory usage issue in the fnbamd process. |
1004258 |
The Strict-SNI SSL Profile might block connections even if SNI and Certificate CN match. |
1008709 |
EST http password are not encrypted properly in the configuration file. |
1009884 |
FortiGate encounters a CPU usage issue in the |
1036265 | The reply-to option under config system alertmail is removed even for custom mail-servers with 2-factor authentication after an upgrade. |
1039663 | The TACACS+ connection times out, irrespective of the remoteauthtimeout setting, due to an issue with the ldapconntimeout setting, after upgrading to version 7.4.4. |
1039771 | FortiOS may reply to an FTM push message using a different egress interface instead of the original interface. |
1042326 |
On FortiGate, the |
1042987 |
NTLM authentication does not work as expected after an upgrade. |
1043222 |
CMPv2 IR does not work as expected due to server certification validation error conditions. |
1044084 |
On the Dashboard > Firewall User Monitor page, the Search field does not display in the GUI when there are a large number (+1000) FSSO user logos. |
1045753 |
An ACME certificate enrollment error is generated without detailed error message information. |
1050942 | The Active Firewall-Authentication for 2FA FAC RADIUS users using PAP method does not work as expected after upgrading to version 7.4.4. |
1060009 | On FortiGate, RADSEC sent incorrect accounting packets due to a hashing issue. |
1066264 |
RADIUS message authenticator checking is not optional under TLS. |
1070560 |
Administrator authentication is bypassed when configuring the TACACS server. |
1070743 |
FortiGate does not send a FortiToken activation code, preventing authentication. |
1072870 |
FortiGate initiates LDAPS sessions that do not respect the |
1080234 |
For FortiGate (versions 7.2.10 and 7.4.5 and later) and FortiNAC (versions 9.2.8 and 9.4.6 and prior) integration, when testing connectivity/user credentials against FortiNAC that acts as a RADIUS server, the FortiGate GUI and CLI returns an invalid secret for the server error. This error is expected when the FortiGate acts as the direct RADIUS client to the FortiNAC RADIUS server due to a change in how FortiGate handles RADIUS protocol in these versions. However, the end-to-end integration for the clients behind the FortiGate and FortiNAC is not impacted. |
1080510 |
When using SCEP, the auto renewal certificate is not initiated. |
1086643 |
FortiGate Captive Portal does not send the full Server Certificate Chain. |
VM
Bug ID |
Description |
---|---|
953526 |
The FortiGate-VM OCI may not detect an extra port attached. |
972520 |
The FortiGate-AWS HA secondary |
1012927 |
When FortiGate returns an ICMP TTL-EXCEEDED message, the |
1046696 | A FortiGate VM HA in Azure Cloud may intermittently go out of synchronization due to an issue in the daemon process. |
1054244 | FortiToken does not work as expected after moving a FortiGate-VM license to a new VM with the same serial number. |
1058355 | FortiGate VM Azure does not work as expected and enters into conserve mode in vWAN setup. |
1061669 |
User may not be able to access FortiGate-KVM with a trial license when there are many |
1066138 |
FortiGate VM performance drops when traffic passes through an inter-vdom link. |
1067046 |
The |
1070910 |
FortiFlex does not install successfully every time after the Day0 configuration using Port2 for the internet connection. |
1072695 |
The VLAN interface is not reachable on a FortiGate VM running KVM with Intel 10G NIC (10Gb ethernet card). |
1073016 |
The OCI SDN connector cannot call the API to the Oracle service when an IAM role is enabled. |
1074600 |
Inadvertent traffic disruption observed on FortiGate-VM64 caused by a deadlock in the |
1082197 |
The FortiGate-VM on VMware ESXi equipped with an Intel E810-XXV network interface card (NIC) using SFP28 transceivers at 25G speed is unable to pass VLAN traffic when DPDK is enabled. |
1094274 |
FortiGate becomes unresponsive due to an error condition when sending IPv6 traffic. |
VoIP
Bug ID |
Description |
---|---|
1070320 | The SIP ALG does not create the expected session for SIP OPTIONS traffic. |
Web Application Firewall
Bug ID |
Description |
---|---|
1067320 |
The Web Application Firewall marks http/s traffic as a malformed constraint. |
1071022 | A matched pattern in the HTTP body cannot be blocked with a waf profile for some content types. |
Web Filter
Bug ID |
Description |
---|---|
537134 |
When a webfilter time-based quota is configured, once quota is reached, long sessions are not terminated. |
1026023 | The webfilter and traffic logs show the incorrect realserver IP address due to a WAD process issue. |
1045884 | When enabling the log all search keywords in the web filter profile and VDOM mode is disabled, the Key Word column is not populated with data. |
1093624 |
The |
WiFi Controller
Bug ID |
Description |
---|---|
1013290 |
WIDS data is not removed from the CLI. |
1028181 | Wi-Fi devices would encounter service delay when roaming over captive-portal SSID with MAC-address authentication. |
1033483 |
The secondary AC |
1048928 |
Cannot retrieve DHCP IP's from the assigned VLAN when connecting Bridge SSID with RADIUS-based MAC authentication. |
1049471 |
On FortiGate 90G and 120G models, traffic is dropped due to the MAC address of the VAP interface being updated with the old MAC address when HA is enabled. |
1050915 |
When upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware. |
1059964 | RADIUS authentication in a WPA2-Enterprise SSID does not use ha-mgmt-interface when ha-direct is enabled. |
1062730 |
On FortiGate, the |
1073390 | FortiGate generates duplicate WiFi event logs when set cw_acd multi-core(set acd-process-count) is enabled. |
1073588 |
Users cannot make any changes to |
1075138 |
On FortiGate, the Source IP shown in the system logs is not referenced anywhere in the network. |
1076738 |
The |
1089563 |
Client |
ZTNA
Bug ID |
Description |
---|---|
1035072 |
FortiClient access to TCP-FWD with saml authentication does not redirect the loop if |
1053309 |
An interruption occurs in the WAD when accessing ZTNA TCP-forwarding service through a proxy-policy with a SAML user group and |
1056179 |
PPPoE encounters a performance issue after an upgrade. |
1075532 |
Long sessions without any authentications terminate after 5 hours. |
Common Vulnerabilities and Exposures
Visit https://fortiguard.com/psirt for more information.
Bug ID |
CVE references |
---|---|
1031370 |
FortiOS 7.6.1 is no longer vulnerable to the following CVE Reference:
|