Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in version 7.6.1. To inquire about a particular bug, please contact Customer Service & Support.

Anti Spam

Bug ID

Description

1050805 When spam mail is received from the server, POP connection times out.

Anti Virus

Bug ID

Description

1044961 On FortiGate, the Scanunit does not work as expected due to zlib data check issue.

1054835

Large file downloads take longer than expected due to a WAD process issue.

1055609

Files sent between FortiGate and FortiSandbox are dropped due to a connection issue.

1058701

On FortiGate, the av-mem-limit does not work as expected when set av-failopen pass configured due to a memory usage issue.

1062753

The incorrect percentage is displayed in the Files Uploaded Today widget to Sandbox.

1068321

MMDB and AVAI DBs are unsigned after upgrading from version 7.0.15 to version 7.2.9.

1070864,

1082877

The scanunit shows error messages that do not provide enough detail when corrupt AV engine or DB events occur.

1073326

Entry-level FortiGate's with 2GB of memory encounter a memory usage issue and do not operate as expected caused by the scanunit initiating an AV engine restart.

1078882

Scanunit tries to scan with no payload, resulting in an error message from FortiNDR and generating an error on FortiGate.

Application Control

Bug ID

Description

951150 The Zoom meeting remote control feature is not blocked during meetings.

990540

FortiGate does not generate traffic logs for established or denied TCP sessions that lack application data.

1060562

The application control profile is missing on the GUI for FortiGate models with 2GB of memory.

1064413

When using SD-WAN load balancing, some sites are slow or inaccessible when the Application Control action is set to Allow.

1066078

Application control cannot detect Facebook as Social Media when certificate-inspection is used.

1066567

Tencent.Meeting application is not blocked by the inline IPS when using HTTP or Socks5 proxy.

Data Loss Prevention

Bug ID

Description

908279

The DLP incorrectly detects a .pdf file as a .mpeg file and blocks the download.

984784

When a DLP profile is set to MAPI, there is a slow connection between Outlook and the Exchange server.

1049719 The DLP dictionary with a regex configuration does not deny an accent mark on FortiGate.

DNS Filter

Bug ID

Description

1058866 DNS translation does not work as expected when a resolved IP matches the external block list entry.

1086355

DNS query logs are not visible on FortiGate when traffic uses VIP for DNS traffic.

Explicit Proxy

Bug ID

Description

900911 When secure-web-proxy is enabled, if the client disconnects without sending any data as soon as the TCP connection with FortiGate is established, a WAD process signal 11 error occurs.

1056600

FortiGate experiences a WAD process issue and produces a wad_find_fwdsvr_by_key error.

1076642

Unable to load pages with cloudflare protected websites with auth enabled, if Auth scheme is set to Form-Based in explicit proxy.

File Filter

Bug ID

Description

1011320 Adding File Filter to a firewall policy will impact performance.

1095866

Filefilter block corrupts file on NetApp Files share instead of completely blocking it.

Firewall

Bug ID

Description

996622

On FortiGate, the IPv6 real server shown as DOWN by the health check but it is considered UP in the kernel.

1007029 On FortiGate, connections are disrupted between client email exchange servers and a virtual server when HTTP2 support is enabled.
1007566

When the FortiGate has thousands of addresses and hundreds address groups, the GUI can take a few minutes to search for a specific address inside the address group dialog.

1028356

Reordering the DNAT policies in the central NAT causes a false hit count.

1030516

An internet interface with egress/outbound shaping encounters a performance issue with sla after rebooting.

1036676 When a loopback interface has an IP that matches a VIP's extip with an extintf "any", FortiGate will match the VIP but the oif loopback causes an unintended policy 0 match and drops.
1047208 The FortiGate virtual server does not setup an http2 connection with a WebSocket server due to a WAD process issue.

1050864

No route is found when the FTP server connects back to FTP client in FTP active mode.

1051891

The SNMP fgIpsAnomalyDetections counter does not increase if the DoS policy is configured in a no management VDOM.

1055733

The F5 HTTP/S monitors for the web server in FortiGate do not function as expected due to HTTP 0.9 traffic.

1057080

On the Firewall Policy page, search results do not display in an expanded format.

1058494 When snat-hairpin-traffic is enabled, SNAT is not automatically applied to hairpin traffic, causing a SNAT mismatch in strict-dirty-session-check.

1059989

Modifying the shaping profile, whether it is assigned to an interface or not, results in IPsec tunnels going down.

1060452

FortiGate in policy-based mode showing the incorrect policy ID in forward traffic logs.

1062333 FortiGate does not reply to an ARP request when VIP is disabled due to an iplist reference issue.

1064748

When a VIP load balancer is configured to use an IPPool and has http-multiplex enabled, FortiGate performs SNATs using the outgoing interface instead of the IPPool.

1068393

Incorrect matching of zones and SD-WAN zones occurs where interfaces do not exist.

1078662

Incorrect checksum for fragments after QTM.

1079590

Intermittent reply traffic is not sent out of FortiGate.

1081542

On FortiGate, packets are dropped when ASIC offloading is enabled.

1052334

The firewall policy name length validation does not work with Korean characters.

1088905

The Virtual Server HTTP healthcheck uses the IP address as a Host even when the full URL is configured in http-get.

FortiGate 6000 and 7000 platforms

Bug ID

Description

986845

On FortiOS, the Security Fabric widget does not display information on blade status.

997161

On FortiGate 6000 FPCs and FortiGate 7000 FPMs the node process may consume large amounts of CPU resources, possibly affecting FPC or FPM performance. (You can run the diagnose sys top command from an FPC or FPM CLI to view CPU usage.) This problem may be caused by security rating result submission.

1016439 Enabling or disabling a vcluster causes some backup routes (proto = 20) to be lost when a routing table has a significant amount of routes (over 10000 routes).

1032573

In an HA configuration, FortiGate does not respond to SNMP queries causing the device to display as being DOWN.

1035601 An SNMP query for policy statistics returns 0 on MBD.

1037965

When applying a script to a configuration, the updated configuration is applied to the FIM but is not fully synchronized on the FPCs.

1048808 If the secondary reboots, after it rejoins the cluster SIP sessions are not resynchronized.

1056894

On FortiGate, IPv6 VRF routing tables appear under the new and old FPC primary units when the primary FPC slot is changed.

1057499 FIM interfaces are DOWN after restoring the root VDOM configuration due to a speed issue.
1060619 CSF is not working as expected.

1081015,

1086953

The secondary 7K slot 3 (FPM) has no ISDB database and will not update.

1086889

FIM encounters a split-brain scenario after rebooting.

1088402

On FortiGate 6K/7K FGSP clusters, the configuration does not synchronize properly with standalone-config-sync enabled.

FortiView

Bug ID

Description

1009287

On the Dashboard > FortiView Sessions page, closing a large number of FortiView sessions (+100) can take longer than expected and result in a CPU usage issue.

1029254

When trying to filter by device using the 1 week filter option, the User device store query error (error code: -1) error message is displayed.

1077555

On FortiGate, the Top Threat - WAN does not show the correct information for the IPS Logs.

GUI

Bug ID

Description

885427

On the Network > Interfaces page, the SFP port is grayed out on the faceplate diagram even though the port is working. This is purely a GUI display issue and does not affect system operation.

Workaround: View the SFP port information and status using the interface list in the CLI.

989512 When the number of users in the Firewall User monitor exceeds 2000, the search bar, column filters, and graphs are no longer displayed due to results being lazily loaded.
991573 In the Assets widget preview window of the Asset & Identities widget, clicking the Refresh button does not update the data.
1009143 On FortiOS, the time displayed in the CLI and in the GUI do not match.
1018682 When creating a firewall policy, applications groups with custom application signatures cannot be saved using the GUI.

1035356

The WAN interface is accessible in the GUI under certain interface configurations even though it is not allowed in the configuration file.

1044745 On the Dashboard > User & Devices page on a VDOM, the Address column shows multiple devices with the FortiGate VLAN gateway instead of the Client IP.
1050865 When updating an administrator password in the GUI, the password expiration date does not update when the new password is created.

1052040

The IP/Netmask column of HA management port hangs in the GUI.

1056800

On FortiOS, IPSec localid cannot be deleted using the GUI.

1057628

Catch WebSocket errors from PerMessageDeflate occur when the client abruptly closes the connection.

1058473 Expired licenses are still displayed in the GUI after 30 days.

1058608

FortiGate Cloud still shows as Activated in the GUI, even when logged out.

1068202

On low end models, the service list is empty when selecting members for a Service Group.

1071907

In the GUI, there is no setting for the type option for the npu_vlink interface.

1092475

GTP-profile do not display in the GUI when Central SNAT is enabled.

HA

Bug ID

Description

824651 Certificate upload causes HA checksum mismatch.
965217 In an HA configuration, FortiGate may experience intermittent heartbeat loss causing unexpected failover to the secondary unit.

1007516

Rx_dropped is observed on ha1 and ha2 interfaces and randomly experiences flapping.

1009939

When bandwidth is low, the tftp backup command on the secondary unit does not work as expected when it should be able to reach the server.

1026794

The HA secondary FortiGate logical topology page shows the FAZ connected interface as FortiAnalyzer.

1036139

FortiGate encounters a memory usage issue caused by cmdbsvr and hasync.

1047094 The HA Secondary unit cannot communicate with FortiGate Cloud when it uses standalone-mgmt-vdom using the HA Primary unit.

1052320

In a vCluster configuration, traffic stops after a VDOM failover.

1054041

On FortiGate's in an HA environment, DHCP clients can not get an IPv4 address from the server with vcluster.

1055336 Using the Test User Credentials button from the Radius Server in the GUI does not honor the custom nas-id-type.
1056138 On FortiGate 120G and 121G models in an HA cluster, if the ha or mgmt interface is used as the heartbeat interface, the HA cluster may not synchronize and the GUI HA page may not load.

1056651

Static routes configured under the secondary unit's standalone-mgmt-vdom do not take effect.

1060006

The standalone-config-sync conf-member kept out-of-synchronization after an upgrade and configuration change.

1060023

FortiGate in an HA environment encounter a CPU uasge issue in hte softriq on FGSP cluster members with more than 200000 session running.

1061492

The HA secondary device sends GARP with the wrong MAC address after the vcluster is removed.

1064728

More sessions on a FGCP secondary unit than the primary unit.

1067274

Reply packets are misdirected in an asymmetric L3 FGSP configuration.

1070745 Sessions may not fail back to the original FGSP peer that owns the session if either the interface name for the monitor-interface or pingsvr-monitor-interface is 7 characters or longer.

1070901

The fgsp_route_health status is incorrect when configuring a monitor-interface or link-monitor-interface with a long interface name.

1084662

FFDB signatures keep flapping on all blades except the master FIM of the primary chassis.

1085371

SNMP v3 times out in FortiGate Azure/AWS in HA setup.

1092547

FortiGate in an HA configuration keeps rebooting continuously during a firmware upgrade.

Hyperscale

Bug ID

Description

1042512 On FortiGate, the CGN Resource Quota field allows an invalid value to be set.

1047362

The sw session and log2host netflow logs cannot be seen even though template is present. Data packet displays an error saying template not found.

1075915

The NP can get stuck after many hours of traffic with mse hash tbl caused by a mse depfail.

ICAP

Bug ID

Description

1072282 ICAP may encounter a 400 Bad Request error with certain websites due to an absent reason-phrase when converting from HTTP/2 to HTTP/1.

Intrusion Prevention

Bug ID

Description

891295

FortiGate experiences a performance issue with geography-type addresses matching in NGFW policy mode.

1001860 On the Security Profiles > Intrusion Prevention page, when a new IPS filter is created with no filter selected, the Details column of the IPS Signatures and Filters table is blank instead of All Attributes.

1016531

FortiGate encounters a memory usage issue in the IPSengine when av-failopen is set to pass.

1040783 FortiGate encounters CPU usage issue due to IPSEngine utilization when using an app-ctrl utm profile.

1066151

Forticron runs diagnose ips debug disable all and diagnose ips ssl debug none constantly due to a processing issue.

1086789

FortiGate encounters a CPU usage issue caused by the IPS engine.

IPsec VPN

Bug ID

Description

1002345 IKE daemon randomly does not operate as expected during phase1 rekeying depending on soft rekey margin, timing, and packet ordering.

1018749

IPsec inserted SA's are not deleted successfully after flushing all tunnels.

1020690 The IPsec Aggregate interface displays as DOWN on the Network > Interfaces and the Policy & Objects > Firewall Policy pages when the member including the Dialup VPN is actually UP. This is purely a GUI display issue and does affect system operation. The correct status is shown on the VPN > IPsec Tunnels page.
1023871 IPSec IKEv2 with SAML cannot match the Entra ID group during EAP due to a buffer size issue.
1024558 IPsec interfaces created on 802.1ad + 802.3ad interfaces with NP offloading enable do not work as expected after a firmware upgrade.
1027537 On the SOC4 platform, L2TP & ETHERIP traffic does not traverse through an IPSec tunnel with NP offload enabled.
1031963 The firewall hit and bytes counts display values of 0 in a policy-based VPN.
1039988 When performing a SAML authentication, authd gets stuck in a loop due to a CPU usage issue.

1041019

When QKD dialup is enabled, IKE SA cannot establish a connection and generates an error.

1042324 The Phase1 monitor BGP remains active when the tunnel is DOWN.

1049015

FortiOS does not enable all available IPsec drivers.

1050646 FortiGate does not always send the full Server Certificate Chain causing disconnections with IKEv2 VPN using the native Windows client.

1054953

If IKEv2 is selected during the VPN FortiClient Remote Access wizard setup in the GUI, the Extensible Authentication Protocol (EAP) configuration cannot be selected using the GUI.

1057165 The IPsec tunnel with QKD experiences flapping each time a DHCP configuration/interface update occurs.

1058691

The IPsec VPN tunnel on the branch unit does not terminate even when the remote gateway IP address becomes unavailable.

1059778

IPsec does not work as expected when the traffic path is spoke dialup to hub1, then from hub1 to another site using a site-to-site tunnel.

1060048

Throughput is limited in Site to Site VPN connections between the FW1kF and the FWVM Google Cloud platform.

1061925

IPsec tunnels are flushed when unrelated changes are made in the system.

1073995

Authentication for native iOS IPsec VPN user with FortiToken 2FA does not work as expected.

1075112

FortiGate enters into conserve mode due to IKED encountering a memory usage issue.

1076636

Unexpected behavior in IKED occurs when a peer attempts to negotiate with two different gateway profiles simultaneously.

1077122

The Phase2 SA is present in the kernel but there is no IKE Phase1 SA after an HA upgrade.

1080164

The tcp-mss setting on the tunnel interface does not take affect for IPv6 traffic.

1080420

The IPsec tunnel with FlexVPN Cisco (ASR1006 Cisco IOS XE Software, Version 17.09.05a) is down after 1 minute.

1081951

FortiGate encounters a steadily increasing IKED memory usage issue after upgrading to version 7.4.5.

1082624

EAP doe snot work as expected for local users inherited from the policy. RADIUS users can authenticate and the tunnel can be established.

Log & Report

Bug ID

Description

979200

In a Policy-Based NGFW, if there is no rule hit in central-snat and session never gets established, there will be no traffic log.

1001583

The GUI experiences a performance issue and reverts to the last input when multiple ports are added to a filter for destination ports.

1024570

The SSH deep-inspection with unsupported-version bypass > log information is not showing.

1024990

Some traffic logs show local-out traffic with the vdom-name.

1031342

On the Security Traffic Log > Security tab, the Details page displays data with a 1/500 log fetched prompt.

1034824 On the Log & Report > Forward Traffic page, application icons may not display in the Application Name column.

1044092

When filtering forward traffic logs using FortiAnalyzer as a source, data takes longer than expected to load and generates a memory error message.

1045253

FortiGate logs are not transferred into FortiGate Cloud Log server.

1050071 The unset pac-file-data from pac-policy does not generate a system event log and the pac-file-data is deleted.

1053334

The appcat log field is not included in the IoT signature logs.

1053412

Alert email displays an error for FDS-license-expiring.

1060204 When the threat feed download times out, a system event log is not generated.

1060316

Event logs are generated with CLEAR TEXT PASSWORD when using the diagnose test authserver tacacs*... command.

1074236

FortiGate cannot connect to FortiAnalyzer due to a hostname resolution issue.

1083537

The FortiAnalyzer serial number disappears from the FortiGate configuration when the OFTP session disconnects.

1086191

An error condition is observed in the fgtlod daemon when FortiCloud uses FortiAnalyzer-Cloud for backend logging.

1087067

On the Log Viewer page, the UTM log Matching log page keeps loading under the Log Details > Security tab.

1088385

FortiGate intermittently loses the FortiAnalyzer serial number and is required to verify again the FortiAnalyzer serial number and certificate.

1091064

Forward traffic does not contain the poluuid and policyname fields.

Proxy

Bug ID

Description

916178

FortiGate encounters an issue with the WAD daemon when deep inspection and SSL exemption are enabled while visiting a server with an expired certificate.

979502

On FortiGate, when the waps file is broken, the WAD process does not start.

1018780

FortiGate encounters a memory usage issue caused by the WAD process after an upgrade.

1020828

An HTTP2 stream issue causes an error condition in the WAD.

1042055

On FortiGate, an interruption occurs in the WAD process when in proxy-mode causing the unit to go into memory conserve mode.

1043423

Unexpected behavior is observed in the WAD user info history daemon with no data in messages, caused by erroneous memory allocation.

1047441

On FortiGate, the WAD process may not work as expected with H2 traffic when creating UTM logs.

1048296 FortiGate experiences an HTTP2 framing error when accessing websites using proxy mode with deep inspection configured due to a frame sizing issue in the WAD process.

1051875

The IP SNI check for strict sni-server-cert-check is skipped due to a WAD process issue.

1054052

The WAD process does not load a self-sign certificate when set admin-server-cert self-sign is configured in an explicit proxy.

1056127

An error condition occurs in the WAD process due to a rare error case during the SSL handshake.

1057442

On FortiGate, erroneous memory allocation is observed in the WAD process.

1057488

On FortiGate, unexpected behavior is observed in the WAD process during the HTTP session freeing.

1060812

When Proxy-mode inline IPS scanning is enabled, the botnet check within the IPS profile does not work as expected when the IPS profile is applied to a proxy-based inspection policy using certificate inspection.

1062516 The WAD process does not work as expected when FortiGate is configured as a HTTP load balancer with an HTTP session and changes are made to the virtual server live.

1064758

The Protocol option tcp window size in a proxy policy does not work as expected.

1067014 All wad-workers encounter a gradual memory usage issue, /proc/pid/maps shows increasing symbolic links to /tmp/casb_shm.

1067942

An error occurs in the WAD process when DoH traffic is sent to a transparent proxy after enabling HTTP policy redirect, and without having a transparent proxy configured.

1069896

A wad-worker experiences a memory usage issue increase over several days.

1078385

FortiGate experiences a memory usage issue in the WAD process when sending AVDBs updates from the config daemon to workers.

REST API

Bug ID

Description

1014694 The count and start API request attributes that required for some API endpoints are skipped, causing the REST API to not function as expected.
1057999 REST API returns an HTTP 500 error when ssl-static-key-ciphers is enabled under global system settings.

1060135

The API Swagger doc cannot be generated due to incorrect attributes.

1074529

FortiGate is unable to rename the Address object with API cmdb/firewall/address/ and Workspace mode transactions.

Routing

Bug ID

Description

969992

On FortiGate, SCTP traffic does not follow the routing table.

981876

The VRRP primary randomly stops sending VRRP advertisement messages for a few seconds.

1003756

When creating a rule on the Network > Routing Objects page, the Prefix-list is set to 0.0.0.0 0.0.0.0 when an incorrect format is entered in the Prefix field.

1006753 When renewing the LTE WWAN IP, some packets are sent using the old IP address causing traffic to drop.

1011816

The BGP neighbor range with a space in the name is ignored.

1023109

The vlan interface and IPSec tunnel interface are not displayed in the GUI after an upgrade.

1027847

FortiGate does not include the ecmp-max-paths setting in the configuration.

1029460

Creating a BGP IPv4 network prefix or neighbor in the GUI unintentionally creates an empty IPv6 network prefix.

1041812

In a hub and spoke HA configuration, SD-WAN pages take longer than expected to load in the GUI when there are a large number of spokes (~350) configured.

1042909

When creating a new static route on the Network > Static Routes page, the Priority field still displays when the Destination is switched from Subnet to Internet Service.

1046169 On FortiGate, outgoing traffic goes through the wrong interface for local-in traffic coming on an SDWAN interface.

1048338

On FortiGate in an HA setup the secondary HA passive device generates unexpected logs.

1049721 When BGP enables local-as-replace-as and there is a network loop condition, the NLRI's as-path is increased indefinitely.

1051709

On FortiOS, the Routes widget does not list out IPv6 routes with non-zero VRF's.

1057135 The gateway/offload value of offloaded one-way UDP sessions is reset when unrelated routing changes are made.

1057474

FortiGate does not generate a PIM register after stopping and starting a multicast stream.

1057504

FortiGate encounters a multicast routing issue in a VRRP environment.

1058616

On FortiOS, the secondary HA device does not display the SD-WAN Rules tab on the Network > SD-WAN page.

1060456 When hovering over a vlan interface on the SD-WAN Rules tab on the Network > SD-WAN page, the interface shows as disabled in the SD-WAN rule even though it is active.

1061899

Packet are duplicated if the latency between SD-WAN channels differs by more than 250ms.

1069060

Routes are not displayed correctly when the BGP configuration is in a specific order.

1071662

Shortcuts are not created for ADVPN2.0 and BGP on loopback for segregated transports.

1078608

The SD-WAN probe-timeout value is reset to 60000 after rebooting.

1085271

An IGMP membership report with a 0.0.0.0 source does not work as expected in kernel 4.19.13.

1085897

During a graceful restart towards Cisco Nexus causes BGP VPNv4 routes not to enter FIB.

1086828

SD-WAN logs show the parent interface instead of the shortcut interface.

1091628

The secondary IP of an interface is removed from the routing table of other VDOMs when a new VDOM is created.

Security Fabric

Bug ID

Description

873222

The automation email does not show the output of some commands.

948322

After deauthorizing a downstream FortiGate from the System > Firmware & Registration page, the page may appear to be stuck to loading.

Workaround: perform a full page refresh to allow the page to load again.

987531

Threat Feed connectors in different VDOMs cannot use the source IP when using internal interfaces.

1007607

When creating a new IPv6 address, SDN connectors cannot be added for dynamic addresses.

1019284

When optimizing a security rating, resolving an alert for one rating causes another alert to appear for another rating and the alerts cycle between both ratings continuously.

1040700

The external connector only allows users to specify the interface in the root vdom and not the vdom it is configured in.

1042972

Cannot test an automation stitch that uses the Schedule trigger from the GUI.

1054407

The Security Rating report does not show test results for downstream FortiGates when the All FortiGates view is selected.

1055616

The Threat feed loaded does not run immediately after restarting FortiGate.

1056262

With a FortiGate configured with a root-vdom and a mgmt-vdom, when an automation stitch is configured for a compromised host with IP-Ban action, the IP is banned from the mgmt-vdom.

1057862

FortiGate models with 2GB of memory that manage many extension devices (FortiSwitches and FortiAPs) may enter conserve mode due to the GUI process experiencing a memory usage issue over time.

1058589 Webhook requests use the same Content-Type: application/json in HTTP headers for all requests, even if it has a custom header.

1075080

The Duplicate Firewall Objects security rating does not work as expected, even it should be passed.

1082980

The AZURE type dynamic firewall address takes longer than normal to resolve itself, even with the correct filter value in the robot test bed.

1088000

The fsvrd listens on port 8013 and provides a certificate with set allowaccess fabric.

SSL VPN

Bug ID

Description

943971 On the VPN > SSL-VPN Settings page, when renaming a selected Restrict Access Host object, the object is deselected.

998219

Internet services cannot be used (IPv4 and IPv6) as destination in SSL VPN policies with dual stack enabled.
1042457 Duplicate log entries are created for SSL VPN when the tunnel is up or down.

1046374

An unauthenticated user mismatch occurs with the user.

1047705

SAML login from a Windows FortiClient is blocked when sslvpn-webmode is disabled in the config system global command.

1061165 SSL VPN encounters a signal 11 interruption and does not work as expected due to a word-length heap memory issue.

1066564

SSL VPN SMB is inaccessible when using Web Mode.

1078149

Internal resources cannot be accessed using FortiClient after a network disruption.

1079185

Incorrect maximum values present in CLI schema files.

1082427

The OS checklist for SSL VPN in FortiOS does not include macOS Sequoia 15.0.

1094825

Unexpected behavior caused by SSL VPN when multiple routes are configured with the same address.

Switch Controller

Bug ID

Description

1035823

When trying to start and stop the FortiSwitch LED blink using the Security Fabric, the GUI shows a Failed to send command error.

1038646

The FortiSwitch registration status changes from Not registered to Failed to fetch status when it is deauthorized and then authorized.

1042390

On the WiFi & Switch Controller > SSID page, NAC policies using a Wildcard MAC Address cannot be saved using the GUI.

Workaround: use the CLI to perform the operation.

1044150

Upgrading FortiSwitch from the FortiGate GUI does not work as expected when strict and moderate tunnel modes are configured.

1052908 When the name of the FortiSwitch does not match its serial number, it shows up as not registered on the System > Firmware & Registration and Security Fabric > Fabric Connectors pages.

1054445

When editing a dynamic port policy, saved changes are not shown in the GUI.

1055052

On FortiOS, NAC policies disappear from the GUI.

1069164

The incorrect timezone is shown for the managed switch.

1071594

The interface dialog takes longer than expected to load the FortiLink interface page when there are a large number of FortiSwitch VMs (300+).

1073340

On the Firmware page, the Registration Status shows a Failed to fetch status error for an online FortiSwitch. The CLI shows that its registered.

1074981

The FortiGate switch port configuration GUI does not allow the de-selection of all values for Allowed VLANs, Security Policy, or QOS Policy.

1077496

FortiGate encounters a CPU usage issue caused in the flcfgd when receiving multiple messages from the WAD daemon.

1092043

The dynamic VLAN is not visible in the GUI.

System

Bug ID

Description

776290

VLAN sub interface event logs for interface status changes are inaccurate.

894966

ACME certificates cannot be renewed manually before their expiration date.

901621

On the NP7 platform, setting the interface configuration using set inbandwidth <x> or set outbandwidth <x> commands stops traffic flow.

907752 On FortiGate 1000D models, the SFP 1G port randomly experiences flapping during operation.
920320 FortiGate encounters increasing Rx_CRC_Errors on SFP ports on the NP6 platform when an Ethernet frame contains carrier extension symbols to Cisco devices.

952104

FortiGate experiences packet loss when using an internal hardware switch.

960707 Egress shaping does not work on NP when applied on the WAN interface.
976314 After upgrading FortiGate and not changing any configuration details, the output of s_duplex in get hardware nic port command displays Half instead of Full. This is purely a display issue and does not affect system operation.

978290

FortiGate cannot communicate with ACME client and cannot generate certificate.

983467

FortiGate 60F and 61F models may experience a memory usage issue during a FortiGuard update due to the ips-helper process. This can cause the FortiGate to go into conserve mode if there is not enough free memory.

999816 FortiGate 100 models may become unresponsive and prevent access to the GUI, requiring a reboot to regain access due to an issue with the SOC3.

1006685

FortiGate enters a loop cycle and generates a large number of LCAP packets when FortiGate does not receive LCAP packets from a peer device.

1008022

After a restarting FortiGate from the GUI, the auto-nego SFP port settings are not reflected in FortiGate.

1011696

When a SIM card is ejected from a FortiGate using dual SIM cards, the log message does not indicate the slot number FortiOS is switching to.

1015347

After changing the admin profile scope to global, the vdom configuration in the admin user is not consistent with the GUI.

1018843 When FortiGate experiences a memory usage issue and enters into conserve mode, the system file integrity check may not work as expected and cause the device to shutdown.

1020602

After configuring a virtual wire pair (VWP) setting, it is not present in FortiGate after a reboot.

1020921 When configuring an SNMP trusted host that matches the management Admin trusted host subnet, the GUI may give an incorrect warning that the current SNMP trusted host does not match. This is purely a GUI display issue and does not impact the actual SNMP traffic.

1022935

FortiGate experiences a CPU usage issue when dedicated-management-cpu is enabled.

1025114 Insufficient free memory on entry-level Fortigate devices with 2 GB RAM may cause unexpected behavior in the IPS engine.

1029353

The SNMP trap is not sent out when a virus is detected on the antivirus scanner.

1029447 FortiGate encounters increasing Rx_CRC_Errors on SFP ports on the NP6 platform when an Ethernet frame contains carrier extension symbols to Cisco devices.
1032018 The SFP+ port LED does not illuminate and displays a speed 10Mbps even though the link status up and speed is set to 1000Mbps.

1032602

FortiGate encounters a memory usage issue on DNS proxy, resulting in FortiGate going into conserve mode.

1034286

FortiGate does not auto negotiate to Full duplex when connecting to FortiSwitch due to a duplication error.

1034821

On FortiGate, NP7 offloaded traffic does not use the updated MAC address from the ARP table to forward traffic using a GRE tunnel.

1039264

The DNS proxy does not forward the response after upgrading FortiGate.

1039564

When the configuration changes using the SSH, a backup failed alert is generated.

1044178

FortiGate does not return an ICMP message with type unreachable and code packet too big with the vne-tunnel.

1045301

Configuration revisions are missing multiple parts of the configuration.

1047996

FortiGate 4800F model split ports do not work as expected causing issues with LACP and MRU on split ports.

1048496

On FortiGate, the snmp daemon does not work as expected resulting in the SNMP queries timing out.

1049119

FortiGate encounters an interruption in the kernel due to a NULL pointer issue.

1050883

Backing up a configuration using SFTP with the domain username does not work when characters @ and \ are in the username.

1050908

In some scenarios, when FortiGate as a DHCP client sends out DHCP-REQUEST packets, the SRC IP address is set in the IP header.

1051961

On FortiGate, IP addresses cannot be assigned within a configured IP range due to a DHCP server issue.

1053536

On FortiGate, the console displays error messages when adding Pre and Post-login banners due to a rare error condition.

1054294

FortiGate reboots after a connected HA heartbeat cable is connected, or running the diag hardware deviceinfo nic ha command.

1055029

FortiGate cannot get updates from the public FortiGuard servers in FIPS-CC mode.

1055392

The traffic shaper does not take effect on the firewall policy when traffic is offloaded to NP7 due to a traffic management issue.

1055805

Duplicate SNMP traps are sent to ha-direct enabled trap servers when two ha-mgmt-intf are configured.

1056166

In the GUI, Can not create query, check_create_cmf_query, firewall, and ippool_grp errors are displayed.

1056174

FortiOS processes packets on a non-active port of a redundant link.

1056578

The DNS server does not operate as expected with forward-only mode enabled.

1057131

A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate.

1057625

FortiGate does not work as expected due to an interruption in the kernel.

1058397

On FortiGate 900 models, when the baudrate is configured, the changes are not applied and is set to 9600.

1059398

The ptp server does not work on the vlan interface.

1061155

Error messages are printed when assigning a transparent vdom to a vdom link interface.

1061334

FortiGate returns a string with a % sign for the OID 1.3.6.1.4.1.12356.101.4.8.2.1.8 (fgLinkMonitorPacketLoss).

1061413

EXPIRE dates are not displayed properly when executing the get sys fortiguard-service status command due to a formatting issue.

1061796

Inaccurate inbound and outbound traffic values on the Bandwidth widget for the EMAC VLAN interface.

1065047

An error is observed in the dnsproxy caused by the use of secondary dns-database zones.

1065553

FortiGate 80F-DSL models display the incorrect connected route.

1065969

FortiGate does not boot up after restoring a configuration file containing an invalid string format.

1066622

The source IP is not replaced as per the set fmg-source-ip after adding the device directly.

1066655

FortiGate 60F and 40F models become stuck after entering conserve mode and hbdev and console access is lost.

1068150

The DHCP relay uses the wrong interface to send DHCP offer packets to the client.

1069554

Upgrading directly from 7.2.4 or earlier versions to 7.2.9, or directly from 7.0.11 or earlier to 7.2.9 is not supported. Users must upgrade following the recommended upgrade path to avoid system hanging.

1071749

Write permission violation log observed in FortiGate in a rare case caused by the host check plugin used in FortiClient/browser side.

1072320

On FortiGate 400E models, the Link/Activity LED for the MGMT & HA port does not go out even after an exec shutdown command.

1072437

FortiWiFi 61F models experience a memory usage issue caused by the WAD daemon.

1072787

When accessing an IPv6 test site using the IPoE from an iPhone, the IPv6 connection does not work as expected.

1075032

On FortiGate, NP7 offloaded traffic does not use the MAC address of a new default gateway to forward traffic using the EMAC-VLAN interface.

1075585

Shared copper WAN1 and WAN2 ports remain down when the interface speed is set to 100full.

1079021

A CPU usage issue in the Softirq space on 40/160 CPU cores causes packets to drop.

1085736

FortiGate cannot restore the configuration file in the following sequence.

  1. private-data-encryption enabled with random key, and configuration is backed up.

  2. private-data-encryption disabled.

  3. private-data-encryption enabled again, with new random key.

  4. Restore configuration file in step 1.

1087109

After a reboot, FortiGate shows the wrong date if the date was set manually prior to the reboot.

1092021

FortiGate logs out when deleting the secondary IP configured on an interface in work space mode.

1093042

FortiGate encounters a memory usage issue caused by the snmpd daemon.

Upgrade

Bug ID

Description

1056126

FortiGate does not boot up properly after an upgrade when it has a large number (500+) of VDOMs configured.

User & Authentication

Bug ID

Description

1003373

FortiGate experiences a gradual memory usage issue in the fnbamd process.

1004258

The Strict-SNI SSL Profile might block connections even if SNI and Certificate CN match.

1008709

EST http password are not encrypted properly in the configuration file.

1009884

FortiGate encounters a CPU usage issue in the authd process after a firmware upgrade.

1036265 The reply-to option under config system alertmail is removed even for custom mail-servers with 2-factor authentication after an upgrade.
1039663 The TACACS+ connection times out, irrespective of the remoteauthtimeout setting, due to an issue with the ldapconntimeout setting, after upgrading to version 7.4.4.
1039771 FortiOS may reply to an FTM push message using a different egress interface instead of the original interface.

1042326

On FortiGate, the two-factor-email-expiry setting in the config system global command is not applicable for administrators.

1042987

NTLM authentication does not work as expected after an upgrade.

1043222

CMPv2 IR does not work as expected due to server certification validation error conditions.

1044084

On the Dashboard > Firewall User Monitor page, the Search field does not display in the GUI when there are a large number (+1000) FSSO user logos.

1045753

An ACME certificate enrollment error is generated without detailed error message information.

1050942 The Active Firewall-Authentication for 2FA FAC RADIUS users using PAP method does not work as expected after upgrading to version 7.4.4.
1060009 On FortiGate, RADSEC sent incorrect accounting packets due to a hashing issue.

1066264

RADIUS message authenticator checking is not optional under TLS.

1070560

Administrator authentication is bypassed when configuring the TACACS server.

1070743

FortiGate does not send a FortiToken activation code, preventing authentication.

1072870

FortiGate initiates LDAPS sessions that do not respect the ssl-min-proto-version option set under the config system global command.

1080234

For FortiGate (versions 7.2.10 and 7.4.5 and later) and FortiNAC (versions 9.2.8 and 9.4.6 and prior) integration, when testing connectivity/user credentials against FortiNAC that acts as a RADIUS server, the FortiGate GUI and CLI returns an invalid secret for the server error.

This error is expected when the FortiGate acts as the direct RADIUS client to the FortiNAC RADIUS server due to a change in how FortiGate handles RADIUS protocol in these versions. However, the end-to-end integration for the clients behind the FortiGate and FortiNAC is not impacted.

1080510

When using SCEP, the auto renewal certificate is not initiated.

1086643

FortiGate Captive Portal does not send the full Server Certificate Chain.

VM

Bug ID

Description

953526

The FortiGate-VM OCI may not detect an extra port attached.

972520

The FortiGate-AWS HA secondary awsd debug result prints raw HTML content.

1012927

When FortiGate returns an ICMP TTL-EXCEEDED message, the geneve option field header is missing.

1046696 A FortiGate VM HA in Azure Cloud may intermittently go out of synchronization due to an issue in the daemon process.
1054244 FortiToken does not work as expected after moving a FortiGate-VM license to a new VM with the same serial number.
1058355 FortiGate VM Azure does not work as expected and enters into conserve mode in vWAN setup.

1061669

User may not be able to access FortiGate-KVM with a trial license when there are many virtio_net interfaces.

1066138

FortiGate VM performance drops when traffic passes through an inter-vdom link.

1067046

The awsd does not handle the sts error message and the dynamic firewall address list as expected.

1070910

FortiFlex does not install successfully every time after the Day0 configuration using Port2 for the internet connection.

1072695

The VLAN interface is not reachable on a FortiGate VM running KVM with Intel 10G NIC (10Gb ethernet card).

1073016

The OCI SDN connector cannot call the API to the Oracle service when an IAM role is enabled.

1074600

Inadvertent traffic disruption observed on FortiGate-VM64 caused by a deadlock in the newcli process.

1082197

The FortiGate-VM on VMware ESXi equipped with an Intel E810-XXV network interface card (NIC) using SFP28 transceivers at 25G speed is unable to pass VLAN traffic when DPDK is enabled.

1094274

FortiGate becomes unresponsive due to an error condition when sending IPv6 traffic.

VoIP

Bug ID

Description

1070320 The SIP ALG does not create the expected session for SIP OPTIONS traffic.

Web Application Firewall

Bug ID

Description

1067320

The Web Application Firewall marks http/s traffic as a malformed constraint.

1071022 A matched pattern in the HTTP body cannot be blocked with a waf profile for some content types.

Web Filter

Bug ID

Description

537134

When a webfilter time-based quota is configured, once quota is reached, long sessions are not terminated.

1026023 The webfilter and traffic logs show the incorrect realserver IP address due to a WAD process issue.
1045884 When enabling the log all search keywords in the web filter profile and VDOM mode is disabled, the Key Word column is not populated with data.

1093624

The iprope lookup does not match regex static urlfilter entries.

WiFi Controller

Bug ID

Description

1013290

WIDS data is not removed from the CLI.

1028181 Wi-Fi devices would encounter service delay when roaming over captive-portal SSID with MAC-address authentication.

1033483

The secondary AC wpad_ac encounters a memory usage issue during stress tests with simulators.

1048928

Cannot retrieve DHCP IP's from the assigned VLAN when connecting Bridge SSID with RADIUS-based MAC authentication.

1049471

On FortiGate 90G and 120G models, traffic is dropped due to the MAC address of the VAP interface being updated with the old MAC address when HA is enabled.

1050915

When upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware.

1059964 RADIUS authentication in a WPA2-Enterprise SSID does not use ha-mgmt-interface when ha-direct is enabled.

1062730

On FortiGate, the set max-clients feature does not work as expected and allows more clients to connect than the maximum value configured.

1073390 FortiGate generates duplicate WiFi event logs when set cw_acd multi-core(set acd-process-count) is enabled.

1073588

Users cannot make any changes to wtp-profile due to an issue with the REST API connection to the cmdbsvr.

1075138

On FortiGate, the Source IP shown in the system logs is not referenced anywhere in the network.

1076738

The user-group is empty after clients pass local authentication with 2FA when connecting Enterprise+User-group SSIDs.

1089563

Client vlanid is lost after roaming between 2 APs when connecting a WPA-PSK(mpsk+vlan) SSID with fast-bss-transition enabled.

ZTNA

Bug ID

Description

1035072

FortiClient access to TCP-FWD with saml authentication does not redirect the loop if set ztna vip and saml SP use the same IP address.

1053309

An interruption occurs in the WAD when accessing ZTNA TCP-forwarding service through a proxy-policy with a SAML user group and h2-support is disabled on the firewall vip.

1056179

PPPoE encounters a performance issue after an upgrade.

1075532

Long sessions without any authentications terminate after 5 hours.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

1031370

FortiOS 7.6.1 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-51385

Resolved issues

Resolved issues

The following issues have been fixed in version 7.6.1. To inquire about a particular bug, please contact Customer Service & Support.

Anti Spam

Bug ID

Description

1050805 When spam mail is received from the server, POP connection times out.

Anti Virus

Bug ID

Description

1044961 On FortiGate, the Scanunit does not work as expected due to zlib data check issue.

1054835

Large file downloads take longer than expected due to a WAD process issue.

1055609

Files sent between FortiGate and FortiSandbox are dropped due to a connection issue.

1058701

On FortiGate, the av-mem-limit does not work as expected when set av-failopen pass configured due to a memory usage issue.

1062753

The incorrect percentage is displayed in the Files Uploaded Today widget to Sandbox.

1068321

MMDB and AVAI DBs are unsigned after upgrading from version 7.0.15 to version 7.2.9.

1070864,

1082877

The scanunit shows error messages that do not provide enough detail when corrupt AV engine or DB events occur.

1073326

Entry-level FortiGate's with 2GB of memory encounter a memory usage issue and do not operate as expected caused by the scanunit initiating an AV engine restart.

1078882

Scanunit tries to scan with no payload, resulting in an error message from FortiNDR and generating an error on FortiGate.

Application Control

Bug ID

Description

951150 The Zoom meeting remote control feature is not blocked during meetings.

990540

FortiGate does not generate traffic logs for established or denied TCP sessions that lack application data.

1060562

The application control profile is missing on the GUI for FortiGate models with 2GB of memory.

1064413

When using SD-WAN load balancing, some sites are slow or inaccessible when the Application Control action is set to Allow.

1066078

Application control cannot detect Facebook as Social Media when certificate-inspection is used.

1066567

Tencent.Meeting application is not blocked by the inline IPS when using HTTP or Socks5 proxy.

Data Loss Prevention

Bug ID

Description

908279

The DLP incorrectly detects a .pdf file as a .mpeg file and blocks the download.

984784

When a DLP profile is set to MAPI, there is a slow connection between Outlook and the Exchange server.

1049719 The DLP dictionary with a regex configuration does not deny an accent mark on FortiGate.

DNS Filter

Bug ID

Description

1058866 DNS translation does not work as expected when a resolved IP matches the external block list entry.

1086355

DNS query logs are not visible on FortiGate when traffic uses VIP for DNS traffic.

Explicit Proxy

Bug ID

Description

900911 When secure-web-proxy is enabled, if the client disconnects without sending any data as soon as the TCP connection with FortiGate is established, a WAD process signal 11 error occurs.

1056600

FortiGate experiences a WAD process issue and produces a wad_find_fwdsvr_by_key error.

1076642

Unable to load pages with cloudflare protected websites with auth enabled, if Auth scheme is set to Form-Based in explicit proxy.

File Filter

Bug ID

Description

1011320 Adding File Filter to a firewall policy will impact performance.

1095866

Filefilter block corrupts file on NetApp Files share instead of completely blocking it.

Firewall

Bug ID

Description

996622

On FortiGate, the IPv6 real server shown as DOWN by the health check but it is considered UP in the kernel.

1007029 On FortiGate, connections are disrupted between client email exchange servers and a virtual server when HTTP2 support is enabled.
1007566

When the FortiGate has thousands of addresses and hundreds address groups, the GUI can take a few minutes to search for a specific address inside the address group dialog.

1028356

Reordering the DNAT policies in the central NAT causes a false hit count.

1030516

An internet interface with egress/outbound shaping encounters a performance issue with sla after rebooting.

1036676 When a loopback interface has an IP that matches a VIP's extip with an extintf "any", FortiGate will match the VIP but the oif loopback causes an unintended policy 0 match and drops.
1047208 The FortiGate virtual server does not setup an http2 connection with a WebSocket server due to a WAD process issue.

1050864

No route is found when the FTP server connects back to FTP client in FTP active mode.

1051891

The SNMP fgIpsAnomalyDetections counter does not increase if the DoS policy is configured in a no management VDOM.

1055733

The F5 HTTP/S monitors for the web server in FortiGate do not function as expected due to HTTP 0.9 traffic.

1057080

On the Firewall Policy page, search results do not display in an expanded format.

1058494 When snat-hairpin-traffic is enabled, SNAT is not automatically applied to hairpin traffic, causing a SNAT mismatch in strict-dirty-session-check.

1059989

Modifying the shaping profile, whether it is assigned to an interface or not, results in IPsec tunnels going down.

1060452

FortiGate in policy-based mode showing the incorrect policy ID in forward traffic logs.

1062333 FortiGate does not reply to an ARP request when VIP is disabled due to an iplist reference issue.

1064748

When a VIP load balancer is configured to use an IPPool and has http-multiplex enabled, FortiGate performs SNATs using the outgoing interface instead of the IPPool.

1068393

Incorrect matching of zones and SD-WAN zones occurs where interfaces do not exist.

1078662

Incorrect checksum for fragments after QTM.

1079590

Intermittent reply traffic is not sent out of FortiGate.

1081542

On FortiGate, packets are dropped when ASIC offloading is enabled.

1052334

The firewall policy name length validation does not work with Korean characters.

1088905

The Virtual Server HTTP healthcheck uses the IP address as a Host even when the full URL is configured in http-get.

FortiGate 6000 and 7000 platforms

Bug ID

Description

986845

On FortiOS, the Security Fabric widget does not display information on blade status.

997161

On FortiGate 6000 FPCs and FortiGate 7000 FPMs the node process may consume large amounts of CPU resources, possibly affecting FPC or FPM performance. (You can run the diagnose sys top command from an FPC or FPM CLI to view CPU usage.) This problem may be caused by security rating result submission.

1016439 Enabling or disabling a vcluster causes some backup routes (proto = 20) to be lost when a routing table has a significant amount of routes (over 10000 routes).

1032573

In an HA configuration, FortiGate does not respond to SNMP queries causing the device to display as being DOWN.

1035601 An SNMP query for policy statistics returns 0 on MBD.

1037965

When applying a script to a configuration, the updated configuration is applied to the FIM but is not fully synchronized on the FPCs.

1048808 If the secondary reboots, after it rejoins the cluster SIP sessions are not resynchronized.

1056894

On FortiGate, IPv6 VRF routing tables appear under the new and old FPC primary units when the primary FPC slot is changed.

1057499 FIM interfaces are DOWN after restoring the root VDOM configuration due to a speed issue.
1060619 CSF is not working as expected.

1081015,

1086953

The secondary 7K slot 3 (FPM) has no ISDB database and will not update.

1086889

FIM encounters a split-brain scenario after rebooting.

1088402

On FortiGate 6K/7K FGSP clusters, the configuration does not synchronize properly with standalone-config-sync enabled.

FortiView

Bug ID

Description

1009287

On the Dashboard > FortiView Sessions page, closing a large number of FortiView sessions (+100) can take longer than expected and result in a CPU usage issue.

1029254

When trying to filter by device using the 1 week filter option, the User device store query error (error code: -1) error message is displayed.

1077555

On FortiGate, the Top Threat - WAN does not show the correct information for the IPS Logs.

GUI

Bug ID

Description

885427

On the Network > Interfaces page, the SFP port is grayed out on the faceplate diagram even though the port is working. This is purely a GUI display issue and does not affect system operation.

Workaround: View the SFP port information and status using the interface list in the CLI.

989512 When the number of users in the Firewall User monitor exceeds 2000, the search bar, column filters, and graphs are no longer displayed due to results being lazily loaded.
991573 In the Assets widget preview window of the Asset & Identities widget, clicking the Refresh button does not update the data.
1009143 On FortiOS, the time displayed in the CLI and in the GUI do not match.
1018682 When creating a firewall policy, applications groups with custom application signatures cannot be saved using the GUI.

1035356

The WAN interface is accessible in the GUI under certain interface configurations even though it is not allowed in the configuration file.

1044745 On the Dashboard > User & Devices page on a VDOM, the Address column shows multiple devices with the FortiGate VLAN gateway instead of the Client IP.
1050865 When updating an administrator password in the GUI, the password expiration date does not update when the new password is created.

1052040

The IP/Netmask column of HA management port hangs in the GUI.

1056800

On FortiOS, IPSec localid cannot be deleted using the GUI.

1057628

Catch WebSocket errors from PerMessageDeflate occur when the client abruptly closes the connection.

1058473 Expired licenses are still displayed in the GUI after 30 days.

1058608

FortiGate Cloud still shows as Activated in the GUI, even when logged out.

1068202

On low end models, the service list is empty when selecting members for a Service Group.

1071907

In the GUI, there is no setting for the type option for the npu_vlink interface.

1092475

GTP-profile do not display in the GUI when Central SNAT is enabled.

HA

Bug ID

Description

824651 Certificate upload causes HA checksum mismatch.
965217 In an HA configuration, FortiGate may experience intermittent heartbeat loss causing unexpected failover to the secondary unit.

1007516

Rx_dropped is observed on ha1 and ha2 interfaces and randomly experiences flapping.

1009939

When bandwidth is low, the tftp backup command on the secondary unit does not work as expected when it should be able to reach the server.

1026794

The HA secondary FortiGate logical topology page shows the FAZ connected interface as FortiAnalyzer.

1036139

FortiGate encounters a memory usage issue caused by cmdbsvr and hasync.

1047094 The HA Secondary unit cannot communicate with FortiGate Cloud when it uses standalone-mgmt-vdom using the HA Primary unit.

1052320

In a vCluster configuration, traffic stops after a VDOM failover.

1054041

On FortiGate's in an HA environment, DHCP clients can not get an IPv4 address from the server with vcluster.

1055336 Using the Test User Credentials button from the Radius Server in the GUI does not honor the custom nas-id-type.
1056138 On FortiGate 120G and 121G models in an HA cluster, if the ha or mgmt interface is used as the heartbeat interface, the HA cluster may not synchronize and the GUI HA page may not load.

1056651

Static routes configured under the secondary unit's standalone-mgmt-vdom do not take effect.

1060006

The standalone-config-sync conf-member kept out-of-synchronization after an upgrade and configuration change.

1060023

FortiGate in an HA environment encounter a CPU uasge issue in hte softriq on FGSP cluster members with more than 200000 session running.

1061492

The HA secondary device sends GARP with the wrong MAC address after the vcluster is removed.

1064728

More sessions on a FGCP secondary unit than the primary unit.

1067274

Reply packets are misdirected in an asymmetric L3 FGSP configuration.

1070745 Sessions may not fail back to the original FGSP peer that owns the session if either the interface name for the monitor-interface or pingsvr-monitor-interface is 7 characters or longer.

1070901

The fgsp_route_health status is incorrect when configuring a monitor-interface or link-monitor-interface with a long interface name.

1084662

FFDB signatures keep flapping on all blades except the master FIM of the primary chassis.

1085371

SNMP v3 times out in FortiGate Azure/AWS in HA setup.

1092547

FortiGate in an HA configuration keeps rebooting continuously during a firmware upgrade.

Hyperscale

Bug ID

Description

1042512 On FortiGate, the CGN Resource Quota field allows an invalid value to be set.

1047362

The sw session and log2host netflow logs cannot be seen even though template is present. Data packet displays an error saying template not found.

1075915

The NP can get stuck after many hours of traffic with mse hash tbl caused by a mse depfail.

ICAP

Bug ID

Description

1072282 ICAP may encounter a 400 Bad Request error with certain websites due to an absent reason-phrase when converting from HTTP/2 to HTTP/1.

Intrusion Prevention

Bug ID

Description

891295

FortiGate experiences a performance issue with geography-type addresses matching in NGFW policy mode.

1001860 On the Security Profiles > Intrusion Prevention page, when a new IPS filter is created with no filter selected, the Details column of the IPS Signatures and Filters table is blank instead of All Attributes.

1016531

FortiGate encounters a memory usage issue in the IPSengine when av-failopen is set to pass.

1040783 FortiGate encounters CPU usage issue due to IPSEngine utilization when using an app-ctrl utm profile.

1066151

Forticron runs diagnose ips debug disable all and diagnose ips ssl debug none constantly due to a processing issue.

1086789

FortiGate encounters a CPU usage issue caused by the IPS engine.

IPsec VPN

Bug ID

Description

1002345 IKE daemon randomly does not operate as expected during phase1 rekeying depending on soft rekey margin, timing, and packet ordering.

1018749

IPsec inserted SA's are not deleted successfully after flushing all tunnels.

1020690 The IPsec Aggregate interface displays as DOWN on the Network > Interfaces and the Policy & Objects > Firewall Policy pages when the member including the Dialup VPN is actually UP. This is purely a GUI display issue and does affect system operation. The correct status is shown on the VPN > IPsec Tunnels page.
1023871 IPSec IKEv2 with SAML cannot match the Entra ID group during EAP due to a buffer size issue.
1024558 IPsec interfaces created on 802.1ad + 802.3ad interfaces with NP offloading enable do not work as expected after a firmware upgrade.
1027537 On the SOC4 platform, L2TP & ETHERIP traffic does not traverse through an IPSec tunnel with NP offload enabled.
1031963 The firewall hit and bytes counts display values of 0 in a policy-based VPN.
1039988 When performing a SAML authentication, authd gets stuck in a loop due to a CPU usage issue.

1041019

When QKD dialup is enabled, IKE SA cannot establish a connection and generates an error.

1042324 The Phase1 monitor BGP remains active when the tunnel is DOWN.

1049015

FortiOS does not enable all available IPsec drivers.

1050646 FortiGate does not always send the full Server Certificate Chain causing disconnections with IKEv2 VPN using the native Windows client.

1054953

If IKEv2 is selected during the VPN FortiClient Remote Access wizard setup in the GUI, the Extensible Authentication Protocol (EAP) configuration cannot be selected using the GUI.

1057165 The IPsec tunnel with QKD experiences flapping each time a DHCP configuration/interface update occurs.

1058691

The IPsec VPN tunnel on the branch unit does not terminate even when the remote gateway IP address becomes unavailable.

1059778

IPsec does not work as expected when the traffic path is spoke dialup to hub1, then from hub1 to another site using a site-to-site tunnel.

1060048

Throughput is limited in Site to Site VPN connections between the FW1kF and the FWVM Google Cloud platform.

1061925

IPsec tunnels are flushed when unrelated changes are made in the system.

1073995

Authentication for native iOS IPsec VPN user with FortiToken 2FA does not work as expected.

1075112

FortiGate enters into conserve mode due to IKED encountering a memory usage issue.

1076636

Unexpected behavior in IKED occurs when a peer attempts to negotiate with two different gateway profiles simultaneously.

1077122

The Phase2 SA is present in the kernel but there is no IKE Phase1 SA after an HA upgrade.

1080164

The tcp-mss setting on the tunnel interface does not take affect for IPv6 traffic.

1080420

The IPsec tunnel with FlexVPN Cisco (ASR1006 Cisco IOS XE Software, Version 17.09.05a) is down after 1 minute.

1081951

FortiGate encounters a steadily increasing IKED memory usage issue after upgrading to version 7.4.5.

1082624

EAP doe snot work as expected for local users inherited from the policy. RADIUS users can authenticate and the tunnel can be established.

Log & Report

Bug ID

Description

979200

In a Policy-Based NGFW, if there is no rule hit in central-snat and session never gets established, there will be no traffic log.

1001583

The GUI experiences a performance issue and reverts to the last input when multiple ports are added to a filter for destination ports.

1024570

The SSH deep-inspection with unsupported-version bypass > log information is not showing.

1024990

Some traffic logs show local-out traffic with the vdom-name.

1031342

On the Security Traffic Log > Security tab, the Details page displays data with a 1/500 log fetched prompt.

1034824 On the Log & Report > Forward Traffic page, application icons may not display in the Application Name column.

1044092

When filtering forward traffic logs using FortiAnalyzer as a source, data takes longer than expected to load and generates a memory error message.

1045253

FortiGate logs are not transferred into FortiGate Cloud Log server.

1050071 The unset pac-file-data from pac-policy does not generate a system event log and the pac-file-data is deleted.

1053334

The appcat log field is not included in the IoT signature logs.

1053412

Alert email displays an error for FDS-license-expiring.

1060204 When the threat feed download times out, a system event log is not generated.

1060316

Event logs are generated with CLEAR TEXT PASSWORD when using the diagnose test authserver tacacs*... command.

1074236

FortiGate cannot connect to FortiAnalyzer due to a hostname resolution issue.

1083537

The FortiAnalyzer serial number disappears from the FortiGate configuration when the OFTP session disconnects.

1086191

An error condition is observed in the fgtlod daemon when FortiCloud uses FortiAnalyzer-Cloud for backend logging.

1087067

On the Log Viewer page, the UTM log Matching log page keeps loading under the Log Details > Security tab.

1088385

FortiGate intermittently loses the FortiAnalyzer serial number and is required to verify again the FortiAnalyzer serial number and certificate.

1091064

Forward traffic does not contain the poluuid and policyname fields.

Proxy

Bug ID

Description

916178

FortiGate encounters an issue with the WAD daemon when deep inspection and SSL exemption are enabled while visiting a server with an expired certificate.

979502

On FortiGate, when the waps file is broken, the WAD process does not start.

1018780

FortiGate encounters a memory usage issue caused by the WAD process after an upgrade.

1020828

An HTTP2 stream issue causes an error condition in the WAD.

1042055

On FortiGate, an interruption occurs in the WAD process when in proxy-mode causing the unit to go into memory conserve mode.

1043423

Unexpected behavior is observed in the WAD user info history daemon with no data in messages, caused by erroneous memory allocation.

1047441

On FortiGate, the WAD process may not work as expected with H2 traffic when creating UTM logs.

1048296 FortiGate experiences an HTTP2 framing error when accessing websites using proxy mode with deep inspection configured due to a frame sizing issue in the WAD process.

1051875

The IP SNI check for strict sni-server-cert-check is skipped due to a WAD process issue.

1054052

The WAD process does not load a self-sign certificate when set admin-server-cert self-sign is configured in an explicit proxy.

1056127

An error condition occurs in the WAD process due to a rare error case during the SSL handshake.

1057442

On FortiGate, erroneous memory allocation is observed in the WAD process.

1057488

On FortiGate, unexpected behavior is observed in the WAD process during the HTTP session freeing.

1060812

When Proxy-mode inline IPS scanning is enabled, the botnet check within the IPS profile does not work as expected when the IPS profile is applied to a proxy-based inspection policy using certificate inspection.

1062516 The WAD process does not work as expected when FortiGate is configured as a HTTP load balancer with an HTTP session and changes are made to the virtual server live.

1064758

The Protocol option tcp window size in a proxy policy does not work as expected.

1067014 All wad-workers encounter a gradual memory usage issue, /proc/pid/maps shows increasing symbolic links to /tmp/casb_shm.

1067942

An error occurs in the WAD process when DoH traffic is sent to a transparent proxy after enabling HTTP policy redirect, and without having a transparent proxy configured.

1069896

A wad-worker experiences a memory usage issue increase over several days.

1078385

FortiGate experiences a memory usage issue in the WAD process when sending AVDBs updates from the config daemon to workers.

REST API

Bug ID

Description

1014694 The count and start API request attributes that required for some API endpoints are skipped, causing the REST API to not function as expected.
1057999 REST API returns an HTTP 500 error when ssl-static-key-ciphers is enabled under global system settings.

1060135

The API Swagger doc cannot be generated due to incorrect attributes.

1074529

FortiGate is unable to rename the Address object with API cmdb/firewall/address/ and Workspace mode transactions.

Routing

Bug ID

Description

969992

On FortiGate, SCTP traffic does not follow the routing table.

981876

The VRRP primary randomly stops sending VRRP advertisement messages for a few seconds.

1003756

When creating a rule on the Network > Routing Objects page, the Prefix-list is set to 0.0.0.0 0.0.0.0 when an incorrect format is entered in the Prefix field.

1006753 When renewing the LTE WWAN IP, some packets are sent using the old IP address causing traffic to drop.

1011816

The BGP neighbor range with a space in the name is ignored.

1023109

The vlan interface and IPSec tunnel interface are not displayed in the GUI after an upgrade.

1027847

FortiGate does not include the ecmp-max-paths setting in the configuration.

1029460

Creating a BGP IPv4 network prefix or neighbor in the GUI unintentionally creates an empty IPv6 network prefix.

1041812

In a hub and spoke HA configuration, SD-WAN pages take longer than expected to load in the GUI when there are a large number of spokes (~350) configured.

1042909

When creating a new static route on the Network > Static Routes page, the Priority field still displays when the Destination is switched from Subnet to Internet Service.

1046169 On FortiGate, outgoing traffic goes through the wrong interface for local-in traffic coming on an SDWAN interface.

1048338

On FortiGate in an HA setup the secondary HA passive device generates unexpected logs.

1049721 When BGP enables local-as-replace-as and there is a network loop condition, the NLRI's as-path is increased indefinitely.

1051709

On FortiOS, the Routes widget does not list out IPv6 routes with non-zero VRF's.

1057135 The gateway/offload value of offloaded one-way UDP sessions is reset when unrelated routing changes are made.

1057474

FortiGate does not generate a PIM register after stopping and starting a multicast stream.

1057504

FortiGate encounters a multicast routing issue in a VRRP environment.

1058616

On FortiOS, the secondary HA device does not display the SD-WAN Rules tab on the Network > SD-WAN page.

1060456 When hovering over a vlan interface on the SD-WAN Rules tab on the Network > SD-WAN page, the interface shows as disabled in the SD-WAN rule even though it is active.

1061899

Packet are duplicated if the latency between SD-WAN channels differs by more than 250ms.

1069060

Routes are not displayed correctly when the BGP configuration is in a specific order.

1071662

Shortcuts are not created for ADVPN2.0 and BGP on loopback for segregated transports.

1078608

The SD-WAN probe-timeout value is reset to 60000 after rebooting.

1085271

An IGMP membership report with a 0.0.0.0 source does not work as expected in kernel 4.19.13.

1085897

During a graceful restart towards Cisco Nexus causes BGP VPNv4 routes not to enter FIB.

1086828

SD-WAN logs show the parent interface instead of the shortcut interface.

1091628

The secondary IP of an interface is removed from the routing table of other VDOMs when a new VDOM is created.

Security Fabric

Bug ID

Description

873222

The automation email does not show the output of some commands.

948322

After deauthorizing a downstream FortiGate from the System > Firmware & Registration page, the page may appear to be stuck to loading.

Workaround: perform a full page refresh to allow the page to load again.

987531

Threat Feed connectors in different VDOMs cannot use the source IP when using internal interfaces.

1007607

When creating a new IPv6 address, SDN connectors cannot be added for dynamic addresses.

1019284

When optimizing a security rating, resolving an alert for one rating causes another alert to appear for another rating and the alerts cycle between both ratings continuously.

1040700

The external connector only allows users to specify the interface in the root vdom and not the vdom it is configured in.

1042972

Cannot test an automation stitch that uses the Schedule trigger from the GUI.

1054407

The Security Rating report does not show test results for downstream FortiGates when the All FortiGates view is selected.

1055616

The Threat feed loaded does not run immediately after restarting FortiGate.

1056262

With a FortiGate configured with a root-vdom and a mgmt-vdom, when an automation stitch is configured for a compromised host with IP-Ban action, the IP is banned from the mgmt-vdom.

1057862

FortiGate models with 2GB of memory that manage many extension devices (FortiSwitches and FortiAPs) may enter conserve mode due to the GUI process experiencing a memory usage issue over time.

1058589 Webhook requests use the same Content-Type: application/json in HTTP headers for all requests, even if it has a custom header.

1075080

The Duplicate Firewall Objects security rating does not work as expected, even it should be passed.

1082980

The AZURE type dynamic firewall address takes longer than normal to resolve itself, even with the correct filter value in the robot test bed.

1088000

The fsvrd listens on port 8013 and provides a certificate with set allowaccess fabric.

SSL VPN

Bug ID

Description

943971 On the VPN > SSL-VPN Settings page, when renaming a selected Restrict Access Host object, the object is deselected.

998219

Internet services cannot be used (IPv4 and IPv6) as destination in SSL VPN policies with dual stack enabled.
1042457 Duplicate log entries are created for SSL VPN when the tunnel is up or down.

1046374

An unauthenticated user mismatch occurs with the user.

1047705

SAML login from a Windows FortiClient is blocked when sslvpn-webmode is disabled in the config system global command.

1061165 SSL VPN encounters a signal 11 interruption and does not work as expected due to a word-length heap memory issue.

1066564

SSL VPN SMB is inaccessible when using Web Mode.

1078149

Internal resources cannot be accessed using FortiClient after a network disruption.

1079185

Incorrect maximum values present in CLI schema files.

1082427

The OS checklist for SSL VPN in FortiOS does not include macOS Sequoia 15.0.

1094825

Unexpected behavior caused by SSL VPN when multiple routes are configured with the same address.

Switch Controller

Bug ID

Description

1035823

When trying to start and stop the FortiSwitch LED blink using the Security Fabric, the GUI shows a Failed to send command error.

1038646

The FortiSwitch registration status changes from Not registered to Failed to fetch status when it is deauthorized and then authorized.

1042390

On the WiFi & Switch Controller > SSID page, NAC policies using a Wildcard MAC Address cannot be saved using the GUI.

Workaround: use the CLI to perform the operation.

1044150

Upgrading FortiSwitch from the FortiGate GUI does not work as expected when strict and moderate tunnel modes are configured.

1052908 When the name of the FortiSwitch does not match its serial number, it shows up as not registered on the System > Firmware & Registration and Security Fabric > Fabric Connectors pages.

1054445

When editing a dynamic port policy, saved changes are not shown in the GUI.

1055052

On FortiOS, NAC policies disappear from the GUI.

1069164

The incorrect timezone is shown for the managed switch.

1071594

The interface dialog takes longer than expected to load the FortiLink interface page when there are a large number of FortiSwitch VMs (300+).

1073340

On the Firmware page, the Registration Status shows a Failed to fetch status error for an online FortiSwitch. The CLI shows that its registered.

1074981

The FortiGate switch port configuration GUI does not allow the de-selection of all values for Allowed VLANs, Security Policy, or QOS Policy.

1077496

FortiGate encounters a CPU usage issue caused in the flcfgd when receiving multiple messages from the WAD daemon.

1092043

The dynamic VLAN is not visible in the GUI.

System

Bug ID

Description

776290

VLAN sub interface event logs for interface status changes are inaccurate.

894966

ACME certificates cannot be renewed manually before their expiration date.

901621

On the NP7 platform, setting the interface configuration using set inbandwidth <x> or set outbandwidth <x> commands stops traffic flow.

907752 On FortiGate 1000D models, the SFP 1G port randomly experiences flapping during operation.
920320 FortiGate encounters increasing Rx_CRC_Errors on SFP ports on the NP6 platform when an Ethernet frame contains carrier extension symbols to Cisco devices.

952104

FortiGate experiences packet loss when using an internal hardware switch.

960707 Egress shaping does not work on NP when applied on the WAN interface.
976314 After upgrading FortiGate and not changing any configuration details, the output of s_duplex in get hardware nic port command displays Half instead of Full. This is purely a display issue and does not affect system operation.

978290

FortiGate cannot communicate with ACME client and cannot generate certificate.

983467

FortiGate 60F and 61F models may experience a memory usage issue during a FortiGuard update due to the ips-helper process. This can cause the FortiGate to go into conserve mode if there is not enough free memory.

999816 FortiGate 100 models may become unresponsive and prevent access to the GUI, requiring a reboot to regain access due to an issue with the SOC3.

1006685

FortiGate enters a loop cycle and generates a large number of LCAP packets when FortiGate does not receive LCAP packets from a peer device.

1008022

After a restarting FortiGate from the GUI, the auto-nego SFP port settings are not reflected in FortiGate.

1011696

When a SIM card is ejected from a FortiGate using dual SIM cards, the log message does not indicate the slot number FortiOS is switching to.

1015347

After changing the admin profile scope to global, the vdom configuration in the admin user is not consistent with the GUI.

1018843 When FortiGate experiences a memory usage issue and enters into conserve mode, the system file integrity check may not work as expected and cause the device to shutdown.

1020602

After configuring a virtual wire pair (VWP) setting, it is not present in FortiGate after a reboot.

1020921 When configuring an SNMP trusted host that matches the management Admin trusted host subnet, the GUI may give an incorrect warning that the current SNMP trusted host does not match. This is purely a GUI display issue and does not impact the actual SNMP traffic.

1022935

FortiGate experiences a CPU usage issue when dedicated-management-cpu is enabled.

1025114 Insufficient free memory on entry-level Fortigate devices with 2 GB RAM may cause unexpected behavior in the IPS engine.

1029353

The SNMP trap is not sent out when a virus is detected on the antivirus scanner.

1029447 FortiGate encounters increasing Rx_CRC_Errors on SFP ports on the NP6 platform when an Ethernet frame contains carrier extension symbols to Cisco devices.
1032018 The SFP+ port LED does not illuminate and displays a speed 10Mbps even though the link status up and speed is set to 1000Mbps.

1032602

FortiGate encounters a memory usage issue on DNS proxy, resulting in FortiGate going into conserve mode.

1034286

FortiGate does not auto negotiate to Full duplex when connecting to FortiSwitch due to a duplication error.

1034821

On FortiGate, NP7 offloaded traffic does not use the updated MAC address from the ARP table to forward traffic using a GRE tunnel.

1039264

The DNS proxy does not forward the response after upgrading FortiGate.

1039564

When the configuration changes using the SSH, a backup failed alert is generated.

1044178

FortiGate does not return an ICMP message with type unreachable and code packet too big with the vne-tunnel.

1045301

Configuration revisions are missing multiple parts of the configuration.

1047996

FortiGate 4800F model split ports do not work as expected causing issues with LACP and MRU on split ports.

1048496

On FortiGate, the snmp daemon does not work as expected resulting in the SNMP queries timing out.

1049119

FortiGate encounters an interruption in the kernel due to a NULL pointer issue.

1050883

Backing up a configuration using SFTP with the domain username does not work when characters @ and \ are in the username.

1050908

In some scenarios, when FortiGate as a DHCP client sends out DHCP-REQUEST packets, the SRC IP address is set in the IP header.

1051961

On FortiGate, IP addresses cannot be assigned within a configured IP range due to a DHCP server issue.

1053536

On FortiGate, the console displays error messages when adding Pre and Post-login banners due to a rare error condition.

1054294

FortiGate reboots after a connected HA heartbeat cable is connected, or running the diag hardware deviceinfo nic ha command.

1055029

FortiGate cannot get updates from the public FortiGuard servers in FIPS-CC mode.

1055392

The traffic shaper does not take effect on the firewall policy when traffic is offloaded to NP7 due to a traffic management issue.

1055805

Duplicate SNMP traps are sent to ha-direct enabled trap servers when two ha-mgmt-intf are configured.

1056166

In the GUI, Can not create query, check_create_cmf_query, firewall, and ippool_grp errors are displayed.

1056174

FortiOS processes packets on a non-active port of a redundant link.

1056578

The DNS server does not operate as expected with forward-only mode enabled.

1057131

A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate.

1057625

FortiGate does not work as expected due to an interruption in the kernel.

1058397

On FortiGate 900 models, when the baudrate is configured, the changes are not applied and is set to 9600.

1059398

The ptp server does not work on the vlan interface.

1061155

Error messages are printed when assigning a transparent vdom to a vdom link interface.

1061334

FortiGate returns a string with a % sign for the OID 1.3.6.1.4.1.12356.101.4.8.2.1.8 (fgLinkMonitorPacketLoss).

1061413

EXPIRE dates are not displayed properly when executing the get sys fortiguard-service status command due to a formatting issue.

1061796

Inaccurate inbound and outbound traffic values on the Bandwidth widget for the EMAC VLAN interface.

1065047

An error is observed in the dnsproxy caused by the use of secondary dns-database zones.

1065553

FortiGate 80F-DSL models display the incorrect connected route.

1065969

FortiGate does not boot up after restoring a configuration file containing an invalid string format.

1066622

The source IP is not replaced as per the set fmg-source-ip after adding the device directly.

1066655

FortiGate 60F and 40F models become stuck after entering conserve mode and hbdev and console access is lost.

1068150

The DHCP relay uses the wrong interface to send DHCP offer packets to the client.

1069554

Upgrading directly from 7.2.4 or earlier versions to 7.2.9, or directly from 7.0.11 or earlier to 7.2.9 is not supported. Users must upgrade following the recommended upgrade path to avoid system hanging.

1071749

Write permission violation log observed in FortiGate in a rare case caused by the host check plugin used in FortiClient/browser side.

1072320

On FortiGate 400E models, the Link/Activity LED for the MGMT & HA port does not go out even after an exec shutdown command.

1072437

FortiWiFi 61F models experience a memory usage issue caused by the WAD daemon.

1072787

When accessing an IPv6 test site using the IPoE from an iPhone, the IPv6 connection does not work as expected.

1075032

On FortiGate, NP7 offloaded traffic does not use the MAC address of a new default gateway to forward traffic using the EMAC-VLAN interface.

1075585

Shared copper WAN1 and WAN2 ports remain down when the interface speed is set to 100full.

1079021

A CPU usage issue in the Softirq space on 40/160 CPU cores causes packets to drop.

1085736

FortiGate cannot restore the configuration file in the following sequence.

  1. private-data-encryption enabled with random key, and configuration is backed up.

  2. private-data-encryption disabled.

  3. private-data-encryption enabled again, with new random key.

  4. Restore configuration file in step 1.

1087109

After a reboot, FortiGate shows the wrong date if the date was set manually prior to the reboot.

1092021

FortiGate logs out when deleting the secondary IP configured on an interface in work space mode.

1093042

FortiGate encounters a memory usage issue caused by the snmpd daemon.

Upgrade

Bug ID

Description

1056126

FortiGate does not boot up properly after an upgrade when it has a large number (500+) of VDOMs configured.

User & Authentication

Bug ID

Description

1003373

FortiGate experiences a gradual memory usage issue in the fnbamd process.

1004258

The Strict-SNI SSL Profile might block connections even if SNI and Certificate CN match.

1008709

EST http password are not encrypted properly in the configuration file.

1009884

FortiGate encounters a CPU usage issue in the authd process after a firmware upgrade.

1036265 The reply-to option under config system alertmail is removed even for custom mail-servers with 2-factor authentication after an upgrade.
1039663 The TACACS+ connection times out, irrespective of the remoteauthtimeout setting, due to an issue with the ldapconntimeout setting, after upgrading to version 7.4.4.
1039771 FortiOS may reply to an FTM push message using a different egress interface instead of the original interface.

1042326

On FortiGate, the two-factor-email-expiry setting in the config system global command is not applicable for administrators.

1042987

NTLM authentication does not work as expected after an upgrade.

1043222

CMPv2 IR does not work as expected due to server certification validation error conditions.

1044084

On the Dashboard > Firewall User Monitor page, the Search field does not display in the GUI when there are a large number (+1000) FSSO user logos.

1045753

An ACME certificate enrollment error is generated without detailed error message information.

1050942 The Active Firewall-Authentication for 2FA FAC RADIUS users using PAP method does not work as expected after upgrading to version 7.4.4.
1060009 On FortiGate, RADSEC sent incorrect accounting packets due to a hashing issue.

1066264

RADIUS message authenticator checking is not optional under TLS.

1070560

Administrator authentication is bypassed when configuring the TACACS server.

1070743

FortiGate does not send a FortiToken activation code, preventing authentication.

1072870

FortiGate initiates LDAPS sessions that do not respect the ssl-min-proto-version option set under the config system global command.

1080234

For FortiGate (versions 7.2.10 and 7.4.5 and later) and FortiNAC (versions 9.2.8 and 9.4.6 and prior) integration, when testing connectivity/user credentials against FortiNAC that acts as a RADIUS server, the FortiGate GUI and CLI returns an invalid secret for the server error.

This error is expected when the FortiGate acts as the direct RADIUS client to the FortiNAC RADIUS server due to a change in how FortiGate handles RADIUS protocol in these versions. However, the end-to-end integration for the clients behind the FortiGate and FortiNAC is not impacted.

1080510

When using SCEP, the auto renewal certificate is not initiated.

1086643

FortiGate Captive Portal does not send the full Server Certificate Chain.

VM

Bug ID

Description

953526

The FortiGate-VM OCI may not detect an extra port attached.

972520

The FortiGate-AWS HA secondary awsd debug result prints raw HTML content.

1012927

When FortiGate returns an ICMP TTL-EXCEEDED message, the geneve option field header is missing.

1046696 A FortiGate VM HA in Azure Cloud may intermittently go out of synchronization due to an issue in the daemon process.
1054244 FortiToken does not work as expected after moving a FortiGate-VM license to a new VM with the same serial number.
1058355 FortiGate VM Azure does not work as expected and enters into conserve mode in vWAN setup.

1061669

User may not be able to access FortiGate-KVM with a trial license when there are many virtio_net interfaces.

1066138

FortiGate VM performance drops when traffic passes through an inter-vdom link.

1067046

The awsd does not handle the sts error message and the dynamic firewall address list as expected.

1070910

FortiFlex does not install successfully every time after the Day0 configuration using Port2 for the internet connection.

1072695

The VLAN interface is not reachable on a FortiGate VM running KVM with Intel 10G NIC (10Gb ethernet card).

1073016

The OCI SDN connector cannot call the API to the Oracle service when an IAM role is enabled.

1074600

Inadvertent traffic disruption observed on FortiGate-VM64 caused by a deadlock in the newcli process.

1082197

The FortiGate-VM on VMware ESXi equipped with an Intel E810-XXV network interface card (NIC) using SFP28 transceivers at 25G speed is unable to pass VLAN traffic when DPDK is enabled.

1094274

FortiGate becomes unresponsive due to an error condition when sending IPv6 traffic.

VoIP

Bug ID

Description

1070320 The SIP ALG does not create the expected session for SIP OPTIONS traffic.

Web Application Firewall

Bug ID

Description

1067320

The Web Application Firewall marks http/s traffic as a malformed constraint.

1071022 A matched pattern in the HTTP body cannot be blocked with a waf profile for some content types.

Web Filter

Bug ID

Description

537134

When a webfilter time-based quota is configured, once quota is reached, long sessions are not terminated.

1026023 The webfilter and traffic logs show the incorrect realserver IP address due to a WAD process issue.
1045884 When enabling the log all search keywords in the web filter profile and VDOM mode is disabled, the Key Word column is not populated with data.

1093624

The iprope lookup does not match regex static urlfilter entries.

WiFi Controller

Bug ID

Description

1013290

WIDS data is not removed from the CLI.

1028181 Wi-Fi devices would encounter service delay when roaming over captive-portal SSID with MAC-address authentication.

1033483

The secondary AC wpad_ac encounters a memory usage issue during stress tests with simulators.

1048928

Cannot retrieve DHCP IP's from the assigned VLAN when connecting Bridge SSID with RADIUS-based MAC authentication.

1049471

On FortiGate 90G and 120G models, traffic is dropped due to the MAC address of the VAP interface being updated with the old MAC address when HA is enabled.

1050915

When upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware.

1059964 RADIUS authentication in a WPA2-Enterprise SSID does not use ha-mgmt-interface when ha-direct is enabled.

1062730

On FortiGate, the set max-clients feature does not work as expected and allows more clients to connect than the maximum value configured.

1073390 FortiGate generates duplicate WiFi event logs when set cw_acd multi-core(set acd-process-count) is enabled.

1073588

Users cannot make any changes to wtp-profile due to an issue with the REST API connection to the cmdbsvr.

1075138

On FortiGate, the Source IP shown in the system logs is not referenced anywhere in the network.

1076738

The user-group is empty after clients pass local authentication with 2FA when connecting Enterprise+User-group SSIDs.

1089563

Client vlanid is lost after roaming between 2 APs when connecting a WPA-PSK(mpsk+vlan) SSID with fast-bss-transition enabled.

ZTNA

Bug ID

Description

1035072

FortiClient access to TCP-FWD with saml authentication does not redirect the loop if set ztna vip and saml SP use the same IP address.

1053309

An interruption occurs in the WAD when accessing ZTNA TCP-forwarding service through a proxy-policy with a SAML user group and h2-support is disabled on the firewall vip.

1056179

PPPoE encounters a performance issue after an upgrade.

1075532

Long sessions without any authentications terminate after 5 hours.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

1031370

FortiOS 7.6.1 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-51385