Fortinet black logo

Known issues

Known issues

The following issues have been identified in Hyperscale firewall for FortiOS 7.2.4 Build 1396. For inquires about a particular bug, please contact Customer Service & Support. The Known issues described in the FortiOS 7.2.4 release notes also apply to Hyperscale firewall for FortiOS 7.2.4 Build 1396.

Bug ID

Description

802182

If you have configured a hardware logging server to use a VLAN interface to send log messages to a remote log server, you can't change the VLAN ID of the VLAN interface. Instead an error message similar to the following appears on the CLI when you attempt to change the VLAN ID: cmdb_txn_cache_data(query=log.npu-server,leve=1) failed. You can work around this issue by removing the hardware logging server or changing its destination, changing the VLAN ID of the VLAN interface, and then restoring the configuration of the hardware logging server.

807523

On NP7 platforms, the config system npu option nat46-force-ipv4-packet-forwarding is missing.

829549 Software ALG sessions can incorrectly add DSE entries to the NP7 session table. Traffic accepted by hyperscale firewall policies with cgn-eif enabled can then be matched with the DSE sessions and pass through the FortiGate.

841712

The config system npu option nat64-force-ipv4-packet-forwarding is not available.

843197

The output of the diagnose sys npu-session list/list-full command does not include policy route information.

846520

After an FGCP HA failover, the NPD/LPMD processes may be stopped by an out of memory killer process after running mixed sessions even when the amount of memory use is not excessive.

872146

In a hyperscale firewall VDOM, intra-zone policy sessions are assigned incorrect policy IDs.

Known issues

The following issues have been identified in Hyperscale firewall for FortiOS 7.2.4 Build 1396. For inquires about a particular bug, please contact Customer Service & Support. The Known issues described in the FortiOS 7.2.4 release notes also apply to Hyperscale firewall for FortiOS 7.2.4 Build 1396.

Bug ID

Description

802182

If you have configured a hardware logging server to use a VLAN interface to send log messages to a remote log server, you can't change the VLAN ID of the VLAN interface. Instead an error message similar to the following appears on the CLI when you attempt to change the VLAN ID: cmdb_txn_cache_data(query=log.npu-server,leve=1) failed. You can work around this issue by removing the hardware logging server or changing its destination, changing the VLAN ID of the VLAN interface, and then restoring the configuration of the hardware logging server.

807523

On NP7 platforms, the config system npu option nat46-force-ipv4-packet-forwarding is missing.

829549 Software ALG sessions can incorrectly add DSE entries to the NP7 session table. Traffic accepted by hyperscale firewall policies with cgn-eif enabled can then be matched with the DSE sessions and pass through the FortiGate.

841712

The config system npu option nat64-force-ipv4-packet-forwarding is not available.

843197

The output of the diagnose sys npu-session list/list-full command does not include policy route information.

846520

After an FGCP HA failover, the NPD/LPMD processes may be stopped by an out of memory killer process after running mixed sessions even when the amount of memory use is not excessive.

872146

In a hyperscale firewall VDOM, intra-zone policy sessions are assigned incorrect policy IDs.