Fortinet black logo

FortiOS Release Notes

Resolved issues

Resolved issues

The following issues have been fixed in version 7.4.2. To inquire about a particular bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

827497

Unsupported file samples are submitted to FortiSandbox for analytics.

845954

Flow AV does not have a limit of how much memory it can use when buffering files for scanning.

911872

When connecting to FortiGate Cloud Sandbox, the connection status takes a long time to update and shows as unreachable.

921175

Make improvements to the AV engine when handling outbreak prevention queries.

937375

Unable to delete malware threat feeds using the CLI.

948182

FortiSandbox side panel statistics only shows only statistics for root/management VDOM.

948371

Scanunit should no longer submit known infected files to FortiSandbox.

961077

Advanced Threat Protection Statistics dashboard is not increasing counters (AV).

962261

Send Files to FortiSandbox for Inspection AV profile setting does not work as expected.

Application Control

Bug ID

Description

820481

For firewall policies using proxy-based inspection mode, some HTTP/2 sessions may be incorrectly detected as unknown applications.

952307

FG-400F sees increased packet loss when using an application list in the policy.

Data Loss Prevention

Bug ID

Description

911830

DLP file type "AND" sensor cannot block the file when it is a DOCX file.

922311

DLP sensor cannot block MS-Office XML files, but can block MS-Office files when setting the profile type as message.

926592

Outlook cannot connect to the Exchange server once the DLP profile protocol is set to MAPI.

Explicit Proxy

Bug ID

Description

782713

Value overflow in destination interface of WAD traffic log.

926178

Post-upgrade, explicit proxy policies may mismatch when an HTTP CONNECT request or TLS SNI of a HTTPS session partially matches to a policy with deep inspection enabled.

942612

Web proxy forward server does not convert HTTP version to the original version when sending them back to the client.

Firewall

Bug ID

Description

665662

Using the append command to add entries to a policy object that mixes the use of wildcard and regular entries can result in an error to the policy during reboot. This applies to interface, address, and service policy objects.

786317

The service field in the traffic log shows the configured custom service name, even for traffic that does not match the FQDN configured in the custom service.

865137

After enabling the ssl-http-location-conversion option in the virtual server, it does not take effect.

875309

Support port block allocation (PBA) IP pools for NAT64 traffic.

921658

SD-WAN IPsec egress traffic shaping is not working when traffic offloading is enabled on an NP7 unit.

924588

Unable to access a real server using VIP with a custom cipher.

925630

Unable to unset http-supported-max-version to start using HTTP/2.

929109

Exported firewall policy is missing the negate option for source, destination, and service fields.

939734

When there are two to seven thousand addresses on the Policy & Objects > Virtual IPs page, clicking Suggestions in the Map to field makes the GUI unresponsive.

940360

FortiGate adds deleted tcp-portrange and udp-portrange after a reboot.

942605

FortiGate accepts the ha-mgmt-intf-only local-in policy from FortiManager, even though the ha-mgmt-status is not enabled.

948393

Policy lookup should not get result with policy_action: deny for non-TCP protocols and non-80/443 TCP ports.

950775

Traffic matches incorrect central SNAT rule when performing NAT46 in NGFW policy mode.

950889

Session clashes occur when incoming traffic matches an expected session and undergoes SNAT, but the SNAT port is already occupied by another session.

951373

Traffic shaping does not match the correct queue for outbound traffic when the class-id range exceeds the [2, 7] limit, which applies to egress shaping.

951684

The maximum size of the server certificate for virtual server should be displayed.

951984

The best output route may not be found for local out DNAT traffic.

952552

When using HTTP1, the TLS handshake from the proxy to the real server does not include the SNI.

952761

BGP and other traffic is getting dropped when IPv4 and IPv6 access lists are applied.

953907

Virtual wire pair interface drops all packet if the prp-port-in/prp-port-out setting is configured under system npu-setting prp on FG-101F.

953921

GUI does not display the configured parameters for traffic shaping policies when editing a policy with an SD-WAN zone.

957749

An action=accept should not be shown in a traffic log when UDP traffic dropped by IPS. The utmaction field is also missing in this scenario.

962984

Server load balancing health monitor does not work with Patroni (PostgreSQL cluster) when content matching is configured.

963071

Drops in multicast traffic, caused by a change in multicast routing (PIM), may occur at the start of multicast communication after upgrading.

967205

Changing the destination in the policy replaces applied services with service, ALL.

FortiGate 6000 and 7000 platforms

Bug ID

Description

886287

The IPsec ESP error log is generated with the wrong interface.

891642

FortiGate 6000 and 7000 platforms do not support managing FortiSwitch devices over FortiLink.

892600

IPv6 static route is removed from the management VDOM.

896758

Virtual clustering is not supported by FortiGate 6000 and 7000 platforms.

905450

SNMP walk failed to get the BGP routing information.

907140

Authenticated users are not synchronized to the secondary FortiGate 6000 or 7000 chassis when the secondary chassis joins a primary chassis to form an FGCP cluster.

907695

The FortiGate 6000 and 7000 platforms do not support IPsec VPN over a loopback interface or an NPU inter-VDOM link interface.

910824

On the FortiGate 7000F platform, fragmented IPv6 ICMP traffic is not load balanced correctly when the dp-icmp-distribution-method option under config load-balance is set to dst-ip. This problem may also occur for other dp-icmp-distribution-method configurations.

914273

SNMP query to fgVdEntSesRate returns a 0 value.

937879

FortiGate-7000F chassis with FIM-7941Fs cannot load balance fragmented IPv6 TCP and UDP traffic. Instead, fragmented IPv6 TCP and UDP traffic received by the FIM-7941F interfaces is sent directly to the primary FPM, bypassing the NP7 load balancers. IPv6 ICMP fragmented traffic load balancing works as expected. Load balancing fragmented IPv6 TCP and UDP traffic works as expected in FortiGate-7000F chassis with FIM-7921Fs.

938475

Memory usage issue occurs when multiple threads try to access a VLAN group.

939119

Statistics displayed in the Session Rate dashboard widget do not match the statistics displayed from the command line.

939171

The Global Sessions does not match the CLI output.

941944

CPU usage data displayed in the FortiGate 6000 GUI is actually CPU usage data for the management board. CPU usage data displayed in the FortiGate 7000 GUI is actually the CPU usage for the primary FIM.

941971

Dashboard widgets for CPU, Memory, Session, and Session Rate show usage as 0% on root and non-root VDOMs.

946943

On 6K and 7K platforms, the management VDOM GUI should not show the WiFi & Switch Controller menu.

947570

In an FGCP cluster, the secondary unit cannot reply to the SNMP query while using the management IP.

947936

On the FortiGate 7060E, only four of six PSUs are shown sometimes.

948750

When EMAC VLAN interfaces are removed spontaneously from the configuration, TCP traffic through their underlying VLAN interface fails.

949175

During FIM failover from FIM2 to FIM1, the NP7 PLE sticks on a cache invalidation, stopping traffic.

949240

SLBC special ports do not match the local-in policy's management path.

954862

Graceful upgrade from 7.0.12 to 7.2.6 or 7.2.7, or from 7.0.12 to 7.4.2 or 7.4.3 will fail on the FortiGate 6501F/6500F, FortiGate 7060E with slot6 occupied, and FortiGate 7121F with slot12 occupied.

FortiView

Bug ID

Description

941521

On the FortiView Web Sites page, the Category filter does not work in the Japanese GUI.

950137

FortiView Application widget does not show data for explicit proxy traffic.

GUI

Bug ID

Description

651648

When a large number of addresses are present (over 17 thousand), searching for an object on the Policy & Objects > Addresses page takes around 20 to 30 seconds to display results.

676306, 719694

When there is a connection issue between the FortiGate and a managed FortiSwitch, unexpected behavior might occur in httpsd when navigating between Switch Controller related GUI pages.

893560

When private data encryption is enabled, the GUI may become unresponsive and HA may fail to synchronize the configuration.

900818

The GUI should not show the interface speed in the SSL VPN interface tooltip.

904817

Changing the IPv4/IPv6 version in the dropdown of one widget will also impact other Session Rate widgets.

924159

A time difference is noticed in the FortiGate GUI and command line when the GUI is refreshed or when logged in on a new tab.

926410

While creating new address from firewall policy, the address slide takes around five seconds to open up.

934644

When the FortiGate is in conserve mode, node process (GUI management) may not release memory properly causing entry-level devices to stay in conserve mode.

940183

No IP results appear when using the search bar of the Assets & Identities dashboard.

940592

Dashboard > IPsec Monitor column selections are not saved across a page refresh.

941723

An error occurred when attempting to perform interface migration from a physical interface containing a VLAN interface to an aggregate interface.

943949

The GUI does not allow parentheses, (), to be used in the interface description.

945221

The GUI does not show any transceiver information until running get system interface transceiver in the CLI.

954356

When connected to the FortiGate GUI on a mobile phone, the table content on some pages like Network > Interfaces, Policy & Objects > Firewall Policy, and WiFi & Switch Controller > Managed FortiSwitches is cut off.

973432

When editing an SD-WAN rule with more than one destination, some destinations are automatically removed.

HA

Bug ID

Description

818432

When private data encryption is enabled, all passwords present in the configuration fail to load and may cause HA failures.

902945

Lost management connectivity to the standby node via in-band management.

904117

When walking through the session list to change the ha_id, some dead sessions could be freed one more time.

924671

There is no response on ha-mgmt-interfaces after a reboot when using a VLAN interface based on hd-sw as the ha-mgmt interface.

925269

Configuration is out-of sync when external feed connectors are applied to a policy.

929156

Asymmetric traffic through one of the FGSP members is allowed, even when the session is in a TCP SYN sent state.

937246

An error condition occurred while forwarding over a VRRP address, caused by the creation of a new VLAN.

940400

SCTP traffic is not forwarded back to the session owner (FGSP asymmetric traffic with IPS , NAT mode, and SCTP).

942504

Temporary network interruption occurs after disabling standalone-config-sync.

946878

When configuring an HA management interface, the GUI does not allow the same interface to be used for multiple management interfaces.

949230

Unable to send a file to a remote HA member when synchronizing a configuration.

950868

Traffic is not forwarded on L2 peer to keep FGSP with an available L2 connection.

953167

Access to console and SSH is lost due to a specific configuration.

953202

The hasync process is stuck at 99.9% on one or both cluster members after a failover.

954098

The set auto-firmware-upgrade disable setting is not synchronized between FGCP members.

955555

Unexpected traffic flow occurs after FGSP is enabled between clusters.

956473

A split brain condition occurs in an HA cluster when failover-hold-time is enabled.

963951

Unable to modify the pingserver-flip-timeout once vcluster is enabled.

965938

Standalone configuration synchronization fails to synchronize because of interface subnet firewall address objects.

Hyperscale

Bug ID

Description

936747

Connections per second (CPS) performance of SIP sessions accepted by hyperscale firewall policies with EIM and EIF disabled that include overload with port block allocation (PBA) GCN IP pools is lower than expected.

949188

ICMP reply packets are dropped by FortiOS in a NAT64 hyperscale policy.

950582

Traffic not passing across the VDOM link.

958066

Observed TCP sessions timing out with a single hyperscale VDOM configuration after loading image from BIOS.

Intrusion Prevention

Bug ID

Description

907259

High CPU usage due to the IPS engine, causing high latency on the network.

916175

Make improvements to the IPS engine when handling a rare buffer overflow case.

934015

RSH subsession timeout when IPS is enabled.

949662

Interface policy logs show the external facing IP instead of the actual source.

952270

IPS logs for VIP traffic shows external IP as a destination for some signatures.

IPsec VPN

Bug ID

Description

780297

IKE debug log filtering functionality exhibits inaccuracies, resulting in the possibility of displaying unmatched logs when filters are set.

852051

Unexpected condition in IPsec engine on SoC4 platforms leads to intermittent IPsec VPN operation.

897867

IPsec VPN between two FortiGates (100F and 60F) experiences slow throughput compared to the available underlay bandwidth.

922064

Firewall becoming unresponsive to DPD/IKE messages, causing IPsec VPNs to drop.

926002

Incorrect traffic order in IPsec aggregate redundant member list after upgrade.

926052

For DHCP-over-IPsec, sometimes the client does not send a delete after the DHCP SA.

930278

Setting loopback-asymroute disable in the phase 1 configuration pushes down the loopback interface index as tunnel's bound_if, causing traffic route lookup failure.

942495

IKEv2 connection issue related to the order of policies using different user groups.

945367

Disabling src-check (RPF) on the parent tunnel is not inherited by ADVPN shortcuts.

945873

Inconsistency of mode-cfg between phase 1 assigned IP address and destination selector addition.

949086

Policy route is not matching ESP traffic.

950445

After a third-party router failover, traffic traversing the IPsec tunnel is lost.

951765

Shortcut created from parent tunnel interface does not inherit MSS value and may face fragmentation.

954614

IPsec phase 2 negotiation fails with failed to create dialup instance, error 22 error message.

954911

IPv6 firewall address IP prefix object is invisible on accessible networks in the GUI.

955552

Split DNS not pushed because the split tunnel is not recognized.

957412

Authentication fails since the EAP proxy cannot get groups by the hostname of FortiGate in the NAS-ID RADIUS attribute.

958516

Acct-Output-Octets are wrapped to 32-bit on RADIUS accounting stop.

960212

IPsec traffic is unidirectional when vpn-id-ipip and offloading are enabled, and the tunnel VRF is greater than 63.

961305

FortiGate is sending ESP packets with source MAC address of port1 HA virtual MAC address.

Limitations

Bug ID

Description

961992

The buffer and description queue limitation of Marvell switch ports causes a performance limitation.

Log & Report

Bug ID

Description

850642

Logs are not seen for traffic passing through the firewall caused by numerous simultaneous configuration changes.

903841

When an administrator login fails, the event log shows that the login was successful.

905849

The log settings disk usage graph should show the usage data in the legend's format.

920376

Content disarm and reconstruction (CDR) files are not consistent in the log view.

931924

SSL VPN web mode login history entries are not seen when logs are being sent to FortiAnalyzer.

932537

If Security Rating is enabled to run on schedule (every four hours), the FortiGate can unintentionally send local-out traffic to fortianalyzer.forticloud.com during the Security Rating run.

933650

When the DNS server does not provide the IPv6 (AAAA record) for the NTP server FQDN, FortiGate NTP shows that the IPv6 server is unresolved -- unreachable, which is not true.

938396

The following intrusion was observed: in the alert mail refers to another field in the anomaly log.

940814

Administrators without read permissions for the threat weight feature cannot see the event log menu.

945287

Cloud logging settings are not retained when the FortiGate language setting is Japanese.

949001

The quarantine-log enable setting changed to disable after restoring a backup configuration.

950768

When a GUI login fails due to exceed_limit, logged in successfully appears in the system event log.

952509

The UUID is used instead of the external resource name in the Threat feed updated system event log.

953667

Override setting under multi-VDOM mode may cause the FortiGate to stop sending logs to FortiAnalyzer or syslog after switching to non-VDOM mode.

961244

Icons in logs evaluations and policies are no longer displayed.

965247

FortiGate syslog format in reliable transport mode is not compliant with RFC 6587.

967100

When FortiAnalyzer Cloud is chosen as log location, archived data cannot be downloaded for intrusion prevention.

970412

Virus/Botnet AV log for machine learning detection hyperlink returns Object Moved Permanently.

Proxy

Bug ID

Description

790426

An error case occurs in WAD while redirecting the web filter HTTPS sessions.

806556

Unexpected behavior in WAD when the ALPN is set to http2 in the ssl-ssh-profile.

845361

A rare error condition occurred in WAD caused by compounded SMB2 requests.

919781

Unexpected behavior in WAD when there are multiple LDAP servers configured on the FortiGate.

938502

Original source IP is not preserved for transparent proxy rule after upgrading.

940149

Inadvertent traffic disruption caused by WAD when it receives an HTTP2 data frame payload on a dead stream.

943998

Unble to access website ( https://ec***.qu***.com/me***) when using a proxy with DPI.

947359

The newly implemented one-way server will set its port to null when closing.

947814

Too many redirects on TWPP after the second KRB keytab is configured.

954104

An error case occurs in WAD when WAD gets the external authenticated users from other daemons.

955006

SNI check is not working when set to inspect all ports.

958464

Unexpected behavior in WAD when building a debug URL.

971489

When cloud-communication is disabled, WAD still connects to productapi.fortinet.com.

974307

An error condition occurs in WAD while coping a file directory.

REST API

Bug ID

Description

944723

The /firewall/vip API does not recognize custom SSL cipher suites.

948356

An error condition occurs in HTTPSD when a REST API request is sent with invalid parameters.

951384

API responses for PBR provides incorrect value if address groups are used in PBR.

951411

Inconsistent handling of web filter profile actions in API transactions.

Routing

Bug ID

Description

820407

Auto-link fails if the FortiGate device initiating the FGFM connection is using an interface with a VRF not set to the default, 0.

848270

Reply traffic from the DNS proxy (DNS database) is choosing the wrong interface.

894795

MP-BGP EVPN source address shows 127.0.0.1, while the loopback interface is with a different address.

897918

When the local traffic is using SD-WAN and the reply is coming on a different interface, the reply is ignored.

906896

Make OSPFv3 update the translator role and translated Type-5 LSA when the ASBR table is updated.

926525

Routing information changed log is being generated from secondary in an HA cluster.

928152

FortiGate generates two OSPF stub entries for the same prefix after upgrading from 6.4 to 7.0.

932092

API call returns recursive next-hop for the gateway address.

934273

Support GR helper mode (peer) for BGP.

935370

SD-WAN performance SLA tcp-connect probes clash with user sessions.

935886

SD-WAN packet duplication feature in force mode suddenly stops duplicating and starts to duplicate again once the FortiGate is rebooted.

938500

Status of OSPF adjacency is Loading on spokes while Full on the hub side.

944351

When using the policy match tool, the Incoming Interface dropdown does not list SD-WAN member interfaces.

946783

Unable to set OSPF interface IP in the GUI.

949623

DNS over TCP does not work when interface-select-method is set to sdwan in the DNS setting, and the corresponding SD-WAN rule is restricted to the TCP protocol only.

951397

Inconsistent GUI output with unusual characters showing up in the SD-WAN rule list settings and the edit SD-WAN rule page.

952543

Reply TCP traffic for inbound local session uses a different egress interface than the originating traffic

952908

Locally originated type 5 and 7 LSAs' forward address value is incorrect.

953744

Connected VLAN routes are getting removed after an HA failover.

954100

Packet loss status in SD-WAN health check occur after an HA failover.

957049

If the router community-list type is expanded and changed to standard, this causes a community-list error.

957627

Learned BGP through routes are not withdrawn on the spoke after the EBGP neighborship is down between the hub and third party device.

963561

When establishing an IPsec tunnel between FortiGate peers using OSPF to exchange routes, the FortiGate sends a stub LSA with a 32-bit netmask.

964182

IPsec traffic with vpn-id-ipip is egressing with the wrong VRF when offloading is enabled.

965752

After HA monitored interface fails over, SD-WAN intermittently does not follow route-map-preferable.

Security Fabric

Bug ID

Description

902344

When there are over 30 downstream FortiGates in the Security Fabric, the root FortiGate's GUI may experience slowness when loading the Fabric Management page, preventing firmware upgrades using the GUI.

907819

Advanced GCP connector does not resolve if one element does not exist.

908489

When one of the downstream FortiGate VM's license is invalid, the root FortiGate will be automatically logged out from accessing the Firmware & Registration page.

920391

Non-management VDOM is not allowed to set a source-ip for config system external-resource.

932935

External connector to VMware 8.0 with verify certificate enabled will fail.

938980

HTTP 400 errors observed using SDN connector to query AKS clusters if local administrator is disabled.

947634

Security Fabric widget shows the serial number instead of the hostname for a secondary FortiGate in HA.

950624

Renaming conflicted Fabric objects on the root FortiGate does not synchronize the changed Fabric objects to the downstream FortiGate.

958396

The number of log IDs under one automation trigger is limited to 16.

975393

Security Fabric messages change after upgrading.

SSL VPN

Bug ID

Description

879329

Destination address of SSL VPN firewall policy may be lost after upgrading when dstaddr is set to all and at least one authentication rule has a portal with split tunneling enabled.

923518

When SSL VPN web mode is disabled, SAML external browser login requests should be blocked.

930275

Firewall policy is not allowing the all destination address with a split-tunneling portal.

933985

FortiGate as SSL VPN client does not work on NP6 and NP6XLite devices.

941676

Japanese key input does not work correctly during RDP in SSL VPN web mode.

947210

Multiple instances of *** code requested backtrace *** for SSL VPN daemon observed during a graceful upgrade (on FG-6000F).

950157

SSL VPN connected/disconnected endpoint event log can be in the wrong sequence.

952860

During a handshake when FortiClient sends a larger-than-MTU hello message, the packet is fragmented by IP layer and dropped by the FortiGate.

957406

OS checklist for SSL VPN in FortiOS does not include macOS Sonoma 14.

958430

If the password renew template is modified with a non-default password renew policy, FortiClient cannot read the HTML page correctly, and returns the error, Server may not be reachable.

Switch Controller

Bug ID

Description

703374

Long DAC-type cable is added to default media type on 10G port on FG-100F.

816790

Console printed DSL related error messages when disconnecting the managed FortiSwitch and connecting to the FortiGate again.

818116

When changing the FortiSwitch FortiLink port status, the configuration is not applied to the FortiSwitch.

904834

FortiGate and FortiManager have different definitions for the value of poe-detection-type on S108EF platform.

911232

The security rating shows an incorrect warning for unregistered FortiSwitches on the Managed FortiSwitches page.

Workaround: navigate to the Diagnostics & Tools pane of the FortiSwitch to see the correct registration status.

931694

Enhance FortiLink event logs for FortiGate-FortiSwitch event log translation.

941673

FortiSwitch event log displays serial number under name when CAPWAP is up or down.

945779

FortiGate CPU VM increases due to the FortiLink process.

949377

NAC policy cannot match the MAC address with a specific VLAN. The NAC policy needs to be deleted and re-createed for it to work again.

953918

FortiGate nac_segment is not showing assigned dynamic VLAN on FortiSwitch ports.

961997

Unable to get interface descriptions for the FortiLink ports by using OID 1.3.6.1.2.1.2.2.1.2.

System

Bug ID

Description

656983

MIB OID fgSysLowMemUsage returns value for devices where it is not applicable.

699379

Host protection engine (HPE) enchantments should be applied to NP6XLite platforms.

713951

Not all ports are coming up after an LAG bounce on 8 × 10 GB lag with ASR 9K. Affected platforms: FG-3960E and FG-3980E.

859393

SNMP poll for fgExplicitProxyRequests returns 0.

860460

On a redundant interface, traffic may drop with some NPU-offload enabled policies when the interface is not initialized properly.

861962

When configuring an 802.3ad aggregate interface with a 1 Gbps speed, the port's LED is off and traffic cannot pass through. Affected platforms: 110xE, 220xE, 330xE, 340xE, and 360xE.

893143

SFP interfaces that are set to 1000auto are not negotiating on the secondary device.

899279

NP7 did not offload jumbo packet, but get NPU INFO: offload=9/9 in the console output.

900663

Refactor the time zone feature to use the IANA time zone database.

900791

The X1 port is always up with FCLF8522P2BTLFTN transceiver.

907657

FortiGate does not perform a disk scan automatically when autorun-log-fsck is enabled.

908831

Unable to set upstream interface without setting the delegated IAID first for IPv6 interface under delegated mode.

909225

ISP traffic is failing with the LAG interfaces on upstream switches.

910651

On FG-600F, all members are up but the LACP status is showing as down after upgrading.

910700

Ports are flapping and down on the FortiGate 3980E.

910829

Degraded traffic bandwidth for download passing from 10G to 1G interfaces.

912092

FortiGate does not send ARP probe for UDP NP-offloaded sessions.

913355

GUI and CLI time mismatch for Central America (Mexico) time zone.

915585

Optimize memory usage, which causes the SLAB memory to increase, in kernel 4.19.

916493

Fail detection function does not work properly on X1 and X2 10G ports.

919901

For FIPS-CC mode, the strict check for basic constraints should be removed for end entity certificates.

922458

Administrator with read-only access to management permissions cannot perform a configuration backup in the GUI.

923473

Sometimes, the configuration cannot be backed up to an FTP server.

924654

MAC flapping on switch when UDP packets passthrough VWP multiple times with ASIC offload.

925647

Memory usage issue caused by repetitive log messages. Affected platforms: FG-100xF.

926546

ICMP and UDP traffic over GRE is not offloaded on NP7 platforms.

926817

Review the temperature sensor for the SoC4 system.

929904

When L3 or L4 hashing algorithm is used, traffic is not forwarded over the same aggregate member after being offloaded by NP7.

930329

LTE modem is missing after upgrading to 7.4.

931299

When the URL filter requests the FortiGuard (FGD) rating server address using DNS, it will try to get both A (IPv4) and AAAA (IPv6) records.

931604

The FortiGate checksum changes and the FortiManager Backup Mode device status becomes out-of-sync.

934115

Administrator can no longer view or edit the VPN settings in the GUI with system:none permissions.

937500

FortiOS does not accept an installation script from FortiManager when creating an extender-profile with login-password-change is set to yes.

937982

High CPU usage might be observed on entry-level FortiGates if the cache size reaches 10% of the system memory.

938174

ARP issue with VXLAN over IPsec and Soft Switch.

938539

The cmdbsvr process is stuck, and is not pushing configurations made in the GUI or CLI.

939013

SNMP walk of the entire MIB fails when the configuration has split-port and a large number of interfaces.

939110

DHCP server on LAN interface is lost after rebooting or restoring the configuration file.

939411

Multiple spawns of hotplug process consuming high CPU resources.

939935

High CPU usage caused by DHCP packets.

939947

FG-1100E SFP interface of port 23 and 24 with transceiver status is down after upgrading.

940504

Loading of the Toss Bank application is delayed or gets stuck on iPhones with hyperscale CGNAT (NAT64).

940752

FortiGate does not allow tagged VLAN 0 packets.

942502

Unexpected behavior occurred in the kernel when creating EMAC VLAN interfaces based on an aggregate interface with the new kernel 4.1.9.

942893

When DHCP IP reservation is edited from the DHCP dashboard widget, the changes are not retained.

943026

Changes to per-IP shaper settings are not reflected on offloaded sessions in NP7 platforms.

943090

Buffer and description queue limitation of Marvell switch port will cause a performance limitation.

943615

When cmdbsvr receives a request to update the version number, it also receives a copy of the query, but this copy is not freed.

943948

FortiGate as L2TP client is not working with Cisco ASR as L2TP server.

945426

FortiGate ports are not in a configured state after the connected switch reboots.

946413

Temperature sensor value missing for FG-180xF, FG-420xF, and FG-440xF platforms.

946714

Unexpected reboot caused by a rare error condition for FG-VM.

947127

Kernel TCP sessions do no timeout after receiving a legitimate RST and the system goes into conserve mode.

947240

FortiGate is not able to resolve ARPs of few hosts due to their ARP replies not reaching the primary FPM.

948448

A super_admin administrator is unable to log in after restoring the VDOM configuration on the admin VDOM and rebooting the FortiGate.

948460

Enabling NP7 offloading is causing packet drops when using a shaping profile.

949481

The tx_collision_err counter in the FortiOS CLI keeps increasing on both 10G SFP+ X1 and X2 interfaces.

949975

SNMP value for OID 1.3.6.1.4.1.12356.101.12.2.2.1.5 returns the wrong value.

950010

Alarm observed for high PECI temperature despite less CPU activity.

952279

The TCP handshake is interrupted when any of the UTM profiles are enabled.

954439

SNMP does not respond if a VRF is set on the interface.

955021

When signal 11 is sent to httpsd process using diagnose sys kill 11 <PID>, httpsd does not restart. The GUI displays a Service unavailable message. GUI access can be restored by rebooting the device.

955074

MSS clamping is not working on VXLAN over IPsec after upgrading.

955798

Interface LED from panel indicates the wrong status.

955998

The traffic is dropped when auto-asic-offload is enabled and passing through a VLAN associated with a 10G redundant interface.

956107

On the FortiGate 400F and 600F, the buffer and description queue limitation of the Marvell switch port causes a performance limitation.

956391

On FG-10xE, when using ports 13 to 16 as virtual switch LAN ports, auto speed is not supported.

956413

FG-1101E ports with AVAGO AFBR-5710PZ transceiver failed to come up after upgrading.

956980

Batch lastlog does not show any errors for password-policy misconfiguration.

957147

FortiGate as DNS server does not resolve domains in the local database on new VDOM.

957714

Memory usage issue occurs when multiple threads try to access a VLAN group.

957846

High CPU usage caused by DHCP packets.

958157

The GeoIP file should close appropriately after opening or using mmap to share memory.

960563

An error condition occurred in the kernel caused by a rare condition while using the GRE tunnels.

963597

Multiple configuration settings are missing after restoring the VDOM.

966761

SNMP OID 1.3.6.1.2.1.4.34.1.5 ipAddressPrefix is not fully implemented.

969230

FEC does not take effect on X5 - X8 ports when running at 25G ULL mode on FG-601F.

Upgrade

Bug ID

Description

871181

FG-3401E link is not coming up using DAC cables after upgrading.

896937

Port channel is down after upgrading the FG-1101E.

940126

Upgrading a FGT-3401E generates BPDUs, which cause the switch to disable the port.

User & Authentication

Bug ID

Description

823884

When a search is performed on a user (User & Authentication > User Definition page), the search results highlight all the groups the user belongs to.

868994

FortiGate receives FSSO user in the format of HOSTNAME$.

907169

WPA2-Enterprise SSID should support EAP-TLS authentication for PKI users that are configured with multi-factor authentication through a RADIUS server.

915998

FortiToken mobile push with ACME gives an untrusted certificate in iOS application.

932989

In some cases, the HA connection is removed and its memory is freed, but it is still read/written in the following process.

939517

On the System > Replacement Messages page, the guest user email template cannot restore to the to default value.

943087

After creating a new guest user, the administrator cannot view the user's password in plaintext in the GUI.

946116

On a FortiGate managed by FortiManager, when a guest administrator logs in with read-only permissions, the administrator can still create and edit the guest user.

947299

Global DH parameter does not modify the SSH connection key exchange.

949699

Administrator single sign-on login with SAML does not work after upgrading the firmware 7.4.1 due to the SAML entity-id field being incorrectly reset to being empty.

955939

PKI users should pass certificate-based authentication over WPA2-Enterprise SSID.

961496

CPU usage issue caused by signature update for device identification.

VM

Bug ID

Description

903037

A false positive SSL VPN login token error message is generated after a successful connection.

932085

In an Azure cluster, the NTP source-ip6 (IPv6) is synchronized while the source-ip (IPv4) is not.

950235

IPv6 multicast packets are triggering a hardware checksum failure error message on the console.

953760

FG-VM is unable to respond to the load balancer's health probe correctly.

956460

FortiGate cannot detect a log disk in some new Azure instances.

957299

On a FortiGate ARM-OCI, after adding more than one network interface card and rebooting, the interface cards are not kept in order.

957886

GCP OS log in integration issues occur in FortiGate deployment.

959859

FG-VM64-AZURE SDN connector does not retry requests to management.azure.com if they fail.

965668

Interfaces are brought down by azd, and traffic is disrupted until manually disabling and enabling the interfaces on the Azure VM.

968740

Unexpected behavior in awsd caused by tags with an empty value on AWS instances while adding a new AWS Fabric connector.

970201

Unexpected reboot caused by a rare error condition for FG-VM.

WAN Optimization

Bug ID

Description

954541

In WANOpt transparent mode, WAN optimization does not keep the original source address of the packets.

Web Application Firewall

Bug ID

Description

939380

User cannot set the match ALL pattern to deny traffic for the web application firewall profile in the GUI.

Web Filter

Bug ID

Description

887699

Web filter override expiry date in the GUI may be one hour off if daylight saving time (DST) is observed.

923548

Newly added local URL filter entry cannot be moved using drag-and-drop.

929110

The strict option for sni-server-cert-check is behaving the same as if it is set to enable, and logs are not generated upon SNI mismatch with the CN or SAN.

945011

URL filter IP address block is not honored by the enhanced policy lookup tool.

947676

Web filter profile setting changes the order of FortiGuard web filter categories.

WiFi Controller

Bug ID

Description

801730

The move function in the CLI does not work for mpsk-profile and mpsk-group.

891804

After initial packets, FG-101F stops forwarding wired traffic over FAP-23JF LAN tunneled with a dynamic VLAN VAP.

896104

An error condtion occured in the kernel when the FortiAP and SSID are in the same software switch.

938840

Excessive MEM POOLuse_up_cnt observed on secondary unit in an HA environment.

941691

Managed FortiSwitch detects multiple MACs using the same IP address.

944465

On the WiFi & Switch Controller > Managed FortiAPs page of a non-management VDOM, the Register button is unavailable in the Device Registration pane.

945356

FortiOS fails to get all of the configured MAC ACL entries.

946796

The eap_proxy daemon may keep reloading randomly due to failing to bind a port. This will cause an IKE and WiFi authentication failure.

949857

Captive portal appears each time after a channel change or if roaming performed (Cisco ISE with FortiGate and FortiAP).

951792

Clients connected to certain FortiAPs do not have internet access.

952889

PMKID should be removed when an Android device is disconnected by the RADIUS CoA DM request with Acct-Session-Id.

958314

AeroScout agent is not working.

967158

WPA2-Enterprise with a Windows NPS server is not working after upgrading the firmware to FortiOS 7.4.1.

973935

On the WiFi & Switch Controller > Managed FortiAPs page, there is an error when changing from a single 5G profile to a dual 5G profile on the FortiAP 831F.

ZTNA

Bug ID

Description

918279

Traffic does not match a simple ZTNA firewall policy when the external interface configured on a ZTNA server is a member of a SD-WAN zone being used in the same ZTNA firewall policy.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

943578

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-44250

952029

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-46717

956553

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2024-23112

959918

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-38545

964415

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-44487

966706

FortiOS7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-48784

Resolved issues

The following issues have been fixed in version 7.4.2. To inquire about a particular bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

827497

Unsupported file samples are submitted to FortiSandbox for analytics.

845954

Flow AV does not have a limit of how much memory it can use when buffering files for scanning.

911872

When connecting to FortiGate Cloud Sandbox, the connection status takes a long time to update and shows as unreachable.

921175

Make improvements to the AV engine when handling outbreak prevention queries.

937375

Unable to delete malware threat feeds using the CLI.

948182

FortiSandbox side panel statistics only shows only statistics for root/management VDOM.

948371

Scanunit should no longer submit known infected files to FortiSandbox.

961077

Advanced Threat Protection Statistics dashboard is not increasing counters (AV).

962261

Send Files to FortiSandbox for Inspection AV profile setting does not work as expected.

Application Control

Bug ID

Description

820481

For firewall policies using proxy-based inspection mode, some HTTP/2 sessions may be incorrectly detected as unknown applications.

952307

FG-400F sees increased packet loss when using an application list in the policy.

Data Loss Prevention

Bug ID

Description

911830

DLP file type "AND" sensor cannot block the file when it is a DOCX file.

922311

DLP sensor cannot block MS-Office XML files, but can block MS-Office files when setting the profile type as message.

926592

Outlook cannot connect to the Exchange server once the DLP profile protocol is set to MAPI.

Explicit Proxy

Bug ID

Description

782713

Value overflow in destination interface of WAD traffic log.

926178

Post-upgrade, explicit proxy policies may mismatch when an HTTP CONNECT request or TLS SNI of a HTTPS session partially matches to a policy with deep inspection enabled.

942612

Web proxy forward server does not convert HTTP version to the original version when sending them back to the client.

Firewall

Bug ID

Description

665662

Using the append command to add entries to a policy object that mixes the use of wildcard and regular entries can result in an error to the policy during reboot. This applies to interface, address, and service policy objects.

786317

The service field in the traffic log shows the configured custom service name, even for traffic that does not match the FQDN configured in the custom service.

865137

After enabling the ssl-http-location-conversion option in the virtual server, it does not take effect.

875309

Support port block allocation (PBA) IP pools for NAT64 traffic.

921658

SD-WAN IPsec egress traffic shaping is not working when traffic offloading is enabled on an NP7 unit.

924588

Unable to access a real server using VIP with a custom cipher.

925630

Unable to unset http-supported-max-version to start using HTTP/2.

929109

Exported firewall policy is missing the negate option for source, destination, and service fields.

939734

When there are two to seven thousand addresses on the Policy & Objects > Virtual IPs page, clicking Suggestions in the Map to field makes the GUI unresponsive.

940360

FortiGate adds deleted tcp-portrange and udp-portrange after a reboot.

942605

FortiGate accepts the ha-mgmt-intf-only local-in policy from FortiManager, even though the ha-mgmt-status is not enabled.

948393

Policy lookup should not get result with policy_action: deny for non-TCP protocols and non-80/443 TCP ports.

950775

Traffic matches incorrect central SNAT rule when performing NAT46 in NGFW policy mode.

950889

Session clashes occur when incoming traffic matches an expected session and undergoes SNAT, but the SNAT port is already occupied by another session.

951373

Traffic shaping does not match the correct queue for outbound traffic when the class-id range exceeds the [2, 7] limit, which applies to egress shaping.

951684

The maximum size of the server certificate for virtual server should be displayed.

951984

The best output route may not be found for local out DNAT traffic.

952552

When using HTTP1, the TLS handshake from the proxy to the real server does not include the SNI.

952761

BGP and other traffic is getting dropped when IPv4 and IPv6 access lists are applied.

953907

Virtual wire pair interface drops all packet if the prp-port-in/prp-port-out setting is configured under system npu-setting prp on FG-101F.

953921

GUI does not display the configured parameters for traffic shaping policies when editing a policy with an SD-WAN zone.

957749

An action=accept should not be shown in a traffic log when UDP traffic dropped by IPS. The utmaction field is also missing in this scenario.

962984

Server load balancing health monitor does not work with Patroni (PostgreSQL cluster) when content matching is configured.

963071

Drops in multicast traffic, caused by a change in multicast routing (PIM), may occur at the start of multicast communication after upgrading.

967205

Changing the destination in the policy replaces applied services with service, ALL.

FortiGate 6000 and 7000 platforms

Bug ID

Description

886287

The IPsec ESP error log is generated with the wrong interface.

891642

FortiGate 6000 and 7000 platforms do not support managing FortiSwitch devices over FortiLink.

892600

IPv6 static route is removed from the management VDOM.

896758

Virtual clustering is not supported by FortiGate 6000 and 7000 platforms.

905450

SNMP walk failed to get the BGP routing information.

907140

Authenticated users are not synchronized to the secondary FortiGate 6000 or 7000 chassis when the secondary chassis joins a primary chassis to form an FGCP cluster.

907695

The FortiGate 6000 and 7000 platforms do not support IPsec VPN over a loopback interface or an NPU inter-VDOM link interface.

910824

On the FortiGate 7000F platform, fragmented IPv6 ICMP traffic is not load balanced correctly when the dp-icmp-distribution-method option under config load-balance is set to dst-ip. This problem may also occur for other dp-icmp-distribution-method configurations.

914273

SNMP query to fgVdEntSesRate returns a 0 value.

937879

FortiGate-7000F chassis with FIM-7941Fs cannot load balance fragmented IPv6 TCP and UDP traffic. Instead, fragmented IPv6 TCP and UDP traffic received by the FIM-7941F interfaces is sent directly to the primary FPM, bypassing the NP7 load balancers. IPv6 ICMP fragmented traffic load balancing works as expected. Load balancing fragmented IPv6 TCP and UDP traffic works as expected in FortiGate-7000F chassis with FIM-7921Fs.

938475

Memory usage issue occurs when multiple threads try to access a VLAN group.

939119

Statistics displayed in the Session Rate dashboard widget do not match the statistics displayed from the command line.

939171

The Global Sessions does not match the CLI output.

941944

CPU usage data displayed in the FortiGate 6000 GUI is actually CPU usage data for the management board. CPU usage data displayed in the FortiGate 7000 GUI is actually the CPU usage for the primary FIM.

941971

Dashboard widgets for CPU, Memory, Session, and Session Rate show usage as 0% on root and non-root VDOMs.

946943

On 6K and 7K platforms, the management VDOM GUI should not show the WiFi & Switch Controller menu.

947570

In an FGCP cluster, the secondary unit cannot reply to the SNMP query while using the management IP.

947936

On the FortiGate 7060E, only four of six PSUs are shown sometimes.

948750

When EMAC VLAN interfaces are removed spontaneously from the configuration, TCP traffic through their underlying VLAN interface fails.

949175

During FIM failover from FIM2 to FIM1, the NP7 PLE sticks on a cache invalidation, stopping traffic.

949240

SLBC special ports do not match the local-in policy's management path.

954862

Graceful upgrade from 7.0.12 to 7.2.6 or 7.2.7, or from 7.0.12 to 7.4.2 or 7.4.3 will fail on the FortiGate 6501F/6500F, FortiGate 7060E with slot6 occupied, and FortiGate 7121F with slot12 occupied.

FortiView

Bug ID

Description

941521

On the FortiView Web Sites page, the Category filter does not work in the Japanese GUI.

950137

FortiView Application widget does not show data for explicit proxy traffic.

GUI

Bug ID

Description

651648

When a large number of addresses are present (over 17 thousand), searching for an object on the Policy & Objects > Addresses page takes around 20 to 30 seconds to display results.

676306, 719694

When there is a connection issue between the FortiGate and a managed FortiSwitch, unexpected behavior might occur in httpsd when navigating between Switch Controller related GUI pages.

893560

When private data encryption is enabled, the GUI may become unresponsive and HA may fail to synchronize the configuration.

900818

The GUI should not show the interface speed in the SSL VPN interface tooltip.

904817

Changing the IPv4/IPv6 version in the dropdown of one widget will also impact other Session Rate widgets.

924159

A time difference is noticed in the FortiGate GUI and command line when the GUI is refreshed or when logged in on a new tab.

926410

While creating new address from firewall policy, the address slide takes around five seconds to open up.

934644

When the FortiGate is in conserve mode, node process (GUI management) may not release memory properly causing entry-level devices to stay in conserve mode.

940183

No IP results appear when using the search bar of the Assets & Identities dashboard.

940592

Dashboard > IPsec Monitor column selections are not saved across a page refresh.

941723

An error occurred when attempting to perform interface migration from a physical interface containing a VLAN interface to an aggregate interface.

943949

The GUI does not allow parentheses, (), to be used in the interface description.

945221

The GUI does not show any transceiver information until running get system interface transceiver in the CLI.

954356

When connected to the FortiGate GUI on a mobile phone, the table content on some pages like Network > Interfaces, Policy & Objects > Firewall Policy, and WiFi & Switch Controller > Managed FortiSwitches is cut off.

973432

When editing an SD-WAN rule with more than one destination, some destinations are automatically removed.

HA

Bug ID

Description

818432

When private data encryption is enabled, all passwords present in the configuration fail to load and may cause HA failures.

902945

Lost management connectivity to the standby node via in-band management.

904117

When walking through the session list to change the ha_id, some dead sessions could be freed one more time.

924671

There is no response on ha-mgmt-interfaces after a reboot when using a VLAN interface based on hd-sw as the ha-mgmt interface.

925269

Configuration is out-of sync when external feed connectors are applied to a policy.

929156

Asymmetric traffic through one of the FGSP members is allowed, even when the session is in a TCP SYN sent state.

937246

An error condition occurred while forwarding over a VRRP address, caused by the creation of a new VLAN.

940400

SCTP traffic is not forwarded back to the session owner (FGSP asymmetric traffic with IPS , NAT mode, and SCTP).

942504

Temporary network interruption occurs after disabling standalone-config-sync.

946878

When configuring an HA management interface, the GUI does not allow the same interface to be used for multiple management interfaces.

949230

Unable to send a file to a remote HA member when synchronizing a configuration.

950868

Traffic is not forwarded on L2 peer to keep FGSP with an available L2 connection.

953167

Access to console and SSH is lost due to a specific configuration.

953202

The hasync process is stuck at 99.9% on one or both cluster members after a failover.

954098

The set auto-firmware-upgrade disable setting is not synchronized between FGCP members.

955555

Unexpected traffic flow occurs after FGSP is enabled between clusters.

956473

A split brain condition occurs in an HA cluster when failover-hold-time is enabled.

963951

Unable to modify the pingserver-flip-timeout once vcluster is enabled.

965938

Standalone configuration synchronization fails to synchronize because of interface subnet firewall address objects.

Hyperscale

Bug ID

Description

936747

Connections per second (CPS) performance of SIP sessions accepted by hyperscale firewall policies with EIM and EIF disabled that include overload with port block allocation (PBA) GCN IP pools is lower than expected.

949188

ICMP reply packets are dropped by FortiOS in a NAT64 hyperscale policy.

950582

Traffic not passing across the VDOM link.

958066

Observed TCP sessions timing out with a single hyperscale VDOM configuration after loading image from BIOS.

Intrusion Prevention

Bug ID

Description

907259

High CPU usage due to the IPS engine, causing high latency on the network.

916175

Make improvements to the IPS engine when handling a rare buffer overflow case.

934015

RSH subsession timeout when IPS is enabled.

949662

Interface policy logs show the external facing IP instead of the actual source.

952270

IPS logs for VIP traffic shows external IP as a destination for some signatures.

IPsec VPN

Bug ID

Description

780297

IKE debug log filtering functionality exhibits inaccuracies, resulting in the possibility of displaying unmatched logs when filters are set.

852051

Unexpected condition in IPsec engine on SoC4 platforms leads to intermittent IPsec VPN operation.

897867

IPsec VPN between two FortiGates (100F and 60F) experiences slow throughput compared to the available underlay bandwidth.

922064

Firewall becoming unresponsive to DPD/IKE messages, causing IPsec VPNs to drop.

926002

Incorrect traffic order in IPsec aggregate redundant member list after upgrade.

926052

For DHCP-over-IPsec, sometimes the client does not send a delete after the DHCP SA.

930278

Setting loopback-asymroute disable in the phase 1 configuration pushes down the loopback interface index as tunnel's bound_if, causing traffic route lookup failure.

942495

IKEv2 connection issue related to the order of policies using different user groups.

945367

Disabling src-check (RPF) on the parent tunnel is not inherited by ADVPN shortcuts.

945873

Inconsistency of mode-cfg between phase 1 assigned IP address and destination selector addition.

949086

Policy route is not matching ESP traffic.

950445

After a third-party router failover, traffic traversing the IPsec tunnel is lost.

951765

Shortcut created from parent tunnel interface does not inherit MSS value and may face fragmentation.

954614

IPsec phase 2 negotiation fails with failed to create dialup instance, error 22 error message.

954911

IPv6 firewall address IP prefix object is invisible on accessible networks in the GUI.

955552

Split DNS not pushed because the split tunnel is not recognized.

957412

Authentication fails since the EAP proxy cannot get groups by the hostname of FortiGate in the NAS-ID RADIUS attribute.

958516

Acct-Output-Octets are wrapped to 32-bit on RADIUS accounting stop.

960212

IPsec traffic is unidirectional when vpn-id-ipip and offloading are enabled, and the tunnel VRF is greater than 63.

961305

FortiGate is sending ESP packets with source MAC address of port1 HA virtual MAC address.

Limitations

Bug ID

Description

961992

The buffer and description queue limitation of Marvell switch ports causes a performance limitation.

Log & Report

Bug ID

Description

850642

Logs are not seen for traffic passing through the firewall caused by numerous simultaneous configuration changes.

903841

When an administrator login fails, the event log shows that the login was successful.

905849

The log settings disk usage graph should show the usage data in the legend's format.

920376

Content disarm and reconstruction (CDR) files are not consistent in the log view.

931924

SSL VPN web mode login history entries are not seen when logs are being sent to FortiAnalyzer.

932537

If Security Rating is enabled to run on schedule (every four hours), the FortiGate can unintentionally send local-out traffic to fortianalyzer.forticloud.com during the Security Rating run.

933650

When the DNS server does not provide the IPv6 (AAAA record) for the NTP server FQDN, FortiGate NTP shows that the IPv6 server is unresolved -- unreachable, which is not true.

938396

The following intrusion was observed: in the alert mail refers to another field in the anomaly log.

940814

Administrators without read permissions for the threat weight feature cannot see the event log menu.

945287

Cloud logging settings are not retained when the FortiGate language setting is Japanese.

949001

The quarantine-log enable setting changed to disable after restoring a backup configuration.

950768

When a GUI login fails due to exceed_limit, logged in successfully appears in the system event log.

952509

The UUID is used instead of the external resource name in the Threat feed updated system event log.

953667

Override setting under multi-VDOM mode may cause the FortiGate to stop sending logs to FortiAnalyzer or syslog after switching to non-VDOM mode.

961244

Icons in logs evaluations and policies are no longer displayed.

965247

FortiGate syslog format in reliable transport mode is not compliant with RFC 6587.

967100

When FortiAnalyzer Cloud is chosen as log location, archived data cannot be downloaded for intrusion prevention.

970412

Virus/Botnet AV log for machine learning detection hyperlink returns Object Moved Permanently.

Proxy

Bug ID

Description

790426

An error case occurs in WAD while redirecting the web filter HTTPS sessions.

806556

Unexpected behavior in WAD when the ALPN is set to http2 in the ssl-ssh-profile.

845361

A rare error condition occurred in WAD caused by compounded SMB2 requests.

919781

Unexpected behavior in WAD when there are multiple LDAP servers configured on the FortiGate.

938502

Original source IP is not preserved for transparent proxy rule after upgrading.

940149

Inadvertent traffic disruption caused by WAD when it receives an HTTP2 data frame payload on a dead stream.

943998

Unble to access website ( https://ec***.qu***.com/me***) when using a proxy with DPI.

947359

The newly implemented one-way server will set its port to null when closing.

947814

Too many redirects on TWPP after the second KRB keytab is configured.

954104

An error case occurs in WAD when WAD gets the external authenticated users from other daemons.

955006

SNI check is not working when set to inspect all ports.

958464

Unexpected behavior in WAD when building a debug URL.

971489

When cloud-communication is disabled, WAD still connects to productapi.fortinet.com.

974307

An error condition occurs in WAD while coping a file directory.

REST API

Bug ID

Description

944723

The /firewall/vip API does not recognize custom SSL cipher suites.

948356

An error condition occurs in HTTPSD when a REST API request is sent with invalid parameters.

951384

API responses for PBR provides incorrect value if address groups are used in PBR.

951411

Inconsistent handling of web filter profile actions in API transactions.

Routing

Bug ID

Description

820407

Auto-link fails if the FortiGate device initiating the FGFM connection is using an interface with a VRF not set to the default, 0.

848270

Reply traffic from the DNS proxy (DNS database) is choosing the wrong interface.

894795

MP-BGP EVPN source address shows 127.0.0.1, while the loopback interface is with a different address.

897918

When the local traffic is using SD-WAN and the reply is coming on a different interface, the reply is ignored.

906896

Make OSPFv3 update the translator role and translated Type-5 LSA when the ASBR table is updated.

926525

Routing information changed log is being generated from secondary in an HA cluster.

928152

FortiGate generates two OSPF stub entries for the same prefix after upgrading from 6.4 to 7.0.

932092

API call returns recursive next-hop for the gateway address.

934273

Support GR helper mode (peer) for BGP.

935370

SD-WAN performance SLA tcp-connect probes clash with user sessions.

935886

SD-WAN packet duplication feature in force mode suddenly stops duplicating and starts to duplicate again once the FortiGate is rebooted.

938500

Status of OSPF adjacency is Loading on spokes while Full on the hub side.

944351

When using the policy match tool, the Incoming Interface dropdown does not list SD-WAN member interfaces.

946783

Unable to set OSPF interface IP in the GUI.

949623

DNS over TCP does not work when interface-select-method is set to sdwan in the DNS setting, and the corresponding SD-WAN rule is restricted to the TCP protocol only.

951397

Inconsistent GUI output with unusual characters showing up in the SD-WAN rule list settings and the edit SD-WAN rule page.

952543

Reply TCP traffic for inbound local session uses a different egress interface than the originating traffic

952908

Locally originated type 5 and 7 LSAs' forward address value is incorrect.

953744

Connected VLAN routes are getting removed after an HA failover.

954100

Packet loss status in SD-WAN health check occur after an HA failover.

957049

If the router community-list type is expanded and changed to standard, this causes a community-list error.

957627

Learned BGP through routes are not withdrawn on the spoke after the EBGP neighborship is down between the hub and third party device.

963561

When establishing an IPsec tunnel between FortiGate peers using OSPF to exchange routes, the FortiGate sends a stub LSA with a 32-bit netmask.

964182

IPsec traffic with vpn-id-ipip is egressing with the wrong VRF when offloading is enabled.

965752

After HA monitored interface fails over, SD-WAN intermittently does not follow route-map-preferable.

Security Fabric

Bug ID

Description

902344

When there are over 30 downstream FortiGates in the Security Fabric, the root FortiGate's GUI may experience slowness when loading the Fabric Management page, preventing firmware upgrades using the GUI.

907819

Advanced GCP connector does not resolve if one element does not exist.

908489

When one of the downstream FortiGate VM's license is invalid, the root FortiGate will be automatically logged out from accessing the Firmware & Registration page.

920391

Non-management VDOM is not allowed to set a source-ip for config system external-resource.

932935

External connector to VMware 8.0 with verify certificate enabled will fail.

938980

HTTP 400 errors observed using SDN connector to query AKS clusters if local administrator is disabled.

947634

Security Fabric widget shows the serial number instead of the hostname for a secondary FortiGate in HA.

950624

Renaming conflicted Fabric objects on the root FortiGate does not synchronize the changed Fabric objects to the downstream FortiGate.

958396

The number of log IDs under one automation trigger is limited to 16.

975393

Security Fabric messages change after upgrading.

SSL VPN

Bug ID

Description

879329

Destination address of SSL VPN firewall policy may be lost after upgrading when dstaddr is set to all and at least one authentication rule has a portal with split tunneling enabled.

923518

When SSL VPN web mode is disabled, SAML external browser login requests should be blocked.

930275

Firewall policy is not allowing the all destination address with a split-tunneling portal.

933985

FortiGate as SSL VPN client does not work on NP6 and NP6XLite devices.

941676

Japanese key input does not work correctly during RDP in SSL VPN web mode.

947210

Multiple instances of *** code requested backtrace *** for SSL VPN daemon observed during a graceful upgrade (on FG-6000F).

950157

SSL VPN connected/disconnected endpoint event log can be in the wrong sequence.

952860

During a handshake when FortiClient sends a larger-than-MTU hello message, the packet is fragmented by IP layer and dropped by the FortiGate.

957406

OS checklist for SSL VPN in FortiOS does not include macOS Sonoma 14.

958430

If the password renew template is modified with a non-default password renew policy, FortiClient cannot read the HTML page correctly, and returns the error, Server may not be reachable.

Switch Controller

Bug ID

Description

703374

Long DAC-type cable is added to default media type on 10G port on FG-100F.

816790

Console printed DSL related error messages when disconnecting the managed FortiSwitch and connecting to the FortiGate again.

818116

When changing the FortiSwitch FortiLink port status, the configuration is not applied to the FortiSwitch.

904834

FortiGate and FortiManager have different definitions for the value of poe-detection-type on S108EF platform.

911232

The security rating shows an incorrect warning for unregistered FortiSwitches on the Managed FortiSwitches page.

Workaround: navigate to the Diagnostics & Tools pane of the FortiSwitch to see the correct registration status.

931694

Enhance FortiLink event logs for FortiGate-FortiSwitch event log translation.

941673

FortiSwitch event log displays serial number under name when CAPWAP is up or down.

945779

FortiGate CPU VM increases due to the FortiLink process.

949377

NAC policy cannot match the MAC address with a specific VLAN. The NAC policy needs to be deleted and re-createed for it to work again.

953918

FortiGate nac_segment is not showing assigned dynamic VLAN on FortiSwitch ports.

961997

Unable to get interface descriptions for the FortiLink ports by using OID 1.3.6.1.2.1.2.2.1.2.

System

Bug ID

Description

656983

MIB OID fgSysLowMemUsage returns value for devices where it is not applicable.

699379

Host protection engine (HPE) enchantments should be applied to NP6XLite platforms.

713951

Not all ports are coming up after an LAG bounce on 8 × 10 GB lag with ASR 9K. Affected platforms: FG-3960E and FG-3980E.

859393

SNMP poll for fgExplicitProxyRequests returns 0.

860460

On a redundant interface, traffic may drop with some NPU-offload enabled policies when the interface is not initialized properly.

861962

When configuring an 802.3ad aggregate interface with a 1 Gbps speed, the port's LED is off and traffic cannot pass through. Affected platforms: 110xE, 220xE, 330xE, 340xE, and 360xE.

893143

SFP interfaces that are set to 1000auto are not negotiating on the secondary device.

899279

NP7 did not offload jumbo packet, but get NPU INFO: offload=9/9 in the console output.

900663

Refactor the time zone feature to use the IANA time zone database.

900791

The X1 port is always up with FCLF8522P2BTLFTN transceiver.

907657

FortiGate does not perform a disk scan automatically when autorun-log-fsck is enabled.

908831

Unable to set upstream interface without setting the delegated IAID first for IPv6 interface under delegated mode.

909225

ISP traffic is failing with the LAG interfaces on upstream switches.

910651

On FG-600F, all members are up but the LACP status is showing as down after upgrading.

910700

Ports are flapping and down on the FortiGate 3980E.

910829

Degraded traffic bandwidth for download passing from 10G to 1G interfaces.

912092

FortiGate does not send ARP probe for UDP NP-offloaded sessions.

913355

GUI and CLI time mismatch for Central America (Mexico) time zone.

915585

Optimize memory usage, which causes the SLAB memory to increase, in kernel 4.19.

916493

Fail detection function does not work properly on X1 and X2 10G ports.

919901

For FIPS-CC mode, the strict check for basic constraints should be removed for end entity certificates.

922458

Administrator with read-only access to management permissions cannot perform a configuration backup in the GUI.

923473

Sometimes, the configuration cannot be backed up to an FTP server.

924654

MAC flapping on switch when UDP packets passthrough VWP multiple times with ASIC offload.

925647

Memory usage issue caused by repetitive log messages. Affected platforms: FG-100xF.

926546

ICMP and UDP traffic over GRE is not offloaded on NP7 platforms.

926817

Review the temperature sensor for the SoC4 system.

929904

When L3 or L4 hashing algorithm is used, traffic is not forwarded over the same aggregate member after being offloaded by NP7.

930329

LTE modem is missing after upgrading to 7.4.

931299

When the URL filter requests the FortiGuard (FGD) rating server address using DNS, it will try to get both A (IPv4) and AAAA (IPv6) records.

931604

The FortiGate checksum changes and the FortiManager Backup Mode device status becomes out-of-sync.

934115

Administrator can no longer view or edit the VPN settings in the GUI with system:none permissions.

937500

FortiOS does not accept an installation script from FortiManager when creating an extender-profile with login-password-change is set to yes.

937982

High CPU usage might be observed on entry-level FortiGates if the cache size reaches 10% of the system memory.

938174

ARP issue with VXLAN over IPsec and Soft Switch.

938539

The cmdbsvr process is stuck, and is not pushing configurations made in the GUI or CLI.

939013

SNMP walk of the entire MIB fails when the configuration has split-port and a large number of interfaces.

939110

DHCP server on LAN interface is lost after rebooting or restoring the configuration file.

939411

Multiple spawns of hotplug process consuming high CPU resources.

939935

High CPU usage caused by DHCP packets.

939947

FG-1100E SFP interface of port 23 and 24 with transceiver status is down after upgrading.

940504

Loading of the Toss Bank application is delayed or gets stuck on iPhones with hyperscale CGNAT (NAT64).

940752

FortiGate does not allow tagged VLAN 0 packets.

942502

Unexpected behavior occurred in the kernel when creating EMAC VLAN interfaces based on an aggregate interface with the new kernel 4.1.9.

942893

When DHCP IP reservation is edited from the DHCP dashboard widget, the changes are not retained.

943026

Changes to per-IP shaper settings are not reflected on offloaded sessions in NP7 platforms.

943090

Buffer and description queue limitation of Marvell switch port will cause a performance limitation.

943615

When cmdbsvr receives a request to update the version number, it also receives a copy of the query, but this copy is not freed.

943948

FortiGate as L2TP client is not working with Cisco ASR as L2TP server.

945426

FortiGate ports are not in a configured state after the connected switch reboots.

946413

Temperature sensor value missing for FG-180xF, FG-420xF, and FG-440xF platforms.

946714

Unexpected reboot caused by a rare error condition for FG-VM.

947127

Kernel TCP sessions do no timeout after receiving a legitimate RST and the system goes into conserve mode.

947240

FortiGate is not able to resolve ARPs of few hosts due to their ARP replies not reaching the primary FPM.

948448

A super_admin administrator is unable to log in after restoring the VDOM configuration on the admin VDOM and rebooting the FortiGate.

948460

Enabling NP7 offloading is causing packet drops when using a shaping profile.

949481

The tx_collision_err counter in the FortiOS CLI keeps increasing on both 10G SFP+ X1 and X2 interfaces.

949975

SNMP value for OID 1.3.6.1.4.1.12356.101.12.2.2.1.5 returns the wrong value.

950010

Alarm observed for high PECI temperature despite less CPU activity.

952279

The TCP handshake is interrupted when any of the UTM profiles are enabled.

954439

SNMP does not respond if a VRF is set on the interface.

955021

When signal 11 is sent to httpsd process using diagnose sys kill 11 <PID>, httpsd does not restart. The GUI displays a Service unavailable message. GUI access can be restored by rebooting the device.

955074

MSS clamping is not working on VXLAN over IPsec after upgrading.

955798

Interface LED from panel indicates the wrong status.

955998

The traffic is dropped when auto-asic-offload is enabled and passing through a VLAN associated with a 10G redundant interface.

956107

On the FortiGate 400F and 600F, the buffer and description queue limitation of the Marvell switch port causes a performance limitation.

956391

On FG-10xE, when using ports 13 to 16 as virtual switch LAN ports, auto speed is not supported.

956413

FG-1101E ports with AVAGO AFBR-5710PZ transceiver failed to come up after upgrading.

956980

Batch lastlog does not show any errors for password-policy misconfiguration.

957147

FortiGate as DNS server does not resolve domains in the local database on new VDOM.

957714

Memory usage issue occurs when multiple threads try to access a VLAN group.

957846

High CPU usage caused by DHCP packets.

958157

The GeoIP file should close appropriately after opening or using mmap to share memory.

960563

An error condition occurred in the kernel caused by a rare condition while using the GRE tunnels.

963597

Multiple configuration settings are missing after restoring the VDOM.

966761

SNMP OID 1.3.6.1.2.1.4.34.1.5 ipAddressPrefix is not fully implemented.

969230

FEC does not take effect on X5 - X8 ports when running at 25G ULL mode on FG-601F.

Upgrade

Bug ID

Description

871181

FG-3401E link is not coming up using DAC cables after upgrading.

896937

Port channel is down after upgrading the FG-1101E.

940126

Upgrading a FGT-3401E generates BPDUs, which cause the switch to disable the port.

User & Authentication

Bug ID

Description

823884

When a search is performed on a user (User & Authentication > User Definition page), the search results highlight all the groups the user belongs to.

868994

FortiGate receives FSSO user in the format of HOSTNAME$.

907169

WPA2-Enterprise SSID should support EAP-TLS authentication for PKI users that are configured with multi-factor authentication through a RADIUS server.

915998

FortiToken mobile push with ACME gives an untrusted certificate in iOS application.

932989

In some cases, the HA connection is removed and its memory is freed, but it is still read/written in the following process.

939517

On the System > Replacement Messages page, the guest user email template cannot restore to the to default value.

943087

After creating a new guest user, the administrator cannot view the user's password in plaintext in the GUI.

946116

On a FortiGate managed by FortiManager, when a guest administrator logs in with read-only permissions, the administrator can still create and edit the guest user.

947299

Global DH parameter does not modify the SSH connection key exchange.

949699

Administrator single sign-on login with SAML does not work after upgrading the firmware 7.4.1 due to the SAML entity-id field being incorrectly reset to being empty.

955939

PKI users should pass certificate-based authentication over WPA2-Enterprise SSID.

961496

CPU usage issue caused by signature update for device identification.

VM

Bug ID

Description

903037

A false positive SSL VPN login token error message is generated after a successful connection.

932085

In an Azure cluster, the NTP source-ip6 (IPv6) is synchronized while the source-ip (IPv4) is not.

950235

IPv6 multicast packets are triggering a hardware checksum failure error message on the console.

953760

FG-VM is unable to respond to the load balancer's health probe correctly.

956460

FortiGate cannot detect a log disk in some new Azure instances.

957299

On a FortiGate ARM-OCI, after adding more than one network interface card and rebooting, the interface cards are not kept in order.

957886

GCP OS log in integration issues occur in FortiGate deployment.

959859

FG-VM64-AZURE SDN connector does not retry requests to management.azure.com if they fail.

965668

Interfaces are brought down by azd, and traffic is disrupted until manually disabling and enabling the interfaces on the Azure VM.

968740

Unexpected behavior in awsd caused by tags with an empty value on AWS instances while adding a new AWS Fabric connector.

970201

Unexpected reboot caused by a rare error condition for FG-VM.

WAN Optimization

Bug ID

Description

954541

In WANOpt transparent mode, WAN optimization does not keep the original source address of the packets.

Web Application Firewall

Bug ID

Description

939380

User cannot set the match ALL pattern to deny traffic for the web application firewall profile in the GUI.

Web Filter

Bug ID

Description

887699

Web filter override expiry date in the GUI may be one hour off if daylight saving time (DST) is observed.

923548

Newly added local URL filter entry cannot be moved using drag-and-drop.

929110

The strict option for sni-server-cert-check is behaving the same as if it is set to enable, and logs are not generated upon SNI mismatch with the CN or SAN.

945011

URL filter IP address block is not honored by the enhanced policy lookup tool.

947676

Web filter profile setting changes the order of FortiGuard web filter categories.

WiFi Controller

Bug ID

Description

801730

The move function in the CLI does not work for mpsk-profile and mpsk-group.

891804

After initial packets, FG-101F stops forwarding wired traffic over FAP-23JF LAN tunneled with a dynamic VLAN VAP.

896104

An error condtion occured in the kernel when the FortiAP and SSID are in the same software switch.

938840

Excessive MEM POOLuse_up_cnt observed on secondary unit in an HA environment.

941691

Managed FortiSwitch detects multiple MACs using the same IP address.

944465

On the WiFi & Switch Controller > Managed FortiAPs page of a non-management VDOM, the Register button is unavailable in the Device Registration pane.

945356

FortiOS fails to get all of the configured MAC ACL entries.

946796

The eap_proxy daemon may keep reloading randomly due to failing to bind a port. This will cause an IKE and WiFi authentication failure.

949857

Captive portal appears each time after a channel change or if roaming performed (Cisco ISE with FortiGate and FortiAP).

951792

Clients connected to certain FortiAPs do not have internet access.

952889

PMKID should be removed when an Android device is disconnected by the RADIUS CoA DM request with Acct-Session-Id.

958314

AeroScout agent is not working.

967158

WPA2-Enterprise with a Windows NPS server is not working after upgrading the firmware to FortiOS 7.4.1.

973935

On the WiFi & Switch Controller > Managed FortiAPs page, there is an error when changing from a single 5G profile to a dual 5G profile on the FortiAP 831F.

ZTNA

Bug ID

Description

918279

Traffic does not match a simple ZTNA firewall policy when the external interface configured on a ZTNA server is a member of a SD-WAN zone being used in the same ZTNA firewall policy.

Common Vulnerabilities and Exposures

Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE references

943578

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-44250

952029

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-46717

956553

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2024-23112

959918

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-38545

964415

FortiOS 7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-44487

966706

FortiOS7.4.2 is no longer vulnerable to the following CVE Reference:

  • CVE-2023-48784