Fortinet black logo

Known issues

Known issues

The following issues have been identified in FortiClient (Windows) 7.0.10. For inquiries about a particular bug or to report a bug, contact Customer Service & Support.

Application Firewall

Bug ID Description
717628 Application Firewall causes issues with Motorola RMS high availability client.

814391

FortiClient Cloud application signatures block allowlisted applications.

823292

FortiClient cannot connect to JVC wireless display.

827788

Threat ID is 0 on Firewall Events.

842534

After upgrade to FortiClient (Windows) 7.0.7, Application Firewall blocks internal webpage.

844997 FortiClient sees several packet losses on different internal resources after connecting telemetry.

853808

FortiClient (Windows) blocks Veeam with messages related to Remote.CMD.Shell and VeeamAgent.exe.

860062

Application Firewall slows down opening Microsoft Active Directory (AD) Users and Computers application.

884911

FortiClient detects IntelliJ IDEA Community Edition 2021.2.2 as Java.Debug.Wire.Protocol.Insecure.Configuration.

891789

Application Firewall blocks CREO Management tool software.

902866

Application Firewall does not block Google Drive.

907089

FortiClient continues blocking MS.Windows.HTTP.Protocol.Stack.CVE-2022-21907.Code.Execution by application firewall.

936039

WhatsApp_Web_File.Download and WhatsApp_Web_File.Upload App signatures do not work in Application Firewall.

Endpoint control

Bug ID Description
780130 FortiClient (Windows) fails or takes long time to get updated Endpoint Control profile from EMS.

804552

FortiClient shows all feature tabs without registering to EMS after upgrade.

815037 After EMS administrator selects Mark All Endpoints As Uninstalled, FortiClient (Windows) connected with verified user changes to unverified user.

816751

Administrator cannot restore a quarantined file through EMS quarantine management if FortiClient (Windows) registered as onboarding user.

817061

Redeploying from another EMS server causes FortiClient (Windows) to not reconnect to EMS automatically.

819552

After upgrading FortiClient with EMS local onboarding user with LDAP, FortiClient (Windows) prompts for registration authentication.

820483

EMS device control does not block camera.

821024

FortiClient fails to send username to EMS, causing EMS to report it as different users.

833717

EMS shows endpoints as offline, while they show their own status as online.

834162

LDAP query for AD group check does not execute.

841764 EMS does not show third party features in endpoint information.
855851 EMS remembered list shows many FQDN duplicates.
868230 Connection expiring due to FortiClient Connect license exceeded error occurs.
880167 FortiClient (Windows) cannot register with EMS due to selecting wrong interface to connect to EMS.

900189

Connection media on-fabric detection rule type does not work properly with Windows 10.

Endpoint management

Bug ID Description
760816 Group assignment rules based on IP addresses do not work when using split tunnel.

904348

FortiClient (Windows) and EMS detect encryption status as not enabled when only one hard disk has encryption (Bitlocker) enabled.

GUI

Bug ID Description
767998 Free VPN-only client includes Action for invalid EMS certificate in settings.

811742

FortiClient (Windows) does not hide software update options when registered to EMS (regression).

826895

FortiClient ignores the listing order of the configured VPN connections in the GUI and tray.

827394

FortiClient does not report profile change update in Notifications.

934351 FortiSASE VPN gets stuck at wrong VPN connection status until FortiClient console restarts from sleep wakeup or network interruption.

Workaround: Restart FortiClient console.

Install and upgrade

Bug ID

Description

749331 Windows Security setting in Windows displays FortiClient is snoozed when FortiEDR is installed.

769639

FortiDeviceGuard is not installed on Windows Server 2022.

783690

There is no reboot prompt after user log in.

820672 ZTNA driver FortiTransCtrl.sys fails to start on Windows Server 2016.

867982

Blank certificate pops up when upgrading.

955066

Upgrade from 7.0.8 to 7.0.9 requires multiple restarts.

956682

Unattended installation of FortiClient 7.0.9 does not reboot PC when there is no user logged in.

Zero Trust tags

Bug ID Description
782394 ZTNA user identity tags do not work.

819120

Zero trust tag rule for AD group does not work when registering FortiClient to EMS with onboarding user.

956947 Zero Trust tags disappear from FortiClient (Windows) avatar if a different user logs in to Windows machine.

Configuration

Bug ID

Description

730415

FortiClient backs up configuration that is missing locally configured ZTNA connection rules.

User and authentication

Bug ID

Description

765184 RADIUS authentication failover between two servers for high availability does not work well.

Performance

Bug ID

Description

749348 Performance issues after upgrade.

Zero Trust Telemetry

Bug ID

Description

683542 FortiClient (Windows) fails to register to EMS if registration key contains a special character: " !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~".

792703

FortiClient (Windows) cannot connect to FortiClient Cloud.

Malware Protection and Sandbox

Bug ID

Description

760073 FortiDeviceGuard could not be installed on Windows Server through installer.
793926 FortiShield blocks spoolsv.exe on Citrix virtual machine servers.

828862

FortiClient does not allow virtual CD-ROM device.

831560

GUI shows ransomware quarantined files after restoration via EMS.

844988 FortiClient (Windows) does not block USB drive if attempting to copy contents even if WPD/USB is set to be blocked in profile.
857041 Windows 10 security center popup shows both FortiClient and Windows Defender are turned off.
863802 EMS and FortiClient (Windows) cannot detect SentinelOne even if they have product on operating system level.
872970 Bubble notifications do not appear when inserting USB drive in endpoint machine.

876925

Antiexploit protection blocks Microsoft Signing application in Chrome.

882904

FortiClient (Windows) does not include XML option to decide if FortiClient (Windows) should be snoozed or allowed to run side by side with FortiEDR.

903371

FortiClient causes an unhandled exception on third party process when AV components are installed but disabled.
915300 FortiClient (Windows) detects file included in exception as malware.

916958

FortiClient (Windows) cannot detect a virus-infected file.

919007

On-deman scan for mapped drives is not possible.

923470

Removable media access modifies registry key NoDriveTypeAutoRun (sets value 44).

925850

RTP stop downloading file on Windows 11.

926155

If Malware Protection is enabled, OS hangs up during export of .MOV file to Telestream switch.

926383

When RTP is enabled, logon takes two to three minutes.

926906

Printing from a web browser fails if web downloads are enabled under Sandbox.

956891

FortiClient does not download EMS allowlist file and prevents file restore from Quarantine Management.

Remote Access

Bug ID

Description

679023

If FortiClient is registered to EMS, both EMS and FortiOS should control save password, always up, and autoconnect.

727695

FortiClient (Windows) on Windows 10 fails to block SSL VPN when it has a prohibit host tag applied.

728240

SSL VPN negate split tunnel IPv6 address does not work.

728244

Negate split tunnel IPv4 address does not work for dual stack mode using IPv6 access.

730756

For SSL VPN dual stack, GUI only shows IPv4 address.

736353 Multigateway failover does not go back to check previous gateways when failing over to see if they are up.
743106 IPsec VPN XAuth does not work with ECDSA certificates.

744597

SSL VPN disconnects and returns hostcheck timeout after 15 to 20 minutes of connection.

755105

When VPN is up, changes for IP properties-> Register this connection's IP to DNS are not restored after VM reboot from power off.

755482

Free VPN-only client does not show token box on rekey and GUI open.

758424

Certificate works for IPsec VPN tunnel if put it in current user store but fails to work if in local machine.

762986

FortiClient (Windows) does not use second FortiGate to connect to resilient tunnel from FortiTray if it cannot reach first remote gateway.

764863 Dialup IPsec VPN over IPv6 drops packets on inbound direction once FortiClient (Windows) establishes tunnel.

772108

When no_dns_registration=1,Register This Connection's Address in DNS of NW IP properties is not selected after VPN is up.

773920 Endpoint switches network connection after IPsec VPN connection and causes VPN to disconnect.

775633

Automatic failover to second remote gateway does not work when using priority-based IPsec VPN resiliency tunnel.

783412 Browser traffic goes directly to ZTNA site when SSL VPN is connected.
790021 Multifactor authentication using Okta with email notification does not work.

793893

FortiClient search domains transfer incorrectly to endpoints.

794110

VPN before logon does not work with Okta multifactor authentication and enforcing acceptance of the disclaimer message.

795334

Always up feature does not work as expected when trying to connect to VPN from tray.

800453 SSL VPN with certificate authentication fails to connect on OS start.
800934 DH group settings should be read-only for tunnel pushed by EMS.

801875

FortiClient cannot connect to VPN when there are two gateways listed using SAML.

814488

SSL VPN with <on_os_start_connect> enabled does not work when the machine is put into sleep mode and changes networks.

815528

If allow_local_lan=0 and per-application split tunnel with exclude mode and full tunnel are configured, FortiClient (Windows) should block local RDP/HTTPS traffic.

818155

FortiClient (Windows) sends SAML response to a different IP address than the request it received from.

821879

VPN autoconnect does not work with IKEv2 IPsec VPN and user certificates.

824298

SSL VPN with certificates cannot connect to VPN on Elitebook 850 G5/Elitebook 850 G3 laptops.

835042

After upgrading FortiClient (Windows), OpenVPN connection fails while FortiClient (Windows) VPN runs with application-based split tunnel enabled.

838030

Citrix application shows blank pages on SSL VPN tunnel.

841144 Users disconnect from VPN after screen locks on endpoint.
841970 GUI gets stuck while connecting SAML SSL VPN with Azure AD and Duo multifactor authentication.
843122 Daily error (-6005) occurs with SAML SSL VPN.
850494 VPN fails to connect at 98% to hotspot/Wi-Fi when dual stack is enabled.
851093 IPv6 DNS requests do not work.
851600 FortiClient fails to connect to SSL VPN with FQDN resolving to multiple IP addresses when it could not reach resolved IP address.
852507 When connecting to SSL VPN using FortiSSLVPNclient.exe, the VPN adapter IP address is incorrect.
854237 FortiClient fails to connect at 98% when connecting to hot spot/Wi-Fi when dual stack is enabled on gateway device.
858806 IKE/IPsec VPN sends the same token code multiple times within a second.
861231 VPN tunnel with on_os_start enabled does not start on Windows Server.
863138 TapiSrv does not run.
869362 FortiClient (Windows) has issues with multiple reconnections without reauthentication.
869477 When it fails a self test, FortiClient (Windows) does not enter FIPS error mode and shut down completely.

869577

FortiClient only adds FQDN route every second or third disconnect/reconnect.

869862

FortiSSLVPNclient.exe does not correctly use predfined VPN profiles for corporate or personal VPNs.

870087

Windows feature DeadGatewayDetection does bypass default route via VPN.

871346

When using SAML login with built-in browser, FortiAuthenticator, saved password and autoconnect selected, FortiClient (Windows) cannot remember username and password.

871374

SAML login does not display user warning when opening multiple connection with Limit Users to One SSL-VPN Connection at a Time.

874208

FortiClient cannot dial up SSL VPN tunnel with ECDSA certificate.

874310 Using closest gateway based on ping speed and TCP round trip for SSL VPN resilience does not work if using different port.

877640

If FortiClient is registered to EMS, option to connect to IPsec VPN on OS start fails to work.

878070

FortiClient (Windows) intermittently grays out SAML button after device wakes from sleep.

882408 Failed to renew password when user expires message displays when logging in to Windows.

887631

Using closest gateway based on TCP round trip time for IPsec VPN resilience does not work if ping is disabled for first gateway.

888602

Autoconnect does not work when based on ping speed/TCP round trip to choose closest FortiGate if FortiClient cannot reach first gateway.

888974 SAML login first connection fails when using external browser for authentication with multifactor authentication.
890217 <on_os_start_connect> does not work when rebooting machine by clicking Restart in menu.

890352

IPsec VPN for FIPS-enabled FortiClient fails to work when EMS-pushed IPsec/SSL VPN tunnel contains application split tunnel settings.

891164

FortiClient does not handle EMS-pushed IPsec VPN configuration of encryption/authentication/DH group that FortiClient FIPS does not support.

891202

Autoconnect only when off-fabric does not work properly with user account and MFA with FortiToken for xAuth.

893237 FortiClient (Windows) gives no chance to reinput password during autoconnect after identity provider password change.

904871

IPsec VPN takes long time to connect and shows Connect button when connection is in progress.

905651

FortiSASE VPN always up has frequent issues when shifting endpoints from one public network to another.

909244 SSL VPN split DNS name resolution stops working.

914018

SSL VPN SAML login fails to work if using YubiKey for MFA.

916240

User from India cannot connect to SSL VPN using SAML authentication but can connect when located in the U.S.

916581

Static DNS entry is registered when on-fabric.

919754

SSL VPN with SAML authentication fails when using an invalid SSL certificate.

920302

Attempt to access local network resource via SMB fails after FortiClient (Windows) establishes IPsec VPN tunnel in some conditions.

920383

FortiClient enables Turn off smart multi-homed name resolution on the Windows machine after successful connection.

921636

SSL_accept fails due to 1:bad signature error.

922463

Always up does not work for IPsec VPN if using DHCP over IPsec.

922535

FortiClient crashes while using IPsec VPN IKEv1.

922941

Connecting to SSL VPN with FQDN resolved to both IPv4 and IPv6 as remote gateway gets stuck at 98%.

924736

IPsec VPN connection fails due to blank password with Duo multifactor authentication.

924823

SSL VPN connection has issues with SAML Azure.

929876

Attack surface reduction rule in Microsoft 365 Defender audits FortiSSLVPNdaemon.exe.

930740

FortiClient (Windows) cannot set up SSL VPN if password contains Polish characters " ", "", " ".

945888

With VPN before logon, there is no one-time password (OTP) token request prompt if using FortiToken Mobile with FortiAuthenticator for OTP.

947381

With <prefer_sslvpn_dns>=0, when SSL VPN is up, FortiClient adds dns-suffix to all network interfaces.

950787

Domain filter cannot block access for specific server FQDN.

956472

FortiClient fails to resolve SRV records with split DNS.

956998

SSL VPN SAML fails to log in with error AADSTS50011.

Vulnerability Scan

Bug ID

Description

741241 FortiClient (Windows) finds vulnerabilities for uninstalled software.

795393

EMS does not remove vulnerability events after successful patch.

849485 FortiClient wrongly detects AnyDesk vulnerabilities CVE-2021-44426 and CVE-2021-44425.

869253

FortiClient detects vulnerability when the required KB is installed.

908266

FortiClient fails to detect vulnerabilities possibly due to FCM skipping certain VIDs when scanning.

955762

FortiClient (Windows) does not detect known vulnerable software.

Logs

Bug ID

Description

820067 FortiClient forwards logs despite being completely disabled.

849043

SSL VPN add/close action does not show on FortiGate Endpoint Event section.

876810 FortiClient does not indicate VPN user in logs when the connection succeeds.

Web Filter and plugin

Bug ID Description

776089

FortiClient (Windows) does not block malicious sites when Web Filter is disabled.

789017

Web Filter is enabled on FortiSASE profile on EMS.

812207

Blocked web client shows dropped connection message instead of URL blocked message.

836906 After FortiClient install, extended uptime results in audio cracking.
871325 Web Filter breaks DW Spectrum.
904840 When a user is doing device recovery in iTunes, error 3500 displays.
909060 User cannot update information on internal portal with Web Filter active.

Avatar and social network login

Bug ID

Description

878050 Avatar does not update on FortiGate dashboards and FortiGate cannot show updated information.

Multitenancy

Bug ID

Description

780308 EMS automatically migrates endpoints to default site.

ZTNA connection rules

Bug ID

Description

735494

Windows 7 does not support TCP forwarding feature.

814953

Using an external browser for SSH ZTNA requires restarting FortiClient on Windows 11.

830135 Hosts file becomes empty after disconnecting/reconnecting to EMS multiple times and with fresh install of FortiClient (Windows).

831943

ZTNA client certificate is not removed from user certificate store after FortiClient uninstall.

836246

Going from off-Fabric to on-Fabric does not stop the ZTNA service and keeps endpoint from connecting.

839589

ZTNA TCP forwarding does not work for Goanywhere application.

919832

ZTNA stops working after days with No ZTNA client certificate was provided error.

949507

ZTNA has multiple client certificates in certificate store.

FSSOMA

Bug ID

Description

841316

Some SSOMA versions do not present client certificate to FortiAuthenticator.

909844 User FSSO sessions drop earlier than expected.

Onboarding

Bug ID

Description

811976

FortiClient (Windows) may prioritize using user information from authentication user registered to EMS.

819989

FortiClient (Windows) does not show login prompt when installed with installer using LDAP/local verification.

License

Bug ID

Description

830899 FortiClient connected to EMS loses license.
874676 EMS tags endpoint with existing ZTNA host tags for vulnerability and AV after EMS administrator updates EMS license from Endpoint Protection Platform to Remote Access.

Endpoint policy and profile

Bug ID

Description

889517 EMS fails to assign the correct endpoint policy and shows FortiClient as out-of-sync despite the client syncing.

Other

Bug ID

Description

780651 FortiClient (Windows) does not update signatures on expected schedule.
834389 FortiClient (Windows) has incompatibility with Fuji Nexim software.
919017 FortiClient (Windows) changes installer checksum/hash for Baramundi management agent.
937175 Windows Firewall shows alert regarding FortiClient.exe.

Known issues

The following issues have been identified in FortiClient (Windows) 7.0.10. For inquiries about a particular bug or to report a bug, contact Customer Service & Support.

Application Firewall

Bug ID Description
717628 Application Firewall causes issues with Motorola RMS high availability client.

814391

FortiClient Cloud application signatures block allowlisted applications.

823292

FortiClient cannot connect to JVC wireless display.

827788

Threat ID is 0 on Firewall Events.

842534

After upgrade to FortiClient (Windows) 7.0.7, Application Firewall blocks internal webpage.

844997 FortiClient sees several packet losses on different internal resources after connecting telemetry.

853808

FortiClient (Windows) blocks Veeam with messages related to Remote.CMD.Shell and VeeamAgent.exe.

860062

Application Firewall slows down opening Microsoft Active Directory (AD) Users and Computers application.

884911

FortiClient detects IntelliJ IDEA Community Edition 2021.2.2 as Java.Debug.Wire.Protocol.Insecure.Configuration.

891789

Application Firewall blocks CREO Management tool software.

902866

Application Firewall does not block Google Drive.

907089

FortiClient continues blocking MS.Windows.HTTP.Protocol.Stack.CVE-2022-21907.Code.Execution by application firewall.

936039

WhatsApp_Web_File.Download and WhatsApp_Web_File.Upload App signatures do not work in Application Firewall.

Endpoint control

Bug ID Description
780130 FortiClient (Windows) fails or takes long time to get updated Endpoint Control profile from EMS.

804552

FortiClient shows all feature tabs without registering to EMS after upgrade.

815037 After EMS administrator selects Mark All Endpoints As Uninstalled, FortiClient (Windows) connected with verified user changes to unverified user.

816751

Administrator cannot restore a quarantined file through EMS quarantine management if FortiClient (Windows) registered as onboarding user.

817061

Redeploying from another EMS server causes FortiClient (Windows) to not reconnect to EMS automatically.

819552

After upgrading FortiClient with EMS local onboarding user with LDAP, FortiClient (Windows) prompts for registration authentication.

820483

EMS device control does not block camera.

821024

FortiClient fails to send username to EMS, causing EMS to report it as different users.

833717

EMS shows endpoints as offline, while they show their own status as online.

834162

LDAP query for AD group check does not execute.

841764 EMS does not show third party features in endpoint information.
855851 EMS remembered list shows many FQDN duplicates.
868230 Connection expiring due to FortiClient Connect license exceeded error occurs.
880167 FortiClient (Windows) cannot register with EMS due to selecting wrong interface to connect to EMS.

900189

Connection media on-fabric detection rule type does not work properly with Windows 10.

Endpoint management

Bug ID Description
760816 Group assignment rules based on IP addresses do not work when using split tunnel.

904348

FortiClient (Windows) and EMS detect encryption status as not enabled when only one hard disk has encryption (Bitlocker) enabled.

GUI

Bug ID Description
767998 Free VPN-only client includes Action for invalid EMS certificate in settings.

811742

FortiClient (Windows) does not hide software update options when registered to EMS (regression).

826895

FortiClient ignores the listing order of the configured VPN connections in the GUI and tray.

827394

FortiClient does not report profile change update in Notifications.

934351 FortiSASE VPN gets stuck at wrong VPN connection status until FortiClient console restarts from sleep wakeup or network interruption.

Workaround: Restart FortiClient console.

Install and upgrade

Bug ID

Description

749331 Windows Security setting in Windows displays FortiClient is snoozed when FortiEDR is installed.

769639

FortiDeviceGuard is not installed on Windows Server 2022.

783690

There is no reboot prompt after user log in.

820672 ZTNA driver FortiTransCtrl.sys fails to start on Windows Server 2016.

867982

Blank certificate pops up when upgrading.

955066

Upgrade from 7.0.8 to 7.0.9 requires multiple restarts.

956682

Unattended installation of FortiClient 7.0.9 does not reboot PC when there is no user logged in.

Zero Trust tags

Bug ID Description
782394 ZTNA user identity tags do not work.

819120

Zero trust tag rule for AD group does not work when registering FortiClient to EMS with onboarding user.

956947 Zero Trust tags disappear from FortiClient (Windows) avatar if a different user logs in to Windows machine.

Configuration

Bug ID

Description

730415

FortiClient backs up configuration that is missing locally configured ZTNA connection rules.

User and authentication

Bug ID

Description

765184 RADIUS authentication failover between two servers for high availability does not work well.

Performance

Bug ID

Description

749348 Performance issues after upgrade.

Zero Trust Telemetry

Bug ID

Description

683542 FortiClient (Windows) fails to register to EMS if registration key contains a special character: " !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~".

792703

FortiClient (Windows) cannot connect to FortiClient Cloud.

Malware Protection and Sandbox

Bug ID

Description

760073 FortiDeviceGuard could not be installed on Windows Server through installer.
793926 FortiShield blocks spoolsv.exe on Citrix virtual machine servers.

828862

FortiClient does not allow virtual CD-ROM device.

831560

GUI shows ransomware quarantined files after restoration via EMS.

844988 FortiClient (Windows) does not block USB drive if attempting to copy contents even if WPD/USB is set to be blocked in profile.
857041 Windows 10 security center popup shows both FortiClient and Windows Defender are turned off.
863802 EMS and FortiClient (Windows) cannot detect SentinelOne even if they have product on operating system level.
872970 Bubble notifications do not appear when inserting USB drive in endpoint machine.

876925

Antiexploit protection blocks Microsoft Signing application in Chrome.

882904

FortiClient (Windows) does not include XML option to decide if FortiClient (Windows) should be snoozed or allowed to run side by side with FortiEDR.

903371

FortiClient causes an unhandled exception on third party process when AV components are installed but disabled.
915300 FortiClient (Windows) detects file included in exception as malware.

916958

FortiClient (Windows) cannot detect a virus-infected file.

919007

On-deman scan for mapped drives is not possible.

923470

Removable media access modifies registry key NoDriveTypeAutoRun (sets value 44).

925850

RTP stop downloading file on Windows 11.

926155

If Malware Protection is enabled, OS hangs up during export of .MOV file to Telestream switch.

926383

When RTP is enabled, logon takes two to three minutes.

926906

Printing from a web browser fails if web downloads are enabled under Sandbox.

956891

FortiClient does not download EMS allowlist file and prevents file restore from Quarantine Management.

Remote Access

Bug ID

Description

679023

If FortiClient is registered to EMS, both EMS and FortiOS should control save password, always up, and autoconnect.

727695

FortiClient (Windows) on Windows 10 fails to block SSL VPN when it has a prohibit host tag applied.

728240

SSL VPN negate split tunnel IPv6 address does not work.

728244

Negate split tunnel IPv4 address does not work for dual stack mode using IPv6 access.

730756

For SSL VPN dual stack, GUI only shows IPv4 address.

736353 Multigateway failover does not go back to check previous gateways when failing over to see if they are up.
743106 IPsec VPN XAuth does not work with ECDSA certificates.

744597

SSL VPN disconnects and returns hostcheck timeout after 15 to 20 minutes of connection.

755105

When VPN is up, changes for IP properties-> Register this connection's IP to DNS are not restored after VM reboot from power off.

755482

Free VPN-only client does not show token box on rekey and GUI open.

758424

Certificate works for IPsec VPN tunnel if put it in current user store but fails to work if in local machine.

762986

FortiClient (Windows) does not use second FortiGate to connect to resilient tunnel from FortiTray if it cannot reach first remote gateway.

764863 Dialup IPsec VPN over IPv6 drops packets on inbound direction once FortiClient (Windows) establishes tunnel.

772108

When no_dns_registration=1,Register This Connection's Address in DNS of NW IP properties is not selected after VPN is up.

773920 Endpoint switches network connection after IPsec VPN connection and causes VPN to disconnect.

775633

Automatic failover to second remote gateway does not work when using priority-based IPsec VPN resiliency tunnel.

783412 Browser traffic goes directly to ZTNA site when SSL VPN is connected.
790021 Multifactor authentication using Okta with email notification does not work.

793893

FortiClient search domains transfer incorrectly to endpoints.

794110

VPN before logon does not work with Okta multifactor authentication and enforcing acceptance of the disclaimer message.

795334

Always up feature does not work as expected when trying to connect to VPN from tray.

800453 SSL VPN with certificate authentication fails to connect on OS start.
800934 DH group settings should be read-only for tunnel pushed by EMS.

801875

FortiClient cannot connect to VPN when there are two gateways listed using SAML.

814488

SSL VPN with <on_os_start_connect> enabled does not work when the machine is put into sleep mode and changes networks.

815528

If allow_local_lan=0 and per-application split tunnel with exclude mode and full tunnel are configured, FortiClient (Windows) should block local RDP/HTTPS traffic.

818155

FortiClient (Windows) sends SAML response to a different IP address than the request it received from.

821879

VPN autoconnect does not work with IKEv2 IPsec VPN and user certificates.

824298

SSL VPN with certificates cannot connect to VPN on Elitebook 850 G5/Elitebook 850 G3 laptops.

835042

After upgrading FortiClient (Windows), OpenVPN connection fails while FortiClient (Windows) VPN runs with application-based split tunnel enabled.

838030

Citrix application shows blank pages on SSL VPN tunnel.

841144 Users disconnect from VPN after screen locks on endpoint.
841970 GUI gets stuck while connecting SAML SSL VPN with Azure AD and Duo multifactor authentication.
843122 Daily error (-6005) occurs with SAML SSL VPN.
850494 VPN fails to connect at 98% to hotspot/Wi-Fi when dual stack is enabled.
851093 IPv6 DNS requests do not work.
851600 FortiClient fails to connect to SSL VPN with FQDN resolving to multiple IP addresses when it could not reach resolved IP address.
852507 When connecting to SSL VPN using FortiSSLVPNclient.exe, the VPN adapter IP address is incorrect.
854237 FortiClient fails to connect at 98% when connecting to hot spot/Wi-Fi when dual stack is enabled on gateway device.
858806 IKE/IPsec VPN sends the same token code multiple times within a second.
861231 VPN tunnel with on_os_start enabled does not start on Windows Server.
863138 TapiSrv does not run.
869362 FortiClient (Windows) has issues with multiple reconnections without reauthentication.
869477 When it fails a self test, FortiClient (Windows) does not enter FIPS error mode and shut down completely.

869577

FortiClient only adds FQDN route every second or third disconnect/reconnect.

869862

FortiSSLVPNclient.exe does not correctly use predfined VPN profiles for corporate or personal VPNs.

870087

Windows feature DeadGatewayDetection does bypass default route via VPN.

871346

When using SAML login with built-in browser, FortiAuthenticator, saved password and autoconnect selected, FortiClient (Windows) cannot remember username and password.

871374

SAML login does not display user warning when opening multiple connection with Limit Users to One SSL-VPN Connection at a Time.

874208

FortiClient cannot dial up SSL VPN tunnel with ECDSA certificate.

874310 Using closest gateway based on ping speed and TCP round trip for SSL VPN resilience does not work if using different port.

877640

If FortiClient is registered to EMS, option to connect to IPsec VPN on OS start fails to work.

878070

FortiClient (Windows) intermittently grays out SAML button after device wakes from sleep.

882408 Failed to renew password when user expires message displays when logging in to Windows.

887631

Using closest gateway based on TCP round trip time for IPsec VPN resilience does not work if ping is disabled for first gateway.

888602

Autoconnect does not work when based on ping speed/TCP round trip to choose closest FortiGate if FortiClient cannot reach first gateway.

888974 SAML login first connection fails when using external browser for authentication with multifactor authentication.
890217 <on_os_start_connect> does not work when rebooting machine by clicking Restart in menu.

890352

IPsec VPN for FIPS-enabled FortiClient fails to work when EMS-pushed IPsec/SSL VPN tunnel contains application split tunnel settings.

891164

FortiClient does not handle EMS-pushed IPsec VPN configuration of encryption/authentication/DH group that FortiClient FIPS does not support.

891202

Autoconnect only when off-fabric does not work properly with user account and MFA with FortiToken for xAuth.

893237 FortiClient (Windows) gives no chance to reinput password during autoconnect after identity provider password change.

904871

IPsec VPN takes long time to connect and shows Connect button when connection is in progress.

905651

FortiSASE VPN always up has frequent issues when shifting endpoints from one public network to another.

909244 SSL VPN split DNS name resolution stops working.

914018

SSL VPN SAML login fails to work if using YubiKey for MFA.

916240

User from India cannot connect to SSL VPN using SAML authentication but can connect when located in the U.S.

916581

Static DNS entry is registered when on-fabric.

919754

SSL VPN with SAML authentication fails when using an invalid SSL certificate.

920302

Attempt to access local network resource via SMB fails after FortiClient (Windows) establishes IPsec VPN tunnel in some conditions.

920383

FortiClient enables Turn off smart multi-homed name resolution on the Windows machine after successful connection.

921636

SSL_accept fails due to 1:bad signature error.

922463

Always up does not work for IPsec VPN if using DHCP over IPsec.

922535

FortiClient crashes while using IPsec VPN IKEv1.

922941

Connecting to SSL VPN with FQDN resolved to both IPv4 and IPv6 as remote gateway gets stuck at 98%.

924736

IPsec VPN connection fails due to blank password with Duo multifactor authentication.

924823

SSL VPN connection has issues with SAML Azure.

929876

Attack surface reduction rule in Microsoft 365 Defender audits FortiSSLVPNdaemon.exe.

930740

FortiClient (Windows) cannot set up SSL VPN if password contains Polish characters " ", "", " ".

945888

With VPN before logon, there is no one-time password (OTP) token request prompt if using FortiToken Mobile with FortiAuthenticator for OTP.

947381

With <prefer_sslvpn_dns>=0, when SSL VPN is up, FortiClient adds dns-suffix to all network interfaces.

950787

Domain filter cannot block access for specific server FQDN.

956472

FortiClient fails to resolve SRV records with split DNS.

956998

SSL VPN SAML fails to log in with error AADSTS50011.

Vulnerability Scan

Bug ID

Description

741241 FortiClient (Windows) finds vulnerabilities for uninstalled software.

795393

EMS does not remove vulnerability events after successful patch.

849485 FortiClient wrongly detects AnyDesk vulnerabilities CVE-2021-44426 and CVE-2021-44425.

869253

FortiClient detects vulnerability when the required KB is installed.

908266

FortiClient fails to detect vulnerabilities possibly due to FCM skipping certain VIDs when scanning.

955762

FortiClient (Windows) does not detect known vulnerable software.

Logs

Bug ID

Description

820067 FortiClient forwards logs despite being completely disabled.

849043

SSL VPN add/close action does not show on FortiGate Endpoint Event section.

876810 FortiClient does not indicate VPN user in logs when the connection succeeds.

Web Filter and plugin

Bug ID Description

776089

FortiClient (Windows) does not block malicious sites when Web Filter is disabled.

789017

Web Filter is enabled on FortiSASE profile on EMS.

812207

Blocked web client shows dropped connection message instead of URL blocked message.

836906 After FortiClient install, extended uptime results in audio cracking.
871325 Web Filter breaks DW Spectrum.
904840 When a user is doing device recovery in iTunes, error 3500 displays.
909060 User cannot update information on internal portal with Web Filter active.

Avatar and social network login

Bug ID

Description

878050 Avatar does not update on FortiGate dashboards and FortiGate cannot show updated information.

Multitenancy

Bug ID

Description

780308 EMS automatically migrates endpoints to default site.

ZTNA connection rules

Bug ID

Description

735494

Windows 7 does not support TCP forwarding feature.

814953

Using an external browser for SSH ZTNA requires restarting FortiClient on Windows 11.

830135 Hosts file becomes empty after disconnecting/reconnecting to EMS multiple times and with fresh install of FortiClient (Windows).

831943

ZTNA client certificate is not removed from user certificate store after FortiClient uninstall.

836246

Going from off-Fabric to on-Fabric does not stop the ZTNA service and keeps endpoint from connecting.

839589

ZTNA TCP forwarding does not work for Goanywhere application.

919832

ZTNA stops working after days with No ZTNA client certificate was provided error.

949507

ZTNA has multiple client certificates in certificate store.

FSSOMA

Bug ID

Description

841316

Some SSOMA versions do not present client certificate to FortiAuthenticator.

909844 User FSSO sessions drop earlier than expected.

Onboarding

Bug ID

Description

811976

FortiClient (Windows) may prioritize using user information from authentication user registered to EMS.

819989

FortiClient (Windows) does not show login prompt when installed with installer using LDAP/local verification.

License

Bug ID

Description

830899 FortiClient connected to EMS loses license.
874676 EMS tags endpoint with existing ZTNA host tags for vulnerability and AV after EMS administrator updates EMS license from Endpoint Protection Platform to Remote Access.

Endpoint policy and profile

Bug ID

Description

889517 EMS fails to assign the correct endpoint policy and shows FortiClient as out-of-sync despite the client syncing.

Other

Bug ID

Description

780651 FortiClient (Windows) does not update signatures on expected schedule.
834389 FortiClient (Windows) has incompatibility with Fuji Nexim software.
919017 FortiClient (Windows) changes installer checksum/hash for Baramundi management agent.
937175 Windows Firewall shows alert regarding FortiClient.exe.