Fortinet white logo
Fortinet white logo

Known issues

Known issues

The following issues have been identified in FortiEndpoint 26.1.b. For inquiries about a particular bug, contact Customer Service & Support.

Endpoint control

Bug ID

Description

1252180 Endpoints on subnet 172.17.0.0/16 cannot register telemetry with FortiEndpoint.

Deployment and installers

Bug ID

Description

1247941 FortiEndpoint deployment to update FortiClient feature sets for the same FortiClient version fails unless the initial deployment was done using the FortiEndpoint-generated FortiClient EXE installer or the MSI file (rather than the MST file).

Endpoint control

Bug ID

Description

1213829

FortiClient auth-period registry is not reset to 0 after User Verification Period is disabled in FortiEndpoint.

Endpoint management

Bug ID

Description

1127493

FortiEndpoint displays inaccurate user information for endpoints running on the Windows Server operating system.

1211682

Unable to delete ADDS authentication server when it is not reachable.

Endpoint policy and profile

Bug ID

Description

1089889 Chromebooks intermittently receive error Failed to retrieve user profile from FortiEndpoint.

1219573

FortiEndpoint fails to apply Entra ID policies to Entra ID-joined devices that use an alias domains instead of the primary UPN domain.

GUI

Bug ID

Description

1186739

Back button in endpoint vulnerability details page returns to Dashboard instead of previous page.

EDR

Bug ID

Description

1050795

No message to explain why the user cannot set the UI to prevention mode when all policies are in simulation mode.

733592

Number of destinations under communication control is limited to 100 IP addresses.

733598

Safari 11.1 on macOS malfunctions when viewing events.

757253

EDR Connect cannot be used to run commands that are user-interactive.

765648

On Linux, threat hunting exclusions only work in kernel space mode, not in user space mode.

771630

Device internal and external IP is missing from Threat Hunting events of Linux devices.

777707

Linux Collector content file is large and uploads slowly to the Central Manager.

807930

Application Control search only works by exact match

809060

EDR Connect session may be disconnected due to inactivity of the EDR Console, even though the Connect session is active.

833152

Raw data IDs appearing in the Collector tray and Incidents view may differ.

837038

Application Control cannot remove multiple tags in one action.

842110

In some network configurations, a rare issue might cause Collectors to be detected as IoT devices.

885691

Threat Hunting: The tooltip displayed when hovering might prevent access to adding a filter.

889410

When switching to Threat Hunting from Incidents > Automated Analysis, queries malfunction when more than one device is involved

Workaround: Filter by the same Collectors directly from Threat Hunting, which brings results.

890339

"Query Parsing Failed" in Threat hunting pops up multiple times after invalid query.

891668

Free text query in threat hunting, when using invalid text, no error message is displayed. The query returns empty results.

892109

Unable to filter by empty registry names in facets in Threat Hunting.

894384

In Threat Hunting, clicking Retrieve Target File for "File Rename" events retrieves the old file name instead of the renamed one.

899736

In a threat hunting search, if you search for "Target.Registry.Path:" AND "Registry.Path" the results will be empty

Workaround: Use either "Target.Registry.Path" or "Registry.Path" in a specific search.

909654

IoT filter by ״First connection=Today״ brings empty results.

914348

Investigation View: Incident response data is inaccurate.

914792

Unarchiving all events in large environments might cause the EDR console to malfunction.

Workaround: Filter events before unarchiving to reduce unarchive size.

915698

In the Investigation View, the message is wrong in the Block address on firewall window when you click Firewall Block.

935001, 938847, 1048422, 1064821, 1066657

System event page default filtering is required.

939481

In some cases, the communication control feature does not work due to unforeseen technical issues.

954553, 969494

Some event log entries in threat hunting display logged event values in incorrect logged event fields.

988884

Incorrect threat hunting profile order of Fortinet pre-defined application profiles.

994324

Improve "file permission change" text in Threat Hunting Exclusions display.

994334

Added Threat Hunting columns are inaccessible unless the columns are narrowed.

994348

Log does not contain concrete helpful errors for API.

994359

Threat Hunting Collection Profiles - rule name and icon not aligned.

1001334

Security events fully covered by an exception retains the full coverage indication icon even after new uncovered raw data items come in.

1003257, 1025493

Missing field in Checkpoint firewall integration.

1014489, 1035403

Failure to delete aggregations in big bulks over 20K.

1039714, 1041152

Confusing error message when uploading a wrong formatted file in Application Control Manager > Upload Applications.

1040055, 1041151

Ad hoc network discovery tooltip has a mistake in Japanese.

1040805, 1048215

Incident view count changes with sort.

1052668, 1060356

Syslog is created with no audit.

1062894, 1063406

No validation for SecurityExclusionRepoEntity.path in exclusions configuration.

1079894, 1081873

Exceptions report can be slow.

Known issues

Known issues

The following issues have been identified in FortiEndpoint 26.1.b. For inquiries about a particular bug, contact Customer Service & Support.

Endpoint control

Bug ID

Description

1252180 Endpoints on subnet 172.17.0.0/16 cannot register telemetry with FortiEndpoint.

Deployment and installers

Bug ID

Description

1247941 FortiEndpoint deployment to update FortiClient feature sets for the same FortiClient version fails unless the initial deployment was done using the FortiEndpoint-generated FortiClient EXE installer or the MSI file (rather than the MST file).

Endpoint control

Bug ID

Description

1213829

FortiClient auth-period registry is not reset to 0 after User Verification Period is disabled in FortiEndpoint.

Endpoint management

Bug ID

Description

1127493

FortiEndpoint displays inaccurate user information for endpoints running on the Windows Server operating system.

1211682

Unable to delete ADDS authentication server when it is not reachable.

Endpoint policy and profile

Bug ID

Description

1089889 Chromebooks intermittently receive error Failed to retrieve user profile from FortiEndpoint.

1219573

FortiEndpoint fails to apply Entra ID policies to Entra ID-joined devices that use an alias domains instead of the primary UPN domain.

GUI

Bug ID

Description

1186739

Back button in endpoint vulnerability details page returns to Dashboard instead of previous page.

EDR

Bug ID

Description

1050795

No message to explain why the user cannot set the UI to prevention mode when all policies are in simulation mode.

733592

Number of destinations under communication control is limited to 100 IP addresses.

733598

Safari 11.1 on macOS malfunctions when viewing events.

757253

EDR Connect cannot be used to run commands that are user-interactive.

765648

On Linux, threat hunting exclusions only work in kernel space mode, not in user space mode.

771630

Device internal and external IP is missing from Threat Hunting events of Linux devices.

777707

Linux Collector content file is large and uploads slowly to the Central Manager.

807930

Application Control search only works by exact match

809060

EDR Connect session may be disconnected due to inactivity of the EDR Console, even though the Connect session is active.

833152

Raw data IDs appearing in the Collector tray and Incidents view may differ.

837038

Application Control cannot remove multiple tags in one action.

842110

In some network configurations, a rare issue might cause Collectors to be detected as IoT devices.

885691

Threat Hunting: The tooltip displayed when hovering might prevent access to adding a filter.

889410

When switching to Threat Hunting from Incidents > Automated Analysis, queries malfunction when more than one device is involved

Workaround: Filter by the same Collectors directly from Threat Hunting, which brings results.

890339

"Query Parsing Failed" in Threat hunting pops up multiple times after invalid query.

891668

Free text query in threat hunting, when using invalid text, no error message is displayed. The query returns empty results.

892109

Unable to filter by empty registry names in facets in Threat Hunting.

894384

In Threat Hunting, clicking Retrieve Target File for "File Rename" events retrieves the old file name instead of the renamed one.

899736

In a threat hunting search, if you search for "Target.Registry.Path:" AND "Registry.Path" the results will be empty

Workaround: Use either "Target.Registry.Path" or "Registry.Path" in a specific search.

909654

IoT filter by ״First connection=Today״ brings empty results.

914348

Investigation View: Incident response data is inaccurate.

914792

Unarchiving all events in large environments might cause the EDR console to malfunction.

Workaround: Filter events before unarchiving to reduce unarchive size.

915698

In the Investigation View, the message is wrong in the Block address on firewall window when you click Firewall Block.

935001, 938847, 1048422, 1064821, 1066657

System event page default filtering is required.

939481

In some cases, the communication control feature does not work due to unforeseen technical issues.

954553, 969494

Some event log entries in threat hunting display logged event values in incorrect logged event fields.

988884

Incorrect threat hunting profile order of Fortinet pre-defined application profiles.

994324

Improve "file permission change" text in Threat Hunting Exclusions display.

994334

Added Threat Hunting columns are inaccessible unless the columns are narrowed.

994348

Log does not contain concrete helpful errors for API.

994359

Threat Hunting Collection Profiles - rule name and icon not aligned.

1001334

Security events fully covered by an exception retains the full coverage indication icon even after new uncovered raw data items come in.

1003257, 1025493

Missing field in Checkpoint firewall integration.

1014489, 1035403

Failure to delete aggregations in big bulks over 20K.

1039714, 1041152

Confusing error message when uploading a wrong formatted file in Application Control Manager > Upload Applications.

1040055, 1041151

Ad hoc network discovery tooltip has a mistake in Japanese.

1040805, 1048215

Incident view count changes with sort.

1052668, 1060356

Syslog is created with no audit.

1062894, 1063406

No validation for SecurityExclusionRepoEntity.path in exclusions configuration.

1079894, 1081873

Exceptions report can be slow.