Resolved issues
The following issues have been fixed in version 6.4.11. To inquire about a particular bug, please contact Customer Service & Support.
Explicit Proxy
Bug ID |
Description |
---|---|
803228 |
When converting an explicit proxy session to SSL redirect, traffic may be interrupted inadvertently in some situations. |
Firewall
Bug ID |
Description |
---|---|
815565 |
Unable to connect to the reserved management interface allowed by the local-in policy. |
HA
Bug ID |
Description |
---|---|
664929 |
The hatalk process crashed when creating a disabled VLAN interface in an A-P cluster. |
722703 |
ISDB is not updating; last update attempt is stuck at an older date. |
779587 |
When an authentication log on length is longer than the |
788702 |
Due to an HA port (Intel i40e) driver issue, not all SW sessions are synchronized to the secondary, so there is a difference. |
837200 |
The hasync process is stuck with high CPU usage when a failover occurs, there is a large number of logons, and the authentication logon length is longer than hasync packet length. |
845572 |
FGCP HA cannot synchronize because of a |
Hyperscale
Bug ID |
Description |
---|---|
763966 |
FGSP synchronizes NP sessions of all VDOMs when syncvd is only set for hyperscale VDOM. |
771857 |
Firewall virtual IP (VIP) features that are not supported by hyperscale firewall policies are no longer visible from the CLI or GUI when configuring firewall VIPs in a hyperscale firewall VDOM. |
782674 |
A few tasks are hung on issuing |
795853 |
VDOM ID and IP addresses in the IPL table are incorrect after disabling EIF/EIM. |
807476 |
After packets go through host interface TX/RX queues, some packet buffers can still hold references to a VDOM when the host queues are idle. This causes a VDOM delete error with |
810025 |
Using EIF to support hairpinning does not work for NAT64 sessions. |
810366 |
Unrelated background traffic gets impacted when changing a policy where a hyperscale license is used. |
839958 |
|
IPsec VPN
Bug ID |
Description |
---|---|
707086 |
Packets with DF bit set that does not need fragmentation are dropped with the message, |
757696 |
Implementing the |
763205 |
IKE crashes after HA failover when the |
828541 |
IPsec DPD packets keep getting sent while IPsec traffic passes through the tunnel (DPD mode is |
830252 |
IPsec VPN statistics are not increasing on the device. |
Proxy
Bug ID |
Description |
---|---|
796910 |
Application wad crash ( |
822271 |
Unable to access a website when deep inspection is enabled in a proxy policy. |
Routing
Bug ID |
Description |
---|---|
822659 |
Secure SD-WAN Monitor in FortiAnalyzer does not show graphs when the SLA target is not configured in SD-WAN performance SLA. |
830254 |
When changing interfaces from dense mode to sparse mode, and then back to dense mode, the interfaces did not show up under dense mode. |
SSL VPN
Bug ID |
Description |
---|---|
830824 |
Veeam Backup Enterprise website has SSL VPN access problem in web mode. |
848437 |
The sslvpn process crashes if a POST request with a body greater than 2 GB is received. |
System
Bug ID |
Description |
---|---|
622803 |
L2TP tunnel is not removed after Android client VPN disconnects. |
675558 |
SFP port with 1G copper SFP always is up. |
735492 |
Many processes are in a "D" state due to |
764954 |
FortiAnalyzer serial number automatically learned from miglogd does not send it to FortiManager through the automatic update. |
766906 |
Hardware logs sent to syslog server with an incorrect timestamp in hyperscale mode. |
800333 |
DoS offload does not work in 6.4.9 and the npd daemon keeps crashing if the |
801040 |
Session anomaly was incorrectly triggered though concurrent sessions on the FortiGate that were below the configured threshold. |
809030 |
Traffic loss occurs when running SNAT PBA pool in a hyperscale VDOM. The NP7 hardware module PRP got stuck, which caused the NP7 to hang. |
810583 |
Running |
818452 |
The |
826440 |
Null pointer causing kernel crash on FWF-61F. |
User & Authentication
Bug ID |
Description |
---|---|
822684 |
When multiple FSSO CA connections are configured at the same time, only the last configured FSSO connection comes up. |
VM
Bug ID |
Description |
---|---|
761736 |
FG-AWS failover does not trigger the elastic IP or route move during an upgrade if the HA connection between the active and passive node breaks for a few seconds and reconnects. |
WiFi Controller
Bug ID |
Description |
---|---|
827902 |
CAPWAP data traffic over redundant IPsec tunnels failing when the primary IPsec tunnel is down (failover to backup tunnel). |
831932 |
The cw_acd process crashes several times after the system enters conserve mode. |
Common Vulnerabilities and Exposures
Visit https://fortiguard.com/psirt for more information.
Bug ID |
CVE references |
---|---|
850842 |
FortiOS 6.4.11 is no longer vulnerable to the following CVE Reference:
|
853448 |
FortiOS 6.4.11 is no longer vulnerable to the following CVE Reference:
|