Fortinet white logo
Fortinet white logo

FortiOS Release Notes

Known issues

Known issues

The following issues have been identified in version 7.4.4. To inquire about a particular bug or report a bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

1028114

FortiGate cannot connect to FortiSandboxCloud when inline content block scan mode is set to default in an antivirus profile.

1031084

When FortiGate is in HA AA mode, the secondary unit does not connect to all FSA types for inline scanning.

Explicit Proxy

Bug ID

Description

1026362

Web pages do not load when persistent-cookie is disabled for session-cookie-based authentication with captive-portal.

Firewall

Bug ID

Description

959065

On the Policy & Objects > Traffic Shaping page, when deleting or creating a shaper, the counters for the other shapers are cleared.

1007566

When the FortiGate has thousands of addresses and hundreds address groups, the GUI can take a few minutes to search for a specific address inside the address group dialog.

Workaround: User can create the address group in the CLI instead by using the exact address name. User can also perform a search in the CLI using a partial match. For example:

config firewall addrgrp
    edit address_group
        set member <pattern>?
    next
end

1057080

On the Firewall Policy page, search results do not display in an expanded format.

FortiGate 6000 and 7000 platforms

Bug ID

Description

790464

After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond.

885205

IPv6 ECMP is not supported for the FortiGate 6000F and 7000E platforms. IPv6 ECMP is supported for the FortiGate 7000F platform.

911244

FortiGate 7000E IPv6 routes may not be synchronized correctly among FIMs and FPMs.

976521

On FortiGate 6000 models, high CPU usage by node process when navigating policy list with 7000 policies in a VDOM.

1006759

After an HA failover, there is no IPsec route in the kernel.

1018594

On FortiGate 7000, if gtp-mode is enabled and then disabled, after disabling gtp-enhanced mode and rebooting the device, traffic is disrupted on the FIM and cannot be recovered.

Workaround: downgrade to version 7.2.x or 7.4.3.

1026665

On the FortiGate 7000F platform with virtual clustering enabled and syslog logging configured, when running the diagnose log test command from a primary vcluster VDOM, some FPMs may not send log messages to the configured syslog servers.

1070365

FGCP HA session synchronization may stop working as expected on a FortiGate 7000F cluster managed by FortiManager. This happens if the HA configuration uses management interfaces as session synchronization interfaces by configuring the session-sync-dev option, for example:

config system ha
    set session-sync-dev 1-M1 1-M2
end

The problem occurs when FortiManager updates the configuration of the FortiGate 7000F devices in the cluster it incorrectly changes to the VDOM of the management interfaces added to the session-sync-dev command from mgmt-vdom to vsys_ha and the interfaces stop working as session sync interfaces.

You can work around the problem by re-configuring the session-sync-dev option on the FortiGate 7000F cluster (this resets the VDOM of the session sync interfaces to vsys_ha) and then retrieving the FortiGate configuration from FortiManager. This synchronizes the correct configuration to FortiManager.

GUI

Bug ID

Description

853352

When viewing entries in the slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100000 entries.

885427

On the Network > Interfaces page, the SFP port is grayed out on the faceplate diagram even though the port is working. This is purely a GUI display issue and does not affect system operation.

Workaround: View the SFP port information and status using the interface list in the CLI.

989512

On the Dashboard > Firewall User monitor widget, when the number of users in the Firewall User monitor exceeds 2000, the search bar is no longer being displayed.

HA

Bug ID

Description

1000808

FortiGate in an HA setup has an unnecessary primary unit selection when a new member joins or reboots one member in the VC cluster when the VC has more than 2 units.

Hyperscale

Bug ID

Description

817562

NPD/LPMD cannot differentiate the different VRFs, and considers all VRFs as 0.

850252

Restoring a specific VDOM configuration from the GUI does not restore the complete configuration.

961328

FortiGate does not choose a random port when set to random mode.

977376

FG-4201F has a 10% performance drop during a CPS test case with DoS policy.

1024274

When Hyperscale logging is enabled with multicast log, the log is not sent to servers that are configured to receive multicast logs.

1024902

After FTP traffic passes, the npu-session stat does not display the accurate amount of actual sessions on FortiGate.

1025908

When running FGSP setup, the session count is approximately 50% less on the peer device.

IPsec VPN

Bug ID

Description

866413

Traffic over GRE tunnel over IPsec tunnel, or traffic over IPsec tunnel with GRE encapsulation is not offloaded on NP7-based units.

897871

GRE over IPsec does not work in transport mode.

944600

CPU usage issues occurred when IPsec VPN traffic was received on the VLAN interface of an NP7 vlink.

970703

FortiGate 6K and 7K models do not support IPsec VPN over vdom-link/npu-vlink.

Log & Report

Bug ID

Description

1010244

When uploading the log file to the FTP server, some parts of the log files are not included in the upload.

Proxy

Bug ID

Description

910678

CPU usage issue in WAD caused by a high number of devices being detected by the device detection feature.

1060812

When Proxy-mode inline IPS scanning is enabled, the botnet check within the IPS profile does not work as expected when the IPS profile is applied to a proxy-based inspection policy using certificate inspection.

Workaround: disable ips.settings.proxy-inline-ips in the CLI.

Routing

Bug ID

Description

903444

The diagnose ip rtcache list command is no longer supported in the FortiOS 4.19 kernel.

1023878

Intermittent SD-WAN SLA fails on all links at the same time with no actual packet loss.

Security Fabric

Bug ID

Description

948322

After deauthorizing a downstream FortiGate from the System > Firmware & Registration page, the page may appear to be stuck to loading.

Workaround: perform a full page refresh to allow the page to load again.

1011833

FortiGate experiences a CPU usage issue in the node process when there multiple administrator sessions running simultaneously on the GUI in a Security Fabric with multiple downstream devices. This may result in slow loading times for multiple GUI pages.

Workaround: Disconnect the other concurrent administrator sessions to avoid overloading node process.

1021684

In some cases, the Security Fabric topology does not load properly and displays a Failed to load Topology Results error.

1057862

FortiGate models with 2GB memory that manage many extension devices (FortiSwitches and FortiAPs) may enter conserve mode due to the GUI process taking up more and more memory over time.

Workaround: Avoid loading Security Fabric widget, Security Rating, and Topology pages.

SSL VPN

Bug ID

Description

1024837

OneLogin SAML does not work with SSL VPN after upgrading to version 7.0.15 or 7.4.3.

System

Bug ID

Description

912383

FGR-70F and FGR-70F-3G4G failed to perform regular reboot process (using execute reboot command) with an SD card inserted.

956697

On NP7 platforms, the FortiGate maybe reboot twice when upgrading to 7.4.2 or restoring a configuration after a factory reset or burn image. This issue does not impact FortiOS functionality.

983467

FortiGate 60F and 61F models may experience a memory usage issue during a FortiGuard update due to the ips-helper process. This can cause the FortiGate to go into conserve mode if there is not enough free memory.

Workaround: User can disable CP acceleration to reduce the memory usage.

config ips global
    set cp-accel-mode none
end

986926

On the FortiGate 90xG models, the ULL interfaces for x5 - x8 are down after being set to 25G speed.

1015698

On FortiGate 601F models, the X5 - X8 interfaces with 25G SFP28 DAC are down after upgrading to version 7.4.4 or later.

1020921

When configuring an SNMP trusted host that matches the management Admin trusted host subnet, the GUI may give an incorrect warning that the current SNMP trusted host does not match. This is purely a GUI display issue and does not impact the actual SNMP traffic.

Workaround: If the trusted host is enabled on all administrative access, make sure the SNMP host IP is included in at least one of these trusted IP/subnets.

1021542

FortiGate reboots twice after a factory reset when gtp-enchanced-mode is enabled.

1021903

After an interface role change, the updated role does not show in the le-switch member list.

1025870

On FortiGate Rugged FGR70F-3G4G models, wan1 and wan2 port mode changes to static after a factory reset.

1029351

The OPC VM does not boot up when in native mode.

1034322

FortiGates using a SOC4 platform with a virtual switch configured may continuously reboot when upgrading due to an interruption in the kernel.

1041457

The kernel 4.19 cannot concurrently reassemble IPv4 fragments for a source IP with more than 64 destination IP addresses.

1041669

FortiGate does not upgrade if private-data-encryption is enabled and the device is not rebooted.

Workaround: Reboot FortiGate after enabling private-data-encryption.

1057131

A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate.

1058397

On FortiGate 900 models, when the baudrate is configured, the changes are not applied and is set to 9600.

Upgrade

Bug ID

Description

955835

When auto-upgrade is disabled, scheduled upgrades on FortiGate are not automatically canceled. To cancel any scheduled upgrades, exec federated-upgrade cancel must be done manually.

1027462

When restoring an FortiGate, the 7.4.1 config file with deprecated Inline CASB entries displays errors messages and causes the confsyncd to not function as expected.

1031574

During a graceful upgrade, the confsync daemon and updated daemon encounter a memory usage issue, causing a race condition.

1055486

On the Firmware and Registration page, when performing a Fabric Upgrade using the GUI for the whole Fabric topology that includes managed FortiAPs and FortiSwitches, the root FortiGate may use an incorrect recommended image for FortiAP and FortiSwitch due to a parsing issue.

User & Authentication

Bug ID

Description

667150

When a remote LDAP user with Two-factor Authentication enabled and Authentication type FortiToken tries to access the internet through firewall authentication, the web page does not receive the FortiToken notification or proceed to authenticate the user.

Workaround: click the Continue button on the authentication page after approving the FortiToken on the mobile device.

884462

NTLM authentication does not work with Chrome.

972391

RADIUS group is not properly displayed as used.

VM

Bug ID

Description

978021

VNI length is zero in the GENEVE header when in FTP passive mode.

1082197

The FortiGate-VM on VMware ESXi equipped with an Intel E810-XXV network interface card (NIC) using SFP28 transceivers at 25G speed is unable to pass VLAN traffic when DPDK is enabled.

WiFi Controller

Bug ID

Description

814541

When there are a large number of managed FortiAP devices (over 500) and a large number of WiFi clients (over 5000), the Managed FortiAPs page and FortiAP Status widget can take a long time to load. This issue does not impact FortiAP operation.

869978

On the FortiGate 200F, CAPWAP tunnel traffic over tunnel SSID is dropped when offloading is enabled.

903922

Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation.

949682

Intermittent traffic disruption observed in cw_acd caused by a rare error condition.

964757

Clients randomly unable to connect to 802.1X SSID when FortiAP has a DTLS policy enabled.

972093

RADIUS accounting data usage is different between the bridge and tunnel VAP.

1050915

When upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware.

Workaround: Upgrade the FortiAPs in smaller batches of up to 20 devices to avoid performance impacts.

ZTNA

Bug ID

Description

819987

SMB drive mapping made through a ZTNA access proxy is inaccessible after rebooting.

1018303

ZTNA does not allow tcp-forwarding SSH traffic to pass through.

1020084

Health check on the ZTNA realserver does not work as expected if a blackhole route is added to the realserver address.

Known issues

Known issues

The following issues have been identified in version 7.4.4. To inquire about a particular bug or report a bug, please contact Customer Service & Support.

Anti Virus

Bug ID

Description

1028114

FortiGate cannot connect to FortiSandboxCloud when inline content block scan mode is set to default in an antivirus profile.

1031084

When FortiGate is in HA AA mode, the secondary unit does not connect to all FSA types for inline scanning.

Explicit Proxy

Bug ID

Description

1026362

Web pages do not load when persistent-cookie is disabled for session-cookie-based authentication with captive-portal.

Firewall

Bug ID

Description

959065

On the Policy & Objects > Traffic Shaping page, when deleting or creating a shaper, the counters for the other shapers are cleared.

1007566

When the FortiGate has thousands of addresses and hundreds address groups, the GUI can take a few minutes to search for a specific address inside the address group dialog.

Workaround: User can create the address group in the CLI instead by using the exact address name. User can also perform a search in the CLI using a partial match. For example:

config firewall addrgrp
    edit address_group
        set member <pattern>?
    next
end

1057080

On the Firewall Policy page, search results do not display in an expanded format.

FortiGate 6000 and 7000 platforms

Bug ID

Description

790464

After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond.

885205

IPv6 ECMP is not supported for the FortiGate 6000F and 7000E platforms. IPv6 ECMP is supported for the FortiGate 7000F platform.

911244

FortiGate 7000E IPv6 routes may not be synchronized correctly among FIMs and FPMs.

976521

On FortiGate 6000 models, high CPU usage by node process when navigating policy list with 7000 policies in a VDOM.

1006759

After an HA failover, there is no IPsec route in the kernel.

1018594

On FortiGate 7000, if gtp-mode is enabled and then disabled, after disabling gtp-enhanced mode and rebooting the device, traffic is disrupted on the FIM and cannot be recovered.

Workaround: downgrade to version 7.2.x or 7.4.3.

1026665

On the FortiGate 7000F platform with virtual clustering enabled and syslog logging configured, when running the diagnose log test command from a primary vcluster VDOM, some FPMs may not send log messages to the configured syslog servers.

1070365

FGCP HA session synchronization may stop working as expected on a FortiGate 7000F cluster managed by FortiManager. This happens if the HA configuration uses management interfaces as session synchronization interfaces by configuring the session-sync-dev option, for example:

config system ha
    set session-sync-dev 1-M1 1-M2
end

The problem occurs when FortiManager updates the configuration of the FortiGate 7000F devices in the cluster it incorrectly changes to the VDOM of the management interfaces added to the session-sync-dev command from mgmt-vdom to vsys_ha and the interfaces stop working as session sync interfaces.

You can work around the problem by re-configuring the session-sync-dev option on the FortiGate 7000F cluster (this resets the VDOM of the session sync interfaces to vsys_ha) and then retrieving the FortiGate configuration from FortiManager. This synchronizes the correct configuration to FortiManager.

GUI

Bug ID

Description

853352

When viewing entries in the slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100000 entries.

885427

On the Network > Interfaces page, the SFP port is grayed out on the faceplate diagram even though the port is working. This is purely a GUI display issue and does not affect system operation.

Workaround: View the SFP port information and status using the interface list in the CLI.

989512

On the Dashboard > Firewall User monitor widget, when the number of users in the Firewall User monitor exceeds 2000, the search bar is no longer being displayed.

HA

Bug ID

Description

1000808

FortiGate in an HA setup has an unnecessary primary unit selection when a new member joins or reboots one member in the VC cluster when the VC has more than 2 units.

Hyperscale

Bug ID

Description

817562

NPD/LPMD cannot differentiate the different VRFs, and considers all VRFs as 0.

850252

Restoring a specific VDOM configuration from the GUI does not restore the complete configuration.

961328

FortiGate does not choose a random port when set to random mode.

977376

FG-4201F has a 10% performance drop during a CPS test case with DoS policy.

1024274

When Hyperscale logging is enabled with multicast log, the log is not sent to servers that are configured to receive multicast logs.

1024902

After FTP traffic passes, the npu-session stat does not display the accurate amount of actual sessions on FortiGate.

1025908

When running FGSP setup, the session count is approximately 50% less on the peer device.

IPsec VPN

Bug ID

Description

866413

Traffic over GRE tunnel over IPsec tunnel, or traffic over IPsec tunnel with GRE encapsulation is not offloaded on NP7-based units.

897871

GRE over IPsec does not work in transport mode.

944600

CPU usage issues occurred when IPsec VPN traffic was received on the VLAN interface of an NP7 vlink.

970703

FortiGate 6K and 7K models do not support IPsec VPN over vdom-link/npu-vlink.

Log & Report

Bug ID

Description

1010244

When uploading the log file to the FTP server, some parts of the log files are not included in the upload.

Proxy

Bug ID

Description

910678

CPU usage issue in WAD caused by a high number of devices being detected by the device detection feature.

1060812

When Proxy-mode inline IPS scanning is enabled, the botnet check within the IPS profile does not work as expected when the IPS profile is applied to a proxy-based inspection policy using certificate inspection.

Workaround: disable ips.settings.proxy-inline-ips in the CLI.

Routing

Bug ID

Description

903444

The diagnose ip rtcache list command is no longer supported in the FortiOS 4.19 kernel.

1023878

Intermittent SD-WAN SLA fails on all links at the same time with no actual packet loss.

Security Fabric

Bug ID

Description

948322

After deauthorizing a downstream FortiGate from the System > Firmware & Registration page, the page may appear to be stuck to loading.

Workaround: perform a full page refresh to allow the page to load again.

1011833

FortiGate experiences a CPU usage issue in the node process when there multiple administrator sessions running simultaneously on the GUI in a Security Fabric with multiple downstream devices. This may result in slow loading times for multiple GUI pages.

Workaround: Disconnect the other concurrent administrator sessions to avoid overloading node process.

1021684

In some cases, the Security Fabric topology does not load properly and displays a Failed to load Topology Results error.

1057862

FortiGate models with 2GB memory that manage many extension devices (FortiSwitches and FortiAPs) may enter conserve mode due to the GUI process taking up more and more memory over time.

Workaround: Avoid loading Security Fabric widget, Security Rating, and Topology pages.

SSL VPN

Bug ID

Description

1024837

OneLogin SAML does not work with SSL VPN after upgrading to version 7.0.15 or 7.4.3.

System

Bug ID

Description

912383

FGR-70F and FGR-70F-3G4G failed to perform regular reboot process (using execute reboot command) with an SD card inserted.

956697

On NP7 platforms, the FortiGate maybe reboot twice when upgrading to 7.4.2 or restoring a configuration after a factory reset or burn image. This issue does not impact FortiOS functionality.

983467

FortiGate 60F and 61F models may experience a memory usage issue during a FortiGuard update due to the ips-helper process. This can cause the FortiGate to go into conserve mode if there is not enough free memory.

Workaround: User can disable CP acceleration to reduce the memory usage.

config ips global
    set cp-accel-mode none
end

986926

On the FortiGate 90xG models, the ULL interfaces for x5 - x8 are down after being set to 25G speed.

1015698

On FortiGate 601F models, the X5 - X8 interfaces with 25G SFP28 DAC are down after upgrading to version 7.4.4 or later.

1020921

When configuring an SNMP trusted host that matches the management Admin trusted host subnet, the GUI may give an incorrect warning that the current SNMP trusted host does not match. This is purely a GUI display issue and does not impact the actual SNMP traffic.

Workaround: If the trusted host is enabled on all administrative access, make sure the SNMP host IP is included in at least one of these trusted IP/subnets.

1021542

FortiGate reboots twice after a factory reset when gtp-enchanced-mode is enabled.

1021903

After an interface role change, the updated role does not show in the le-switch member list.

1025870

On FortiGate Rugged FGR70F-3G4G models, wan1 and wan2 port mode changes to static after a factory reset.

1029351

The OPC VM does not boot up when in native mode.

1034322

FortiGates using a SOC4 platform with a virtual switch configured may continuously reboot when upgrading due to an interruption in the kernel.

1041457

The kernel 4.19 cannot concurrently reassemble IPv4 fragments for a source IP with more than 64 destination IP addresses.

1041669

FortiGate does not upgrade if private-data-encryption is enabled and the device is not rebooted.

Workaround: Reboot FortiGate after enabling private-data-encryption.

1057131

A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate.

1058397

On FortiGate 900 models, when the baudrate is configured, the changes are not applied and is set to 9600.

Upgrade

Bug ID

Description

955835

When auto-upgrade is disabled, scheduled upgrades on FortiGate are not automatically canceled. To cancel any scheduled upgrades, exec federated-upgrade cancel must be done manually.

1027462

When restoring an FortiGate, the 7.4.1 config file with deprecated Inline CASB entries displays errors messages and causes the confsyncd to not function as expected.

1031574

During a graceful upgrade, the confsync daemon and updated daemon encounter a memory usage issue, causing a race condition.

1055486

On the Firmware and Registration page, when performing a Fabric Upgrade using the GUI for the whole Fabric topology that includes managed FortiAPs and FortiSwitches, the root FortiGate may use an incorrect recommended image for FortiAP and FortiSwitch due to a parsing issue.

User & Authentication

Bug ID

Description

667150

When a remote LDAP user with Two-factor Authentication enabled and Authentication type FortiToken tries to access the internet through firewall authentication, the web page does not receive the FortiToken notification or proceed to authenticate the user.

Workaround: click the Continue button on the authentication page after approving the FortiToken on the mobile device.

884462

NTLM authentication does not work with Chrome.

972391

RADIUS group is not properly displayed as used.

VM

Bug ID

Description

978021

VNI length is zero in the GENEVE header when in FTP passive mode.

1082197

The FortiGate-VM on VMware ESXi equipped with an Intel E810-XXV network interface card (NIC) using SFP28 transceivers at 25G speed is unable to pass VLAN traffic when DPDK is enabled.

WiFi Controller

Bug ID

Description

814541

When there are a large number of managed FortiAP devices (over 500) and a large number of WiFi clients (over 5000), the Managed FortiAPs page and FortiAP Status widget can take a long time to load. This issue does not impact FortiAP operation.

869978

On the FortiGate 200F, CAPWAP tunnel traffic over tunnel SSID is dropped when offloading is enabled.

903922

Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation.

949682

Intermittent traffic disruption observed in cw_acd caused by a rare error condition.

964757

Clients randomly unable to connect to 802.1X SSID when FortiAP has a DTLS policy enabled.

972093

RADIUS accounting data usage is different between the bridge and tunnel VAP.

1050915

When upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware.

Workaround: Upgrade the FortiAPs in smaller batches of up to 20 devices to avoid performance impacts.

ZTNA

Bug ID

Description

819987

SMB drive mapping made through a ZTNA access proxy is inaccessible after rebooting.

1018303

ZTNA does not allow tcp-forwarding SSH traffic to pass through.

1020084

Health check on the ZTNA realserver does not work as expected if a blackhole route is added to the realserver address.