Known issues
The following issues have been identified in version 7.4.4. To inquire about a particular bug or report a bug, please contact Customer Service & Support.
Anti Virus
Bug ID |
Description |
---|---|
1028114 |
FortiGate cannot connect to FortiSandboxCloud when |
1031084 |
When FortiGate is in HA AA mode, the secondary unit does not connect to all FSA types for inline scanning. |
Explicit Proxy
Bug ID |
Description |
---|---|
1026362 |
Web pages do not load when |
Firewall
Bug ID |
Description |
---|---|
959065 |
On the Policy & Objects > Traffic Shaping page, when deleting or creating a shaper, the counters for the other shapers are cleared. |
1007566 |
When the FortiGate has thousands of addresses and hundreds address groups, the GUI can take a few minutes to search for a specific address inside the address group dialog. Workaround: User can create the address group in the CLI instead by using the exact address name. User can also perform a search in the CLI using a partial match. For example: config firewall addrgrp edit address_group set member <pattern>? next end |
1057080 |
On the Firewall Policy page, search results do not display in an expanded format. |
FortiGate 6000 and 7000 platforms
Bug ID |
Description |
---|---|
790464 |
After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond. |
885205 |
IPv6 ECMP is not supported for the FortiGate 6000F and 7000E platforms. IPv6 ECMP is supported for the FortiGate 7000F platform. |
911244 |
FortiGate 7000E IPv6 routes may not be synchronized correctly among FIMs and FPMs. |
976521 |
On FortiGate 6000 models, high CPU usage by node process when navigating policy list with 7000 policies in a VDOM. |
1006759 |
After an HA failover, there is no IPsec route in the kernel. |
1018594 |
On FortiGate 7000, if Workaround: downgrade to version 7.2.x or 7.4.3. |
1026665 |
On the FortiGate 7000F platform with virtual clustering enabled and syslog logging configured, when running the |
1070365 |
FGCP HA session synchronization may stop working as expected on a FortiGate 7000F cluster managed by FortiManager. This happens if the HA configuration uses management interfaces as session synchronization interfaces by configuring the config system ha set session-sync-dev 1-M1 1-M2 end The problem occurs when FortiManager updates the configuration of the FortiGate 7000F devices in the cluster it incorrectly changes to the VDOM of the management interfaces added to the You can work around the problem by re-configuring the |
GUI
Bug ID |
Description |
---|---|
853352 |
When viewing entries in the slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100000 entries. |
885427 |
On the Network > Interfaces page, the SFP port is grayed out on the faceplate diagram even though the port is working. This is purely a GUI display issue and does not affect system operation. Workaround: View the SFP port information and status using the interface list in the CLI. |
989512 |
On the Dashboard > Firewall User monitor widget, when the number of users in the Firewall User monitor exceeds 2000, the search bar is no longer being displayed. |
HA
Bug ID |
Description |
---|---|
1000808 |
FortiGate in an HA setup has an unnecessary primary unit selection when a new member joins or reboots one member in the VC cluster when the VC has more than 2 units. |
Hyperscale
Bug ID |
Description |
---|---|
817562 |
NPD/LPMD cannot differentiate the different VRFs, and considers all VRFs as 0. |
850252 |
Restoring a specific VDOM configuration from the GUI does not restore the complete configuration. |
961328 |
FortiGate does not choose a random port when set to random mode. |
977376 |
FG-4201F has a 10% performance drop during a CPS test case with DoS policy. |
1024274 |
When Hyperscale logging is enabled with multicast log, the log is not sent to servers that are configured to receive multicast logs. |
1024902 |
After FTP traffic passes, the |
1025908 |
When running FGSP setup, the session count is approximately 50% less on the peer device. |
IPsec VPN
Bug ID |
Description |
---|---|
866413 |
Traffic over GRE tunnel over IPsec tunnel, or traffic over IPsec tunnel with GRE encapsulation is not offloaded on NP7-based units. |
897871 |
GRE over IPsec does not work in transport mode. |
944600 |
CPU usage issues occurred when IPsec VPN traffic was received on the VLAN interface of an NP7 vlink. |
970703 |
FortiGate 6K and 7K models do not support IPsec VPN over vdom-link/npu-vlink. |
Log & Report
Bug ID |
Description |
---|---|
1010244 |
When uploading the log file to the FTP server, some parts of the log files are not included in the upload. |
Proxy
Bug ID |
Description |
---|---|
910678 |
CPU usage issue in WAD caused by a high number of devices being detected by the device detection feature. |
1060812 |
When Proxy-mode inline IPS scanning is enabled, the botnet check within the IPS profile does not work as expected when the IPS profile is applied to a proxy-based inspection policy using certificate inspection. Workaround: disable |
Routing
Bug ID |
Description |
---|---|
903444 |
The |
1023878 |
Intermittent SD-WAN SLA fails on all links at the same time with no actual packet loss. |
Security Fabric
Bug ID |
Description |
---|---|
948322 |
After deauthorizing a downstream FortiGate from the System > Firmware & Registration page, the page may appear to be stuck to loading. Workaround: perform a full page refresh to allow the page to load again. |
1011833 |
FortiGate experiences a CPU usage issue in the node process when there multiple administrator sessions running simultaneously on the GUI in a Security Fabric with multiple downstream devices. This may result in slow loading times for multiple GUI pages. Workaround: Disconnect the other concurrent administrator sessions to avoid overloading node process. |
1021684 |
In some cases, the Security Fabric topology does not load properly and displays a Failed to load Topology Results error. |
1057862 |
FortiGate models with 2GB memory that manage many extension devices (FortiSwitches and FortiAPs) may enter conserve mode due to the GUI process taking up more and more memory over time. Workaround: Avoid loading Security Fabric widget, Security Rating, and Topology pages. |
SSL VPN
Bug ID |
Description |
---|---|
1024837 |
OneLogin SAML does not work with SSL VPN after upgrading to version 7.0.15 or 7.4.3. |
System
Bug ID |
Description |
---|---|
912383 |
FGR-70F and FGR-70F-3G4G failed to perform regular reboot process (using |
956697 |
On NP7 platforms, the FortiGate maybe reboot twice when upgrading to 7.4.2 or restoring a configuration after a factory reset or burn image. This issue does not impact FortiOS functionality. |
983467 |
FortiGate 60F and 61F models may experience a memory usage issue during a FortiGuard update due to the ips-helper process. This can cause the FortiGate to go into conserve mode if there is not enough free memory. Workaround: User can disable CP acceleration to reduce the memory usage. config ips global set cp-accel-mode none end |
986926 |
On the FortiGate 90xG models, the ULL interfaces for x5 - x8 are down after being set to 25G speed. |
1015698 |
On FortiGate 601F models, the X5 - X8 interfaces with 25G SFP28 DAC are down after upgrading to version 7.4.4 or later. |
1020921 |
When configuring an SNMP trusted host that matches the management Admin trusted host subnet, the GUI may give an incorrect warning that the current SNMP trusted host does not match. This is purely a GUI display issue and does not impact the actual SNMP traffic. Workaround: If the trusted host is enabled on all administrative access, make sure the SNMP host IP is included in at least one of these trusted IP/subnets. |
1021542 |
FortiGate reboots twice after a factory reset when |
1021903 |
After an interface role change, the updated role does not show in the le-switch member list. |
1025870 |
On FortiGate Rugged FGR70F-3G4G models, |
1029351 |
The OPC VM does not boot up when in native mode. |
1034322 |
FortiGates using a SOC4 platform with a virtual switch configured may continuously reboot when upgrading due to an interruption in the kernel. |
1041457 |
The kernel 4.19 cannot concurrently reassemble IPv4 fragments for a source IP with more than 64 destination IP addresses. |
1041669 |
FortiGate does not upgrade if Workaround: Reboot FortiGate after enabling |
1057131 |
A FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode. Users may need to reboot the FortiGate. |
1058397 |
On FortiGate 900 models, when the baudrate is configured, the changes are not applied and is set to 9600. |
Upgrade
Bug ID |
Description |
---|---|
955835 |
When |
1027462 |
When restoring an FortiGate, the 7.4.1 config file with deprecated Inline CASB entries displays errors messages and causes the confsyncd to not function as expected. |
1031574 |
During a graceful upgrade, the confsync daemon and updated daemon encounter a memory usage issue, causing a race condition. |
1055486 |
On the Firmware and Registration page, when performing a Fabric Upgrade using the GUI for the whole Fabric topology that includes managed FortiAPs and FortiSwitches, the root FortiGate may use an incorrect recommended image for FortiAP and FortiSwitch due to a parsing issue. |
User & Authentication
Bug ID |
Description |
---|---|
667150 |
When a remote LDAP user with Two-factor Authentication enabled and Authentication type FortiToken tries to access the internet through firewall authentication, the web page does not receive the FortiToken notification or proceed to authenticate the user. Workaround: click the Continue button on the authentication page after approving the FortiToken on the mobile device. |
884462 |
NTLM authentication does not work with Chrome. |
972391 |
RADIUS group is not properly displayed as used. |
VM
Bug ID |
Description |
---|---|
978021 |
VNI length is zero in the GENEVE header when in FTP passive mode. |
1082197 |
The FortiGate-VM on VMware ESXi equipped with an Intel E810-XXV network interface card (NIC) using SFP28 transceivers at 25G speed is unable to pass VLAN traffic when DPDK is enabled. |
WiFi Controller
Bug ID |
Description |
---|---|
814541 |
When there are a large number of managed FortiAP devices (over 500) and a large number of WiFi clients (over 5000), the Managed FortiAPs page and FortiAP Status widget can take a long time to load. This issue does not impact FortiAP operation. |
869978 |
On the FortiGate 200F, CAPWAP tunnel traffic over tunnel SSID is dropped when offloading is enabled. |
903922 |
Physical and logical topology is slow to load when there are a lot of managed FortiAP devices (over 50). This issue does not impact FortiAP management and operation. |
949682 |
Intermittent traffic disruption observed in cw_acd caused by a rare error condition. |
964757 |
Clients randomly unable to connect to 802.1X SSID when FortiAP has a DTLS policy enabled. |
972093 |
RADIUS accounting data usage is different between the bridge and tunnel VAP. |
1050915 |
When upgrading more than 30 managed FortiAPs at the same time using the Managed FortiAP page, the GUI may become slow and unresponsive when selecting the firmware. Workaround: Upgrade the FortiAPs in smaller batches of up to 20 devices to avoid performance impacts. |
ZTNA
Bug ID |
Description |
---|---|
819987 |
SMB drive mapping made through a ZTNA access proxy is inaccessible after rebooting. |
1018303 |
ZTNA does not allow tcp-forwarding SSH traffic to pass through. |
1020084 |
Health check on the ZTNA realserver does not work as expected if a blackhole route is added to the realserver address. |