Known issues
Known issues are organized into the following categories:
To inquire about a particular bug or report a bug, please contact Customer Service & Support.
New known issues
The following issues have been identified in version 7.6.0.
Application Control
Bug ID |
Description |
---|---|
990540 |
FortiGate does not generate traffic logs for established or denied TCP sessions that lack application data. |
1060562 |
The application control profile is missing on the GUI for FortiGate models with 2GB of memory. Workaround: Administrators can configure the application control profile using the CLI or using the GUI inline edit option on the policy list if the profile is already configured for the policy. |
DNS Filter
Bug ID |
Description |
---|---|
1058866 |
DNS translation does not work as expected when a resolved IP matches the external block list entry. |
Endpoint Control
Bug ID |
Description |
---|---|
1019658 |
On FortiGate, not all registered endpoint EMS tags are displayed in the GUI. |
1038004 |
FortiGate may not display the correct user information for some FortiClient instances. |
Firewall
Bug ID |
Description |
---|---|
990528 |
When searching for an IP address on the Firewall Policy page, the search/filter functionality does not return the expected results. |
1007029 |
On FortiGate, connections are disrupted between client email exchange servers and a virtual server when HTTP2 support is enabled. |
FortiGate 6000 and 7000 platforms
Bug ID |
Description |
---|---|
653335 |
SSL VPN user status does not display on the FortiManager GUI. |
936320 |
When there is a heavy traffic load, there are no results displayed on any FortiView pages in the GUI. |
950983 |
Feature Visibility options are visible in the GUI on a |
986845 |
On FortiOS, the Security Fabric widget does not display information on blade status. |
998615 |
When doing a GUI-packet capture on FortiGate, the through-traffic packets are not captured. |
1014826 |
SLBC does not function as expected with IPsec over TCP enabled. |
1032573 |
In an HA configuration, FortiGate does not respond to SNMP queries causing the device to display as being DOWN. |
1037965 |
When applying a script to a configuration, the updated configuration is applied to the FIM but is not fully synchronized on the FPCs. |
1056894 |
On FortiGate, IPv6 VRF routing tables appear under the new and old FPC primary units when the primary FPC slot is changed. |
FortiView
Bug ID |
Description |
---|---|
1009287 |
On the Dashboard > FortiView Sessions page, closing a large number of FortiView sessions (+100) can take longer than expected and result in a CPU usage issue. |
1034148 |
The Application Bandwidth widget on the Dashboard > Status page does not display some external applications bandwidth data. |
GUI
Bug ID |
Description |
---|---|
1009143 |
On FortiOS, the time displayed in the CLI and in the GUI do not match. |
1018682 |
When creating a firewall policy, applications groups with custom application signatures cannot be saved using the GUI. |
1047146 |
After a firmware upgrade, a VLAN interface used in IPsec, SSL VPN, or SD-WAN is not displayed on the interface list or the SD-WAN page and cannot be configured in the GUI. |
1050865 |
When updating an administrator password in the GUI, the password expiration date does not update when the new password is created. |
HA
Bug ID |
Description |
---|---|
851743 |
When running the |
965217 |
In an HA configuration, FortiGate may experience intermittent heartbeat loss causing unexpected failover to the secondary unit. |
1055336 |
Using the Test User Credentials button from the Radius Server in the GUI does not honor the custom |
1070745 |
Sessions may not fail back to the original FGSP peer that owns the session if either the interface name for the |
Hyperscale
Bug ID |
Description |
---|---|
1030907 |
With a FGSP and FGCP setup, sessions do not show on the HA secondary when the FGSP peer is in HA. |
1042011 |
On FortiGate, an login error message displays in the event log after completing an automation. |
1042512 |
On FortiGate, the CGN Resource Quota field allows an invalid value to be set. |
1093287 |
Using fixed-allocation IP Pools may cause NP7 NSS/PRP modules to become stuck, potentially disrupting traffic. Other PBA IP pools do not have this issue. |
IPsec VPN
Bug ID |
Description |
---|---|
735398 |
On FortiGate, the IKE anti-replay does not log duplicate ESP packets when SA is offloaded in the event log. |
995912 |
After a firmware upgrade, some VPN tunnels experience intermittent signal disruptions causing traffic to be re-routed. |
1020690 |
The IPsec Aggregate interface displays as DOWN on the Network > Interfaces and the Policy & Objects > Firewall Policy pages when the member including the Dialup VPN is actually UP. This is purely a GUI display issue and does affect system operation. The correct status is shown on the VPN > IPsec Tunnels page. |
1031963 |
The firewall |
1042371 |
RADIUS authentication with EAP-TLS does not work as expected through IPsec tunnels. |
1054953 |
If IKEv2 is selected during the VPN FortiClient Remote Access wizard setup in the GUI, the Extensible Authentication Protocol (EAP) configuration cannot be selected using the GUI. |
Log & Report
Bug ID |
Description |
---|---|
611460 |
On FortiOS, the Log & Report > Forward Traffic page does not completely load the entire log when the log exceeds 200MB. |
1034824 |
On the Log & Report > Forward Traffic page, application icons may not display in the Application Name column. |
1044092 |
When filtering forward traffic logs using FortiAnalyzer as a source, data takes longer than expected to load and generates a memory error message. |
1053334 |
The |
Proxy
Bug ID |
Description |
---|---|
1023054 |
After an upgrade on a 2GB FortiGate device, the firewall policy does not switch from Proxy-based to Flow-based in the Inspection mode field. |
1042055 |
On FortiGate, an interruption occurs in the WAD process when in proxy-mode causing the unit to go into memory conserve mode. |
1054052 |
The WAD process does not load a self-sign certificate when |
REST API
Bug ID |
Description |
---|---|
938349 |
Unsuccessful API user login attempts do not get reset within the time specified in |
993345 |
The router API does not include all ECMP routes for SD-WAN included in the |
1051870 |
After a firmware upgrade, some vlan interfaces attached to LAG interface are not displayed in the GUI. |
Routing
Bug ID |
Description |
---|---|
1029460 |
Creating a BGP IPv4 network prefix or neighbor in the GUI unintentionally creates an empty IPv6 network prefix. |
1041812 |
In a hub and spoke HA configuration, SD-WAN pages take longer than expected to load in the GUI when there are a large number of spokes (~350) configured. |
1042909 |
When creating a new static route on the Network > Static Routes page, the Priority field still displays when the Destination is switched from Subnet to Internet Service. |
Security Fabric
Bug ID |
Description |
---|---|
1007607 |
When creating a new IPv6 address, SDN connectors cannot be added for dynamic addresses. |
1011833 |
FortiGate experiences a CPU usage issue in the |
1019284 |
When optimizing a security rating, resolving an alert for one rating causes another alert to appear for another rating and the alerts cycle between both ratings continuously. |
1019844 |
In an HA configuration, when the primary FortiGate unit fails over to a downstream unit, the previous primary unit displays as being permanently disconnected. |
1040058 |
The Security Rating topology and results does not display non-FortiGate devices. |
1042972 |
Cannot test an automation stitch that uses the Schedule trigger from the GUI. |
1054407 |
The Security Rating report does not show test results for downstream FortiGates when the All FortiGates view is selected. Workaround: Individual results can still be viewed for each downstream FortiGate by changing the FortiGate selection to the individual FortiGate. |
1056262 |
With a FortiGate configured with a |
Switch Controller
Bug ID |
Description |
---|---|
1042390 |
On the WiFi & Switch Controller > SSID page, NAC policies using a Wildcard MAC Address cannot be saved using the GUI. Workaround: use the CLI to perform the operation. |
1054445 |
When editing a dynamic port policy, saved changes are not shown in the GUI. |
System
Bug ID |
Description |
---|---|
947982 |
On NP7 platforms, DSW packets are missing resulting in VOIP experiencing performance issues during peak times. |
952104 |
FortiGate experiences packet loss when using an internal hardware switch. |
971466 |
FortiGateRugged 60 models may experience packet loss when directly connected to Cisco switch. |
1003925 |
After deleting a redundant port on FortiGate, the port does not register as being available and generates an error. |
1006685 |
FortiGate enters a loop cycle and generates a large number of LCAP packets when FortiGate does not receive LCAP packets from a peer device. |
1008022 |
After a restarting FortiGate from the GUI, the |
1020602 |
After configuring a virtual wire pair (VWP) setting, it is not present in FortiGate after a reboot. |
1022935 |
FortiGate experiences a CPU usage issue when |
1029353 |
The SNMP trap is not sent out when a virus is detected on the antivirus scanner. |
1041726 |
Traffic flow speed is reduced or interrupted when the traffic shaper is enabled. |
1047085 |
The FortiOS GUI is unresponsive due to a CPU usage issue with the |
1049119 |
FortiGate encounters an interruption in the kernel due to a NULL pointer issue. |
1051961 |
On FortiGate, IP addresses cannot be assigned within a configured IP range due to a DHCP server issue. |
1055392 |
The traffic shaper does not take effect on the firewall policy when traffic is offloaded to NP7 due to a traffic management issue. |
1056578 |
The DNS server does not operate as expected with |
1065969 |
FortiGate does not boot up after restoring a configuration file containing an invalid string format. |
Upgrade
Bug ID |
Description |
---|---|
1043815 |
Upgrading the firmware for a large number (100+) of FortiSwitch or FortiAP devices at the same time may cause performance issues with the GUI and some devices may not upgrade. Workaround: pace out the upgrade schedule and upgrade devices in smaller batches. |
1056126 |
FortiGate does not boot up properly after an upgrade when it has a large number (500+) of VDOMs configured. |
User & Authentication
Bug ID |
Description |
---|---|
802089 |
User groups from FortiManager are not synchronized across all units except the MBD. |
1009884 |
FortiGate encounters a CPU usage issue in the |
1021719 |
On the System > Certificates page, the Create Certificate pane does not function as expected after creating a new certificate. |
1044084 |
On the Dashboard > Firewall User Monitor page, the Search field does not display in the GUI when there are a large number (+1000) FSSO user logos. |
VM
Bug ID |
Description |
---|---|
1012927 |
When FortiGate returns an ICMP TTL-EXCEEDED message, the |
1082197 |
The FortiGate-VM on VMware ESXi equipped with an Intel E810-XXV network interface card (NIC) using SFP28 transceivers at 25G speed is unable to pass VLAN traffic when DPDK is enabled. |
Web Filter
Bug ID |
Description |
---|---|
1040147 |
Options set in |
1058007 |
Web filter custom replacement messages in group configurations cannot be edited in FortiGate. |
WiFi Controller
Bug ID |
Description |
---|---|
1028181 |
Wi-Fi devices would encounter service delay when roaming over captive-portal SSID with MAC-address authentication. |
ZTNA
Bug ID |
Description |
---|---|
1053309 |
An interruption occurs in the WAD when accessing ZTNA TCP-forwarding service through a proxy-policy with a SAML user group and |
Existing known issues
The following issues have been identified in a previous version of FortiOS and remain in FortiOS 7.6.0.
Firewall
Bug ID |
Description |
---|---|
959065 |
On the Policy & Objects > Traffic Shaping page, when deleting or creating a shaper, the counters for the other shapers are cleared. |
1007566 |
When the FortiGate has thousands of addresses and hundreds address groups, the GUI can take a few minutes to search for a specific address inside the address group dialog. Workaround: User can create the address group in the CLI instead by using the exact address name. User can also perform a search in the CLI using a partial match. For example: config firewall addrgrp edit address_group set member <pattern>? next end |
1057080 |
On the Firewall Policy page, search results do not display in an expanded format. |
FortiGate 6000 and 7000 platforms
Bug ID |
Description |
---|---|
790464 |
After a failover, ARP entries are removed from all slots when an ARP query of single slot does not respond. |
994241 |
On FortiGate 7000F using FGSP and FGCP, when TCP traffic takes an asymmetric path, the TCP ACK and data packets might be dropped in NP7. |
997161 |
On FortiGate 6000 FPCs and FortiGate 7000 FPMs the node process may consume large amounts of CPU resources, possibly affecting FPC or FPM performance. (You can run the diagnose sys top command from an FPC or FPM CLI to view CPU usage.) This problem may be caused by security rating result submission. Workaround: Use the following commands to disable automatic security rating results submission and to disable running scheduled security ratings checks: config system global set security-rating-result-submission disable set security-rating-run-on-schedule disable end Once you have entered these commands, use the following command to restart the node process:
|
1006759 |
After an HA failover, there is no IPsec route in the kernel. |
1056894 |
On FortiGate, IPv6 VRF routing tables appear under the new and old FPC primary units when the primary FPC slot is changed. |
FortiView
Bug ID |
Description |
---|---|
1009287 |
On the Dashboard > FortiView Sessions page, closing a large number of FortiView sessions (+100) can take longer than expected and result in a CPU usage issue. |
1034148 |
The Application Bandwidth widget on the Dashboard > Status page does not display some external applications bandwidth data. |
GUI
Bug ID |
Description |
---|---|
853352 |
When viewing entries in slide-out window of the Policy & Objects > Internet Service Database page, users cannot scroll down to the end if there are over 100,000 entries. |
885427 |
On the Network > Interfaces page, the SFP port is grayed out on the faceplate diagram even though the port is working. This is purely a GUI display issue and does not affect system operation. Workaround: View the SFP port information and status using the |
HA
Bug ID |
Description |
---|---|
1054041 |
On FortiGate's in an HA environment, DHCP clients can not get an IPv4 address from the server with vcluster. |
IPsec VPN
Bug ID |
Description |
---|---|
944600 |
CPU usage issues occurred when IPsec VPN traffic was received on the VLAN interface of an NP7 vlink. |
Log & Report
Bug ID |
Description |
---|---|
1001583 |
The GUI experiences a performance issue and reverts the last input when multiple ports are added to a filter for destination ports. |
Proxy
Bug ID |
Description |
---|---|
1060812 |
When Proxy-mode inline IPS scanning is enabled, the botnet check within the IPS profile does not work as expected when the IPS profile is applied to a proxy-based inspection policy using certificate inspection. Workaround: disable |
Routing
Bug ID |
Description |
---|---|
1003756 |
When creating a rule on the Network > Routing Objects page, the Prefix-list is set to 0.0.0.0 0.0.0.0 when an incorrect format is entered in the Prefix field. |
Security Fabric
Bug ID |
Description |
---|---|
1057862 |
FortiGate models with 2GB of memory that manage many extension devices (FortiSwitches and FortiAPs) may enter conserve mode due to the GUI process experiencing a memory usage issue over time. Workaround: Avoid loading Security Fabric widget, Security Rating, and Topology pages. |
Switch Controller
Bug ID |
Description |
---|---|
961142 |
An interface in FortiLink is flapping with an MCLAG FortiSwitch using DAC on an OPSFPP-T-05-PAB transceiver. |
System
Bug ID |
Description |
---|---|
901621 |
On the NP7 platform, setting the interface configuration using Workaround: unset the config system interface edit <port> unset inbandwidth unset outbandwidth next end |
1020921 |
When configuring an SNMP trusted host that matches the management Admin trusted host subnet, the GUI may give an incorrect warning that the current SNMP trusted host does not match. This is purely a GUI display issue and does not impact the actual SNMP traffic. Workaround: If the trusted host is enabled on all administrative access, make sure the SNMP host IP is included in at least one of these trusted IP/subnets. |
1046484 |
After shutting down FortiGate, the system automatically boots up again. |
1058256 |
On FortiGate, interfaces with DAC cables remain down after upgrading to version 7.4.4. |
1058397 |
On FortiGate 900 models, when the baudrate is configured, the changes are not applied and is set to 9600. |
VM
Bug ID |
Description |
---|---|
1073016 |
The OCI SDN connector cannot call the API to the Oracle service when an IAM role is enabled. |
1094274 |
FortiGate becomes unresponsive due to an error condition when sending IPv6 traffic. |