Fortinet white logo
Fortinet white logo

Known issues

Known issues

Known issues are organized into the following categories:

To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

New known issues

The following issues have been identified in version 7.4.6.

Policy & Objects

Bug ID

Description

969923 The "View Mode" button, which is used to check the interface in Pair View, is missing in the Firewall Policy under Policy Packages.

Others

Bug ID

Description

1111686 FortiManager Cloud's GUI may crash with the error "Oops! Sorry, an unexpected error has occurred." when downloading a backup or accessing the "Last Script Run" option under Device Database.

Existing known issues

The following issues have been identified in a previous version of FortiManager Cloud and remain in FortiManager Cloud 7.4.6.

AP Manager

Bug ID

Description

1032762 Since FortiOS 7.4.4 now supports the selection of multiple 802.11 protocols and has trimmed the band options, importing FortiOS 7.4.3 AP profiles may result in some bands and channels being un-matched or unset.
1041445 The AP attributes do not automatically update in the AP Manager.
1050466 The 802.11ax-5g AP profile is missing for all FortiAPs that support WiFi 6.

Device Manager

Bug ID

Description

973365

FortiManager Cloud does not display the IP addresses of FortiGate interfaces configured with DHCP addressing mode.

Workaround:

Disable Addressing Mode from DHCP to Manual in FortiManager Cloud Device DB, then retrieve from FortiGate and IP will be updated successfully.

974925

The NTP Server setting may not display the correct configuration. This issue might occur on managed devices running FortiOS version 7.4.2 or higher.

Workaround:

Edit NTP server setting under CLI configuration.

980362 The Firmware Version column in Device Manager incorrectly shows "Upgrading FortiGate from V1 to V2" even after a successful upgrade has been completed.
1004220 The SD-WAN Overlay template creates route-map names that exceed the 35-character limit.
1062545 When using the backslash "\" in the preshared key of IPSEC settings, the install may fail.

1063850

FortiManager Cloud is attempting to install a "PRIVATE KEY" with every installation, even after retrieving the config.

1086303

An installation error may occur when binding and installing the created VLAN interface to the software switch due to ip-managed-by-fortiipam. No issues have been observed with the installation of VLAN interfaces or physical interfaces.

Workaround:

Use a script (CLI template) on device database on FortiManager Cloud to unset "ip-managed-by-fortiipam" under wan interface (every time before installation), and then install the configuration.

FortiSwitch Manager

Bug ID

Description

1110598

Unable to add per device mapping config for FortiSwitch VLAN.

Workaround:

A script can be run on "Policy Package or ADOM Database". The following is an example:

config fsp vlan
							edit "vlan200"
							set vlanid 200
							set _dhcp-status disable
							config interface
							set ip-managed-by-fortiipam disable
							end
 
							config dynamic_mapping
							edit "FortiGate-80F-POE"-"root"
							set _dhcp-status disable
							config interface
							set vlanid 20
							end

							config dhcp-server
							set dns-service default
							set ntp-service default
							set timezone-option default
							end
							next
							end
							next
						end

Others

Bug ID

Description

830592

Upgrade of ADOM type FortiProxy is not supported.

1019261

Unable to upgrade ADOM from 7.0 to 7.2, due to the error "Do not support urlfilter-table for global scope webfilter profile".

Workaround:

Run the following script against the ADOM DB:

config webfilter profile

edit "g-default"

config web

unset urlfilter-table

end

next

end

1049457 When FortiAnalyzer is added as a managed device, users may encounter an issue in the FortiManager Cloud GUI when expanding the log details.

1080463

An admin with access to a specific ADOM can view the database and clone objects to another ADOM, even if they do not have direct access to it.

Policy & Objects

Bug ID

Description

845022 SDN Connector failed to import objects from VMware VSphere.
971065 When the number of Custom Internet Services exceeds 256, installation fails due to this limitation.
1025012

Configuring the SSL/SSH inspection profile may result in the following error: "The server certificate replacement mode cannot support category exemptions."

Workaroud:

  1. Modify the SSL/SSH inspection profiles.

  2. Toggle from Protecting SSL Server to Multiple Clients Connecting to multiple Servers.

  3. Remove the categories from the Exempt from SSL inspection list.

  4. Toggle back to Protecting SSL Server and click OK.

  5. Then install.

1030914 Copy and paste function in GUI removes name of the policy rule and adds unwanted default security profiles (SSL-SSH no-inspection and default PROTOCOL OPTIONS).

1057228

Importing the SDN Objects, with multiple tags, will add multiple entries listed as SDN objects; when clients add anything into the filters section, browser immediately redirects to an error page showing: "Oops! Sorry, an unexpected error has occurred"

1079128

ZTNA Server Per-Device Mapping may display a copy error failure if a new per-device mapping is created without specifying the object interface.

1086603

Unable to create local-in policy with ISDB objects

Script

Bug ID

Description

931088

Unable to delete VDOMs using the FortiManager Cloud script. Interfaces remain in the device database, causing the installation to fail.

1085374

FortiManager Cloud does not support exporting the TCL scripts via CLI.

System Settings

Bug ID

Description

825319 FortiManager Cloud fails to promote a FortiGate HA member (running on firmware 7.2.0 to 7.2.4) to the Primary.
1063040

Unable to import a local certificate into FortiManager Cloud. This issue may occur if the certificate is encrypted with a newer OpenSSL version that FortiManager Cloud does not yet support.

Workaround:

Convert the latest certificate to the legacy format before uploading it to FortiManager Cloud.

Known issues

Known issues

Known issues are organized into the following categories:

To inquire about a particular bug or to report a bug, please contact Fortinet Customer Service & Support.

New known issues

The following issues have been identified in version 7.4.6.

Policy & Objects

Bug ID

Description

969923 The "View Mode" button, which is used to check the interface in Pair View, is missing in the Firewall Policy under Policy Packages.

Others

Bug ID

Description

1111686 FortiManager Cloud's GUI may crash with the error "Oops! Sorry, an unexpected error has occurred." when downloading a backup or accessing the "Last Script Run" option under Device Database.

Existing known issues

The following issues have been identified in a previous version of FortiManager Cloud and remain in FortiManager Cloud 7.4.6.

AP Manager

Bug ID

Description

1032762 Since FortiOS 7.4.4 now supports the selection of multiple 802.11 protocols and has trimmed the band options, importing FortiOS 7.4.3 AP profiles may result in some bands and channels being un-matched or unset.
1041445 The AP attributes do not automatically update in the AP Manager.
1050466 The 802.11ax-5g AP profile is missing for all FortiAPs that support WiFi 6.

Device Manager

Bug ID

Description

973365

FortiManager Cloud does not display the IP addresses of FortiGate interfaces configured with DHCP addressing mode.

Workaround:

Disable Addressing Mode from DHCP to Manual in FortiManager Cloud Device DB, then retrieve from FortiGate and IP will be updated successfully.

974925

The NTP Server setting may not display the correct configuration. This issue might occur on managed devices running FortiOS version 7.4.2 or higher.

Workaround:

Edit NTP server setting under CLI configuration.

980362 The Firmware Version column in Device Manager incorrectly shows "Upgrading FortiGate from V1 to V2" even after a successful upgrade has been completed.
1004220 The SD-WAN Overlay template creates route-map names that exceed the 35-character limit.
1062545 When using the backslash "\" in the preshared key of IPSEC settings, the install may fail.

1063850

FortiManager Cloud is attempting to install a "PRIVATE KEY" with every installation, even after retrieving the config.

1086303

An installation error may occur when binding and installing the created VLAN interface to the software switch due to ip-managed-by-fortiipam. No issues have been observed with the installation of VLAN interfaces or physical interfaces.

Workaround:

Use a script (CLI template) on device database on FortiManager Cloud to unset "ip-managed-by-fortiipam" under wan interface (every time before installation), and then install the configuration.

FortiSwitch Manager

Bug ID

Description

1110598

Unable to add per device mapping config for FortiSwitch VLAN.

Workaround:

A script can be run on "Policy Package or ADOM Database". The following is an example:

config fsp vlan
							edit "vlan200"
							set vlanid 200
							set _dhcp-status disable
							config interface
							set ip-managed-by-fortiipam disable
							end
 
							config dynamic_mapping
							edit "FortiGate-80F-POE"-"root"
							set _dhcp-status disable
							config interface
							set vlanid 20
							end

							config dhcp-server
							set dns-service default
							set ntp-service default
							set timezone-option default
							end
							next
							end
							next
						end

Others

Bug ID

Description

830592

Upgrade of ADOM type FortiProxy is not supported.

1019261

Unable to upgrade ADOM from 7.0 to 7.2, due to the error "Do not support urlfilter-table for global scope webfilter profile".

Workaround:

Run the following script against the ADOM DB:

config webfilter profile

edit "g-default"

config web

unset urlfilter-table

end

next

end

1049457 When FortiAnalyzer is added as a managed device, users may encounter an issue in the FortiManager Cloud GUI when expanding the log details.

1080463

An admin with access to a specific ADOM can view the database and clone objects to another ADOM, even if they do not have direct access to it.

Policy & Objects

Bug ID

Description

845022 SDN Connector failed to import objects from VMware VSphere.
971065 When the number of Custom Internet Services exceeds 256, installation fails due to this limitation.
1025012

Configuring the SSL/SSH inspection profile may result in the following error: "The server certificate replacement mode cannot support category exemptions."

Workaroud:

  1. Modify the SSL/SSH inspection profiles.

  2. Toggle from Protecting SSL Server to Multiple Clients Connecting to multiple Servers.

  3. Remove the categories from the Exempt from SSL inspection list.

  4. Toggle back to Protecting SSL Server and click OK.

  5. Then install.

1030914 Copy and paste function in GUI removes name of the policy rule and adds unwanted default security profiles (SSL-SSH no-inspection and default PROTOCOL OPTIONS).

1057228

Importing the SDN Objects, with multiple tags, will add multiple entries listed as SDN objects; when clients add anything into the filters section, browser immediately redirects to an error page showing: "Oops! Sorry, an unexpected error has occurred"

1079128

ZTNA Server Per-Device Mapping may display a copy error failure if a new per-device mapping is created without specifying the object interface.

1086603

Unable to create local-in policy with ISDB objects

Script

Bug ID

Description

931088

Unable to delete VDOMs using the FortiManager Cloud script. Interfaces remain in the device database, causing the installation to fail.

1085374

FortiManager Cloud does not support exporting the TCL scripts via CLI.

System Settings

Bug ID

Description

825319 FortiManager Cloud fails to promote a FortiGate HA member (running on firmware 7.2.0 to 7.2.4) to the Primary.
1063040

Unable to import a local certificate into FortiManager Cloud. This issue may occur if the certificate is encrypted with a newer OpenSSL version that FortiManager Cloud does not yet support.

Workaround:

Convert the latest certificate to the legacy format before uploading it to FortiManager Cloud.