Resolved issues
The following issues have been fixed in 7.6.7. To inquire about a particular bug, please contact Customer Service & Support.
AP Manager
|
Bug ID |
Description |
|---|---|
|
1239191 |
When SSID configured with per-device mapping, during the installation, the FortiManager will report error: Commit failed: ssid fortinet is used by vap. |
|
1239368 |
Duplicate SSID occurs when accented character is used at the end of the SSID name. |
Device Manager
|
Bug ID |
Description |
|---|---|
|
894948 |
FortiManager fails to push the FortiAnalyzer override settings to the FortiGate. |
|
895994 |
When using the 'where used' feature in Phase 2 quick mode selector, objects do not appear, and they can be removed. |
|
1001557 |
Metadata variables are not supported for the "XAUTH" field in IPsec tunnel provisioning templates. |
|
1015138 |
Unable to edit interface with dhcp reservation. |
|
1028515 |
The Greenwich time zone on FortiGate does not supported on the FortiManager. |
|
1189821 |
Failure to add FortiAnalyzer occurs when using the HA cluster's virtual IP in FortiManager. |
|
1191558 |
Changes to SD-WAN performance SLA values are not reflected in the device database or the install preview when the detect-mode is set to remote. |
|
1194361 |
Installation fails when device description contains single quote characters. |
|
1204427 |
Script log results do not display logs from the most recent script execution; only logs from previous executions are shown. |
|
1209816 |
The Install Wizard may appear empty after an upgrade when device-level settings are configured. This issue has been observed in environments where configuration inconsistencies were addressed before the upgrade using the |
|
1215217 |
The install preview does not load if a device in the device group is offline, but it works fine if all the devices are online. |
|
1224965 |
Device identification is disabled when changing interface role from LAN to undefined. |
|
1240231 |
After upgrading FortiManager to version 7.6.5, remote access to FortiGate devices may fail with the error Error reading from remote server when using non-standard ports. |
|
1244586 |
Installation failure occurs when unsetting the " |
|
1246821 |
FortiManager retrieve may fail when an admins remote-group exists only in the root VDOM and the VDOM order starts with a non-root VDOM, causing invalid reference detection during device addition. |
|
1247501 |
Installation error occurs when using metadata variables on IP range field in system template. |
|
1251613 |
Registration of FortiGate-VM64-KVM as Device model to FortiManager may fail due to incorrect platform identification. |
|
1254998 |
Incorrect Interface Syntax Selection for FGT90G/91G Gen1/Gen2 During Model Device (ZTP) Creation has been observed. |
|
1269401 |
Performing device deletion may appear very slow. While the deletion process is still ongoing, clients performing policy package installation tasks may experience delays before the task starts or completes. This behavior has been observed in some cases where FortiManager manages more than 6,000 device groups. |
FortiSwitch Manager
|
Bug ID |
Description |
|---|---|
|
1118271 |
FortiSwitch Device information is not displayed when FortiSwitch version is 7.4.3. |
|
1227473 |
FortiManager attempts to install set poe-status disable on FortiSwitch ports that already have PoE disabled. The issue persists and reoccurs after configuration installation and synchronization. |
|
1244165 |
When centrally managing switches via FortiManager, the "Switch-id" is limited to 16 characters. Configuring a hostname exceeding this limit triggers the error: "Switch-id: Value too long." |
|
1246204 |
Firmware upgrade tasks stall when multiple upgrades for the same FortiSwitch are run concurrently. |
|
1268279 |
Deleting custom-command from FortiSwitch Manager template is not deleting it from device. |
Global ADOM
|
Bug ID |
Description |
|---|---|
|
1150670 |
Installation failure occurs when upgrading global ADOM from v7.2 to v7.4 due to gno-inspection settings. |
|
1163223 |
A global object loses its global status when transferred from a local ADOM to an FortiGate device and then re-imported into another local ADOM, resulting in a duplicate object error. |
|
1177672 |
When global policy package assignment fails, it may impacts the policy packages on the ADOM. |
|
1201449 |
Global policy assignment configured with Automatically Install Policies to ADOM Devices may get stuck during deployment. |
|
1232811 |
Unassigning a Global Policy Package may fail when it is referenced by SSL inspection profiles in the root ADOM. |
|
1244194 |
Global Policy Block appended to Global Policy Package is not visible under root ADOM PP when assigned. |
|
1245741 |
The Promote to Global feature for objects created in an ADOM may fail if the object name contains a forward slash (/) character. |
Others
|
Bug ID |
Description |
|---|---|
|
1081121 |
The syslog server is unable to receive FortiManager event logs when the reliable option is enabled. |
|
1179653 |
The API interface performance in version 7.6 may appear slower compared to previous versions. |
|
1180920 |
After the installation, an event alert was received indicating that the FGFM tunnel is flapping. |
|
1185269 |
The local log syslog feature set facility is not functioning properly. |
|
1189184 |
Copy Policy Package operations may take longer than usual and remain stuck for an extended duration, even for small changes. This issue may occur when FortiOS does not return a response to FGFM requests from FortiManager. |
|
1194429 |
FortiGuard Query Services displays an incorrect date for the Query Status when viewing the Number of Queries graph. |
|
1201248 |
Historical logs are not displayed when FortiAnalyzer feature is enabled. |
|
1203535 |
FortiManager does not support the |
| 1210368 | Connectivity issue occurs when FortiManager and FortiProxy are in config-sync-only cluster mode with the default certificate. |
|
1210519 |
Central-management settings are deleted on the primary unit when adding a FortiProxy HA cluster via Device Discover. This issue may occur when the FortiManager ADOM is configured in backup mode and the FortiProxy central-management setting is also set to the backup mode. Refreshing the device may trigger the issue. |
|
1230277 |
If the ADOM in an earlier FortiManager version contains DLP dictionary entries named fg-*, which are reserved in FortiManager 7.6, the upgrade from ADOM 7.4 to 7.6 will fail. The upgrade process attempts to copy these reserved-name objects, but ADOM 7.6 does not allow them to be created or modified. |
|
1234093 |
Time discrepancy occurs between formatted and raw logs when using GMT timezone. |
|
1239748 |
Unable to delete Meta Variables with the following Error: The data is invalid for selected url. |
|
1241163 |
After upgrading from 7.6.4 or earlier, users may encounter a blank GUI screen upon login if the ADOM flag value (flags) contains an incorrect value. |
|
1241561 |
ADOM integrity check fails when running |
|
1244008 |
When FortiAnalyzer is added as a managed device in FortiManager, executing any of the " |
|
1246091 |
FortiOS 7.4.10 partially supported by FortiManager 7.6.5/7.6.6. See the FortiManager 7.6.5/7.6.6 Release Notes for Compatibility Issues. |
|
1247597 |
FortiManager is unable to sync user information from the pxGrid connector. |
|
1251516 |
Installation failure occurs when pushing primus HSM ( on-premises Hardware Security Module) settings via provisioning templates to FortiProxy. |
|
1252855 |
ADOM upgrade from 7.4 to 7.6 may fail repeatedly during the dynamic_mapping copy phase with the error message: "unexpected input." |
|
1255147 |
The fmg-admin is able to click both the text label and the toggle. |
|
1256462 |
FortiClient fails to pull AV signatures from FortiManager acting as FDS server when receiving UM objects over HTTP. |
|
1257065 |
FortiGuard subscription status shows unknown when trial license has expired. |
|
1257789 |
Root ADOM upgrade fails when duplicate policy package names exist within a policy block. |
| 1258369 | FortiCarrier is incorrectly identified as FortiGate when managed by FortiManager 7.6.6. |
| 1264965 | After upgrading FortiManager from 7.6.4 to 7.6.7 or 8.0.0, some ADOMs may incorrectly display a "License Expired" status due to incorrect ADOM flag values. |
|
1266515 |
When importing a custom firewall service definition through a FortiManager script that mixes the set protocol TCP/UDP/SCTP parameter with |
| 1266798 | SNMP passwords may be exposed when a FortiGate configuration is downloaded from FortiManager using the API. |
| 1267057 | An error condition in Security Console may occur during device settings installation when an IPsec template is present in the template group. |
|
1268146 |
An error occurs when upgrading FortiManager due to password length limitations. |
|
1284743 |
In an FortiGate HA setup running on a public cloud platform and managed by FortiManager, FortiManager may attempt to install or modify `vdom-exception` configurations, such as static routes. This may lead to issues during a failover event, including routes being deleted or other unexpected behavior. |
Policy and Objects
|
Bug ID |
Description |
|---|---|
|
1101351 |
Unable to create ZTNA Server with SAML SSO Server. |
|
1171027 |
NAT64 policy and CNAT cannot be created or modified in FortiManager. |
|
1182465 |
Installation fails when FortiManager creates a default shaping-profile and binds it to an interface. |
|
1189177 |
The FortiManager configuration attempted to change the order of custom service objects, but this returned an "Unknown action 0" error. |
|
1194560 |
Missing CASB applications occur when FortiManager fetches casb application data without the 'get reserved' option. |
|
1202792 |
The installation may fail with a "Current passphrase is invalid" error. This can occur when installing an SSID with an MPSK profile, where the MPSK passphrase is not inherited during copy operations or after a FortiManager upgrade. |
|
1209756 |
Policy package installation fails for FGT-30G due to SSL VPN settings not supported by this FortiGate model. |
|
1224582 |
FortiManager tries to delete access-proxy and all ZTNA-related configuration from the firewall. |
|
1224598 |
The Policy Package Diff does not display any differences and throws an error. |
|
1227209 |
Insert above or insert below fails when using ISDB objects in the policies. |
|
1232760 |
Permit-stun-host configuration is not applied during installation when NAT is disabled. |
|
1234646 |
FortiManager fails to display installation preview info. Preview stays blank with just a special character. |
|
1235065 |
When loading an ssh cert, there is no password option and encrypted keys are not accepted. |
|
1240260 |
When the Policy Package setting "Policy Offload Level" is set to Default mode, the Copy Policy Validation may fail and display an error log "COMMIT FAIL - invalid value". |
|
1240764 |
Users may experience slowness when loading large policy packages while switching between Interface Pair views. |
|
1242292 |
When configuring ISDB entries through the GUI, the default port value may be incorrectly applied, resulting in inaccurate port assignments within the configuration. |
|
1242707 |
Policy package status does not change to "Out of Sync" on FortiManager when local changes are made on FortiGate. |
|
1245964 |
In FortiOS 7.4.10, CLI syntax changes can cause install failures on low-memory (2GB) models when pushing configuration for: web-proxy global proxy-fqdn firewall ssl-ssh-profile ssh For more details, please review the Special Notices in the FortiManager 7.6.5/7.6.6 Release Notes. |
| 1246604 | Installation may fail when FortiManager attempts to purge internet-service-custom entries. This issue may occur when some internet-service-custom entries are reserved and cannot be modified or deleted on the FortiOS side, but FortiManager still attempts to update or remove them during installation. |
|
1247668 |
Importing firewall policies may fail when adding an FortiGate with a large number of policies (e.g., over 60K). |
|
1249297 |
Policies disappear from policy block GUI when policy block name contains '/' character. |
|
1252128 |
Firewall Policy object lists are auto-compressed when more than 3 objects per rule are present. |
|
1255176 |
Policy package installation may stuck when dynamic mapping member of a "firewall addrgrp" is empty. |
|
1257115 |
Policy package installation may fail on hardware devices when policy-offload-level is set to default. |
|
1257828 |
Searching in Policy Packages/Policies with certain keywords may result in an unexpected error. |
|
1258985 |
When disabling the HTTPS protocol under "Protocol Port Mapping" of any "SSL/SSH Inspection" profile, FortiManager tries to push the command "unset ports" which is not recognized by the FortiGate. As a result, the error "Must set at least one port or enable ssl inspect-all. ..."is generated during the Policy Package Installation. |
| 1258986 | Import & Install may fail when a policy package includes a firewall policy that references a firewall internet-service-fortiguard object. |
| 1262128 | Installation may fail with the error "Current passphrase is invalid. Must be 8 to 63 characters long or 64 hex digits." when configuring Wireless Controller Virtual Access Points (VAPs). |
| 1263852 | Duplicate policy ID occurs when Policy Lock is enabled. |
|
1265850 |
When attempting to view "Where Used" for a url-filter list, the GUI continuously loads and does not return any results, even after several minutes. |
|
1270583 |
Installation fails when FortiManager pushes an invalid limit for policing type shaping-profile. |
| 1274562 | Policy package installation preview fails to load, and the installation may fail with empty logs when the psksecret value in the IPsec VPN configuration contains unmatched double quotation marks. |
|
1287157 |
GUI may crash when clicking Next in the Import Wizard before the Conflict Configuration table has fully loaded. |
|
1287203 |
When attempting to view "Where Used" for a Web Content Filter, the GUI continuously loads and does not return any results, even after several minutes. |
Revision History
|
Bug ID |
Description |
|---|---|
|
1248791 |
ADOM revision history may be lost when upgrading the ADOM to version 7.6. |
Services
|
Bug ID |
Description |
|---|---|
|
1180123 |
FortiManager downloads and pushes full-version objects between FDS and FortiGate, which can result in high traffic usage. |
System Settings
|
Bug ID |
Description |
|---|---|
|
1158131 |
The GUI permits configuring the management port to a port number already in use, resulting in loss of access to the GUI. |
|
1235915 |
Trusted host configuration is not enforced when administrator accounts use SSH key authentication. |
|
1238985 |
In a VRRP HA setup, the 3rd and 4th HA members may not properly synchronize with the master. |
|
1257096 |
Policy package changes are unavailable to FortiManager-admins authenticated by Radius with ADOM scope and ext-auth-adom-override enabled. |
VPN Manager
|
Bug ID |
Description |
|---|---|
|
1256324 |
Installation may fail after creating VPN communities of any type. |
|
1262311 |
In a FortiManager 7.4 ADOM, attempts to create or retrieve SSL VPN web portal settings for FortiOS 7.4 devices may fail due to per-VDOM limit validation errors. |