Fortinet white logo
Fortinet white logo

Known Issues Version 9.4.6

Known Issues Version 9.4.6

Ticket # Description

1080122

FortiGate running FOS version 7.2.11, 7.4.6 or 7.6.1 will fail CLI/GUI RADIUS server connectivity test with FortiNAC. This is due to a new requirement in FOS where responses from the RADIUS server (FortiNAC) must contain the Message-Authenticator attribute. Note RADIUS client connectivity is not affected.

1071760

Hosts not being set as managed by MDM for multiple MDM's. Workaround: In the MDM service connector, disable "Remove Hosts Deleted From MDM Server".

1016576

FortiNAC sometimes creates duplicate virtual interfaces.

1048537

Duplicate AP's created if DHCP is used to assign IPs to Mist AP's.

1022276

NCM standalone and HA CA license entitlement is correctly reflected, but accessing the portal on Primary CA throws "You do not have permission to access this page" and accessing any menu under Policy & Objects throws “Server Error”.

1039188

Custom login form custom User Registration Approval not being sent.

1022348

Delays in dynamic address tag being sent due to host VPN adapter association.

1029194

Device type failing to load when modifying a host.

970257

Specified role not assigned to devices registered via the Portal, instead NAC-Default is assigned.

1030210

Need to prevent dir sync from running multiple processes at once.

1030103

Model Configuration > 500 error if there are no CLI configurations.

1022559

FortiNAC has no ability to support weak SSH ciphers.

995406

Hosts/Adapters - Quick Search: Unexpected results.

1014123

Mist AP's do not discover properly if Hostname is not configured.

1010097 Re-scanning a host at risk causes false positives having Required Critical Updates applied on endpoint compliance scan.
1002475 Unable to scan using Dissolvable Agent with spaces in scan name.

993873,

995406

Host Search with wildcard provides unexpected results.
827283 The Roaming Guest Logical Network is missing from the Model Configuration of FortiGate and possibly from other vendors.
955985 Extreme switch with 'description-string' in switchport config won't display connected adapters in GUI device model.
974270 Non fabric root FortiGate do not have dynamic tags after firmware update.
932546 In [9.4.4] on NCM, 'Server Responses' appear duplicated when distributing firmware.
928827 Host aging is not applied to IP Phone device type.
924474 Unable to select SSIDs when creating/modifying a port group under System > Groups. Workaround: Under SSID tab, right click SSID, select Group Membership & select the desired group.
800326 Cisco chassis switch with a Cisco WLC connected via port channel shows as a rogue.
863826 License Management view in the UI always displays "Base" for the License Name when using subscription licenses. Workaround: Use the License Information Dashboard Widget.
861201 Windows 11 Domain Check.
852670 AP showing up as learned uplink not WAP Uplink.
827283 Roaming Guest Logical Network missing from FortiGate Model Configuration and possibly other vendors.
826653 FortiNAC supplied Dynamic Addresses on the FortiGate can become orphaned in FortiNAC High Availability environments. This can cause unintended network access.
824088 Unable to update existing Registered Host records using Legacy View > Hosts > Import.
776077 Local Radius to Winbind connection cannot be secured at this time.
767548 Register Game system with Host Inventory success page is not working.
710583 L2 Polling Mist APs can result in more API requests than Mist allows per hour.
708936 FortiNAC will log off SSO for sessions that remain connected to a managed FortiGate IPSec VPN tunnel after 12 hours.
Not all models of all network devices can be configured to perform Physical MAC Address Filtering even though the Admin UI indicates that the configuration can be set. Resolution: Hosts can be disabled by implementing a Dead-end VLAN.
For Portal v2 configurations, web pages that are stored in the site directory to be used for Scan Configurations will not be included when you do an Export of the Portal v2 configuration. Resolution: The files in the site directory are backed up with the Remote Backup feature, but otherwise keep a copy of these files in a safe place.
Removing a device from the L2 Wired Devices or L2 Wireless Devices Group does not disable L2 (Hosts) Polling under the Polling tab in Topology.
The "Set all hosts 'Risk State' to 'Safe'" button changes the status of all hosts marked At-Risk to Safe. However, the status of the individual scans for each host remain unchanged.
In a Layer 3 High Availability (HA) environment, configWizard must have a DHCP scope defined. Running configWizard without a DHCP scope can cause a failover.
On FortiNAC appliances with CentOS 7, duplicate log messages may appear in dhcpd.log for each sub interface (eth1, eth1:1, eth1:2, etc).
System > Settings > Updates > Operating System will only record and display dates of OS updates that are completed through the Administrative UI. If Operating System updates are run via command line using the "yum" tool, the update is not recorded. Resolution: Execute Operating System Updates through the Administrative UI in order to maintain update history.
Only English versions of AV/AS and their corresponding definitions are supported.
Anti-Virus product Iolo technologies System Mechanic Professional is currently not supported.

Known Issues Version 9.4.6

Known Issues Version 9.4.6

Ticket # Description

1080122

FortiGate running FOS version 7.2.11, 7.4.6 or 7.6.1 will fail CLI/GUI RADIUS server connectivity test with FortiNAC. This is due to a new requirement in FOS where responses from the RADIUS server (FortiNAC) must contain the Message-Authenticator attribute. Note RADIUS client connectivity is not affected.

1071760

Hosts not being set as managed by MDM for multiple MDM's. Workaround: In the MDM service connector, disable "Remove Hosts Deleted From MDM Server".

1016576

FortiNAC sometimes creates duplicate virtual interfaces.

1048537

Duplicate AP's created if DHCP is used to assign IPs to Mist AP's.

1022276

NCM standalone and HA CA license entitlement is correctly reflected, but accessing the portal on Primary CA throws "You do not have permission to access this page" and accessing any menu under Policy & Objects throws “Server Error”.

1039188

Custom login form custom User Registration Approval not being sent.

1022348

Delays in dynamic address tag being sent due to host VPN adapter association.

1029194

Device type failing to load when modifying a host.

970257

Specified role not assigned to devices registered via the Portal, instead NAC-Default is assigned.

1030210

Need to prevent dir sync from running multiple processes at once.

1030103

Model Configuration > 500 error if there are no CLI configurations.

1022559

FortiNAC has no ability to support weak SSH ciphers.

995406

Hosts/Adapters - Quick Search: Unexpected results.

1014123

Mist AP's do not discover properly if Hostname is not configured.

1010097 Re-scanning a host at risk causes false positives having Required Critical Updates applied on endpoint compliance scan.
1002475 Unable to scan using Dissolvable Agent with spaces in scan name.

993873,

995406

Host Search with wildcard provides unexpected results.
827283 The Roaming Guest Logical Network is missing from the Model Configuration of FortiGate and possibly from other vendors.
955985 Extreme switch with 'description-string' in switchport config won't display connected adapters in GUI device model.
974270 Non fabric root FortiGate do not have dynamic tags after firmware update.
932546 In [9.4.4] on NCM, 'Server Responses' appear duplicated when distributing firmware.
928827 Host aging is not applied to IP Phone device type.
924474 Unable to select SSIDs when creating/modifying a port group under System > Groups. Workaround: Under SSID tab, right click SSID, select Group Membership & select the desired group.
800326 Cisco chassis switch with a Cisco WLC connected via port channel shows as a rogue.
863826 License Management view in the UI always displays "Base" for the License Name when using subscription licenses. Workaround: Use the License Information Dashboard Widget.
861201 Windows 11 Domain Check.
852670 AP showing up as learned uplink not WAP Uplink.
827283 Roaming Guest Logical Network missing from FortiGate Model Configuration and possibly other vendors.
826653 FortiNAC supplied Dynamic Addresses on the FortiGate can become orphaned in FortiNAC High Availability environments. This can cause unintended network access.
824088 Unable to update existing Registered Host records using Legacy View > Hosts > Import.
776077 Local Radius to Winbind connection cannot be secured at this time.
767548 Register Game system with Host Inventory success page is not working.
710583 L2 Polling Mist APs can result in more API requests than Mist allows per hour.
708936 FortiNAC will log off SSO for sessions that remain connected to a managed FortiGate IPSec VPN tunnel after 12 hours.
Not all models of all network devices can be configured to perform Physical MAC Address Filtering even though the Admin UI indicates that the configuration can be set. Resolution: Hosts can be disabled by implementing a Dead-end VLAN.
For Portal v2 configurations, web pages that are stored in the site directory to be used for Scan Configurations will not be included when you do an Export of the Portal v2 configuration. Resolution: The files in the site directory are backed up with the Remote Backup feature, but otherwise keep a copy of these files in a safe place.
Removing a device from the L2 Wired Devices or L2 Wireless Devices Group does not disable L2 (Hosts) Polling under the Polling tab in Topology.
The "Set all hosts 'Risk State' to 'Safe'" button changes the status of all hosts marked At-Risk to Safe. However, the status of the individual scans for each host remain unchanged.
In a Layer 3 High Availability (HA) environment, configWizard must have a DHCP scope defined. Running configWizard without a DHCP scope can cause a failover.
On FortiNAC appliances with CentOS 7, duplicate log messages may appear in dhcpd.log for each sub interface (eth1, eth1:1, eth1:2, etc).
System > Settings > Updates > Operating System will only record and display dates of OS updates that are completed through the Administrative UI. If Operating System updates are run via command line using the "yum" tool, the update is not recorded. Resolution: Execute Operating System Updates through the Administrative UI in order to maintain update history.
Only English versions of AV/AS and their corresponding definitions are supported.
Anti-Virus product Iolo technologies System Mechanic Professional is currently not supported.