Fortinet black logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.0.1. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID Description
561711 The TLS 1.3 performance needs to be improved.

677234

Web pages included in the external list (FortiGuard Category Threat Feed) should be blocked when users try to access them through https://translate.google.com.

706786 The WAN-optimization daemon (WAD) crashes at wad_cert_picker_get_X509_issuer.

725373

When the SSL Negotiation log is enabled, there should be an SSL UTM log available.

726691

LACP does not work between a FortiProxy unit and a Cisco Catalyst 9500.

728641 The abbreviated handshake fails when a fatal illegal parameter is received.

733104

The transparent proxy policy is not matching the proxy address object URL pattern.

733135

Validating the SSL certificate should not time out.

734840

The web filter blocks websites in proxy mode because validating the SSL certificate fails.

737285

There is a certificate error when using the proxy policy and the website being accessed has an incomplete certificate chain.

738331 When an address group is configured with an excluded address object on a proxy policy, the excluded members should be excluded in the address group.
739091 The WAD crashes multiple times at wad_tunnel_msg_ssl_handshake_send with signal 11 (Segmentation error).
739610 When the ssh-policy-redirect option is disabled, SSH-over-HTTP traffic still tries to match the SSH policy.
739923 The WAD causes memory usage to increase from 50% to 75% after one day.
740222 The set filter-by file-type-and-size command is missing from under the config dlp sensor command.
741866 An overrun problem occurred in WAN optimization when using explicit proxy.
741867 Negative returns occurred in WAN optimization when using explicit proxy.

741869

Memory is corrupted when a transparent proxy policy is used with web caching, IPS, web filter, and antivirus scanning.

742108 The WAD crashed with signal 11 (Segmentation error) when the video filter was being used.
742141 When external resources reply with HTTP 301, 302, 307, or 308, the response codes are not accepted.

742178

After an interface is configured as the HA management interface, all input rules (such as Telnet, HTTP, SSH, and ping) are removed from the IP tables, and the interface cannot be accessed.

742241

When a security profile (such as antivirus, Application Control, or IPS) is active, traffic with the content encoding type of amz-1.0 does not work through the proxy.

742437

When a ZTNA rule is created in the GUI, it does not include the destination address or source interface.

742620

The WAD crashes at fts_ssl_port_open_with_keys with signal 11 when there is HTTPS traffic with WAN optimization and SSL offload enabled.

743168

The WAD crashes continuously with signal 11 (segmentation fault).

743259

The GUI is not displaying the number of hits or active sessions.

743379

After upgrading to FortiProxy 7.0, the maximum number of proxy address objects is reduced from 24,576 to 8,192.

743602

An “empty reply from server” error results when there is HTTPS traffic with WAN optimization.

743656

If there is an authentication scheme configured but no authentication rules, the WAD user receives a 403 Forbidden error.

743750

There were many WAD scan unit crashes.

743894

When downloading 10 million samples with WAN optimization enabled, the download will stop halfway through.

743927

When UTM is enabled, ICAP server sessions are not included in the total number of licensed sessions.

743975

The URL column should be available to add to the HTTP Transaction logs.

743976

When two FortiProxy units and in a Config -Sync cluster, both FortiProxy units have the same hdisk, and one of the FortiProxy units keeps shutting down.

744312

The video filter prevents office.com to not load after the user logs in.

744430

The pencil button cannot used to edit fields in a policy.

744433

FortiProxy logs are not listing user names.

744563

The AND/OR logic is missing from the user group.

744569

The GUI should allow both the local user database and the remote user database to be selected at the same time.

744571

The GUI does not have the same matching criteria for authentication rules as the CLI.

744636

External files should be synchronized between blades.

744855

After upgrading to FortiProxy 7.0.0, some commands under config firewall profile-group are missing.

744857

After upgrading to FortiProxy 7.0.0, the link status for the aggregate interface is down in the GUI.

745115

The GUI does not display FSSO users on the User Monitor.

745212

The WAD crashes a with signal 11 when the video filter is being used.

745566

When CP9 is enabled on a FortiProxy 400E, HTTPS traffic fails.

745572

The WAD crashes at conn_pool_connection_error with signal 11 when the ICAP server cannot be reached.

746005

The GUI needs to allow the HTTP incoming port to be configured.

746007

Policies do not show the configured IP pool name in the GUI.

746009

When the IP pool is configured, the setting is not applied on outbound traffic.

746435

Configuring the ICAP server should not cause a crash.

746506

Stream-based antivirus scanning is not working for large files when using an ICAP local server.

746569

The options for the SSL/SSH inspection profile are not displayed correctly in the GUI.

746977

The forward server uses an invalid IP address with an explicit web proxy policy.

747250

The URL and IP external threat feeds are truncated.

747434

The ICAP server crashes when traffic is sent to the ICAP client.

748573

The set transparent command (under config firewall policy) is not working .

748764

The GUI does not let users configure an external malware block list.

748788

Security Profiles > Web Application Firewall is available in the GUI, but it is not used.

749432

After an FPX-4000E was rebooted, it started to automatically format the disk.

749625

The datadrv2 file is missing from FPX_VMWARE-v700-build0029-FORTINET.out.ovf.zip.

750600

During the antivirus scanning of an HTTP request, a segmentation fault occurs.

750641

When an SSH request is sent to an ICAP client with IPv6, a crash occurs.

750650

The WAD crashes when the HTTPS request tries to match the URL address and fast-policy-match is disabled.

750893

The WAD crashes multiple times at wad_http_clt_read_hdr with HTTP transparent proxy traffic.

751188

The remote server group field is missing from the ICAP profile in the GUI.

751303

The WAD crashes every few seconds.

751693

The WAD crashes with signal 6 when using web filtering with WISP enabled.

751811

The WAD informer is not learning the global system correctly.

751972

When using the proxy policy and the SDN connector dynamic address, traffic is blocked.

752125

The FPX-2000E, FPX-4000E, and FPX-400E models should support the unicast gateway for an HA Config-Sync cluster.

752354

The ICAP client crashes when sending FTP-over-HTTP traffic.

752410

The HTTP request does not match the policy when the proxy address is used with a specific (non-ALL) service.

752416

When the server setting is mismatched, the WAD sessions are cleared after a while.

753138

The SSH policy does not find matches when the address is set to a specific value.

753208

When IPS and application control are configured on a transparent proxy or SSH tunnel policy

753335

There are some issues with the ZTNA menu and pages in the GUI.

753422

When configuring a WAN-optimization policy, users should be able to set the values for the set ssl-ssh-profile and set webcache-https commands.

754499

Using the GUI or the diagnose wad user clear command to unauthenticate a user does not clear the user node in the kernel.

754572

When web caching is enabled, the image analyzer does not replace the blocked image.

754762

When an antivirus profile is enabled in a WAN-optimization proxy policy, the EICAR test file should be blocked when it is sent with HTTPS.

754969

The explicit FTP proxy policy selects a random destination port when the FTP client initiates the FTP session without using the default port.

755365

Firefox does not show the authentication pop-up message when explicit proxy is used.

755401

The WAD crashes multiple times at wad_http_body_move with signal 6.

755698

When the policy is not matched, user notes should not be cleared by the HTTPS request.

755706

The user monitor in the GUI is not displaying correct information.

755751

The kernel user should be refreshed.

755753

The WAD crashes at wad_diag_session_close.

755861

When upgrading FortiProxy, the units for the proxy-auth-timeout value need to be converted.

755878

The display is incorrect when configuring authentication rules in the GUI.

756364

The Policy & Objects > Policy table is not displaying users or user groups in the Source Address column.

756370

Using Insert Empty Policy > Above or Insert Empty Policy > Below creates a transparent policy instead of an explicit policy.

756402

The WAD crashes when there are multiple session-based user notes in WAD and IP-based authentication is triggered.

756421

In the GUI, the SSL Certificate SSL profile will not save without the server certificate.

756716

The WAD crashes at wad_hauth_start_usernum_report_task; afterward, the policy list in the worker is empty

Common vulnerabilities and exposures

FortiProxy 7.0.1 is no longer vulnerable to the following CVEs:

  • CWE-190
  • CWE-788
  • CVE-2021-41024

Visit https://fortiguard.com/psirt for more information.

Resolved issues

The following issues have been fixed in FortiProxy 7.0.1. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID Description
561711 The TLS 1.3 performance needs to be improved.

677234

Web pages included in the external list (FortiGuard Category Threat Feed) should be blocked when users try to access them through https://translate.google.com.

706786 The WAN-optimization daemon (WAD) crashes at wad_cert_picker_get_X509_issuer.

725373

When the SSL Negotiation log is enabled, there should be an SSL UTM log available.

726691

LACP does not work between a FortiProxy unit and a Cisco Catalyst 9500.

728641 The abbreviated handshake fails when a fatal illegal parameter is received.

733104

The transparent proxy policy is not matching the proxy address object URL pattern.

733135

Validating the SSL certificate should not time out.

734840

The web filter blocks websites in proxy mode because validating the SSL certificate fails.

737285

There is a certificate error when using the proxy policy and the website being accessed has an incomplete certificate chain.

738331 When an address group is configured with an excluded address object on a proxy policy, the excluded members should be excluded in the address group.
739091 The WAD crashes multiple times at wad_tunnel_msg_ssl_handshake_send with signal 11 (Segmentation error).
739610 When the ssh-policy-redirect option is disabled, SSH-over-HTTP traffic still tries to match the SSH policy.
739923 The WAD causes memory usage to increase from 50% to 75% after one day.
740222 The set filter-by file-type-and-size command is missing from under the config dlp sensor command.
741866 An overrun problem occurred in WAN optimization when using explicit proxy.
741867 Negative returns occurred in WAN optimization when using explicit proxy.

741869

Memory is corrupted when a transparent proxy policy is used with web caching, IPS, web filter, and antivirus scanning.

742108 The WAD crashed with signal 11 (Segmentation error) when the video filter was being used.
742141 When external resources reply with HTTP 301, 302, 307, or 308, the response codes are not accepted.

742178

After an interface is configured as the HA management interface, all input rules (such as Telnet, HTTP, SSH, and ping) are removed from the IP tables, and the interface cannot be accessed.

742241

When a security profile (such as antivirus, Application Control, or IPS) is active, traffic with the content encoding type of amz-1.0 does not work through the proxy.

742437

When a ZTNA rule is created in the GUI, it does not include the destination address or source interface.

742620

The WAD crashes at fts_ssl_port_open_with_keys with signal 11 when there is HTTPS traffic with WAN optimization and SSL offload enabled.

743168

The WAD crashes continuously with signal 11 (segmentation fault).

743259

The GUI is not displaying the number of hits or active sessions.

743379

After upgrading to FortiProxy 7.0, the maximum number of proxy address objects is reduced from 24,576 to 8,192.

743602

An “empty reply from server” error results when there is HTTPS traffic with WAN optimization.

743656

If there is an authentication scheme configured but no authentication rules, the WAD user receives a 403 Forbidden error.

743750

There were many WAD scan unit crashes.

743894

When downloading 10 million samples with WAN optimization enabled, the download will stop halfway through.

743927

When UTM is enabled, ICAP server sessions are not included in the total number of licensed sessions.

743975

The URL column should be available to add to the HTTP Transaction logs.

743976

When two FortiProxy units and in a Config -Sync cluster, both FortiProxy units have the same hdisk, and one of the FortiProxy units keeps shutting down.

744312

The video filter prevents office.com to not load after the user logs in.

744430

The pencil button cannot used to edit fields in a policy.

744433

FortiProxy logs are not listing user names.

744563

The AND/OR logic is missing from the user group.

744569

The GUI should allow both the local user database and the remote user database to be selected at the same time.

744571

The GUI does not have the same matching criteria for authentication rules as the CLI.

744636

External files should be synchronized between blades.

744855

After upgrading to FortiProxy 7.0.0, some commands under config firewall profile-group are missing.

744857

After upgrading to FortiProxy 7.0.0, the link status for the aggregate interface is down in the GUI.

745115

The GUI does not display FSSO users on the User Monitor.

745212

The WAD crashes a with signal 11 when the video filter is being used.

745566

When CP9 is enabled on a FortiProxy 400E, HTTPS traffic fails.

745572

The WAD crashes at conn_pool_connection_error with signal 11 when the ICAP server cannot be reached.

746005

The GUI needs to allow the HTTP incoming port to be configured.

746007

Policies do not show the configured IP pool name in the GUI.

746009

When the IP pool is configured, the setting is not applied on outbound traffic.

746435

Configuring the ICAP server should not cause a crash.

746506

Stream-based antivirus scanning is not working for large files when using an ICAP local server.

746569

The options for the SSL/SSH inspection profile are not displayed correctly in the GUI.

746977

The forward server uses an invalid IP address with an explicit web proxy policy.

747250

The URL and IP external threat feeds are truncated.

747434

The ICAP server crashes when traffic is sent to the ICAP client.

748573

The set transparent command (under config firewall policy) is not working .

748764

The GUI does not let users configure an external malware block list.

748788

Security Profiles > Web Application Firewall is available in the GUI, but it is not used.

749432

After an FPX-4000E was rebooted, it started to automatically format the disk.

749625

The datadrv2 file is missing from FPX_VMWARE-v700-build0029-FORTINET.out.ovf.zip.

750600

During the antivirus scanning of an HTTP request, a segmentation fault occurs.

750641

When an SSH request is sent to an ICAP client with IPv6, a crash occurs.

750650

The WAD crashes when the HTTPS request tries to match the URL address and fast-policy-match is disabled.

750893

The WAD crashes multiple times at wad_http_clt_read_hdr with HTTP transparent proxy traffic.

751188

The remote server group field is missing from the ICAP profile in the GUI.

751303

The WAD crashes every few seconds.

751693

The WAD crashes with signal 6 when using web filtering with WISP enabled.

751811

The WAD informer is not learning the global system correctly.

751972

When using the proxy policy and the SDN connector dynamic address, traffic is blocked.

752125

The FPX-2000E, FPX-4000E, and FPX-400E models should support the unicast gateway for an HA Config-Sync cluster.

752354

The ICAP client crashes when sending FTP-over-HTTP traffic.

752410

The HTTP request does not match the policy when the proxy address is used with a specific (non-ALL) service.

752416

When the server setting is mismatched, the WAD sessions are cleared after a while.

753138

The SSH policy does not find matches when the address is set to a specific value.

753208

When IPS and application control are configured on a transparent proxy or SSH tunnel policy

753335

There are some issues with the ZTNA menu and pages in the GUI.

753422

When configuring a WAN-optimization policy, users should be able to set the values for the set ssl-ssh-profile and set webcache-https commands.

754499

Using the GUI or the diagnose wad user clear command to unauthenticate a user does not clear the user node in the kernel.

754572

When web caching is enabled, the image analyzer does not replace the blocked image.

754762

When an antivirus profile is enabled in a WAN-optimization proxy policy, the EICAR test file should be blocked when it is sent with HTTPS.

754969

The explicit FTP proxy policy selects a random destination port when the FTP client initiates the FTP session without using the default port.

755365

Firefox does not show the authentication pop-up message when explicit proxy is used.

755401

The WAD crashes multiple times at wad_http_body_move with signal 6.

755698

When the policy is not matched, user notes should not be cleared by the HTTPS request.

755706

The user monitor in the GUI is not displaying correct information.

755751

The kernel user should be refreshed.

755753

The WAD crashes at wad_diag_session_close.

755861

When upgrading FortiProxy, the units for the proxy-auth-timeout value need to be converted.

755878

The display is incorrect when configuring authentication rules in the GUI.

756364

The Policy & Objects > Policy table is not displaying users or user groups in the Source Address column.

756370

Using Insert Empty Policy > Above or Insert Empty Policy > Below creates a transparent policy instead of an explicit policy.

756402

The WAD crashes when there are multiple session-based user notes in WAD and IP-based authentication is triggered.

756421

In the GUI, the SSL Certificate SSL profile will not save without the server certificate.

756716

The WAD crashes at wad_hauth_start_usernum_report_task; afterward, the policy list in the worker is empty

Common vulnerabilities and exposures

FortiProxy 7.0.1 is no longer vulnerable to the following CVEs:

  • CWE-190
  • CWE-788
  • CVE-2021-41024

Visit https://fortiguard.com/psirt for more information.