Resolved issues
The following issues have been fixed in FortiProxy 7.0.12. For inquiries about a particular bug, please contact Customer Service & Support.
|
Bug ID |
Description |
|---|---|
|
772418 |
Fix ICAP client not forwarding response when host matches FQDN. |
|
834299 |
SSH command filter no longer works after prompt change. |
|
861899 |
FortiView Application Bandwidth widget shows nothing. |
|
870099 |
LDAP cache was not updated properly after the user group changed in Active Directory server. |
|
873073 |
WAD debug filter does not work properly with SSL deep-inspection using hardware crypto. |
|
876758 |
SSH public keys are lost after upgrading from Beta 1 to latest interim build, and they can no longer be configured. |
|
877836 |
Multiple attempts to join a domain with wrong credentials causes WAD to crash. |
|
883131 |
Correlation log does not show security action when application category is unknown. |
|
892116 |
Issue with the WAD debug filter on |
|
896345 |
Fine-grained user/group level authorization timeout configuration. |
|
896476 |
FortiProxy rejects CONNECT request with body and extra data. |
|
903925, 923610, 923847, 931277, 932620, 932623, 912281, 928710, 938018, 934477 |
Fix some GUI issues. |
|
905188 |
Unexpect hang-up on FPX-4000E. |
|
909271 |
Authenticated users using an IP-based authentication rule may need to be re-authenticated per request. |
|
910329 |
Clean up HA Active-Active mode related CLI options. |
|
913013 |
Update voltage monitoring with official Supermicro values. |
|
913705, 913955 |
Remove |
|
914303 |
HTTP transaction log is recorded as "https" scheme for "Ftp over HTTP" transaction. |
|
914533 |
FortiGate DLP filter EXE files does not work on Windows. |
|
917330 |
Some non-http traffic was redirected to WAD unexpectedly when L7 address exists in policy. |
|
917412 |
FPX-2000G and FPX-4000G STA and UID LED color issue. |
|
919643 |
FortiProxy kernel memory leak. |
|
920083 |
EIP of mgmt-intf is mistakenly moved from secondary FPX to the primary in an AWS A-P HA cluster. |
|
921158 |
Issue with format string that causes httpsd and CLI crash. |
|
921642 |
Memory leak in client certificate cache for virtual server access proxy. |
|
921902 |
LDAP search type default is unset due to an incorrect default value. |
|
924449 |
Shaping policy matching failure. |
|
924524 |
WAD crashes at wad_fw_policy_check_user when authorization is required for FTPS login on the FortiProxy. |
|
924586 |
FortiProxy HA config-sync-only secondaries receive system updates triggered by both updated and hasync. |
|
924740 |
Need to verify filters of wad debug trace and make sure all the necessary info is logged and filter works properly. |
|
924919 |
Explicit FTPS authentication with transparent policy does not work. |
|
925043 |
FortiProxy trial license is invalid when memory is more than 2 GB while the minimum required memory is 4GB. |
|
926178, 930776 |
Add option to enable/disable application level category policy match for deep inspection . |
|
926491 |
WAD policy matching crashed at matching the source address due to null source and destination addresses in dummy policy. |
|
926927 |
Fix for a crash caused by a missing safe check during code porting. |
|
927004 |
Validate address group members when config is loaded. If an error occurs while loading iptables rules for a specific policy, skip only the malformed policy instead of aborting the policy loading as a whole. |
|
927838 |
FortiProxy matches user to wrong user group and hits the wrong policy. |
|
928979 |
When multiple ports are configured for a firewall policy's service, only traffic to the first port matches the policy. |
|
929971 |
Fix scanunit error logs on non-error case. |
|
931778 |
Fix HTTP request to FQDN address not directed to WAN when |
|
932475 |
FortiProxy not showing proxy policy after restoring the configuration, but it is shown in the CLI. |
|
932487 |
WAD worker memory usage slowly increased. |
|
933593 |
Show full user-agent in the http-transaction log when extended-log is enabled |
|
935749 |
Explicit policy was not added to policy list when the policy changes its web-proxy. |
| 936409 |
FortiProxy did not support nested addrgrp definition, which caused a configuration error while upgrading. |
|
929821 |
"Bad gateway" error message and httpsd process exits with segmentation fault when generating a TAC report from GUI. |
|
927316 |
SNAT uses interface IP address instead of address from IP pool with forward server. |
|
933030 |
Disable netflow and sflow commands which are not supported by FortiProxy. |
|
933588 |
Build compile error during upgrade. |
|
934498 |
When log-http-transaction is enabled, forward traffic to WAD only when UTM is enabled or the action of the policy is deny. |
|
939241 939575 |
High CPU when DNS server is busy. |
|
939160 |
WAD crash on traffic when VDOM is enabled and a global webfilter profile is attached to a policy. |
|
935917 |
The respective corresponding sandbox should be displayed correctly. |
|
936513 |
DNS is not updated with HA reserved mgmt interface.. |
Common vulnerabilities and exposures
FortiProxy 7.0.12 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.
|
Bug ID |
CVE reference |
|---|---|
|
923315 |