Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.2.6. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

772418

Fix ICAP client not forwarding response when host matches FQDN.

834299

SSH command filter no longer works after prompt change.

870099

LDAP cache was not updated properly after the user group changed in Active Directory server.

876758

SSH public keys are lost after upgrading from Beta 1 to latest interim build, and they can no longer be configured.

883131

Correlation log does not show security action when application category is unknown.

892116

Issue with the WAD debug filter on vd_id and dst6 or src6.

896476

FortiProxy rejects CONNECT request with body and extra data.

903925, 931277, 932620, 932623, 912281, 934477, 928710, 938018

Fix some GUI issues.

905188

Unexpect hang-up on FPX-4000E.

906862

FortiProxy ESXi VM reboots randomly.

909271

Authenticated users using an IP-based authentication rule may need to be re-authenticated per request.

910841

Fix DLP signature update version number.

910978

FortiNBI does not support PAC file and does not work using manually configuration.

913013

Update voltage monitoring with official Supermicro values.

913705, 913955

Remove extended-log option in AV/FF/DLP and extend log-http-transaction to three options: all, utm, and disable.

914533

FortiGate DLP filter EXE files does not work on Windows.

917330

Some non-http traffic was redirected to WAD unexpectedly when L7 address exists in policy.

917412

FPX-2000G and FPX-4000G STA and UID LED color issue.

919463

FortiProxy kernel memory leak.

920083

EIP of mgmt-intf is mistakenly moved from secondary FPX to the primary in an AWS A-P HA cluster.

921902

LDAP search type default is unset due to an incorrect default value.

922092

WAD debug settings do not show the correct category.

924586

FortiProxy HA config-sync-only secondaries receive system updates triggered by both updated and hasync.

924740

Need to verify filters of wad debug trace and make sure all the necessary info is logged and filter works properly.

924919

Explicit FTPS authentication with transparent policy does not work.

926178, 930776

Add option to enable/disable application level category policy match for deep inspection.

926927

Fix for a crash caused by a missing safe check during code porting.

927004

Validate address group members when config is loaded. If an error occurs while loading iptables rules for a specific policy, skip only the malformed policy instead of aborting the policy loading as a whole.

929232

Non-root VDOM explicit proxy DNS fails.

929971

Fix scanunit error logs on non-error case.

931778

Fix HTTP request to FQDN address not directed to WAN when dst_address includes wildcard FQDN.

932475, 935925

FortiProxy not showing proxy policy after restoring the configuration, but it is shown in the CLI.

932487

WAD worker memory usage slowly increased.

933593

Show full user-agent in the http-transaction log when extended-log is enabled

934833

Fix a bug preventing Chrome from installing the FNBI extension.

935749

Explicit policy was not added to policy list when the policy changes its web-proxy.

935917

The respective corresponding sandbox should be displayed correctly.

936409

FortiProxy did not support nested addrgrp definition, which caused a configuration error while upgrading.

929821

"Bad gateway" error message and httpsd process exits with segmentation fault when generating a TAC report from GUI.

933030

Disable netflow and sflow commands which are not supported by FortiProxy.

933588

Build compile error during upgrade.

927635

Web proxy in transparent mode cannot match interfaces.

934498

When log-http-transaction is enabled, forward traffic to WAD only when UTM is enabled or the action of the policy is deny.

669491

Some online help links do not work.

937773

When HA is enabled, the Security Fabric, Physical Topology, and Logical Topology pages fail to load correctly.

927316

SNAT uses interface IP address instead of address from IP pool with forward server.

938767

Alternative DNS does not work.

939241

939575

High CPU when DNS server is busy.

937734

Crash with custom IPs and implicit FTPS traffic.

939160

WAD crash on traffic when VDOM is enabled and a global webfilter profile is attached to a policy.

936513

DNS is not updated with HA reserved mgmt interface.

Common vulnerabilities and exposures

FortiProxy 7.2.6 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

923315

CVE-2023-45583

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.2.6. For inquiries about a particular bug, please contact Customer Service & Support.

Bug ID

Description

772418

Fix ICAP client not forwarding response when host matches FQDN.

834299

SSH command filter no longer works after prompt change.

870099

LDAP cache was not updated properly after the user group changed in Active Directory server.

876758

SSH public keys are lost after upgrading from Beta 1 to latest interim build, and they can no longer be configured.

883131

Correlation log does not show security action when application category is unknown.

892116

Issue with the WAD debug filter on vd_id and dst6 or src6.

896476

FortiProxy rejects CONNECT request with body and extra data.

903925, 931277, 932620, 932623, 912281, 934477, 928710, 938018

Fix some GUI issues.

905188

Unexpect hang-up on FPX-4000E.

906862

FortiProxy ESXi VM reboots randomly.

909271

Authenticated users using an IP-based authentication rule may need to be re-authenticated per request.

910841

Fix DLP signature update version number.

910978

FortiNBI does not support PAC file and does not work using manually configuration.

913013

Update voltage monitoring with official Supermicro values.

913705, 913955

Remove extended-log option in AV/FF/DLP and extend log-http-transaction to three options: all, utm, and disable.

914533

FortiGate DLP filter EXE files does not work on Windows.

917330

Some non-http traffic was redirected to WAD unexpectedly when L7 address exists in policy.

917412

FPX-2000G and FPX-4000G STA and UID LED color issue.

919463

FortiProxy kernel memory leak.

920083

EIP of mgmt-intf is mistakenly moved from secondary FPX to the primary in an AWS A-P HA cluster.

921902

LDAP search type default is unset due to an incorrect default value.

922092

WAD debug settings do not show the correct category.

924586

FortiProxy HA config-sync-only secondaries receive system updates triggered by both updated and hasync.

924740

Need to verify filters of wad debug trace and make sure all the necessary info is logged and filter works properly.

924919

Explicit FTPS authentication with transparent policy does not work.

926178, 930776

Add option to enable/disable application level category policy match for deep inspection.

926927

Fix for a crash caused by a missing safe check during code porting.

927004

Validate address group members when config is loaded. If an error occurs while loading iptables rules for a specific policy, skip only the malformed policy instead of aborting the policy loading as a whole.

929232

Non-root VDOM explicit proxy DNS fails.

929971

Fix scanunit error logs on non-error case.

931778

Fix HTTP request to FQDN address not directed to WAN when dst_address includes wildcard FQDN.

932475, 935925

FortiProxy not showing proxy policy after restoring the configuration, but it is shown in the CLI.

932487

WAD worker memory usage slowly increased.

933593

Show full user-agent in the http-transaction log when extended-log is enabled

934833

Fix a bug preventing Chrome from installing the FNBI extension.

935749

Explicit policy was not added to policy list when the policy changes its web-proxy.

935917

The respective corresponding sandbox should be displayed correctly.

936409

FortiProxy did not support nested addrgrp definition, which caused a configuration error while upgrading.

929821

"Bad gateway" error message and httpsd process exits with segmentation fault when generating a TAC report from GUI.

933030

Disable netflow and sflow commands which are not supported by FortiProxy.

933588

Build compile error during upgrade.

927635

Web proxy in transparent mode cannot match interfaces.

934498

When log-http-transaction is enabled, forward traffic to WAD only when UTM is enabled or the action of the policy is deny.

669491

Some online help links do not work.

937773

When HA is enabled, the Security Fabric, Physical Topology, and Logical Topology pages fail to load correctly.

927316

SNAT uses interface IP address instead of address from IP pool with forward server.

938767

Alternative DNS does not work.

939241

939575

High CPU when DNS server is busy.

937734

Crash with custom IPs and implicit FTPS traffic.

939160

WAD crash on traffic when VDOM is enabled and a global webfilter profile is attached to a policy.

936513

DNS is not updated with HA reserved mgmt interface.

Common vulnerabilities and exposures

FortiProxy 7.2.6 is no longer vulnerable to the following CVE reference. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

923315

CVE-2023-45583