Fortinet opublikował najnowszą aktualizację oprogramowania dla urządzeń FortiAP o oznaczeniu 6.4.8. Aktualizacja obejmuje wiele udoskonaleń, między innymi usprawniono modele FAP-231F, 234 i 23jf, gdzie problem dotyczył błędnego działania portu konsoli do urządzenia. Aktualizacja ponadto naprawiła połączenia w standardzie 802.11n i 802.11ac, jak również skorygowana została przepustowość łącza w oparciu o standard 802.11ax, przy włączonej opcji PMF. Dzięki nowszej wersji, poprawiono przydzielanie sieci VLAN, przy uwierzytelnieniu RADIUS-MAC. Po więcej informacji zapraszam do dalszej części artykułu.
Aktualnie wspierane modele:
- FAP-231F,
- FAP-234F,
- FAP-23J,
- FFAP-431F,
- FAP-432F,
- FAP-433F
- FAP-831F
Rozwiązane problemy:
Bug ID | Description |
---|---|
421233 | FortiAP failed to disable wireless multimedia (WMM) settings in the QoS profile. |
606388 | Sometimes, FortiGate would report SSID’s from authorized FortiAP devices as „fake-ap-on-air”. |
651452 | The console port of FAP-231F, 234F and 23JF would occasionally lock-up. |
716641 | On local-standalone SSID, RADIUS authentication requests were not sent to the secondary RADIUS server when the first one was unreachable. |
719386 | Synchronize FortiPresence data reporting based on the system time of the WiFi Controller. |
724927 | FortiAP would take a long time to connect back to the WiFi Controller after implementing reboot from FortiAP CLI. |
733260 | Draeger Delta devices suffered from multicast packets loss for a long period of time. |
746769 | Fixed a Target Assert issue: ar_wal_peer.c:4578 Assertion 0 failedparam0 :zero, param1 :zero, param2 :zero . |
754299 | FortiAP devices previously connected to FortiLAN Cloud could not reconnect after some time. |
754327 | Fixed a dynamic VLAN assignment issue when RADIUS-MAC authentication was delayed. |
754775 | FortiAP might send corrupted IPv6 client information to FortiGate when reconnected. |
767608 | 802.11n and 802.11ac clients could not connect with local-standalone SSID. |
767941 | 802.11ax clients got low throughput when connected to an SSID with PMF set to optional. |
774055 | Captive-portal SSID with VLAN ID could not work as the DNS IP was blocked. |
776707 | Sometimes, FortiAP didn’t report LLDP info to the WiFi Controller. |
779712 | FortiAP would stop responding to SNMP queries sometimes. |
Common vulnerabilities and exposures
FortiAP 6.4.8 is no longer vulnerable to the following common vulnerabilities and exposures (CVE) references:
Bug ID | Description |
---|---|
786638 | Command injection in FortiAP CLI |
Znane problemy:
Bug ID | Description |
---|---|
645121 | FortiAP should report detected station information from radio1 and radio2 when FortiPresence is enabled. |
692160 | Wireless packets captured by FortiAP radio in Sniffer mode are corrupted. |
761298 | FAP-234F Bluetooth Low Energy (BLE) function cannot work. |
767916 | When wireless clients are connected to different radios of the same tunnel-mode SSID with static or dynamic VLAN, they cannot ping each other. |
795661 | Wireless clients cannot communicate with wired clients behind a switch connected to mesh-Ethernet bridge. |
Notatki producenta: FortiAP 6.4.8
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie