Producent oprogramowania Fortinet, udostępnił najnowszą wersję FortiClient o oznaczeniu 7.0.0. Dzięki nowej wersji, będziemy mogli się spodziewać poprawienia wielu błędów. Mowa tutaj o problemach przy połączeniach, gdzie tunel VPN powodował wiele problemów. W wersji 7.0.0, rozwiązano problem z autoryzującą poprzez FortiToken, ponieważ nie zawsze aplikacja żądała potwierdzania tokenem. Problem dotyczący połączenia VPN przed zalogowaniem do Windowsa, został skorygowany. Po aktualizacji oprogramowania, wyświetlane informacje na FortiGate są bardziej dokładne i nie mają już tylu problemów. Po więcej szczegółowych informacji, zapraszam do dalszej części artykułu.
Wspierane system:
Windows:
- Microsoft Windows 10 (32-bit and 64-bit)
- Microsoft Windows 8.1 (32-bit and 64-bit)
- Microsoft Windows 7 (32-bit and 64-bit)
- Microsoft Windows Server 2019
- Microsoft Windows Server 2016
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2012
- Microsoft Windows Server 2008 R2
MacOs:
- macOS Big Sur (wersja 11)
- macOS Catalina (wersja 10.15)
- macOS Mojave (wersja 10.14)
Linux:
- Ubuntu od 16.04
- CentOS od 7.4
- Red Hat od 7.4
Rozwiązane problemy:
Zero Trust Telemetry
Endpoint control
Bug ID | Description |
---|---|
693087 | EMS should show Owner for an endpoint device. |
Logs
Bug ID | Description |
---|---|
599560 | Notification page reports USB block alert source as unknown. |
654336 | Event log epenfeatures contains firewall, which is disabled. |
664452 | Endpoint Control logs improvement. |
700466 | Create proper logs and message when license expires. |
Malware Protection and Sandbox
Bug ID | Description |
---|---|
602768 | Cloud-based malware detection does not honor allowlisted files. |
704823 | Antivirus scan does not start. |
Remote Access
Bug ID | Description |
---|---|
617420 | Remote Access VPN with prelogon without user interaction. |
645174 | FortiClient sometimes does not use the remoteauthtimeout value configured on the FortiGate for SSL VPN. |
671392 | Windows restart does not remove SSL VPN tunnel that VPN before logon established. |
677766 | When VPN tunnel goes down, the single host route for the VPN server stays. |
682675 | SSL VPN users cannot set new PIN after it has expired when using RSA RADIUS authentication. |
688043 | VPN before logon does not prompt for FortiToken request. |
689176 | IPsec VPN failover to SSL VPN when using VPN before logon does not work properly. |
690769 | User cannot start VPN connection with ENTER key. |
695054 | IPsec VPN disconnects right after the tunnel establishes. |
695133 | DNS resolution is inconsistent when IPv6 is enabled on the desktop. |
698177 | Public IP address detection and SSL VPN. |
Web Filter and plugin
Bug ID | Description |
---|---|
696581 | FortiClient extension pauses download when extension is installed but not in use. |
Other
Znane problemy do rozwiązania:
FortiSASE SIA
Bug ID | Description |
---|---|
701552 | FortiSASE SIA tunnel reconnection issues after FortiSASE SIA portal removes VPN user. |
Application Firewall
Bug ID | Description |
---|---|
710910 | The Application Firewall tab becomes visible after reboot when it should remain hidden. |
GUI
Bug ID | Description |
---|---|
708855 | GUI shows site is unavailable when blocked. |
Endpoint control
Bug ID | Description |
---|---|
699686 | EMS does not receive software inventory from FortiClient (Windows). |
702660 | Switching Active Directory users does not modify user details in EMS Endpoints pane. |
FSSOMA
Bug ID | Description |
---|---|
705256 | SSOMA fails to call WTSQueryUserToken. |
Zero Trust Telemetry
Bug ID | Description |
---|---|
587327 | Device detection/VPN autoconnect frequency is too often. |
652647 | FortiClient fails to upload large diagnostics tool result file to EMS. |
687611 | FortiClient should calculate AD group-based policy rule for tags. |
693928 | After FortiClient successfully migrates to a new EMS, it does not remove original EMS from EMS list. |
697795 | FortiClient fails to calculate on-fabric result. |
701552 | SASE SIA tunnel reconnection issues after SASE SIA portal removes VPN user. |
702660 | Switching AD users does not modify user details in EMS Endpoints table. |
705010 | EMS shows endpoints with incorrect usernames. |
705664 | FortiGate waits about one minute to get ztna-ems-tag update. |
714131 | Migrating FortiClient to a different server fails when connection key is enabled. |
Malware Protection and Sandbox
Bug ID | Description |
---|---|
590688 | FortiClient says FortiSandbox scan does not support file type when extension is supported and enabled on FortiSandbox. |
683027 | FortiClient (Windows) shows quarantine message, even if Application Firewall is not installed and quarantine mode will not work. |
691328 | FortiClient upgrade does not upgrade antivirus engine as deployed through an EMS installer. |
705761 | FortiClient (Windows) does not block USB drives when removable media access is configured to block WPD devices. |
713557 | Exceptions do not work for AntiExploit module. |
Remote Access
Bug ID | Description |
---|---|
700092 | VPN does not connect when using domain user account. |
700440 | Application-based split tunneling does not work. |
702965 | Host check interval does not work as expected after PC has previously gone into sleep mode. |
703939 | FortiClient does not send UID to SSL VPN daemon. |
706023 | FortiClient (Windows) loses DNS settings after restarting computer. |
707882 | IPsec VPN fails to autoconnect and displays Failed to launch IPsec service error. |
709001 | SSL VPN host check validation does not work for SAML user. |
710603 | VPN resets with each EMS push. |
711227 | Per-user autoconnect starts autoconnecting before logging onto Windows. |
711402 | Per-user autoconnect does not establish and remains connected after logging onto Windows. |
713909 | If Enable VPN before Windows is enabled and there are multiple tunnels configured, there is long delay before Windows login prompt. |
714564 | SAML connection stays in connecting state and never return with error when FortiGate gateway is inaccessible. |
Console
Bug ID | Description |
---|---|
690679 | EMS cannot tag endpoints based on nested AD groups. |
703213 | Reusing/sharing SAML identity provider cookie. |
707440 | Clear Logs button on Settings page is disabled after unlocking settings. |
Vulnerability Scan
Bug ID | Description |
---|---|
630202 | Vulnerability Scan cannot detect Zoom.exe installer. |
Logs
Bug ID | Description |
---|---|
709729 | realtime_scan log disappears after ten seconds. |
Other
Bug ID | Description |
---|---|
69182 | FortiClient does not support the pound (£) sign. |
689936 | GUI issue when connecting to IPsec VPN using FortiTray. |
Notatki producenta: FortiClient 7.0.0
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie