Fortinet opublikował nową wersję FortiClient EMS 7.0.9! Nowa wersja EMS jest pozbawiona problemów związanych między innymi z przydzielaniem prawidłowej polityki na podstawie grupy użytkowników, poprawiono synchronizację pomiędzy Active Directory a EMS, poprawiono wydajność aplikacji oraz funkcjonowanie interfejsu administratora. Po więcej informacji, zapraszam do dalszej części artykułu.
Rozwiązane problemy (FortiClient EMS 7.0.9):
Endpoint management
Bug ID | Description |
---|---|
864708 | Exclude Endpoint From Management does not work for groups but works when applied per-device. |
880639 | Changing client’s group in Active Directory (AD) does not sync to EMS. |
890943 | Google user enumeration enumerates over the whole domain if only a sub-organization unit is specified. |
904508 | FortiClient (Linux) group assignment rules by operating system filter option does not capture all Linux versions. |
909331 | EMS DBNull error occurs while syncing AD. |
917055 | Domain machines move to Other Endpoints. |
Endpoint policy and profile
Bug ID | Description |
---|---|
909361 | EMS does not assign policy based on user group. |
913053 | EMS fails to match AD-joined device to default policy after the device is matched to a specific policy at least once. |
Deployment and installers
Bug ID | Description |
---|---|
825169 | Zero trust network access (ZTNA) feature under deployment package feature selection does not support macOS. |
917921 | User cannot create FortiClient deployment package. |
License
Bug ID | Description |
---|---|
820291 | FortiClient cannot register with EMS after EMS releases the ZTNA license used by Chrome. |
898169 | User cannot redistribute licenses to multiple EMS sites. |
Logs
Bug ID | Description |
---|---|
877262 | User cannot delete endpoint events. |
Zero Trust tags
Bug ID | Description |
---|---|
919888 | Logged in domain tag does not calculate if user is local. |
Performance
Bug ID | Description |
---|---|
903414 | Error – Update Service – DAS command is retried (attempt 1) after update to 7.0.8. |
926872 | FortiClient Cloud fcmdaemon crashes. |
Dashboard
Bug ID | Description |
---|---|
821570 | Vulnerability count between vulnerability widgets and the actual number of vulnerabilities does not match. |
887564 | Login to EMS license registration prompt results in Server encountered an error, please try again later error. |
Install and upgrade
Bug ID | Description |
---|---|
861179 | Procedure for upgrading EMS always on high availability in multisubnet environment is unclear. |
892968 | On upgraded FortiClient Cloud, endpoint policy modification shows GUI error after saving changes. |
898831 | Upgrading EMS from 7.0.7 to 7.0.8 fails with The INSERT statement conflicted with the FOREIGN KEY constraint „FK__group_con__group error. |
907336 | Upgrading EMS from 7.0.7 to 7.0.8 gets stuck and never finishes. |
Multitenancy
Bug ID | Description |
---|---|
820803 | License distribution modal shows incorrect information. |
ZTNA connection rules
Bug ID | Description |
---|---|
923148 | Revoking ZTNA certificate unintentionally causes ZTNA TCP forwarding to work inconsistently. |
Other
Bug ID | Description |
---|---|
872897 | EMS request data size maximum limit is too small for some cases (django.core.exceptions.RequestDataTooBig). |
Znane problemy (FortiClient EMS 7.0.9):
Multitenancy
Dashboard
Bug ID | Description |
---|---|
817485 | Drilldown on macOS vulnerability includes unrelated vulnerabilities. |
Endpoint management
Endpoint policy and profile
Bug ID | Description |
---|---|
466124 | User cannot change <nat_alive_freq> value. |
826013 | Setting Vulnerability Scan patch status to Not does not work. |
826940 | EMS does not save <temp_whitelist_timeout> in an endpoint profile. |
833819 | Backing up configuration files on FortiClient Cloud results in import errors. |
925199 | GUI does not save the Sandbox authorization status after saving profile. |
License
Bug ID | Description |
---|---|
823458 | EMS with Endpoint Protection Platform (EPP)-only license and ZTNA feature enabled reports EPP license as consumed but fails to quarantine endpoint. |
823690 | EMS includes Removable Media Access feature when using ZTNA user-based license. |
827875 | Non-default site’s License information page shows irrelevant license information. |
828944 | EMS does not show A new license has been detected… if synced with FortiCloud account. |
846993 | EMS with multitenancy enabled wipes license from multiple sites. |
868174 | EMS shows features for future license. |
Install and upgrade
Bug ID | Description |
---|---|
820546 | EMS disables New EMS Version is available for deployment EMS alert after upgrade. |
Zero Trust tagging
Bug ID | Description |
---|---|
765375 | User in Active Directory Group Zero Trust Network Access rule does not identify domains. |
810778 | FortiClient tag information is not shared equally to connected FortiGate Fabric devices. |
815736 | EMS fails to apply NOT for On-Fabric Status rule while creating a new tag. |
843774 | EMS ZTNA Monitor shows VPN connected IP address when IP address range matches with LAN IP address. |
911533 | Active Directory group zero trust network access tag is not calculated on EMS and FortiClient. |
Deployment and installers
System Settings
Bug ID | Description |
---|---|
807340 | EMS tries to connect to FortiGuard Anycast server on port 8000. |
829631 | User cannot disable Delete Timeout option. |
861109 | EMS does not send email alerts for AD events. |
Chromebook
Bug ID | Description |
---|---|
777957 | EMS assigns the wrong profile. |
Administration
Bug ID | Description |
---|---|
678899 | Persisting LDAP configuration in multitenancy global/default/non-default administration users. |
828490 | EMS fails to update email address from personal information from FortiClient. |
913251 | Viewing endpoint details results in API error for administrators with restricted permissions. |
924646 | Your permissions might have been updated message displays on endpoints with vulnerability/antivirus scan request with endpoint administrator. |
Performance
Bug ID | Description |
---|---|
731097 | Updating or disabling policy assigned to large number of AD endpoints takes long time to process. |
759729 | Possible slow httpd file handle leak. |
Configuration
Bug ID | Description |
---|---|
745913 | SMTP configuration fails authentication. |
Endpoint control
Bug ID | Description |
---|---|
776626 | FortiClient may fail to get Web Filter custom message when EMS runs in high availability mode. |
813439 | FortiClient registered with EMS IP address does not deregister from EMS when Enforce invitation-only registration for is set to ALL. |
813531 | EMS does not push profile to endpoints if they connect to EMS after enabling the feature under EMS System Settings. |
863131 | GUI does not show or shows inconsistent quarantine files. |
GUI
Bug ID | Description |
---|---|
717433 | Patching a vulnerability for a specific endpoint patches it on others. |
731074 | Importing the same JSON file for zero trust tagging twice introduces duplicate tags. |
793313 | Detailed deployment states list does not fit in window. |
811774 | EMS with Remote Access-only license shows unrelated feature options on GUI. |
819205 | License widget shows Forensic license as NaN used of X when no license is in use. |
Malware Protection and Sandbox
Bug ID | Description |
---|---|
793926 | FortiShield blocks spoolsv.exe on Citrix virtual machine servers. |
ZTNA connection rules
Bug ID | Description |
---|---|
838317 | ZTNA status display should be updated in Endpoint Details. |
872353 | Zero trust tag user notification message does not display. |
Upgrade
Bug ID | Description |
---|---|
918021 | EMS cannot enforce user verification after upgrade from 6.4.8. |
Logs
Bug ID | Description |
---|---|
856952 | EMS is missing update daemon logs. |
Software Inventory
Bug ID | Description |
---|---|
924530 | Install count sort under software inventory does not work. |
Onboarding
Bug ID | Description |
---|---|
819203 | Authorized user group name should be full path. |
820060 | EMS displays same device list with the same login and registration LDAP user on verified user and unverified user tables. |
Fabric devices
Bug ID | Description |
---|---|
850144 | FortiClient Cloud connection fails/breaks during HA failover. |
Other
Bug ID | Description |
---|---|
585763 | User cannot login to FortiClient cloud if they used the same browser for login to on-premise EMS. |
766163 | Improve browser compatibility with FortiClient Cloud. |
797264 | FortiClient cannot update signatures from FortiManager. |
832144 | User cannot call EMS APIs. |
887172 | EMS fails to get update from FortiManager. |
Notatki producenta: FortiClient EMS 7.0.9
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie