FortiManager 5.6.6
Właśnie wyszła aktualizacja oprogramowania dla FortiManager ! Menedżer został dzisiaj obdarzony aktualizacją o numerze 5.6.6, a my przedstawiamy zmiany które wprowadził producent, warto zwrócić uwagę na ilośc naprawionych błędów przez producenta, dlatego też zachęcamy do lektury jak i do aktualizacji urządzenia.
Wprowadzone poprawki:
AP Manager
Bug ID Description
450434 The „wtp-mode” is unset after changed AP configuration from AP Manager.
496657 AP Manager GUI’s device list is missing some FortiGate devices with managed APs.
500022 FortiManager should let users to select FortiAP from firmware list.
504394 The WiFi profile for FAP221E should display RADIO 2.
509769 When attempting to assign the default profile to FAP221E, FortiManager returns an error on
unknown wtp-ip.
Device Manager
Bug ID Description
480400 FortiManager does not show the correct FortiGate’s system time under Device Manager.
488577 FortiManager GUI should display more than 50 SD-WANs to allow more firewalls to be managed.
491367 User may not be able to import policies it take a long time to load zone mapping.
491926 Renaming ADOM interface during import fails to add policies.
492801 When FIPS is enabled, the AES256 option should be available on FortiManager’s VPN phase1.
494537 Virtual switch-interface moves to root VDOM after changing it directly on FortiGate 140D-POE.
494923 IKE version grayed out in existing tunnels, unlike FortiOS GUI.
495785 Import process keeps loading and becomes unresponsive where there are 7000 policies configured on FortiGate.
500177 FortiManager does not push IPsec Phase1 XAUTH user group configuration to the firewall.
500293 FortiManager fails to configure Alert email settings on no management VDOM when FortiGate has no disk.
503926 Import should simply add all SD-WAN status check entries to FortiManager without any error.
505916 Copying firewall policy from one policy package to another causing source policy package to go in to Modified state.
509329 Importing policies may consume high CPU resources.
Global ADOM
Bug ID Description
482925 Internet Service destination is not displayed in IPv4 Header/Footer Policy in Global ADOM.
465511 Task Monitor does not give the exact status of total and pending tasks when an automaticinstall is performed from the Global ADOM.
HA
Bug ID Description
500682 Cluster members should be able to ping each other if there are no trusted host restrictions.
Policy and Objects
Bug ID Description
293781 If reset operation is done via FortiGate’s GUI, new Hit Count details should be reflected in FortiManager’s GUI.
453702 FortiManager should be able to filter policy using Hit Count, Bytes, Packets, First Used, or Last Used.
459753 The message, waiting for other session id (xxxx), username (xxxxx), should be truncated.
461772 Wildcard FQDN should be available to be selected when editing firewall policy.
467535 Explicit proxy policy should be configurable with Application Profile that blocks Proxy Category.
473973 Drag-and-drop should not allow coexisting of both security profiles and profile groups.
474629 When Security Profile Groups are created on the FortiManager, they are all pushed to all FortiGates on the next policy install.
476220 Users are unable to edit objects from the Explicit Proxy Policy view within a 5.4 ADOM.
476227 FortiManager should not clear any filters applied on Policy or Objects when admin locks the ADOM or changes the view.
479258 The import policy operation on one device should not cause other packages to change status.
492293 When selecting an object on a policy with many objects, the user still needs to scroll down to find the highlighted object.
492893 Installing custom IPS and Application Control signatures with the same Attack ID will cause install to fail.
494253 FortiManager may not display all service objects when it encounters an error on an object.
496827 Users are unable to delete LDAP server if user group is deleted before removing the LDAP members.
498642 LDAP browse from ADOM objects does not work if the primary LDAP server is not reachable.
499721 Cloning replacement message group does not keep custom HTML rather sets to default.
501313 Policy Package Clone fails caused by invalid installation targets.
501477 Push to device function installs all the address objects to FortiGate even when the objects are not being used.
502047 Policy install fails when IP pool object type is changed from fixed port range to overload.
503664 Right-pane object selector does not show profile groups.
505469 User may not be able to install an external CA certificate.
507677 After creating an IPS filter, it is not possible to edit it in order to add or remove certain signatures.
507919 FortiManager must recognize that internet-service-custom object is part of master internet-service object and need to be installed or imported properly.
508324 Policy package status should remain synchronized after cloning a policy packing and its installation targets are removed.
508456 In workspace mode, when a referenced object is deleted, but the changes are discarded, FortiManager leaves behind the object reference in the policy, despite the address object already deleted.
508584 wisp-servers should be available in GUI under the advanced web filter options.
509173 Policy Package Install may fail after upgrading from 5.4.5 to 5.6.4.
509185 FortiManager may install default certificate instead of the dynamically mapped certificate.
509790 When creating a new LDAP user on FortiManager, the LDAP browser ID column is showing the user cn instead of SAMAccount.
509854 If firewall address groups are recursively defined, FortiManager may run into infinite loop. This causes the data check to fail causing the security console daemon to crash.
510936 Adding a new device to address object should not set the interface to any for previous associated devices.
512167 FortiManager may not be able to configure a custom IPS signature due to change with „–protocol” on FortiGate.
Revision History
Bug ID Description
473169 Users are unable to proceed to device install screen through install wizard if default device selection for ADOM is set to unselect all.
477678 FortiManager should not unset admin-scp when it is set as enabled.
484608 Installation fails when creating a dial-up VPN with peer type set to use a dial-up user group.
486536 Policy package install fails due to VIP overlap error with FQDN VIP.
490500 RADIUS source IP and VAP errors occur when installing a policy that has security profiles on FortiWiFi-60E.
499734 Install attempt to any of the managed devices may hang due to null interface within system DHCP server entries.
504382 After setting a ssl/ssh profile with Multiple Clients Connecting to Multiple Servers and setting a non-CA certificate in the CA certificate field, and then selecting Protecting SSL Server with a non-CA certificate, FortiManager returns an error during install.
508080 FortiManager pushes a lot of move commands to FortiGate when moving a policy from top to bottom.
515102 When installing policy package, FortiManager should not apply media type parameter on VLAN
interfaces.
Script
Bug ID Description
459030 Changes made on ha-mgmt-interface via CLI script should be installed.
499342 When running a CLI script on Policy Package/ADOM, a firewall address with .067 (example 10.10.10.067/32) is configured. The script runs without error. The subnet is accepted but the address is configured as .55 (10.10.10.55/32) instead.
507394 FortiManager may return an error, Error:response with errors, when creating a new script.
Script
Bug ID Description
478050 When FortiManager provides services to FortiGate HA, FortiManager shows duplicate entries under FortiGuard > Package Management > Service Status after the FortiGate failover.
501456 Web filter license and service should activate or deactivate immediately after contract is received or withdrawn via update process.
508469 FortiManager may render the values for the horizontal axis with a gray area.
System Settings
Bug ID Description
469471 FortiManager is not able to resolve IP address for the domain name, smtp.office365.com.
474712 Auto-backup process does not work and results in out-of-sync FortiGate configuration in Backup ADOM.
488836 Wildcard TACACS+ admin should be able to access more than one ADOM.
499066 FortiManager cannot verify PKI admin client certificate if the CA chain has more than two certificates.
510459 The device lock and unlock actions should generate event logs.
VPN Manager
Bug ID Description
481717 VPN Monitor may not show some tunnels connections.
504541 FortiManager should allow users to upload AP profiles and create new AP Profiles under 5.2 ADOM.
504957 VPN Manager Monitor took more than 10 minutes to load page with 16000 tunnels.
4785376 FortiManager is unable to install VPN script and install log reports duplicated VPN remote gateways.
Others
Bug ID Description
492852 After enabling workflow, there is high consumption on CPU resources caused by the svc dvmdb reader process.
494072 Central DNAT is incorrectly translated to Central SNAT in Japanese language on GUI.
501485 FortiManager should not change Web Filter Local Category ID during ADOM upgrade.
501507 Strong-crypto parameter should be visible using JSON API.
507434 Console unable to accept username with space character.
Znane problemy:
Device Manager
Bug ID Description
506163 FortiManager GUI may not display zone members.
506697 Logical interfaces on FortiGate are not shown under the HA port monitor page on the FortiManager.
Policy & Objects
Bug ID Description
510929 During import, there is no notification to remind users that some objects may be renamed.
511717 Policy package install fails intermittently when installing traffic shaping configuration to FortiGate.
System Settings
Bug ID Description
508680 Setting for specified policy package with in admin user is gone after ADOM upgrade.
Others
Bug ID Description
511580 The category-override setting under web filter profile may be changed after upgraded FortiManager.
512410 FortiManager’s Master unit may no delete temporary file, showconf, causing the tmp directory to fill up and retrieves to fail.
512705 When using XML API to get the latest revision of FortiGate device, FortiManager may show the administrator password in clear text.
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie