Fortinet publikuje aktualizację oprogramowania autorskiego systemu operacyjnego dedykowanego dla FortiGate. Lista naprawionych błędów wykrytych w poprzedniej wersji oprogramowania kolejny raz utwierdza nas w przekonaniu, iż producent robi wszystko co w jego mocy aby software dla nowoczesnych zapór sieciowych FortiGate był dopracowany w każdym aspekcie! Zachęcamy do aktualizacji urządzeń oraz lektury zmian jakie wprowadzono w systemie operacyjnym FortiOS 5.6.8.
Rozwiązane problemy:
Explicit Proxy
Bug ID Description
477289 Proxy is unexpectedly sending FIN packet (FTP over HTTP traffic).
521344 Explicit FTP proxy doesn’t work with second IP address.
Firewall
Bug ID Description
441176 SNMP trap failed to send when LDB real server is down.
479577 Firewall policy should not allow to config dstaddr to „any” which doesn’t exist.
492034 Traffic not matching expected sessions and getting denied.
525995 Session marked dirty when routing table updated for route which is not related to the session.
GUI
Bug ID Description
516295 Error connecting to FortiCloud message while trying to access Forticloud Reports in GUI.
525666 Deleting an object in a non-root VDOM via Reference column deletes the related ID object in the root VDOM.
HA
Bug ID Description
488383 Cluster fails to sync after adding a new VDOM and rebooting with switch-controller disabled.
494029 After failover, cannot connect to management-IP of backup device.
517537 Slave out-of-sync. Unable to log into slave unit.
525182 WLAN guest user in VDOM makes the cluster out of sync.
IPsec VPN
Bug ID Description
493918 Memory leak with IKED.
Log & Report
Bug ID Description
477393 Negative values in 'Load Balance’ monitor logs.
503897 Fortigate-501E units generating logs only for five minutes after rebooting the unit, then do not generate any more logs.
Proxy
Bug ID Description
470407 IPv6-Happy-Eyeballs-Mechanism not working with proxy-based Webfilter-Profile.
491675 FTP Server is not accessible when AV profile is set to proxy based inspection.
512936 SSL certificate inspection in proxy mode doesn’t use CN from Valid Certificate for categorization when SNI is not present.
526667 FGT doesn’t forward Request:port command after 0byte file transmission.
531575 Website access failure due to OCSP check in WAD + Deep SSL inspection.
534346 WAD memory leak on OCSP certificate caching.
Routing
Bug ID Description
518655 IPv6 doesn’t respond to neighbor solicitation request.
SSL-VPN
Bug ID Description
500901 SSL VPN web portal connect to FMG (5.6.3) unable to view Managed devices and policy packages.
518406 Unable to load WebPage through SSL VPN webmode.
523647 Search result gives empty output upon accessing the url <https://ieeexplore.ieee.org> via SSL VPN bookmark.
530833 Synology NAS login page stuck after login when accessing by SSL VPN Web portal.
Switch Controller
Bug ID Description
525450 Managed FSWs details always opened at top of screen.
System
Bug ID Description
370151 CPU doesn’t remove dirty flag when returns session back to NP6.
461370 Auto MDIX does not work when interface is set to 10full/100full. It only works when interface is set to auto.
466805 Adding USB Host devices to a virtual machine connected by USB to FortiGate 500D causes the units to restart in loop.
482497 Running diagnose npu np6lite session in FG-201E results in high CPU and system instability.
495378 Port2 goes down after running for right days on FG-800D.
508304 IP is not updating in DDNS with 60D models.
513419 High CPU on some cores of CPU & packet drops around 2-3%.
519246 ipmc_sensord process not checking sensors due to pending jobs.
519493 If remote-side change systemID, only one port goes down, the other remains up.
526252 High memory caused by updated daemon.
524422 Merge br_6-0_sp back to 6.0 and 6.2.
524915 5.6 FortiOS replies with wrong numbers for SNMP ifSpeed and ifHighSpeed OIDs when interface is down.
526168 SLBC: System went into out-of-sync after FortiGuard update.
533287 FortiGate lost VLAN tag when using virtual wire pair.
User & Device
Bug ID Description
Single Sign-on, multiple FSSO polling servers with the same AD (LDAP) server, cannot select the same user or group.
525929 LDAPS requests fail with fnbamd stop error „Not enough bytes”. LDAP works fine. Additional timeout observed.
VM
Bug ID Description
528405 FortiMeter Consumption is not accurate.
Znane problemy do rozwiązania:
Application Control
Bug ID Description
435951 Traffic keeps going through the DENY NGFW policy configured with URL category.
448247 Traffic-shaper in shaping policy does not work for specific application category like as P2P.
FortiView
Bug ID Description
366627 FortiView Cloud Application may display incorrect drill down File and Session list in the Applications View.
368644 Physical Topology: Physical Connection of stacked FortiSwitch may be incorrect.
375172 FortiGate under a FortiSwitch may be shown directly connected to an upstream FortiGate.
408100 Log fields are not aligned with columns after drill down on FortiView and Log details.
FortiSwitch-Controller/FortiLink
Bug ID Description
304199 Using HA with FortiLink can encounter traffic loss during failover.
357360 DHCP snooping may not work on IPv6.
369099 FortiSwitch authorizes successfully, but fails to pass traffic until you reboot FortiSwitch.
404399 FortiLink goes down when connecting to ForiSwitch 3.4.2 b192.
GUI
Bug ID Description
356174 FortiGuard updategrp read-write privilege admin cannot open FortiGuard page.
374844 Should show ipv6 address when set ipv6 mode to pppoe/dhcp on GUI > Network >Interfaces.
442231 Link cannot show different colors based on link usage legend in logical topology real time view.
445113 IPS engine 3.428 on Fortigate sometimes cannot detect Psiphon packets that iscan can detect.
451776 Admin GUI has limit of 10 characters for OTP.
HA
Bug ID Description
481943 Green checkmarks indicating HA sync status on GUI only appear beside virtual cluster 1.
Log & Report
Bug ID Description
412649 In NGFW Policy mode, FortiGate does not create webfilter logs.
Security Fabric
Bug ID Description
403229 In FortiView display from FortiAnalyzer, the upstream FortiGate cannot drill down to final level for downstream traffic.
411368 In FortiView with FortiAnalyzer, the combined MAC address is displayed in the Device field.
SSL-VPN
Bug ID Description
405239 URL rewritten incorrectly for a specific page in application server.
System
Bug ID Description
295292 If private-data-encryption is enabled, when restoring config to a FortiGate, the FortiGate may not prompt the user to enter the key.
436580 PDQ_ISW_SSE drops at +/-100K CPS on FG-3700D with FOS 5.4 only.
436746 NP6 counter shows packet drops on FG-1500D. Pure firewall policy without UTM.
440411 Monitor NP6 IPsec engine status.
457096 FortiGate to FortiManager tunnel (FGFM) using the wrong source IP when multiple paths exist.
464873 RADIUS COA Disconnect-ACK message ignore RADIUS server source-ip setting.
Więcej informacji znajdą Państwo w notatkach: Notatki do wydania
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie