Producent oprogramowania Fortinet udostępnił najnowszą aktualizację produktu FortiOS do wersji 7.6.2. W tej wersji poprawiono wiele kluczowych problemów, w szczególności rozwiązano błąd powodujący utratę ruchu ADVPN IPsec po odnowieniu tunelu (Bug ID: 1103594), naprawiono problem z wysyłaniem wygasłego certyfikatu serwera VPN pomimo jego aktualizacji (Bug ID: 1077157) oraz usunięto awarię IkEd w IPsec, która mogła wymuszać ponowne połączenie klientów (Bug ID: 1073670). Poniżej znajdują się szczegółowe informacje na ten temat.
Wspierane urządzenia:
FortiGate | FG-40F, FG-40F-3G4G, FG-60F, FG-61F, FG-70F, FG-71F, FG-80F, FG-80F-BP, FG-80F-DSL, FG-80F-POE, FG-81F, FG-81F-POE, FG-90G, FG-91G, FG-100F, FG-101F, FG-120G, FG-121G, FG-200E, FG-200F, FG-201E, FG-201F, FG-300E, FG-301E, FG‑400E, FG-400E-BP, FG‑401E, FG-400F, FG-401F, FG‑500E, FG-501E, FG-600E, FG-601E, FG-600F, FG-601F, FG-800D, FG‑900D, FG-900G, FG-901G, FG-1000D, FG-1000F, FG-1001F, FG-1100E, FG-1101E, FG-1800F, FG-1801F, FG-2000E, FG-2200E, FG-2201E, FG-2500E, FG-2600F, FG-2601F, FG-3000D, FG-3000F, FG-3001F, FG-3100D, FG‑3200D, FG-3200F, FG-3201F, FG-3300E, FG-3301E, FG-3400E, FG-3401E, FG-3500F, FG-3501F, FG-3600E, FG-3601E, FG-3700D, FG-3700F, FG-3701F, FG-3960E, FG‑3980E, FG-4200F, FG-4201F, FG-4400F, FG-4401F, FG-4800F, FG-4801F, FG-5001E, FG‑5001E1, FG-6000F, FG-7000E, FG-7000F |
FortiWiFi | FWF-40F, FWF-40F-3G4G, FWF-60F, FWF-61F, FWF-80F-2R, FWF-80F-2R-3G4G-DSL, FWF-81F-2R, FWF-81F-2R-3G4G-DSL, FWF-81F-2R-POE, FWF-81F-2R-3G4G-POE |
FortiGate Rugged | FGR-60F, FGR-60F-3G4G, FGR-70F, FGR-70F-3G4G |
FortiFirewall | FFW-1801F, FFW-2600F, FFW-3001F, FFW-3501F, FFW-3980E, FFW-4200F, FFW-4400F, FFW-4401F, FFW-4801F, FFW-VM64, FFW-VM64-KVM |
FortiGate VM | FG-ARM64-AWS, FG-ARM64-AZURE, FG-ARM64-GCP, FG-ARM64-KVM, FG-ARM64-OCI, FG-VM64, FG-VM64-ALI, FG-VM64-AWS, FG-VM64-AZURE, FG‑VM64‑GCP, FG-VM64-HV, FG-VM64-IBM, FG-VM64-KVM, FG‑VM64‑OPC, FG‑VM64-RAXONDEMAND, FG-VM64-XEN |
FortiGate 6000 and 7000 support
FortiOS 7.6.2 supports the following FG-6000F, FG-7000E, and FG-7000F models:
FG-6000F | FG-6001F, FG-6300F, FG-6301F, FG-6500F, FG-6501F |
FG-7000E | FG-7030E, FG-7040E, FG-7060E |
FG-7000F | FG-7081F, FG-7121F |
Rozwiązane problemy:
GUI
Bug ID | Description |
---|---|
1092489 | The config system fortiguard > fortiguard-anycast setting was changed to automatically disable when the FortiGuard page is shown on GUI. |
1110382 | Admin can log in to GUI (HTTPS) with password, even when admin-https-pki-required is enabled. |
HA
Bug ID | Description |
---|---|
1108895 | In an FGSP cluster, enabling and disabling standalone-config-sync results in the local dev_base being deleted and synchronized with the peer, which leads to the absence of the dev_base . |
Intrusion Prevention
Bug ID | Description |
---|---|
1107445 | Remove IPS diagnose command diagnose ips cfgscript run . |
IPsec VPN
Bug ID | Description |
---|---|
1103594 | ADVPN IPsec traffic over shortcut drops when IPsec tunnel rekeys. |
1012615 | IPsec VPN traffic is dropped after upgrading to version 7.4.3. |
1073670 | An IkEd crash on secondary causes IPsec client to reconnect. |
SSL VPN
Bug ID | Description |
---|---|
1077157 | FortiGate sends out expired server certificate for a given SSL VPN realm, even when the certificate configured in virtual-host-server-cert has been updated. |
1101837 | Insufficient session expiration in SSL VPN using SAML authentication. |
System
Bug ID | Description |
---|---|
1102416 | Cannot push config sfp-dsl enable and vectoring under interface. |
User & Authentication
Bug ID | Description |
---|---|
1075207 | fnbam may crash due to configuration of two wildcard-enabled remote admins in separate VDOMs. |
VM
Bug ID | Description |
---|---|
1012000 | When unicast HA setup has a large number of interfaces, FGT Hyper-V takes a long time to boot up. |
Notatki producenta: FortiOS 7.6.2 Release Notes
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie