Fortios v6.0.2 Release Notes
Fortios v6.0.2 Release Notes
Version 6.0.2
FORTINET DOCUMENT LIBRARY
https://docs.fortinet.com
FORTINET VIDEO GUIDE
https://video.fortinet.com
FORTINET BLOG
https://blog.fortinet.com
CUSTOMER SERVICE & SUPPORT
https://support.fortinet.com
FORTINET COOKBOOK
http://cookbook.fortinet.com
NSE INSTITUTE
https://training.fortinet.com
FORTIGUARD CENTER
https://fortiguard.com/
FEEDBACK
Email: techdocs@fortinet.com
December 7, 2018
FortiOS 6.0.2 Release Notes
01-602-502422-20181207
TABLE OF CONTENTS
Change Log 4
Introduction 5
Supported models 5
What’s new in FortiOS 6.0.2 6
Special Notices 7
WAN optimization and web caching functions 7
FortiGuard Security Rating Service 7
Built-in certificate 8
FortiGate and FortiWiFi-92D hardware limitation 8
FG-900D and FG-1000D 9
FortiClient (Mac OS X) SSL VPN requirements 9
FortiClient profile changes 9
Use of dedicated management interfaces (mgmt1 and mgmt2) 9
Using FortiAnalyzer units running older versions 10
Upgrade Information 11
Upgrading to FortiOS 6.0.2 11
Fortinet Security Fabric upgrade 11
Minimum version of TLS services automatically changed 12
Downgrading to previous firmware versions 12
Amazon AWS enhanced networking compatibility issue 13
FortiGate VM firmware 13
Firmware image checksums 14
FortiGuard update-server-location setting 14
Product Integration and Support 15
FortiOS 6.0.2 support 15
Language support 17
SSL VPN support 17
SSL VPN standalone client 17
SSL VPN web mode 18
SSL VPN host compatibility list 18
Resolved Issues 20
Known Issues 29
Limitations 33
Citrix XenServer limitations 33
Open source XenServer limitations 33
2018-08-09 Deleted IE 11 from Product Integration and Support > SSL VPN web mode.
Added 493091 to Resolved Issues.
2018-08-22 Added Microsoft Hyper-V Server 2016 to Product Integration and Support > FortiOS 6.0.2
support.
This document provides the following information for FortiOS 6.0.2 build 0163:
l Special Notices
l Upgrade Information
l Product Integration and Support
l Resolved Issues
l Known Issues
l Limitations
For FortiOS documentation, see the Fortinet Document Library.
Supported models
FortiOS Carrier FortiOS Carrier 6.0.2 images are delivered upon request and are not available on the
customer support firmware download page.
For a list of new features and enhancements that have been made in FortiOS 6.0.2, see the What’s New for FortiOS
6.0.2 document.
WAN optimization and web caching functions are removed from 60D and 90D series platforms, starting from 6.0.0 due
to their limited disk size. Platforms affected are:
l FGT-60D
l FGT-60D-POE
l FWF-60D
l FWF-60D-POE
l FGT-90D
l FGT-90D-POE
l FWF-90D
l FWF-90D-POE
l FGT-94D-POE
Upon upgrading from 5.6 patches to 6.0.0, diagnose debug config-error-log read will show command
parse error about wanopt and webcache settings.
Not all FortiGate models can support running the FortiGuard Security Rating Service as a Fabric "root" device. The
following FortiGate platforms can run the FortiGuard Security Rating Service when added to an existing Fortinet
Security Fabric managed by a supported FortiGate model:
l FGR-30D-A
l FGR-30D
l FGR-35D
l FGR-60D
l FGR-90D
l FGT-200D
l FGT-200D-POE
l FGT-240D
l FGT-240D-POE
l FGT-280D-POE
l FGT-30D
l FGT-30D-POE
l FGT-30E
l FGT-30E-MI
l FGT-30E-MN
l FGT-50E
l FGT-51E
l FGT-52E
l FGT-60D
l FGT-60D-POE
l FGT-70D
l FGT-70D-POE
l FGT-90D
l FGT-90D-POE
l FGT-94D-POE
l FGT-98D-POE
l FWF-30D
l FWF-30D-POE
l FWF-30E
l FWF-30E-MI
l FWF-30E-MN
l FWF-50E-2R
l FWF-50E
l FWF-51E
l FWF-60D
l FWF-60D-POE
l FWF-90D
l FWF-90D-POE
l FWF-92D
Built-in certificate
FortiGate and FortiWiFi D-series and above have a built in Fortinet_Factory certificate that uses a 2048-bit certificate
with the 14 DH group.
FortiOS 5.4.0 reported an issue with the FG-92D model in the Special Notices > FG-92D High Availability in Interface
Mode section of the release notes. Those issues, which were related to the use of port 1 through 14, include:
l PPPoE failing, HA failing to form.
l IPv6 packets being dropped.
l FortiSwitch devices failing to be discovered.
l Spanning tree loops may result depending on the network topology.
FG-92D and FWF-92D do not support STP. These issues have been improved in FortiOS 5.4.1, but with some side
effects with the introduction of a new command, which is enabled by default:
config global
set hw-switch-ether-filter <enable | disable>
l ARP (0x0806), IPv4 (0x0800), and VLAN (0x8100) packets are allowed.
l BPDUs are dropped and therefore no STP loop results.
l PPPoE packets are dropped.
l IPv6 packets are dropped.
l FortiSwitch devices are not discovered.
l HA may fail to form depending the network topology.
l All packet types are allowed, but depending on the network topology, an STP loop may result.
CAPWAP traffic will not offload if the ingress and egress traffic ports are on different NP6 chips. It will only offload if
both ingress and egress ports belong to the same NP6 chip.
When using SSL VPN on Mac OS X 10.8, you must enable SSLv3 in FortiOS.
With introduction of the Fortinet Security Fabric, FortiClient profiles will be updated on FortiGate. FortiClient profiles
and FortiGate are now primarily used for Endpoint Compliance, and FortiClient Enterprise Management Server (EMS) is
now used for FortiClient deployment and provisioning.
The FortiClient profile on FortiGate is for FortiClient features related to compliance, such as Antivirus, Web Filter,
Vulnerability Scan, and Application Firewall. You may set the Non-Compliance Action setting to Block or Warn.
FortiClient users can change their features locally to meet the FortiGate compliance criteria. You can also use
FortiClient EMS to centrally provision endpoints. The EMS also includes support for additional features, such as VPN
tunnels or other advanced options. For more information, see the FortiOS Handbook – Security Profiles.
For optimum stability, use management ports (mgmt1 and mgmt2) for management traffic only. Do not use
management ports for general user traffic.
When using FortiOS 6.0.2 with FortiAnalyzer units running 5.6.5 or lower, or 6.0.0/6.0.1, FortiAnalyzer might report
increased bandwidth and session counts if there are sessions that last longer than two minutes.
For accurate bandwidth and session counts, upgrade the FortiAnalyzer unit to 5.6.6 or higher, or 6.0.2 or higher.
Supported upgrade path information is available on the Fortinet Customer Service & Support site.
1. Go to https://support.fortinet.com.
2. From the Download menu, select Firmware Images.
3. Check that Select Product is FortiGate.
4. Click the Upgrade Path tab and select the following:
l Current Product
l Current FortiOS Version
l Upgrade To FortiOS Version
5. Click Go.
If you are upgrading from version 5.6.2 or 5.6.3, this caution does not apply.
Before upgrading, ensure that port 4433 is not used for admin-port or admin-sport (in
config system global), or for SSL VPN (in config vpn ssl settings).
If you are using port 4433, you must change admin-port, admin-sport, or the SSL VPN
port to another port number before upgrading.
FortiOS 6.0.2 greatly increases the interoperability between other Fortinet products. This includes:
l FortiAnalyzer 6.0.0
l FortiClient 6.0.0
l FortiClient EMS 6.0.0
l FortiAP 5.4.4 and later
l FortiSwitch 3.6.4 and later
Upgrade the firmware of each product in the correct order. This maintains network connectivity without the need to use
manual steps.
Before upgrading any product, you must read the FortiOS Security Fabric Upgrade Guide.
If Security Fabric is enabled, then all FortiGate devices must be upgraded to 6.0.2. When
Security Fabric is enabled, you cannot have some FortiGate devices running 6.0.2 and some
running 5.6.x.
For improved security, FortiOS 6.0.2 uses the ssl-min-proto-version option (under config system
global) to control the minimum SSL protocol version used in communication between FortiGate and third-party SSL
and TLS services.
When you upgrade to FortiOS 6.0.2 and later, the default ssl-min-proto-version option is TLS v1.2. The
following SSL and TLS services inherit global settings to use TLS v1.2 as the default. You can override these settings.
l Email server (config system email-server)
l Certificate (config vpn certificate setting)
l FortiSandbox (config system fortisandbox)
l FortiGuard (config log fortiguard setting)
l FortiAnalyzer (config log fortianalyzer setting)
l LDAP server (config user ldap)
l POP3 server (config user pop3)
Downgrading to previous firmware versions results in configuration loss on all models. Only the following settings are
retained:
l operation mode
l interface IP/management IP
l static route table
l DNS settings
l VDOM parameters/settings
l admin user account
l session helpers
l system access profiles
If you have long VDOM names, you must shorten the long VDOM names (maximum 11 characters) before
downgrading:
1. Back up your configuration.
2. In the backup configuration, replace all long VDOM names with its corresponding short VDOM name.
For example, replace edit <long_vdom_name>/<short_name> with edit <short_name>/<short_
name>.
3. Restore the configuration.
4. Perform the downgrade.
With this new enhancement, there is a compatibility issue with older AWS VM versions. After downgrading a 6.0.2
image to an older version, network connectivity is lost. Since AWS does not provide console access, you cannot recover
the downgraded image.
When downgrading from 6.0.2 to older versions, running the enhanced nic driver is not allowed. The following AWS
instances are affected:
l C3
l C4
l R3
l I2
l M4
l D2
FortiGate VM firmware
Fortinet provides FortiGate VM firmware images for the following virtual environments:
l .out: Download the 64-bit firmware image to upgrade your existing FortiGate VM installation.
l .out.OpenXen.zip: Download the 64-bit package for a new FortiGate VM installation. This package contains
the QCOW2 file for Open Source XenServer.
l .out.CitrixXen.zip: Download the 64-bit package for a new FortiGate VM installation. This package
contains the Citrix XenServer Virtual Appliance (XVA), Virtual Hard Disk (VHD), and OVF files.
Linux KVM
l .out: Download the 64-bit firmware image to upgrade your existing FortiGate VM installation.
l .out.kvm.zip: Download the 64-bit package for a new FortiGate VM installation. This package contains
QCOW2 that can be used by qemu.
Microsoft Hyper-V
l .out: Download the 64-bit firmware image to upgrade your existing FortiGate VM installation.
l .out.hyperv.zip: Download the 64-bit package for a new FortiGate VM installation. This package contains
three folders that can be imported by Hyper-V Manager on Hyper-V 2012. It also contains the file fortios.vhd
in the Virtual Hard Disks folder that can be manually added to the Hyper-V Manager.
l .out: Download either the 64-bit firmware image to upgrade your existing FortiGate VM installation.
l .ovf.zip: Download either the 64-bit package for a new FortiGate VM installation. This package contains Open
Virtualization Format (OVF) files for VMware and two Virtual Machine Disk Format (VMDK) files used by the OVF
file during deployment.
The MD5 checksums for all Fortinet software and firmware releases are available at the Customer Service & Support
portal, https://support.fortinet.com. After logging in select Download > Firmware Image Checksums, enter the image
file name including the extension, and select Get Checksum Code.
The FortiGuard update-server-location default setting is different between hardware platforms and VMs. On
hardware platforms, the default is any. On VMs, the default is usa.
On VMs, after upgrading from 5.6.3 or earlier to 5.6.4 or later (including 6.0.0 or later), update-server-location
is set to usa.
If necessary, set update-server-location to use the nearest or low-latency FDS servers.
The following table lists 6.0.2 product integration and support information:
FortiClient: l 6.0.0
l Microsoft Windows See important compatibility information in Fortinet Security Fabric upgrade on
l Mac OS X page 11.
l Linux If FortiClient is being managed by a FortiGate, you must upgrade FortiClient
before upgrading FortiGate.
FortiClient for Linux is supported on Ubuntu 16.04 and later, Red Hat 7.4 and
later, and CentOS 7.4 and later.
If you are using FortiClient only for IPsec VPN or SSL VPN, FortiClient version
5.6.0 and later are supported.
Fortinet Single Sign-On l 5.0 build 0268 and later (needed for FSSO agent support OU in group filters)
(FSSO) l Windows Server 2016 Datacenter
l Windows Server 2016 Standard
l Windows Server 2008 (32-bit and 64-bit)
l Windows Server 2008 R2 64-bit
l Windows Server 2012 Standard
l Windows Server 2012 R2 Standard
l Novell eDirectory 8.8
FortiExtender l 3.2.1
AV Engine l 6.00012
Virtualization Environments
Microsoft l Hyper-V Server 2008 R2, 2012, 2012 R2, and 2016
Language support
Language support
Language GUI
English ✔
Chinese (Simplified) ✔
Chinese (Traditional) ✔
French ✔
Japanese ✔
Korean ✔
Portuguese (Brazil) ✔
Spanish ✔
The following table lists SSL VPN tunnel client standalone installer for the following operating systems.
Linux CentOS 6.5 / 7 (32-bit & 64-bit) 2336. Download from the Fortinet Developer Network
Linux Ubuntu 16.04 (32-bit & 64-bit) https://fndn.fortinet.net.
Other operating systems may function correctly, but are not supported by Fortinet.
SSL VPN standalone client no longer supports the following operating systems:
l Microsoft Windows 7 (32-bit & 64-bit)
l Microsoft Windows 8 / 8.1 (32-bit & 64-bit)
l Microsoft Windows 10 (64-bit)
l Virtual Desktop for Microsoft Windows 7 SP1 (32-bit)
The following table lists the operating systems and web browsers supported by SSL VPN web mode.
Other operating systems and web browsers may function correctly, but are not supported by Fortinet.
The following table lists the antivirus and firewall client software packages that are supported.
The following issues have been fixed in version 6.0.2. For inquires about a particular bug, please contact Customer
Service & Support.
AntiVirus
Bug ID Description
487946 MSS value increases when AV or WEB filter in use resulting in Packet too big message.
Application Control
Bug ID Description
423140 All IPS sessions lost when new custom signature added.
Bug ID Description
477392 Cannot use FAC username password and FortiToken two-factor authenticate login HA slave unit.
481469 Failed to resolve hostname for configured CRL URL on a non-managment VDOM.
488566 Renaming guest user group name doesn't reflect under Guest administrator account assigned
leads to black page.
491175 diag test application fnbamd 1 causes fnbamd to enter an idle state and causes
authentication failure.
493470 Authenticated user receives Oops "Authentication requested" referencing a proxy policy which
does not have authentication.
493930 Admins who use dedicated HA mgmt interfaces are not visible in the CLI.
495210 Guest user accounts do not show expiration time, but time until expiration only.
496524 After successful wired portal auth, the wired PC still gets many http redirection and fails to access
the internet.
Connectivity
Bug ID Description
479607 Scheduled auto-update happens twice in 10 seconds but a log entry for the first try is not logged.
DLP
Bug ID Description
478524 Diskless model missing full-archive-proto in config DLP sensor when only FortiCloud
logging enabled.
486958 Scanunit signal 14 alarm clock caused by DLP scanning bz2 file.
Firewall
Bug ID Description
475539 Inaccurate netflow export. Traffic measurements do not match with SNMP readings.
478681 Should be able to disable SNAT when a VIP exists and central-NAT is enabled.
492961 Set utm-status disable did not hide profile-group. Unset profile-group will make
profile-protocol-options empty.
502579 Local-In-Policies with FQDN address is not working after upgrade from 5.6 to 6.0.1.
FortiView
Bug ID Description
414172 HTTPsd / DNSproxy/ high CPU/memory with high rate UDP 1Byte spoofing traffic.
GUI
Bug ID Description
402457 Suggest to improve IPsec VPN monitor page Proxy ID Source and Proxy ID Destination fields.
Bug ID Description
444104 Accept/Decline buttons cannot be seen in GUI with a long login disclaimer and screen under certain
resolutions.
449598 Remote LDAP User Definition wizard does not pull users.
457627 Want the ability to change the date/time format displayed in the GUI of the FortiGate.
457721 FortiLink Switch-controller GUI - allow user to edit Port Description for FortiLink/ISL.
457966 Virtual wire pair > Add VLAN range filter on GUI.
460617 GUI FortiGuard Check Again button doesn't work as expected due to FortiGuard service 8888/53
incorrectly routed.
462011 GUI is blank when accessed with RADIUS user with read-access profile and the FortiGate is
managed by FortiManager.
462072 GUI should show full FQDN name in reputation search result.
468797 Cannot filter by date or timestamp when viewing logs from FortiCloud.
469082 prof_admin profile admins are not able to display GUI IPv4 source address.
470241 Raw logs are downloaded from the default location even if you select another log device in GUI.
472023 Outbreak prevention detection makes "clean" counter increment in Advanced Threat Protection
Stats widget.
472558 DHCP Server GUI - GUI populates wrong information when switching from DHCP Relay to DHCP
Server.
473808 Column filter is not persistent and is removed after refreshing the page.
477870 Alias for modem interface present in GUI but not in CLI.
479468 The link status is lost after SD-WAN GUI changes to List Edit.
479937 GUI should hide options that don't apply to certificate inspection.
481902 When accessing FortiView > Websites page, gets error Failed to get FortiView data and httpsd
keeps crashing.
Bug ID Description
489674 When scroll to the end of an muTable, GUI should shows 100% of entry.
489675 The Firefox web browser sometimes cannot delete performance SLA rules.
493351 Object tooltip of last page should not always display on current page.
493773 SD-WAN rule in GUI unable to select (whether as source or destination) the address group grp_
citrixfarm.
494724 When creating trunk interface on managed FSW, FSW ports in right-side list show down, even
when some are up.
496613 Editing web filter profile in GUI deletes web-proxy profile and URL filter entries.
HA
Bug ID Description
408886 Uninterrupted upgrade from B718 to tag 9702 failed with 1.5M BGP routes and 6M sessions load.
461915 When standalone config sync is enabled in FGSP, IPv6 setting of interface is synced.
473806 Management interface IP address replicating to slave when using standalone management
VDOMs.
473806 Management interface IP address replicating to slave when using standalone management
VDOMs.
485340 HA failover does not work after changing system time manually.
486552 vcluster HA failover fails with large site-to-site IPsec VPN configuration on 3800D.
487444 FortiGate stops accepting traffic from any interface in a hardware switch after HA failover in
80/81E.
491311 Management port has sync'ed when creating a new NAT VDOM.
493759 When vcluster2 is removed from HA config, all active sessions are killed once session-ttl
is reached.
501147 Moving VDOM to virtual cluster from GUI causes cluster to go out of sync.
IPS
Bug ID Description
IPsec VPN
Bug ID Description
486756 Traffic is not fragmented for IPsec VPN when Proxy-based UTM is enabled.
491305 Packet from FortiClient cannot go through VXLAN over IPsec depending on packet size.
492046 FortiGate does not respond to INFORMATIONAL exchange message as requested by RFC.
Bug ID Description
493140 Need to see application signature names instead of LDS under Logs & Report > System event logs.
494040 Creating or modifying security profiles generate multiple logs with misleading action.
497357 FortiGate logs show the action as block when we use DNS filter and if a DNS query timeout
happens.
498519 Web filter authentication failed to set status field in the event log message.
Proxy
Bug ID Description
Bug ID Description
491630 With UTM enabled, client failed to get response from server, gets 500 Internal error.
494081 WAD process crashes with signal 11 after upgrading the firmware to v5.6.4.
Router
Bug ID Description
482631 OSPF adjacencies lost, FGFMD high CPU while pushing policies from FortiManager.
491679 FortiGate chooses higher metric OSPF E2 route for traffic under some circumstance.
492063 Route map not able to set attribute with BGP conditional advertisement.
493454 Large PIM SM bootstrap packets are not forwarded with kernel 3.2.
494393 Router access list should not default to prefix any and exact match disable.
SSL VPN
Bug ID Description
483712 sslvpnd consumes high memory causing FortiGate to enter conserve mode.
486918 SSL VPN web mode unable to load the page correctly.
494960 SSL VPN web mode has trouble loading internal web application.
494978 authd registers SSL VPN user with wrong user/group information and breaking SSL VPN after
upgrade to 5.6.4.
501769 SSL VPN: Bookmark to internal web site not loading correctly - JavaScript errors.
Switch
Bug ID Description
System
Bug ID Description
370953 SLBC worker blade failed to re-synchronize with the config master blade due to the frozen confsync
daemon.
414081 SMB1 support has been by default disabled under part models.
462178 Front panel SPEED LED is flashing green when transmitting and receiving data.
Affected models: FG-60D, FG-60E, FG-80E, FG-90D, and FG-500D.
Affected versions: 5.6, 6.0, and 6.2.
481783 DHCP address assignment sometimes fails - DHCPD crashing multiple times.
485781 Deleting EMAC VLAN interface on a different VDOM causing connectivity loss to the EMAC VLAN
for 5-7 pings.
493219 Softirq and nice are taking high CPU resources when sending and receiving packets with a virtual
wire pair.
494603 FortiGate in transparent mode is not accessible over https/ssh (administrative access) once trusted
host is configured.
499332 No error message when configuring address .067 and address converted with .55.
Upgrade
Bug ID Description
495994 After upgrade to 5.4.9, observing a lot of IPS syntax errors on the console screen.
VM
Bug ID Description
493091 Allow using smaller FGT-VM license in bigger virtual instance to benefit presence of extra network
interfaces.
499154 FortiGate Azure rejects static route configure pushing from FortiManager.
501911 In FOS-AWS prompt, user password = instance ID, and force user to change password upon initial
log in.
VoIP
Bug ID Description
Web Filter
Bug ID Description
454634 Web filter set warning-prompt per-domain is warning per-category instead of per-domain.
476806 FortiOS incorrectly sends ICMP "Destination Unreachable" with WF/certificate inspection.
486171 The Web Rating Overrides option doesn't work with flow-mode.
490377 The Web Rating Overrides option doesn't work properly on proxy-based.
Web Proxy
Bug ID Description
WiFi
Bug ID Description
471638 FortiGate disconnects all clients when they roam from AP to AP.
Bug ID Description
491769 Support for third-party external portal with RADIUS MAC authentication.
The following issues have been identified in version 6.0.2. For inquires about a particular bug or to report a bug, please
contact Customer Service & Support.
Application Control
Bug ID Description
435951 Traffic keeps going through the DENY NGFW policy configured with URL category.
FortiGate 3815D
Bug ID Description
FortiSwitch-Controller/FortiLink
Bug ID Description
FortiView
Bug ID Description
375172 FortiGate under a FortiSwitch may be shown directly connected to an upstream FortiGate.
460016 In Fortiview > Threats, drill down one level, click Return and the graph is cleared.
GUI
Bug ID Description
256264 Realtime session list cannot show IPv6 session and related issues.
439185 AV quarantine cannot be viewed and downloaded from detail panel when source is FortiAnalyzer.
Bug ID Description
442231 Link cannot show different colors based on link usage legend in logical topology real time view.
470589 The Forward Traffic Log Details panel Security tab does not display security log details when
multiple log devices are enabled.
487350 FortiGuard Filtering Services Availability showing Unavailable on GUI when no valid Anti-spam
license is present.
HA
Bug ID Description
451470 Unexpected performance reduction in case of Inter-Chassis HA fail-back with enabling HA override.
479987 FG MGMT1 does not authenticate Admin RADIUS users through primary unit (secondary unit
works).
503433 hasync daemon crashes when admin session times out and cluster could be out of sync for a short
period.
IPS
Bug ID Description
445113 IPS engine 3.428 on FortiGate sometimes cannot detect Psiphon packets that iscan can detect.
IPsec VPN
Bug ID Description
469798 The interface shaping with egress shaping profile doesn't work for offloaded traffic.
481201 The OCVPN feature is delayed about one day after registering on FortiCare.
501027 FCT ipsec_vpn IKE version 2 can't register on IPsec virtual tunnel interface.
Bug ID Description
412649 In NGFW Policy mode, FortiGate does not create webfilter logs.
Security Fabric
Bug ID Description
403229 In FortiView display from FortiAnalyzer, the upstream FortiGate cannot drill down to final level for
downstream traffic.
411368 In FortiView with FortiAnalyzer, the combined MAC address is displayed in the Device field.
SSL VPN
Bug ID Description
System
Bug ID Description
364280 User cannot use ssh-dss algorithm to login to FortiGate via SSH.
436746 NP6 counter shows packet drops on FG-1500D. Pure firewall policy without UTM.
472843 When FortiManager is set for DM = set verify-install-disable, FortiGate does not
always save script changes.
482497 Running diagnose npu np6lite session in FGT-201E results in high CPU and system
instability.
494042 If we create VLAN in VDOM A, then we cannot create ZONE name with the same VLAN name in
VDOM B.
Upgrade
Bug ID Description
470575 After upgrading from 5.6.3, g-sniffer-profile and sniffer-profile exist for IPS and
webfilter.
473075 When upgrading, multicast policies are lost when there is a zone member as interface.
Bug ID Description
481408 When upgrading from 5.6.3 to 6.0.0, the IPv6 policy is lost if there is SD-WAN member as
interface.
494217 Peer user SSL VPN personal bookmarks do not show when upgrade to 6.0.1.
Workaround: Use CLI to rename the user bookmark to the new name.
Web Filter
Bug ID Description
When using Linux Ubuntu version 11.10, XenServer version 4.1.0, and libvir version 0.9.2, importing issues may arise
when using the QCOW2 format and existing HDA issues.