Skip to main content
Best answer by bbilut

Looks like they recently added these two issues to the list of "Known Issues" with 6.2.5

 

630070 - HA is failing over with crashes. 645848 - FortiOS is providing self-signed CA certificate intermittently with flow-based SSL certificate inspection.

18 replies

SecurityPlus
Explorer III
August 20, 2020

Any early adopters? I have not tried 6.2 nor 6.4 yet though I am interested.

James_G
New Member
August 21, 2020
6.4.2 still seems to have less issues, I am seeing reports of this one (6.2.5) breaking SSL inspection.
bommi
bommiAuthor
New Member
August 21, 2020

Right now only one of my customers did the upgrade from 6.2.4 on a fgt-30e without any issues.

MartinOlszynski
New Member
August 24, 2020

Fortigate 101E:

Upgrade issue

 

JasperW
New Member
August 25, 2020

I upgraded my FGT201E saturday the 22nd from 6.2.4 to 6.2.5. The upgrade process went smooth. I do have problems with SSL Deep Inspection, especially (strangely enough) on exempted addresses.

In a proxy-based policy with "ssl deep inspection" enabled, some exempted addresses do not load in the browser, a connection failed error appears in the browser. I haven't pin pointed yet why certain sites that are exempted do not load while others do. In flow-based policies the problem does not occur.

My workaround for now is to add the same exempted addresses to a policy higher up in the processing order which does not have deep inspection enabled at all and is a flow-based policy. We don't mind that these addresses are not scanned, they were exempted in the first place. I use the same "address group" which holds my "SSL Deep Scanning Exempted addresses" both for the policy and for the SSL/SSH Inspection Security Profile.

I do notice from time to time that a page needs to be reloaded before an exempted wildcard address loads succesfully. This is probably because the address learned from the DNS-request wasn't yet loaded into the policy (https://docs.fortinet.com...-in-firewall-policies) thus the "lower" proxy-based policy is used instead.

With flow-based policies which have ssl deep inspection enabled the problem with exempted addresses does not occur. We need proxy-based policies though to enable us to block certain file types.

 

We use QUIC too (enabled), it doesn't seem to make a difference if we disable it.

MasterBratac
New Member
September 8, 2020

JasperW wrote:

I upgraded my FGT201E saturday the 22nd from 6.2.4 to 6.2.5. The upgrade process went smooth. I do have problems with SSL Deep Inspection, especially (strangely enough) on exempted addresses.

In a proxy-based policy with "ssl deep inspection" enabled, some exempted addresses do not load in the browser, a connection failed error appears in the browser. I haven't pin pointed yet why certain sites that are exempted do not load while others do. In flow-based policies the problem does not occur.

We do have the same problem on a cluster with two FG100D. Funny thing is, that the exempted Fortinet websites didn't work a all ... we went back to 6.2.4.

I also had chat contact to fortinet support .... they said, that this problem is not yet known ... 

So I'm glad, that I'm not the only one ... anything new on this toppic?

bbilut
bbilutAnswer
New Member
September 8, 2020

Looks like they recently added these two issues to the list of "Known Issues" with 6.2.5

 

630070 - HA is failing over with crashes. 645848 - FortiOS is providing self-signed CA certificate intermittently with flow-based SSL certificate inspection.

Wayne11
Explorer
August 25, 2020

We are in the same boat as JasperW, upgraded from 6.2.3 to 6.2.5 on a 200E Cluster and all proxy based policies with deep inspection were resetting the traffic to plenty pages. Switched the policy to Flow and everything works. 

But yeah, we also need a possibility to block users from downloading file types and used the DLP for that until today.

 

I was always a big fan from Fortinet and their products, but in the past few months, if not even years, they released so many bugs, we are close to decide to kick them out for all our subsidiaries worldwide  There is almost no concept in the builds, they remove a basic feature like DLP from the GUI, remove all DLP Filter settings from the existing policies after 6.2.2, switch it to the Webfilter and name it "File Filter", bring it back to the GUI in 6.4, sometimes I think they use dices to make decisions.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!