Skip to main content
fchowdhury
Visitor III
April 5, 2023
Solved

Issue after Fortimanager Upgrade

  • April 5, 2023
  • 5 replies
  • 3804 views

Hello Team,

I have upgraded the FortiManager to 6.4.11 and we have fortigate firewalls with version 6.2.12 and 6.4.8.

After the upgrade when I go to create new rules Insert Above or Insert Below in fortigate firewall running 6.4.8 I get the below error message.

firewall/policy/509: logtraffic cannot be set to utm when policy action is deny.

Interestingly Policy 509 doesn't exist.

But the firewall with version 6.2.12 doesn't have any issue.

It seems to be a bug affecting fortios version 6.4.x

Anyone can confirm if it's a bug or how do I resolve the issue.

 

Thanks

Best answer by fchowdhury

This is to inform that this behavior is a bug in FortiManager Version 6.4.11 and 7.0.6. The bug is fixed in FortiManager Version 7.0.7 as per the release notes.

Bug ID 889563

5 replies

gfleming
Staff
Staff
April 6, 2023

Sounds like a bug. But if you're absolutely certain you do not have policy ID 509 on your FortiGate you could try running a script on the policy package in FortiManager to delete policy ID 509

 

config firewall policy

  delete 509

fchowdhury
Visitor III
April 6, 2023

Hell Graham,

It doesn't help... Also noticed the same with Fortimanager running 7.0.6 version and Fortigate Firewalls running 6.4.6.

Seems to be issue with all Firewalls running FortiOS 6.4.x

 

Thanks

gfleming
Staff
Staff
April 6, 2023

I would suggest talking to TAC then.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!