Skip to main content
emnoc
New Member
March 30, 2018
Solved

v6.0 is here

  • March 30, 2018
  • 6 replies
  • 95701 views
I hope it 's  all good  ;)
Best answer by thuynh_FTNT

Andy Bailey wrote:

I've attached the output your requested Roman and Jordan. Thanks for your help.

 

Nothing really obvious for me. I tried opening the policy and then clicking ok (no changes) and again (no changes) same result both times. I tried Edge instread of Firefox too- no changes there either.

 

The key lines seem to be:-

 

[httpsd 9510 - 1522869450    error] cmdb_commit_from_json[1426] -- error saving request object to CLI (-651) [httpsd 9510 - 1522869450    error] _api_cmdb_v2_config[1137] -- error editing object (nret=-651) [httpsd 9510 - 1522869450    error] api_return_http_result[516] -- API error -651 raised

Interestingly I can delete policies- I just tried deleting a couple of unused policies and that worked fine (highlighted from the "IPv4 Policy" list and then just delete.

 

Any other ideas?

Hi Andy, we've tried with several FGTs and were unable to reproduce your issue. Looks like it's specific to your config after upgrade. From your CLI debug output, the CLI is rejecting the change (any policy edit save) from the GUI.

0: config firewall policy 0: edit 15 0: set ssl-ssh-profile "SSL Certs-Block Untrusted\\Invalid" -651: end

 

Here are a few other things to try:

1. Can you use the CLI to edit a policy? You can use the above commands to see further error reported by the CLI

2. Can you use the GUI to create new Policy? if not, please also include CLI and httpsd debug message

3. Does this happen to any policy edit via the GUI? 4. Can you check if your interfaces are correctly upgraded?

5. Which FGT model are you using? if possible, can you share your full config with us? you can email me the config at thuynh@fortinet.com

 

Tri

6 replies

RobertReynolds
New Member
March 30, 2018

https://docs.fortinet.com/uploaded/files/4328/fortios-v6.0.0-release-notes.pdf

 

Beta and interims have been good.

 

Nice Easter surprise.

Kenundrum
New Member
March 30, 2018

I'm reading through some of the documentation. I was interested in the fabric changes.

So far- you still cannot have VDOMs enabled and participate in a security fabric which is still ridiculous. Also- the guide appears to be inconsistent for setting up a fabric as far as what is required. The diagrams show that a fortianalyzer is required, but all the text makes it seem like it is optional by referring to it as a recommended item. As I understand it, in 5.4 you only needed fortigates, in 5.6 you need an analyzer to use fabric features. Is that requirement now dropped again? Unfortunately almost all my devices have multiple VDOMs (mixing transparent and NAT modes) so I haven't been able to verify myself.

khj
New Member
April 1, 2018

Totally agree.

I was excited about the new feature that attempts to make the swithcontroller work with mulitble VDOMs. I have not tried it yet, as the documentation says that some of the bare essentials like STP (and related), QoS, 802.1X etc. are not supported with this feature enabled.

It would be really helpful to know what is on the roadmap for VDOMs in the near future that actually works.

 

 

rkhair
New Member
April 1, 2018

did the upgrade on my 100d, after i tested it on my DC 100d which was fine.. however the one in my office did the upgrade, comes up and all seems okay but cannot access the web interface through http or https.. ssh works fine and the firewall is letting traffic through and VPNs etc. are up, but the web interface on http or https is totally knackered! tried changing ports via SSH and enabling the http/https access on other interfaces, same thing!

 

Just a warning

neonbit
New Member
April 1, 2018

Upgraded 201E from 5.6.3 to 6.0 and working great for me so far. Tested local logging, SSLVPNs with RDP bookmarks and tunnel mode, VLANs,  dialupVPNs, DHCP sever and DNS server and all working fine so far.

 

Registered the FortiClient Linux (beta) to the FGT and it now shows up on the FGT (including my avatar).

 

I like how when you open the policy section it now defaults to the collapse all view instead of the expand all one like it was before.

 

One thing that I noted in the release notes is if you're upgrading from 5.6.3 > 6.0.0 you can't have any VLANs tied to an interface, and then have a zone referencing the interface and the zone. Hope it doesn't burn anyone that didn't read the notes!

 

All up very happy with this build so far, especially for a X.0 GA build.

btp
New Member
April 3, 2018

Just upgraded - and notice that a subinterface (VLAN) that I created under wan1 in GUI, and then popped over to another VDOM, lost the reference to the main interface (wan1). I had to enter it manually afterwards.

 

config system interface
edit "TUBA"
set vdom "GET"
set vlanid 10
next
end

emnoc
emnocAuthor
New Member
April 3, 2018

[191:root:2c]Destroy sconn 0x561cbd00, connSize=0. (root) [190:root:2c]req: /remote/hostcheck_install?auth_type=16&u [190:root:2c]rmt_hcinstall_cb_handler:450 remote check failed

 

So did you find a reason why? I just found out my sslvpn authentication rule didn't cary over when I push my FWF50E from v5.6.3 to v6.0.0.

 

Ken

 

rkhair
New Member
April 3, 2018

anyone notice that there 'web rating overrides' don't work? non of mine have worked since the upgrade to v6 tried to recreate them etc, but they seem to be just ignored.

Bruno_Pereira
New Member
May 2, 2018

I have found BUG ID 0480176: "sslvpn crash signal 11 and Forticlient users disconnect" The solution is wait for firmware 6.0.1 that will be delivered on May 28, 2018

ijquest
New Member
May 24, 2018

Hi, I´ve recently installed FortiOS 6.0 (v6.0.0 build0076 (GA)) in two FG´s (200E & 100E), and the "Web Rating Overrides" doesn´t work again. In this version, Fortigates ignores the Web Rating Overrides configuration.

 

Any solution please? Thanks

sejrik
New Member
May 29, 2018

i hear about some critical bugs in fortiweb V6.0 .

did anyone notice any ?

whats the diffrence between 5.9.1 and 6.0