FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
spoojary
Staff
Staff
Article Id 329089
Description

This article describes a known issue where Application Control is no longer visible in the FortiGate Web GUI after upgrading to FortiOS 7.6.0. Notably, this issue only occurs on FortiGates with 2GB of memory or less.

Scope

FortiGate 7.6.0 only.

Solution

After upgrading to FortiOS 7.6.0, it has been observed that Application Control will no longer be visible in the Web GUI. The section under Security Profiles > Application Control will no longer be accessible, nor will Application Control be available as a toggle under System -> Feature Visibility.

 

This is a regression that is covered under Issue #1060562 and it is set to be resolved in the upcoming FortiOS 7.6.1. The regression was accidentally introduced as part of the proxy-related feature changes made to FortiGates with 2GB or less of memory (see this article for more information).

 

Note that this is an issue specific to FortiOS 7.6.0 only: FortiOS 7.4 and earlier are not affected at the time of this writing.

The issue has been resolved in FortiOS version 7.6.1 (scheduled for release in November, 2024).

 

Workaround:

 

It is still possible to configure and apply Application Control profiles using the CLI while on FortiOS 7.6.0, so that is the recommended workaround at this time. Refer to the following links for further information on the subject:

 

It's also technically possible to edit Firewall Policies that have existing Application Control profiles via the GUI, but there are several caveats:

  • It is only possible to edit the settings of a specific Application Control profile via Firewall Policy overview page (Policy & Objects -> Firewall Policy). Selecting and editing a specific policy shows that the Application Control section is unavailable.
  • It is not possible to change the Application Control profile assigned to the Firewall Policy. It is only possible to remove it or leave the existing profile assigned.