| Description | This article describes an issue when the firewall policy does not work with a proxy policy after an upgrade from v7.4.3 to v7.4.4, v7.4.7. |
| Scope | FortiGate v7.4.4, v7.4.7 |
| Solution |
This issue is caused by a bug introduced in v7.4.4 and v7.4.7 also where FortiGate blocks traffic if a one-time schedule or recurring schedule is used in the explicit proxy policy. The traffic matches the implicit deny policy even though the schedule is showing active (not expired) due to WAD getting the wrong time zone after chroot.
execute time diagnose test app wad 1000 diagnose test app wad 2300 diagnose test app wad 156 diagnose debug enable diagnose debug console timestamp enable diagnose wad debug enable level info diagnose wad debug enable category policy
Sample output:
Ertiga-kvm10 # [I]2024-08-02 16:36:35.846993 [p:2075][s:305508864][r:227] wad_http_conn_req_classify :6140 no security profil
This issue is fixed in v7.6.0. Apply the 'always' schedule as a workaround until the system is upgraded to the fixed version. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.