Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
storaid
Contributor

NOW! FortiOS v5.2.5...

build701

Appeared in the download portal....

but [size="5"]no enhancements?????[/size]

 

FWF60D x2 FWF60C x3 FGT80C rev.2 FGT200B-POE FAP220B x3 FAP221B x2

FSW224B x1

FWF60D x2 FWF60C x3 FGT80C rev.2 FGT200B-POE FAP220B x3 FAP221B x2 FSW224B x1
2 Solutions
ede_pfau
Esteemed Contributor III

Jeez....

 

no enhancements! Fortinet finally keeps it's promise and just fixes things. Lo and behold. Keep up the good work, give us a rock solid v5.2 and put all the fancy new stuff into v5.4.

 

just my 2ct


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
HA
Contributor

Hello,

 

Problems occurs with SSL Inspection on 5.2.5. If you use SSL Inspection, it's better to run 5.2.3 (stable).

 

Regards,

 

HA

 

View solution in original post

69 REPLIES 69
VicAndr
New Contributor III

After upgrading FortiOS from v.5.2.3 to v.5.2.5, I see authentication issues on WPA2-Enterprise WiFi networks with remote RADIUS. Some clients/devices can connect to the wireless networks and others - cannot. ...did not have this problem while our FG/FWF units were on v.5.2.3. 

 

I see the same problem on different boxes: FWF80-CM, FG110C. Has anyone experienced the same problem?

Chris

VicAndr wrote:

After upgrading FortiOS from v.5.2.3 to v.5.2.5, I see authentication issues on WPA2-Enterprise WiFi networks with remote RADIUS. Some clients/devices can connect to the wireless networks and others - cannot. ...did not have this problem while our FG/FWF units were on v.5.2.3. 

 

I see the same problem on different boxes: FWF80-CM, FG110C. Has anyone experienced the same problem?

I have activated RadiusAuth (via QNAP) on a FWF60D (v5.2.5) since 2 Weeks.

Actually I detected no problems.

Currently connected devices are HTCOne (m7), Apple Ipad2 (IOS9.2), Lenovo TAB, ASUS Tab.

Paul_S
Contributor

Will someone running 5.2.5 please create a new object from a policy edit screen and see if this known issue affects them. Thank you.

 

BUG#286226 - Users may not be able to create new address objects from the Firewall Policy.

FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x                   [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5  |  Fortimail 5.3.11 Network+, Security+

FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5 | Fortimail 5.3.11 Network+, Security+
ISOffice

Hi Paul S,

 

We have a couple of 100D Appliances (v5.2.5, build 701), running Active-Passive. I was able to create an address object on-the-fly from within the Firewall Policy without any issues.

 

Hope this helps,

 

John P

Paul_S

ISOffice wrote:

Hi Paul S,

 

We have a couple of 100D Appliances (v5.2.5, build 701), running Active-Passive. I was able to create an address object on-the-fly from within the Firewall Policy without any issues.

 

Hope this helps,

 

John P

Thank you! I asked my SE about this bug too. Apparently the bug just means you cannot hit enter, you have to click the create button to the right. a minor issue in my opinion compared to not being able to create an object from that screen at all.

FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x                   [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5  |  Fortimail 5.3.11 Network+, Security+

FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5 | Fortimail 5.3.11 Network+, Security+
rpedrica

@Shogg, it's in the 5.2.5 Release Notes ...

shogg
New Contributor

rpedrica wrote:

@Shogg, it's in the 5.2.5 Release Notes ...

I've searched through the 5.2.5 release notes twice now and can't find that reference...the only mention I see is under the "Resolved Bugs" section: 

 

"287871  Administrative HTTPS and SSLVPN access using second WAN interface does not work as expected after  upgrade to 5.2.4."   ...nothing under the "Known Issues" section...that was why I was asking.    Could be I am just going blind.
tony8304
New Contributor

Hi All,

about the GUI access issue in 5.2.4, is this still exist in 5.2.5?

 

Thanks 

Tony

Bono
New Contributor

tony8304 wrote:

Hi All,

about the GUI access issue in 5.2.4, is this still exist in 5.2.5?

 

Thanks 

Tony

If you are talking about System tab which disappears, bug is still here.

Bono
New Contributor

Quick warning for everyone who is thinking of upgrading, I just drove 800KM though snow storm because of this bug.

I got 80D fortigate and with 5.2.3 and 5.2.4 device was stable but I upgraded device because of memory flash wear problem. And after 20 days I have logged to interface on public port and I saw error msg:

Log DescriptionSSL Message Authentication Code corrupted

MessageCorrupted MAC packet detected

 

after that all port forwards and managements ports are gone, I could ping the Fortigate but I cannot connect to it. Also I got one other IP as VIP which I use to web server and I could reach that IP but everything is so slow and of course I didn't enabled management on that IP.

When I got to the firm I saw there is no Internet and forti push updates failed because there was no Internet.

I don't know if anyone else experienced this but this is one nasty problem which cost me few hundred euros.

It's funny that I have now made backup so if it dies again I can connect to fortigate, because from local network I could connect to it. And I will connect via Mikrotik backup which costs 50€ and it's working reliably.

I'm only glad from my 10 devices I only upgraded one or I would be all over the country because of this.

Labels
Top Kudoed Authors