So nobody shouts out this release yet because the release note site is having problems now?
Toshi
According to TAC the iked crash is a known issue, which was fixed with 6.4.3 but didn't go in 6.2.6., and likely in 6.2.7.
does it always happen or only in certain situations? anything more known?
I asked the conditions of the crash when they replied to me yesterday. I'll update when I get the answer.
did they get back to you Toshi?
Yes they did but not with an answer I wanted. TAC got a reply from Dev or QA saying "config change". But that doesn't explain what I'm seeing after the upgrade. And TAC guy himself was not satisfied with the answer either because he couldn't recreate it, so he requested further explanation.
He also requested this bug to be listed in those release notes.
I just got an update. The condition is:
- a configuration change when the IPsec interface is in a zone or sdwan interface
And the tech recreated the problem with similar config to mine: an IPsec VPN interface in a zone, and added a new policy using the zone. I don't think this is the only way to trigger the crash but probably a similar situation happened when I upgraded.
He also said it's now in 6.2.6 release notes (6689554 under IPsec VPN section). But previous comment about the fix on 6.4.3 was wrong. It never happens to 6.4.2 or 6.4.3, therefore no update on 6.4.3 release notes.
There finally there is a special patch is available for this problem. So you can request it if your issue is identified as the same.
toshiesumi wrote:It is not the only way to trigger the crash, as we did not have any of our IPsec interfaces in a zone or sdwan.I just got an update. The condition is:
- a configuration change when the IPsec interface is in a zone or sdwan interface
And the tech recreated the problem with similar config to mine: an IPsec VPN interface in a zone, and added a new policy using the zone. I don't think this is the only way to trigger the crash but probably a similar situation happened when I upgraded.
He also said it's now in 6.2.6 release notes (6689554 under IPsec VPN section). But previous comment about the fix on 6.4.3 was wrong. It never happens to 6.4.2 or 6.4.3, therefore no update on 6.4.3 release notes.
There finally there is a special patch is available for this problem. So you can request it if your issue is identified as the same.
Thanks for keep this thread updated!
there is a bulletin since November 25th on the support portal that says it can happen after upgrade to 6.2.6 and any configuration change or address change on dynamic interface.
the solution will be in 6.2.7 and as Toshi mentions you can contact them for 6.2.6, which is an interim build then i assume.
Interim builds are not covered by support, you should know this before doing the upgrade.
Is there any ETA for 6.2.7? Will it be released in weeks or months?
NSE 4/5/7
Anyone using FortiOS 6.2.6 with ngfw policy mode?
Seeing a massive amount of ips engine crashes on my 60f.
NSE 4/5/7
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.