Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Toshi_Esumi
SuperUser
SuperUser

6.2.6

So nobody shouts out this release yet because the release note site is having problems now?

 

Toshi

22 REPLIES 22
Toshi_Esumi

According to TAC the iked crash is a known issue, which was fixed with 6.4.3 but didn't go in 6.2.6., and likely in 6.2.7.

boneyard

does it always happen or only in certain situations? anything more known?

Toshi_Esumi

I asked the conditions of the crash when they replied to me yesterday. I'll update when I get the answer.

boneyard

did they get back to you Toshi?

Toshi_Esumi

Yes they did but not with an answer I wanted. TAC got a reply from Dev or QA saying "config change". But that doesn't explain what I'm seeing after the upgrade. And TAC guy himself was not satisfied with the answer either because he couldn't recreate it, so he requested further explanation.

He also requested this bug to be listed in those release notes.

Toshi_Esumi

I just got an update. The condition is:

- a configuration change when the IPsec interface is in a zone or sdwan interface

And the tech recreated the problem with similar config to mine: an IPsec VPN interface in a zone, and added a new policy using the zone. I don't think this is the only way to trigger the crash but probably a similar situation happened when I upgraded.

He also said it's now in 6.2.6 release notes (6689554 under IPsec VPN section). But previous comment about the fix on 6.4.3 was wrong. It never happens to 6.4.2 or 6.4.3, therefore no update on 6.4.3 release notes.

There finally there is a special patch is available for this problem. So you can request it if your issue is identified as the same.

lubyou

toshiesumi wrote:

I just got an update. The condition is:

- a configuration change when the IPsec interface is in a zone or sdwan interface

And the tech recreated the problem with similar config to mine: an IPsec VPN interface in a zone, and added a new policy using the zone. I don't think this is the only way to trigger the crash but probably a similar situation happened when I upgraded.

He also said it's now in 6.2.6 release notes (6689554 under IPsec VPN section). But previous comment about the fix on 6.4.3 was wrong. It never happens to 6.4.2 or 6.4.3, therefore no update on 6.4.3 release notes.

There finally there is a special patch is available for this problem. So you can request it if your issue is identified as the same.

It is not the only way to trigger the crash, as we did not have any of our IPsec interfaces in a zone or sdwan.

Thanks for keep this thread updated!

boneyard
Valued Contributor

there is a bulletin since November 25th on the support portal that says it can happen after upgrade to 6.2.6 and any configuration change or address change on dynamic interface.

 

the solution will be in 6.2.7 and as Toshi mentions you can contact them for 6.2.6, which is an interim build then i assume.

bommi
Contributor III

Interim builds are not covered by support, you should know this before doing the upgrade.

Is there any ETA for 6.2.7? Will it be released in weeks or months?

NSE 4/5/7

NSE 4/5/7
bommi
Contributor III

Anyone using FortiOS 6.2.6 with ngfw policy mode?

Seeing a massive amount of ips engine crashes on my 60f.

NSE 4/5/7

NSE 4/5/7
Labels
Top Kudoed Authors