Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Carl_Wallmark
Valued Contributor

FortiOS 4.3.2 is out

.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
39 REPLIES 39
Allan_Mouawad

DaniloMolini
I had the same issue earlier last week. The problem seems to be the Fortiguard IP addresses were not being saved on the device. If you goto the CLI and type the following: diag debug rating You should get a list of IP addresses. When I was getting the gethostbyname() errors this list was empty. I typed ' get system fortiguard' to get the main settings and then retyped ' diag debug rating' and the list refreshed fine. If it doesn' t refresh for you, you can always add the IP addresses manually, like: config system fortiguard set hostname 208.91.112.194 end
TMX1
New Contributor

Where did the FortiClient download link disappear to now ? It used to be in the System -> Status -> License Information
ejhardin

Two issues that I have noticed. Both Fortigate 200B and 60C: If you have a firewall policy using the " any" interface and try to move a policy from the gui you get an error " Moving a policy from one interface/zone pair to a different interface/zone pair is not permitted" . Doing it from the CLI works just fine. So far just on my 60C: Issue with creating a new firewall address and then using it in a firewall policy it shows as blank and the cli shows " " . Restart resolved the issue but not sure for how long.
veechee
New Contributor

I updated a standalone 60C to 4.3.2 last weekend and so far it' s running okay. I noticed that the IPS rules I had got reset but overall it' s working okay. Memory usage is higher than same config was on 4.2.8 which is dissapointing. I' m happy enough with it to leave it on that 60C, but the units I have with IPSec VPNs site-to-site I am going to leave on 4.2.8+ until at least a couple more patches come out for 4.3.
kckong
New Contributor III

I have tried the IPS on MR3 patch 2, the performance is much better than MR2. In MR2 build 328, I found that if I enable the IPS checking on my FGT-60B, the bandwidth will be drop 5/6, from about 28MB down to only 5MB. In MR3 patch, the bandwidth only drop about 1/6
Phuoc_Ngo
New Contributor

IPS rules I had got reset but overall it' s working okay. Memory usage is higher than same config was on 4.2.8 which is dissapointing.
We upgraded our stand alone (310B device) a week ago and keep on seeing the Daemon scanunitd shut down and restart every single day. It seem like the process is unstable.
veechee
New Contributor

Phuoc Ngo, I just upgraded to 4.3.2 and noticed the scanunitd shuts down and starts up after every push update, so I think this is not that it' s unstable, but instead that the Event log now records that event whereas in 4.2.x it did not. Does anyone know otherwise?
vanc
New Contributor II

That' s normal. scanunitd needs to restart to use the updated virus signatures.
ORIGINAL: veechee Phuoc Ngo, I just upgraded to 4.3.2 and noticed the scanunitd shuts down and starts up after every push update, so I think this is not that it' s unstable, but instead that the Event log now records that event whereas in 4.2.x it did not. Does anyone know otherwise?
Phuoc_Ngo
New Contributor

Anybody experience the system going into conserve mode? Our firewall (310B devices) went into conserve mode for a minutes or so with 1,800 concurrent session connection. That number of sessions is not even one percent of the firewall capacity. Date Time 2011-10-11 14:36:59 Date 2011-10-11 Time 14:36:59 Level critical critical Sub Type system ID 22802 Service im Message The system has entered system conserve mode
Carl_Wallmark
Valued Contributor

I have seen it with the smaller/older units like the 100A.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Labels
Top Kudoed Authors