Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
k_theos
New Contributor

FortiOS 6.4.3 problems!

Hello everyone, I am managing a Fortigate 60E, which up until yesterday, was running  FortiOS 6.2.1 build 0932(GA) for many months without any issue. I backed up the configuration and upgraded the system with the latest firmware and patches, following the proper upgrade path up to FortiOS v6.4.3 build1778 (GA) so the system is up to date. Ever since the upgrade, users complain about websites being blocked, general internet browsing delay and out of nowhere, "encrypted network traffic, untrusted certificate" prompt messages from their ESET antivirus, which i am not sure how relevant to our Fortigate device is but users claim that they started having these problems today which is after the FortiOS upgrade. Most of the websites being blocked have already been set up in the Policy & Objects ----> Addresses in the FQDN section to have access before the upgrade

 

I am running out of ideas atm and i am not sure if there is a way to properly downgrade the system back to 6.2.2 without creating bigger problems

 

Currently i am forced to turn Web filter off so everyone can work but this is not a solution of course.

 

Any ideas or anyone with similar problem ? Regards

5 REPLIES 5
ede_pfau
SuperUser
SuperUser

I guess you are using the built-in Factory certificate for SSL inspection. This is different in each firmware version. Either import it onto your users' PCs, or use a commercial cert which your users trust.

The complaint of ESET is correct...


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
vbhoj74

Just a thought, Will restoring the old backup not restore the old Fortinet CA SSL certificate ?

k_theos

I spend a good few hours last night trying to experiment and see if i can find a solution. In the end i downgraded back to the old firmware waiting for customer's feedback. The problem with the new firmware was that, not all users had connection issues after the upgrade but only a few

 

In my case i wasn't able to replicate the problem either. No ESET warnings no nothing.

 

Thank you all for your feedback

vbhoj74

ede_pfau wrote:

I guess you are using the built-in Factory certificate for SSL inspection. This is different in each firmware version. Either import it onto your users' PCs, or use a commercial cert which your users trust.

The complaint of ESET is correct...

I'm also new to Fortigate, correct me if I'm wrong, I think the SSL CA certificate is tied to the box, not the firmware. Firmware upgrade should not effect the SSL certificate.

boneyard
Valued Contributor

are you currently using proxy mode or flow mode?

 

do you still have access to the logs during the issue?

 

did the webfilter log show rating errors? did you check if you are HTTPS or UDP to communicate with FortiGuard?

Labels
Top Kudoed Authors