[UPGRADED: 201407300634] FortiGate NPU&FortiOS v5.0.x Learning...

雖然4.0MR3已經EOL了..
不過, 今天又發放了P16版本...
修了不少bugs..
Upgrade
Email Filter
Firewall
Table 7: Resolved upgrade issues
Bug ID Description
216937 Resolved an issue that would cause the FortiGate to stop responding during a
firmware upgrade.
Table 8: Resolved email filtering issues
Bug ID Description
206338 SMTP splice mode now works correctly.
178125 Resolved SMTP MTA timeout issues caused by SMTP splice mode changes
related to SMTP body filter bypass changes.
Table 9: Resolved firewall issues
Bug ID Description
244552 Resolved an issue with how schedules are determined that would rarely cause
some traffic to be matched with the wrong firewall policy.
221388 Resolved an issued that caused Sflow traffic captures to show incorrect frame
length.
231201 Resolved an issued that caused proxyworker outages after vdom creation/deletion.
225508 Resolved an issued that with proxy-based IMAP processing in which the
STARTTLS command's CRLF for terminated identifier was changed to LF.
201556 Resolved a firewall load balancing issue that blocked Outlook RPC requests.
171261 Resolved an issue that prevented custom replacement messages from displaying
images during flow based webfiltering.
212547 Resolved an issue that blocked TLS sessions when UTM enabled.
203335 Resolved an issue that blocked firewall load balancing health checking.
225480 Resolved an issue with FortiOS in Transparent mode blocking SMTP traffic. Resolved Issues Page 24 FortiOS v4.0 MR3 Patch Release 16 Release Notes
FortiOS Carrier
High Availability
IPsec VPN
Logging and Reporting
217049 Resolved an issue with firewall throughput for the FortiGate-40C.
206480 Resolved an issue that caused multicast encrypted packets to be dropped by XLP
processors in Fastpath mode.
Table 9: Resolved firewall issues (continued)
Bug ID Description
Table 10: Resolved FortiOS Carrier issues
Bug ID Description
191807 Resolved an issue that prevented the carrier_ep field from appearing in traffic logs
when dynamic profiles are enabled.
207312 MIME header parsing now works correctly when no whitespace exists after the
colon following the field name.
Table 11: Resolved high availability issues
Bug ID Description
220856 Resolved an issue with virtual clustering that would cause HA out of synch
messages when deleting a VDOM.
208454 Resolved an issue that prevented IPSec tunnels with NAT traversal enabled from
being synchronized to all cluster units. As a result, NAT traversal tunnels would not
resume after a failover.
Table 12: Resolved IPsec VPN issues
Bug ID Description
190285 Resolved an issue that prevented offloaded IPSec traffic from flowing after an
IPsec rekey.
Table 13: Resolved logging and reporting issues
Bug ID Description
207158 Resolved an issue that prevented log directories from being created by
Fortimanager for VDOMs.
216207 Resolved an issue that reversed src and dst interfaces in ICMP host unreachable
log messages.Resolved Issues Page 25 FortiOS v4.0 MR3 Patch Release 16 Release Notes
Routing
SSL VPN
206998 FortiOS uploads new logs only when uploading logs to FortiAnalyzer using FTP.
161008 Resolved an issue that preventing logging firewall multicast policy DENY log
messages.
Table 14: Resolved routing issues
Bug ID Description
210710 Resolved an issue where PPPOE renew/flapping causes GRE tunnels to stop
passing traffic.
222255 Resolved an issue that prevented OSPF graceful restart from working if multiple
helpers are configured.
199589 Resolved an issue the prevented OSPF from reconverging after HA failover if the
topology is changed during failover.
223729 Resolved an issue that caused route entry 0.0.0/32 to close the connection to BGP
neighbors.
209766 Resolved an issue that prevented IGMP leave messages from taking effect.
Table 13: Resolved logging and reporting issues (continued)
Bug ID Description
Table 15: Resolved SSL VPN issues
Bug ID Description
231092 Resolved an issue that caused SSL VPN plugins to fail new Java Manifest
requirements.
200513 Resolved an issue that prevented displaying specific emails on OWA 2007 through
SSL Web portal with IE.
203649 Resolved an issue that caused SSL VPN crashes for FGT VMs when the using
client certificate.
209222 Resolved SSL VPN issues with Windows clustered SMB shares.Resolved Issues Page 26 FortiOS v4.0 MR3 Patch Release 16 Release Notes
System
Web-Based Manager
Web Filtering
Table 16: Resolved system issues
Bug ID Description
214637 Resolved an issue that caused the configuration to get corrupted after certain
CRLs are uploaded.
204117 Resolved a memory leak with IPS packet and DLP archive jobs left in shared
memory.
207572 Resolved an issue that caused intermittent crashes with no crashdump.
207034 Resolved an issue that caused file system crashes when connected to a ZTE 3g
modem.
218871 Resolved an issue that caused excessive session clash logs.
216108 Resolved an issue that caused NP4 interfaces on FGT-800Cs to stop forwarding
traffic periodically.
124642 The command execute backup config managementstation has been
added to the FGT-1240B.
192089 Resolved an issue that caused inconsistent L2 hashing results for NPU sessions
with link aggregation interfaces.
223931 Resolved an issue that caused SNMP interface polling to cause CPU usage spikes.
201853 Resolved an issue that caused ntpd hangs resulting in FortiGate units going out of
sync with time servers.
179613 Resolved an issue that prevented port9 to port12 of the FGT-3040B from
negotiating with Huawei router model NE40.
Table 17: Resolved Web-based manager issues
Bug ID Description
191565 Resolved an issue that prevented GUI access until the FortiGate is rebooted.
Table 18: Resolved Web filtering issues
Bug ID Description
200350 Resolved an issue that prevented the authenticaiton keep alive page from
displaying when Webfilter quotas are assigned with more than 3 categories.
188248 Resolved an URL filtering issue that caused memory leaks.Resolved Issues Page 27 FortiOS v4.0 MR3 Patch Release 16 Release Notes
VoIP
Wireless
Table 19: Resolved VoIP issues
Bug ID Description
207507 Resolved an issue that caused H323 cals to drop after a while because the session
is removed from the session table.
205931 Resolved an issue that prevented H225 RAS:locationRequest Ipaddress field from
being translated by the session-helper.
Table 20: Resolved wireless issues
Bug ID Description
173570 Resolved an issues that caused the Motorola MC30/31 barcode scanner to
repeatedly get dropped from the Wifi connection.
vxr wrote:
v5.2的討論建議在...(恕刪)
不好意思請問下,
關於Fortigate DHCP + 無線分享器AP模式 Wifi取得IP問題
在別樓我有發問,這裡
大概是行動裝置、筆電無線網卡透過AP無法取得Fortigate發配的IP,
但接有線卻沒問題。需將無線分享器重開 才能透過無線取得IP
而我無線分享器有三種廠牌、多種不同型號都有這問題,但若讓AP自行發配IP就沒問題

Fortigate DHCP IP發放範圍台廠100-254,30台電腦。陸廠30-254,40台電腦
租用時間1天
------------------------------------------
有網友回應說是:
99%是f牌防火牆的DHCP相容性問題...造成WIFI拿不到IP...
看他有沒有選項能增加相容...
------------------------------------------
IThome邦幫忙也有相同案例
不知道這問題有沒有的解??
因為以前台、陸廠使用SonicWall時 印象中沒這問題。

被蟑螂綁架的豬 wrote:
不好意思請問下,關於Fortigate DHCP + 無線分享器AP模式 Wifi取得IP問題...(恕刪)

我在使用上沒遇到過這個問題呢,都可以由 Fortigate 的 DHCP 成功的取得IP,不論有線或無線

您幫忙確認一下是無法取得 IP,還是有取得 IP 但無法上網呢。另外一篇文章中也有人覺得可能是 DHCP 中 DNS Option 欄位設定的問題。





不想唸物理了...
是透過Wifi無法取得IP(抓不到),但同台無線分享器插有線的裝置就可以取得
要重開AP後 透過Wifi的行動裝置或筆電才行抓到IP,每隔一段時間發生一次
而Fortigate DNS我是設定主內部主機 次外部ISP主機
取得DNS是沒什麼問題

難不成我無線路由器買太Low End了...
我大概都買500~1000家用等級而已

我想到了!無線網卡用Intel最容易發生,其他也是有~但沒這麼頻繁
對岸MIS常反應用無線抓不到IP要重啟無線分享器,我不確定他使用的裝置
而我、老闆娘、台幹NB 無線都是Intel晶片就常碰到抓不到IP 要重開AP
(網卡驅動新舊版都試過,若無線AP設Route Mode就不會有事)
wenwenwen wrote:
您幫忙確認一下是無法取得 IP,還是有取得 IP 但無法上網呢。另外一篇文章中也有人覺得可能是 DHCP 中 DNS Option 欄位設定的問題。
4.0MR3 P17發佈..
緊急修復一個跟NPU有關的bug..
Resolved an issue that caused kernel panic and auto-reboot when pinging through
accelerated ports.
just now FortiOS v5.0.8 has been released....!
Summary of Enhancements
Firewall
• Support IPv6 DoS policy on XLP (211082)
System
• LTE Daemon support for Novatel U679 (Bell) (225531,234743)
• Port kernel profiling function (237984)
#dia sys profile cpumask 0xffffffff
# dia sys profile start
# dia sys profile stop
# dia sys profile show
• Support IPv6 DoS policy on XLP. (186581)
• Add SPAN support for FG-200D/240D/280D. (217060)
• When a crash occurs, generate an event log to record some brief information about it.
(238137)
• Add MIB entities for USB LTE Modem and change USB MODEM widget GUI. (237150)
Wireless
• FAP 11ac radio support for DARRP. (243332)
• Radius Accounting for Wireless. (228497, 224968)

Default Behavior/Config Change
The following table lists FortiOS default behavior/Config change.
Table 6: FortiOS default behavior/Config change
Bug ID Description
247953 Add a default DHCP server for management port on 200D, 240D, 280D-POE,
100D and 140D.
247162 Hide switch controller on 600/800/1000 series.
246438 Change FG-30D default to full GUI.
246577 Configurable syslog server setting by WebGUI for 3600C, 3950B, 3700D.
247321 Move URL match list into explicit proxy page.
188763 Improvement to default mesh SSID. => 預設mesh已經被銷毀

Resolved Issues
This chapter describes issues with past releases of FortiOS v5.0 that have been resolved for FortiOS v5.0 Patch Release 8. For inquires about a particular bug, please contact Customer Service & Support.

FortiOS v5.0.9 has been released...
緊急修復一個安全性漏洞...
Fixed insufficient sanitization of Telnet and SSH usernames when displayed in
the web administration interface
vxr wrote:
FortiOS v5...(恕刪)

4.0MR3 P18 has been released...
同v5.0.9的安全漏洞修復...
vxr大大請教一下,
Fortigate 80C可以將log的紀錄寫在USB Disk裡面嗎?
FortiOS是V4.0 MR3 Patch 18,謝謝!
≡≡ 覺人之詐,不憤于言;受人之侮,不動于色;察人之過,不揚于他;施人之惠,不記于心 ≡≡

HIMALAYAS wrote:
vxr大大請教一下,...(恕刪)

要短路一個jumper...
在PCB版上的USB附近有一個2pins的JUSB jumper..

這會遇到一個情況..
他的boot全部都會配置到那你安裝的USB Disk..
因此你需要進BIOS重新再裝一次OS...

5.0.x與4.x皆可使用(5.2.x封殺)..
文章分享
評分
評分
複製連結
請輸入您要前往的頁數(1 ~ 35)

今日熱門文章 網友點擊推薦!