Producent oprogramowania Fortinet, udostępnił najnowszą wersję FortiClient o oznaczeniu 7.0.0. Dzięki nowej wersji, będziemy mogli się spodziewać poprawienia wielu błędów. Mowa tutaj o problemach przy połączeniach, gdzie tunel VPN powodował wiele problemów. W wersji 7.0.0, rozwiązano problem z autoryzującą poprzez FortiToken, ponieważ nie zawsze aplikacja żądała potwierdzania tokenem. Problem dotyczący połączenia VPN przed zalogowaniem do Windowsa, został skorygowany. Po aktualizacji oprogramowania, wyświetlane informacje na FortiGate są bardziej dokładne i nie mają już tylu problemów. Po więcej szczegółowych informacji, zapraszam do dalszej części artykułu.
Wspierane system:
Windows:
- Microsoft Windows 10 (32-bit and 64-bit)
- Microsoft Windows 8.1 (32-bit and 64-bit)
- Microsoft Windows 7 (32-bit and 64-bit)
- Microsoft Windows Server 2019
- Microsoft Windows Server 2016
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2012
- Microsoft Windows Server 2008 R2
MacOs:
- macOS Big Sur (wersja 11)
- macOS Catalina (wersja 10.15)
- macOS Mojave (wersja 10.14)
Linux:
- Ubuntu od 16.04
- CentOS od 7.4
- Red Hat od 7.4
Rozwiązane problemy:
Zero Trust Telemetry
Endpoint control
| Bug ID | Description |
|---|---|
| 693087 | EMS should show Owner for an endpoint device. |
Logs
| Bug ID | Description |
|---|---|
| 599560 | Notification page reports USB block alert source as unknown. |
| 654336 | Event log epenfeatures contains firewall, which is disabled. |
| 664452 | Endpoint Control logs improvement. |
| 700466 | Create proper logs and message when license expires. |
Malware Protection and Sandbox
| Bug ID | Description |
|---|---|
| 602768 | Cloud-based malware detection does not honor allowlisted files. |
| 704823 | Antivirus scan does not start. |
Remote Access
| Bug ID | Description |
|---|---|
| 617420 | Remote Access VPN with prelogon without user interaction. |
| 645174 | FortiClient sometimes does not use the remoteauthtimeout value configured on the FortiGate for SSL VPN. |
| 671392 | Windows restart does not remove SSL VPN tunnel that VPN before logon established. |
| 677766 | When VPN tunnel goes down, the single host route for the VPN server stays. |
| 682675 | SSL VPN users cannot set new PIN after it has expired when using RSA RADIUS authentication. |
| 688043 | VPN before logon does not prompt for FortiToken request. |
| 689176 | IPsec VPN failover to SSL VPN when using VPN before logon does not work properly. |
| 690769 | User cannot start VPN connection with ENTER key. |
| 695054 | IPsec VPN disconnects right after the tunnel establishes. |
| 695133 | DNS resolution is inconsistent when IPv6 is enabled on the desktop. |
| 698177 | Public IP address detection and SSL VPN. |
Web Filter and plugin
| Bug ID | Description |
|---|---|
| 696581 | FortiClient extension pauses download when extension is installed but not in use. |
Other
Znane problemy do rozwiązania:
FortiSASE SIA
| Bug ID | Description |
|---|---|
| 701552 | FortiSASE SIA tunnel reconnection issues after FortiSASE SIA portal removes VPN user. |
Application Firewall
| Bug ID | Description |
|---|---|
| 710910 | The Application Firewall tab becomes visible after reboot when it should remain hidden. |
GUI
| Bug ID | Description |
|---|---|
| 708855 | GUI shows site is unavailable when blocked. |
Endpoint control
| Bug ID | Description |
|---|---|
| 699686 | EMS does not receive software inventory from FortiClient (Windows). |
| 702660 | Switching Active Directory users does not modify user details in EMS Endpoints pane. |
FSSOMA
| Bug ID | Description |
|---|---|
| 705256 | SSOMA fails to call WTSQueryUserToken. |
Zero Trust Telemetry
| Bug ID | Description |
|---|---|
| 587327 | Device detection/VPN autoconnect frequency is too often. |
| 652647 | FortiClient fails to upload large diagnostics tool result file to EMS. |
| 687611 | FortiClient should calculate AD group-based policy rule for tags. |
| 693928 | After FortiClient successfully migrates to a new EMS, it does not remove original EMS from EMS list. |
| 697795 | FortiClient fails to calculate on-fabric result. |
| 701552 | SASE SIA tunnel reconnection issues after SASE SIA portal removes VPN user. |
| 702660 | Switching AD users does not modify user details in EMS Endpoints table. |
| 705010 | EMS shows endpoints with incorrect usernames. |
| 705664 | FortiGate waits about one minute to get ztna-ems-tag update. |
| 714131 | Migrating FortiClient to a different server fails when connection key is enabled. |
Malware Protection and Sandbox
| Bug ID | Description |
|---|---|
| 590688 | FortiClient says FortiSandbox scan does not support file type when extension is supported and enabled on FortiSandbox. |
| 683027 | FortiClient (Windows) shows quarantine message, even if Application Firewall is not installed and quarantine mode will not work. |
| 691328 | FortiClient upgrade does not upgrade antivirus engine as deployed through an EMS installer. |
| 705761 | FortiClient (Windows) does not block USB drives when removable media access is configured to block WPD devices. |
| 713557 | Exceptions do not work for AntiExploit module. |
Remote Access
| Bug ID | Description |
|---|---|
| 700092 | VPN does not connect when using domain user account. |
| 700440 | Application-based split tunneling does not work. |
| 702965 | Host check interval does not work as expected after PC has previously gone into sleep mode. |
| 703939 | FortiClient does not send UID to SSL VPN daemon. |
| 706023 | FortiClient (Windows) loses DNS settings after restarting computer. |
| 707882 | IPsec VPN fails to autoconnect and displays Failed to launch IPsec service error. |
| 709001 | SSL VPN host check validation does not work for SAML user. |
| 710603 | VPN resets with each EMS push. |
| 711227 | Per-user autoconnect starts autoconnecting before logging onto Windows. |
| 711402 | Per-user autoconnect does not establish and remains connected after logging onto Windows. |
| 713909 | If Enable VPN before Windows is enabled and there are multiple tunnels configured, there is long delay before Windows login prompt. |
| 714564 | SAML connection stays in connecting state and never return with error when FortiGate gateway is inaccessible. |
Console
| Bug ID | Description |
|---|---|
| 690679 | EMS cannot tag endpoints based on nested AD groups. |
| 703213 | Reusing/sharing SAML identity provider cookie. |
| 707440 | Clear Logs button on Settings page is disabled after unlocking settings. |
Vulnerability Scan
| Bug ID | Description |
|---|---|
| 630202 | Vulnerability Scan cannot detect Zoom.exe installer. |
Logs
| Bug ID | Description |
|---|---|
| 709729 | realtime_scan log disappears after ten seconds. |
Other
| Bug ID | Description |
|---|---|
| 69182 | FortiClient does not support the pound (£) sign. |
| 689936 | GUI issue when connecting to IPsec VPN using FortiTray. |
Notatki producenta: FortiClient 7.0.0
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie
