Helpful ReplyHot!FortiOS 5.4.8 Is Out?

Author
SecurityPlus
Gold Member
  • Total Posts : 169
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/08/11 18:41:34
  • Status: offline
2018/01/18 21:16:17 (permalink)
0

FortiOS 5.4.8 Is Out?

In the process of upgrading a FortiGate 60E from 5.4.6 to 5.4.7. It looks as though I need to get a special build to do this as the upgrade page of the UI says that I can not upgrade from FortiOS v5.4.7 build1167 from FortiOS v5.4.6 build6408. I presume that I need to download FortiOS v5.4.7 build6453. Is this correct?
 
While looking for the correct image to download I noticed a listing for 5.4.8.
https://support.fortinet....ad/FirmwareImages.aspx
 
Has this been released? Has anyone tried 5.4.8 yet?

FWF30E, FG50E, FWF50E, FG60D, FWF60D, FG80E, FG100D
FortiOS 5.2, 5.4, and 5.6
FAP-221E. FAP-221C
#1
SecurityPlus
Gold Member
  • Total Posts : 169
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/08/11 18:41:34
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/01/18 21:42:02 (permalink)
0
I see the FortiOS 5.4.8 Release Notes.
 
I don't see the What's New in 5.4.8 yet.
#2
ede_pfau
Expert Member
  • Total Posts : 5624
  • Scores: 380
  • Reward points: 0
  • Joined: 2004/03/09 01:20:18
  • Location: Heidelberg, Germany
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/01/19 04:21:57 (permalink)
0
Resolved issues...lo and behold!
458586 In the Policy list page, Interface Pair View always displays as expand-all.

 
@SecurityPlus: I think it's build 6501 for the 60E, available for download (at 13:20 CET).

Ede

" Kernel panic: Aiee, killing interrupt handler!"
#3
SecurityPlus
Gold Member
  • Total Posts : 169
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/08/11 18:41:34
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/01/19 14:09:08 (permalink)
0
I will check again. Thanks.
#4
Silver
Gold Member
  • Total Posts : 263
  • Scores: -1
  • Reward points: 0
  • Joined: 2013/02/25 00:43:47
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/01/19 20:57:04 (permalink)
0
Anyone try 5.4.8
#5
ede_pfau
Expert Member
  • Total Posts : 5624
  • Scores: 380
  • Reward points: 0
  • Joined: 2004/03/09 01:20:18
  • Location: Heidelberg, Germany
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/01/20 03:56:37 (permalink)
0
Yes, on a 60E. Glitch-free so far.
I still can't believe they've fixed the policy view bug. Another way to make customers happy...introduce a completely unnecessary bug, keep it alive for some patches and then remove it.
My impression is that the policy table is displayed in a different fashion, more like 'faded in' as a whole. The RN are interesting, lots of fixes and (alas) quite some known issues.

Ede

" Kernel panic: Aiee, killing interrupt handler!"
#6
apex
Bronze Member
  • Total Posts : 31
  • Scores: 0
  • Reward points: 0
  • Joined: 2011/08/24 06:33:11
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/01/23 02:26:37 (permalink)
0
I like the bug ID #441284 - under resolved issues in the release notes.
I'm sure this referenced website will suddenly get a huge amount of hits 
funny..
#7
ddskier
Gold Member
  • Total Posts : 381
  • Scores: 16
  • Reward points: 0
  • Joined: 2007/04/10 08:18:06
  • Location: Chicago, IL
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/01/25 09:22:37 (permalink)
0
I believe that Sebastiaan Koopmans stated in within the 5.4.6 posting, that there as a SSL VPN throughput issue with that firmware version.
 
Does anyone know if that issue has been resolved in 5.4.8?

-DDSkier

FCNSA, FCNSP
FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
#8
danilo.cardoso
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/02/05 11:15:32
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/02/06 02:31:38 (permalink)
0
Well.
I´m planning to upgrade my 100D to that version from the old 5.0.9.
 
Just taking some courage. 
#9
SecurityPlus
Gold Member
  • Total Posts : 169
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/08/11 18:41:34
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/02/06 06:00:09 (permalink)
0
Are you planning to follow the supported upgrade path cookbook?
http://cookbook.fortinet....-upgrade-paths-fortios

What features of the 100D are you using?

Is this firewall under support should you encounter any problems?
#10
danilo.cardoso
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/02/05 11:15:32
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/02/06 08:45:31 (permalink)
0
SecurityPlus
Are you planning to follow the supported upgrade path cookbook?
http://cookbook.fortinet....-upgrade-paths-fortios

What features of the 100D are you using?

Is this firewall under support should you encounter any problems?



 
These are the enable features on global config
 
config system global    set admin-concurrent enable    set admin-https-redirect enable    set admin-maintainer enable    set allow-traffic-redirect enable    set auth-policy-exact-match enable    set batch-cmdb enable    set csr-ca-attribute enable    set dst enable    set endpoint-control-fds-access enable    set fds-statistics enable    set gui-antivirus enable    set gui-ap-profile enable    set gui-application-control enable    set gui-certificates enable    set gui-client-reputation enable    set gui-dynamic-routing enable    set gui-endpoint-control enable    set gui-explicit-proxy enable    set gui-implicit-policy enable    set gui-ips enable    set gui-multiple-utm-profiles enable    set gui-vpn enable    set gui-vulnerability-scan enable    set gui-webfilter enable    set ipsec-hmac-offload enable    set phase1-rekey enable    set registration-notification enable    set remoteauthtimeout 5    set send-pmtu-icmp enable    set sslvpn-cipher-hardware-acceleration enable    set sslvpn-kxp-hardware-acceleration enable    set strict-dirty-session-check enable    set wireless-controller enable
#11
SecurityPlus
Gold Member
  • Total Posts : 169
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/08/11 18:41:34
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/02/06 22:23:01 (permalink)
0
It would be beneficial to review the release notes for each version that you will encounter or pass. I wonder if it would be worth taking this in stages instead of doing this in mass.
#12
Baptiste
Gold Member
  • Total Posts : 144
  • Scores: 13
  • Reward points: 0
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/02/07 00:21:21 (permalink) ☄ Helpfulby NeilG 2018/03/13 14:27:31
0
danilo.cardoso
Well.
I´m planning to upgrade my 100D to that version from the old 5.0.9.
Just taking some courage. 



Don't forget to save you config before and after each upgrade
 
You can check if some items are not correctly upgrade :
diagnose debug config-error-log read




FGT 100D 5.4.9 + FTK200
FGT 60E 5.6.3 & 6.0.0
FGT 40C 5.0.13
FAZ VM 6.0.0
FAP 210B/221C/223C/321C/421E
#13
ddskier
Gold Member
  • Total Posts : 381
  • Scores: 16
  • Reward points: 0
  • Joined: 2007/04/10 08:18:06
  • Location: Chicago, IL
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/02/14 07:22:53 (permalink)
0
FYI - I believe I have identified a bug with IPV6 BGP.   It doesn't seem to be announcing our prefix to the upstream ISP.
 
Fortinet took a look at it and recommended we roll back firmware until they can lab this out and figure out the issue.

-DDSkier

FCNSA, FCNSP
FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
#14
ddskier
Gold Member
  • Total Posts : 381
  • Scores: 16
  • Reward points: 0
  • Joined: 2007/04/10 08:18:06
  • Location: Chicago, IL
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/02/27 08:33:02 (permalink)
0
I believe I have also identified another bug with SSLVPN using IPV6.   The LDAP audentication fails on IPv6 but works normally on IPv4.  Strange.
 
Fortinet is also researching this bug as well.

-DDSkier

FCNSA, FCNSP
FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
#15
ddskier
Gold Member
  • Total Posts : 381
  • Scores: 16
  • Reward points: 0
  • Joined: 2007/04/10 08:18:06
  • Location: Chicago, IL
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/03/09 18:37:55 (permalink) ☄ Helpfulby NeilG 2018/03/13 14:27:39
5 (2)
Update on IPv6 BGP Issue.   Fortinet support was able to finally repro the issue in their labs and they were able to suggest a fix for the issue.  Added the following line to config router bgp:
 
set network-import-check disable

-DDSkier

FCNSA, FCNSP
FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
#16
NeilG
Silver Member
  • Total Posts : 71
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/03/04 11:00:39
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/03/13 14:28:19 (permalink)
0
ddskier
Update on IPv6 BGP Issue.   Fortinet support was able to finally repro the issue in their labs and they were able to suggest a fix for the issue.  Added the following line to config router bgp:
 
set network-import-check disable


 
 
Thanks for updating us on your resolution!
#17
ddskier
Gold Member
  • Total Posts : 381
  • Scores: 16
  • Reward points: 0
  • Joined: 2007/04/10 08:18:06
  • Location: Chicago, IL
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/03/21 08:05:20 (permalink)
0
Official word from Fortinet.   Not LDAP IPv6 support until 6.0

-DDSkier

FCNSA, FCNSP
FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
#18
seadave
Gold Member
  • Total Posts : 282
  • Scores: 30
  • Reward points: 0
  • Joined: 2004/11/03 18:02:09
  • Location: Seattle, WA
  • Status: offline
Re: FortiOS 5.4.8 Is Out? 2018/03/29 16:41:30 (permalink)
0
ddskier
Update on IPv6 BGP Issue.   Fortinet support was able to finally repro the issue in their labs and they were able to suggest a fix for the issue.  Added the following line to config router bgp:
 
set network-import-check disable


I'd be interested to know how many people are using IPv6.  We are so far away from that still.  Regardless that is a good bug catch and solid resolution.
#19
Jump to:
© 2018 APG vNext Commercial Version 5.5