Helpful ReplyHot!FortiOS 6.2.5 is out!

Author
bommi
Gold Member
  • Total Posts : 154
  • Scores: 14
  • Reward points: 0
  • Joined: 2016/08/03 03:42:49
  • Location: Germany
  • Status: offline
2020/08/20 11:07:09 (permalink)
#1
SecurityPlus
Gold Member
  • Total Posts : 367
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/08/11 18:41:34
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/20 11:24:45 (permalink)
0
Any early adopters? I have not tried 6.2 nor 6.4 yet though I am interested.

FWF30E, FG40F, FG50E, FWF50E, FG60D, FWF60D, FG60E, FG60F, FG80E, FG100D
FortiOS 5.2, 5.4, 5.6, 6.0, 6.2, and 6.4
FortiSwitch FS-224E-POE
FAP-221E, FAP-221C
#2
James_G
Gold Member
  • Total Posts : 247
  • Scores: 11
  • Reward points: 0
  • Joined: 2016/02/28 02:55:47
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/21 06:03:43 (permalink) ☄ Helpfulby SecurityPlus 2020/08/21 07:27:16
0
6.4.2 still seems to have less issues, I am seeing reports of this one (6.2.5) breaking SSL inspection.
#3
bommi
Gold Member
  • Total Posts : 154
  • Scores: 14
  • Reward points: 0
  • Joined: 2016/08/03 03:42:49
  • Location: Germany
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/21 07:03:26 (permalink)
0
Right now only one of my customers did the upgrade from 6.2.4 on a fgt-30e without any issues.
#4
SecurityPlus
Gold Member
  • Total Posts : 367
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/08/11 18:41:34
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/21 09:18:07 (permalink)
0
James_G, where do you see these reports?

FWF30E, FG40F, FG50E, FWF50E, FG60D, FWF60D, FG60E, FG60F, FG80E, FG100D
FortiOS 5.2, 5.4, 5.6, 6.0, 6.2, and 6.4
FortiSwitch FS-224E-POE
FAP-221E, FAP-221C
#5
James_G
Gold Member
  • Total Posts : 247
  • Scores: 11
  • Reward points: 0
  • Joined: 2016/02/28 02:55:47
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/21 10:23:41 (permalink)
0
SecurityPlus
James_G, where do you see these reports?


Fortinet forum on Reddit
#6
Toshi Esumi
Expert Member
  • Total Posts : 2241
  • Scores: 215
  • Reward points: 0
  • Joined: 2014/11/06 09:56:42
  • Status: online
Re: FortiOS 6.2.5 is out! 2020/08/21 13:47:20 (permalink)
0
The report was SSL inspection only with QUIC though.
#7
Toshi Esumi
Expert Member
  • Total Posts : 2241
  • Scores: 215
  • Reward points: 0
  • Joined: 2014/11/06 09:56:42
  • Status: online
Re: FortiOS 6.2.5 is out! 2020/08/21 14:00:07 (permalink)
0
, of which claim is questionable because currently FGT can't scan QUIC. Only way is to block QUIC. See another thread at Reddit:
https://www.reddit.com/r/fortinet/comments/fshvui/quic_inspection_on_the_horizon/
 
#8
James_G
Gold Member
  • Total Posts : 247
  • Scores: 11
  • Reward points: 0
  • Joined: 2016/02/28 02:55:47
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/21 14:20:48 (permalink)
0
toshiesumi
The report was SSL inspection only with QUIC though.


Yeah it's an odd report as you said, quic not supported, but something underlying I think. Will know more in coming days.
#9
Toshi Esumi
Expert Member
  • Total Posts : 2241
  • Scores: 215
  • Reward points: 0
  • Joined: 2014/11/06 09:56:42
  • Status: online
Re: FortiOS 6.2.5 is out! 2020/08/21 14:26:24 (permalink)
0
James_G
toshiesumi
The report was SSL inspection only with QUIC though.


Yeah it's an odd report as you said, quic not supported, but something underlying I think. Will know more in coming days.

I'm more concerned with those many known issues, including still some WAD issues and SSL VPN ones, then of course GUI issues, etc.
#10
MartinOlszynski
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/08/24 04:15:10
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/24 04:21:14 (permalink)
0
Fortigate 101E:
Upgrade issue
 
post edited by MartinOlszynski - 2020/08/24 06:21:44

Attached Image(s)

#11
JasperW
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/01/17 01:56:35
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/25 01:44:15 (permalink)
0
I upgraded my FGT201E saturday the 22nd from 6.2.4 to 6.2.5. The upgrade process went smooth. I do have problems with SSL Deep Inspection, especially (strangely enough) on exempted addresses.
In a proxy-based policy with "ssl deep inspection" enabled, some exempted addresses do not load in the browser, a connection failed error appears in the browser. I haven't pin pointed yet why certain sites that are exempted do not load while others do. In flow-based policies the problem does not occur.

My workaround for now is to add the same exempted addresses to a policy higher up in the processing order which does not have deep inspection enabled at all and is a flow-based policy. We don't mind that these addresses are not scanned, they were exempted in the first place. I use the same "address group" which holds my "SSL Deep Scanning Exempted addresses" both for the policy and for the SSL/SSH Inspection Security Profile.

I do notice from time to time that a page needs to be reloaded before an exempted wildcard address loads succesfully. This is probably because the address learned from the DNS-request wasn't yet loaded into the policy (https://docs.fortinet.com...-in-firewall-policies) thus the "lower" proxy-based policy is used instead.
With flow-based policies which have ssl deep inspection enabled the problem with exempted addresses does not occur. We need proxy-based policies though to enable us to block certain file types.
 
We use QUIC too (enabled), it doesn't seem to make a difference if we disable it.
#12
Wayne1
Gold Member
  • Total Posts : 202
  • Scores: 4
  • Reward points: 0
  • Joined: 2004/03/11 08:04:32
  • Location: Switzerland
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/08/25 05:55:36 (permalink)
0
We are in the same boat as JasperW, upgraded from 6.2.3 to 6.2.5 on a 200E Cluster and all proxy based policies with deep inspection were resetting the traffic to plenty pages. Switched the policy to Flow and everything works. 
But yeah, we also need a possibility to block users from downloading file types and used the DLP for that until today.
 
I was always a big fan from Fortinet and their products, but in the past few months, if not even years, they released so many bugs, we are close to decide to kick them out for all our subsidiaries worldwide  There is almost no concept in the builds, they remove a basic feature like DLP from the GUI, remove all DLP Filter settings from the existing policies after 6.2.2, switch it to the Webfilter and name it "File Filter", bring it back to the GUI in 6.4, sometimes I think they use dices to make decisions.

 
FG-200E, FG-200D, FG-100E, FG-60E, FWF-60D, FWF-60E, FAZVM64, Fortimail VM
#13
MasterBratac
Gold Member
  • Total Posts : 218
  • Scores: 4
  • Reward points: 0
  • Joined: 2007/01/09 15:02:48
  • Location: Germany
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/09/08 07:15:29 (permalink)
0
JasperW
I upgraded my FGT201E saturday the 22nd from 6.2.4 to 6.2.5. The upgrade process went smooth. I do have problems with SSL Deep Inspection, especially (strangely enough) on exempted addresses.
In a proxy-based policy with "ssl deep inspection" enabled, some exempted addresses do not load in the browser, a connection failed error appears in the browser. I haven't pin pointed yet why certain sites that are exempted do not load while others do. In flow-based policies the problem does not occur.


We do have the same problem on a cluster with two FG100D. Funny thing is, that the exempted Fortinet websites didn't work a all ... we went back to 6.2.4.
I also had chat contact to fortinet support .... they said, that this problem is not yet known ... 
So I'm glad, that I'm not the only one ... anything new on this toppic?
#14
bbilut
Bronze Member
  • Total Posts : 24
  • Scores: 4
  • Reward points: 0
  • Joined: 2019/07/29 07:01:03
  • Location: Chicago Area
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/09/08 09:11:09 (permalink) ☄ Helpfulby tanr 2020/09/09 07:52:41
5 (1)
Looks like they recently added these two issues to the list of "Known Issues" with 6.2.5
 
630070 - HA is failing over with crashes.
645848 - FortiOS is providing self-signed CA certificate intermittently with flow-based SSL certificate inspection.
#15
NeilG
Silver Member
  • Total Posts : 89
  • Scores: 4
  • Reward points: 0
  • Joined: 2014/03/04 11:00:39
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/09/08 09:50:32 (permalink)
0
That would imply that even flow based deep inspection is having issues, where the prior posts were indicating that flow based fixed the proxy-based deep inspection breaking lots of pages especial those that are whitelisted/exempted.
 
That is not good at all.
#16
bbilut
Bronze Member
  • Total Posts : 24
  • Scores: 4
  • Reward points: 0
  • Joined: 2019/07/29 07:01:03
  • Location: Chicago Area
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/09/08 09:57:11 (permalink)
0
I'm still on 6.2.4 and I normally decrypt with a cert that I imported into the unit. I just exported the stock self-signed (Fortinet cert) from the firewall and added into my Windows group policy so all my Windows machines will have that cert as well.
#17
andr_gin
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/10/21 08:21:35
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/09/08 10:21:04 (permalink)
0
Installed 6.2.5 von our 60F. Many websites including this forum are not accessible. Rolled back to 6.2.4
Even 6.2.4 seems to have some serious issues with with packet capture and I suspect SSL inspection, but at least it somehow works.
#18
bbilut
Bronze Member
  • Total Posts : 24
  • Scores: 4
  • Reward points: 0
  • Joined: 2019/07/29 07:01:03
  • Location: Chicago Area
  • Status: offline
Re: FortiOS 6.2.5 is out! 2020/09/16 10:31:35 (permalink)
0
I see these recently added this to the release notes.
 
2020-09-10 - Added FGR-60F to Special branch supported models.
#19
Jump to:
© 2020 APG vNext Commercial Version 5.5