FortiOS 5.4.1 Release Notes

System

Bug ID Description
275631 Multicast Traffic cannot be offloaded by XLP in NAT mode when there is no PIM enabled.
301947 On NP6 ports, hairpinned traffic is blocked after the traffic that initialized the original NATs stops responding.
303626 Switch VLAN is not accessible in trunk (LACP) mode on 200 series platforms.
297923 Newly created HW switch on NP4 platforms is not accessible until users reboot.
304118 VLAN and hardware switch interface loses the secondary IP during the upgrade from v5.2 to v5.4.
303906 The CLI stops working when configuring Interface Policy6.
304472 Health-check over PPPOE interface does not work after a FGT reboot.
304320 LENC FGT is not able to update the modem-list and message-update; it is notable to connect to FortiAnalyzer.
303959 When the VDOM is enabled, the EAP_proxy is not able to handle the certificate chain with a depth of more than two.
304667 When FGT has only one disk and it is used by WANopt, the factory reset does not reset the disk to log.
305058 FortiGate encounters a system hang issue caused by the dialup ipsec vpn. The unregister_netdevice error message appears.
307675,

310201,

307299

Split port was mapped to the wrong VDOM and traffic could not go through.
363356 Change SNMP counters fgVpnTunEntInOctets/fgVpnTunEntOutOctets from

32bit to 64bit.

294859 dmz1 interface status is down on some units.
310071 Specific SFP shared ports LED (Port18 on FG-1000C) is not lit properly.
309821 ICMPv6 packets with Hop-by-Hop Options are not decoded properly by the built in sniffer.
256614 Admin server key is accessible via print-file/gzfile.
310686 Admin status is down in the Fail Detect feature on the 40G interface.
302272 medium_type is incorrect on shared ports.
Bug ID Description
301702 Fragmented packets are not forwarded in transparent mode.
273848 License Status did not differentiate between low-crypto-license and LENC license.
301842 NP6 PBA Leak occurred.
307342 Extend DHCP Option Support to 8 Fields.
309452 diag command could give read-only admins certain elevated privileges.
300249 Alert Email are sent out with the wrong time interval.
371660 FortiManager is unable to set uninterruptible-upgrade settings on the FortiGate.
370951 FortiCloud activation fails if traffic is sourced from an interface other than the default route path.
371104 Allow reply packet to pass if asymroute is enabled.
368459 Ensure 802.3ad and LACP does not send traffic to down port.
Bug ID Description
306486 FortiOS SSH backdoor.

Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

This entry was posted in FortiOS and tagged , , on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

3 thoughts on “FortiOS 5.4.1 Release Notes

  1. David

    FYI. I ran into a terrible problem using a Fortigate VM00. 5.4.1 will not run because the virtual appliance only has 1GB of memory available. Fortinet was nice enough to diagnose the problem, but really does not have an easy way of upgrading to the 2GB virtual appliance.

    Reply
  2. Pablo

    Problems of download speed, I have a fortigate 30e and I have problems in the download speed 4.2 mbps, instead in upload speed is correct 89.55 mbps, I do not know where the problem may come from. I have version 5.4.1 build1064. You can help me.

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.