Fortiproxy 1.2.9 Release Notes
Fortiproxy 1.2.9 Release Notes
Notes
Version 1.2.9
FORTINET DOCUMENT LIBRARY
http://docs.fortinet.com
FORTINET VIDEO GUIDE
http://video.fortinet.com
FORTINET BLOG
https://blog.fortinet.com
CUSTOMER SERVICE & SUPPORT
https://support.fortinet.com
http://cookbook.fortinet.com/how-to-work-with-fortinet-support/
FORTIGATE COOKBOOK
http://cookbook.fortinet.com
FORTINET TRAINING SERVICES
http://www.fortinet.com/training
FORTIGUARD CENTER
http://www.fortiguard.com
FORTICAST
http://forticast.fortinet.com
FEEDBACK
Email: [email protected]
Revision 1
TABLE OF CONTENTS
Change log 4
Introduction 5
Security modules 5
Caching and WAN optimization 6
Whatʼs new 7
Supported models 7
Product integration and support 9
Web browser support 9
Fortinet product support 9
Software upgrade path 9
Virtualization environment support 9
New deployment of the FortiProxy VM 9
Upgrading the FortiProxy VM 10
Downgrading the FortiProxy VM 10
Resolved issues 11
Common vulnerabilities and exposures 13
Known issues 14
Change log
FortiProxy delivers a class-leading Secure Web Gateway, security features, unmatched performance,
and the best user experience for web sites and cloud-based applications. All FortiProxy models include
the following features out of the box:
Security modules
The unique FortiProxy architecture offers granular control over security, understanding user needs and
enforcing Internet policy compliance with the following security modules:
l Web filtering
o The web-filtering solution is designed to restrict or control the content a reader is authorized to
signature database, along with sophisticated spam filtering tools on Fortinet appliances and
agents, to detect and block a wide range of spam messages. Updates to the IP reputation and
spam signature databases are provided continuously by the FDN.
l CIFS filtering
o CIFS UTM scanning, which includes antivirus file scanning and data leak prevention (DLP) file
filtering.
l Application control
o Application control technologies detect and take action against network traffic based on the
network.
l Antivirus
o Antivirus uses a suite of integrated security technologies to protect against a variety of threats,
including both known and unknown malicious codes (malware), plus Advanced Targeted Attacks
(ATAs), also known as Advanced Persistent Threats (APTs).
l SSL/SSH inspection (MITM)
o SSL/SSH inspection helps to unlock encrypted sessions, see into encrypted packets, find threats,
actively seeking and blocking external threats before they can reach potentially vulnerable
network devices.
l Content Analysis
o Content Analysis allow you to detect adult content images in real time. This service is a real-time
All traffic between a client network and one or more web servers is intercepted by a web cache policy.
This policy causes the FortiProxy unit to cache pages from the web servers on the FortiProxy unit and
makes the cached pages available to users on the client network. Web caching can be configured for
standard and reverse web caching.
FortiProxy supports WAN optimization to improve traffic performance and efficiency as it crosses the
WAN. FortiProxy WAN optimization consists of a number of techniques that you can apply to improve
the efficiency of communication across your WAN. These techniques include protocol optimization,
byte caching, SSL offloading, and secure tunneling.
Protocol optimization can improve the efficiency of traffic that uses the CIFS, FTP, HTTP, or MAPI
protocol, as well as general TCP traffic. Byte caching caches files and other data on FortiProxy units to
reduce the amount of data transmitted across the WAN.
FortiProxy is intelligent enough to understand the differing caching formats of the major video services
in order to maximize cache rates for one of the biggest contributors to bandwidth usage. FortiProxy will:
l Detect the same video ID when content comes from different CDN hosts
l Support seek forward/backward in video
l Detect and cache separately; advertisements automatically played before the actual videos
Whatʼs new
l You can now back up the FortiProxy configuration to a SSH File Transfer Protocol (SFTP) server. Use the
following CLI command:
l You can now create a data loss prevention (DLP) sensor with a filter to block files of a specific file type
that also exceed a specified file size. Use the following CLI commands:
l The new set wccp-local-route {enable | disable} command (under config system
settings) controls whether WCCP uses the local route when the WCCP cache engine is enabled.
Supported models
FortiProxy l FPX-2000E
l FPX-4000E
l FPX-400E
l FPX-AZURE
l FPX-HY
l FPX-KVM
FortiProxy VM l FPX-KVM-AWS
l FPX-KVM-GCP
l FPX-KVM-OPC
l FPX-VMWARE
Product integration and support
NOTE: Fortinet recommends running the FortiProxy VM with 2G+ memory because the AI-based
Image Analyzer uses more memory comparing to the previous version.
The following issue has been fixed in FortiProxy 1.2.9. For inquiries about a particular bug, please
contact Customer Service & Support.
Bug ID Description
604699 Adding an extra space to the HOST header causes a memory leak.
When using MAPI over HTTP (Active-Passive) mode, the WAN-optimization tunnels are
609568
sometimes not established.
634890 FortiProxy does not support IPsec PFS and Diffie-Hellman group 20.
644299 The WAN-optimization daemon (WAD) process crashes when the local ICAP server handles
an oversized file when the oversize option is enabled.
645851 FTPS using the explicit-FTP proxy does not work for some clients.
651314 There are multiple fnbamd crashes when a Config-Sync cluster was configured with LDAP
authentication and load balancing.
When the FortiProxy unit is configured as a WCCP client, redirected traffic is being dropped
657563
when web caching is enabled in the policy.
661981 The update time is incorrect in the output for the get sys ha status command, and the
host name is empty in the output for the dia sys ha status command.
After FortiProxy is upgraded, the policy type of explicit-ftp changes to transparent if explicit-
662558
ftp is disabled.
665159 Uploading a virus file over 48k is not blocked in stream-scan mode.
667581 After config icap local-server is configured on a FortiProxy unit with a specified
incoming-ip, the explicit FTP configured with a different incoming-ip does not respond to the
sync packet.
Bug ID Description
669251 Removed the OPTIONS method from the HTTP 405 “Method Not Allowed” response.
669878 Running the exec report run CLI command causes the report daemon to crash.
Changing the setting for a Content Analysis category still allows images that should be
670528
blocked.
670862 After configuring two LDAP servers in krb-keytab, the PAC cache does not behave as
expected.
675625 The button keeps spinning if an invalid Google domain is added and then Apply is clicked on
the Edit Web Filter Profile page
676516 The active method in the authentication rule should not select the header type scheme.
677158 The DLP file name pattern cannot be added in the GUI.
677606 When the policy type is explicit FTP, the web cache and web proxy profile should be hidden.
677843 The WAD process is causing high memory usage, and the wa_cs process is crashing.
678746 When applying log settings, the confirmation page is displayed twice.
680892 The DLP system is not blocking files according to the configured file type.
681017 The Security Fabric widget in the FortiProxy dashboard should display the correct IP address.
681461 When incoming-ip is set for explicit FTP proxy, iptables ignore it.
682254 When deploying a new FortiProxy VM on Azure, you can set the user name and password;
however, you cannot log in to the VM with the user name and password that was configured.
682618 Deleting one or more policy from the GUI results in multiple confirmation pages.
683833 The WAD process is causing high memory usage and is crashing.
Common vulnerabilities and exposures
l CVE-2018-13379
l CVE-2018-13380
l CVE-2018-13381
l CVE-2018-13382
l CVE-2018-13383
Visit https://fortiguard.com/psirt for more information.
Known issues
FortiProxy 1.2.9 includes the known issues listed in this section. For inquires about a particular issue,
please contact Fortinet Customer Service & Support.
Bug ID Description
499787 The FortiGuard firmware versions are not listed on the System > Firmware page.
Copyright© 2020 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet,
Inc., in the U.S. and other jurisdictions, and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company
names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and
actual performance and other results may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein
represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written
contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified
performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For
absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. In no event does Fortinet make any
commitment related to future deliverables, features, or development, and circumstances may change such that any forward-looking statements herein are not accurate.
Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify,
transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.