Open Bugs
Open Bugs in Version 6.4.0
Table last updated: 2022-11-02
Bug ID |
Headline |
---|---|
Lina CPU is low and traffic gets lost for FTDv ESXi 12 core and FTDv KVM 12 core platforms |
|
App agent heart beat can miss in MI scenario |
|
FMC Dashboard is showing incorrect value as FMC latest product updates |
|
vFTD 6.4 fails to establish OSPF adjacency due to "ERROR: ip_multicast_ctl failed to get channel" |
|
NAP policy/SSL policy name name unknown in syslog on 6.3 FTD managed by 6.4 FMC |
|
Users not showing correctly in FDM Events |
|
Validation: Data Plane - Management Access does not handle RA-VPN port collission |
|
first boot script S97compress-client-resources failed in FTD quietly. |
|
Unable to create RAVPN Conn-Profile if group-policy attr and FQDN are edited in the same wizard flow |
|
Fail to update login history when converting TempID to RealID. 1x log per ID, history lost |
|
ASA SFR: seeing "Error importing SFO: Unable to load container" while trying to import ACP with IPS |
|
User with sessions on FMC not properly updated after user info is downloaded from AD |
|
few preprocessors won't be enabled if enable from 'My Changes' layer of Policy Layers |
|
If a custom app is added in sub domain, snort doesn't restart on registered devices at older version |
|
Generating troubleshooting files stopped in Japanese |
|
Newly Added Application protocol are not able to view under Hosts |
|
Access Policy doesn't reflect the modified user correctly |
|
Unable to edit scheduled task on Task details |
|
Unable to add categories in intrusion rule |
|
Unable to Create Alerts with Japanese Name |
|
VPN Troubleshooting logs setup takes abnormal time span |
|
S2S VPN Wizard showing no pre-configured certificates available |
|
FDM/FTDvirtual unable to support/deploy "ignore-ipsec-keyusage" flexconfig object |
|
Upgrade to 6.4.0 may fail due to ids_event_msg_map table having NULL entries in the msg field |
|
Network discovery not working with network groups containing literals - user or Cisco created. |
|
6.4.0-102 2140 w/ SSL policy runs out of 1550 and 9472 blocks. doesn't recover |
|
Optimizing memory allocation of deploy process(AQS subgroup) to allow huge policy deployments |
|
Cannot change MTU size on ASAv/FTDv after upgrade |
|
Removing a BVI and its DHCP pool simultaneiously causes policy deploy failures |
|
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability |
|
Apache HTTP Server URL Normalization Denial of Service Vulnerability |
|
Apache HTTP Server mod_http2 Use-After-Free Denial of Service Vulnerab |
|
Apache HTTP Server mod_auth_digest Race Condition Access Control Bypas |
|
RunQuery not compatible with Java Development Kit 13 |
|
Snort file mempool corruption leads to performance degradation and process failure. |
|
Firepower Device Manager (FDM) option to disable SSL rekey is not reflected on the config |
|
Snort crash due to missing data in /ngfw/var/sf/fwcfg/interface_info.conf file |
|
Policy deployment fails subsequent to SRU |
|
SQL client not able to query FMC using external database access |
|
Certificate mapping for AnyConnect on FTD no longer working. |
|
Firepower FTD transparent does not decode non-ip packets |
|
Calls fail once anyconnect configuration is added to the site to site VPN tunnel |
|
Using same variable names between byte_extract and byte_math accross SIDs breaks snort validation |
|
Application classification is not retried if a flow is marked brute force failed. |
|
The time/timezone set on GUI is inconsistent on Virtual firepower management center |
|
SFR httpsd process down after upgrade failure from 6.3.0.4 to 6.4 |
|
FMC not sending some audit messages to remote syslog server |
|
log rotation for ngfw-onbox logs NOT happening at expected log size |
|
RabbitMQ keeps crashing if dets file is corrupt |
|
Firepower 4100 series all FTW interfaces link flap at the same time but occur rarely |
|
Inconsistent allocation of cores for snort and lina between instances |
|
Snort consumes memory causing block depletion |
|
Excessive logging from the daq modules process_snort_verdict verdict blacklist |
|
FDM deployment error if 2nd tunnel has overlapping crypto ACL |
|
Traceback while secondary reverting from active to standby |
|
SID 26932 false positive which triggers on QUIC traffic instead of NTP |
|
Reduce SSL HW mode flow table memory usage to reduce the probability of Snort going in D state |
|
FTD manual certificate enrollment fails with "&" (ampersand) in Organisation subject field |
|
ASA traceback and reload on process name LINA |
|
FP 2k running FTD 6.4.0.7 traceback and reload on process name LINA |
|
AAA RADIUS server connection failure |
|
6.4.0.9 upgrade from 6.4.0 with CC mode causes httpsd.conf to have an incorrect config |
|
AppId caches proxy IP instead of tunneled IP for ultrasurf |
|
FTD Traceback and Reload on Lina thread due to lock contention |
|
FTD traceback and reload on thread "IKEv2 Mgd Timer Thread" |
|
6.6.0-90: [Firepower 1010] Tomcat restarted during SRU update because of out of memory |
|
sfipproxy may fail to bind listeners for secondary FMC |
|
NAT policy configuration after NAT policy deployment on FP 8130 is not seen |
|
ASA traceback and reload for the CLI "show asp table socket 18421590 det" |
|
Supervisor software needs to be upgraded to address CVE-2017-11610 |
|
Stunnel 5.00 through 5.13, when using the redirect option, does not re |
|
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the li |
|
FDM: AnyConnect "Validation failed due to duplicate name:" |
|
FTD Lina traceback and reload in the QOS function |
|
Firepower 4100/9300 - Fail-to-wire (FTW) EPM ports link flap during show tech collection |
|
In GNOME glib-networking through 2.64.2, the implementation of GTlsCli |
|
FTD upgrade fails due to HA config sync taking over 1h |
|
FDM - New firewall session getting created after performing HA Failover for traffic in progress |
|
FMC cannot add ACL rule with geolocation because "An internal error occurred." |
|
Binary rules (SO rules) are not loaded when snort reloads |
|
Unable to deploy if device with same UUID is trying to connect |
|
When would have dropped events are generated some event data is invalid. |