Fortinet black logo

New Features

Device detection changes when upgrading to 6.2  6.2.1

Copy Link
Copy Doc ID 761d83e3-4a7b-11e9-94bf-00505692583a:657677
Download PDF

Device detection changes when upgrading to 6.2 6.2.1

In FortiOS 6.0.x, the device detection feature contains multiple sub-components, which are independent:

  • Visibility – Detected information is available for topology visibility and logging.
  • FortiClient endpoint compliance – Information learned from FortiClient can be used to enforce compliance of those endpoints.
  • MAC-address-based device policies – Detected devices can be defined as custom devices, and then used in device-based policies.

In FortiOS 6.2, these functionalities have changed:

  • Visibility – Configuration of the feature remains the same as FortiOS 6.0, including FortiClient information.
  • FortiClient endpoint compliance – A new fabric connector replaces this, and aligns it with all other endpoint connectors for dynamic policies. For more information, see Dynamic Policy - FortiClient EMS (Connector) in the FortiOS 6.2.0 New Features Guide.
  • MAC-address-based policies – A new address type is introduced (MAC address range), which can be used in regular policies. The previous device policy feature can be achieved by manually defining MAC addresses, and then adding them to regular policy table in 6.2. For more information, see MAC Addressed-Based Policies in the FortiOS 6.2.0 New Features Guide.

If you were using device policies in 6.0.x, you will need to migrate these policies to the regular policy table manually after upgrading to 6.2.0.

To migrate the policies to the regular policy table:
  1. Create MAC-based firewall addresses for each device.
  2. Apply the addresses to the regular IPv4 policy table.

Device detection changes when upgrading to 6.2 6.2.1

In FortiOS 6.0.x, the device detection feature contains multiple sub-components, which are independent:

  • Visibility – Detected information is available for topology visibility and logging.
  • FortiClient endpoint compliance – Information learned from FortiClient can be used to enforce compliance of those endpoints.
  • MAC-address-based device policies – Detected devices can be defined as custom devices, and then used in device-based policies.

In FortiOS 6.2, these functionalities have changed:

  • Visibility – Configuration of the feature remains the same as FortiOS 6.0, including FortiClient information.
  • FortiClient endpoint compliance – A new fabric connector replaces this, and aligns it with all other endpoint connectors for dynamic policies. For more information, see Dynamic Policy - FortiClient EMS (Connector) in the FortiOS 6.2.0 New Features Guide.
  • MAC-address-based policies – A new address type is introduced (MAC address range), which can be used in regular policies. The previous device policy feature can be achieved by manually defining MAC addresses, and then adding them to regular policy table in 6.2. For more information, see MAC Addressed-Based Policies in the FortiOS 6.2.0 New Features Guide.

If you were using device policies in 6.0.x, you will need to migrate these policies to the regular policy table manually after upgrading to 6.2.0.

To migrate the policies to the regular policy table:
  1. Create MAC-based firewall addresses for each device.
  2. Apply the addresses to the regular IPv4 policy table.