What's new for hyperscale firewall for FortiOS 6.4.8
This section lists the new NP7 hyperscale firewall features added to FortiOS 6.4.8. For new FortiOS 6.4.8 NP7 features, see What's new for FortiGates with NP7 processors for FortiOS 6.4.8.
-
The
policy-offload-level
options of theconfig system npu
command have been simplified. For FortiOS 6.4.8 you can only selectdisable
,dos-offload
, orfull-offload
. See Enabling hyperscale firewall features. -
You can configure NP7 processors to override the DF setting and fragment and forward packet that a NAT46 hyperscale firewall policy has converted to an IPv6 packet that exceeds the outgoing interface MTU instead of dropping it. See Allowing packet fragments for NP7 NAT46 policies when the DF bit is set to 1.
-
You can use the new
log-processing
hardware logging option to change how the FortiGate queues CPU or host logging packets to allow or prevent dropped packets. See Configuring hardware logging. -
New option to enable or disable background NP7 SSE scanning and configure some SSE scanning options. See Configuring background SSE scanning.
-
Hyperscale firewall VDOMs have improved support for asymmetric routing and ECMP. See Hyperscale firewall VDOM asymmetric routing with ECMP support.
-
You can configure how the NP7 hyperscale firewall policy engine handles traffic in a hyperscale firewall VDOM that matches a blackhole route or a loopback route. See Adjusting NP7 hyperscale firewall blackhole and loopback route behavior and Viewing the NP7 hyperscale policy engine routing configuration.
-
You can enable or disable hyperscale firewall per-policy accounting for all hyperscale traffic. See Enabling or disabling per-policy accounting for hyperscale firewall traffic.
-
You can display the current NP7 hyperscale firewall hardware session list by sending a query to the NP7 Session Search Engine (SSE). See Displaying information about NP7 hyperscale firewall hardware sessions.
For more information about FortiOS 6.4.8 hyperscale firewall, see the FortiOS 6.4.8 Hyperscale Firewall Release Notes.