What's new for FortiGates with NP7 processors for FortiOS 6.4.6
FortiOS 6.4.6 includes support for FortiGates with NP7 processors and for NP7 hyperscale firewall features. For information about NP7 processors, see:
For information about NP7 hyperscale firewall features, see the FortiOS 6.4.6 Hyperscale Firewall Guide.
The following new features for FortiGates that include NP7 processors have been added to FortiOS 6.4.6.
-
Re-designed NP7 HPE, see NP7 Host Protection Engine (HPE).
-
New
config system npu
options:
The following new FortiOS 6.2.7 features are also available for FortiOS 6.4.6.
-
You can improve overall performance by keeping accelerated VDOM link interfaces from consuming excessive NP7 bandwidth. See Bandwidth control for NPU accelerated VDOM link interfaces.
-
When configuring a VLAN interface, you can set the maximum outgoing bandwidth that traffic over the VLAN interface can use. See Controlling the maximum outgoing VLAN bandwidth.
-
FortiGates with NP7 processors now support synchronizing HA session sync packets to multiple CPUs, see Distributing HA session synchronization packets to multiple CPUs.
-
You can now enable or disable hash table entry spread for NP7 processors, see hash-tbl-spread (disable | enable}.
-
NP7 Host Protection Engine (HPE) enhancements, to prevent SYN_ACK reflection attacks and limit the maximum number of TCP FIN and RST packets. See NP7 Host Protection Engine (HPE).