Fortinet black logo

Changes in default behavior

Changes in default behavior

Bug ID

Description

537354

Interface egress shaping offload to NPU when shaping-offload is enabled.

728234

ZTNA configurations no longer require a firewall policy to forward traffic to the access proxy VIP. This is implicitly generated based on the ZTNA rule configuration.

Changes:

  • Firewall policies no longer have the ZTNA toggle for switching between Full ZTNA and IP/MAC filtering.
  • To perform IP/MAC filtering with ZTNA tags, assign tags under IP/MAC Based Access Control in a firewall policy.
  • ZTNA rules must include a source interface.

Upgrading:

  • If an access-proxy type proxy-policy does not have a srcintf, then after upgrading it will be set to any.
  • To display the srcintf as any in the GUI, System > Feature Visibility should have Multiple Interface Policies enabled.

  • All full ZTNA firewall policies will be automatically removed.

729879

When FIPS-CC mode is enabled, subject-match can now be configured. The default value is no longer superset, so it keeps the current setting.

Changes in default behavior

Bug ID

Description

537354

Interface egress shaping offload to NPU when shaping-offload is enabled.

728234

ZTNA configurations no longer require a firewall policy to forward traffic to the access proxy VIP. This is implicitly generated based on the ZTNA rule configuration.

Changes:

  • Firewall policies no longer have the ZTNA toggle for switching between Full ZTNA and IP/MAC filtering.
  • To perform IP/MAC filtering with ZTNA tags, assign tags under IP/MAC Based Access Control in a firewall policy.
  • ZTNA rules must include a source interface.

Upgrading:

  • If an access-proxy type proxy-policy does not have a srcintf, then after upgrading it will be set to any.
  • To display the srcintf as any in the GUI, System > Feature Visibility should have Multiple Interface Policies enabled.

  • All full ZTNA firewall policies will be automatically removed.

729879

When FIPS-CC mode is enabled, subject-match can now be configured. The default value is no longer superset, so it keeps the current setting.