Fortinet black logo

Changes in default behavior

Changes in default behavior

Bug ID

Description

718290

When using FortiGuard servers for DNS, FortiOS will default to using DNS over TLS (DoT) to secure the DNS traffic. New FortiGuard DNS servers are added as primary and secondary servers.

748811

Accept MTU in ICMP fragmentation needed for ESP packets. In the IPsec phase 2 settings, if ipv4-df is enabled, the DF flag in the new IP header is set to the same as the original IP header. If ipv4-df is disabled, the DF flag in the new IP header is set to 0.

759012

The default DNS servers have changed, and the default setting is to use DoT and SDNS.

Changes in default behavior

Bug ID

Description

718290

When using FortiGuard servers for DNS, FortiOS will default to using DNS over TLS (DoT) to secure the DNS traffic. New FortiGuard DNS servers are added as primary and secondary servers.

748811

Accept MTU in ICMP fragmentation needed for ESP packets. In the IPsec phase 2 settings, if ipv4-df is enabled, the DF flag in the new IP header is set to the same as the original IP header. If ipv4-df is disabled, the DF flag in the new IP header is set to 0.

759012

The default DNS servers have changed, and the default setting is to use DoT and SDNS.