Fortinet black logo

Changes in default behavior

Changes in default behavior

Bug ID

Description

798427

The following enhancements have been added to the FortiSandbox Files FortiView monitor:

  • Add a pie chart with different file statuses for disk data sources.
  • Add the Reports view, which lists PDF reports after they are downloaded successfully.
  • PDF reports are downloaded on-demand. By default, only 10 are kept in memory.
  • PDFs are deleted from memory after 24 hours.

841712

On FortiGates licensed for hyperscale firewall features, the config system setting options nat46-force-ipv4-packet-forwarding and nat64-force-ipv6-packet-forwarding now also apply to NP7-offloaded traffic. The config system npu option nat46-force-ipv4-packet-forwarding has been removed.

844004

Change the default ip-managed-by-fortiipam setting to inherit-global.

config system interface
    edit <name>
        set ip-managed-by-fortiipam {enable | disable | inherit-global}
    next 
end

The default setting inherits from the global configuration (inherit-global) through the relevant manage- option under config system ipam.

864035

When the auto-firmware-upgrade setting is enabled, the FortiGate checks for updates every day between the firmware upgrade time interval. When a newer firmware is found, the installation is scheduled after the upgrade delay in days (0-14, default = 3) between the firmware upgrade time interval. After a successful update, an email is sent to the account owner.

config system fortiguard
    set auto-firmware-upgrade {enable | disable}
    set auto-firmware-upgrade-delay <integer>
end

Affected platforms: FG-40F, FG-40F-3G4G, FG-60E, FG-60E-DSL, FG-60E-DSLJ, FG-60E-POE, FG-60F, FG-61E, FG-61F, FG-70F, FG-71F, FG-80E, FG-80E-POE, FG-80F, FG-80F-BP, FG-80F-POE, FG-81E, FG-81E-POE, FG-81F, FG-81F-POE, FG-90E, FG-91E, FGR-60F, FGR-60F-3G4G, FGR-70F, FGR-70F-3G4G, FWF-40F, FWF-40F-3G4G, FWF-60E, FWF-60E-DSL, FWF-60E-DSLJ.

883727

For FortiGates with NP7 processors, the policy-offload-level option of the config system npu command has been removed. The policy offload level is only set using the policy-offload-level option of the config system settings command, allowing you to configure the policy offload level separately for each VDOM. By default, policy-offload-level is set to disable. You can change the policy-offload-level to dos-offload. If your FortiGate is configured for hyperscale firewall features, you can set the policy-offload-level to full-offload in a hyperscale firewall VDOM.

Changes in default behavior

Bug ID

Description

798427

The following enhancements have been added to the FortiSandbox Files FortiView monitor:

  • Add a pie chart with different file statuses for disk data sources.
  • Add the Reports view, which lists PDF reports after they are downloaded successfully.
  • PDF reports are downloaded on-demand. By default, only 10 are kept in memory.
  • PDFs are deleted from memory after 24 hours.

841712

On FortiGates licensed for hyperscale firewall features, the config system setting options nat46-force-ipv4-packet-forwarding and nat64-force-ipv6-packet-forwarding now also apply to NP7-offloaded traffic. The config system npu option nat46-force-ipv4-packet-forwarding has been removed.

844004

Change the default ip-managed-by-fortiipam setting to inherit-global.

config system interface
    edit <name>
        set ip-managed-by-fortiipam {enable | disable | inherit-global}
    next 
end

The default setting inherits from the global configuration (inherit-global) through the relevant manage- option under config system ipam.

864035

When the auto-firmware-upgrade setting is enabled, the FortiGate checks for updates every day between the firmware upgrade time interval. When a newer firmware is found, the installation is scheduled after the upgrade delay in days (0-14, default = 3) between the firmware upgrade time interval. After a successful update, an email is sent to the account owner.

config system fortiguard
    set auto-firmware-upgrade {enable | disable}
    set auto-firmware-upgrade-delay <integer>
end

Affected platforms: FG-40F, FG-40F-3G4G, FG-60E, FG-60E-DSL, FG-60E-DSLJ, FG-60E-POE, FG-60F, FG-61E, FG-61F, FG-70F, FG-71F, FG-80E, FG-80E-POE, FG-80F, FG-80F-BP, FG-80F-POE, FG-81E, FG-81E-POE, FG-81F, FG-81F-POE, FG-90E, FG-91E, FGR-60F, FGR-60F-3G4G, FGR-70F, FGR-70F-3G4G, FWF-40F, FWF-40F-3G4G, FWF-60E, FWF-60E-DSL, FWF-60E-DSLJ.

883727

For FortiGates with NP7 processors, the policy-offload-level option of the config system npu command has been removed. The policy offload level is only set using the policy-offload-level option of the config system settings command, allowing you to configure the policy offload level separately for each VDOM. By default, policy-offload-level is set to disable. You can change the policy-offload-level to dos-offload. If your FortiGate is configured for hyperscale firewall features, you can set the policy-offload-level to full-offload in a hyperscale firewall VDOM.