Fortinet black logo

FortiManager 6.4.7 and FortiOS 6.4.9 compatibility issues

FortiManager 6.4.7 and FortiOS 6.4.9 compatibility issues

This section identifies interoperability issues that have been identified with FortiManager 6.4.7 and FortiOS 6.4.9 in mantis 765709. FortiOS 6.4.9 includes syntax changes not supported by FortiManager 6.4.7.

The following default values changed:

  • system snmp community events default value changed from cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp to cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp pool-usage.
  • system snmp user events default value changed from cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp to cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp pool-usage.

The following objects were added:

    (attr) system automation-action verify-host-cert
    (attr) system global early-tcp-npu-session
    (attr) system ha uninterruptible-primary-wait
    (attr) system interface dhcp-relay-request-all-server
    (attr) system netflow interface
    (attr) system netflow interface-select-method
    (attr) system sdn-connector verify-certificate
    (attr) system sflow interface
    (attr) system sflow interface-select-method
    (attr) system vdom-netflow interface
    (attr) system vdom-netflow interface-select-method
    (attr) system vdom-sflow interface
    (attr) system vdom-sflow interface-select-method
    (attr) vpn ipsec phase1 inbound-dscp-copy
    (attr) vpn ipsec phase1-interface inbound-dscp-copy
    (attr) vpn ipsec phase2 inbound-dscp-copy
    (attr) vpn ipsec phase2-interface inbound-dscp-copy
    (attr) vpn ssl settings ciphersuite
    (attr) vpn ssl settings status
    (attr) wireless-controller apcfg-profile ap-family

Additional option changes:

    router multicast6 interface
        tag: tz -> None
    system snmp community events
        option-list (tag|opt): None -> ["pool-usage"]
    system snmp user events
        option-list (tag|opt): None -> ["pool-usage"]
    system vdom-link type
        option-list (tag|opt): None -> ["npupair"]
    system vxlan
        tag: nat -> None
    vpn ssl settings banned-cipher
        option-list (tag|opt): None -> ["AESCCM", "ARIA", "CHACHA20"]

FortiManager 6.4.7 and FortiOS 6.4.9 compatibility issues

This section identifies interoperability issues that have been identified with FortiManager 6.4.7 and FortiOS 6.4.9 in mantis 765709. FortiOS 6.4.9 includes syntax changes not supported by FortiManager 6.4.7.

The following default values changed:

  • system snmp community events default value changed from cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp to cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp pool-usage.
  • system snmp user events default value changed from cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp to cpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp pool-usage.

The following objects were added:

    (attr) system automation-action verify-host-cert
    (attr) system global early-tcp-npu-session
    (attr) system ha uninterruptible-primary-wait
    (attr) system interface dhcp-relay-request-all-server
    (attr) system netflow interface
    (attr) system netflow interface-select-method
    (attr) system sdn-connector verify-certificate
    (attr) system sflow interface
    (attr) system sflow interface-select-method
    (attr) system vdom-netflow interface
    (attr) system vdom-netflow interface-select-method
    (attr) system vdom-sflow interface
    (attr) system vdom-sflow interface-select-method
    (attr) vpn ipsec phase1 inbound-dscp-copy
    (attr) vpn ipsec phase1-interface inbound-dscp-copy
    (attr) vpn ipsec phase2 inbound-dscp-copy
    (attr) vpn ipsec phase2-interface inbound-dscp-copy
    (attr) vpn ssl settings ciphersuite
    (attr) vpn ssl settings status
    (attr) wireless-controller apcfg-profile ap-family

Additional option changes:

    router multicast6 interface
        tag: tz -> None
    system snmp community events
        option-list (tag|opt): None -> ["pool-usage"]
    system snmp user events
        option-list (tag|opt): None -> ["pool-usage"]
    system vdom-link type
        option-list (tag|opt): None -> ["npupair"]
    system vxlan
        tag: nat -> None
    vpn ssl settings banned-cipher
        option-list (tag|opt): None -> ["AESCCM", "ARIA", "CHACHA20"]