FortiManager 6.4.7 and FortiOS 6.4.9 compatibility issues
This section identifies interoperability issues that have been identified with FortiManager 6.4.7 and FortiOS 6.4.9 in mantis 765709. FortiOS 6.4.9 includes syntax changes not supported by FortiManager 6.4.7.
The following default values changed:
system snmp community events
default value changed fromcpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp
tocpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp pool-usage
.system snmp user events
default value changed fromcpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp
tocpu-high mem-low log-full intf-ip vpn-tun-up vpn-tun-down ha-switch ha-hb-failure ips-signature ips-anomaly av-virus av-oversize av-pattern av-fragmented fm-if-change bgp-established bgp-backward-transition ha-member-up ha-member-down ent-conf-change av-conserve av-bypass av-oversize-passed av-oversize-blocked ips-pkg-update ips-fail-open faz-disconnect wc-ap-up wc-ap-down fswctl-session-up fswctl-session-down load-balance-real-server-down per-cpu-high dhcp pool-usage
.
The following objects were added:
(attr) system automation-action verify-host-cert (attr) system global early-tcp-npu-session (attr) system ha uninterruptible-primary-wait (attr) system interface dhcp-relay-request-all-server (attr) system netflow interface (attr) system netflow interface-select-method (attr) system sdn-connector verify-certificate (attr) system sflow interface (attr) system sflow interface-select-method (attr) system vdom-netflow interface (attr) system vdom-netflow interface-select-method (attr) system vdom-sflow interface (attr) system vdom-sflow interface-select-method (attr) vpn ipsec phase1 inbound-dscp-copy (attr) vpn ipsec phase1-interface inbound-dscp-copy (attr) vpn ipsec phase2 inbound-dscp-copy (attr) vpn ipsec phase2-interface inbound-dscp-copy (attr) vpn ssl settings ciphersuite (attr) vpn ssl settings status (attr) wireless-controller apcfg-profile ap-family
Additional option changes:
router multicast6 interface tag: tz -> None system snmp community events option-list (tag|opt): None -> ["pool-usage"] system snmp user events option-list (tag|opt): None -> ["pool-usage"] system vdom-link type option-list (tag|opt): None -> ["npupair"] system vxlan tag: nat -> None vpn ssl settings banned-cipher option-list (tag|opt): None -> ["AESCCM", "ARIA", "CHACHA20"]