New features or enhancements
Bug ID |
Description |
---|---|
578099 |
FortiAP profile support for FortiAP-231E NPI model. CLI changes:
GUI changes:
API changes:
|
588083 |
Support MAC and weight in device identification signatures to improve IoT detection. All device identification signatures have been updated to:
|
599925 |
Add option to enable/disable DFS zero-wait functionality on FAP-U platforms (the default is config wireless-controller wtp-profile edit "FAPU431F-default" config platform set type U431F end set handoff-sta-thresh 30 config radio-1 set band 802.11ax-5G set zero-wait-dfs disable end config radio-2 set band 802.11ax end config radio-3 set mode monitor end next end |
600474 |
Add config wireless-controller vap edit "lo-sd-cap" set ssid "local-stand-cap" set security captive-portal set external-web "https://172.18.56.163/portal/index.php" set radius-server "peap" set local-standalone enable set local-bridging enable set portal-type external-auth next end |
605709 |
Add new profiles for FAP-431F and FAP-433F NPI platforms. config wireless-controller wtp-profile edit "FAP433F-default" config platform set type 433F set ddscan enable end set handoff-sta-thresh 55 config radio-1 set band 802.11ax,n,g-only end config radio-2 set band 802.11ax-5G end config radio-3 set mode monitor end next edit "FAP431F-default" config platform set type 431F set ddscan enable end set handoff-sta-thresh 55 config radio-1 set band 802.11ax,n,g-only end config radio-2 set band 802.11ax-5G end config radio-3 set mode monitor end next end |
609167 |
FortiGate will assign a report index for each managed FAP so the FAP can send client, rogue AP, and rogue station information in order. This avoids a burst in CPU usage to deal with report from all FAPs at the same time. This is not a visible functionality. It is a back end optimization feature. |
610596 |
Users can define IPv6 MAC addresses and apply them in a firewall policy, virtual wire pair policy, and other policy types. |
612176 |
Support setting DiffServ code for SD-WAN health check probe packets. When an SD-WAN health check packet is sent out, the differentiated services code point (DSCP) can be set with a CLI command ( config system virtual-wan-link config health-check edit h1 ... set diffservcode Differentiated services code point (DSCP) in the IP header of the probe packet. ... next end end
|
618812 |
Use RADIUS accounting information from authenticated RSSO users to populate source and destination user fields in traffic logs. |
625080 |
Support IPv6 with vNP/DPDK on FortiGate-VM to improve the performance of firewall and flow UTMs, allowing for greater throughput. |