New features or enhancements
More detailed information is available in the New Features Guide.
Bug ID |
Description |
---|---|
477886 |
PRP support for SoC4:
config system npu set prp-port-in "port1" set prp-port-out "port2" end |
611992 |
Add a specific |
621725 |
Add settings to enable flow control and pause metering. Pause metering allows the FortiSwitch to apply flow control to ingress traffic when the queue is congested and to resume once it is cleared. |
628963 |
When 802.1x authentication requests to a RADIUS server time out, the |
634357 |
Add NPU support for GTP-U encapsulated in IPv6. |
638352 |
To avoid large number of new IKEv2 negotiations from starving other SAs from progressing to established states, the following enhancements have been made to the IKE daemon:
The IKE embryonic limit can now be configured in the CLI: config system global set ike-embryonic-limit <integer> end |
641077 |
After authorizing a FortiAP, administrators can also register the FortiAP to FortiCloud directly from the FortiGate GUI. |
647800 |
AWS and Azure now support FIPS ciphers mode. |
649075 |
FortiGate-VMs on AWS now use Amazon EC2 instance metadata service version 2 (IMDSv2) to query and retrieve metadata from the AWS cloud. |
650936 |
Add support for FortiFlex, an enterprise license agreement for virtual machine licensing where users can manage and monitor their VM subscription in the FortiCloud portal. |
651866 |
FortiSwitch events now have their own category on the Events log page. |
652003 |
In a tenant VDOM, allow |
652225 |
Configuring the DiffServ code in phase 2 of an IPsec tunnel allows the tag to be applied to the ESP packet. NPU offloading must be disabled for this tunnel. |
652503 |
By configuring the service chain and service index, NSX-T east-west traffic can be redirected to a designated FortiGate VDOM. config nsxt setting set liveness {enable | disable} set service <service name> end config nsxt service-chain edit <ID> set name <chain name> config service-index edit <forward index> set reverse-index <value> set name <index name> set vd <VDOM> next end next end The default value for |
655920 |
Support 802.11v load balancing and optimized roaming. |
655931 |
Adaptive Radio Architecture (ARA) allows FortiAPs to calculate the network coverage factor (NCF) based on radio interference. When Dynamic Radio Mode Assignment (DRMA) is enabled, if interference crosses a threshold, the radio becomes redundant by moving from AP mode to monitor mode. config wireless-controller wtp-profile edit <profile> config radio-1 set band 802.11n/g-only set drma {enable | disable} set drma-sensitivity {high | medium | low} end next end |
656039 |
Allow SD-WAN duplication rules to specify SD-WAN service rules to trigger packet duplication. This allows SD-WAN duplication to occur based on an SD-WAN rule instead of the source, destination, or service parameters in the duplication rule. |
657598 |
In an application control list, the config application list edit <list> config entries edit 1 set category <ID> set exclusion <signature ID> ... <signature ID> next end next end |
658006 |
Simplify FortiExtender deployment so it is displayed in the topology. |
658525 |
The limit of BGP paths that can be selected and advertised has increased to 255 (originally 8). |
659127 |
Add support to deploy FortiGate-VMs that are paravirtualized with SR-IOV and DPDK/vNP on OCI shapes that use Mellanox network cards. |
659346 |
Add additional information such as DHCP server MAC, gateway, subnet, and DNS to wireless DHCP logs. |
660250 |
Add global option config system global set fortiipam-integration {enable | disable} end |
660273 |
By default, the FortiGate uses the outbound interface's IP to communicate with a FortiSwitch managed over layer 3. The |
661131 |
Enabling IGMP snooping on an SSID allows the wireless controller to detect which FortiAPs have IGMP clients. The wireless controller will only forward a multicast stream to the FortiAP where there is a listener for the multicast group. |
663530 |
IoT background scanning is disabled by default. Users can enable this option on the FortiLink Interface page in the GUI or with the |
664312 |
Integrate Broadcom bnxt_en 1.10.1 driver to drive new vfNIC to replace 1.9.2 version. The following new cards are supported:
|
665735 |
The user device store allows user and device data collected from different daemons to be centralized for quicker access and performance: diagnose user-device-store device memory list diagnose user-device-store device memory query mac <value> diagnose user-device-store device memory query ip <value> diagnose user-device-store device disk list diagnose user-device-store device disk query <SQL WHERE clause> |
668362 |
Support multiple LDAP server configurations for Kerberos keytab and agentless NTLM domain controller in multiple forest deployments. |
668991 |
Security Fabric rating reports can now be generated in multi-VDOM mode, against all VDOMs. The Security Rating is visible under Global scope. |