Changes in CLI
Bug ID |
Description |
---|---|
735470 |
The following settings under
|
736850 |
Add Change the default setting of config firewall ssl-ssh-profile edit <name> config SSL set inspect-all deep-inspection set unsupported-ssl-version {allow | block} set min-allowed-ssl-version {ssl-3.0 | tls-1.0 | tls-1.1 | tls-1.2 | tls-1.3} end next end |
738151 |
Previously, SSL certificate options for VIP access proxy configurations contained an option for CA certificates. A configuration using a CA certificate would cause a ERR_SSL_KEY_USAGE_INCOMPATIBLE error because it is not a server certificate. Now, the CLI will filter out certificates that do not exist, are a CA certificate, or are not valid. Previous configurations in which SSL certificate options get filtered are upgraded to use default the FORTINET_SSL certificate. |
749250 |
Add setting for IPv4 reachable time (previously only IPv6 was supported). config system interface edit <name> set reachable-time <integer> next end The IPv4 reachable time is measured in milliseconds (30000 - 3600000, default = 30000). |
751346 |
Allow IPv6 DNS server override to be set when DHCPv6 prefix delegation is enabled. config system interface edit <name> config ipv6 set ip6-mode static set dhcp6-prefix-delegation enable set ip6-dns-server-override enable end next end |
753631 |
Add option to configure H323/RAS direct model traffic. config system settings set h323-direct-model {enable | disable} end The setting is disabled by default (the wide open pinhole will be closed); however when upgrading from an older version, the setting will be enabled to preserve the previous behavior. |