Fortinet white logo
Fortinet white logo

FortiOS Release Notes

New features or enhancements

New features or enhancements

More detailed information is available in the New Features Guide.

Feature ID

Description

480717

Add new command to all FortiGate models that have dedicated management (mgmt, mgmt1, mgmt2) ports.

config system dedicated-mgmt

685910

Added SoC4 driver support for the IEEE 802.1ad, also known as QinQ.

930522

Remote access with read and write rights through FortiGate Cloud now requires a paid FortiGate Cloud subscription. The FortiGate can still be accessed in a read-only state with the free tier of FortiGate Cloud. Alternatively, you can access your FortiGate through its web interface.

Please contact your Fortinet Sales/Partner for details on purchasing a FortiGate Cloud Service subscription license for your FortiGate device.

936747

On FortiGates with multiple NP7 processors with hyperscale enabled, you can use the following command to optimize NP7 network session setup (NSS) engine performance.

config system npu
    set nss-threads-option {4T-EIF | 4T-NOEIF | 2T}
end
  • 4T-EIF: the NSS is configured with four threads and the Endpoint Independent Filtering (EIF) feature is allowed (the default). NSS with four threads supports the maximum NP7 Connections Per Second (CPS) performance.

  • 4T-NOEIF: the NSS is configured with four threads and the EIF feature is not allowed. Also supports the maximum NP7 CPS performance.

  • 2T: the NSS is configured with two threads and the EIF feature is allowed. This setting reduces the maximum NP7 CPS performance.

Note

Changing the nss-threads-option causes the FortiGate to restart.

1006448

Enhanced SSL VPN security by restricting and validating HTTP messages that are used only by web mode and tunnel mode.

1013511

This enhancement requires the kernel to verify the signed hashes of important file-system and object files during bootup. This prevents unauthorized changes to file-systems to be mounted, and other unauthorized objects to be loaded into user space on boot-up. If the signed hash verification fails, the system will halt.

New features or enhancements

New features or enhancements

More detailed information is available in the New Features Guide.

Feature ID

Description

480717

Add new command to all FortiGate models that have dedicated management (mgmt, mgmt1, mgmt2) ports.

config system dedicated-mgmt

685910

Added SoC4 driver support for the IEEE 802.1ad, also known as QinQ.

930522

Remote access with read and write rights through FortiGate Cloud now requires a paid FortiGate Cloud subscription. The FortiGate can still be accessed in a read-only state with the free tier of FortiGate Cloud. Alternatively, you can access your FortiGate through its web interface.

Please contact your Fortinet Sales/Partner for details on purchasing a FortiGate Cloud Service subscription license for your FortiGate device.

936747

On FortiGates with multiple NP7 processors with hyperscale enabled, you can use the following command to optimize NP7 network session setup (NSS) engine performance.

config system npu
    set nss-threads-option {4T-EIF | 4T-NOEIF | 2T}
end
  • 4T-EIF: the NSS is configured with four threads and the Endpoint Independent Filtering (EIF) feature is allowed (the default). NSS with four threads supports the maximum NP7 Connections Per Second (CPS) performance.

  • 4T-NOEIF: the NSS is configured with four threads and the EIF feature is not allowed. Also supports the maximum NP7 CPS performance.

  • 2T: the NSS is configured with two threads and the EIF feature is allowed. This setting reduces the maximum NP7 CPS performance.

Note

Changing the nss-threads-option causes the FortiGate to restart.

1006448

Enhanced SSL VPN security by restricting and validating HTTP messages that are used only by web mode and tunnel mode.

1013511

This enhancement requires the kernel to verify the signed hashes of important file-system and object files during bootup. This prevents unauthorized changes to file-systems to be mounted, and other unauthorized objects to be loaded into user space on boot-up. If the signed hash verification fails, the system will halt.