通常,组织具有远程用户使用虚拟专用网络(VPN)连接将其互联网流量重定向到其数据中心的下一代防火墙(NGFW)。执行其安全功能后,NGFW将用户的网络流量发送到NGFW的WAN链接。建立了具有VPN连接的远程用户在通过此回程的WAN连接访问Internet时也会经历高潜伏期,因为防火墙的WAN链接变得拥挤其他远程用户生成的Internet流量。SASE通过允许远程用户直接连接到云传递的FWAA的最接近地理点点(POP)来降低此潜伏期。此外,每个POP可以扩展以满足用户需求并减少单个WAN链接成为这些远程用户的拥塞点的可能性。
更改日志8简介9使用forticlient 11 SWG无代理模式12专用公共IP地址12嵌入到板载指南13 FORTFELEX许可16许可更新通知17远程VPN用户识别17所需的服务和端口17 AS IAM用户签名为IAM用户18遥控器22 23 fortect 22 22 fort fortigens 22 Fortigitig 22 fortigitig 22 support 26 Pre-logon VPN 26 ZTNA Windows tagging rules for certificate subject CN regex or wildcard matching 28 Central management 28 Network restrictions removed 29 SD-WAN On-Ramp support 30 Supporting external IdP users 30 Dashboards 31 Adding a custom dashboard 31 Resetting all dashboards 32 Drilling down on vulnerabilities 32 FortiView monitors 33 Adding a custom monitor 34 Resetting all monitors 34 Monitoring边缘设备带宽用法35边设备36边设备40 fortiextender 40先决条件40查看新的fortiextender的通知43将fortiextender配置为fortiextender fortiSase lan Extension 44 FortiGate 52先决条件53查看通知,以新的FortiGate 54配置FortiGate 54 FortiGate 54 Fortigate 54 Fortendies 54 Fortipecip 57
版权所有©2024 Fortinet,Inc。保留所有权利。fortinet®,fortigate®,forticare®和fortiguard®以及某些其他标记是Fortinet,Inc。的注册商标,此处的其他Fortinet名称也可以注册和/或Fortinet的普通法商标。所有其他产品或公司名称可能是其各自所有者的商标。的性能和其他指标,实际绩效和其他结果可能会有所不同。网络变量,不同的网络环境和其他条件可能会影响性能结果。Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet's Chief Legal Officer, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding在Fortinet上。为了绝对清晰,任何此类保修都将仅限于与Fortinet内部实验室测试相同的理想条件下的性能。Fortinet完全根据明示或暗示的任何盟约,代表和保证。Fortinet保留更改,修改,转让或以其他方式修改本出版物的权利,恕不另行通知,最新版本的出版物应适用。
Change log 4 Introduction 5 What's new 6 What's new for 24.1.56 (24.1.c) 6 What's new for 24.1.37 (24.1.b) 7 What's new for 24.1.10 (24.1.a) 8 What's new for 23.4.49 (23.4.b) 9 What's new for 23.4.31 (23.4.a) 10 Special notices 11 Removable media access 11 Activating the FortiClientNetwork extension 11 Select availability features 13 Product integration and support 14 Supported FortiClient features 14 Common use cases 16 SIA for FortiClient agent-based remote users 17 SIA for FortiExtender site-based remote users 17 SIA for FortiGate SD-WAN secure edge site-based remote users 18 SIA for FortiAP site-based remote users 18 Log forwarding 18 ZTNA 18 SPA 19 SPA Service Connection license 19 SPA FortiCloud account prerequisites 19 SPA using a FortiGate SD-WAN hub 19 Spa使用Fortisase Spa Hub 20 Spa使用Fortisase Spa Hub带有织物叠加层编织器20解决问题21已知问题22限制23 Forticlient Desktop(Windows,MacOS,MacOS,Linux)23 Forticlient Android Android 23 Forticlient Cloud Cloud 23 fortisandbox 23 Fortisandbox 23 Fortisandbox 23 fortisandbox 23
Change log 4 Introduction 5 What's new 6 What's new for 24.2.12 (24.2.a) 6 What's new for 24.1.56 (24.1.c) 7 What's new for 24.1.37 (24.1.b) 8 What's new for 24.1.10 (24.1.a) 9 What's new for 23.4.49 (23.4.b) 9 Special notices 11 Removable media access 11 Activating the FortiClientNetwork extension 11 Select availability features 13 Product integration and support 14 Supported FortiClient features 14 Common use cases 17 SIA for FortiClient agent-based remote users 18 SIA for FortiExtender site-based remote users 18 SIA for FortiGate SD-WAN secure edge site-based remote users 18 SIA for FortiAP site-based remote users 19 Log forwarding 19 ZTNA 19 SPA 19 SPA Service Connection license 19 SPA FortiCloud account prerequisites 20 SPA using a FortiGate SD-WAN hub 20 Spa使用Fortisase Spa Hub 20 Spa使用Fortisase Spa Hub使用Fortisase Spa Hub带有织物叠加层编排器21 SPA 21 SPA用于MSSP Hub 21解决问题22已知问题23限制24 Forticlient Desktop(Windows,MacOS,MacOS,Linux)24 Forticlient
更改log 4引言5什么是什么新功能6 24.2.44(24.2.b)6的新功能24.2.12(24.2.a)6的新功能24.1.56(24.1.c)7的新功能24.1.37(24.1.37(24.1.b)的新功能what for what for 24.1.b)8什么是24.1.1.10(24.1.1.1.1.a)的新功能。 extension 11 Select availability features 13 Product integration and support 14 Supported FortiClient features 14 Common use cases 17 SIA for FortiClient agent-based remote users 18 SIA for FortiExtender site-based remote users 18 SIA for FortiGate SD-WAN secure edge site-based remote users 19 SIA for FortiAP site-based remote users 19 SIA for SD-WAN On-Ramp site-based remote users 19 Supported SD-WAN On-Ramp IPsec devices 20 Log forwarding 20 ZTNA 20 SPA 20 SPA Service Connection license 20 SPA FortiCloud account prerequisites 21 SPA using a FortiGate SD-WAN hub 21 SPA using a FortiSASE SPA hub 21 SPA using a FortiSASE SPA hub with Fabric overlay orchestrator 22 SPA for an MSSP hub 22 Resolved issues 23 Known issues 25 Limitations 26 FortiClient desktop (Windows, macOS, Linux) 26 FortiClient Android 26 FortiClient Cloud 26 Authentication 26 fortisandbox 27
Change log 5 Introduction 6 What's new 7 What's New for 24.3.42 (24.3.b) 7 What's New for 24.3.20 (24.3.a) 8 What's new for 24.2.63 (24.2.c) 8 What's new for 24.2.44 (24.2.b) 10 What's new for 24.2.12 (24.2.a) 10 Special notices 12 On-shore Dubai customers 12 Removable media access 12 Activating the FortiClientNetwork extension 12 Select availability features 14 Product integration and support 15 Supported FortiClient features 15 Common use cases 18 SIA for FortiClient agent-based remote users 19 SIA for FortiExtender site-based remote users 19 SIA for FortiGate SD-WAN secure edge site-based remote users 20 SIA for FortiAP site-based remote users 20 SIA for SD-WAN On-Ramp site-based remote users 20 Supported SD-WAN On-Ramp IPsec devices 21 Log forwarding 21 Central management using FortiManager 21 ZTNA 21 SPA 21 SPA Service Connection license 22 SPA FortiCloud account prerequisites 22 SPA using a FortiGate SD-WAN hub 22 SPA using a FortiSASE SPA hub 22 SPA using a FortiSASE SPA hub with Fabric overlay orchestrator 23 SPA for an MSSP hub 23 Resolved issues 24 Known issues 26 Limitations 27 FortiAP 27 FortiClient desktop (Windows, macOS, Linux) 27 Forticlient Android 27 Forticlient Cloud 27 Forticloud 28身份验证28
更改日志5简介6什么是新的7新功能24.3.56(24.3.c)7 24.3.42(24.3.b)的新功能是24.3.20(24.3.a)9的新功能,什么是24.2.63(24.2.c)的新功能,什么是新功能(24.2.c)9什么是24.2.44.2.44(24.2.b)的新事物,for 24.2.44(24.2.b)11 for 24.2.2.2.2.2.2.1.2.2.1. 24.2.2.1. 24.2.12(24 d.2.12)(24 d.2.12)(24 d.2.12) 13 Removable media access 13 Activating the FortiClientNetwork extension 13 Select availability features 15 Beta features 16 Product integration and support 17 Supported FortiClient features 17 Common use cases 20 SIA for FortiClient agent-based remote users 21 SIA for FortiExtender site-based remote users 22 SIA for FortiGate SD-WAN secure edge site-based remote users 22 SIA for FortiAP site-based remote users 22 SIA for SD-WAN On-Ramp site-based remote users 23 Supported SD-WAN坡道IPSEC设备23日志转发23使用Fortimanager 23远程浏览器隔离24 ZTNA 24 ZTNA 24 SPA 24 SPA服务连接许可证24 Spa Forticloud帐户24 Spa使用Fortigate SD-WAN HUB 25 SPA使用Fortigate SD-WAN HUB 25 SPA使用Fortisase Spa Spa 25 Spa使用Fortisase Spa for Fortisase Spa 27 fortisase Spa 27 30限制31 Fortiap 31 Forticlient桌面(Windows,MacOS,Linux)31 Forticlient Android 31
SIA用于基于代理的远程用户是最典型的用例,它涉及在包括Windows,MacOS和Linux端点在内的支持端点上安装和配置ForticLient。Fortisase Administration指南称此用例基于ForticLient代理模式。在这种用例中,富特酶防火墙作为服务(FWAA)介于端点和互联网之间。因为ForticLient基本上建立了使用FWAAS的全隧道SSL VPN,因此基于代理的SIA可以使用VPN策略来确保所有互联网流量和协议。每个端点连接到安全性POP。您可以通过将身份验证源配置为Active Directory(AD)/LDAP,RADIUS或SAML身份提供商(SAML IDP)来实现基于代理的远程用户身份验证。
A.它提供基于硬件的防火墙用于网络分割。B.它与软件定义的网络(SDN)解决方案集成在一起。C.它可以在端点上识别安全姿势检查的属性。D.它可以为远程员工启用VPN连接。答案:C说明:Fortisase通过识别安全姿势检查端点上的属性来支持零信任网络访问(ZTNA)原理。ZTNA原则需要在授予对网络资源的访问之前,需要连续验证用户和设备凭据及其安全姿势。安全姿势检查:Fortisase可以通过检查符合安全策略(例如防病毒状态,补丁级别和配置设置)来评估端点的安全姿势。这可以确保仅授予合规和安全的设备访问网络。零信任网络访问(ZTNA):ZTNA基于“永不信任,始终验证”的原则,该原则需要对用户和设备可信度进行持续评估。Fortisase通过执行这些安全姿势检查并执行访问控制策略在实施ZTNA中起着至关重要的作用。问题2在部署基于Fortisase代理的客户端时,与无代理解决方案相比,有三个功能可用?(选择三个。)