我们长期致力于开发和交付统一平台,通过发布Fortios 7.6的最新更新,这是我们行业领先的操作系统的最新更新。此更新在Fortinet Security Fabrage上注入了新的功能和服务,这是当今市场上最成熟,最全面的网络安全平台。与竞争对手刚刚跳上平台潮流不同,多年来,我们一直在努力地建造和完善安全结构,从而获得最广泛的产品覆盖率。这些对安全结构的最新增强功能包括在我们所有三个支柱中添加新的生成AI功能,为我们的防火墙,Sase和SOC运营添加新的托管服务,为我们的统一代理商提供新的集成以及新的数据保护。
Change Log 4 Introduction 5 FortiGate open ports 6 FortiAnalyzer open ports 9 FortiAP-S open ports 11 FortiAuthenticator open ports 12 FortiClient open ports 15 FortiClient 15 FortiClient EMS 16 FortiClient for Chromebook 17 FortiClient EMS for Chromebook 18 FortiGate Cloud open ports 19 FortiDB open ports 20 FortiGuard open ports 21 FortiMail open ports 23 FortiManager open ports 26 FortiPortal open ports 28 FortiSandbox open ports 29 Services and port numbers required for FortiSandbox 29 3rd-party servers open ports 31 Fortinet proprietary protocols 33 FGCP - FortiGate Clustering Protocol 34 FGSP - FortiGate Session Life Support Protocol 42 FGFM - FortiGate to FortiManager Protocol 46 SLBC - Session-aware Load Balancing Cluster 49 Fortinet Security Fabric 57 Fortiguard 59 Anycast和Unicast Services 61 Fortilink 62 Fortios WAN优化63 FSSO -FortInet单签名67 OFTP-优化的面料传输协议71 Forticlient EMS-端点管理服务器72
更改日志6介绍和支持的模型8支持的模型8 Fortigation 6000和7000支持8特殊通知9超大的不相容性和限制9 FortiGate 6000和7000不相容性和7000不相容性和限制9删除OCVPN支持9删除OCVPN支持9删除WTP配置文件9 Admin and super_admin administrators cannot log in after a prof_admin VDOM administrator restores the VDOM configuration and reboots the FortiGate 11 SMB drive mapping with ZTNA access proxy 11 Remote access with write rights through FortiGate Cloud 12 FortiGuard Web Filtering Category v10 update 12 FortiAP-W2 models may experience bootup failure during automatic firmware and federated upgrade process if they are powered by a managed FortiSwitch's PoE port 12 CLI系统权限13使用ECMP途径的本地流量可以使用不同的端口或服务器13 CLI的变化15 GUI行为的变化16违约行为的变化17表尺寸的变化17新功能或增强功能19 Cloud 6000和7000平台19 GUI 19 GUI 20 Hyperscale 20 Hyperscale 20 Hyperscale 20 Lan Edge 20 LAN Edge 21 Log&Report
Change log 4 Introduction 5 Executive summary 5 Intended audience 5 About this guide 5 Design overview 6 Deployment procedures 7 Example 1: FortiLink NAC policy to match device information 7 Example 2: Using a dynamic port policy with 802.1X authentication 12 Example 3: Dynamic detection with a vulnerability NAC policy 20 Example 4: Using EMS-tag NAC policies 25 Example 5: FortiOS automation stitch 29 Appendix A: Products used in this guide 33附录B:文档参考34
Change Log 6 Introduction and supported models 9 Supported models 9 Special notices 10 IPsec phase 1 interface type cannot be changed after it is configured 10 IP pools and VIPs are not considered local addresses for certain FortiOS versions 10 Support for FortiGates with NP7 processors and hyperscale firewall features 10 Changes in CLI 11 Changes in GUI behavior 13 Changes in default behavior 14 Changes in default values 15 Changes in table size 16 New features or enhancements 17 Upgrade information 30 Fortinet Security Fabric upgrade 30 Downgrading to previous firmware versions 31 Firmware image checksums 32 Strong cryptographic cipher requirements for FortiAP 32 FortiGate VM VDOM licenses 32 VDOM link and policy configuration is lost after upgrading if VDOM and VDOM link have the same name 32 GUI firmware upgrade does not respect upgrade path 33 Product integration and support 34 Virtualization environments 35 Language support 35 SSL VPN支持36 SSL VPN Web模式36解决问题37反垃圾邮件37抗病毒37应用程序控制37数据泄漏预防38端点控制38显式代理38 FIREWALL 38 FORTIVIEW 40 GUI 40 HA 42 HYPERSCALE 42 HYPERSCALE 43 ICAP 44 ICAP 44
变更日志 16 FortiOS CLI 参考 17 命令和选项的可用性 17 命令树 17 CLI 配置命令 19 alertemail 20 配置 alertemail 设置 20 防病毒 27 配置防病毒豁免列表 27 配置防病毒配置文件 28 配置防病毒隔离 58 配置防病毒设置 62 应用程序 64 配置应用程序自定义 64 配置应用程序组 65 配置应用程序列表 66 配置应用程序名称 75 配置应用程序规则设置 77 身份验证 78 配置身份验证规则 78 配置身份验证方案 80 配置身份验证设置 82 自动化 86 配置自动化设置 86 CASB 87 配置 CASB 配置文件 87 配置 CASB SAAS 应用程序 90 配置 CASB 用户活动 91 证书 97 配置证书 ca 97 配置证书 crl 99 配置本地证书 100 配置远程证书 104 直径过滤器 106 配置直径过滤器配置文件 106 dlp 109 配置 dlp 数据类型 109 配置 dlp 字典 110 配置 dlp 精确数据匹配 112 配置 dlp 文件模式 113 配置 dlp fp-doc-source 117 配置 dlp 配置文件 120 配置 dlp 灵敏度 125 配置 dlp 传感器 126
Change Log 5 Getting started 6 Registration 6 Basic configuration 6 Resources 7 Administrator access 9 Management network 9 User authentication for management network access 9 Who can access the FortiGate 9 What can administrators access 10 How can users access the FortiGate 10 Administrative settings 10 Day to day operations 12 Configuration changes 12 Policy configuration changes 13 Logging and reporting 14 Performance monitoring 14 Identity and access management 15 Certificates 17 Certificate usage 17 Security profiles 19 Opened ports for Authentication Override在Web滤清器中替换消息中20 SSL/TLS深度检查21迁移23使用配置文件手动迁移配置24远程访问26 SSL VPN 26 IPSEC VPN 27非VPN 27非VPN远程访问27高可用性和高可用性28高可用性28高可用性28高可用性28
Change Log 6 Introduction and supported models 8 Supported models 8 FortiGate 6000 and 7000 support 8 Special notices 9 Hyperscale incompatibilities and limitations 9 FortiGate 6000 and 7000 incompatibilities and limitations 9 SSL VPN removed from 2GB RAM models for tunnel and web mode 9 2 GB RAM FortiGate models no longer support FortiOS proxy-related features 10 FortiGate VM memory and upgrade 10 Hyperscale NP7 hardware limitation 10 FortiGate cannot restore configuration file 10 Changes in CLI 12 Changes in GUI behavior 13 Changes in default behavior 14 Changes in table size 15 New features or enhancements 16 Cloud 16 GUI 16 LAN Edge 17 Log & Report 20 Network 21 Policy & Objects 26 SD-WAN 27 Security Fabric 28 Security Profiles 29 System 31 User & Authentication 34 VPN 34 ZTNA 35 Upgrade information 37 Fortinet Security Fabric upgrade 37 Downgrading to previous firmware版本39固件图像校验和39 FortiGate 6000和7000升级信息39 CP-ACCEL模式的默认设置2GB内存模型40产品集成和支持41虚拟化环境42语言支持42 SSL VPN VPN支持43
更改log 4什么新功能5 fortios 7.2.1 5 fortios 7.2.0 5支持的RFCS 6 BGP 6密码学7 DHCP 8 DHCP 8 DIFFSERV 8 DNS 8 ICMP 9 ICMP 9 ICMP 9 IP 9 IP 9 IP 9 IPEC 9 IPV4 10 IPV4 10 IPV4 10 IPV6 10 IS-IS-IS-IS-IS 11 LDAP 11 NAT 11 NAT 11 NAT 11 OSPF 11 PPP 12 PPP 12 RIP 12 RIP 12 RIP 12 RIP 12 SFLP 12 SFLP 12 SFLP 12 SFLP 12 SFLP 12 SFLP 12 SFLP 12 SFLP 12 SFLP 12 Sftp 12 Sftp 12 Sftp 12 sftp 12 Sftp 12 Sftp 12 Sftp 12 Sftp TACACS+ 14 TCP 14 TLS 14 VPN 15无线15其他协议15杂项16
Change Log 6 Introduction and supported models 7 Supported models 7 FortiGate 6000 and 7000 support 7 Special notices 8 FortiManager support for updated FortiOS private data encryption key 8 FortiGate cannot restore configuration file after private-data-encryption is re-enabled 9 Hyperscale incompatibilities and limitations 10 FortiGate 6000 and 7000 incompatibilities and limitations 10 SSL VPN removed from 2GB RAM models for tunnel and Web模式10 2 GB RAM FortiGate模型不再支持与Fortios代理相关的功能10 FortiGate VM内存和升级11 Hyperscale NP7 NP7硬件限制11 GUI与IPSEC TCP在同一界面11 ssl VPN上的冲突不受IPSEC TCP的冲突。默认值19表尺寸20的变化20新功能或增强功能21云21 GUI 22 LAN EDGE 22网络22网络23策略与物体26 SD-WAN 27 SD-WAN 27安全织物30安全构造30安全配置文件30系统31用户和身份验证32 VPN 32 WIFI Controller 33 ZTNA 33 ZTNA 33升级信息33升级信息35 FortInet Security FaftInet Problade 35 FortInet diffore fort Grade diffore fort Grade difgrade to Grade difgrade difgrade difgrade difgrade 37