Fortios Features That Are Not Supported By Fortigate-7000 V5.4.5 - Fortinet FortiGate-7060E Handbook

Fortios
Hide thumbs Also See for FortiGate-7060E:
Table of Contents

Advertisement

FortiGate-7000 v5.4.5 special features and
limitations
For monitoring purpose, IPMI over IP is supported on SMM Ethernet ports. See your FortiGate-7000 system
guide for details.

FortiOS features that are not supported by FortiGate-7000 v5.4.5

The following mainstream FortiOS 5.4.5 features are not supported by the FortiGate-7000 v5.4.5:
Hardware switch
l
Switch controller
l
WiFi controller
l
WAN load balancing (SD-WAN)
l
IPv4 over IPv6, IPv6 over IPv4, IPv6 over IPv6 features
l
GRE tunneling is only supported after creating a load balance flow rule, for example:
l
config load-balance flow-rule
edit 0
set status enable
set vlan 0
set ether-type ip
set protocol gre
set action forward
set forward-slot master
set priority 3
end
Hard disk features including, WAN optimization, web caching, explicit proxy content caching, disk logging, and GUI-
l
based packet sniffing.
Log messages should be sent only using the management aggregate interface
l
IPsec VPN tunnels terminated by the FortiGate-7000
This section lists FortiGate-7000 limitations for IPsec VPN tunnels terminated by the FortiGate-7000:
Interface-based IPsec VPN is recommended.
l
Policy based IPsec VPN is supported, but requires creating flow-rules for each Phase 2 selector.
l
Dynamic routing and policy routing is not supported for IPsec interfaces.
l
IPsec static routes don't consider distance, weight, priority settings. IPsec static routes are always installed in the
l
routing table, regardless of the tunnel state.
IPsec tunnels are not load-balanced across the FPMs, all IPsec tunnel sessions are sent to the primary FPM
l
module.
IPsec VPN dialup or dynamic tunnels require a flow rule that sends traffic destined for IPsec dialup IP pools to the
l
primary FPM module.
In an HA configuration, IPsec SAs are not synchronized to the backup chassis. IPsec SAs are re-negociated after a
l
failover.
FortiGate-7000
Fortinet Technologies Inc.
FortiOS features that are not supported by FortiGate-7000
v5.4.5
74

Advertisement

Table of Contents
loading

Table of Contents