Fortinet opublikował aktualizację oprogramowania układowego dla produktu FortiSwitch, oznaczoną wersją 7.0.7! Nowa wersja przede wszystkim zwiększa bezpieczeństwo silnej kryptografii poprzez wyeliminowanie słabszych algorytmów szyfrowania. Rozwiązano również problemy zgłaszane przez administratorów rozwiązania.
Nowości w FortiSwitchOS 7.0.7:
Release 7.0.7 provides the following new features:
- To increase the security of strong cryptography, additional weaker ciphers algorithms are now removed. When you enable strong cryptography (
set strong-crypto enable
underconfig system global
), the following ciphers and algorithms are currently supported:- Ciphers (encryption algorithms):
- chacha20-poly1305@openssh.com
- aes128-ctr
- aes192-ctr
- aes256-ctr
- aes128-gcm@openssh.com
- aes256-gcm@openssh.com
- Key-exchange algorithms:
- curve25519-sha256@libssh.org
- diffie-hellman-group-exchange-sha256
- Host-key algorithm:
- ssh-ed25519
- Message authentication code algorithms:
- umac-128-etm@openssh.com
- hmac-sha2-256-etm@openssh.com
- hmac-sha2-512-etm@openssh.com
- Ciphers (encryption algorithms):
Wspierane modele:
FortiSwitch 1xx | FS-108E, FS-108E-POE, FS-108E-FPOE, FS-108F, FS-108F-POE, FS-108F-FPOE, FS-124E, FS-124E-POE, FS-124E-FPOE, FS-124F, FS-124F-POE, FS-124F-FPOE, FS-148E, FS-148E-POE, FS-148F, FS-148F-POE, FS-148F-FPOE |
FortiSwitch 2xx | FS-224D-FPOE, FS-224E, FS-224E-POE, FS-248D, FS-248E-POE, FS-248E-FPOE |
FortiSwitch 4xx | FS-424D, FS-424D-FPOE, FS-424D-POE, FS-424E, FS-424E-POE, FS-424E-FPOE, FS-424E-Fiber, FS-M426E-FPOE, FS-448D, FS-448D-FPOE, FS-448D-POE, FS-448E, FS-448E-POE, FS-448E-FPOE |
FortiSwitch 5xx | FS-524D-FPOE, FS-524D, FS-548D, FS-548D-FPOE |
FortiSwitch 1xxx | FS-1024D, FS-1024E, FS-1048D, FS-1048E, FS-T1024E |
FortiSwitch 3xxx | FS-3032D, FS-3032E |
FortiSwitch Rugged | FSR-112D-POE, FSR-124D |
Rozwiązane problemy:
Bug ID | Description |
---|---|
463161 | There is an “Invalid root configuration data” error reported after the firmware is upgraded. |
769456 | Support needed for PoE compatibility for the FS-124F-POE, FS-124F-FPOE, FS-148F-POE, and FS-148F-FPOE models. |
829804 | Changed which CLI commands are available, depending on whether the user has the enhanced debugging license. |
848619 | When connecting FS-124F-POE to FS-148F-POE with the FTLF8519P3BNLFTN, the SFP module port does not come up on the FS-148F-POE when auto-module is configured. |
856123 | When the network-monitor settings are enabled, there are multiple “CPU_SENSOR (78.0%) cleared warning threshold of (85.0%)” messages in the log. |
860773 | The output of the diagnose sys psu status command is wrong for the FSR-112D-POE model when both power supply units (PSUs) are connected and on. |
872727 | After upgrading the FS-448D-FPOE model, the status of PSU2 is wrongly reported as “Not inserted.” |
896010 | The FS-524D and FS-524D-FPOE models will assign two split ports with the same physical MAC address. |
902493 | The FS-148F-FPOE and FS-148F-POE models need to provide power over Ethernet (PoE) power to Cisco phones with Key Expansion Modules (KEMs). |
904617 | After a switch is rebooted, the Open Shortest Path First (OSPF) protocol advertises incorrect routes. |
906594 | The GUI needs to support static IP/32. |
914774 | Enabling energy-efficient Ethernet (EEE) on the FS-448E-POE disrupts traffic. |
917919 | The GUI produces an “Internal server error” after an administrator user that is more than 35 characters long tries to log in. |
924247 | Sticky MAC addresses and the MAC learning limit are not working on the FS-1xx models. |
Znane problemy:
Bug ID | Description |
---|---|
382518, 417024, 417073, 417099, 438441 | DHCP snooping and dynamic ARP inspection (DAI) do not work with private VLANs (PVLANs). |
414972 | IGMP snooping might not work correctly when used with 802.1x Dynamic VLAN functionality. |
463161 | Upgrading the FS-448D from FortiSwitchOS 3.5.6 to 3.6.3 fails with an “Invalid root configuration data.” error. |
480605 | When DHCP snooping is enabled on the FSR-112D-POE, the switched virtual interface (SVI) cannot get the IP address from the DHCP server.
Workarounds: |
510943 | The time-domain reflectometer (TDR) function (cable diagnostics feature) reports unexpected values.
Workaround: When using the cable diagnostics feature on a port (with the |
542031 | For the 5xx switches, the diagnose switch physical-ports led-flash command flashes only the SFP port LEDs, instead of all the port LEDs. |
548783 | Some models support setting the mirror destination to “internal.” This is intended only for debugging purposes and might prevent critical protocols from operating on ports being used as mirror sources. |
572052 | Backup files from FortiSwitchOS 3.x that have 16-character-long passwords fail when restored on FortiSwitchOS 6.x. In FortiSwitchOS 6.x, file backups fail with passwords longer than 15 characters.
Workaround: Use passwords with a maximum of 15 characters for FortiSwitchOS 3.x and 6.x. |
585550 | When packet sampling is enabled on an interface, packets that should be dropped by uRPF will be forwarded. |
606044, 610149 | The results are inaccurate when running cable diagnostics on the FS-108E, FS-124E, FS-108E-POE, FS-108E-FPOE, FS-124E-POE, FS-124E-FPOE, FS-148E, and FS-148E-POE models. |
609375 | The FortiSwitchOS supports four priority levels (critical, high, medium, and low); however, The SNMP Power Ethernet MIB only supports three levels. To support the MIB, a power priority of medium is returned as low for the PoE MIB. |
667079 | For the FSR-112D-POE model:
|
673433 | Some 7-meter DAC cables cause traffic loss for the FS-448E model. |
724813 | The set enforce-first-as {disable | enable} command should have been placed under config neighbor and does not work in its current location (directly under config router bgp ). There is no patch available for this issue. |
784585 | When a dynamic LACP trunk has formed between switches in an MRP ring, the MRP ring cannot be closed. Deleting the dynamic LACP trunk does not fix this issue. MRP supports only physical ports and static trunks; MRP does not support dynamic LACP trunks.
Workaround: Disable MRP and then re-enable MRP. |
833450 | Do not use multicast IP addresses in the ranges of 224-239.0.0.x and 224-239.128.0.x on the FS-2xxD, FS-2xxE, FS-4xxD, and FS-4xxE models.
Workaround: Upgrade to FortiSwitchOS 7.2.4 or 7.4.0. |
Notatki producenta: FortiSwitch 7.0.7
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie