diff --git a/configs/fortigate/fortigate.conf b/configs/fortigate/fortigate.conf index 231193b..48bfd52 100644 --- a/configs/fortigate/fortigate.conf +++ b/configs/fortigate/fortigate.conf @@ -1,18 +1,18 @@ -#config-version=F2K61F-7.0.17-FW-build0682-250113:opmode=0:vdom=1:user=jpoland -#conf_file_ver=6251333490717899 -#buildno=0682 +#config-version=F2K61F-7.4.9-FW-build2829-250924:opmode=0:vdom=1:user=jpoland +#conf_file_ver=642393963644344 +#buildno=2829 #global_vdom=1 config vdom edit root next -edit scsd -next edit Policy next edit TEST next +edit scsd +next end config global @@ -21,7 +21,7 @@ config system global set admin-console-timeout 0 set admin-forticloud-sso-login disable set admin-host '' - set admin-hsts-max-age 15552000 + set admin-hsts-max-age 63072000 set admin-https-pki-required disable set admin-https-redirect enable unset admin-https-ssl-banned-ciphers @@ -30,7 +30,6 @@ config system global set admin-lockout-duration 60 set admin-lockout-threshold 3 set admin-login-max 100 - set admin-maintainer enable set admin-port 80 set admin-restrict-local disable set admin-scp disable @@ -50,6 +49,7 @@ config system global set auth-cert "Fortinet_Factory" set auth-http-port 1000 set auth-https-port 1003 + set auth-ike-saml-port 1001 set auth-keepalive disable set auth-session-limit block-new set auto-auth-extension-device enable @@ -58,6 +58,7 @@ config system global set av-failopen pass set av-failopen-session disable set batch-cmdb enable + set bfd-affinity "1" set block-session-timer 30 set br-fdb-max-entry 8192 set cert-chain-max 8 @@ -67,27 +68,38 @@ config system global set cli-audit-log disable set cloud-communication enable set clt-cert-req disable - set cmdbsvr-affinity "0" + set cmdbsvr-affinity "1" set cpu-use-threshold 90 set csr-ca-attribute enable set daily-restart disable set default-service-source-port 1-65535 + set delay-tcp-npu-session disable set device-idle-timeout 300 set dh-params 2048 + set dhcp-lease-backup-interval 60 set dnsproxy-worker-count 1 - set dst enable set early-tcp-npu-session disable set extender-controller-reserved-network 10.252.0.1 255.255.0.0 set faz-disk-buffer-size 0 set fds-statistics enable unset fgd-alert-subscription + set forticonverter-config-upload disable + set forticonverter-integration disable set fortiextender disable set fortiextender-data-port 25246 set fortiextender-discovery-lockdown disable + set fortiextender-provision-on-authorization disable set fortiextender-vlan-mode disable + set fortigslb-integration disable set fortiservice-port 8013 set fortitoken-cloud enable - set gui-allow-default-hostname disable + set fortitoken-cloud-push-status enable + set fortitoken-cloud-region '' + set fortitoken-cloud-sync-interval 24 + set geoip-full-db disable + set gtpu-dynamic-source-port disable + set gui-app-detection-sdwan disable + set gui-auto-upgrade-setup-warning disable set gui-cdn-usage disable set gui-certificates enable set gui-custom-language disable @@ -99,34 +111,36 @@ config system global set gui-firmware-upgrade-warning enable set gui-forticare-registration-setup-warning enable set gui-fortigate-cloud-sandbox disable - set gui-fortiguard-resource-fetch enable set gui-ipv6 disable set gui-local-out disable set gui-replacement-message-groups disable set gui-rest-api-cache enable set gui-theme jade set gui-wireless-opensecurity disable - set ha-affinity "0" + set gui-workflow-management disable + set ha-affinity "1" set honor-df enable set hostname "noc-fortigate-a" set hyper-scale-vdom-num 250 set igmp-state-limit 3200 + set interface-subnet-usage enable set internet-service-database full + set ip-conflict-detection disable set ip-fragment-mem-thresholds 32 set ip-src-port-range 1024-25000 set ipsec-asic-offload enable set ipsec-ha-seqjump-rate 10 set ipsec-hmac-offload enable - set ipsec-soft-dec-async disable set ipv6-accept-dad 1 set ipv6-allow-anycast-probe disable - set ipv6-allow-local-in-slient-drop enable + set ipv6-allow-local-in-silent-drop enable set ipv6-allow-multicast-probe disable set ipv6-allow-traffic-redirect enable set language english set ldapconntimeout 500 set lldp-reception disable set lldp-transmission disable + set log-single-cpu-high disable set log-ssl-connection disable set log-uuid-address disable set login-timestamp disable @@ -153,49 +167,54 @@ config system global set proxy-auth-timeout 10 set proxy-cert-use-mgmt-vdom disable set proxy-hardware-acceleration enable - set proxy-re-authentication-mode session + set proxy-keep-alive-mode session set proxy-resource-mode disable set proxy-worker-count 0 + set purdue-level 3 + set quic-ack-thresold 3 + set quic-congestion-control-algo cubic + set quic-max-datagram-size 1500 + set quic-pmtud enable + set quic-tls-handshake-timeout 5 + set quic-udp-payload-size-shaping-per-cid enable set radius-port 1812 set reboot-upon-config-restore enable set refresh 0 set remoteauthtimeout 120 set reset-sessionless-tcp disable + set rest-api-key-url-query disable set revision-backup-on-logout enable set revision-image-auto-backup disable set scanunit-count 0 - set security-rating-result-submission enable set security-rating-run-on-schedule enable set send-pmtu-icmp enable + set sflowd-max-children-num 6 set snat-route-change disable set special-file-23-support disable set speedtest-server disable + set speedtestd-ctrl-port 5200 + set speedtestd-server-port 5201 set split-port '' set ssd-trim-freq weekly set ssd-trim-hour 1 set ssd-trim-min 60 set ssd-trim-weekday sunday - set ssh-enc-algo chacha20-poly1305@openssh.com aes256-ctr aes256-gcm@openssh.com - set ssh-kex-algo diffie-hellman-group-exchange-sha256 curve25519-sha256@libssh.org ecdh-sha2-nistp256 ecdh-sha2-nistp384 ecdh-sha2-nistp521 - set ssh-mac-algo hmac-sha2-256 hmac-sha2-256-etm@openssh.com hmac-sha2-512 hmac-sha2-512-etm@openssh.com set ssl-min-proto-version TLSv1-2 set ssl-static-key-ciphers enable - set sslvpn-cipher-hardware-acceleration disable - set sslvpn-ems-sn-check disable - set sslvpn-kxp-hardware-acceleration disable set sslvpn-max-worker-count 0 - set sslvpn-plugin-version-check enable + set sslvpn-web-mode enable set strict-dirty-session-check enable set strong-crypto enable set switch-controller enable - set switch-controller-reserved-network 10.255.0.0 255.255.0.0 + set switch-controller-reserved-network 10.255.0.1 255.255.0.0 set sys-perf-log-interval 5 + set syslog-affinity "0" set tcp-halfclose-timer 120 set tcp-halfopen-timer 10 set tcp-option enable set tcp-rst-timer 5 set tcp-timewait-timer 1 - set timezone 12 + set timezone "US/Eastern" set traffic-priority tos set traffic-priority-level medium set two-factor-email-expiry 60 @@ -206,17 +225,19 @@ config system global set udp-idle-timer 180 set url-filter-affinity "0" set url-filter-count 1 + set user-device-store-max-device-mem 2 set user-device-store-max-devices 507278 - set user-device-store-max-unified-mem 2536393932 + set user-device-store-max-unified-mem 2536393318 set user-device-store-max-users 507278 - set user-server-cert "Fortinet_Factory" set vdom-mode multi-vdom set vip-arp-range restricted set virtual-switch-vlan disable + set vpn-ems-sn-check disable set wad-affinity "0" set wad-csvc-cs-count 1 set wad-csvc-db-count 0 set wad-memory-change-granularity 10 + set wad-restart-mode none set wad-source-affinity enable set wad-worker-count 0 set wifi-ca-certificate "Fortinet_Wifi_CA" @@ -244,7 +265,13 @@ config system accprofile set wanoptgrp read-write set wifi read-write set admintimeout-override disable - set system-diagnostics enable + set cli-diagnose disable + set cli-get enable + set cli-show enable + set cli-exec enable + set cli-config enable + set system-execute-ssh enable + set system-execute-telnet enable next edit "NOC_Dashboard" set scope vdom @@ -261,7 +288,13 @@ config system accprofile set wanoptgrp read set wifi read set admintimeout-override enable - set system-diagnostics disable + set cli-diagnose disable + set cli-get enable + set cli-show enable + set cli-exec enable + set cli-config enable + set system-execute-ssh enable + set system-execute-telnet enable set admintimeout 0 next edit "Read_Only" @@ -279,17 +312,24 @@ config system accprofile set wanoptgrp read set wifi read set admintimeout-override disable - set system-diagnostics enable + set cli-diagnose disable + set cli-get enable + set cli-show enable + set cli-exec enable + set cli-config enable + set system-execute-ssh enable + set system-execute-telnet enable next end +config system isf-queue-profile +end config system npu set dedicated-management-cpu disable - set ipsec-ob-np-sel rr + set dedicated-lacp-queue disable config dos-options set npu-dos-meter-mode global set npu-dos-tpe-mode enable end - set policy-offload-level disable set napi-break-interval 0 config hpe set all-protocol 400000 @@ -309,7 +349,9 @@ config system npu set enable-shaper disable end set capwap-offload enable - set default-qos-type shaping + set vxlan-offload enable + set default-qos-type policing + set shaping-stats disable set gtp-support disable set per-session-accounting traffic-log-only set session-acct-interval 5 @@ -339,6 +381,8 @@ config system npu set tcp-csum-err drop set udp-csum-err drop set icmp-csum-err drop + set gre-csum-err drop + set sctp-csum-err drop set ipv6-land trap-to-host set ipv6-proto-err trap-to-host set ipv6-unknopt trap-to-host @@ -464,9 +508,27 @@ config system npu set weight 13 next end + set custom-etype-lookup disable end + set qos-mode disable set double-level-mcast-offload disable set qtm-buf-mode 6ch + set ipsec-ob-np-sel rr + set max-receive-unit 10000 + config sw-eh-hash + set computation xor16 + set ip-protocol include + set source-ip-upper-16 include + set source-ip-lower-16 include + set destination-ip-upper-16 include + set destination-ip-lower-16 include + set source-port include + set destination-port include + set netmask-length 32 + end + config sw-tr-hash + set draco15 enable + end end config system npu-vlink end @@ -474,7 +536,8 @@ config system vdom-link end config wireless-controller inter-controller set inter-controller-mode disable - set inter-controller-key ENC eHQAZvmBSb+BVm46O44w3RrLvudhWg/ytjhRqbzNqlhgdjNSc098MMNm7i0IFeCtVmQJAm1WRETFtSDQFVTphqIesoMPi2XtF8AleVGD9Jdy0l/Z8H/vLJKCo16JSq28GTbf1mr8dG5n1RN5F6snNLdHPc4ThRK4eklyfmYePLDovtTlr3QmKlexcyQLgjPbx/9dBw== + set l3-roaming disable + set inter-controller-key ENC ZmlsZZn2w3be/mZLqfwOHw5UwBLtk9b92nHMkmAPjff0gGTc6T2ZAx9Gd9/+/op/MDAvixueGH6caXt2KS1RTyiLbp9GNitEQA9v1AQ4vlOjFSm96zLRti3u7yqpOlWoUmIHUOMDYg3ykU7CZQOplihrTha45OpKE9+hpFYkXhrxYMilhOCRJNwdu1qQ3bj/ARVp1FlmMjY3dkVA set inter-controller-pri primary set fast-failover-max 10 set fast-failover-wait 10 @@ -482,7 +545,11 @@ end config wireless-controller global set name '' set location '' + set acd-process-count 0 + set wpad-process-count 0 set image-download enable + set rolling-wtp-upgrade disable + set rolling-wtp-upgrade-threshold "-80" set max-retransmit 3 set control-message-offload ebp-frame aeroscout-tag ap-list sta-list sta-cap-list stats aeroscout-mu sta-health spectral-analysis set data-ethernet-II enable @@ -497,16 +564,15 @@ config wireless-controller global set tunnel-mode compatible set nac-interval 120 set ap-log-server disable + set max-sta-cap 0 + set max-sta-cap-wtp 8 + set max-rogue-ap 0 + set max-rogue-ap-wtp 16 + set max-rogue-sta 0 + set max-ble-device 0 end config system switch-interface end -config system lte-modem - set status disable - set extra-init '' - set authtype none - set apn '' - set modem-port 255 -end config system interface edit "port1" set vdom "root" @@ -551,7 +617,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -560,6 +625,7 @@ config system interface set description '' set alias "HA Port 1" set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -576,12 +642,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -601,7 +669,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -609,11 +678,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port2" set vdom "root" @@ -658,7 +728,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -667,6 +736,7 @@ config system interface set description '' set alias "HA Port 2" set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -683,12 +753,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -708,7 +780,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -716,11 +789,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port3" set vdom "root" @@ -765,7 +839,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -774,6 +847,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -790,12 +864,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -815,7 +891,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -823,11 +900,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port4" set vdom "root" @@ -872,7 +950,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -881,6 +958,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -897,12 +975,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -922,7 +1002,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -930,11 +1011,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port5" set vdom "scsd" @@ -945,10 +1027,10 @@ config system interface set status up set type physical set src-check enable - set disconnect-threshold 0 set trunk disable set description '' set alias '' + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -963,8 +1045,11 @@ config system interface set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 - set dhcp-relay-request-all-server disable + set port-mirroring disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set dns-server-override enable @@ -980,10 +1065,10 @@ config system interface set status up set type physical set src-check enable - set disconnect-threshold 0 set trunk disable set description '' set alias '' + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -998,8 +1083,11 @@ config system interface set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 - set dhcp-relay-request-all-server disable + set port-mirroring disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set dns-server-override enable @@ -1049,7 +1137,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1058,6 +1145,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1074,12 +1162,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1099,7 +1189,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1107,11 +1198,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port8" set vdom "root" @@ -1156,7 +1248,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1165,6 +1256,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1181,12 +1273,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1206,7 +1300,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1214,11 +1309,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port9" set vdom "TEST" @@ -1263,7 +1359,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1272,6 +1367,7 @@ config system interface set description '' set alias "LAN_Test" set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1288,12 +1384,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1313,7 +1411,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1321,11 +1420,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port10" set vdom "TEST" @@ -1370,7 +1470,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1379,6 +1478,7 @@ config system interface set description '' set alias "WAN_Test" set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1395,12 +1495,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1420,7 +1522,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1428,11 +1531,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port11" set vdom "root" @@ -1477,7 +1581,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1486,6 +1589,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1502,12 +1606,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1527,7 +1633,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1535,11 +1642,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port12" set vdom "root" @@ -1584,7 +1692,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1593,6 +1700,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1609,12 +1717,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1634,7 +1744,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1642,11 +1753,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port13" set vdom "root" @@ -1691,7 +1803,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1700,6 +1811,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1716,12 +1828,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1741,7 +1855,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1749,11 +1864,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port14" set vdom "root" @@ -1798,7 +1914,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1807,6 +1922,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1823,12 +1939,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1848,7 +1966,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1856,11 +1975,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port15" set vdom "root" @@ -1905,7 +2025,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -1914,6 +2033,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -1930,12 +2050,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -1955,7 +2077,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -1963,11 +2086,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port16" set vdom "root" @@ -2012,7 +2136,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2021,6 +2144,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2037,12 +2161,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2062,7 +2188,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2070,11 +2197,12 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set speed 10000auto - set mtu-override disable + set speed auto set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port17" set vdom "scsd" @@ -2086,10 +2214,10 @@ config system interface set type physical set src-check enable set mediatype sr - set disconnect-threshold 0 set trunk disable set description '' set alias '' + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -2104,8 +2232,11 @@ config system interface set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 - set dhcp-relay-request-all-server disable + set port-mirroring disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set dns-server-override enable @@ -2122,10 +2253,10 @@ config system interface set type physical set src-check enable set mediatype sr - set disconnect-threshold 0 set trunk disable set description '' set alias '' + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -2140,8 +2271,11 @@ config system interface set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 - set dhcp-relay-request-all-server disable + set port-mirroring disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set dns-server-override enable @@ -2158,10 +2292,10 @@ config system interface set type physical set src-check enable set mediatype sr - set disconnect-threshold 0 set trunk disable set description '' set alias '' + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -2176,8 +2310,11 @@ config system interface set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 - set dhcp-relay-request-all-server disable + set port-mirroring disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set dns-server-override enable @@ -2194,10 +2331,10 @@ config system interface set type physical set src-check enable set mediatype sr - set disconnect-threshold 0 set trunk disable set description '' set alias '' + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -2212,8 +2349,11 @@ config system interface set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 - set dhcp-relay-request-all-server disable + set port-mirroring disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set dns-server-override enable @@ -2264,7 +2404,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2273,6 +2412,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2289,13 +2429,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2315,7 +2457,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2324,10 +2467,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 25000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port22" set vdom "root" @@ -2373,7 +2517,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2382,6 +2525,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2398,13 +2542,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2424,7 +2570,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2433,10 +2580,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 25000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port23" set vdom "root" @@ -2482,7 +2630,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2491,6 +2638,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2507,13 +2655,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2533,7 +2683,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2542,10 +2693,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 25000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port24" set vdom "root" @@ -2591,7 +2743,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2600,6 +2751,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2616,13 +2768,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2642,7 +2796,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2651,10 +2806,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 25000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port25" set vdom "scsd" @@ -2700,7 +2856,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2709,6 +2864,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2725,12 +2881,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2750,7 +2908,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2759,10 +2918,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port26" set vdom "root" @@ -2808,7 +2968,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2817,6 +2976,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2833,12 +2993,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2858,7 +3020,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2867,10 +3030,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port27" set vdom "root" @@ -2916,7 +3080,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -2925,6 +3088,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -2941,12 +3105,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -2966,7 +3132,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -2975,10 +3142,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port28" set vdom "root" @@ -3024,7 +3192,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3033,6 +3200,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3049,12 +3217,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3074,7 +3244,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3083,10 +3254,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port29" set vdom "scsd" @@ -3132,7 +3304,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3141,6 +3312,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3157,12 +3329,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3182,7 +3356,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3191,10 +3366,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port30" set vdom "root" @@ -3240,7 +3416,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3249,6 +3424,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3265,12 +3441,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3290,7 +3468,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3299,10 +3478,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port31" set vdom "root" @@ -3348,7 +3528,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3357,6 +3536,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3373,12 +3553,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3398,7 +3580,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3407,10 +3590,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port32" set vdom "root" @@ -3456,7 +3640,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3465,6 +3648,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3481,12 +3665,14 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3506,7 +3692,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3515,10 +3702,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port33" set vdom "root" @@ -3564,7 +3752,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3573,6 +3760,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3589,13 +3777,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3615,7 +3805,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3624,10 +3815,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 100Gfull - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port34" set vdom "root" @@ -3673,7 +3865,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3682,6 +3873,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3698,13 +3890,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3724,7 +3918,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3733,10 +3928,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 100Gfull - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port35" set vdom "root" @@ -3782,7 +3978,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3791,6 +3986,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3807,13 +4003,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3833,7 +4031,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3842,10 +4041,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 100Gfull - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "port36" set vdom "root" @@ -3891,7 +4091,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -3900,6 +4099,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -3916,13 +4116,15 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 set forward-error-correction disable + set eap-supplicant disable set np-qos-profile 0 + set port-mirroring disable config ipv6 set ip6-mode static set nd-mode basic @@ -3942,7 +4144,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -3951,10 +4154,11 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 100Gfull - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable + set sw-algorithm default next edit "mgmt1" set vdom "root" @@ -4001,7 +4205,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -4009,6 +4212,7 @@ config system interface set trunk disable set description '' set alias '' + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -4027,6 +4231,14 @@ config system interface set ap-discover enable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -4042,7 +4254,8 @@ config system interface set ip6-send-adv disable set autoconf disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set defaultgw enable set dns-server-override enable set dns-server-protocol cleartext @@ -4053,10 +4266,10 @@ config system interface set trust-ip6-1 ::/0 set trust-ip6-2 ::/0 set trust-ip6-3 ::/0 - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable next edit "mgmt2" set vdom "root" @@ -4103,7 +4316,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -4111,6 +4323,7 @@ config system interface set trunk disable set description '' set alias '' + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -4129,6 +4342,14 @@ config system interface set ap-discover enable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -4144,7 +4365,8 @@ config system interface set ip6-send-adv disable set autoconf disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set defaultgw enable set dns-server-override enable set dns-server-protocol cleartext @@ -4155,10 +4377,10 @@ config system interface set trust-ip6-1 ::/0 set trust-ip6-2 ::/0 set trust-ip6-3 ::/0 - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable next edit "ha1" set vdom "root" @@ -4204,7 +4426,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -4213,6 +4434,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -4229,11 +4451,19 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -4253,7 +4483,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -4262,10 +4493,10 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable next edit "ha2" set vdom "root" @@ -4311,7 +4542,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -4320,6 +4550,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -4336,11 +4567,19 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -4360,7 +4599,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -4369,10 +4609,10 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed 10000full - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable next edit "modem" set vdom "root" @@ -4414,7 +4654,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -4423,6 +4662,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -4442,6 +4682,14 @@ config system interface set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -4460,12 +4708,14 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set ipunnumbered 0.0.0.0 set username '' - set password ENC cgwHE6Tbk5nPSjNj7Mw8P92Pq1KXbiVRt9QX9lHYeCSwxO6siBvdbeVyToAj0g70uLWuxatLRq5BkGjaQluA1Ws9QOSdEpWyp3bzL2ex/vnKWTrkVLW+R3IR8tcDNkegClG0hhyUSTizoS61Eo2MTZMzjG7DF7qlPiZdYQWkhFiwWTpF2gZhRbOq0FxiPKMMbLTpdg== + set pppoe-egress-cos cos0 + set password ENC syQUyBMOAxT0qaZurFdBWXl79yyvmVlUBWeubQs9GPJkKOc1irAlICnlyihPocsDMYMzPKZColgEa2KKWeLE36/9W7Jt9sM20QGlnryjMPn7HryPmQVePd/72EtQcdLkffs7ggQowywwbZtJf9i+kfWV61N86L++ukd6qQKczyI5kjpMixcWjUZg96GUmcWdW5uNoVlmMjY3dkVA set idle-timeout 0 set disc-retry-timeout 1 set padt-retry-timeout 1 @@ -4478,10 +4728,10 @@ config system interface set dns-server-protocol cleartext set auth-type auto set speed auto - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable next edit "naf.root" set vdom "root" @@ -4526,6 +4776,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -4537,9 +4788,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set nd-mode basic set ip6-address ::/0 @@ -4549,11 +4807,11 @@ config system interface set ip6-retrans-time 0 set ip6-hop-limit 0 set ip6-prefix-mode dhcp6 - set ip6-delegated-prefix-iaid 0 set dhcp6-prefix-delegation disable set dhcp6-information-request disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -4599,9 +4857,11 @@ config system interface set weight 0 set external disable set trunk disable + set remote-ip 0.0.0.0 0.0.0.0 set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -4613,9 +4873,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -4632,7 +4899,8 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -4649,8 +4917,6 @@ config system interface set arpforward enable set broadcast-forward disable set bfd global - set icmp-send-redirect enable - set icmp-accept-redirect enable set reachable-time 30000 set ips-sniffer-mode disable set ident-accept disable @@ -4681,6 +4947,7 @@ config system interface set description '' set alias "SSL VPN interface" set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -4692,15 +4959,21 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic set ip6-address ::/0 unset ip6-allowaccess - set icmp6-send-redirect enable set ra-send-mtu enable set ip6-reachable-time 0 set ip6-retrans-time 0 @@ -4711,240 +4984,8 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable - set dns-server-override enable - set dns-server-protocol cleartext - set wccp disable - next - edit "naf.scsd" - set vdom "scsd" - set vrf 0 - set distance 5 - set priority 1 - set dhcp-relay-interface-select-method auto - set dhcp-relay-service disable - set ip 0.0.0.0 0.0.0.0 - set arpforward enable - set broadcast-forward disable - set bfd global - set icmp-send-redirect enable - set icmp-accept-redirect enable - set reachable-time 30000 - set ips-sniffer-mode disable - set ident-accept disable - set ipmac disable - set status up - set netbios-forward disable - set wins-ip 0.0.0.0 - set type tunnel - set netflow-sampler disable - set sflow-sampler disable - set src-check disable - set sample-rate 2000 - set polling-interval 20 - set sample-direction both - set explicit-web-proxy disable - set explicit-ftp-proxy disable - set proxy-captive-portal disable - set tcp-mss 0 - set inbandwidth 0 - set outbandwidth 0 - set egress-shaping-profile '' - set ingress-shaping-profile '' - set spillover-threshold 0 - set ingress-spillover-threshold 0 - set weight 0 - set external disable - set trunk disable - set description '' - set alias '' - set security-mode none - set estimated-upstream-bandwidth 0 - set estimated-downstream-bandwidth 0 - set measured-upstream-bandwidth 0 - set measured-downstream-bandwidth 0 - set bandwidth-measure-time 0 - set monitor-bandwidth disable - set role undefined - set snmp-index 57 - set preserve-session-route disable - set auto-auth-extension-device disable - set ap-discover enable - set ip-managed-by-fortiipam disable - set switch-controller-igmp-snooping-proxy disable - set switch-controller-igmp-snooping-fast-leave disable - config ipv6 - set nd-mode basic - set ip6-address ::/0 - set icmp6-send-redirect enable - set ra-send-mtu enable - set ip6-reachable-time 0 - set ip6-retrans-time 0 - set ip6-hop-limit 0 - set ip6-prefix-mode dhcp6 - set ip6-delegated-prefix-iaid 0 - set dhcp6-prefix-delegation disable - set dhcp6-information-request disable - end - set dhcp-relay-request-all-server disable - set dns-server-override enable - set dns-server-protocol cleartext - set wccp disable - next - edit "l2t.scsd" - set vdom "scsd" - set vrf 0 - set distance 5 - set priority 1 - set dhcp-relay-interface-select-method auto - set dhcp-relay-service disable - set ip 0.0.0.0 0.0.0.0 - unset allowaccess - set arpforward enable - set broadcast-forward disable - set bfd global - set icmp-send-redirect enable - set icmp-accept-redirect enable - set reachable-time 30000 - set ips-sniffer-mode disable - set ident-accept disable - set ipmac disable - set status up - set netbios-forward disable - set wins-ip 0.0.0.0 - set type tunnel - set netflow-sampler disable - set sflow-sampler disable - set src-check enable - set sample-rate 2000 - set polling-interval 20 - set sample-direction both - set explicit-web-proxy disable - set explicit-ftp-proxy disable - set proxy-captive-portal disable - set tcp-mss 0 - set inbandwidth 0 - set outbandwidth 0 - set egress-shaping-profile '' - set ingress-shaping-profile '' - set spillover-threshold 0 - set ingress-spillover-threshold 0 - set weight 0 - set external disable - set trunk disable - set description '' - set alias '' - set security-mode none - set estimated-upstream-bandwidth 0 - set estimated-downstream-bandwidth 0 - set measured-upstream-bandwidth 0 - set measured-downstream-bandwidth 0 - set bandwidth-measure-time 0 - set monitor-bandwidth disable - set role undefined - set snmp-index 58 - set preserve-session-route disable - set auto-auth-extension-device disable - set ap-discover enable - set ip-managed-by-fortiipam disable - set switch-controller-igmp-snooping-proxy disable - set switch-controller-igmp-snooping-fast-leave disable - config ipv6 - set ip6-mode static - set nd-mode basic - set ip6-address ::/0 - unset ip6-allowaccess - set icmp6-send-redirect enable - set ra-send-mtu enable - set ip6-reachable-time 0 - set ip6-retrans-time 0 - set ip6-hop-limit 0 - set dhcp6-prefix-delegation disable - set dhcp6-information-request disable - set ip6-send-adv disable - set autoconf disable - set dhcp6-relay-service disable - end - set dhcp-relay-request-all-server disable - set dns-server-override enable - set dns-server-protocol cleartext - set wccp disable - next - edit "ssl.scsd" - set vdom "scsd" - set vrf 0 - set distance 5 - set priority 1 - set dhcp-relay-interface-select-method auto - set dhcp-relay-service disable - set ip 0.0.0.0 0.0.0.0 - unset allowaccess - set arpforward enable - set broadcast-forward disable - set bfd global - set icmp-send-redirect enable - set icmp-accept-redirect enable - set reachable-time 30000 - set ips-sniffer-mode disable - set ident-accept disable - set ipmac disable - set status up - set netbios-forward disable - set wins-ip 0.0.0.0 - set type tunnel - set netflow-sampler disable - set sflow-sampler disable - set src-check enable - set sample-rate 2000 - set polling-interval 20 - set sample-direction both - set explicit-web-proxy disable - set explicit-ftp-proxy disable - set proxy-captive-portal disable - set tcp-mss 0 - set inbandwidth 0 - set outbandwidth 0 - set egress-shaping-profile '' - set ingress-shaping-profile '' - set spillover-threshold 0 - set ingress-spillover-threshold 0 - set weight 0 - set external disable - set trunk disable - set description '' - set alias "SSL VPN interface" - set security-mode none - set estimated-upstream-bandwidth 0 - set estimated-downstream-bandwidth 0 - set measured-upstream-bandwidth 0 - set measured-downstream-bandwidth 0 - set bandwidth-measure-time 0 - set monitor-bandwidth disable - set role undefined - set snmp-index 45 - set preserve-session-route disable - set auto-auth-extension-device disable - set ap-discover enable - set ip-managed-by-fortiipam disable - set switch-controller-igmp-snooping-proxy disable - set switch-controller-igmp-snooping-fast-leave disable - config ipv6 - set ip6-mode static - set nd-mode basic - set ip6-address ::/0 - unset ip6-allowaccess - set icmp6-send-redirect enable - set ra-send-mtu enable - set ip6-reachable-time 0 - set ip6-retrans-time 0 - set ip6-hop-limit 0 - set dhcp6-prefix-delegation disable - set dhcp6-information-request disable - set ip6-send-adv disable - set autoconf disable - set dhcp6-relay-service disable - end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -4989,6 +5030,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5000,9 +5042,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set nd-mode basic set ip6-address ::/0 @@ -5012,11 +5061,11 @@ config system interface set ip6-retrans-time 0 set ip6-hop-limit 0 set ip6-prefix-mode dhcp6 - set ip6-delegated-prefix-iaid 0 set dhcp6-prefix-delegation disable set dhcp6-information-request disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -5059,9 +5108,11 @@ config system interface set weight 0 set external disable set trunk disable + set remote-ip 0.0.0.0 0.0.0.0 set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5073,9 +5124,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5092,7 +5150,8 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -5109,8 +5168,6 @@ config system interface set arpforward enable set broadcast-forward disable set bfd global - set icmp-send-redirect enable - set icmp-accept-redirect enable set reachable-time 30000 set ips-sniffer-mode disable set ident-accept disable @@ -5138,6 +5195,7 @@ config system interface set description '' set alias "SSL VPN interface" set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5149,15 +5207,21 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic set ip6-address ::/0 unset ip6-allowaccess - set icmp6-send-redirect enable set ra-send-mtu enable set ip6-reachable-time 0 set ip6-retrans-time 0 @@ -5168,7 +5232,8 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -5216,6 +5281,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5227,9 +5293,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set nd-mode basic set ip6-address ::/0 @@ -5239,11 +5312,11 @@ config system interface set ip6-retrans-time 0 set ip6-hop-limit 0 set ip6-prefix-mode dhcp6 - set ip6-delegated-prefix-iaid 0 set dhcp6-prefix-delegation disable set dhcp6-information-request disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -5289,9 +5362,11 @@ config system interface set weight 0 set external disable set trunk disable + set remote-ip 0.0.0.0 0.0.0.0 set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5303,9 +5378,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5322,7 +5404,8 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -5339,6 +5422,174 @@ config system interface set arpforward enable set broadcast-forward disable set bfd global + set reachable-time 30000 + set ips-sniffer-mode disable + set ident-accept disable + set ipmac disable + set status up + set netbios-forward disable + set wins-ip 0.0.0.0 + set type tunnel + set netflow-sampler disable + set sflow-sampler disable + set src-check enable + set sample-rate 2000 + set polling-interval 20 + set sample-direction both + set explicit-web-proxy disable + set explicit-ftp-proxy disable + set proxy-captive-portal disable + set tcp-mss 0 + set inbandwidth 0 + set outbandwidth 0 + set egress-shaping-profile '' + set ingress-shaping-profile '' + set spillover-threshold 0 + set ingress-spillover-threshold 0 + set weight 0 + set external disable + set trunk disable + set description '' + set alias "SSL VPN interface" + set security-mode none + set ike-saml-server '' + set estimated-upstream-bandwidth 0 + set estimated-downstream-bandwidth 0 + set measured-upstream-bandwidth 0 + set measured-downstream-bandwidth 0 + set bandwidth-measure-time 0 + set monitor-bandwidth disable + set role undefined + set snmp-index 47 + set preserve-session-route disable + set auto-auth-extension-device disable + set ap-discover enable + set switch-controller-igmp-snooping-proxy disable + set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end + config ipv6 + set ip6-mode static + set nd-mode basic + set ip6-address ::/0 + unset ip6-allowaccess + set ra-send-mtu enable + set ip6-reachable-time 0 + set ip6-retrans-time 0 + set ip6-hop-limit 0 + set dhcp6-prefix-delegation disable + set dhcp6-information-request disable + set ip6-send-adv disable + set autoconf disable + set dhcp6-relay-service disable + end + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' + set dns-server-override enable + set dns-server-protocol cleartext + set wccp disable + next + edit "naf.scsd" + set vdom "scsd" + set vrf 0 + set distance 5 + set priority 1 + set dhcp-relay-interface-select-method auto + set dhcp-relay-service disable + set ip 0.0.0.0 0.0.0.0 + set arpforward enable + set broadcast-forward disable + set bfd global + set icmp-send-redirect enable + set icmp-accept-redirect enable + set reachable-time 30000 + set ips-sniffer-mode disable + set ident-accept disable + set ipmac disable + set status up + set netbios-forward disable + set wins-ip 0.0.0.0 + set type tunnel + set netflow-sampler disable + set sflow-sampler disable + set src-check disable + set sample-rate 2000 + set polling-interval 20 + set sample-direction both + set explicit-web-proxy disable + set explicit-ftp-proxy disable + set proxy-captive-portal disable + set tcp-mss 0 + set inbandwidth 0 + set outbandwidth 0 + set egress-shaping-profile '' + set ingress-shaping-profile '' + set spillover-threshold 0 + set ingress-spillover-threshold 0 + set weight 0 + set external disable + set trunk disable + set description '' + set alias '' + set security-mode none + set ike-saml-server '' + set estimated-upstream-bandwidth 0 + set estimated-downstream-bandwidth 0 + set measured-upstream-bandwidth 0 + set measured-downstream-bandwidth 0 + set bandwidth-measure-time 0 + set monitor-bandwidth disable + set role undefined + set snmp-index 57 + set preserve-session-route disable + set auto-auth-extension-device disable + set ap-discover enable + set switch-controller-igmp-snooping-proxy disable + set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end + config ipv6 + set nd-mode basic + set ip6-address ::/0 + set icmp6-send-redirect enable + set ra-send-mtu enable + set ip6-reachable-time 0 + set ip6-retrans-time 0 + set ip6-hop-limit 0 + set ip6-prefix-mode dhcp6 + set dhcp6-prefix-delegation disable + set dhcp6-information-request disable + end + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' + set dns-server-override enable + set dns-server-protocol cleartext + set wccp disable + next + edit "l2t.scsd" + set vdom "scsd" + set vrf 0 + set distance 5 + set priority 1 + set dhcp-relay-interface-select-method auto + set dhcp-relay-service disable + set ip 0.0.0.0 0.0.0.0 + unset allowaccess + set arpforward enable + set broadcast-forward disable + set bfd global set icmp-send-redirect enable set icmp-accept-redirect enable set reachable-time 30000 @@ -5368,9 +5619,11 @@ config system interface set weight 0 set external disable set trunk disable + set remote-ip 0.0.0.0 0.0.0.0 set description '' - set alias "SSL VPN interface" + set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5378,13 +5631,20 @@ config system interface set bandwidth-measure-time 0 set monitor-bandwidth disable set role undefined - set snmp-index 47 + set snmp-index 58 set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5401,7 +5661,93 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' + set dns-server-override enable + set dns-server-protocol cleartext + set wccp disable + next + edit "ssl.scsd" + set vdom "scsd" + set vrf 0 + set distance 5 + set priority 1 + set dhcp-relay-interface-select-method auto + set dhcp-relay-service disable + set ip 0.0.0.0 0.0.0.0 + unset allowaccess + set arpforward enable + set broadcast-forward disable + set bfd global + set reachable-time 30000 + set ips-sniffer-mode disable + set ident-accept disable + set ipmac disable + set status up + set netbios-forward disable + set wins-ip 0.0.0.0 + set type tunnel + set netflow-sampler disable + set sflow-sampler disable + set src-check enable + set sample-rate 2000 + set polling-interval 20 + set sample-direction both + set explicit-web-proxy disable + set explicit-ftp-proxy disable + set proxy-captive-portal disable + set tcp-mss 0 + set inbandwidth 0 + set outbandwidth 0 + set egress-shaping-profile '' + set ingress-shaping-profile '' + set spillover-threshold 0 + set ingress-spillover-threshold 0 + set weight 0 + set external disable + set trunk disable + set description '' + set alias "SSL VPN interface" + set security-mode none + set ike-saml-server '' + set estimated-upstream-bandwidth 0 + set estimated-downstream-bandwidth 0 + set measured-upstream-bandwidth 0 + set measured-downstream-bandwidth 0 + set bandwidth-measure-time 0 + set monitor-bandwidth disable + set role undefined + set snmp-index 45 + set preserve-session-route disable + set auto-auth-extension-device disable + set ap-discover enable + set switch-controller-igmp-snooping-proxy disable + set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end + config ipv6 + set ip6-mode static + set nd-mode basic + set ip6-address ::/0 + unset ip6-allowaccess + set ra-send-mtu enable + set ip6-reachable-time 0 + set ip6-retrans-time 0 + set ip6-hop-limit 0 + set dhcp6-prefix-delegation disable + set dhcp6-information-request disable + set ip6-send-adv disable + set autoconf disable + set dhcp6-relay-service disable + end + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext set wccp disable @@ -5449,7 +5795,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -5458,6 +5803,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -5474,11 +5820,19 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5498,7 +5852,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -5507,10 +5862,10 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed auto - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable next edit "npu0_vlink1" set vdom "root" @@ -5555,7 +5910,6 @@ config system interface set outbandwidth 0 set egress-shaping-profile '' set ingress-shaping-profile '' - set disconnect-threshold 0 set spillover-threshold 0 set ingress-spillover-threshold 0 set weight 0 @@ -5564,6 +5918,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission vdom @@ -5580,11 +5935,19 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5604,7 +5967,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -5613,10 +5977,10 @@ config system interface set dns-server-override enable set dns-server-protocol cleartext set speed auto - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable next edit "SRIC_BOCES" set vdom "scsd" @@ -5663,6 +6027,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5674,9 +6039,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5693,12 +6065,13 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override disable set wccp disable set interface "outside lag" + set mtu-override disable next edit "vpn-042e9903" set vdom "scsd" @@ -5745,6 +6118,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5756,9 +6130,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5775,13 +6156,14 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override enable - set mtu 1427 set wccp disable set interface "outside lag" + set mtu-override enable + set mtu 1427 next edit "SCHC" set vdom "scsd" @@ -5828,6 +6210,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5839,9 +6222,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5858,12 +6248,13 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override disable set wccp disable set interface "outside lag" + set mtu-override disable next edit "vpn-0fc50345" set vdom "scsd" @@ -5910,6 +6301,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -5921,9 +6313,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -5940,13 +6339,14 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override enable - set mtu 1427 set wccp disable set interface "outside lag" + set mtu-override enable + set mtu 1427 next edit "inside lag" set vdom "scsd" @@ -5998,6 +6398,7 @@ config system interface set description '' set alias "Inside" set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission enable @@ -6014,12 +6415,20 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6039,7 +6448,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -6047,18 +6457,20 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable set lacp-mode active - set lacp-ha-slave enable + set lacp-ha-secondary enable set system-id-type auto set lacp-speed slow set min-links 1 set min-links-down operational set algorithm L4 set link-up-delay 50 + set aggregate-type physical + set sw-algorithm default next edit "outside lag" set vdom "scsd" @@ -6110,6 +6522,7 @@ config system interface set description '' set alias "Outside" set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception enable set lldp-transmission enable @@ -6127,12 +6540,20 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6152,7 +6573,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -6160,18 +6582,20 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable set lacp-mode active - set lacp-ha-slave enable + set lacp-ha-secondary enable set system-id-type auto set lacp-speed slow set min-links 1 set min-links-down operational set algorithm L4 set link-up-delay 50 + set aggregate-type physical + set sw-algorithm default next edit "city_phones lag" set vdom "scsd" @@ -6223,6 +6647,7 @@ config system interface set description "City Phones" set alias "City_Phones" set security-mode none + set ike-saml-server '' set device-identification disable set lldp-reception vdom set lldp-transmission enable @@ -6239,12 +6664,20 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable + set ip-managed-by-fortiipam inherit-global set switch-controller-mgmt-vlan 4094 set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable set swc-first-create 0 + set eap-supplicant disable set np-qos-profile 0 + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6264,7 +6697,8 @@ config system interface set dhcp6-relay-service disable end set priority 1 - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dhcp-client-identifier '' set dhcp-renew-time 0 set idle-timeout 0 @@ -6272,18 +6706,20 @@ config system interface set padt-retry-timeout 1 set dns-server-override enable set dns-server-protocol cleartext - set mtu-override disable set wccp disable set drop-overlapped-fragment disable set drop-fragment disable + set mtu-override disable set lacp-mode active - set lacp-ha-slave enable + set lacp-ha-secondary enable set system-id-type auto set lacp-speed slow set min-links 1 set min-links-down operational set algorithm L4 set link-up-delay 50 + set aggregate-type physical + set sw-algorithm default next edit "vpn-0403e61" set vdom "scsd" @@ -6330,6 +6766,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -6341,9 +6778,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6360,13 +6804,14 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override enable - set mtu 1427 set wccp disable set interface "outside lag" + set mtu-override enable + set mtu 1427 next edit "Highstreet" set vdom "scsd" @@ -6413,6 +6858,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -6424,9 +6870,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6443,13 +6896,14 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override enable - set mtu 1427 set wccp disable set interface "outside lag" + set mtu-override enable + set mtu 1427 next edit "Highstreet_2" set vdom "scsd" @@ -6496,6 +6950,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -6507,9 +6962,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6526,13 +6988,14 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override enable - set mtu 1427 set wccp disable set interface "outside lag" + set mtu-override enable + set mtu 1427 next edit "DPS" set vdom "scsd" @@ -6579,6 +7042,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -6590,9 +7054,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6609,12 +7080,13 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override disable set wccp disable set interface "outside lag" + set mtu-override disable next edit "RAP" set vdom "scsd" @@ -6661,6 +7133,7 @@ config system interface set description '' set alias '' set security-mode none + set ike-saml-server '' set estimated-upstream-bandwidth 0 set estimated-downstream-bandwidth 0 set measured-upstream-bandwidth 0 @@ -6672,9 +7145,16 @@ config system interface set preserve-session-route disable set auto-auth-extension-device disable set ap-discover enable - set ip-managed-by-fortiipam disable set switch-controller-igmp-snooping-proxy disable set switch-controller-igmp-snooping-fast-leave disable + set eap-supplicant disable + config mirroring-filter + set filter-srcip 0.0.0.0 0.0.0.0 + set filter-dstip 0.0.0.0 0.0.0.0 + set filter-sport 0 + set filter-dport 0 + set filter-protocol 0 + end config ipv6 set ip6-mode static set nd-mode basic @@ -6691,12 +7171,13 @@ config system interface set autoconf disable set dhcp6-relay-service disable end - set dhcp-relay-request-all-server disable + set dhcp-relay-source-ip 0.0.0.0 + set dhcp-relay-circuit-id '' set dns-server-override enable set dns-server-protocol cleartext - set mtu-override disable set wccp disable set interface "outside lag" + set mtu-override disable next end config system physical-switch @@ -6709,6 +7190,7 @@ config system virtual-switch end config system password-policy set status disable + set login-lockout-upon-downgrade disable end config system password-policy-guest-admin set status disable @@ -6941,7 +7423,7 @@ config system admin set sms-server fortiguard set sms-phone '' set guest-auth disable - set password ENC SH2MDEFNFDa99Ek1hpleBgiK/Y4kqbUFUwJAsBe8xloCdaOTzZxl3FBk2fFPqo= + set password ENC PB2P0kuXlxq+fAxE7YFWNe4J4LgUEAAMb9LL3y8zzVZh4qGe+Ui6oEvH1L318PasK3lkwtie2s3Ct9jDEE3vNMNga0KZkySK8Ant4oRjuJDDFU= set allow-remove-admin-session enable next edit "jkafta72.admin" @@ -6980,7 +7462,7 @@ config system admin set sms-server fortiguard set sms-phone '' set guest-auth disable - set password ENC SH2+WrS1YeN2wN1qqkANtIzxrsLUfFr9LiJpDb6HCiJyT4X4CBY5YkYHLg5LrY= + set password ENC PB2/w6nufSySeFZ0NlH3RdiLizG70o8bT63PX+WQQu4o78tMYQHMWWHsbr10CMGWAnsI7LInym+HV0ULcFDeA+zCCT7cnMxVIMIV17sWLvUzCQ= set allow-remove-admin-session enable next edit "estein66.admin" @@ -7029,12 +7511,19 @@ config system sso-admin end config system sso-forticloud-admin edit "FortiGateCloud" + set accprofile '' set vdom "root" next edit "4fc9e93dd975@fortigatecloud.com" + set accprofile '' set vdom "root" next end +config system sso-fortigate-cloud-admin +end +config system npu-post + set npu-group-effective-scope 255 +end config system fsso-polling set status enable set listening-port 8000 @@ -7045,13 +7534,14 @@ config system ha set group-name "SCSD_Fortigate" set mode a-p set sync-packet-balance disable - set password ENC zVhFIlBOTPDwZcZr90rn7twe2W4XmBfchgAOKtkF7NosfYROHM0w4Yhv9SYJsEkS6WWDC+XOq92JXrnStDDAbC6vGNdSHegMgpH2fZB7OPicEpM76dmKdcwXCcJPb1FUGs9jxh7jVKXBAONRUI0+gfSUhv8HQLrOAoaYG1ufsayG8aT6PQnuA1LVf4lByrPhl3JOBA== + set password ENC nSTxUFgtvFuuixrcFYSmn7WiNGbZ6Pnhp3Ww5rMEUCe6OLcNHmHpVGhimGOf8tjrx1qH8Egn2HhRV16gMKqDzfLYFiHESAk9d5YgyL2ZFlzgdin8k/dDx0TLcIUtS7w1x26xuNGH+QWWbFpzQV7lzUflxrpVY01IWSDP9oxoGUt2xA41I6gqgA2GfH1/0aPLAf4V9FlmMjY3dkVA set hbdev "port1" 50 "port2" 50 unset session-sync-dev set route-ttl 10 set route-wait 0 set route-hold 10 set multicast-ttl 600 + set evpn-ttl 60 set sync-config enable set encryption disable set authentication disable @@ -7064,8 +7554,9 @@ config system ha set arps-interval 8 set session-pickup disable set link-failed-signal disable - set uninterruptible-upgrade enable + set upgrade-mode uninterruptible set uninterruptible-primary-wait 30 + set standalone-mgmt-vdom disable set ha-mgmt-status disable set ha-eth-type "8890" set hc-eth-type "8891" @@ -7075,13 +7566,15 @@ config system ha set priority 200 unset monitor unset pingserver-monitor-interface - unset vdom - set vcluster2 disable + set vcluster-status disable set ssd-failover disable set memory-compatible-mode disable set memory-based-failover disable set failover-hold-time 0 - set logical-sn disable + set override-wait-time 0 + set pingserver-failover-threshold 0 + set pingserver-secondary-force-reset enable + set pingserver-flip-timeout 60 end config system ha-monitor set monitor-vlan disable @@ -7128,32 +7621,27 @@ config system dns set alt-primary 0.0.0.0 set alt-secondary 0.0.0.0 set log disable + set fqdn-cache-ttl 0 + set fqdn-max-refresh 3600 + set fqdn-min-refresh 60 end config system ddns end config system sflow - set collector-ip 0.0.0.0 - set collector-port 6343 - set source-ip 0.0.0.0 - set interface-select-method auto end config system netflow - set collector-ip 0.0.0.0 - set collector-port 2055 - set source-ip 0.0.0.0 set active-flow-timeout 1800 set inactive-flow-timeout 15 set template-tx-timeout 1800 set template-tx-counter 20 - set interface-select-method auto end config system replacemsg-image edit "logo_fnet" - set image-type gif + set image-type png set image-base64 '' next edit "logo_fguard_wf" - set image-type gif + set image-type png set image-base64 '' next edit "logo_v3_fguard_app" @@ -7233,7 +7721,7 @@ config system replacemsg http "url-block" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -7272,7 +7760,7 @@ config system replacemsg http "url-block" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -7385,7 +7873,7 @@ config system replacemsg http "urlfilter-err" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -7424,7 +7912,7 @@ config system replacemsg http "urlfilter-err" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -7527,7 +8015,7 @@ config system replacemsg http "infcache-block" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -7566,7 +8054,7 @@ config system replacemsg http "infcache-block" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -7669,7 +8157,7 @@ config system replacemsg http "http-contenttypeblock" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -7708,7 +8196,7 @@ config system replacemsg http "http-contenttypeblock" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -7812,7 +8300,7 @@ config system replacemsg http "https-invalid-cert-block" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -7851,7 +8339,7 @@ config system replacemsg http "https-invalid-cert-block" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -7975,7 +8463,7 @@ config system replacemsg http "https-untrusted-cert-block" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -8014,7 +8502,7 @@ config system replacemsg http "https-untrusted-cert-block" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -8138,7 +8626,7 @@ config system replacemsg http "https-blocklisted-cert-block" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -8177,7 +8665,7 @@ config system replacemsg http "https-blocklisted-cert-block" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -8250,6 +8738,152 @@ config system replacemsg http "https-blocklisted-cert-block" set header http set format html end +config system replacemsg http "https-ech-block" + set buffer " + +
+ + + + +%%QUOTA_TABLE%%
+ + @@ -11925,7 +15386,7 @@ config system replacemsg auth "auth-portal-page" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -11964,7 +15425,7 @@ config system replacemsg auth "auth-portal-page" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -12065,7 +15526,7 @@ config system replacemsg auth "auth-password-page" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -12104,7 +15565,7 @@ config system replacemsg auth "auth-password-page" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -12150,6 +15611,15 @@ config system replacemsg auth "auth-password-page"Please set a new one.
+%%EXTRAINFO%%
@@ -12423,7 +15893,7 @@ config system replacemsg auth "auth-next-fortitoken-page" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -12462,7 +15932,7 @@ config system replacemsg auth "auth-next-fortitoken-page" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -12575,7 +16045,7 @@ config system replacemsg auth "auth-email-token-page" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -12614,7 +16084,7 @@ config system replacemsg auth "auth-email-token-page" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -12726,7 +16196,7 @@ config system replacemsg auth "auth-sms-token-page" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -12765,7 +16235,7 @@ config system replacemsg auth "auth-sms-token-page" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -12878,7 +16348,7 @@ config system replacemsg auth "auth-email-harvesting-page" } .message-container { height: 500px; - width: 600px; + width: 500px; padding: 0; margin: 10px; } @@ -12917,7 +16387,7 @@ config system replacemsg auth "auth-email-harvesting-page" max-width: 100%; display: inline-flex; align-items: baseline; - virtical-align: top; + vertical-align: top; box-sizing: border-box; margin: .3em; } @@ -12956,7 +16426,7 @@ config system replacemsg auth "auth-email-harvesting-page"