Technical Tip: Security Level naming changed from 0/1/2 to low/low/high from v7.0.16/v7.2.11/v7.4.6/v7.6.1 onward
| Description | This article describes a behavior change since v7.0.16/v7.2.11/v7.4.6/v7.6.1, where now the Security Level information uses the low/high attributes instead of 0/1/2. |
| Scope | FortiGate. |
| Solution | Since firmware v7.0.16/v7.2.11/v7.4.6/v7.6.1, the Security Level naming has changed from the common 0, 1, and 2 levels, low and high. In v7.0.15 and other versions, it would be seen the following information by using the following command:
get system status
When set as Security Level 0 in the boot menu:
FortiGate-60F # get sys status
When set as Security Level 1 in the boot menu:
FortiGate-60F # get sys status
When set as Security Level 2 in the boot menu:
FortiGate-60F # get sys status
In v7.0.16, the naming of the level has changed as follows:
When set as Security Level 0 in the boot menu:
FortiGate-60F # get sys status
When set as Security Level 1 in the boot menu:
FortiGate-60F # get sys status
When set as Security Level 2 in the boot menu:
FortiGate-60F # get system status
If the device is running firmware versions lower than v7.0.12/v7.2.5/v7.4.0, but it supports a BIOS version with the integrity checking enhancement, it is possible to check the current security level by interrupting the boot sequence as below:
[C]: Configure TFTP parameters.
[S]: Set serial port baudrate (will take effect on next boot).
Please select security level: [1] <----- Current value is set to level 1.
For more information about the change, see BIOS security Low and High level classification. |
