What's new
FortiADC 8.0.3 introduces enhancements and new features across various modules including Web Application Firewall, Server Load Balance, Global Load Balance, and more.
More detailed information is available in the New Features Guide.
FortiAI
FortiAI Assistant Log Analysis Enhancements 8.0.3
You can now use the FortiAI Assistant to perform deep-dive analysis on individual log entries for more granular operational and security insights. This update expands the assistant's capabilities to evaluate specific events within your traffic and security logs, transforming raw data into clear, actionable intelligence for faster troubleshooting and threat response.
Application Access Manager
Agentless Application Gateway New Features 8.0.3
Agentless Application Gateway (AAG) has been significantly enhanced to provide more flexible application delivery and granular access control:
-
SLB Virtual Server Integration: AAG now leverages the full power of FortiADC by integrating the new WebAPP-Internal-Advanced bookmark type with SLB HTTP/S Virtual Servers. This enables enterprise-grade features such as WAF, advanced Load Balancing, Health Checks, and Scripting for bookmarked applications.
-
Shareable Bookmarks: Bookmarks are now independent, shareable objects decoupled from App Groups. This allows for simplified object reuse and more efficient, centralized management across the platform.
-
User Group Matching: The Authentication policy now supports User Group Match conditions. This allows administrators to define more granular access permissions based on specific user group memberships.
-
Unauthenticated URL Redirection: For unauthenticated sessions, AAG now supports URL auto-redirection. This ensures a smoother user experience by automatically guiding users to the appropriate destination or login portal.
Web Application Firewall
WAF Signature Support for HTTP/3 and HTTP/2 8.0.3
FortiADC 8.0.3 now supports Web Application Firewall (WAF) Web Attack Signature scanning for HTTP/3 and HTTP/2 Virtual Servers. This update allows you to apply robust security policies to modern high-performance traffic, ensuring your services are protected against known web-based vulnerabilities.
RESTful API Input Security Check 8.0.3
You can now benefit from automated, deep-level security inspections for the FortiADC RESTful API to detect and prevent sophisticated exploits such as command injection and path traversal. FortiADC 8.0.3 introduces a specialized, independent signature database that performs real-time validation of API requests before business logic is executed. This feature ensures robust protection for the management interface by inspecting multiple input locations including headers, request bodies, query arguments, and URL paths without requiring any manual configuration.
Security Fabric
External ICAP Server Support 8.0.3
FortiADC 8.0.3 introduces support for external Internet Content Adaptation Protocol (ICAP) servers through a new Fabric Connector to provide an additional layer of file inspection. This feature allows FortiADC to act as an ICAP client, sending files to a third-party ICAP server for deep scanning after the local AntiVirus (AV) engine has performed its initial check. To use this feature, you enable ICAP scanning within an AntiVirus profile and associate it with a Virtual Server. If the ICAP server detects a threat, FortiADC automatically blocks the request and logs the event.
FortiSandbox Cloud Connectivity Enhancements 8.0.3
FortiADC 8.0.3 simplifies the integration with FortiSandbox by introducing an automated connection process and expanded regional support. These updates eliminate the need for manual account configuration, allowing the system to establish a secure link and retrieve available service regions automatically.
Server Load Balance
TLS 1.3 Hardening and Post-Quantum Cryptography Support 8.0.3
FortiADC 8.0.3 introduces advanced hardening for TLS 1.3 handshakes and adds support for Post-Quantum Cryptography (PQC) to protect data against future quantum computing threats. These enhancements provide granular control over cryptographic parameters through new security level settings and customizable signature and group selections.
FQDN Real Server DNS Cache and Refresh Configuration 8.0.3
FortiADC 8.0.3 introduces enhanced control over Domain Name System (DNS) resolution for Real Servers configured with Fully Qualified Domain Names (FQDN). This update allows you to manually configure the Time to Live (TTL) for cached DNS responses and define a minimum refresh interval, ensuring more predictable traffic steering when backend IP addresses change. By customizing these settings, you can prevent premature cache expiration or reduce the frequency of DNS queries to your nameservers.
Load Balance Pool Support in Stream Scripts 8.0.3
You can now use Stream Scripting to load balance an entire real server pool, instead of only individual real servers, by leveraging the new LB:routing() script command and Layer 7 content routing capabilities for non-HTTP protocols. This enhancement allows scripts to inspect the application-layer payload and programmatically select a destination real server pool based on real-time traffic analysis.
Log & Report
Security Log GUI Redesign and Enhancements 8.0.3
Following the updates to the Traffic and Script logs, FortiADC 8.0.3 brings a complete redesign to the Security Logs. This update aligns the security interface with the modern, high-performance standard used across the platform while adding specialized investigation tools such as an Analyze with AI button, a Log Details side panel, and one-click Policy Exceptions.
Script Log Enhancement 8.0.3
Following the redesign of the Traffic Log interface in version 8.0.1, FortiADC 8.0.3 extends these modern GUI enhancements to the Script Logs. This update ensures a consistent user experience across different log types, aligning the Script Log interface with the streamlined, high-performance layout used for traffic analysis.
GUI
Enhanced User Interface and Workflow Reorganization 8.0.3
You can now navigate a more intuitive and streamlined management interface designed to enhance workflow efficiency and configuration consistency. FortiADC 8.0.3 introduces a large-scale reorganization of the management interface, refining navigation across the System, Server Load Balance, Global Load Balance, and Web Application Firewall menus. These updates simplify complex configurations, better align with policy creation flows, and centralize security-first settings for more efficient daily management.
Platform
OpenSSL Upgrade to 3.5 8.0.3
FortiADC 8.0.3 upgrades the OpenSSL library to version 3.5 to align with the latest security compliance requirements and upstream fixes.