Special notices
Upgrade recommended
FortiClient (Linux) 7.4.6 has been updated to recognize newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers (see Resolved issues). We recommend upgrading your existing 7.4 deployments to 7.4.6 to take advantage of this change. See CSB-260303-1 for more information.
No IKEv1 support for IPsec VPN
FortiClient (Linux) 7.4.6 does not support IKEv1 for IPsec VPN. Please migrate to using IKEv2 instead.
No new version of VPN-only agent
FortiClient (Linux) 7.4.4 to 7.4.6 do not include a new version of the free VPN-only agent as no feature updates were made to the free VPN-only agent between 7.4.3 and 7.4.6. Users can continue to use the FortiClient (Linux) 7.4.3 free VPN-only agent.
Using the same default MTU size for VPN interfaces across all platforms
Starting from 7.4.4, FortiClient (Linux) uses the same default MTU size for SSL and IPsec VPN interfaces as Windows and macOS, which improves connection efficiency. You can modify the MTU size using the <mtu_size> XML option. See the XML Reference Guide.
No support for concurrent third-party tunneling or proxy clients
Using third-party tunneling or proxy clients (including VPN, DNS, HTTP(s), SOCKS, ZTNA or PAC files) in parallel or nested combination with FortiClient's VPN, ZTNA or Web Filter is not recommended nor supported.
ZTNA certificates
Zero trust network access (ZTNA) certificate provisioning requires Trusted Platform Module (TPM) 2.0 on the endpoint with one of the following:
- Maximum of TLS 1.2 in FortiOS
- Maximum of TLS 1.3 in FortiOS if the TPM 2.0 implementation in the endpoint supports RSA PSS signatures
For ZTNA tags for checking certificates, FortiClient (Linux) does not check user certificates and only checks root certificate authority certificates installed on the system. These routes are:
|
Operating system |
Route |
|---|---|
| Ubuntu |
/etc/ssl/certs/ca-certificates.crt |
|
/etc/pki/tls/certs/ca-bundle.crt |
FortiGuard Web Filtering Category v10 Update
Fortinet has updated its web filtering categories to v10, which includes two new URL categories for AI chat and cryptocurrency websites. To use the new categories, customers must upgrade their Fortinet products to one of the versions below:
- FortiManager - Fixed in 6.0.12, 6.2.9, 6.4.7, 7.0.2, 7.2.0, 7.4.0.
- FortiOS - Fixed in 7.2.8 and 7.4.1.
- FortiClient - Fixed in Windows 7.2.3, macOS 7.2.3, Linux 7.2.3.
- FortiClient EMS - Fixed in 7.2.1.
- FortiMail - Fixed in 7.0.7, 7.2.5, 7.4.1.
- FortiProxy - Fixed in 7.4.1.
Please read the following CSB for more information to caveats on the usage in FortiManager and FortiOS: https://support.fortinet.com/Information/Bulletin.aspx