DOCUMENT LIBRARY
7.6.0
DOCUMENT LIBRARY
Products
Best Practices
Hardware Guides
Products A-Z
Summary
By Solution
By 4D Pillars
By Cloud
All Products
Secure Networking
Unified SASE
Security Operations
Secure SD-WAN
Secure Access Service Edge (SASE)
ZTNA
LAN Edge
Identity and Access Management
Next Generation Firewall
Web Application Firewall
Public Cloud
Private Cloud
FortiCloud
Secure Networking
Hybrid Mesh Firewall
FortiGate/FortiOS
FortiGate-5000
|
6000
|
7000
NOC Management
FortiManager
|
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP/FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
|
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
More >>
Security Operations
Security Operations Automation
FortiAnalyzer
|
FortiAnalyzer Cloud
FortiSIEM
|
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiPAM
Early Detection & Prevention
FortiSandbox
|
FortiSandbox Cloud
FortiNDR
|
FortiNDR Cloud
FortiDeceptor
FortiRecon
More >>
Secure Networking
Hybrid Mesh Firewall
FortiGate/FortiOS
FortiGate-5000
|
6000
|
7000
NOC Management
FortiManager
|
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP/FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
|
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
|
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
|
FortiAnalyzer Cloud
FortiSIEM
|
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
|
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiToken
|
FortiIdentity Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
|
FortiSandbox Cloud
FortiNDR
|
FortiNDR Cloud
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
|
6000
|
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
|
FortiManager Cloud
FortiAnalyzer
|
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP/FortiWiFi
FortiExtender
|
FortiExtender Cloud
Application Delivery
FortiADC
|
FortiGSLB
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
|
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/FortiOS
FortiAP/FortiWiFi
FortiExtender
|
FortiExtender Cloud
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiIdentity Cloud
FortiToken
Application Gateway
FortiGate/FortiOS
FortiProxy
FortiADC
|
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
|
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
|
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiIdentity Cloud
FortiToken
Wireless
FortiAP/FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiIdentity Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
FortiGate/FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
|
FortiManager Cloud
FortiAnalyzer
|
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Web Application / API Protection
FortiWeb
FortiAppSec Cloud
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiClient Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiIdentity Cloud
FortiAuthenticator Cloud
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Managed Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Platform as a service (PAAS)
FortiSASE
FortiAnalyzer Cloud
FortiManager Cloud
FortiClient Cloud
FortiSandbox Cloud
FortiMail Cloud
FortiSOAR Cloud
Other SAAS Services
Overlay-as-a-Service
FortiRecon
FortiConverter
ForiIPAM
FortiFlex
FortiCare Elite
FortiTIP Cloud
4D Resources
Solution Hubs
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Web Application Firewall
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
FortiAIOps
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP/FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiBranchSASE
FortiCache
FortiCamera
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiFone
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiNDR Cloud
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
AV Engine
AWS Firewall Rules
AscenLink
CTAP Cloud
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Kubernetes Controller
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIGate
FortiAIOps
FortiAP / FortiWiFi
FortiAP-U Series
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAppSec Cloud
FortiAuthenticator
FortiAuthenticator Cloud
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCASB
FortiCNAPP
FortiCNP
FortiCWP
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiData
FortiData Private Cloud
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDevice
FortiEDR/XDR
FortiEdge Cloud
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate CNF
FortiGate Cloud
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGuest
FortiHypervisor
FortiIPAM
FortiIdentity Cloud
FortiInsight
FortiInsight Cloud
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail Appliance and VM
FortiMail Cloud - Hosted
FortiMail Workspace Security
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRPS
FortiRecon
FortiRecorder
FortiSASE
FortiSASE-Sovereign
FortiSAT
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSRA Private Cloud
FortiSRA Public Cloud
FortiSandbox
FortiSandbox PaaS
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSwitch
FortiSwitch Manager
FortiSwitch-AX Chassis
FortiSwitchNMS
FortiTIP Cloud
FortiTap
FortiTelemetry
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWLM
FortiWeb
FortiWeb Manager
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
SOCaaS
Security Awareness and Training
Wireless Controller
Ordering Guides
AV Engine
AWS Firewall Rules
CTAP Cloud
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Kubernetes Controller
FortiADC Manager
FortiAIOps
FortiAP / FortiWiFi
FortiAP-U Series
FortiAnalyzer
FortiAnalyzer BigData
FortiAppSec Cloud
FortiAuthenticator
FortiBranchSASE
FortiCASB
FortiCNAPP
FortiCWP
FortiCamera
FortiCare Elite
FortiCarrier
FortiCentral
FortiClient
FortiCloud Services
FortiController
FortiConverter Service
FortiConverter Tool
FortiDAST
FortiDDoS-F
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiData
FortiDeceptor
FortiDeceptor DaaS
FortiDevSec
FortiDevice
FortiEDR/XDR
FortiEdge Cloud
FortiEndpoint
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate CNF
FortiGate Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGuest
FortiHypervisor
FortiIPAM
FortiIdentity Cloud
FortiInsight
FortiIsolator
FortiMail Appliance and VM
FortiMail Workspace Security
FortiManager
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiPAM
FortiPhish
FortiPolicy
FortiPortal
FortiPresence
FortiProxy
FortiRecon
FortiRecorder
FortiSASE
FortiSASE-Sovereign
FortiSIEM
FortiSOAR
FortiSRA
FortiSandbox
FortiSwitch
FortiSwitch Manager
FortiSwitch-AX Chassis
FortiSwitchNMS
FortiTIP Cloud
FortiTelemetry
FortiTester
FortiToken
FortiVoice
FortiWeb
FortiWeb Manager
FortiZTP
IPS Engine
Managed FortiGate Service
SOCaaS
Security Awareness and Training
Wireless Controller
Ordering Guides
All Products
AV Engine
AWS Firewall Rules
AscenLink
CTAP Cloud
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Kubernetes Controller
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIGate
FortiAIOps
FortiAP / FortiWiFi
FortiAP-U Series
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAppSec Cloud
FortiAuthenticator
FortiAuthenticator Cloud
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCASB
FortiCNAPP
FortiCNP
FortiCWP
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiData
FortiData Private Cloud
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDevice
FortiEDR/XDR
FortiEdge Cloud
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate CNF
FortiGate Cloud
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGuest
FortiHypervisor
FortiIPAM
FortiIdentity Cloud
FortiInsight
FortiInsight Cloud
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail Appliance and VM
FortiMail Cloud - Hosted
FortiMail Workspace Security
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRPS
FortiRecon
FortiRecorder
FortiSASE
FortiSASE-Sovereign
FortiSAT
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSRA Private Cloud
FortiSRA Public Cloud
FortiSandbox
FortiSandbox PaaS
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSwitch
FortiSwitch Manager
FortiSwitch-AX Chassis
FortiSwitchNMS
FortiTIP Cloud
FortiTap
FortiTelemetry
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWLM
FortiWeb
FortiWeb Manager
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
SOCaaS
Security Awareness and Training
Wireless Controller
Ordering Guides
FortiGate / FortiOS
FortiManager
FortiAnalyzer
New Features
Overview
GUI
General usability enhancements
GUI support for local-in policies
GUI support for internet service groups
GUI displays logic between firewall policy objects
GUI support to create policies in FortiView Sources and traffic logs
GUI improvements to device upgrade
GUI support for enhanced logging for threat feeds
Expanded support for Advanced Threat Protection Statistics widget
GUI improvements to the IPsec VPN Wizard
GUI improvements to Security Rating
GUI support for web proxy forward server over IPv6
GUI support for security posture tags in dial-up IPsec VPN tunnels 7.6.1
CLI diagnostic shortcuts in the GUI 7.6.1
Asset Details pane 7.6.1
GUI access for global search 7.6.3
GUI warnings for IKE-TCP port conflicts 7.6.3
GUI improvements of PIM support for VRFs 7.6.3
Support filtering on policy list statistics 7.6.4
Enhanced security rating tooltip controls 7.6.5
Enforce FortiCare registration after new GUI login 7.6.5
Enforce FortiCare registration with read-only CLI 7.6.5
Enhanced setup wizard for networking connectivity support 7.6.5
Network
General
Configure the VRRP hello timer in milliseconds
FortiGate as a recursive DNS resolver
BGP network prefixes utilize firewall addresses and groups
Support UDP-Lite traffic
Custom LSA refresh rates and fast link-down detection on VLAN interfaces for OSPF
Filter NetFlow sampling
SOCKS proxy supports UTM scanning, authentication, and forward server
Implement the interface name as the source IP address in RADIUS, LDAP, and DNS configurations
Include groups in PIM join/prune messages
Automatic LTE connection establishment
Netflow sampling
Support source-IP interface for system DNS database
Extended VRF ID range for enhanced network scalability 7.6.1
Enhanced PIM support for VRFs 7.6.1
Including denied multicast sessions in the session table 7.6.1
Support specific VRF ID for local-out traffic 7.6.1
Support source IP interface for system DNS 7.6.1
Improvements to IPsec monitoring 7.6.1
Connectivity Fault Management (CFM) now available for FG-80F-POE and FG-20xF models 7.6.3
Application and network performance monitoring with FortiTelemetry 7.6.3
Fortinet Support Tool for capturing incidents
Support configuring users and groups in policy routes 7.6.3
Support additional NIC interface diagnostics 7.6.4
Auto speed negotiation for 10G Base-T on FortiGate 100xF devices 7.6.4
Add support for 802.1X on a virtual switch when added to a software switch 7.6.5
IPv6
DHCPv6 enhancements
Recursive resolution of BGP routes using IPv6 prefix with on-link flag from route aggregation
Enhancing SIP reliability in 464XLAT environments 7.6.1
Explicit and Transparent Proxy
Specifying outgoing interface and VRF for a web proxy forward server or isolator server 7.6.1
Isolator servers in proxy policies 7.6.1
GUI support of isolator servers for proxy policies 7.6.3
SD-WAN
Overlays and underlays
ADVPN 2.0 enhancements
ADVPN 2.0 overlay placeholders for shortcuts between spokes 7.6.1
SD-WAN Setup wizard for guided configuration 7.6.1
Fabric Overlay Orchestrator Topology dashboard widget for hub FortiGates 7.6.3
Hub-to-spoke traffic shaping by IKE bandwidth negotiation 7.6.4
ADVPN 2.0 enhancement: trigger just one shortcut for each distinct underlay path 7.6.4
ADVPN spoke-to-spoke traffic shaping by IKE bandwidth negotiation 7.6.4
Routing
Allow SD-WAN hubs to suppress BGP routes when all links to a spoke are down 7.6.5
Performance SLA
Embed SLA priorities in ICMP probes
Embed SLA status in ICMP probes
Map SD-WAN member priorities to BGP MED attribute when spoke advertises routes using iBGP to hub 7.6.1
FortiGuard SLA database for SD-WAN performance SLA 7.6.1
Passive monitoring of TCP metrics 7.6.1
Application performance monitoring 7.6.3
SD-WAN speed test enhancements 1 7.6.5
SD-WAN speed test enhancements 2 7.6.5
IPv6 probe-response through interface configuration 7.6.5
Service rules
Allow SD-WAN rules to steer IPv6 multicast traffic
Specify SD-WAN zones in some policies 7.6.1
Hybrid strategy for service rules 7.6.4
General
Create default configuration of SD-WAN on FortiGate models with two WAN ports 7.6.5
Policy and objects
NGFW
Seven-day policy hit counter
Policies
NPTv6 protocol for IPv6 address translation
MAP-E supports multiple VNE interfaces in the same VDOM
Full cone NAT for fixed port range IP pools
Custom port ranges for PBA and FPR IP pools
HTTP transaction logging
Support for NAT64 in FPR IP pools
Support for randomized port selection in IP pool mechanisms 7.6.1
Enhanced security with default local-in policy 7.6.1
DHCP-PD support for MAP-E 7.6.1
Objects
RSSO dynamic address subtype 7.6.1
New ISDB record for SOCaaS 7.6.1
Apply FQDN address groups within the ISDB 7.6.1
GUI support for FQDN address groups within the ISDB 7.6.4
Dynamic telemetry firewall address type 7.6.4
IPv6 wildcard addresses 7.6.4
NGFW policy support for FQDN address groups in the ISDB 7.6.5
Zero Trust Network Access
Security posture and EMS connector
Share ZTNA information through the EMS connector
Extend ZTNA error codes and replacement messages 7.6.4
Share used security posture tags with EMS 7.6.4
Application gateway
ZTNA agentless web-based application access 7.6.1
General
ZTNA support for UDP traffic
ZTNA support for SaaS application access control in the GUI
Include EMS tag information in traffic logs
ZTNA single sign-on with Entra ID 7.6.3
ZTNA tags on 2 GB entry-level platforms in IP/MAC-based access control 7.6.3
Security profiles
Antivirus
Sanitize Microsoft OneNote files through content disarm and reconstruction
Stream-based antivirus scanning for HTML and Javascript files
Zero-day malware stream scanning 7.6.3
Support FortiSandbox inline scanning in flow mode 7.6.4
Web filter
Introduce URL risk-scores in determining policy action 7.6.1
IPS
AI and ML-based IPS detection 7.6.3
Data loss prevention
FortiGuard managed DLP dictionaries
Integration with FortiData 7.6.4
Use MPIP labels directly with DLP profiles 7.6.4
Application control
Introducing domain fronting protection
Virtual patching
Streamline IoT/OT device detection 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
Others
Support the Zstandard compression algorithm for web content
DNS filtering in proxy policies
DNS translation support for Service records over the DNS Filter profile
Control TLS connections that utilize Encrypted Client Hello
Selective forwarding to ICAP server 7.6.1
Control TLS connections that utilize Encrypted Client Hello in flow mode 7.6.3
Inline CASB security profile to support control factors in exchanged JSON data for custom SaaS applications 7.6.3
Hybrid post-quantum cryptography in SSL deep inspection in flow mode 7.6.5
Support proxy-based inspection for email protocols on models with 2 GB RAM 7.6.5
Protecting LLM and GenAI
Application control support for generative AI 7.6.4
VPN
IPsec and SSL VPN or Agentless VPN
Automatic selection of IPsec tunneling protocol
Security posture tag match enforced before dial-up IPsec VPN connection
Enhancing security with Post-Quantum Cryptography for IPsec key exchange 7.6.1
Migration from SSL VPN tunnel mode to IPsec VPN 7.6.3
Agentless VPN 7.6.3
Configure FortiClient SIA for IPsec VPN tunnels 7.6.3
Support Quantum Key Distribution and Post-Quantum Cryptography 7.6.3
Post-Quantum Cryptography for Agentless VPN 7.6.5
Allow UDP port 443 for dialup IPsec VPN 7.6.5
User and authentication
Authentication
Customizable password reuse thresholds
Trigger RADIUS authentication with DNS and ICMP queries
Authentication sessions preserved after a reboot
SCIM server support
GUI support for SCIM clients 7.6.1
Bearer token authentication for SCIM 7.6.1
Support SAML authentication in a proxy policy using SCIM 7.6.4
Support SAML users when configuring local users 7.6.4
Configure FTM push with dynamic IP handling in the GUI 7.6.4
Per-Session SAML authentication logging and logout support for ZTNA and explicit proxy users 7.6.5
LAN Edge
Wireless
Support the 802.11mc protocol in FortiAP
Support OpenRoaming Standards on FortiAP
Support segregating WLAN traffic on FortiAPs operating in WAN-LAN mode
Support isolating mDNS traffic on the Bonjour profile
Support RADIUS NAS-ID on FortiAPs in standalone mode
Improve packet detection on the FortiAP sniffer
Support RADSEC on WPA2/WPA3-Enterprise SSID
Add GUI support for configuring wireless data rates and sticky client thresholds
Support self-registration of MPSKs through FortiGuest
Support IKEv2 for FortiAP IPsec data channel management
Support WPA3-SAE and WPA3-SAE Transition security modes in MPSK profiles
Add Advanced WIDS Options 7.6.1
Support RADSEC on Local Bridge mode captive portals 7.6.1
Add a RADIUS Called Station ID setting 7.6.1
Support remote TACACS access to FortiAP 7.6.1
Support RADIUS Accounting messages over FortiGuest MPSK Authentication 7.6.1
Add profile support for Zero-Wait DFS on select FortiAP models 7.6.4
Support Zero-Touch Provisioning for Mesh Leaf FortiAPs 7.6.4
Support manual captive portal trigger for bridge mode SSIDs 7.6.4
Support FortiAP management through IPv6 7.6.5
Enhance DARRP with FortiAIOps 7.6.5
Support Wi-Fi 7 MLO on FortiAP K-series models 7.6.5
Enhance GUI support for configuring mesh leaf FortiAPs 7.6.5
Support CA requests through EST and SCEP servers 7.6.5
Support Filter-ID for RADIUS authentication in WPA2-Enterprise 7.6.5
Improve security during FortiWiFi setup 7.6.5
New default configurations on FortiWiFi platforms 7.6.5
Switch controller
Change the priority of MAB and EAP 802.1X authentication
Send SNMP traps for MAC address changes
Support QinQ with the switch controller 7.6.1
Enhance network performance with VLAN pruning 7.6.1
Provide an enhanced GUI for NAC policies 7.6.3
Support IPv6 addresses for managed FortiSwitch units 7.6.3
Prevent automatically created VLANs 7.6.3
Add event logging for IPv4 source guard 7.6.4
Layer-3 switch configuration 7.6.4
Support maximum burst size for storm control 7.6.4
Increase length of managed FortiSwitch names 7.6.4
Integrate FortiSwitch NAC and 802.1X authentication 7.6.4
FortiExtender
Support fast failover for FortiExtender
Support VLAN over FortiExtender LAN-extension mode 7.6.1
Support split tunneling in LAN extension mode 7.6.1
Support multiple APNs in WAN extension mode 7.6.1
Support FortiCare registration for FortiExtender 7.6.1
Add GUI support for split tunneling in LAN extension mode 7.6.3
Add GUI support for multiple APNs in WAN extension mode 7.6.3
Add GUI support for FortiCare registration for FortiExtender 7.6.3
System
General
Restrict local administrator logins through the console
Configure TCP NPU session delay globally
Object usage included in the print tablesize command output
Sequential firmware upgrades for FortiGate Fabric devices
Simplified device registration for Security Fabric devices 7.6.1
Firmware upgrade report 7.6.1
Optimizations for physical FortiGate devices with 2 GB RAM 7.6.3
Automatic firmware upgrades for FortiGate appliances with invalid support contracts or that have reached EOES 7.6.4
Enhance administrative authentication and session monitoring 7.6.4
Enhanced firmware upgrade management for extension devices 7.6.4
FortiSASE-Sovereign licensing and management for FortiGate 91G and 901G 7.6.5
Memory optimizations for start-up configs, NPs, and NTurbo 7.6.5
FortiGuard
Streamline timezone updates with a downloadable database
Streamlined subscription and FortiGuard settings management 7.6.1
FortiGate StateRamp support 7.6.1
AMQP-powered subscription notifications for FortiGuard 7.6.3
High availability
Manual and automatic HA virtual MAC address assignment
Backup heartbeat interface mitigates split-brain scenarios
RSSO authenticated user logon information synchronized between FGSP peers
FGSP support for failover with asymmetric traffic and UTM
Monitor routing prefix for FGSP session failover 7.6.1
Single FortiGuard license for FortiGate A-P HA cluster 7.6.1
Improve manual failover of FortiGates deployed in an A-P architecture with VWP and using wildcard VLAN 7.6.4
Certificates
ACME External Account Binding support 7.6.3
Security
Encrypt configuration files in the eCryptfs file system
Closed network VM license security enhancement
OpenSSL FIPS provider installed globally at startup
Enhance real-time file system integrity checking
Use per-FortiGate generated random password for private-data-encryption 7.6.1
Enhanced administrator password security 7.6.1
BIOS security Low and High level classification 7.6.1
Automatic firmware upgrade control 7.6.1
Enhanced HTTPS management security with post-quantum TLS algorithms 7.6.5
SNMP
Ethernet Statistics Group
Non-management VDOMs perform queries using SNMP v3
SNMP support for BIOS security level
Security Fabric
Fabric settings and connectors
Apply threat feed connectors as source addresses in central SNAT
Automatic serial number retrieval from FortiManager
Support multi-tenant FortiClient Cloud fabric connectors in the GUI 7.6.1
Generic connector for importing addresses 7.6.1
Support mTLS client certification for external feed connections 7.6.1
GUI support for mTLS of external feed connections 7.6.3
Enhancing FortiSandbox TLS security with CA and CN controls 7.6.3
External SDN connectors
Multus CNI for Kubernetes connectors 7.6.4
Import IPv6 addresses from an APIC controller 7.6.4
Security ratings
Enhanced security rating customization 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
General
Enhanced security visibility for IoT/OT vulnerabilities 7.6.1
Log and report
Logging
Logging MAC address flapping events
Non-management VDOMs send logs to both global and vdom-override syslog servers
Logging message IDs
Incorporating endpoint device data in the web filter UTM logs
Set the source interface for syslog and NetFlow settings
Logging detection of duplicate IPv4 addresses
Logging local traffic per local-in policy
Logs generated when starting and stopping packet capture and TCP dump operations
Include zone information fields in logs 7.6.4
Cloud
Public and private cloud
Azure SDN connector relay through FortiManager support
IBM Cloud virtual network interface support
GCP SDN connector relay through FortiManager support
Support the AWS r8g instance family
Support the AWS c8g instance family
KVM Red Hat Enterprise Linux 9.4 support
Azure SDN connector moves private IP address on trusted NIC during A-P HA failover 7.6.1
Support the OCI E5.Flex instance type 7.6.1
Azure SDN connector GraphQL bulk query support 7.6.1
AWS NitroTPM support 7.6.1
AWS SDN connector IPv6 address object support 7.6.1
GCP C4 Intel instance support 7.6.1
FortiGate-VM GDC V support 7.6.1
OCI SDN connector IPv6 address object support 7.6.1
GCP SDN connector IPv6 address object support 7.6.1
Support for Azure upcoming MANA NIC 7.6.1
Azure SDN connector IPv6 address object support 7.6.1
FGT_VM64_KVM IPsec performance improvement through virtio and RPS 7.6.1
FGT_VM64_KVM IPsec performance through DPDK improvement 7.6.1
FortiGate-VM config system affinity-packet-redistribution optimization 7.6.1
OCI support for on-premise solutions 7.6.1
AliCloud GWLB support 7.6.1
AliCloud instance type support 7.6.3
AWS c8gn instance type support 7.6.4
Support for user managed scaling 7.6.5
Operational Technology
System
CLI to configure FGR-70F/FGR-70F-3G4G GPIO/DIO module alarm functionality 7.6.1
SNMP traps and automation-stitch notifications for DIO module alarm functionality 7.6.1
Support Ethernet layer protocols in the IPS engine 7.6.3
Index
7.6.0
7.6.1
7.6.3
7.6.4
7.6.5
Change Log
Home
FortiGate / FortiOS 7.6.0
New Features
7.6.0
7.6.0
7.4.0
7.2.0
7.0.0
6.4.0
6.2.0
VPN
VPN
This section includes information about VPN related new features:
IPsec and SSL VPN or Agentless VPN
Previous
Next
VPN
VPN
This section includes information about VPN related new features:
IPsec and SSL VPN or Agentless VPN
Previous
Next
Home
Products
Summary
Secure Networking
Hybrid Mesh Firewall
FortiGate/FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
NOC Management
FortiManager
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP/FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Hybrid Mesh Firewall
FortiGate/FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
NOC Management
FortiManager
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP/FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
More >>
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiPAM
Early Detection & Prevention
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiRecon
More >>
Security Operations Automation
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiToken
FortiIdentity Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
By Solution
Secure Networking
Hybrid Mesh Firewall
FortiGate/FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
NOC Management
FortiManager
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP/FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiToken
FortiIdentity Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
By 4D Pillars
Secure SD-WAN
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP/FortiWiFi
FortiExtender
FortiExtender Cloud
Application Delivery
FortiADC
FortiGSLB
Secure Access Service Edge(SASE)
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/FortiOS
FortiAP/FortiWiFi
FortiExtender
FortiExtender Cloud
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiIdentity Cloud
FortiToken
ZTNA
Application Gateway
FortiGate/FortiOS
FortiProxy
FortiADC
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiIdentity Cloud
FortiToken
LAN Edge
Wireless
FortiAP/FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity and Access Management
Identity
FortiAuthenticator
FortiAuthenticator Cloud
FortiIdentity Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
Next Generation Firewall
FortiGate/FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Web Application Firewall
Web Application / API Protection
FortiWeb
FortiAppSec Cloud
By Cloud
Public Cloud
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
Private Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
FortiCloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiClient Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiIdentity Cloud
FortiAuthenticator Cloud
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Best Practices
4D Resources
Define, Design, Deploy, Demo
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Web Application Firewall
Solution Hubs
Curated Links by Solution
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
Hardware Guides
FortiAIOps
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP/FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiBranchSASE
FortiCache
FortiCamera
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiFone
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiNDR Cloud
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Products A-Z
AV Engine
AWS Firewall Rules
AscenLink
CTAP Cloud
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Kubernetes Controller
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIGate
FortiAIOps
FortiAP / FortiWiFi
FortiAP-U Series
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAppSec Cloud
FortiAuthenticator
FortiAuthenticator Cloud
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCASB
FortiCNAPP
FortiCNP
FortiCWP
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiData
FortiData Private Cloud
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDevice
FortiEDR/XDR
FortiEdge Cloud
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate CNF
FortiGate Cloud
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGuest
FortiHypervisor
FortiIPAM
FortiIdentity Cloud
FortiInsight
FortiInsight Cloud
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail Appliance and VM
FortiMail Cloud - Hosted
FortiMail Workspace Security
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRPS
FortiRecon
FortiRecorder
FortiSASE
FortiSASE-Sovereign
FortiSAT
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSRA Private Cloud
FortiSRA Public Cloud
FortiSandbox
FortiSandbox PaaS
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSwitch
FortiSwitch Manager
FortiSwitch-AX Chassis
FortiSwitchNMS
FortiTIP Cloud
FortiTap
FortiTelemetry
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWLM
FortiWeb
FortiWeb Manager
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
SOCaaS
Security Awareness and Training
Wireless Controller
Ordering Guides
AV Engine
AWS Firewall Rules
CTAP Cloud
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Kubernetes Controller
FortiADC Manager
FortiAIOps
FortiAP / FortiWiFi
FortiAP-U Series
FortiAnalyzer
FortiAnalyzer BigData
FortiAppSec Cloud
FortiAuthenticator
FortiBranchSASE
FortiCASB
FortiCNAPP
FortiCWP
FortiCamera
FortiCare Elite
FortiCarrier
FortiCentral
FortiClient
FortiCloud Services
FortiController
FortiConverter Service
FortiConverter Tool
FortiDAST
FortiDDoS-F
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiData
FortiDeceptor
FortiDeceptor DaaS
FortiDevSec
FortiDevice
FortiEDR/XDR
FortiEdge Cloud
FortiEndpoint
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate CNF
FortiGate Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGuest
FortiHypervisor
FortiIPAM
FortiIdentity Cloud
FortiInsight
FortiIsolator
FortiMail Appliance and VM
FortiMail Workspace Security
FortiManager
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiPAM
FortiPhish
FortiPolicy
FortiPortal
FortiPresence
FortiProxy
FortiRecon
FortiRecorder
FortiSASE
FortiSASE-Sovereign
FortiSIEM
FortiSOAR
FortiSRA
FortiSandbox
FortiSwitch
FortiSwitch Manager
FortiSwitch-AX Chassis
FortiSwitchNMS
FortiTIP Cloud
FortiTelemetry
FortiTester
FortiToken
FortiVoice
FortiWeb
FortiWeb Manager
FortiZTP
IPS Engine
Managed FortiGate Service
SOCaaS
Security Awareness and Training
Wireless Controller
Ordering Guides
Download PDF
Table of Contents
Select Other Version
Overview
GUI
General usability enhancements
GUI support for local-in policies
GUI support for internet service groups
GUI displays logic between firewall policy objects
GUI support to create policies in FortiView Sources and traffic logs
GUI improvements to device upgrade
GUI support for enhanced logging for threat feeds
Expanded support for Advanced Threat Protection Statistics widget
GUI improvements to the IPsec VPN Wizard
GUI improvements to Security Rating
GUI support for web proxy forward server over IPv6
GUI support for security posture tags in dial-up IPsec VPN tunnels 7.6.1
CLI diagnostic shortcuts in the GUI 7.6.1
Asset Details pane 7.6.1
GUI access for global search 7.6.3
GUI warnings for IKE-TCP port conflicts 7.6.3
GUI improvements of PIM support for VRFs 7.6.3
Support filtering on policy list statistics 7.6.4
Enhanced security rating tooltip controls 7.6.5
Enforce FortiCare registration after new GUI login 7.6.5
Enforce FortiCare registration with read-only CLI 7.6.5
Enhanced setup wizard for networking connectivity support 7.6.5
Network
General
Configure the VRRP hello timer in milliseconds
FortiGate as a recursive DNS resolver
BGP network prefixes utilize firewall addresses and groups
Support UDP-Lite traffic
Custom LSA refresh rates and fast link-down detection on VLAN interfaces for OSPF
Filter NetFlow sampling
SOCKS proxy supports UTM scanning, authentication, and forward server
Implement the interface name as the source IP address in RADIUS, LDAP, and DNS configurations
Include groups in PIM join/prune messages
Automatic LTE connection establishment
Netflow sampling
Support source-IP interface for system DNS database
Extended VRF ID range for enhanced network scalability 7.6.1
Enhanced PIM support for VRFs 7.6.1
Including denied multicast sessions in the session table 7.6.1
Support specific VRF ID for local-out traffic 7.6.1
Support source IP interface for system DNS 7.6.1
Improvements to IPsec monitoring 7.6.1
Connectivity Fault Management (CFM) now available for FG-80F-POE and FG-20xF models 7.6.3
Application and network performance monitoring with FortiTelemetry 7.6.3
Fortinet Support Tool for capturing incidents
Support configuring users and groups in policy routes 7.6.3
Support additional NIC interface diagnostics 7.6.4
Auto speed negotiation for 10G Base-T on FortiGate 100xF devices 7.6.4
Add support for 802.1X on a virtual switch when added to a software switch 7.6.5
IPv6
DHCPv6 enhancements
Recursive resolution of BGP routes using IPv6 prefix with on-link flag from route aggregation
Enhancing SIP reliability in 464XLAT environments 7.6.1
Explicit and Transparent Proxy
Specifying outgoing interface and VRF for a web proxy forward server or isolator server 7.6.1
Isolator servers in proxy policies 7.6.1
GUI support of isolator servers for proxy policies 7.6.3
SD-WAN
Overlays and underlays
ADVPN 2.0 enhancements
ADVPN 2.0 overlay placeholders for shortcuts between spokes 7.6.1
SD-WAN Setup wizard for guided configuration 7.6.1
Fabric Overlay Orchestrator Topology dashboard widget for hub FortiGates 7.6.3
Hub-to-spoke traffic shaping by IKE bandwidth negotiation 7.6.4
ADVPN 2.0 enhancement: trigger just one shortcut for each distinct underlay path 7.6.4
ADVPN spoke-to-spoke traffic shaping by IKE bandwidth negotiation 7.6.4
Routing
Allow SD-WAN hubs to suppress BGP routes when all links to a spoke are down 7.6.5
Performance SLA
Embed SLA priorities in ICMP probes
Embed SLA status in ICMP probes
Map SD-WAN member priorities to BGP MED attribute when spoke advertises routes using iBGP to hub 7.6.1
FortiGuard SLA database for SD-WAN performance SLA 7.6.1
Passive monitoring of TCP metrics 7.6.1
Application performance monitoring 7.6.3
SD-WAN speed test enhancements 1 7.6.5
SD-WAN speed test enhancements 2 7.6.5
IPv6 probe-response through interface configuration 7.6.5
Service rules
Allow SD-WAN rules to steer IPv6 multicast traffic
Specify SD-WAN zones in some policies 7.6.1
Hybrid strategy for service rules 7.6.4
General
Create default configuration of SD-WAN on FortiGate models with two WAN ports 7.6.5
Policy and objects
NGFW
Seven-day policy hit counter
Policies
NPTv6 protocol for IPv6 address translation
MAP-E supports multiple VNE interfaces in the same VDOM
Full cone NAT for fixed port range IP pools
Custom port ranges for PBA and FPR IP pools
HTTP transaction logging
Support for NAT64 in FPR IP pools
Support for randomized port selection in IP pool mechanisms 7.6.1
Enhanced security with default local-in policy 7.6.1
DHCP-PD support for MAP-E 7.6.1
Objects
RSSO dynamic address subtype 7.6.1
New ISDB record for SOCaaS 7.6.1
Apply FQDN address groups within the ISDB 7.6.1
GUI support for FQDN address groups within the ISDB 7.6.4
Dynamic telemetry firewall address type 7.6.4
IPv6 wildcard addresses 7.6.4
NGFW policy support for FQDN address groups in the ISDB 7.6.5
Zero Trust Network Access
Security posture and EMS connector
Share ZTNA information through the EMS connector
Extend ZTNA error codes and replacement messages 7.6.4
Share used security posture tags with EMS 7.6.4
Application gateway
ZTNA agentless web-based application access 7.6.1
General
ZTNA support for UDP traffic
ZTNA support for SaaS application access control in the GUI
Include EMS tag information in traffic logs
ZTNA single sign-on with Entra ID 7.6.3
ZTNA tags on 2 GB entry-level platforms in IP/MAC-based access control 7.6.3
Security profiles
Antivirus
Sanitize Microsoft OneNote files through content disarm and reconstruction
Stream-based antivirus scanning for HTML and Javascript files
Zero-day malware stream scanning 7.6.3
Support FortiSandbox inline scanning in flow mode 7.6.4
Web filter
Introduce URL risk-scores in determining policy action 7.6.1
IPS
AI and ML-based IPS detection 7.6.3
Data loss prevention
FortiGuard managed DLP dictionaries
Integration with FortiData 7.6.4
Use MPIP labels directly with DLP profiles 7.6.4
Application control
Introducing domain fronting protection
Virtual patching
Streamline IoT/OT device detection 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
Others
Support the Zstandard compression algorithm for web content
DNS filtering in proxy policies
DNS translation support for Service records over the DNS Filter profile
Control TLS connections that utilize Encrypted Client Hello
Selective forwarding to ICAP server 7.6.1
Control TLS connections that utilize Encrypted Client Hello in flow mode 7.6.3
Inline CASB security profile to support control factors in exchanged JSON data for custom SaaS applications 7.6.3
Hybrid post-quantum cryptography in SSL deep inspection in flow mode 7.6.5
Support proxy-based inspection for email protocols on models with 2 GB RAM 7.6.5
Protecting LLM and GenAI
Application control support for generative AI 7.6.4
VPN
IPsec and SSL VPN or Agentless VPN
Automatic selection of IPsec tunneling protocol
Security posture tag match enforced before dial-up IPsec VPN connection
Enhancing security with Post-Quantum Cryptography for IPsec key exchange 7.6.1
Migration from SSL VPN tunnel mode to IPsec VPN 7.6.3
Agentless VPN 7.6.3
Configure FortiClient SIA for IPsec VPN tunnels 7.6.3
Support Quantum Key Distribution and Post-Quantum Cryptography 7.6.3
Post-Quantum Cryptography for Agentless VPN 7.6.5
Allow UDP port 443 for dialup IPsec VPN 7.6.5
User and authentication
Authentication
Customizable password reuse thresholds
Trigger RADIUS authentication with DNS and ICMP queries
Authentication sessions preserved after a reboot
SCIM server support
GUI support for SCIM clients 7.6.1
Bearer token authentication for SCIM 7.6.1
Support SAML authentication in a proxy policy using SCIM 7.6.4
Support SAML users when configuring local users 7.6.4
Configure FTM push with dynamic IP handling in the GUI 7.6.4
Per-Session SAML authentication logging and logout support for ZTNA and explicit proxy users 7.6.5
LAN Edge
Wireless
Support the 802.11mc protocol in FortiAP
Support OpenRoaming Standards on FortiAP
Support segregating WLAN traffic on FortiAPs operating in WAN-LAN mode
Support isolating mDNS traffic on the Bonjour profile
Support RADIUS NAS-ID on FortiAPs in standalone mode
Improve packet detection on the FortiAP sniffer
Support RADSEC on WPA2/WPA3-Enterprise SSID
Add GUI support for configuring wireless data rates and sticky client thresholds
Support self-registration of MPSKs through FortiGuest
Support IKEv2 for FortiAP IPsec data channel management
Support WPA3-SAE and WPA3-SAE Transition security modes in MPSK profiles
Add Advanced WIDS Options 7.6.1
Support RADSEC on Local Bridge mode captive portals 7.6.1
Add a RADIUS Called Station ID setting 7.6.1
Support remote TACACS access to FortiAP 7.6.1
Support RADIUS Accounting messages over FortiGuest MPSK Authentication 7.6.1
Add profile support for Zero-Wait DFS on select FortiAP models 7.6.4
Support Zero-Touch Provisioning for Mesh Leaf FortiAPs 7.6.4
Support manual captive portal trigger for bridge mode SSIDs 7.6.4
Support FortiAP management through IPv6 7.6.5
Enhance DARRP with FortiAIOps 7.6.5
Support Wi-Fi 7 MLO on FortiAP K-series models 7.6.5
Enhance GUI support for configuring mesh leaf FortiAPs 7.6.5
Support CA requests through EST and SCEP servers 7.6.5
Support Filter-ID for RADIUS authentication in WPA2-Enterprise 7.6.5
Improve security during FortiWiFi setup 7.6.5
New default configurations on FortiWiFi platforms 7.6.5
Switch controller
Change the priority of MAB and EAP 802.1X authentication
Send SNMP traps for MAC address changes
Support QinQ with the switch controller 7.6.1
Enhance network performance with VLAN pruning 7.6.1
Provide an enhanced GUI for NAC policies 7.6.3
Support IPv6 addresses for managed FortiSwitch units 7.6.3
Prevent automatically created VLANs 7.6.3
Add event logging for IPv4 source guard 7.6.4
Layer-3 switch configuration 7.6.4
Support maximum burst size for storm control 7.6.4
Increase length of managed FortiSwitch names 7.6.4
Integrate FortiSwitch NAC and 802.1X authentication 7.6.4
FortiExtender
Support fast failover for FortiExtender
Support VLAN over FortiExtender LAN-extension mode 7.6.1
Support split tunneling in LAN extension mode 7.6.1
Support multiple APNs in WAN extension mode 7.6.1
Support FortiCare registration for FortiExtender 7.6.1
Add GUI support for split tunneling in LAN extension mode 7.6.3
Add GUI support for multiple APNs in WAN extension mode 7.6.3
Add GUI support for FortiCare registration for FortiExtender 7.6.3
System
General
Restrict local administrator logins through the console
Configure TCP NPU session delay globally
Object usage included in the print tablesize command output
Sequential firmware upgrades for FortiGate Fabric devices
Simplified device registration for Security Fabric devices 7.6.1
Firmware upgrade report 7.6.1
Optimizations for physical FortiGate devices with 2 GB RAM 7.6.3
Automatic firmware upgrades for FortiGate appliances with invalid support contracts or that have reached EOES 7.6.4
Enhance administrative authentication and session monitoring 7.6.4
Enhanced firmware upgrade management for extension devices 7.6.4
FortiSASE-Sovereign licensing and management for FortiGate 91G and 901G 7.6.5
Memory optimizations for start-up configs, NPs, and NTurbo 7.6.5
FortiGuard
Streamline timezone updates with a downloadable database
Streamlined subscription and FortiGuard settings management 7.6.1
FortiGate StateRamp support 7.6.1
AMQP-powered subscription notifications for FortiGuard 7.6.3
High availability
Manual and automatic HA virtual MAC address assignment
Backup heartbeat interface mitigates split-brain scenarios
RSSO authenticated user logon information synchronized between FGSP peers
FGSP support for failover with asymmetric traffic and UTM
Monitor routing prefix for FGSP session failover 7.6.1
Single FortiGuard license for FortiGate A-P HA cluster 7.6.1
Improve manual failover of FortiGates deployed in an A-P architecture with VWP and using wildcard VLAN 7.6.4
Certificates
ACME External Account Binding support 7.6.3
Security
Encrypt configuration files in the eCryptfs file system
Closed network VM license security enhancement
OpenSSL FIPS provider installed globally at startup
Enhance real-time file system integrity checking
Use per-FortiGate generated random password for private-data-encryption 7.6.1
Enhanced administrator password security 7.6.1
BIOS security Low and High level classification 7.6.1
Automatic firmware upgrade control 7.6.1
Enhanced HTTPS management security with post-quantum TLS algorithms 7.6.5
SNMP
Ethernet Statistics Group
Non-management VDOMs perform queries using SNMP v3
SNMP support for BIOS security level
Security Fabric
Fabric settings and connectors
Apply threat feed connectors as source addresses in central SNAT
Automatic serial number retrieval from FortiManager
Support multi-tenant FortiClient Cloud fabric connectors in the GUI 7.6.1
Generic connector for importing addresses 7.6.1
Support mTLS client certification for external feed connections 7.6.1
GUI support for mTLS of external feed connections 7.6.3
Enhancing FortiSandbox TLS security with CA and CN controls 7.6.3
External SDN connectors
Multus CNI for Kubernetes connectors 7.6.4
Import IPv6 addresses from an APIC controller 7.6.4
Security ratings
Enhanced security rating customization 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
General
Enhanced security visibility for IoT/OT vulnerabilities 7.6.1
Log and report
Logging
Logging MAC address flapping events
Non-management VDOMs send logs to both global and vdom-override syslog servers
Logging message IDs
Incorporating endpoint device data in the web filter UTM logs
Set the source interface for syslog and NetFlow settings
Logging detection of duplicate IPv4 addresses
Logging local traffic per local-in policy
Logs generated when starting and stopping packet capture and TCP dump operations
Include zone information fields in logs 7.6.4
Cloud
Public and private cloud
Azure SDN connector relay through FortiManager support
IBM Cloud virtual network interface support
GCP SDN connector relay through FortiManager support
Support the AWS r8g instance family
Support the AWS c8g instance family
KVM Red Hat Enterprise Linux 9.4 support
Azure SDN connector moves private IP address on trusted NIC during A-P HA failover 7.6.1
Support the OCI E5.Flex instance type 7.6.1
Azure SDN connector GraphQL bulk query support 7.6.1
AWS NitroTPM support 7.6.1
AWS SDN connector IPv6 address object support 7.6.1
GCP C4 Intel instance support 7.6.1
FortiGate-VM GDC V support 7.6.1
OCI SDN connector IPv6 address object support 7.6.1
GCP SDN connector IPv6 address object support 7.6.1
Support for Azure upcoming MANA NIC 7.6.1
Azure SDN connector IPv6 address object support 7.6.1
FGT_VM64_KVM IPsec performance improvement through virtio and RPS 7.6.1
FGT_VM64_KVM IPsec performance through DPDK improvement 7.6.1
FortiGate-VM config system affinity-packet-redistribution optimization 7.6.1
OCI support for on-premise solutions 7.6.1
AliCloud GWLB support 7.6.1
AliCloud instance type support 7.6.3
AWS c8gn instance type support 7.6.4
Support for user managed scaling 7.6.5
Operational Technology
System
CLI to configure FGR-70F/FGR-70F-3G4G GPIO/DIO module alarm functionality 7.6.1
SNMP traps and automation-stitch notifications for DIO module alarm functionality 7.6.1
Support Ethernet layer protocols in the IPS engine 7.6.3
Index
7.6.0
7.6.1
7.6.3
7.6.4
7.6.5
Change Log
7.6.0
7.4.0
7.2.0
7.0.0
6.4.0
6.2.0