DOCUMENT LIBRARY
DOCUMENT LIBRARY
Products
Best Practices
Hardware Guides
Products A-Z
Summary
By Solution
By 4D Pillars
By Cloud
Secure Networking
Unified SASE
Security Operations
Secure SD-WAN
Secure Access Service Edge (SASE)
ZTNA
LAN Edge
Identity and Access Management
Next Generation Firewall
Public Cloud
Private Cloud
FortiCloud
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
More >>
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiTrust Identity
FortiPAM
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
More >>
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
/
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
/
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken
/
FortiToken Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Application Delivery
FortiADC
/
FortiGSLB
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/ FortiOS
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Application Gateway
FortiGate/ FortiOS
FortiProxy
FortiADC
/
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
/
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
/
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Wireless
FortiAP / FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiEdge Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiToken Cloud
FortiTrust Identity
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Managed Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Platform as a service (PAAS)
FortiSASE
FortiAnalyzer Cloud
FortiManager Cloud
FortiClient Cloud
FortiSandbox Cloud
FortiMail Cloud
FortiSOAR Cloud
Other SAAS Services
Overlay-as-a-Service
FortiRecon
FortiConverter
ForiIPAM
FortiFlex
FortiCare Elite
4D Resources
Solution Hubs
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiGate
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Search documents and hardware ...
New Features
Overview
GUI
General usability enhancements
GUI support for local-in policies
GUI support for internet service groups
GUI displays logic between firewall policy objects
GUI support to create policies in FortiView Sources and traffic logs
GUI improvements to device upgrade
GUI support for enhanced logging for threat feeds
Expanded support for Advanced Threat Protection Statistics widget
GUI improvements to the IPsec VPN Wizard
GUI improvements to Security Rating
GUI support for web proxy forward server over IPv6
Network
General
Configure the VRRP hello timer in milliseconds
FortiGate as a recursive DNS resolver
BGP network prefixes utilize firewall addresses and groups
Support UDP-Lite traffic
Custom LSA refresh rates and fast link-down detection on VLAN interfaces for OSPF
Filter NetFlow sampling
SOCKS proxy supports UTM scanning, authentication, and forward server
Implement the interface name as the source IP address in RADIUS, LDAP, and DNS configurations
Include groups in PIM join/prune messages
Automatic LTE connection establishment
Netflow sampling
Extended VRF ID range for enhanced network scalability 7.6.1
Enhanced PIM support for VRFs 7.6.1
Including denied multicast sessions in the session table 7.6.1
Support specific VRF ID for local-out traffic 7.6.1
Support source IP interface for system DNS 7.6.1
IPv6
DHCPv6 enhancements
Recursive resolution of BGP routes using IPv6 prefix with on-link flag from route aggregation
Enhancing SIP reliability in 464XLAT environments 7.6.1
Explicit and Transparent Proxy
Specifying outgoing interface and VRF for a web proxy forward server or isolator server 7.6.1
SD-WAN
Overlays and underlays
ADVPN 2.0 enhancements
ADVPN 2.0 overlay placeholders for shortcuts between spokes 7.6.1
SD-WAN Setup wizard for guided configuration 7.6.1
Performance SLA
Embed SLA priorities in ICMP probes
Embed SLA status in ICMP probes
Map SD-WAN member priorities to BGP MED attribute when spoke advertises routes using iBGP to hub 7.6.1
FortiGuard SLA database for SD-WAN performance SLA 7.6.1
Service rules
Allow SD-WAN rules to steer IPv6 multicast traffic
Specify SD-WAN zones in some policies 7.6.1
Policy and objects
NGFW
Seven-day policy hit counter
Policies
NPTv6 protocol for IPv6 address translation
MAP-E supports multiple VNE interfaces in the same VDOM
Full cone NAT for fixed port range IP pools
Custom port ranges for PBA and FPR IP pools
HTTP transaction logging
Support for NAT64 in FPR IP pools
Support for randomized port selection in IP pool mechanisms 7.6.1
Enhanced security with default local-in policy 7.6.1
Objects
RSSO dynamic address subtype 7.6.1
New ISDB record for SOCaaS 7.6.1
Zero Trust Network Access
Security posture and EMS connector
Share ZTNA information through the EMS connector
Application gateway
ZTNA agentless web-based application access 7.6.1
General
ZTNA support for UDP traffic
ZTNA support for SaaS application access control in the GUI
Include EMS tag information in traffic logs
Security profiles
Antivirus
Sanitize Microsoft OneNote files through content disarm and reconstruction
Stream-based antivirus scanning for HTML and Javascript files
Web filter
Introduce URL risk-scores in determining policy action 7.6.1
Data loss prevention
FortiGuard managed DLP dictionaries
Application control
Introducing domain fronting protection
Virtual patching
Streamline IoT/OT device detection 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
Others
Support the Zstandard compression algorithm for web content
DNS filtering in proxy policies
DNS translation support for Service records over the DNS Filter profile
Control TLS connections that utilize Encrypted Client Hello
VPN
IPsec and SSL VPN
Automatic selection of IPsec tunneling protocol
Security posture tag match enforced before dial-up IPsec VPN connection
User and authentication
Authentication
Customizable password reuse thresholds
Trigger RADIUS authentication with DNS and ICMP queries
Authentication sessions preserved after a reboot
SCIM server support
LAN Edge
Wireless
Support the 802.11mc protocol in FortiAP
Support OpenRoaming Standards on FortiAP
Support segregating WLAN traffic on FortiAPs operating in WAN-LAN mode
Support isolating mDNS traffic on the Bonjour profile
Support RADIUS NAS-ID on FortiAPs in standalone mode
Improve packet detection on the FortiAP sniffer
Support RADSEC on WPA2/WPA3-Enterprise SSID
Add GUI support for configuring wireless data rates and sticky client thresholds
Support self-registration of MPSKs through FortiGuest
Support IKEv2 for FortiAP IPsec data channel management
Support WPA3-SAE and WPA3-SAE Transition security modes in MPSK profiles
Add Advanced WIDS Options 7.6.1
Support RADSEC on Local Bridge mode captive portals 7.6.1
Add a RADIUS Called Station ID setting 7.6.1
Support remote TACACS access to FortiAP 7.6.1
Support RADIUS Accounting messages over FortiGuest MPSK Authentication 7.6.1
Switch controller
Change the priority of MAB and EAP 802.1X authentication
Send SNMP traps for MAC address changes
Support QinQ with the switch controller 7.6.1
Enhance network performance with VLAN pruning 7.6.1
FortiExtender
Support fast failover for FortiExtender
Support VLAN over FortiExtender LAN-extension mode 7.6.1
System
General
Restrict local administrator logins through the console
Configure TCP NPU session delay globally
Object usage included in the print tablesize command output
Simplified device registration for Security Fabric devices 7.6.1
Firmware upgrade report 7.6.1
FortiGuard
Streamlined subscription and FortiGuard settings management 7.6.1
High availability
Manual and automatic HA virtual MAC address assignment
Backup heartbeat interface mitigates split-brain scenarios
RSSO authenticated user logon information synchronized between FGSP peers
FGSP support for failover with asymmetric traffic and UTM
Security
Encrypt configuration files in the eCryptfs file system
Closed network VM license security enhancement
OpenSSL FIPS provider installed globally at startup
Enhance real-time file system integrity checking
SNMP
Ethernet Statistics Group
Non-management VDOMs perform queries using SNMP v3
SNMP support for BIOS security level
Security Fabric
Fabric settings and connectors
Apply threat feed connectors as source addresses in central SNAT
Support multi-tenant FortiClient Cloud fabric connectors in the GUI 7.6.1
Security ratings
Enhanced security rating customization 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
General
Enhanced security visibility for IoT/OT vulnerabilities 7.6.1
Log and report
Logging
Logging MAC address flapping events
Non-management VDOMs send logs to both global and vdom-override syslog servers
Logging message IDs
Incorporating endpoint device data in the web filter UTM logs
Set the source interface for syslog and NetFlow settings
Logging detection of duplicate IPv4 addresses
Logging local traffic per local-in policy
Logs generated when starting and stopping packet capture and TCP dump operations
Cloud
Public and private cloud
Azure SDN connector relay through FortiManager support
IBM Cloud virtual network interface support
GCP SDN connector relay through FortiManager support
Support the AWS r8g instance family
Support the AWS c8g instance family
Azure SDN connector moves private IP address on trusted NIC during A-P HA failover 7.6.1
Support the OCI E5.Flex instance type 7.6.1
Azure SDN connector GraphQL bulk query support 7.6.1
AWS NitroTPM support 7.6.1
AWS SDN connector IPv6 address object support 7.6.1
GCP C4 Intel instance support 7.6.1
FortiGate-VM GDC V support 7.6.1
OCI SDN connector IPv6 address object support 7.6.1
GCP SDN connector IPv6 address object support 7.6.1
Support for Azure upcoming MANA NIC 7.6.1
Azure SDN connector IPv6 address object support 7.6.1
FGT_VM64_KVM IPsec performance improvement through virtio and RPS 7.6.1
FGT_VM64_KVM IPsec performance through DPDK improvement 7.6.1
FortiGate-VM config system affinity-packet-redistribution optimization 7.6.1
Index
7.6.0
7.6.1
Change Log
Home
FortiGate / FortiOS 7.6.0
New Features
7.6.0
7.6.0
7.4.0
7.2.0
7.0.0
6.4.0
6.2.0
OCI SDN connector IPv6 address object support
7.6.1
OCI SDN connector IPv6 address object support
7.6.1
OCI SDN connectors support IPv6 address objects.
Previous
Next
OCI SDN connector IPv6 address object support
7.6.1
OCI SDN connector IPv6 address object support
7.6.1
OCI SDN connectors support IPv6 address objects.
Previous
Next
Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiFlex
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
FortiGuard ABP
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Next Generation Firewall
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Download PDF
Table of Contents
Overview
GUI
General usability enhancements
GUI support for local-in policies
GUI support for internet service groups
GUI displays logic between firewall policy objects
GUI support to create policies in FortiView Sources and traffic logs
GUI improvements to device upgrade
GUI support for enhanced logging for threat feeds
Expanded support for Advanced Threat Protection Statistics widget
GUI improvements to the IPsec VPN Wizard
GUI improvements to Security Rating
GUI support for web proxy forward server over IPv6
Network
General
Configure the VRRP hello timer in milliseconds
FortiGate as a recursive DNS resolver
BGP network prefixes utilize firewall addresses and groups
Support UDP-Lite traffic
Custom LSA refresh rates and fast link-down detection on VLAN interfaces for OSPF
Filter NetFlow sampling
SOCKS proxy supports UTM scanning, authentication, and forward server
Implement the interface name as the source IP address in RADIUS, LDAP, and DNS configurations
Include groups in PIM join/prune messages
Automatic LTE connection establishment
Netflow sampling
Extended VRF ID range for enhanced network scalability 7.6.1
Enhanced PIM support for VRFs 7.6.1
Including denied multicast sessions in the session table 7.6.1
Support specific VRF ID for local-out traffic 7.6.1
Support source IP interface for system DNS 7.6.1
IPv6
DHCPv6 enhancements
Recursive resolution of BGP routes using IPv6 prefix with on-link flag from route aggregation
Enhancing SIP reliability in 464XLAT environments 7.6.1
Explicit and Transparent Proxy
Specifying outgoing interface and VRF for a web proxy forward server or isolator server 7.6.1
SD-WAN
Overlays and underlays
ADVPN 2.0 enhancements
ADVPN 2.0 overlay placeholders for shortcuts between spokes 7.6.1
SD-WAN Setup wizard for guided configuration 7.6.1
Performance SLA
Embed SLA priorities in ICMP probes
Embed SLA status in ICMP probes
Map SD-WAN member priorities to BGP MED attribute when spoke advertises routes using iBGP to hub 7.6.1
FortiGuard SLA database for SD-WAN performance SLA 7.6.1
Service rules
Allow SD-WAN rules to steer IPv6 multicast traffic
Specify SD-WAN zones in some policies 7.6.1
Policy and objects
NGFW
Seven-day policy hit counter
Policies
NPTv6 protocol for IPv6 address translation
MAP-E supports multiple VNE interfaces in the same VDOM
Full cone NAT for fixed port range IP pools
Custom port ranges for PBA and FPR IP pools
HTTP transaction logging
Support for NAT64 in FPR IP pools
Support for randomized port selection in IP pool mechanisms 7.6.1
Enhanced security with default local-in policy 7.6.1
Objects
RSSO dynamic address subtype 7.6.1
New ISDB record for SOCaaS 7.6.1
Zero Trust Network Access
Security posture and EMS connector
Share ZTNA information through the EMS connector
Application gateway
ZTNA agentless web-based application access 7.6.1
General
ZTNA support for UDP traffic
ZTNA support for SaaS application access control in the GUI
Include EMS tag information in traffic logs
Security profiles
Antivirus
Sanitize Microsoft OneNote files through content disarm and reconstruction
Stream-based antivirus scanning for HTML and Javascript files
Web filter
Introduce URL risk-scores in determining policy action 7.6.1
Data loss prevention
FortiGuard managed DLP dictionaries
Application control
Introducing domain fronting protection
Virtual patching
Streamline IoT/OT device detection 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
Others
Support the Zstandard compression algorithm for web content
DNS filtering in proxy policies
DNS translation support for Service records over the DNS Filter profile
Control TLS connections that utilize Encrypted Client Hello
VPN
IPsec and SSL VPN
Automatic selection of IPsec tunneling protocol
Security posture tag match enforced before dial-up IPsec VPN connection
User and authentication
Authentication
Customizable password reuse thresholds
Trigger RADIUS authentication with DNS and ICMP queries
Authentication sessions preserved after a reboot
SCIM server support
LAN Edge
Wireless
Support the 802.11mc protocol in FortiAP
Support OpenRoaming Standards on FortiAP
Support segregating WLAN traffic on FortiAPs operating in WAN-LAN mode
Support isolating mDNS traffic on the Bonjour profile
Support RADIUS NAS-ID on FortiAPs in standalone mode
Improve packet detection on the FortiAP sniffer
Support RADSEC on WPA2/WPA3-Enterprise SSID
Add GUI support for configuring wireless data rates and sticky client thresholds
Support self-registration of MPSKs through FortiGuest
Support IKEv2 for FortiAP IPsec data channel management
Support WPA3-SAE and WPA3-SAE Transition security modes in MPSK profiles
Add Advanced WIDS Options 7.6.1
Support RADSEC on Local Bridge mode captive portals 7.6.1
Add a RADIUS Called Station ID setting 7.6.1
Support remote TACACS access to FortiAP 7.6.1
Support RADIUS Accounting messages over FortiGuest MPSK Authentication 7.6.1
Switch controller
Change the priority of MAB and EAP 802.1X authentication
Send SNMP traps for MAC address changes
Support QinQ with the switch controller 7.6.1
Enhance network performance with VLAN pruning 7.6.1
FortiExtender
Support fast failover for FortiExtender
Support VLAN over FortiExtender LAN-extension mode 7.6.1
System
General
Restrict local administrator logins through the console
Configure TCP NPU session delay globally
Object usage included in the print tablesize command output
Simplified device registration for Security Fabric devices 7.6.1
Firmware upgrade report 7.6.1
FortiGuard
Streamlined subscription and FortiGuard settings management 7.6.1
High availability
Manual and automatic HA virtual MAC address assignment
Backup heartbeat interface mitigates split-brain scenarios
RSSO authenticated user logon information synchronized between FGSP peers
FGSP support for failover with asymmetric traffic and UTM
Security
Encrypt configuration files in the eCryptfs file system
Closed network VM license security enhancement
OpenSSL FIPS provider installed globally at startup
Enhance real-time file system integrity checking
SNMP
Ethernet Statistics Group
Non-management VDOMs perform queries using SNMP v3
SNMP support for BIOS security level
Security Fabric
Fabric settings and connectors
Apply threat feed connectors as source addresses in central SNAT
Support multi-tenant FortiClient Cloud fabric connectors in the GUI 7.6.1
Security ratings
Enhanced security rating customization 7.6.1
Unified OT virtual patching and IPS signatures 7.6.1
General
Enhanced security visibility for IoT/OT vulnerabilities 7.6.1
Log and report
Logging
Logging MAC address flapping events
Non-management VDOMs send logs to both global and vdom-override syslog servers
Logging message IDs
Incorporating endpoint device data in the web filter UTM logs
Set the source interface for syslog and NetFlow settings
Logging detection of duplicate IPv4 addresses
Logging local traffic per local-in policy
Logs generated when starting and stopping packet capture and TCP dump operations
Cloud
Public and private cloud
Azure SDN connector relay through FortiManager support
IBM Cloud virtual network interface support
GCP SDN connector relay through FortiManager support
Support the AWS r8g instance family
Support the AWS c8g instance family
Azure SDN connector moves private IP address on trusted NIC during A-P HA failover 7.6.1
Support the OCI E5.Flex instance type 7.6.1
Azure SDN connector GraphQL bulk query support 7.6.1
AWS NitroTPM support 7.6.1
AWS SDN connector IPv6 address object support 7.6.1
GCP C4 Intel instance support 7.6.1
FortiGate-VM GDC V support 7.6.1
OCI SDN connector IPv6 address object support 7.6.1
GCP SDN connector IPv6 address object support 7.6.1
Support for Azure upcoming MANA NIC 7.6.1
Azure SDN connector IPv6 address object support 7.6.1
FGT_VM64_KVM IPsec performance improvement through virtio and RPS 7.6.1
FGT_VM64_KVM IPsec performance through DPDK improvement 7.6.1
FortiGate-VM config system affinity-packet-redistribution optimization 7.6.1
Index
7.6.0
7.6.1
Change Log