FortiOS 7.6.5 release notes
FortiOS 7.6.5 adds enhancements across GUI, LAN Edge, logging, networking, policy, SD-WAN, security profiles, system, authentication, VPN, and WiFi. It also changes several defaults affecting IPsec, NP7, asymmetric ICMP routing, dual-WAN provisioning, FortiGuard updates, hyperscale quotas, and tunnel-mode SSIDs.
Official Fortinet release notes ↗What's new
- #1183975
Setup wizard supports gateway configuration and offline licensing
The setup wizard can configure a gateway for FortiCare connectivity and accepts offline license-file uploads in air-gapped environments.
- #1186780
Security Rating tooltips provide insight controls
Tooltips include a button to view all insights and controls to hide individual insights while retaining an indication that insights are hidden.
- #1078408
FortiAP management supports IPv6
FortiAP devices can be managed over IPv6, improving integration and scalability in IPv6-based networks.
- #1095618
FortiAIOps can manage DARRP channel selection
When available, FortiAIOps collects radio data through REST APIs and recommends channels to reduce Wi-Fi interference.
- #1139482
FWF G-series client mode gains modern WPA authentication
Client mode on FWF G-series models supports WPA2/WPA3-Enterprise and WPA3-SAE.
- #1150610
FortiAP certificate enrollment supports EST and SCEP
FortiAPs can automatically request certificates from EST or SCEP servers configured in the WTP profile, replacing manual CA uploads through TFTP and simplifying renewal.
- #1185065
FortiAP-K models support Wi-Fi 7 MLO
Multi-Link Operation permits simultaneous transmission over 2.4, 5, and 6 GHz bands.
- #1187026
Mesh leaf FortiAP settings available in GUI
Mesh leaf FAP settings can be configured directly through the GUI.
- #1187056
Unsupported new FortiAP models use an MVP profile
An AP newer than the running FortiOS release is classified as FAP MVP, a generic Wi-Fi 7 2x2 dual-band profile providing limited management and visibility until FortiOS is upgraded to a release that fully supports the model.
- #1200877
FortiAP 222KL supports LoRaWAN gateway operation
The AP can receive LoRaWAN sensor data and securely forward it to supported network servers while also operating as a Wi-Fi access point.
- #1217645
Software-switch virtual switches support 802.1X
802.1X can be enabled on virtual switches within a software switch when `intra-switch-policy` is set to `explicit`, enabling dynamic VLAN and traffic controls.
- #1170883
Hostname resolution timing is configurable for logs
When Resolved hostnames is enabled under Log Settings, On log creation (`resolve-ip`) adds the resolved hostname as `dstname`, while When viewed (`resolve-hosts`) resolves destination addresses when logs are fetched. If both are enabled through CLI, On log creation takes precedence.
- #1099374
NP7 can offload denied sessions
Denied sessions can be offloaded to NP7 processors to reduce CPU load using `config system npu set session-denied-offload {enable | disable} end`.
- #1124535
Delegated IPv6 prefixes gain DNSSL control
Administrators can control whether delegated-prefix domains are included in Router Advertisement DNSSL options using `config ip6-delegated-prefix-list edit <id> set dnssl-service {enable | disable} next end`.
- #1078303
ISDB FQDN groups supported in NGFW policies
FQDN address groups within the Internet Service Database can be applied to NGFW policies as well as firewall policies.
- #1169071
Passive FQDN learning can be disabled per address
Passive learning is enabled by default and can be overridden using `config firewall address edit <address> set passive-fqdn-learning {disable | enable} next end`.
- #1135850
SD-WAN HTTP and TWAMP health checks support IPv6
IPv6 is supported for HTTP and TWAMP SD-WAN health checks, and `probe-response` is available in interface `ip6-allowaccess`. Example: `config system sdwan config health-check edit "ipv6_test" set addr-mode ipv6 set server 2000:172:16:200::1 set protocol twamp next end end`. The responder can be enabled with `config system interface edit "port3" config ipv6 set ip6-address 2000:172:16:200::1/64 set ip6-allowaccess ping https ssh probe-response end next end config system probe-response set mode twamp end`.
- #1156116
SD-WAN speed tests dynamically update QoS bandwidth
Scheduled speed-test results can automatically update interface inbound and outbound bandwidth for QoS while respecting configured minimum and maximum values. FTNT_Auto is used when no cloud server group is specified, and failed cloud tests are retried.
- #1187047
Scheduled speed tests gain windows and retry controls
Recurring firewall schedules can select a three-hour labeled window, with speed-test start randomized within it, using `config firewall schedule recurring edit <name> set label-day <none | over-night | early-morning | morning | midday | afternoon | evening | night | late-night> next end`. Retry behavior is configured with `config system speed-test-schedule edit "port1" set retries <value> set retry-pause <value> next end`. A preferred cloud server group can be selected with `config system speed-test-schedule edit "port1" set server-name <server group name> next end`.
- #1187158
SD-WAN hubs can suppress routes to dead spokes
A hub can detect a spoke receiving no SLA probes for a configurable duration and mark its routes for suppression. A BGP outbound route map can match suppression state and adjust MED to steer traffic through another hub. Relevant controls include `set update-bgp-route {enable | disable}` under the SD-WAN health check and `set match-suppress enable` in a route-map rule.
- #1166828
Proxy inspection for email restored on 2 GB models
FortiGate models with 2 GB RAM can again use proxy-based inspection for SMTP/SMTPS, POP3/POP3S, IMAP/IMAPS, and NNTP services in firewall policies.
- #1178045
FortiSandbox inline block timeout is configurable
Configure the timeout from 30 to 180 seconds using `config antivirus profile edit <name> set fortisandbox-scan-timeout <30-180> next end`.
- #1000357
Hyperscale SNMP reports CGNAT IP and PBA usage
Newly supported MIB fields are `fgFwIppStatsFreePBAs`, `fgFwIppStatsInusePBAs`, `fgFwIppStatsTotalPBAs`, `fgFwIppStatsInuseIPs`, and `fgFwIppStatsFreeIPs`.
- #1006397
Federated upgrades report per-device failures
Federated upgrade reporting now identifies each failed device and its specific failure reason.
- #1123102
FortiSASE Sovereign licensing supports 91G and 901G
FortiSASE Sovereign licensing bundles are supported on FortiGate 91G and 901G. Enabling `config system sov-sase set status enable end` makes the FortiGate GUI and CLI read-only; subsequent configuration changes are managed from the FortiSASE-Sovereign Portal.
- #1133400
Low-memory FortiGate models receive memory optimizations
On affected systems, the router daemon starts only when routing configuration exists, NP-reserved memory is reduced, and nTurbo maximum frame size is 1500. Interfaces with a higher MTU are not offloaded to nTurbo. Affected 2 GB families are 40F, 60F, and 50G; affected 4 GB families are 70F, 80F, and 70G.
- #1165591
Black-box debug logs support SCP and SFTP upload
Supported TPM/NVMe models such as FG-700G can upload black-box logs using `diagnose debug black-box upload scp <destination string> <yyyymmdd>` or `diagnose debug black-box upload sftp <destination ip> <user> <pwd> <dst folder> <yyyymmdd>`.
- #1202253
HTTPS administration supports quantum-resistant TLS
The management interface supports hybrid post-quantum key exchange and PQC certificates while retaining compatibility with clients that do not support PQC.
- #1216102
Web-proxy SAML sign-on timeout is configurable
The sign-on URL timeout can be set from 30 to 3600 seconds using `config web-proxy global set auth-sign-timeout <30-3600> end`, giving clients more time to reach the identity provider.
- #1152420
Agentless VPN supports post-quantum cryptography
New CLI options allow pure and hybrid PQC algorithms for Agentless VPN.
- #1195216
SSL deep inspection supports TLS 1.3 hybrid PQC
Flow-mode SSL deep inspection supports TLS 1.3 hybrid post-quantum key exchanges such as X25519MLKEM768 for compatibility with modern browsers and PQC-enabled servers.
- #1205594
IPsec IKE negotiation can use UDP port 443
Configure port 443 using `config system settings set ike-port 443 end`.
- #1211127
WiFi controllers process RADIUS Filter-ID
During 802.1X authentication, Filter-ID can map clients to existing user groups and create WSSO firewall authentication entries so the appropriate firewall policy applies without another login.
Breaking changes
- #1185772
Default open SSIDs and soft-switch interfaces removed
Default soft-switch interfaces and open SSIDs are removed across FortiWiFi platforms. On 4xF, 6xF, and G-series models, the default WiFi VAP remains in tunnel mode with preconfigured IP, DHCP, and firewall policies. On 8xF-2R models, VAPs use bridge mode with the hardware switch, receive DHCP from the internal interface, and are controlled by firewall policy.
- #1189709
FortiWiFi first-boot SSID and setup workflow changed
FWF models broadcast a temporary unique MAC-based SSID for only five minutes after first power-up instead of a static default SSID. Initial login requires an administrator password change and launches a WiFi Setup Wizard to customize or disable WiFi.
- #1107163
Default IPsec DH groups changed
For CLI-created Phase 1 and Phase 2 tunnels, the defaults change from DH groups 14 and 5 to groups 20 and 21. During upgrade, VPNs using the prior defaults are updated to groups 14, 20, and 21.
- #1138921
NP7 VLAN lookup and hash-table queue defaults changed
On NP7 systems, `vlan-lookup-cache` defaults to disabled and `htab-msg-queue` defaults to dedicated: `config system npu set vlan-lookup-cache disable set htab-msg-queue dedicated end`. Changing `vlan-lookup-cache` requires a system restart.
- #1166396
Asymmetric ICMP reply routing behavior changed
With `asymroute-icmp` or `asymroute6-icmp` enabled, replies are no longer required to use the arrival interface. If no return route exists through that interface, FortiOS selects the best available route. Settings: `config system settings set asymroute-icmp {enable | disable} set asymroute6-icmp {enable | disable} end`.
- #1176942
IKE SAML local-in matching is more restrictive
When `auth-ike-saml-port` is used, iprope matches local-in traffic only if the destination port equals `auth-ike-saml-port` and the destination interface has `ike-saml-server` enabled.
- #1189391
Dual-WAN models receive a default SD-WAN configuration
On affected two-WAN-port models, both WAN ports default to DHCP, an SD-WAN zone is created with both ports, the default firewall policy uses that zone, and an SLA tests 1.1.1.1 and 9.9.9.9. Affected families are 6xE, 6xF, 7xF, 7xG, 8xE, 8xF, 9xE, 9xG, 10xE, 100EF, 10xF, 12xG, 140E, 20xE, and 20xF, where x can be 0 or 1.
- #1204277
FortiGuard auto-update schedule defaults to daily
The default FortiGuard package update schedule changes from automatic to daily.
- #1118690
Hyperscale session quota defaults changed
IPv4 and IPv6 high session-quota thresholds now default to 64000 and low thresholds to 51200. Relevant controls are `config system npu set ipv6-prefix-session-quota {disable | enable} set ipv6-prefix-session-quota-high <high-threshold> set ipv6-prefix-session-quota-low <low-threshold> set ipv4-session-quota {disable | enable} set ipv4-session-quota-high <high-threshold> set ipv4-session-quota-low <low-threshold> end`.
- #1200360
Tunnel-mode SSID quarantine defaults to disabled
New tunnel-mode SSIDs no longer enable quarantine by default, avoiding automatic creation of unused quarantine VLANs.
Features removed
- #1000357
Expiring-PBA SNMP field is unsupported
The `fgFwIppStatsExpiringPBAs` SNMP field is not supported by FortiOS 7.6.5.