FortiOS 7.6.5 release notes

synced 2026-08-02

FortiOS 7.6.5 adds enhancements across GUI, LAN Edge, logging, networking, policy, SD-WAN, security profiles, system, authentication, VPN, and WiFi. It also changes several defaults affecting IPsec, NP7, asymmetric ICMP routing, dual-WAN provisioning, FortiGuard updates, hyperscale quotas, and tunnel-mode SSIDs.

Official Fortinet release notes ↗

What's new

  • #1183975

    Setup wizard supports gateway configuration and offline licensing

    The setup wizard can configure a gateway for FortiCare connectivity and accepts offline license-file uploads in air-gapped environments.

  • #1186780

    Security Rating tooltips provide insight controls

    Tooltips include a button to view all insights and controls to hide individual insights while retaining an indication that insights are hidden.

  • #1078408

    FortiAP management supports IPv6

    FortiAP devices can be managed over IPv6, improving integration and scalability in IPv6-based networks.

  • #1095618

    FortiAIOps can manage DARRP channel selection

    When available, FortiAIOps collects radio data through REST APIs and recommends channels to reduce Wi-Fi interference.

  • #1139482

    FWF G-series client mode gains modern WPA authentication

    Client mode on FWF G-series models supports WPA2/WPA3-Enterprise and WPA3-SAE.

  • #1150610

    FortiAP certificate enrollment supports EST and SCEP

    FortiAPs can automatically request certificates from EST or SCEP servers configured in the WTP profile, replacing manual CA uploads through TFTP and simplifying renewal.

  • #1185065

    FortiAP-K models support Wi-Fi 7 MLO

    Multi-Link Operation permits simultaneous transmission over 2.4, 5, and 6 GHz bands.

  • #1187026

    Mesh leaf FortiAP settings available in GUI

    Mesh leaf FAP settings can be configured directly through the GUI.

  • #1187056

    Unsupported new FortiAP models use an MVP profile

    An AP newer than the running FortiOS release is classified as FAP MVP, a generic Wi-Fi 7 2x2 dual-band profile providing limited management and visibility until FortiOS is upgraded to a release that fully supports the model.

  • #1200877

    FortiAP 222KL supports LoRaWAN gateway operation

    The AP can receive LoRaWAN sensor data and securely forward it to supported network servers while also operating as a Wi-Fi access point.

  • #1217645

    Software-switch virtual switches support 802.1X

    802.1X can be enabled on virtual switches within a software switch when `intra-switch-policy` is set to `explicit`, enabling dynamic VLAN and traffic controls.

  • #1170883

    Hostname resolution timing is configurable for logs

    When Resolved hostnames is enabled under Log Settings, On log creation (`resolve-ip`) adds the resolved hostname as `dstname`, while When viewed (`resolve-hosts`) resolves destination addresses when logs are fetched. If both are enabled through CLI, On log creation takes precedence.

  • #1099374

    NP7 can offload denied sessions

    Denied sessions can be offloaded to NP7 processors to reduce CPU load using `config system npu set session-denied-offload {enable | disable} end`.

  • #1124535

    Delegated IPv6 prefixes gain DNSSL control

    Administrators can control whether delegated-prefix domains are included in Router Advertisement DNSSL options using `config ip6-delegated-prefix-list edit <id> set dnssl-service {enable | disable} next end`.

  • #1078303

    ISDB FQDN groups supported in NGFW policies

    FQDN address groups within the Internet Service Database can be applied to NGFW policies as well as firewall policies.

  • #1169071

    Passive FQDN learning can be disabled per address

    Passive learning is enabled by default and can be overridden using `config firewall address edit <address> set passive-fqdn-learning {disable | enable} next end`.

  • #1135850

    SD-WAN HTTP and TWAMP health checks support IPv6

    IPv6 is supported for HTTP and TWAMP SD-WAN health checks, and `probe-response` is available in interface `ip6-allowaccess`. Example: `config system sdwan config health-check edit "ipv6_test" set addr-mode ipv6 set server 2000:172:16:200::1 set protocol twamp next end end`. The responder can be enabled with `config system interface edit "port3" config ipv6 set ip6-address 2000:172:16:200::1/64 set ip6-allowaccess ping https ssh probe-response end next end config system probe-response set mode twamp end`.

  • #1156116

    SD-WAN speed tests dynamically update QoS bandwidth

    Scheduled speed-test results can automatically update interface inbound and outbound bandwidth for QoS while respecting configured minimum and maximum values. FTNT_Auto is used when no cloud server group is specified, and failed cloud tests are retried.

  • #1187047

    Scheduled speed tests gain windows and retry controls

    Recurring firewall schedules can select a three-hour labeled window, with speed-test start randomized within it, using `config firewall schedule recurring edit <name> set label-day <none | over-night | early-morning | morning | midday | afternoon | evening | night | late-night> next end`. Retry behavior is configured with `config system speed-test-schedule edit "port1" set retries <value> set retry-pause <value> next end`. A preferred cloud server group can be selected with `config system speed-test-schedule edit "port1" set server-name <server group name> next end`.

  • #1187158

    SD-WAN hubs can suppress routes to dead spokes

    A hub can detect a spoke receiving no SLA probes for a configurable duration and mark its routes for suppression. A BGP outbound route map can match suppression state and adjust MED to steer traffic through another hub. Relevant controls include `set update-bgp-route {enable | disable}` under the SD-WAN health check and `set match-suppress enable` in a route-map rule.

  • #1166828

    Proxy inspection for email restored on 2 GB models

    FortiGate models with 2 GB RAM can again use proxy-based inspection for SMTP/SMTPS, POP3/POP3S, IMAP/IMAPS, and NNTP services in firewall policies.

  • #1178045

    FortiSandbox inline block timeout is configurable

    Configure the timeout from 30 to 180 seconds using `config antivirus profile edit <name> set fortisandbox-scan-timeout <30-180> next end`.

  • #1000357

    Hyperscale SNMP reports CGNAT IP and PBA usage

    Newly supported MIB fields are `fgFwIppStatsFreePBAs`, `fgFwIppStatsInusePBAs`, `fgFwIppStatsTotalPBAs`, `fgFwIppStatsInuseIPs`, and `fgFwIppStatsFreeIPs`.

  • #1006397

    Federated upgrades report per-device failures

    Federated upgrade reporting now identifies each failed device and its specific failure reason.

  • #1123102

    FortiSASE Sovereign licensing supports 91G and 901G

    FortiSASE Sovereign licensing bundles are supported on FortiGate 91G and 901G. Enabling `config system sov-sase set status enable end` makes the FortiGate GUI and CLI read-only; subsequent configuration changes are managed from the FortiSASE-Sovereign Portal.

  • #1133400

    Low-memory FortiGate models receive memory optimizations

    On affected systems, the router daemon starts only when routing configuration exists, NP-reserved memory is reduced, and nTurbo maximum frame size is 1500. Interfaces with a higher MTU are not offloaded to nTurbo. Affected 2 GB families are 40F, 60F, and 50G; affected 4 GB families are 70F, 80F, and 70G.

  • #1165591

    Black-box debug logs support SCP and SFTP upload

    Supported TPM/NVMe models such as FG-700G can upload black-box logs using `diagnose debug black-box upload scp <destination string> <yyyymmdd>` or `diagnose debug black-box upload sftp <destination ip> <user> <pwd> <dst folder> <yyyymmdd>`.

  • #1202253

    HTTPS administration supports quantum-resistant TLS

    The management interface supports hybrid post-quantum key exchange and PQC certificates while retaining compatibility with clients that do not support PQC.

  • #1216102

    Web-proxy SAML sign-on timeout is configurable

    The sign-on URL timeout can be set from 30 to 3600 seconds using `config web-proxy global set auth-sign-timeout <30-3600> end`, giving clients more time to reach the identity provider.

  • #1152420

    Agentless VPN supports post-quantum cryptography

    New CLI options allow pure and hybrid PQC algorithms for Agentless VPN.

  • #1195216

    SSL deep inspection supports TLS 1.3 hybrid PQC

    Flow-mode SSL deep inspection supports TLS 1.3 hybrid post-quantum key exchanges such as X25519MLKEM768 for compatibility with modern browsers and PQC-enabled servers.

  • #1205594

    IPsec IKE negotiation can use UDP port 443

    Configure port 443 using `config system settings set ike-port 443 end`.

  • #1211127

    WiFi controllers process RADIUS Filter-ID

    During 802.1X authentication, Filter-ID can map clients to existing user groups and create WSSO firewall authentication entries so the appropriate firewall policy applies without another login.

Breaking changes

  • #1185772

    Default open SSIDs and soft-switch interfaces removed

    Default soft-switch interfaces and open SSIDs are removed across FortiWiFi platforms. On 4xF, 6xF, and G-series models, the default WiFi VAP remains in tunnel mode with preconfigured IP, DHCP, and firewall policies. On 8xF-2R models, VAPs use bridge mode with the hardware switch, receive DHCP from the internal interface, and are controlled by firewall policy.

  • #1189709

    FortiWiFi first-boot SSID and setup workflow changed

    FWF models broadcast a temporary unique MAC-based SSID for only five minutes after first power-up instead of a static default SSID. Initial login requires an administrator password change and launches a WiFi Setup Wizard to customize or disable WiFi.

  • #1107163

    Default IPsec DH groups changed

    For CLI-created Phase 1 and Phase 2 tunnels, the defaults change from DH groups 14 and 5 to groups 20 and 21. During upgrade, VPNs using the prior defaults are updated to groups 14, 20, and 21.

  • #1138921

    NP7 VLAN lookup and hash-table queue defaults changed

    On NP7 systems, `vlan-lookup-cache` defaults to disabled and `htab-msg-queue` defaults to dedicated: `config system npu set vlan-lookup-cache disable set htab-msg-queue dedicated end`. Changing `vlan-lookup-cache` requires a system restart.

  • #1166396

    Asymmetric ICMP reply routing behavior changed

    With `asymroute-icmp` or `asymroute6-icmp` enabled, replies are no longer required to use the arrival interface. If no return route exists through that interface, FortiOS selects the best available route. Settings: `config system settings set asymroute-icmp {enable | disable} set asymroute6-icmp {enable | disable} end`.

  • #1176942

    IKE SAML local-in matching is more restrictive

    When `auth-ike-saml-port` is used, iprope matches local-in traffic only if the destination port equals `auth-ike-saml-port` and the destination interface has `ike-saml-server` enabled.

  • #1189391

    Dual-WAN models receive a default SD-WAN configuration

    On affected two-WAN-port models, both WAN ports default to DHCP, an SD-WAN zone is created with both ports, the default firewall policy uses that zone, and an SLA tests 1.1.1.1 and 9.9.9.9. Affected families are 6xE, 6xF, 7xF, 7xG, 8xE, 8xF, 9xE, 9xG, 10xE, 100EF, 10xF, 12xG, 140E, 20xE, and 20xF, where x can be 0 or 1.

  • #1204277

    FortiGuard auto-update schedule defaults to daily

    The default FortiGuard package update schedule changes from automatic to daily.

  • #1118690

    Hyperscale session quota defaults changed

    IPv4 and IPv6 high session-quota thresholds now default to 64000 and low thresholds to 51200. Relevant controls are `config system npu set ipv6-prefix-session-quota {disable | enable} set ipv6-prefix-session-quota-high <high-threshold> set ipv6-prefix-session-quota-low <low-threshold> set ipv4-session-quota {disable | enable} set ipv4-session-quota-high <high-threshold> set ipv4-session-quota-low <low-threshold> end`.

  • #1200360

    Tunnel-mode SSID quarantine defaults to disabled

    New tunnel-mode SSIDs no longer enable quarantine by default, avoiding automatic creation of unused quarantine VLANs.

Features removed

  • #1000357

    Expiring-PBA SNMP field is unsupported

    The `fgFwIppStatsExpiringPBAs` SNMP field is not supported by FortiOS 7.6.5.