FortiOS 7.6.7 release notes

build 3704synced 2026-07-31

FortiOS 7.6.7 adds enhancements across FortiASIC, GUI, hyperscale, LAN Edge, networking, policy, Security Fabric, security profiles, system, VPN, and ZTNA. Upgrade-impacting changes include new NP7 traffic-handling defaults, fail-closed NGFW policy behavior when IPS is unavailable, HA-role-aware CLI prompts, a lower default IPsec tunnel MTU on specified models, and changed factory defaults on FortiGate 20xG ports.

Official Fortinet release notes ↗

What's new

  • #1192303

    NP7 VLAN accounting controls

    Adds controls to enable or disable VLAN accounting and adjust its message interval. VLAN accounting is enabled by default. Use `config system npu set vlan-accounting {disable | enable} set vlan-acct-interval <milliseconds> end`. The interval defaults to 200 ms and supports 100–10000 ms; increasing it can reduce VLAN lookup messages, CG-FULL conditions, or packet drops on busy systems with many VLANs.

  • #1205727

    Configurable NP7 link-scan interval

    Allows tuning the interval between NP7 link-failure scans to potentially reduce FGCP HA failover delays and send gratuitous ARP sooner. Use `config system npu set np-linkscan-interval <milliseconds> end`. The range is 50–1000 ms and the default is 1000 ms.

  • #1288373

    NPU offload for IPsec over VNE

    Adds driver-level hardware acceleration for IPsec over VNE interfaces on SoC5/NP7Lite and NP7 platforms, improving throughput and performance.

  • #1176612

    Legal Third Party GUI panel

    Adds a searchable and exportable GUI inventory of third-party software, licenses, license terms, and version information.

  • #1260021

    Firmware changes during seven-day setup

    Administrators can manually upgrade or downgrade through the GUI or CLI during the seven-day setup period. Registration is required afterward.

  • #1212583

    Hyperscale EIF timer controls

    Adds controls for Endpoint Independent Filtering/full-cone NAT refresh direction, TTL, and extra timeouts: `config system npu set eif-tcp-refresh-dir {both | outgoing | incoming} set eif-udp-refresh-dir {both | outgoing | incoming} set eif-tcp-ttl <time> set eif-udp-ttl <time> set extra-timeout-tcp <time> set extra-timeout-udp <time> end`.

  • #1220140

    RSSO prefix lengths in hyperscale logs

    Hyperscale hardware logging can include RADIUS server prefix lengths for RSSO users using `set rsso-ipv6-prefix-length <length>` and `set rsso-ipv4-prefix-length <length>` under the NPU log server group. Defaults are 64 for IPv6 and 32 for IPv4.

  • #1197063

    Ukraine 6 GHz channel support

    Adds channels 1 through 93 in the 6 GHz range for all G and K platforms in the Ukraine-U region.

  • #1238935

    Global trunk-port selection criteria

    Adds global switch-controller configuration for trunk-port selection criteria on Marvell platforms, replacing the prior per-trunk approach.

  • #1244920

    Dynamic VLAN with VLAN pooling

    Allows Dynamic VLAN and VLAN Pooling to be enabled simultaneously on a RADIUS-authenticated VAP. RADIUS assignment is used when present, with fallback to the local VLAN pool.

  • #1244925

    VLAN pools spanning WTP groups

    Allows multiple WTP groups to be selected when creating a VLAN entry in WTP group mode.

  • #1249992

    Wi-Fi 7 MLO on standalone FortiAPK VAPs

    Enables MultiLink Operation on local standalone VAPs for FortiAPK models, with authentication handled directly by the FortiAP.

  • #1215201

    External active GNSS antenna support

    Adds external active GNSS antenna support on FWF50G5G for stronger reception and improved GPS accuracy and reliability.

  • #1215886

    Source checks for reply packets

    Adds strict-RPF-like source verification for reply packets. Configure with `config system settings set src-check-reply {enable | disable} end`. The default is disabled.

  • #1105204

    SCIM groups in firewall and VPN authorization

    Allows SCIM groups to be used directly in firewall policies without local group mapping. Also supports IPsec VPN authorization by matching certificate SAN fields to SCIM user attributes.

  • #1250003

    Firmware-upgrade completion automation

    Adds the default Firmware Upgrade Complete stitch, Auto Firmware Upgrade Complete trigger, and Auto Upgrade Complete Email Notification action. Firmware-upgrade email wording is clearer, and the former Firmware Upgrade Notification default stitch is disabled.

  • #1199124

    WebSocket UTM inspection

    Adds WebSocket inspection for DLP, antivirus, IPS, and File Filter detection and blocking of sensitive data, malware, and restricted files.

  • #1223803

    Customizable DHCP Option 82

    Allows administrators to choose any combination of Option 82 suboptions and define a custom delimiter, replacing three fixed, noneditable styles.

  • #1238520

    Seven-day pre-registration setup period

    Models that normally require registration for full GUI and CLI access now permit full configuration for seven days before registration becomes mandatory.

  • #1254298

    5G modem monitoring and upgrades in GUI

    Adds GUI monitoring of 5G modem status and GUI-driven modem firmware upgrades.

  • #1256067

    Forced firmware update protocol support

    Enhances FCPC with a ForcedUpdate flag and major.minor.patch-build version reporting. If the firmware license is invalid, FortiGuard can ignore the license check and allow an update when source and target major/minor versions match. Related logs, notifications, and automation messaging are clearer.

  • #1256235

    Per-member HA SNMP identity

    Preserves per-member SNMP location, description, and contact data so each HA unit can be identified separately in monitoring systems.

  • #1274821

    CFM support on G-series FortiGate

    Adds Connectivity Fault Management support on FortiGate G-series platforms for Ethernet fault diagnosis and troubleshooting.

  • #1212772

    Automatic IPsec shaping refresh on NP7Lite

    On NP7Lite/SoC5 systems, `config system npu set mcs-auto-start enable end` automatically flushes or reinstalls affected IPsec SAs and clears offloaded sessions after outbandwidth or egress-shaping changes. It is disabled by default. Without it, established offloaded IPsec tunnels do not inherit such changes until their SAs and sessions are rebuilt.

  • #1212920

    Improved native remote-access VPN wizard

    Generated native VPN configurations work out of the box on supported operating systems. The default is L2TP over IPsec for Windows, Android, macOS, and iOS; IKEv2 is also configurable for Windows and Android.

  • #1235059

    IPsec multipath

    Distributes encrypted traffic across multiple sub-tunnels and CPU queues grouped as one logical super tunnel, enabling parallel CPU use and higher throughput. Configure with `config vpn ipsec phase1-interface edit <name> set multipath <integer> next end`.

  • #1262907

    Unaddressed IPsec interfaces for PIM

    Allows an unaddressed IPsec tunnel interface to act as a PIM interface by borrowing a loopback address. Example: `config router multicast config interface edit "p1" set update-source "lo1" next end end`.

  • #1206912

    EMS root CA opt-out for secure web proxy

    Adds `config authentication setting set ems-root-ca {enable | disable} end` for FortiClient, ZTNA, and endpoint authentication. It defaults to enabled; when disabled, WAD validates the client certificate against the configured user CA.

Breaking changes

  • #1207557

    Dedicated VM activation FQDNs with Anycast

    When Anycast is enabled, VM license activation now uses `vmactivation1.fortinet.net`, `vmactivation2.fortinet.net`, and `vmactivation3.fortinet.net` instead of general update FQDNs. Firewall and DNS allowlists may require updates.

  • #1238339

    NP7 critical-traffic handling defaults changed

    The dedicated host queue and `dedicated-management-cpu` are enabled by default; the NP7 DSWH profile and busy-retry behavior are changed. Under extreme load, regular host queues now drop at DSWH rather than applying backpressure to DSW. Disabling the dedicated management CPU may maximize CPS performance but removes the new isolation of CPU0 for critical traffic.

  • #1239371

    GovRamp factory-default NTP servers changed

    After factory reset in GovRamp mode, defaults change from `time-a-g.nist.gov`/`129.6.15.28` and `time-b-g.nist.gov`/`129.6.15.29` to `ntp1.fortinetgov.com`/`23.249.63.60` or `23.249.63.61` and `ntp2.fortinetgov.com`/`23.249.63.62` or `23.249.63.63`.

  • #1240706

    NGFW policy mode fails closed without IPS

    NGFW policy-mode VDOMs now drop traffic when IPS sockets are unavailable, including during startup, IPS upgrades, or manual IPS shutdown. Previously traffic could bypass inspection.

  • #1256231

    HA role added to CLI prompt

    The CLI prompt now dynamically includes Primary or Secondary, for example `FortiGate(Secondary) (global) #`. Automation such as Ansible that expects a fixed prompt may fail and should be updated.

  • #1288059

    FortiGate 20xG port defaults changed

    After factory reset or out-of-box initialization on FortiGate 20xG models, port1 and port2 are removed from the virtual switch and configured for DHCP to support ZTP.

  • #1248524

    Default IPsec tunnel MTU reduced

    The default MTU changes from 1420 to 1402 on FG-5xG, FG-7xG, FG-9xG, FG-12xG, FG-20xG, FG-40xF, FG-60xF, FG-70xG, FG-90xG, FG-100xF, FG-180xF, FG-260xF, FG-300xF, FG-320xF, FG-350xF, FG-370xF, FG-420xF, FG-440xF, FG-480xF, FG-7000F, FG-ARM64-AWS, FG-ARM64-AZURE, FG-ARM64-GCP, FG-ARM64-KVM, FG-ARM64-OCI, FG-ARM64-XEN, FG-VM64, FG-VM64-ALI, FG-VM64-AZURE, FG-VM64-AWS, FG-VM64-GCP, FG-VM64-HV, FG-VM64-IBM, FG-VM64-XEN, FG-VM64-KVM, and FG-VM64-OPC.

Upgrade notes

  • #1245249

    Expanded pre-registration CLI access

    Before registration, the following configuration trees are permitted to support central management, ZTP, and LTP: `config firewall policy`, `config router setting`, `config router static`, `config router static6`, `config system admin`, `config system central-management`, `config system dns`, `config system interface`, `config system pppoe-interface`, and `config system settings`.

Special notices

  • Registration required after setup window

    For models subject to registration restrictions, full configuration and manual firmware changes are available during the seven-day setup period; registration is required after that period.