FortiOS 7.6.7 release notes
FortiOS 7.6.7 adds enhancements across FortiASIC, GUI, hyperscale, LAN Edge, networking, policy, Security Fabric, security profiles, system, VPN, and ZTNA. Upgrade-impacting changes include new NP7 traffic-handling defaults, fail-closed NGFW policy behavior when IPS is unavailable, HA-role-aware CLI prompts, a lower default IPsec tunnel MTU on specified models, and changed factory defaults on FortiGate 20xG ports.
Official Fortinet release notes ↗What's new
- #1192303
NP7 VLAN accounting controls
Adds controls to enable or disable VLAN accounting and adjust its message interval. VLAN accounting is enabled by default. Use `config system npu set vlan-accounting {disable | enable} set vlan-acct-interval <milliseconds> end`. The interval defaults to 200 ms and supports 100–10000 ms; increasing it can reduce VLAN lookup messages, CG-FULL conditions, or packet drops on busy systems with many VLANs.
- #1205727
Configurable NP7 link-scan interval
Allows tuning the interval between NP7 link-failure scans to potentially reduce FGCP HA failover delays and send gratuitous ARP sooner. Use `config system npu set np-linkscan-interval <milliseconds> end`. The range is 50–1000 ms and the default is 1000 ms.
- #1288373
NPU offload for IPsec over VNE
Adds driver-level hardware acceleration for IPsec over VNE interfaces on SoC5/NP7Lite and NP7 platforms, improving throughput and performance.
- #1176612
Legal Third Party GUI panel
Adds a searchable and exportable GUI inventory of third-party software, licenses, license terms, and version information.
- #1260021
Firmware changes during seven-day setup
Administrators can manually upgrade or downgrade through the GUI or CLI during the seven-day setup period. Registration is required afterward.
- #1212583
Hyperscale EIF timer controls
Adds controls for Endpoint Independent Filtering/full-cone NAT refresh direction, TTL, and extra timeouts: `config system npu set eif-tcp-refresh-dir {both | outgoing | incoming} set eif-udp-refresh-dir {both | outgoing | incoming} set eif-tcp-ttl <time> set eif-udp-ttl <time> set extra-timeout-tcp <time> set extra-timeout-udp <time> end`.
- #1220140
RSSO prefix lengths in hyperscale logs
Hyperscale hardware logging can include RADIUS server prefix lengths for RSSO users using `set rsso-ipv6-prefix-length <length>` and `set rsso-ipv4-prefix-length <length>` under the NPU log server group. Defaults are 64 for IPv6 and 32 for IPv4.
- #1197063
Ukraine 6 GHz channel support
Adds channels 1 through 93 in the 6 GHz range for all G and K platforms in the Ukraine-U region.
- #1238935
Global trunk-port selection criteria
Adds global switch-controller configuration for trunk-port selection criteria on Marvell platforms, replacing the prior per-trunk approach.
- #1244920
Dynamic VLAN with VLAN pooling
Allows Dynamic VLAN and VLAN Pooling to be enabled simultaneously on a RADIUS-authenticated VAP. RADIUS assignment is used when present, with fallback to the local VLAN pool.
- #1244925
VLAN pools spanning WTP groups
Allows multiple WTP groups to be selected when creating a VLAN entry in WTP group mode.
- #1249992
Wi-Fi 7 MLO on standalone FortiAPK VAPs
Enables MultiLink Operation on local standalone VAPs for FortiAPK models, with authentication handled directly by the FortiAP.
- #1215201
External active GNSS antenna support
Adds external active GNSS antenna support on FWF50G5G for stronger reception and improved GPS accuracy and reliability.
- #1215886
Source checks for reply packets
Adds strict-RPF-like source verification for reply packets. Configure with `config system settings set src-check-reply {enable | disable} end`. The default is disabled.
- #1105204
SCIM groups in firewall and VPN authorization
Allows SCIM groups to be used directly in firewall policies without local group mapping. Also supports IPsec VPN authorization by matching certificate SAN fields to SCIM user attributes.
- #1250003
Firmware-upgrade completion automation
Adds the default Firmware Upgrade Complete stitch, Auto Firmware Upgrade Complete trigger, and Auto Upgrade Complete Email Notification action. Firmware-upgrade email wording is clearer, and the former Firmware Upgrade Notification default stitch is disabled.
- #1199124
WebSocket UTM inspection
Adds WebSocket inspection for DLP, antivirus, IPS, and File Filter detection and blocking of sensitive data, malware, and restricted files.
- #1223803
Customizable DHCP Option 82
Allows administrators to choose any combination of Option 82 suboptions and define a custom delimiter, replacing three fixed, noneditable styles.
- #1238520
Seven-day pre-registration setup period
Models that normally require registration for full GUI and CLI access now permit full configuration for seven days before registration becomes mandatory.
- #1254298
5G modem monitoring and upgrades in GUI
Adds GUI monitoring of 5G modem status and GUI-driven modem firmware upgrades.
- #1256067
Forced firmware update protocol support
Enhances FCPC with a ForcedUpdate flag and major.minor.patch-build version reporting. If the firmware license is invalid, FortiGuard can ignore the license check and allow an update when source and target major/minor versions match. Related logs, notifications, and automation messaging are clearer.
- #1256235
Per-member HA SNMP identity
Preserves per-member SNMP location, description, and contact data so each HA unit can be identified separately in monitoring systems.
- #1274821
CFM support on G-series FortiGate
Adds Connectivity Fault Management support on FortiGate G-series platforms for Ethernet fault diagnosis and troubleshooting.
- #1212772
Automatic IPsec shaping refresh on NP7Lite
On NP7Lite/SoC5 systems, `config system npu set mcs-auto-start enable end` automatically flushes or reinstalls affected IPsec SAs and clears offloaded sessions after outbandwidth or egress-shaping changes. It is disabled by default. Without it, established offloaded IPsec tunnels do not inherit such changes until their SAs and sessions are rebuilt.
- #1212920
Improved native remote-access VPN wizard
Generated native VPN configurations work out of the box on supported operating systems. The default is L2TP over IPsec for Windows, Android, macOS, and iOS; IKEv2 is also configurable for Windows and Android.
- #1235059
IPsec multipath
Distributes encrypted traffic across multiple sub-tunnels and CPU queues grouped as one logical super tunnel, enabling parallel CPU use and higher throughput. Configure with `config vpn ipsec phase1-interface edit <name> set multipath <integer> next end`.
- #1262907
Unaddressed IPsec interfaces for PIM
Allows an unaddressed IPsec tunnel interface to act as a PIM interface by borrowing a loopback address. Example: `config router multicast config interface edit "p1" set update-source "lo1" next end end`.
- #1206912
EMS root CA opt-out for secure web proxy
Adds `config authentication setting set ems-root-ca {enable | disable} end` for FortiClient, ZTNA, and endpoint authentication. It defaults to enabled; when disabled, WAD validates the client certificate against the configured user CA.
Breaking changes
- #1207557
Dedicated VM activation FQDNs with Anycast
When Anycast is enabled, VM license activation now uses `vmactivation1.fortinet.net`, `vmactivation2.fortinet.net`, and `vmactivation3.fortinet.net` instead of general update FQDNs. Firewall and DNS allowlists may require updates.
- #1238339
NP7 critical-traffic handling defaults changed
The dedicated host queue and `dedicated-management-cpu` are enabled by default; the NP7 DSWH profile and busy-retry behavior are changed. Under extreme load, regular host queues now drop at DSWH rather than applying backpressure to DSW. Disabling the dedicated management CPU may maximize CPS performance but removes the new isolation of CPU0 for critical traffic.
- #1239371
GovRamp factory-default NTP servers changed
After factory reset in GovRamp mode, defaults change from `time-a-g.nist.gov`/`129.6.15.28` and `time-b-g.nist.gov`/`129.6.15.29` to `ntp1.fortinetgov.com`/`23.249.63.60` or `23.249.63.61` and `ntp2.fortinetgov.com`/`23.249.63.62` or `23.249.63.63`.
- #1240706
NGFW policy mode fails closed without IPS
NGFW policy-mode VDOMs now drop traffic when IPS sockets are unavailable, including during startup, IPS upgrades, or manual IPS shutdown. Previously traffic could bypass inspection.
- #1256231
HA role added to CLI prompt
The CLI prompt now dynamically includes Primary or Secondary, for example `FortiGate(Secondary) (global) #`. Automation such as Ansible that expects a fixed prompt may fail and should be updated.
- #1288059
FortiGate 20xG port defaults changed
After factory reset or out-of-box initialization on FortiGate 20xG models, port1 and port2 are removed from the virtual switch and configured for DHCP to support ZTP.
- #1248524
Default IPsec tunnel MTU reduced
The default MTU changes from 1420 to 1402 on FG-5xG, FG-7xG, FG-9xG, FG-12xG, FG-20xG, FG-40xF, FG-60xF, FG-70xG, FG-90xG, FG-100xF, FG-180xF, FG-260xF, FG-300xF, FG-320xF, FG-350xF, FG-370xF, FG-420xF, FG-440xF, FG-480xF, FG-7000F, FG-ARM64-AWS, FG-ARM64-AZURE, FG-ARM64-GCP, FG-ARM64-KVM, FG-ARM64-OCI, FG-ARM64-XEN, FG-VM64, FG-VM64-ALI, FG-VM64-AZURE, FG-VM64-AWS, FG-VM64-GCP, FG-VM64-HV, FG-VM64-IBM, FG-VM64-XEN, FG-VM64-KVM, and FG-VM64-OPC.
Upgrade notes
- #1245249
Expanded pre-registration CLI access
Before registration, the following configuration trees are permitted to support central management, ZTP, and LTP: `config firewall policy`, `config router setting`, `config router static`, `config router static6`, `config system admin`, `config system central-management`, `config system dns`, `config system interface`, `config system pppoe-interface`, and `config system settings`.
Special notices
Registration required after setup window
For models subject to registration restrictions, full configuration and manual firmware changes are available during the seven-day setup period; registration is required after that period.