DOCUMENT LIBRARY
DOCUMENT LIBRARY
Products
Best Practices
Hardware Guides
Products A-Z
Summary
By Solution
By 4D Pillars
By Cloud
Secure Networking
Unified SASE
Security Operations
Secure SD-WAN
Secure Access Service Edge (SASE)
ZTNA
LAN Edge
Identity and Access Management
Next Generation Firewall
Public Cloud
Private Cloud
FortiCloud
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
More >>
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiTrust Identity
FortiPAM
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
More >>
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
/
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
/
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken
/
FortiToken Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Application Delivery
FortiADC
/
FortiGSLB
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/ FortiOS
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Application Gateway
FortiGate/ FortiOS
FortiProxy
FortiADC
/
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
/
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
/
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Wireless
FortiAP / FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiEdge Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiToken Cloud
FortiTrust Identity
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Managed Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Platform as a service (PAAS)
FortiSASE
FortiAnalyzer Cloud
FortiManager Cloud
FortiClient Cloud
FortiSandbox Cloud
FortiMail Cloud
FortiSOAR Cloud
Other SAAS Services
Overlay-as-a-Service
FortiRecon
FortiConverter
ForiIPAM
FortiFlex
FortiCare Elite
4D Resources
Solution Hubs
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiGate
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Search documents and hardware ...
New Features
Overview
Device Manager
Device and Groups
Auto-link setting is exposed to control configuration installation during ZTP 7.4.1
LTE modem data usage and status has been added to device monitoring widgets 7.4.2
Filter function is available for Device Manager table columns 7.4.3
Firmware Template can filter the FortiGate HA Clusters and trigger upgrade only on cluster with all nodes up 7.4.3
Granular control over what values to keep when a conflict occurs during import 7.4.4
SD-WAN
Automated SD-WAN post overlay process creates policies to allow the health-checks traffic to flow between Branch and HUB
Automated SD-WAN overlay process adds "branch_id" meta variable auto assignment
SD-WAN monitoring map integrates with Cloud Assisted Monitoring Service to allow FortiGate interface speed tests from inside FortiManager
SDWAN monitoring map enhancements
SDWAN template for heterogeneous WAN link types
SD-WAN usability improvement allow drag-and-drop of SD-WAN rules and cut/copy and paste before and after operation 7.4.1
SD-WAN Monitoring dashboards allows full widgets customization 7.4.2
Link, SLA, Application, and Rules status monitoring widgets added to SD-WAN Monitor 7.4.3
Layer-2 physical interface TX, RX, CRC errors, speed, and duplex mode added to SD-WAN monitoring 7.4.3
Quick access to per-device SD-WAN monitoring added to SD-WAN Monitor Template View 7.4.3
Templates
Preview CLI configuration for the device provisioning templates
Fortinet factory-default wireless and extender templates
Jinja Templates have direct access to the device DB to support generation of dynamic configuration
Fabric Authorization Template is integrated with Device Blueprint and supports meta variables 7.4.1
Support for FortiOS automatic firmware patch upgrade and scheduling 7.4.1
Support model FortiGate HA cluster in device blueprint 7.4.1
Factory default SSIDs and AP Profiles configuration updated 7.4.2
System Provisioning Template supports interface, server mode, and source IP configuration for NTP 7.4.3
System Templates support metadata variables to configure hostname, time zone, and geographic coordinates 7.4.3
FortiManager provides a warning for SSLVPN feature removal when upgrading an affected desktop FortiGate model to 7.6 7.4.3
Central Management
AP Manager
Multiple optimizations to the factory default SSID and AP-profiles 7.4.1
Export Managed FortiAPs and import FortiAPs from a CSV file 7.4.2
FortiSwitch Manager
Per-device VRRP mapping can be used under FortiSwitch Profiles
FortiManager allows switchport export to another VDOM, and configuration of the exported port in the destination VDOM
FortiSwitch replacement procedure can be executed from FortiManager GUI
Custom commands can be assigned/unassigned at once to multiple managed FortiSwitches 7.4.1
FortiManager creates packet capture for managed FortiSwitches 7.4.1
FortiSwitch packet capture can run an schedule 7.4.2
FortiSwitch devices can be imported from a CSV file 7.4.2
Extender Manager
Central firmware upgrade for FortiExtender MODEM 7.4.2
Others
FortiManager supports install preview for model devices
VPN Monitoring displays IPsec VPN tunnels created by IPsec templates and SD-WAN overlay wizard
FortiManager supports CLI diff in the workflow approval sessions
Internet Service database update occurs only if specific policy objects require a FortiGuard update 7.4.1
FortiManager supports uploading and hosting of an external threat feed 7.4.1
Fabric connector support for FortiManager to connect to a remote FortiAnalyzer 7.4.1
FortiManager support for managing account level entitlements for FortiSandbox Cloud 7.4.2
Auto-link will only trigger an IPS/Application Control update if the signatures used in the Policy Package require a newer version 7.4.2
Remote access to FortiOS GUI from FortiManager 7.4.2
FortiManager manages the licenses for air-gapped FortiWeb via the FortIFlex connector 7.4.2
FortiManager manages the licenses for air-gapped FortiGate via the FortiFlex connector 7.4.2
ADOM version 7.4 supports FortiOS versions 7.4, 7.2, and 7.0 7.4.2
Upstream FortiManager provides delta only updates to downstream FortiManagers in cascade mode 7.4.2
Proxy settings server URL page enhanced with drag-and-drop and better user experience 7.4.2
Firmware upgrade report 7.4.2
Meta variables are available in the SSID, FortiSwitch VLANs and FortiSwitch Templates configuration 7.4.2
Enforce Device Configuration option allows auto-link to push changes on FortiGate management interface during ZTP 7.4.2
Meta variable support in EMS connector allows for installing different connector names and IP addresses on each FortiGate 7.4.3
FortiManager can centrally update the SIEM and SOAR content package for FortiAnalyzer 7.4.3
FortiManager detects FortiGate HA clusters operating in MVC mode, provides a warning, and prevents cluster firmware upgrade 7.4.4
The VPN Monitor table view can be filtered using the greater than (>) or less than (<) signs on incoming/outgoing bandwidth columns 7.4.4
Policy and Objects
Policy
Install preview support for partial install
Policy Package installation added link to the progress report page for installation errors
Support for IoT Virtual Patching in NAC policies using pre-built severity filters
Policy deletion warning message improved with selected policy number and name reference 7.4.1
Enable option for persistent policy hit-count on ADOM database 7.4.1
Partial install pushes only the instructed configuration (JSON API) 7.4.1
Policy partial install supports policy reorder/move operation ( JSON API) 7.4.1
Create a new policy based on the logged traffic and traffic hit count 7.4.1
Policy revision supports the revert policy function 7.4.2
Policy Block usability improvements 7.4.2
Support added for "Install On" function for policy blocks 7.4.2
Policy Package consistency check result can be exported as PDF file 7.4.3
Every policy change generates a revision and administrator is prompted to add a change note 7.4.3
Policy to Log and Log to Policy adds a persistent right-click action on all table columns. 7.4.3
Objects
Import and export meta variables in CSV format 7.4.2
Import from an SDN connector IPv6 firewall address type 7.4.3
Cisco ACI connector supports IPv6 firewall address import 7.4.3
Metavariable support added under address group members and dynamic interface configurations 7.4.3
Maximum value for the proxy address table has been increased to 400K 7.4.3
Security Fabric
Updated CSF topology view on FortiManager
System
High Availability (HA)
FortiManager supports different VM type platforms to form the FortiManager cluster
FortiManager-HA support automatic VRRP failover in Azure 7.4.2
Administrators
A new restricted admin profile can be used to only change the administrators passwords 7.4.2
Granular admin permission grants IPS Admin access to only IPS objects and prevents changes for regular Firewall Admin on IPS Profiles 7.4.2
ADOM
ADOM 7.2 Policy Package supports installation on FortiGate 7.4 7.4.1
7.2 ADOM managing mixed FOS versions 7.4.1
FortiManager can upgrade multiple ADOMs (same version) at the same time 7.4.1
FortiManager supports setting a time zone for each ADOM 7.4.2
Others
Block out contract device from upgrading to next or major or minor release
Automatic system backup setup in GUI to configure a backup schedule and visualize backup history 7.4.1
FortiManager and FortiAnalyzer support HTTP/2 for improved security, multiplexing, and reduced network latency 7.4.1
Backup strategy and configuration setup added to the FortiManager setup wizard 7.4.2
FortiManager system backup and restore operations adds mandatory password, and the backup file is encrypted with AES256 7.4.2
Migrate the FortiManager instance from a different platform supported in the GUI 7.4.3
Full page configuration available for select menus 7.4.3
FortiCare integration into FortiManager for links to documentation, video tutorials, release notes, and more 7.4.3
FortiManager supports IPv6 address type for syslog server configuration 7.4.3
FortiManager introduces OS firmware levels Feature(F) and Mature(M) 7.4.4
Management Extensions
Cisco ACI Connector (Universal Connector) supports Endpoint Security Groups (ESGs) 7.4.1
Azure Connector (Universal Connector) directly communicate with AZURE to resolve and update dynamic firewall objects on managed FortiGates 7.4.2
Support Universal Connector for FortiManager HA 7.4.2
Cloud Services
FortiManager used as single-pane management tool to orchestrate FortiGate deployment in AWS
FortiManager supports backups using Azure's enhanced backup policy 7.4.2
AWS FortiManager-VM HA and EIP 7.4.2
FortiManager supports M6 and M7 instance types in AWS 7.4.3
FortiManager can act as proxy relay for individual FortiGate connections to GCP 7.4.4
FortiManager can act as proxy relay for individual FortiGate connections to Azure 7.4.4
FortiManager supports Azure virtual WAN inbound Software Load Balancer configuration and FortiGate PAYG license information 7.4.4
Other
New FortiManager UX design
Fabric and External connector pages have been reorganized for an enhanced user experience
FortiManager connector relay to AWS will proxy all individual FortiGate requests
FortiManager key areas have been reorganized to enhance user experience
FortiManager imports EPGs entries using the Cisco ACI connector as individual objects
Index
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
Change Log
Home
FortiManager 7.4.0
New Features
7.4.0
7.6.0
7.4.0
7.2.0
7.0.0
6.4.0
6.2.7
6.2.3
6.2.2
6.2.1
6.2.0
System
System
This section lists the new features added to
FortiManager
for system settings:
High Availability (HA)
Administrators
ADOM
Others
Previous
Next
System
System
This section lists the new features added to
FortiManager
for system settings:
High Availability (HA)
Administrators
ADOM
Others
Previous
Next
Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiFlex
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
FortiGuard ABP
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Next Generation Firewall
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Download PDF
Table of Contents
Overview
Device Manager
Device and Groups
Auto-link setting is exposed to control configuration installation during ZTP 7.4.1
LTE modem data usage and status has been added to device monitoring widgets 7.4.2
Filter function is available for Device Manager table columns 7.4.3
Firmware Template can filter the FortiGate HA Clusters and trigger upgrade only on cluster with all nodes up 7.4.3
Granular control over what values to keep when a conflict occurs during import 7.4.4
SD-WAN
Automated SD-WAN post overlay process creates policies to allow the health-checks traffic to flow between Branch and HUB
Automated SD-WAN overlay process adds "branch_id" meta variable auto assignment
SD-WAN monitoring map integrates with Cloud Assisted Monitoring Service to allow FortiGate interface speed tests from inside FortiManager
SDWAN monitoring map enhancements
SDWAN template for heterogeneous WAN link types
SD-WAN usability improvement allow drag-and-drop of SD-WAN rules and cut/copy and paste before and after operation 7.4.1
SD-WAN Monitoring dashboards allows full widgets customization 7.4.2
Link, SLA, Application, and Rules status monitoring widgets added to SD-WAN Monitor 7.4.3
Layer-2 physical interface TX, RX, CRC errors, speed, and duplex mode added to SD-WAN monitoring 7.4.3
Quick access to per-device SD-WAN monitoring added to SD-WAN Monitor Template View 7.4.3
Templates
Preview CLI configuration for the device provisioning templates
Fortinet factory-default wireless and extender templates
Jinja Templates have direct access to the device DB to support generation of dynamic configuration
Fabric Authorization Template is integrated with Device Blueprint and supports meta variables 7.4.1
Support for FortiOS automatic firmware patch upgrade and scheduling 7.4.1
Support model FortiGate HA cluster in device blueprint 7.4.1
Factory default SSIDs and AP Profiles configuration updated 7.4.2
System Provisioning Template supports interface, server mode, and source IP configuration for NTP 7.4.3
System Templates support metadata variables to configure hostname, time zone, and geographic coordinates 7.4.3
FortiManager provides a warning for SSLVPN feature removal when upgrading an affected desktop FortiGate model to 7.6 7.4.3
Central Management
AP Manager
Multiple optimizations to the factory default SSID and AP-profiles 7.4.1
Export Managed FortiAPs and import FortiAPs from a CSV file 7.4.2
FortiSwitch Manager
Per-device VRRP mapping can be used under FortiSwitch Profiles
FortiManager allows switchport export to another VDOM, and configuration of the exported port in the destination VDOM
FortiSwitch replacement procedure can be executed from FortiManager GUI
Custom commands can be assigned/unassigned at once to multiple managed FortiSwitches 7.4.1
FortiManager creates packet capture for managed FortiSwitches 7.4.1
FortiSwitch packet capture can run an schedule 7.4.2
FortiSwitch devices can be imported from a CSV file 7.4.2
Extender Manager
Central firmware upgrade for FortiExtender MODEM 7.4.2
Others
FortiManager supports install preview for model devices
VPN Monitoring displays IPsec VPN tunnels created by IPsec templates and SD-WAN overlay wizard
FortiManager supports CLI diff in the workflow approval sessions
Internet Service database update occurs only if specific policy objects require a FortiGuard update 7.4.1
FortiManager supports uploading and hosting of an external threat feed 7.4.1
Fabric connector support for FortiManager to connect to a remote FortiAnalyzer 7.4.1
FortiManager support for managing account level entitlements for FortiSandbox Cloud 7.4.2
Auto-link will only trigger an IPS/Application Control update if the signatures used in the Policy Package require a newer version 7.4.2
Remote access to FortiOS GUI from FortiManager 7.4.2
FortiManager manages the licenses for air-gapped FortiWeb via the FortIFlex connector 7.4.2
FortiManager manages the licenses for air-gapped FortiGate via the FortiFlex connector 7.4.2
ADOM version 7.4 supports FortiOS versions 7.4, 7.2, and 7.0 7.4.2
Upstream FortiManager provides delta only updates to downstream FortiManagers in cascade mode 7.4.2
Proxy settings server URL page enhanced with drag-and-drop and better user experience 7.4.2
Firmware upgrade report 7.4.2
Meta variables are available in the SSID, FortiSwitch VLANs and FortiSwitch Templates configuration 7.4.2
Enforce Device Configuration option allows auto-link to push changes on FortiGate management interface during ZTP 7.4.2
Meta variable support in EMS connector allows for installing different connector names and IP addresses on each FortiGate 7.4.3
FortiManager can centrally update the SIEM and SOAR content package for FortiAnalyzer 7.4.3
FortiManager detects FortiGate HA clusters operating in MVC mode, provides a warning, and prevents cluster firmware upgrade 7.4.4
The VPN Monitor table view can be filtered using the greater than (>) or less than (<) signs on incoming/outgoing bandwidth columns 7.4.4
Policy and Objects
Policy
Install preview support for partial install
Policy Package installation added link to the progress report page for installation errors
Support for IoT Virtual Patching in NAC policies using pre-built severity filters
Policy deletion warning message improved with selected policy number and name reference 7.4.1
Enable option for persistent policy hit-count on ADOM database 7.4.1
Partial install pushes only the instructed configuration (JSON API) 7.4.1
Policy partial install supports policy reorder/move operation ( JSON API) 7.4.1
Create a new policy based on the logged traffic and traffic hit count 7.4.1
Policy revision supports the revert policy function 7.4.2
Policy Block usability improvements 7.4.2
Support added for "Install On" function for policy blocks 7.4.2
Policy Package consistency check result can be exported as PDF file 7.4.3
Every policy change generates a revision and administrator is prompted to add a change note 7.4.3
Policy to Log and Log to Policy adds a persistent right-click action on all table columns. 7.4.3
Objects
Import and export meta variables in CSV format 7.4.2
Import from an SDN connector IPv6 firewall address type 7.4.3
Cisco ACI connector supports IPv6 firewall address import 7.4.3
Metavariable support added under address group members and dynamic interface configurations 7.4.3
Maximum value for the proxy address table has been increased to 400K 7.4.3
Security Fabric
Updated CSF topology view on FortiManager
System
High Availability (HA)
FortiManager supports different VM type platforms to form the FortiManager cluster
FortiManager-HA support automatic VRRP failover in Azure 7.4.2
Administrators
A new restricted admin profile can be used to only change the administrators passwords 7.4.2
Granular admin permission grants IPS Admin access to only IPS objects and prevents changes for regular Firewall Admin on IPS Profiles 7.4.2
ADOM
ADOM 7.2 Policy Package supports installation on FortiGate 7.4 7.4.1
7.2 ADOM managing mixed FOS versions 7.4.1
FortiManager can upgrade multiple ADOMs (same version) at the same time 7.4.1
FortiManager supports setting a time zone for each ADOM 7.4.2
Others
Block out contract device from upgrading to next or major or minor release
Automatic system backup setup in GUI to configure a backup schedule and visualize backup history 7.4.1
FortiManager and FortiAnalyzer support HTTP/2 for improved security, multiplexing, and reduced network latency 7.4.1
Backup strategy and configuration setup added to the FortiManager setup wizard 7.4.2
FortiManager system backup and restore operations adds mandatory password, and the backup file is encrypted with AES256 7.4.2
Migrate the FortiManager instance from a different platform supported in the GUI 7.4.3
Full page configuration available for select menus 7.4.3
FortiCare integration into FortiManager for links to documentation, video tutorials, release notes, and more 7.4.3
FortiManager supports IPv6 address type for syslog server configuration 7.4.3
FortiManager introduces OS firmware levels Feature(F) and Mature(M) 7.4.4
Management Extensions
Cisco ACI Connector (Universal Connector) supports Endpoint Security Groups (ESGs) 7.4.1
Azure Connector (Universal Connector) directly communicate with AZURE to resolve and update dynamic firewall objects on managed FortiGates 7.4.2
Support Universal Connector for FortiManager HA 7.4.2
Cloud Services
FortiManager used as single-pane management tool to orchestrate FortiGate deployment in AWS
FortiManager supports backups using Azure's enhanced backup policy 7.4.2
AWS FortiManager-VM HA and EIP 7.4.2
FortiManager supports M6 and M7 instance types in AWS 7.4.3
FortiManager can act as proxy relay for individual FortiGate connections to GCP 7.4.4
FortiManager can act as proxy relay for individual FortiGate connections to Azure 7.4.4
FortiManager supports Azure virtual WAN inbound Software Load Balancer configuration and FortiGate PAYG license information 7.4.4
Other
New FortiManager UX design
Fabric and External connector pages have been reorganized for an enhanced user experience
FortiManager connector relay to AWS will proxy all individual FortiGate requests
FortiManager key areas have been reorganized to enhance user experience
FortiManager imports EPGs entries using the Cisco ACI connector as individual objects
Index
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
Change Log