FortiOS 7.4 End of Support: How Long It Lasts and Which FortiGates Stop There

FortiOS 7.2 reaches End of Support on 30 September 2026. Most FortiGate estates have spent the last few months moving to 7.4, and the obvious next question is how long that buys them.
The short answer: FortiOS 7.4 receives engineering support until 11 May 2027 and reaches End of Support on 11 November 2028. That is a comfortable runway on paper. The longer answer depends on the hardware underneath. A group of FortiGate models that run 7.4 today will never run anything newer, and on several of the models that can move on, the step to 7.6 removes features the appliance is actually used for.
This article covers both halves: the 7.4 dates, and the question of whether your appliance can go any further.
How long is FortiOS 7.4 supported?
FortiOS 7.4 reaches End of Engineering Support on 11 May 2027 and End of Support on 11 November 2028. Both dates moved by twelve months in March 2026, when Fortinet extended the 7.4 and 7.6 lifecycles under Customer Support Bulletin CSB-260330-1. After November 2028, the branch receives no security patches and no technical support.
The arithmetic follows Fortinet’s lifecycle policy. FortiOS 7.4 went generally available on 11 May 2023. After the extension, the branch gets 48 months of engineering support, followed by an 18-month must-fix period. 11 May 2023 plus 48 months is 11 May 2027. Another 18 months takes you to 11 November 2028.
The FortiOS lifecycle, current as of publication
| Branch | General availability | End of Engineering Support | End of Support |
|---|---|---|---|
| FortiOS 8.0 | 21 April 2026 | 21 April 2029 | 21 October 2030 |
| FortiOS 7.6 | 25 July 2024 | 25 July 2028 | 25 January 2030 |
| FortiOS 7.4 | 11 May 2023 | 11 May 2027 | 11 November 2028 |
| FortiOS 7.2 | 31 March 2022 | 31 March 2025 | 30 September 2026 |
Source: Fortinet Product Life Cycle information and Fortinet Community technical tip 224876 (CSB-260330-1). The Product Life Cycle page sits behind a support-portal login.
What stops on 11 May 2027, and what stops on 11 November 2028
The two dates are often read as one. They are not.
End of Engineering Support (11 May 2027). Fortinet stops producing routine maintenance builds and fixes for ordinary defects. The branch enters the must-fix window: new builds only for critical PSIRT vulnerabilities and industry-wide operational problems. With an active FortiCare contract you can still open TAC cases.
End of Support (11 November 2028). The engineering obligation ends completely. No security fixes, including for vulnerabilities that are being exploited. TAC will ask you to move to a supported branch before it investigates an issue.
That second date matters more than it sounds, because FortiGate edge vulnerabilities are exploited quickly. CVE-2024-21762, an out-of-bounds write in the FortiOS SSL VPN, and CVE-2024-23113, in the FortiGate management protocol, were both added to CISA’s Known Exploited Vulnerabilities catalogue. When CVE-2024-23113 was listed in October 2024, the Shadowserver Foundation counted roughly 87,000 exposed Fortinet IP addresses. On a branch past End of Support, the next vulnerability of that kind simply stays open.
Which FortiGates stop at 7.4?
This is the question the date tables do not answer. Fortinet decides per release which models it supports, and the E-series is split. Some E-series models appear in the FortiOS 7.4 supported-models list but not in the list for 7.6.0. For those units, 7.4 is the last branch they will ever run.
| Model family | Highest FortiOS branch | What it means |
|---|---|---|
| FortiGate 60E, 61E (incl. POE and DSL variants) | 7.4 | No upgrade target after 7.4. Plan the replacement before 11 November 2028 at the latest. |
| FortiGate 80E, 81E (incl. POE) | 7.4 | Same position as the 60E. |
| FortiGate 90E, 91E | 7.4 | Same position as the 60E. |
| FortiGate 140E, 140E-POE | 7.4 | Same position as the 60E. |
| FortiGate 100E, 101E, 100EF | 7.2 | Not in the 7.4 supported-models list. No supported firmware after 30 September 2026. |
| FortiGate 200E, 300E, 400E, 500E (and 1-variants) | 7.6 | Listed in the FortiOS 7.6.0 release notes, so they can follow to 7.6. |
| FortiGate 40F, 60F, 61F (2 GB memory) | 7.6 and 8.0 | Can upgrade, but lose SSL VPN and proxy-based features. See the next section. |
| Larger F-series and the G-series | 7.6 and 8.0 | Full upgrade path. |
Based on the supported-models lists in the FortiOS 7.4.0 and 7.6.0 release notes. Later point releases can add or drop models, so confirm your exact model in Fortinet’s Upgrade Path Tool.
There is a second clock on these units. Your appliance has two expiry dates: the firmware branch it runs, and the hardware itself. Several E-series models reach hardware end of support before 7.4 does, which means no RMA and no renewable support contract, even while the firmware is still patched. The FortiGate hardware end-of-life timeline lists those dates per model.
What the step from 7.4 to 7.6 changes
If your appliance can run 7.6, the upgrade is usually the right call. It is not a neutral one.
SSL VPN on 2 GB models. From FortiOS 7.6.0, SSL VPN web mode and tunnel mode are removed on models with 2 GB of memory, which includes the 40F, 60F and 61F. To check whether your unit falls into that group, run diagnose hardware sysinfo conserve and look at the total memory.
SSL VPN tunnel mode on every model. From FortiOS 7.6.3, Fortinet removed SSL VPN tunnel mode across all FortiGate models. Fortinet’s own note is blunt: “Settings will not be upgraded from previous versions.” The SSL VPN configuration is not converted. It is dropped. If remote users still connect over SSL VPN when you upgrade, they stop connecting. Fortinet’s route forward is IPsec dial-up, which means new FortiClient profiles on every endpoint. The background is in why Fortinet deprecated SSL VPN.
Proxy-based inspection on 2 GB models. Proxy features are no longer available on the 2 GB models. Policies and security profiles that rely on proxy inspection mode have to move to flow-based inspection before or during the upgrade.
Do not skip 7.4. The upgrade from 7.2 to 7.6 runs through an intermediate 7.4 build, because major releases carry configuration conversions. Administrators on r/fortinet describe what happens when that step is skipped: object definitions change silently, including a service object that ended up matching TCP only. Follow the sequence the Upgrade Path Tool gives you for your model and build.
Mature builds first. A recurring theme among FortiGate administrators is caution about early 7.6 builds. Many recommend running a late, mature 7.4 build rather than moving to 7.6 as soon as it is available. Fortinet marks mature builds with an “M” tag in its release information.
Three options, compared honestly
Once you know which group your appliances fall into, the decision narrows to three paths.
| Stay on 7.4 | Upgrade to 7.6 | Move remote access off the firewall | |
|---|---|---|---|
| Best fit | E-series capped at 7.4, with a replacement already budgeted | 4 GB and larger F- and G-series | Estates where the upgrade removes SSL VPN or the hardware is capped |
| Security patches | Until 11 November 2028, critical fixes only after 11 May 2027 | Until 25 January 2030 | Depends on the platform; the firewall keeps its local role |
| Remote access | SSL VPN keeps working until the branch ends | Rebuild SSL VPN as IPsec dial-up | Rebuilt once, outside the appliance |
| Hardware | Replacement still needed later | No replacement needed yet | Capped units can stay as local routers until their hardware ends |
| Main risk | Hardware end of support arrives before the firmware ends | Feature loss on 2 GB units, upgrade windows | A second platform to manage |
For an F-series or G-series appliance with 4 GB or more, upgrading in place is usually right, and nothing in this article argues otherwise.
The picture changes where the upgrade path forces you to rebuild remote access anyway. On a 2 GB unit, or on any unit going to 7.6.3 or later, SSL VPN disappears and IPsec dial-up takes its place. That is a new client profile on every laptop and a listening port that stays open on the firewall. If you are rebuilding remote access regardless, it is fair to compare rebuilding it on the appliance with moving it to a platform that does not depend on the appliance at all. That comparison is what an EU-sovereign single SASE platform such as Jimber is built for: ZTNA for users, web security and firewalling from one platform, with no inbound VPN port on the perimeter. The wider picture is in every vendor’s SSL VPN timeline, and WireGuard versus ZTNA covers the option many FortiGate administrators ask about next.
For the capped E-series, the calculation is simpler. The hardware needs replacing before November 2028 either way. The only open question is whether the replacement has to do everything the old box did.
What this means under NIS2 and CyFun
NIS2 Article 21 requires risk-management measures that include vulnerability handling and basic cyber hygiene. A perimeter firewall on a firmware branch without security fixes is a known, documented risk. It belongs in your risk analysis, with the compensating controls you rely on and a date by which it is resolved.
In Belgium, the CCB’s CyberFundamentals framework asks for security updates at every assurance level. An auditor who finds an edge device on an unsupported branch will ask for the exception and the plan behind it. The same question increasingly comes from cyber insurers at renewal, where questionnaires ask about unsupported or end-of-life edge devices.
None of this makes 7.4 a problem today. It does make the capped units a dated item on your risk register rather than something to revisit in 2028.
The case for staying fully on FortiGate
Experienced FortiGate administrators raise three solid objections to moving anything off the appliance. They deserve a straight answer.
“The Security Fabric is the point.” One FortiManager view of firewall policy, SD-WAN, FortiSwitch and FortiAP is genuinely efficient, and a second platform means a second place to manage policy. True. The answer is scope: moving remote access and web egress out does not move your LAN, your switching or your east-west inspection. It removes the one function that forces an open inbound port and a client rebuild.
“IPsec on FortiGate hardware is fast and free.” FortiGate network processors accelerate IPsec well, and IPsec dial-up carries no per-user licence beyond FortiCare. Also true. The cost that does not appear on the licence is operational: client profiles on every endpoint, multi-step upgrade windows per cluster, and an exposed VPN listener that has been the entry point in several of the exploited Fortinet vulnerabilities of the last two years.
“Fortinet extended support once, it will again.” CSB-260330-1 added a year to both 7.4 and 7.6. It may happen again. Planning around an extension that has not been announced is still a bet, and it does nothing for models whose hardware support ends before the firmware does.
What to do next
Start with the inventory. For each FortiGate, note the model, the memory, the current build and the highest branch it can run. The table above sorts most estates into three groups within an hour. Capped E-series units get a replacement date. 2 GB units get a decision on SSL VPN before anyone schedules a 7.6 upgrade. Everything else gets a normal upgrade plan through a mature 7.4 build.
If the SSL VPN question is where you land, you can test the alternative without touching the FortiGate: try Jimber free and put remote access for a pilot group on ZTNA alongside your current setup. If you would rather walk through your inventory with us first, book a demo.
Frequently asked questions
When is FortiOS 7.4 end of support?
FortiOS 7.4 reaches End of Support on 11 November 2028. End of Engineering Support follows earlier, on 11 May 2027. Both dates were extended by twelve months in March 2026 under Fortinet bulletin CSB-260330-1. After November 2028 there are no security fixes and no technical support for the branch.
What is the difference between End of Engineering Support and End of Support?
End of Engineering Support stops routine maintenance and ordinary bug fixes. The branch then enters an 18-month must-fix period with builds only for critical security issues and industry-wide defects. End of Support ends all of it: no patches, and TAC will ask you to upgrade before investigating.
Can a FortiGate 60E run FortiOS 7.6?
No. The 60E and 61E appear in the FortiOS 7.4 supported-models list but not in the list for 7.6.0. The same applies to the 80E, 81E, 90E, 91E and 140E. For these models, FortiOS 7.4 is the last branch, supported until 11 November 2028 at the latest.
Can a FortiGate 100E run FortiOS 7.4?
No. The 100E, 101E and 100EF are not in the FortiOS 7.4 supported-models list. Their last branch is 7.2, which reaches End of Support on 30 September 2026. After that date, these units have no supported firmware to move to.
Does FortiOS 7.6 still support SSL VPN?
Only partly, and only on early builds. From 7.6.0, SSL VPN web and tunnel mode are removed on 2 GB models such as the 40F and 60F. From 7.6.3, tunnel mode is removed on all models. The configuration is not converted, so remote users must move to IPsec dial-up or another access method first.
Can I upgrade directly from FortiOS 7.2 to 7.6?
You should not. Major releases include configuration conversions, and skipping the intermediate 7.4 step has caused silent changes to objects and policies. Use Fortinet’s Upgrade Path Tool, enter your model and current build, and follow the exact sequence it returns.
How do I check whether my FortiGate is a 2 GB model?
Run diagnose hardware sysinfo conserve in the CLI and read the total memory. Units with 2 GB lose SSL VPN from FortiOS 7.6.0 and cannot use proxy-based inspection features. Check this before you schedule a 7.6 upgrade, not after.
Which FortiOS 7.4 build should I run?
Run a build Fortinet marks as mature, shown with an “M” tag in its release information, and check the known-issues list in the release notes for your model before upgrading. Many administrators prefer a late mature 7.4 build over an early 7.6 build.
Is running FortiOS 7.4 a NIS2 problem?
Not while the branch is supported. It becomes one when a perimeter device runs firmware without security fixes. For models capped at 7.4, record the November 2028 end date in your risk register now, with a replacement plan, so it does not surface first during an audit or an insurance renewal.