Skip to main content
agomes
Staff
Staff
March 26, 2026

Technical Tip: FortiADC behavior when the license expire

  • March 26, 2026
  • 0 replies
  • 217 views
Description This article describes the behavior of FortiADC when its license expires, including the operational impact and affected features.
Scope FortiADC v7.x and earlier.
Solution

When the license of a FortiADC physical device expires, the system enters a state where core functionality remains operational but is no longer updated. The behavior can be summarized as follows:

 

Operational continuity.

The device continues to process traffic normally. Core features such as Server Load Balancing (SLB), persistence, and application availability remain fully functional. There is no traffic interruption caused by license expiration on physical appliances.

 

FortiGuard updates suspension.

The device stops receiving both automatic and manual updates from FortiGuard services. This impacts several security components:

  • WAF Signatures: No new signatures have been received to protect against newly discovered vulnerabilities.
  • IP Reputation and GeoIP databases: These databases remain frozen at their last updated version, reducing effectiveness against emerging threats.
  • Antivirus and IPS: No new malware definitions or intrusion signatures are updated.

 

Deactivation of advanced features.

Certain features that depend on active subscriptions or cloud connectivity are disabled or hidden in the GUI:

  • WAF Adaptive Learning: Configuration settings are hidden, and machine learning-based policies stop functioning.
  • Advanced Bot Protection (ABP): The connector fails, and bot protection becomes ineffective.
  • AI Threat Analytics: The AI-based threat analysis service stops immediately.

 

Additional notes:

  • Security Fabric connectors may be impacted when the license is no longer valid.
  • System logs will register events indicating license status changes (for example, event ID 0003000235).
  • The command get system status can be used to verify the expiration status of each security engine.

 

Technical references:

The information in this article is based on the official Fortinet documentation for FortiADC version 7.6.6:

  • FortiADC administration guide.
    • Section Support Contract: Describes that system functionality remains operational, but without updates when the license is invalid.
    • Section FortiGuard Services: Explains the dependency of WAF, IPS, and AV databases on an active license.
    • Section Licensing Requirements (Adaptive Learning & ABP): Details how these features are hidden or disabled after license expiration.

 

  • FortiADC CLI reference guide.
    • Section config system global: Describes the impact on Security Fabric connectors when the license is not valid.
    • Command get system status: Official method to verify license status and expiration of security engines.

 

  • FortiADC log reference: Describes system events generated when license status changes, including event ID 0003000235.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!