Skip to main content
ekrishnan
Staff
Staff
June 22, 2026

Technical Tip: Upgrading FortiAuthenticator in air-gap environment and its behavior

  • June 22, 2026
  • 0 replies
  • 26 views

Description

This article describes the procedure and behavior of FortiAuthenticator when upgrading in an air-gap environment

Scope

FortiAuthenticator.

Solution

The following should be done to upgrade the FortiAuthenticator,

  1. Download the required FortiAuthenticator image from Fortinet Support.

  2. Once downloaded, upload the image and proceed to backup and upgrade

  3. If using a VM instance, it is advisable to take a snapshot of the VM before the upgrade.

  4. The FortiAuthenticator will reboot during the upgrade process and eventually will show the login page after the upgrade is successful.


Note: FortiAuthenticator VM or Hardware license itself will not have any impact after the upgrade in an air-gap environment, but the following services will need to have internet to validate their license and subscription after the reboot, as this will require communication to the FortiGuard servers:

  • FortiToken mobile license.

  • FortiToken Hardware license.

  • FortiToken Cloud license.

  • FortiGuard messaging service.

  • FortiGuard SMS service.


The screenshots below show the scenario before and after the upgrade:


Air gap environment:

997679f9.png


Before upgrade (License info):


053df13f.png


After upgrade:

eefc0802.png


Based on the upgrade result the VM license itself will not be impacted however the FortiGuard relied services such as the FortiToken Cloud will need internet to validate its license and subscription.