Skip to main content
nalexiou
Staff & Editor
Staff & Editor
March 3, 2025

Technical Tip: Enforcing FortiCare registration starting from v7.2.11, v7.4.8, v7.6.5, v8.0.0

  • March 3, 2025
  • 2 replies
  • 38809 views

Description

This article describes the expected result that a new FortiGate must register with FortiCare before it can be fully configured, as well as how to perform initial configuration to enable registration.

Scope

FortiOS v7.2.11 or v7.4.8 and later, FortiGate G-series models.

Solution

In FortiGate G-series hardware platforms such as FortiGate-30G and FortiGate-201G, the FortiGate shows a prompt on initial login, saying: 'Register with FortiCare. This step is required to activate threat protection services and receive firmware & package updates.'

 

Enforcement Introduction:

  • In v7.4.8, only FortiGate-20XG and 90XG models had the prompt, and it was possible to configure the devices using CLI before registration.

  • In v7.4.9 and later, most G series models have the FortiCare registration check, and some CLI configuration is restricted.

 

The 'Register with FortiCare' prompt will be displayed when logging in to the device via the GUI. On earlier firmware versions, there is no option to skip it.

 

kb1.PNG

 

Enhancements:

The FortiCare registration check logic is optimized starting in FortiOS v7.4.10 and v7.6.5, allowing IP address configuration using the GUI before registration, a seven-day setup period after first power on, as well as a manual license upload option for air-gap deployments.

 

1.png

 

For more details on the use of an off-network license file, including where to download the file, see the FortiOS Administration Guide: Registering recent FortiGate models in an air-gapped environment.

 

CLI configuration is available before registration:


When logging in to the CLI, the following warning displays:

The device is not registered with FortiCare.
Any configuration change is not allowed.


Although the warning states configuration changes are not allowed, it is still possible to partially configure the device using CLI to enable internet access and FortiCare registration:

 

config firewall policy
config router static
config router static6
config system arp-table
config system dhcp
config system dhcp6
config system evpn
config system geneve
config system gre-tunnel
config system interface
config system ipip-tunnel
config system ipsec-aggregate
config system ipv6-neighbor-cache
config system link-monitor
config system mobile-tunnel
config system nd-proxy
config system pppoe-interface
config system proxy-arp
config system sdwan
config system speed-test-schedule
config system vdom-link
config system virtual-wire-pair
config system vne-interface
config system vxlan
config system zone

 

As a further enhancement in FortiOS v7.4.12, v7.6.7 and above, it will be possible to edit the following additional configuration locations before FortiCare registration:

 

config system admin
config system central-management
config system dns
config system interface
config system pppoe-interface
config system settings

 

Notes:

  • Starting with FortiOS v7.4.10, newer FortiGate hardware models provide a seven-day grace period for initial configuration before mandatory FortiCare registration enforcement. The grace period is triggered upon the first power-on event of the FortiGate device. The countdown timer is suspended when logging out of the FortiOS management interface, and the device is powered off. For more information, see Seven-day setup period for GUI and CLI configuration.

  • The 'gui-forticare-registration-setup-warning' setting is for a different function and does not affect G series FortiCare registration enforcement. The following setting does not affect the G-series check:


config system global
    set gui-forticare-registration-setup-warning <enable | disable> 
end   


  • By default, FortiGate devices with newer BIOS versions are configured with FortiCare registration level 2, requiring registration before GUI access. This setting can be changed to level 1 via the BIOS menu to bypass FortiCare registration.


78181873.png

 

To change the FortiCare registration level, refer to the document: Enforce FortiCare registration after new GUI login 7.2.11.


Related documents:

    2 replies

    New Member
    August 13, 2026

    This might be the dumbest most annoying change Fortinet has made to date! Being stuck at the registration prompt prior to initial configuration?! How dumb is this? You can’t register because well, the Fortigate is unconfigured and doesn’t have Internet access! The only two options are OK or LOG OUT. I can’t click ok because I can’t set the country and reseller. My only option is to click LOG OUT! So now I have to somehow configure via CLI? Also, before I replace the unit currently in place I need to setup side by side to make sure my config is good. This is just another time waster! Thanks Fortinet

    FelixG
    Visitor III
    August 27, 2026

    This is one of the worst design decisions I’ve ever seen a vendor make. We’ve been migrating a fleet of Fortigate VMs to Flexpoint licensing, but just a few weeks into the process, it broke down. Even though the Flex Token is installed and the asset is registered with FortiCloud, it still shows up as „Unregistered with FortiCare“ in Our Manager, preventing further provisioning and configuration.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!