Technical Tip: FortiGate license activation fails with response code 401 when FortiManager acts as local FortiGuard
| Description | This article describes the issue when FortiGate Auto-Scalling gets error 401 when it is necessary to validate the license from FortiManager (FortiManager acts as a local FDS). |
| Scope | FortiGate, AWS, FortiManager. |
| Solution | FortiGate -> (local FDS) FortiManager -> FortiGuard.
When FortiGate is in Auto-Scaling, if one goes down for whatever reason, the auto-scaling mechanism will automatically build a brand new FortiGate, using the same license that was being used by the one that went down.
However, when FortiGate 1 is down and FortiGate 2 is up, FortiManager acts as a Local FDS and fails to validate the license.
diagnose fmupdate view-linkd-log fds [FMG-->FDS] Request: Protocol=3.0|Command=VMSetup|Firmware=FGVMA6-FW-7.02-1688|SerialNumber=FGVM01TMXXXXXXX|Connection=Internet|Address=XX.XX.1.41:0|Language=en-US|TimeZone=8|UpdateMethod=1|Uid=ec23382ab2273e8f28a14XXXXXXXXXXXX|VMPlatform=AWS^M ^M [FDS-->FMG] Response: Protocol=3.0|Response=200|Firmware=FPT033-FW-6.9-0233|SerialNumber=FPT-FDS-PLA1-005|Server=FDSG|Persistent=false|PEER_IP=XX.XX.56.45^M ^M FCP_CONN:: received package ready check_vmlic: Received a new instance but current one is valid. serial:FGVM01TM25XXXXXX old_uid:ec23834ff0d573fd6a58ed31XXXXXXX, new_uid:ec23382ab2273e8f28a14bbdXXXXXXXX
The 401 error is likely due to a duplicated license from deploying the FortiGate on VM#1 and then VM#2 shortly after. This scenario results in the FortiGuard server having records of both VM UUIDs.
Related document: Validating the FortiGate-VM license with FortiManager on an air-gapped environment.
This behavior occurs if FortiManager acts as local FortiGuard.
Two workarounds can be performed to avoid the license error 401.
|
