Skip to main content
asengar
Staff
Staff
July 25, 2023

Technical Tip: How to update the license for FortiGate in Transparent mode without internet (offline)

  • July 25, 2023
  • 0 replies
  • 59351 views

Description

 

This article describes how to update the license offline when there is no internet access to the FortiGate.

 

Scope

 

FortiGate v7.2.0 and above.

 

Solution

 

  • When the firewall is operated in the Transparent mode in the network and only used for Intranet traffic as a switch to inspect and forward the traffic, so without internet connectivity, the license update or the FortiGuard database update is not possible automatically.

  • Below 7.2.0, internet access was mandatory for updating the license, or it was done with the help of FortiManager (no manual update).

  • From v7.2.0 and later, it is possible to download the offline license for the hardware device by logging into the support portal.

  • V7.4.0 and later show an error message firmware image cannot be installed because the device's FortiGuard License for firmware upgrades could not be verified and may have expired. Verify or renew the license to install the upgrade. 


Steps to Download the Offline License File:

 

  1. To obtain the licensing file, access the Fortinet Support.

  2. Once logged into the portal, Go to Services -> Asset Management. On the dashboard, the assets information will be displayed. Select the FortiGate.

    10.png

 

  1. Once selecting FortiGate, the list of firewalls in the network will appear along with the serial number product details.

  2. Select the serial number of the device that needs to download the license file.

11.png


  1. In the license and key section, select Get the license file, the license file will be downloaded in the format .lic with the device serial number FGT******947Off-NetworkLicenseFile.lic.

  2. Once the .lic file is downloaded upload the file in the FortiGate.

  3. In FortiGate go to System -> FortiGuard -> Manual update -> Upload the file downloaded. 

  4. Initially, the services will be showing as pending and once the file is uploaded successfully it will change to licensed and registered for FortiCare support. To manually upload the license from CLI, use the following command:


execute restore manual-license {ftp | tftp} <license file name> <server>


Important: This procedure should be performed during a maintenance window, as a firewall reboot may be required to synchronize the license file.

Note:

The manual offline license upload is only available for hardware models in v7.2. With v7.4, this is Uploading the FortiGate-VM license.

If the firmware of the firewall is below v7.2.0, this is not feasible, so it is necessary to upgrade the device to v7.2.0, follow the upgrade path, and then follow the same procedure.

 

Related articles:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!