| Solution | FortiGate-VM permanent licenses are no longer available for purchase as of September 29, 2025, although FortiGuard services and support can still be renewed. The last service extension date is September 29, 2029. See Product Life Cycle. An existing FortiGate device with a permanent VM license can be migrated to a subscription (s-series) BYOL using either the Device Migration or License Migration method below. Subscription BYOL FortiGate-VM SKUs include both the device and service entitlements and contain 'FGVVS' in their name, for example, 'FC2-10-FGVVS-814-12-02'. For more details on available SKUs, see the FortiGate-VM datasheet matching the hosting platform, such as FortiGate®-VM on Linux KVM.
When planning a migration, schedule a maintenance window and review the Expected changes and Considerations below.
Expected changes: - The device serial number changes.
- Built-in local certificates such as Fortinet_Factory, Fortinet_Factory_Backup, and Fortinet_SSL are regenerated with a new private key.
- The subscription period begins when the service entitlement is registered to FortiCloud. Entitlements registered to the old serial number are not carried over to the new serial number.
- Although the firmware version remains the same, devices with different license types cannot form an HA cluster.
- S-series devices do not include additional VDOM licenses by default. If a device has more VDOMs than supported by the device's licensing, all traffic VDOMs other than 'root' will be disabled until a subscription for additional VDOMs is applied to the device. See this article: Troubleshooting Tip: FortiGate VM stops passing traffic when a new VDOM is created.
Considerations for determining migration method: - Device Migration is the more flexible and easily reversible of the two methods.
- License Migration is the simpler method. However, it is more difficult to reverse: taking a VM snapshot is strongly recommended to allow recovery in case the migration is not successful.
- If no downtime is permitted, use the Device Migration method and deploy the new device in advance, with different IP addresses. Validate that the new device is operational and create a coherent cutover plan to move existing traffic over to the new device.
- If using the License Migration method to apply the new license to the same instance, a VM snapshot is essential to allow recovery in case the migration is not successful.
- The s-series and permanent license types cannot form an FGCP HA cluster with each other. When migrating an HA cluster, care must be taken to isolate or shut down devices as necessary to avoid HA split-brain, a condition that can otherwise cause serious degradation in traffic handling and device management. See this article: Technical Tip: High availability split brain.
- Regardless of the method used, the FortiGate device reboots when applying a new license, and must validate the new license with FortiGuard or a connected FortiManager device before it can pass data traffic.
Device migration: - Take a full configuration backup of the old device using a super_admin account, see Configuration backups and reset.
- Deploy a new VM with the new license on the same firmware version, see VM. Do not use the same IP addresses
- Shut down the old device.
- If relevant, associate the old device's IP addresses, networks, and routing to the new device using tools provided by the Public or Private Cloud platform.
- Restore the configuration backup taken from the old device.
Note: If the platform has TPM support, the old device may have private-data-encryption enabled previously, see TPM support for FortiGate-VM. If this feature was previously enabled, enter the master-encryption-password on the new device before restoring the production device's configuration. License Migration: - Go to the Support site Asset Management Portal and log in to the intended FortiCloud account. The asset will be registered to this account.
- Select 'Register More' and enter the Contract Registration Code from the Service Registration Document. This creates the device's serial number.
- Open the new serial number in the product list and download the license file from the support portal.
- Take a VM snapshot or checkpoint of the existing device. This is critical to allow recovery if an issue is encountered during migration. This may require shutting down the device.
- Upload the new subscription license directly to the existing device in Dashboard -> Status -> Select Virtual Machine Widget -> Select FortiGate VM License -> Upload the license file.

- Select OK and confirm. The device reboots.

- Allow the FortiGate to validate the license against a remote FortiGuard server. This requires internet access; see this document, VM license.
- The first time the unit boots after the new S-series license is applied, only one CPU is activated. This is expected. After the license is validated, reboot the device again to activate the subscribed number of CPUs.
 A note on PAYG licensing: Some public cloud platforms, including AWS, Azure, and GCP, offer FortiGate Virtual Machines with 'on-demand' or 'Pay as you go' (PAYG) licensing, which is different from the BYOL s-series (subscription license). The licensing cost for on-demand instances is included as part of the instance cost. For example, see the FortiGate Public Cloud Administration Guides, such as Order Types for AWS. These platforms also support BYOL licensing, similar to private cloud hosting solutions. However, the on-demand/PAYG license type is not compatible with the BYOL license type- it is not possible to migrate a virtual machine between them. |