Skip to main content
Dhruvin_patel
Staff
Staff
September 23, 2025

Troubleshooting Tip: 'No Subscription' displayed for the FortiGate in FortiGate Cloud portal despite an active entitlement

  • September 23, 2025
  • 0 replies
  • 922 views
Description This article describes an issue where a FortiGate device displays a 'No Subscription' status and provides read-only access in the FortiGate Cloud portal. In addition, FortiGate Cloud Log Retention may appear as a Free License on the FortiGate despite a valid entitlement being present. This behavior may occur after an entitlement is transferred from one FortiGate device to another.
Scope FortiGate Cloud.
Solution

The entitlement has been transferred after the RMA from the replaced device to the new device.

 

Entitlement example:

 

Entitlement_ FG100FTK21048354.PNG

 

The portal shows that the FortiGate Cloud service on the FortiGate will expire in December 2028; however, the FortiGate displays the license type as Basic instead of Paid.

 

diagnose test application forticldd 2

Server: log-controller, task=0/10, watchdog is off
Domain name: globallogctrl.fortinet.net
Address of log-controller: 1
173.243.132.25:443
Source IP: 0.0.0.0
Source IP6: [::]
Statistics: total=19, discarded=0, sent=19, last_updated=451619 secs ago
http connection: is not in progress
Current address: 173.243.132.25:443
Source IP: 0.0.0.0:0
Calls: connect=57, rxtx=77
Current tasks number: 0
Account: name=xyz@gmail.com, status=200, type=basic
Current volume: 0B
Current tasks number: 0
Update timer fires in 19548 secs
Daily volume reset timer fires in 43658 secs

 

As a first step, run the following command on the FortiGate to refresh the license status, and then kill the fgfmd process to recreate the tunnel between the FortiGate and FortiGate Cloud.

 

diagnose fdsm contract-controller-update
fnsysctl killall fgfmd

 

Afterwards, check the license type using the command (diagnose test application forticldd 2).

 

If the FortiGate still shows the same issue, run the following commands to receive updates from FortiGuard.

 

diagnose debug reset

diagnose debug application update -1

diagnose debug console time enable
diagnose debug enable
execute update-now

 

Wait for five minutes to receive updates from FortiGuard, and then press Ctrl + C and enter diagnose debug disable to stop the debugs.

 

Recheck the license type. If the above steps do not resolve the issue, open a ticket with TAC to have the device license manually synchronized with FortiGate Cloud. There is a known issue with FortiCare where license change notifications may fail to be sent, which can prevent the updated entitlement from being reflected correctly.

Once the license has been manually synchronized, run the CLI command 'execute fortiguard-log update' to manually trigger an update and refresh the FortiGate Cloud log retention license status on FortiGate.

 

Related article:

Technical Tip: FortiCompanion to RMA Services

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!