Internet traffic blocked when FortiGuard/UTM license expires – fail-open or fail-closed behavior?
Hello, I would like to clarify the expected FortiGate behavior when a FortiGuard/UTM license expires. Our FortiGate 81F had a UTM contract that expired on August 6, 2026. A new license contract was purchased/renewed on Friday, but the new contract has not yet been activated. After the previous contract expired, Internet traffic through one of our existing firewall policies was blocked. Basic websites could not be accessed. The affected firewall policy had the following security profiles enabled: - AntiVirus - Web Filter - DNS Filter - Application Control - IPS - File Filter When we disabled these security profiles, Internet connectivity immediately returned to normal. Fortinet Customer Service stated in the support ticket: “internet connectivity will not be affected due to the absence of a license.” They also stated that basic firewall policies that do not rely on subscription-based security services should continue to function. Therefore, I would like to understand the technical behavior: 1. Which specific FortiGuard security profile can cause a firewall policy to stop forwarding traffic when its license expires? 2. When a licensed security profile becomes unavailable because the license has expired, is the expected behavior fail-open or fail-closed? 3. If the expected behavior is fail-open, why would traffic be blocked in this situation? 4. Is there a FortiOS configuration or documented behavior that explains why disabling the security profiles restores Internet connectivity? FortiGate model: 81F The relevant security profiles are shown in the attached screenshot. We are not asking how to use expired FortiGuard services without a license. We are trying to understand why basic Internet connectivity was interrupted while waiting for the newly renewed contract to become active. Thank you.

