Skip to main content
gaboikari
New Member
February 4, 2026
Solved

Issue installing a VM FortiGate

  • February 4, 2026
  • 4 replies
  • 1189 views

Good day,

 

     I'm trying to install a Fortigate 7.6.6 VM for a lab and have this issue

 

license.jpg

 

    After that I only get a white screen, and enter the trial license window or the device or anything. This is my configuration

 

FortiGate-VM64-KVM (port1) # show
config system interface
edit "port1"
set vdom "root"
set mode dhcp
set distance 1
set allowaccess ping https ssh http
set type physical
set snmp-index 1
next
end

 

FortiGate-VM64-KVM (dns) # show
config system dns
set primary 8.8.8.8
set secondary 8.8.4.4
end

 

FortiGate-VM64-KVM (1) # get
seq-num : 1
status : enable
dst : 0.0.0.0 0.0.0.0
gateway : 10.16.13.20
preferred-source : 0.0.0.0
distance : 1
weight : 0
priority : 1
device : port1

 

This is what I get when I do the 

 

diagnose debug enable diagnose debug application update -1 execute update-now

 


FortiGate-VM64-KVM # execute update-now
upd_daemon[1981]-Received update request from pid=2518

FortiGate-VM64-KVM # do_setup[349]-Starting SETUP
upd_act_setup[126]-Trying Setup, fmg=0
__upd_comm_rcv[990]-data_len=24, pkg(buf=0x7ffdc0de1a9c, sz=8516, pos=0)
__upd_fix_rx_pkg[1009]-Failed, length=24, no res header.
upd_act_setup[137]-Failed receiving setup response, fmg=0, ret=-1
upd_act_setup[149]-Setup failed, fmg=0.
do_setup[353]-SETUP failed
upd_daemon[2157]-Disabling remaining actions 11

 

I can ping the FortiGate Servers without issues

 

FortiGate-VM64-KVM # execute ping service.fortiguard.net
PING guard.fortinet.net (12.34.97.71): 56 data bytes
64 bytes from 12.34.97.71: icmp_seq=0 ttl=52 time=61.2 ms
64 bytes from 12.34.97.71: icmp_seq=1 ttl=52 time=60.6 ms
64 bytes from 12.34.97.71: icmp_seq=2 ttl=52 time=64.6 ms
64 bytes from 12.34.97.71: icmp_seq=3 ttl=52 time=61.1 ms
64 bytes from 12.34.97.71: icmp_seq=4 ttl=52 time=60.6 ms

--- guard.fortinet.net ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 60.6/61.6/64.6 ms

FortiGate-VM64-KVM # execute ping update.fortiguard.net
PING fds1.fortinet.com (12.34.97.16): 56 data bytes
64 bytes from 12.34.97.16: icmp_seq=0 ttl=52 time=61.0 ms
64 bytes from 12.34.97.16: icmp_seq=1 ttl=52 time=60.9 ms
64 bytes from 12.34.97.16: icmp_seq=2 ttl=52 time=60.4 ms
64 bytes from 12.34.97.16: icmp_seq=3 ttl=52 time=60.6 ms
64 bytes from 12.34.97.16: icmp_seq=4 ttl=52 time=60.2 ms

--- fds1.fortinet.com ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 60.2/60.6/61.0 ms

 

My only way to get to the FortiGuard servers is the static route I created

 

FortiGate-VM64-KVM # get router info routing-table database
Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP
O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
V - BGP VPNv4
> - selected route, * - FIB route, p - stale info

Routing table for VRF=0
S *> 0.0.0.0/0 [1/0] via 10.16.13.20, port1, [1/0]
C *> 10.16.13.0/24 is directly connected, port1

 

I can't seem to find how to solve the issue. Tried forcing the Fortiguard update interface to the port1 and the issue is the same.

 

FortiGate-VM64-KVM # get system status
Version: FortiGate-VM64-KVM v7.6.6,build3652,260127 (GA.M)
First GA patch build date: 240724
Current Security Level: High
Firmware Signature: certified
Virus-DB: 1.00000(2018-04-09 18:07)
Extended DB: 1.00000(2018-04-09 18:07)
Extreme DB: 1.00000(2018-04-09 18:07)
AV AI/ML Model: 0.00000(2001-01-01 00:00)
IPS-DB: 6.00741(2015-12-01 02:30)
IPS-ETDB: 6.00741(2015-12-01 02:30)
IPS-MLDB: 0.00000(2001-01-01 00:00)
APP-DB: 6.00741(2015-12-01 02:30)
AIAP-DB: 0.00000(2001-01-01 00:00)
Proxy-IPS-DB: 6.00741(2015-12-01 02:30)
Proxy-IPS-ETDB: 6.00741(2015-12-01 02:30)
Proxy-APP-DB: 6.00741(2015-12-01 02:30)
FMWP-DB: 0.00000(2001-01-01 00:00)
IPS Malicious URL Database: 1.00001(2015-01-01 01:01)
IoT-Detect: 0.00000(2022-08-17 17:31)
OT-Detect-DB: 0.00000(2001-01-01 00:00)
OT-Patch-DB: 0.00000(2001-01-01 00:00)
OT-Threat-DB: 6.00741(2015-12-01 02:30)
IPS-Engine: 7.01168(2025-11-19 22:41)
Timezone DB Version: 1.003
Timezone DB IANA Version: 2024a
Serial-Number: FGVMEVTMBHEDF96B
License Status: Invalid
VM Resources: 1 CPU/1 allowed, 1993 MB RAM/2048 MB allowed
Log hard disk: Available
Hostname: FortiGate-VM64-KVM
Operation Mode: NAT
Current virtual domain: root
Max number of virtual domains: 2
Virtual domains status: 1 in NAT mode, 0 in TP mode
Virtual domain configuration: disable
FIPS-CC mode: disable
Current HA mode: standalone
Branch point: 3652
Release Version Information: GA
FortiOS x86-64: Yes
System time: Wed Feb 4 13:26:58 2026
Last reboot reason: warm reboot

 

    I read some months back that restarting some daemons solve the issue but can't seem to find the documentation. If someone knows hot to solve the issue and can help me I'll appreciate it

 

 

Best answer by magliano

@gaboikari Oh, okay, I understand. This might be helpful then.

 

https://docs.fortinet.com/document/fortigate/7.6.6/administration-guide/441460

4 replies

magliano
Staff
Staff
February 5, 2026

Hello @gaboikari ,

 

Could you please try this KB? https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-stucks-in-Validating-License-screen/ta-p/242654

 

It may help with the issue you are experiencing.

 

Best regards,

gaboikari
gaboikariAuthor
New Member
February 5, 2026

Good day @magliano 

 

    I checked that KB before and tried this step

 

config system fortiguard

    set interface-select-method specify (the default option is auto)

    set interface <WAN-interface>

end

 

     And didn't work. The rest of the steps are not for me because I can reach the DNS and I don't use a proxy. I read several forums and did several steps without any solution, even deleted the machine and installed it again in another platform and the result is the same. I used VMWare and KMV and the error is the same in both cases.

magliano
Staff
Staff
February 5, 2026

@gaboikari  Thanks for the information. Two things come to mind:

  1. Could you please check this KB? https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-VM-License-management-validation-and/ta-p/197019

  2. It’s also possible that the license is for a VM with fewer vCPUs and less memory than what is currently configured.

Best regards

gaboikari
gaboikariAuthor
New Member
February 5, 2026

Hello @magliano ,

 

     FortiGate 7.6.6 requires at least 1 vCPU and 2GB RAM, less than that and gives an error via console saying that doesn't have enough ram. I have the minimum requiered and since is version 7.6.6 it doesn't have the 15 day trial license, I'm trying to create a trial license in my account but I need first that the device connect to the cloud with my credentials so it can autoregister the license

 

Imagen CPU Fortigate.jpg 

magliano
Staff
maglianoAnswer
Staff
February 5, 2026

@gaboikari Oh, okay, I understand. This might be helpful then.

 

https://docs.fortinet.com/document/fortigate/7.6.6/administration-guide/441460

gaboikari
gaboikariAuthor
New Member
February 5, 2026

Hello @magliano ,

 

     Thanks for the answer, that helped.

 

ss.jpg

magliano
Staff
Staff
February 5, 2026

Nice, happy to help @gaboikari 

HameMoradi
New Member
March 3, 2026

Hello @magliano,

Hope you are doing well.

I can ping service.fortiguard.net & update.fortiguard.net from my VM but I got the below error while trying to get the "Failed to download VM license"

 

FortiGate-VM64-KVM # diagnose hardware sysinfo vm full
UUID: cb043e9ab9cb479b9988a081d0f948e7
valid: 0
status: 3
code: 502
warn: 0
copy: 0
received: 4294940603
warning: 4294940603
recv:
dup:

FortiGate-VM64-KVM # diagnose debug vm-print-license
SerialNumber: FGVMEVV-B1Y9LB9A
CreateDate: Tue Mar 3 10:14:34 2026
Model: EVAL (1)
CPU: 1
MEM: 2048
VDOM license:
permanent: 2
subscription: 0


FortiGate-VM64-KVM # execute vm-license
This VM is using the evaluation license. This license does not expire.
Limitations of the Evaluation VM license include:
1.Support for low encryption operation only
2.Maximum of 1 CPU and 2GiB of memory
3.Maximum of three interfaces, firewall policies, and routes each
4.No FortiCare Support
This operation will reboot the system !
Do you want to continue? (y/n)y

Failed to download VM license.

FortiGate-VM64-KVM # execute ping service.fortiguard.net
PING guard.fortinet.net (173.243.138.91): 56 data bytes
64 bytes from 173.243.138.91: icmp_seq=0 ttl=44 time=158.8 ms
64 bytes from 173.243.138.91: icmp_seq=1 ttl=44 time=157.7 ms
^C
--- guard.fortinet.net ping statistics ---
2 packets transmitted, 2 packets received, 0% packet loss
round-trip min/avg/max = 157.7/158.2/158.8 ms

FortiGate-VM64-KVM # execute ping update.fortiguard.net
PING fds1.fortinet.com (12.34.97.16): 56 data bytes
64 bytes from 12.34.97.16: icmp_seq=0 ttl=55 time=99.6 ms
64 bytes from 12.34.97.16: icmp_seq=1 ttl=55 time=99.5 ms
64 bytes from 12.34.97.16: icmp_seq=2 ttl=55 time=100.4 ms
^C
--- fds1.fortinet.com ping statistics ---
3 packets transmitted, 3 packets received, 0% packet loss
round-trip min/avg/max = 99.5/99.8/100.4 ms

 

Thank you!