Skip to main content
Pratik2023
New Member
July 17, 2026
Solved

Unable to Add FortiGate Evolution License on FortiGate VM (FFW_VM64_KVM-v8.0.0) Installed in EVE-NG

  • July 17, 2026
  • 5 replies
  • 104 views

Hi everyone,

I have installed the following FortiGate VM image in EVE-NG:

Image: FFW_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvm

After booting the VM, I don't see any option to add or upload an Evolution License during the initial setup.

When I click Cancel on the Add License screen, it immediately returns me to the device login window, and I'm unable to proceed any further.

Has anyone experienced this issue before?

Could you please help me with the following questions:

  • Is this VM image compatible with an Evolution License?
  • How can I upload or activate the Evolution License on this image?
  • Is there any additional configuration required for EVE-NG or the VM before licensing?

I have attached a screenshot of the issue for reference.

Any suggestions or guidance would be greatly appreciated.

 

Best answer by kaman

Hi Pratik2023,
 

The PANIC: double fault with RIP: 0xfff0 is a classic symptom of the CPU trying to execute code from address 0xfff0, the reset vector. This happens when the kernel image is not a valid FortiGate kernel or the boot loader cannot find the correct entry point.
 

The correct filename pattern is: fgt_vm64_kvm-vx.x.x.x-buildxxxx-fortinet.out.kvm.zip
 

https://community.fortinet.com/fortigate-3/troubleshooting-tip-invalid-license-error-during-fortigate-kvm-deployment-132039


Check BIOS security level (if you can get to boot menu). Interrupt the boot process by pressing any key when you see:

please wait for os to boot, or press any key to display configuration menu......


Then:

[i]  -> system information
[u]  -> set security level

Set it to level 1 (or 0 if level 1 still panics):

[1]: level 1 - check image with result only

Then try booting again. If it boots, the issue is BIOS security level 2 rejecting the image signature after the license activation reboot.


Then, verify VM resources (CPU/RAM) via the command 'get system status'


If you have found a solution, please like and accept it to make it easily accessible to others.
 
Regards,
Aman

5 replies

kaman
Staff
Staff
July 18, 2026

Hi Pratik2023,
 

This is a classic wrong-image scenario. This usually occurs because the FortiFirewall VM Image was downloaded instead of the FortiGate VM Image, or the Upgrade Image was downloaded instead of the New Deployment image from the VM Images page under the Support tab at the support.fortinet.com portal.
 

Make sure that the correct image has been downloaded to be used to provision the FortiGate VM. 'FFW' stands for FortiFirewall product and 'FGT' stands for FortiGate product. Refer to this document for more information: https://community.fortinet.com/fortigate-3/technical-tip-fortifirewall-ffw-vs-fortigate-fgt-146709
 

Please refer to the documents below for more information:
 

https://community.fortinet.com/fortigate-3/troubleshooting-tip-license-is-invalid-for-current-vm-configuration-upload-a-new-license-or-reconfigure-the-vm-102882


https://community.fortinet.com/fortigate-3/troubleshooting-tip-invalid-license-error-during-fortigate-kvm-deployment-132039


If you have found a solution, please like and accept it to make it easily accessible to others.
 

Regards,
Aman

Pratik2023
New Member
July 22, 2026

hi Kaman ji,

Thanks for your assistance on issue. kindly check below issue post addition of correct FGT v8.0.0 & credentials for evolution license i’m getting below messages on cli terminal.

 

FortiGate-VM64-KVM # Requesting FortiCare Trial license, proxy:(null)
Requesting FortiCare Trial license, proxy:(null)


The system is going down NOW !!

Please stand by while rebooting the system.
Restarting system
PANIC: double fault, error_code: 0x0
Kernel panic - not syncing: Machine halted.
CPU: 0 PID: 1 Comm: initXXXXXXXXXXX Tainted: P                  4.19.13 #1
Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
Stack:
 <#DF>
 fffffe0000007e88 ffffffffb8ea39ba ffffffffb95dc60b 0000000000000000
 fffffe0000007f08 ffffffffb84f42c2 0000010000000008 fffffe0000007f18
 fffffe0000007eb8 5c4663803bd63200 0000000000000000 ffff933934c32080
 0000000000000000 fffffe0000007e88 ffff933934c32080 0000000000000004
 fffffe0000007f58 0000000000000000 ffff933934c32080 0000000000000000
 fffffe0000007f20 ffffffffb8440833 fffffe0000007f58 fffffe0000007f48
 ffffffffb841817f 0000000000000001 0000000000000000 0000000000000000
 fffffe0000007f59 ffffffffb9000aae 0000000000000000 0000000000000000
 0000000000000000 0000000000000000 0000000000000000 0000000000000000
 0000000000000000 0000000000000000 0000000000000000 0000000000000000
 0000000000000000 0000000000000000 0000000000000623 0000000000000000
 0000000000000000 ffffffffffffffff 000000000000fff0 0000000000000010
 0000000000010002 0000000000000000 0000000000000018
 </#DF>
Call Trace:
 <#DF>
 dump_stack+0x63/0x81
 panic+0xe3/0x263
 df_debug+0x28/0x35
 do_double_fault+0x7b/0x8f
 double_fault+0x1e/0x30
RIP: 0010:0xfff0
Code: Bad RIP value.
RSP: 0018:0000000000000000 EFLAGS: 00010002
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000623 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
 </#DF>
Kernel Offset: 0x38200000 from 0xffffffff80200000 (relocation range: 0xffffffff8                                                                                                             0000000-0xffffffffbfffffff)
Rebooting in 5 seconds..
PANIC: double fault, error_code: 0x0
CPU: 0 PID: 1 Comm: initXXXXXXXXXXX Tainted: P                  4.19.13 #1
Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
RIP: 0010:0xfff0

kaman
Staff
kamanAnswer
Staff
July 22, 2026

Hi Pratik2023,
 

The PANIC: double fault with RIP: 0xfff0 is a classic symptom of the CPU trying to execute code from address 0xfff0, the reset vector. This happens when the kernel image is not a valid FortiGate kernel or the boot loader cannot find the correct entry point.
 

The correct filename pattern is: fgt_vm64_kvm-vx.x.x.x-buildxxxx-fortinet.out.kvm.zip
 

https://community.fortinet.com/fortigate-3/troubleshooting-tip-invalid-license-error-during-fortigate-kvm-deployment-132039


Check BIOS security level (if you can get to boot menu). Interrupt the boot process by pressing any key when you see:

please wait for os to boot, or press any key to display configuration menu......


Then:

[i]  -> system information
[u]  -> set security level

Set it to level 1 (or 0 if level 1 still panics):

[1]: level 1 - check image with result only

Then try booting again. If it boots, the issue is BIOS security level 2 rejecting the image signature after the license activation reboot.


Then, verify VM resources (CPU/RAM) via the command 'get system status'


If you have found a solution, please like and accept it to make it easily accessible to others.
 
Regards,
Aman

Pratik2023
New Member
July 22, 2026

Hi Aman ji,

After wiping out the node, I reconfigured the FortiGate for internet connectivity. I also checked the CPU and RAM, and both are aligned with the required specifications.

However, I'm still facing an issue. I'm able to log in to the FortiGate firewall via the GUI, but after 2–3 seconds, the dashboard automatically redirects me back to the login page.

 

kaman
Staff
Staff
July 23, 2026

Hi Pratik2023,
 

++ Please verify the CPU and memory utilization during the time the issue occurs:
 

get system performance status
dia sys top
dia sys top-mem
dia debug crashlog read
 

++ Please verify the administrator profile and session timeout settings:
 

# Check admin profile timeout settings
show system accprofile

# Check admin user configuration
show system admin

# Check global admin timeout
show full | grep admintimeout


set admintimeout 0     under config system accprofile      <----- Admin session will never be logged out automatically due to inactivity.


Additionally, please review the System Events logs and check for any brute-force lockout
 

Please run the HTTPS debug logs and review the output for any relevant errors or events related to the issue:
 

diagnose debug reset
diagnose debug console timestamp enable
diagnose debug application httpsd -1
diagnose debug application http_authd -1
diagnose debug enable 
 

Please refer to the documents below for more information:
 

https://community.fortinet.com/fortigate-3/technical-tip-gui-login-page-times-out-after-upgrading-to-v7-4-8-or-v7-6-3-with-never-timeout-enabled-on-admin-profile-210318

https://community.fortinet.com/fortigate-3/technical-tip-expected-behavior-on-admin-idle-timeout-142674


Regards,
Aman

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!