FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
adavila
Staff & Editor
Staff & Editor
Article Id 198217

Description

 
This article explains how to enable encryption on LENC devices when these are in an HA cluster.

 

Scope

 

FortiGate, HA cluster.


Solution

 
The first step is to register the license in the Fortinet Customer Service and Support web portal at support.fortinet.com. This will generate the license key. This step must be repeated for all members in the cluster.

The license keys must then be entered into each device.
 
  1. Using the CLI on the primary device.

 

execute crypto-license <high-encryption-key>

 
  1. Change in the CLI to the secondary device, where <id> is the ID for the other member of the cluster:
 
execute ha manage <id>
 
  1. Enter the key in the secondary device.
 
execute crypto-license <high-encryption-key>
 
  1. (Optional) In order to use deep inspection with strong encryption certificates with more than 512 bits, renew all default certificates.

Follow the steps in Technical Tip: Unable to perform deep inspection after upgrade from LENC to High Encrypt to renew them.