Description
This article explains how to enable encryption on LENC devices when these are in an HA cluster.
Scope
FortiGate, HA cluster.
Solution
The first step is to register the license in the Fortinet Customer Service and Support web portal at support.fortinet.com. This will generate the license key. This step must be repeated for all members in the cluster.
The license keys must then be entered into each device.
- Using the CLI on the primary device.
execute crypto-license <high-encryption-key>
- Change in the CLI to the secondary device, where <id> is the ID for the other member of the cluster:
execute ha manage <id>
- Enter the key in the secondary device.
execute crypto-license <high-encryption-key>
- (Optional) In order to use deep inspection with strong encryption certificates with more than 512 bits, renew all default certificates.
Follow the steps in Technical Tip: Unable to perform deep inspection after upgrade from LENC to High Encrypt to renew them.