FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
DPadula
Staff
Staff
Article Id 273173
Description This article describes that FortiGate keeps showing the message 'Requires FortiAnalyzer Cloud entitlement'.
Scope FortiGate v6.4.4 and higher.
Solution

Make sure to have the FortiAnalyzer Cloud license activated on the FortiCloud portal; the SOCaaS license is optional as per below:

 

Step 1: 

Go to https://support.fortinet.com/ and log in using the username and password.

 

Step 2:

Go to Product -> My Assets, search for the serial number to check the licenses, and select the device's serial number.

 

portal.JPG

 

Step 3:

The Entitlement box will show the active and valid licenses (green check mark).

 

Entitlement.png

 

As the FortiAnalyzer Cloud is based on a level account license, it is possible to check from the FortiGate CLI:

 

diag test update info

 

Screenshot 2024-07-31 195623.png

 

Note:

  • To have the FortiAnalyzer Cloud available for configuration, make sure to use a firmware version higher than v6.4.4. Otherwise, it will not be possible to select the 'FortiAnalyzer Cloud' option. The screenshot below is from a FortiGate running version v6.2.15, not compatible with FortiAnalyzer Cloud services. 
  • FortiGate series 30E and 50E do not support firmware versions higher than v6.2.x. 

 

Fortigate30e-FortiAnalyzerIssue.bmp

 

If FortiGates are in HA (High Availability mode), it is necessary to have FortiAnalyzer Cloud Entitlement on both FortiGates in HA configuration. If only one peer has entitlement and the other one does not, the cloud logging will not function as desired.