Description | This article describes the license validation for FortiGate virtual machine (VM) appliances in air-gap environments. |
Scope | FortiGate-VM appliances. |
Solution |
FortiGate-VM licenses have a 30-day license timeout period, and if the license can not be validated within that time, the VM will stop working as a firewall. The license status will change before the timeout occurs and the license status is shown as invalid.
Error: VM license shows as invalid. In any case, if a FortiGate-VM is in an airgap environment (without internet access), it can not validate against a FortiManager or FortiGuard server. Its license status will become invalid in 30 days.
To resolve the invalid issue, the FortiGate-VM has to connect with the FortiGuard server or FortiManager (if used for FortiGuard updates) for license validation.
Once connected with FortiManager or FortiGuard for license validation, it can initiate updates manually as below.
diagnose debug reset diagnose debug application update -1 execute update-now diagnose debug enable
To stop the debug:
diagnose debub disable diagnose debub reset
Validate the license from CLI using 'get system fortiguard-service status'.
Note: Manual licensing for air-gap environments is supported only on FortiGate hardware appliances. Manual licensing is currently not supported on FortiGate virtual machine (VM) appliances. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.