FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pkumari
Staff
Staff
Article Id 344350
Description This article describes the license validation for FortiGate virtual machine (VM) appliances in air-gap environments.
Scope FortiGate-VM appliances.
Solution

FortiGate-VM licenses have a 30-day license timeout period, and if the license can not be validated within that time, the VM will stop working as a firewall. The license status will change before the timeout occurs and the license status is shown as invalid.

 

Error: VM license shows as invalid.

In any case, if a FortiGate-VM is in an airgap environment (without internet access), it can not validate against a FortiManager or FortiGuard server. Its license status will become invalid in 30 days.

 

To resolve the invalid issue, the FortiGate-VM has to connect with the FortiGuard server or FortiManager (if used for FortiGuard updates) for license validation.

 

Once connected with FortiManager or FortiGuard for license validation, it can initiate updates manually as below.

 

diagnose debug reset

diagnose debug application update -1

execute update-now

diagnose debug enable

 

To stop the debug:

 

diagnose debub disable

diagnose debub reset

 

Validate the license from CLI using 'get system fortiguard-service status'.

 

Note:

Manual licensing for air-gap environments is supported only on FortiGate hardware appliances. Manual licensing is currently not supported on FortiGate virtual machine (VM) appliances.