FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dsrivastava
Staff
Staff
Article Id 240941
Description This article describes features that work, even if the Fortigate has never had the subscription in the first place.
Scope

VM FortiGate has a license check, which is unrelated to the FortiGuard subscription.

This license check requires non-stop online communication with the FortiGuard servers.
The VM FortiGate will stop working completely, if it cannot reach FortiGuard servers for a long time (30 days usually), unless using a special, offline license.

Solution

Security rules.

The FortiGate will continue filtering traffic according to the Security Rulebase.

- All kinds of NAT: SNAT, DNAT, VIP, dynamic pools, etc.
- VPN - all types, IPSec site-to-site, Remote Access as SSL VPN in web mode, and full tunnel with FortiClient and as IPSec client.
- IPS with the signatures last updated before the subscription expired. That is, IPS will continue working, but new signatures will not be downloaded.
- AppControl using the signatures last updated before the subscription expired.
- Web/URL Filtering using static allow/block lists. Without a subscription, the firewall cannot query FortiGuard for URL web ratings, so Web filtering using Fortiguard assigned Categories will not work. But if the static block/allows URL lists, it will work. Also blocking ActiveX controls will work too.
- All types of interfaces: physical, VLANs, Virtual Wire, Loopbacks, LAGs, redundant, Zones.
- Security rules modes: proxy and flow. All modes of proxy mode will work: Explicit, Transparent.
- SSL/SSH inspection - certificate and deep packet inspection.
- Applying UTM in both: Policy based and Profile based modes.
- VDOMs.
- High Availability (HA).
- QOS.
- SD-WAN feature, including AppControl integration (but see above about Application Control signature updates).
- WAF with the signatures last updated before the subscription expired.
- VIP of load balancing type.
- DoS/DDoS protection rules.
- Device inventory.
- Access Point controller.
- FortiSwitch management.
- All types of logging, Netflow/sFlow export.
- GRE and VXLAN traffic encapsulation.
- VRFs, if supported by FortiOS version.
- One-arm sniffer.
- Static, all dynamic protocol, and Policy Based routing.
- All types of authentication: local, LDAP, Radius, Tacacs, SAML, MFA.
- SNMP.
- DHCP server.
- Internet Service Database (ISDB).
- External Threat Feeds.
- VOIP protections and profiles.
- Configuration version revisions.
- DLP.