FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
RBA
Staff
Staff
Article Id 391962
Description This article describes an issue related to the logical Serial Number feature not working on FortiGate 100F/101F.
Scope FortiGate-100F/101F v7.2.8 and prior versions.
Solution

Logical SN is enabled under HA config as per the CLI Reference guide: config system ha.

 

config system ha
...
    set logical-sn enable
...
end

 

By default, the setting is logical-sn disable.

 

However, the feature would not work as expected: The license would not be reflected on the FortiGate.

 

The command 'get system ha status’ output does not reflect the logical Serial Number.

 

diagnose debug disable
diagnose debug reset
diagnose debug app update -1
diagnose debug enable
execute update-now

 

Enabling the above debugs would generate the following logs.

 

upd_act_HA_contract_info[739]-Error updating FSCI -1
No valid cluster key as logical-sn is enabled.
No valid cluster key as logical-sn is enabled.

 

To disable debug:

 

diagnose debug disable

diagnose debug reset

 

The feature was originally implemented in v6.2.0 but was disabled due to errors. The command would still appear; however feature is disabled.

The support was added back in v7.2.9; however, 100F and 101F do not support the feature yet. This is added as a known issue in v7.2.9 and a known issue in v7.2.10.

This known issue with ID 1137565 for 10xF models, where the logical-sn command is missing and is fixed in versions 7.2.12 (expected release in the first week of September 2025), v7.4.8, and v7.6.3. Refer to the release notes for further information.

 

Note:

If the FortiGate can not be upgraded to the fixed FortiOS version due to a license issue, as shown in the screenshot below, here are the steps to resolve this issue:

 

Capture.JPG

 

  1. Disassociate the FortiGate with the VSN SN. It looks like this: FG100FHA25004166. From the FortiCloud portal, use the "Dismiss HA" button to try to remove the VSN, or if needed, open a ticket with CS. CS will help to de-register the FortiGate in question.
  2. Upgrade the firmware to the GA build, which has the fix, and ensure that the logical-sn is properly configured under the HA setting.
  1. By this point, FortiGate can be re-registered again and form the VSN.

 

Related article:

Single FortiGuard license for FortiGate A-P HA cluster - FortiGate 7.4.8 administration guide