FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
SassiVeeran
Staff
Staff
Article Id 225851
Description This article describes the steps required to migrate FortiGate-VM HA pair VM licenses from Evaluation/Trial to production.
Scope To migrate FortiGate-VM evaluation to a VALID license status in HA and Standalone.
Solution

Example migration:

  • (Old unit) FGVM1 and FGVM2 running in Evaluation/Trial license ---->  HA.
  • Migrating to (New unit) FGVM3 and FGVM4 running in VALID license ----> HA.

 

Migrate licenses of FGVM1 and FGVM2 to FGVM3 and FGVM4.

 

vm.png

 

  1. Download the full license from the asset portal. Related document: Download VM License file.
  2. Shut down the FGVM1 and FGVM2 first. Virtual Machine instances should be in a shutdown state for a minimum of 90 minutes so that the existing license details are removed from FortiGuard Servers. This will avoid seeing the 'Duplicate license detected' error message.
  3. Upload the full license to FGVM3 and FGVM4. HA requires that both units have the same license. Therefore, upload the license to both VMs simultaneously.
  4. If the HA Reserved Management Interface is not configured, then the GUI access to the Secondary VM is not possible. Switch to Secondary VM through CLI and upload the license file as mentioned in the articles below: Technical Tip: How to access the secondary unit from the primary with the 'execute ha manage' comman...and Technical Tip: How to upload VM license from CLI via FTP/TFTP server.

   5. Once the upload is completed, the new unit will restart itself. Verify the license status in the new VM as VALID.     

       See Technical Tip: FortiGate-VM License management, validation, and troubleshooting. 

 

Additional Info:

  1. After migrating the license, the new VM will be shown as the old VMs (FGVM1 and FGVM2) in the asset portal. The serial number will carry over to the new VM.
  2. The initial configuration in the new VM will not be affected during license migration.
  3. The Migration can happen across the Deployment Region and is independent of the Availability Zone or Resource group.


Note: The same procedure will work with Standalone and a full license to move between VMS. A user might be able to move the FortiGate VM license between different VMs without any issue. When uploading the new license to the VM, the VM serial number will be the same as the License.