FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Renante_Era
Staff
Staff
Article Id 299369
Description This article describes how to fix an issue where the FortiGate license/subscription is not updating.
Scope FortiGate, FortiOS.
Solution
  1. Verify that the FortiGates are in an HA cluster.

get system ha status

 

  1. Confirm that the cluster member licenses/subscriptions were renewed.
  2. Ensure that both device were able to reach FortiGuard.

exec ping update.fortiguard.net

exec ping service.fortiguard.net

exec update-now

 

  1. View the Dashboard and confirm whether the license was updated. If necessary, fail-over to the secondary device and execute update-now.


exec ha manage 1 <username>.

exec update-now

 

Note:

  • If the above command didn't work, use exec ha manage 0 <username>.
  • Make sure both FortiGates are running the same FortiOS firmware version.
  • All FortiGates in the cluster must have the same level of licensing for FortiGuard, FortiCloud, FortiClient, and VDOMs. FortiToken licenses can be added at any time because they are synchronized with all cluster members.
  • Ensure that not only the FortiGates have Internet connection but public hostnames especially the FortiGuard FQDN's can also be resolved by the DNS servers configured.