FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
atahir
Staff
Staff
Article Id 336811
Description

This article describes how to use the FortiManager VM Trial license and how to add FortiGate without a Serial Number.

Scope

FortiManager, FortiGate.

Solution

With a FortiCare account, users can receive a free trial license for a FortiManager virtual machine (VM) to try the product. After evaluating the product, users or organizations can purchase an add-on license and upgrade the FortiManager VM.

 

Requirements:

  1. The FortiManager VM must be running FortiManager 7.0.0 or later.
  2. The user must have access to a device with a browser to access the FortiManager GUI.
  3. The user must have internet access to connect to FortiCloud and the FortiCare account on the Technical Support Site and to receive the license agreement.

License agreement:

The user must accept the terms of the license agreement before activating the trial license.

 

The FortiManager VM trial license includes:

  1. Support to add three devices/VDOMs.
  2. Support to use two ADOMs.

The FortiManager VM with a trial license does not support:

  1. FortiAnalyzer features.
  2. FortiGuard subscriptions.
  3. The built-in FortiGuard Distribution Server (FDS).

 

Error message: 

 

FGFMs(probing...): __get_handler: serial number (FG81FPTK21000047) in 'get' message doesn't match the subject CN (FG81FPTK21000454) or SAN in peer's certificate, exit.

 

How to enable the option to accept FortiGate to FortiManager (FGFM) without the peer certificate  or serial number (SN):

To accept FortiGate to FortiManager (FGFM) connections even when the peer certificate does not have a serial number (SN) or does not match (HA Pair), use the following commands on the FortiManager:

 

config sys global

    set fgfm-peercert-withoutsn (enable | disable)

 

  • disable: The peer's certificate must include a serial number in the subject CN or SAN.
  • enable: The peer's certificate might not include a serial number in the subject CN or SAN.

While adding the device from FortiManager, on the FortiGate CLI, the user should run the following command:

Forcing FortiGate to send an authorization request:

 

exec central-mgmt register-device <FMG S/N> <FGT password>

 

Related articles: