Is there a way to successfully perform periodic license validation on FortiVM without setting the default route to the Internet?
Due to certain circumstances, I need to permanently set the default route to the LAN side. However, when I do this, the license validation fails.
I assumed that as long as the FortiGate could reach FortiGuard servers and resolve their names, it would be fine. So I added static routes for the following destinations to enable connectivity.
・service.fortiguard.net
・update.fortiguard.net
・guard.fortinet.net
Ping to those destinations succeeded.
Currently, the license validation only succeeds when the default route is set to the Internet.
Is there any way to resolve this issue?
Software Version:7.4.7
Every license should have entitlement file for the license, you can upload it manually to the forti.
You should be able to install the entitlement file from forticloud or request it from the support team.
I have already uploaded the license file, but the FortiGate should still periodically perform license validation with FortiGuard.
If the validation fails a certain number of times, some features become restricted.
I want to know how to prevent this when there is no default route to the Internet.
You are correct, my apologies
the only official solution to that is using fortimanager as a licensing server.
"In closed environments without internet access, you must license the FortiGate-VM offline using a FortiManager as a license server. If the FortiGate-VM cannot validate its license within the 30-day license timeout period, the FortiGate discards all packets, effectively ceasing operation as a firewall."
so seems like you have only 2 options at the moment.
But, I'd suggest contacting TAC just to make sure there is nothing else to do in the matter.
| User | Count |
|---|---|
| 2803 | |
| 1425 | |
| 812 | |
| 750 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.