Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
anonymous2124
New Contributor

License Verification for FortiVM without Internet

Is there a way to successfully perform periodic license validation on FortiVM without setting the default route to the Internet?


Due to certain circumstances, I need to permanently set the default route to the LAN side. However, when I do this, the license validation fails.

I assumed that as long as the FortiGate could reach FortiGuard servers and resolve their names, it would be fine. So I added static routes for the following destinations to enable connectivity.
・service.fortiguard.net
・update.fortiguard.net
・guard.fortinet.net
Ping to those destinations succeeded.

 

Currently, the license validation only succeeds when the default route is set to the Internet.
Is there any way to resolve this issue?
Software Version:7.4.7

3 REPLIES 3
Shyy
New Contributor II

Every license should have entitlement file for the license, you can upload it manually to the forti.
You should be able to install the entitlement file from forticloud or request it from the support team.

anonymous2124

I have already uploaded the license file, but the FortiGate should still periodically perform license validation with FortiGuard.

If the validation fails a certain number of times, some features become restricted.

I want to know how to prevent this when there is no default route to the Internet.

Shyy
New Contributor II

You are correct, my apologies 

the only official solution to that is using fortimanager as a licensing server.

 

"In closed environments without internet access, you must license the FortiGate-VM offline using a FortiManager as a license server. If the FortiGate-VM cannot validate its license within the 30-day license timeout period, the FortiGate discards all packets, effectively ceasing operation as a firewall."

so seems like you have only 2 options at the moment.
But, I'd suggest contacting TAC just to make sure there is nothing else to do in the matter.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors