Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
EhsRjb
New Contributor

New FortiOS on EVE-NG

Hello there,

We have a couple of challenges in deploying FortiGate and FortiWeb on EVE-NG Community in the Lab. As you know, the current exam version is based on FortiOS 7.6 and this renewing is probably going to continue, which means we have to get ready for next versions.

 

The problem is:

1. When we download FortiGate 7.6.4 & 7.6.3, both version looks incompatible with EVE-NG on VMWare workstation (25H2 and 17.5) and Hyper-V. The former hangs in "Formating shared partition and the later hangs in a stage ahead (somewhere logging about IPS..... ). Some folks advised using V7.2.x or... . But, this is not the answer I'm looking for. Same problem with last to versions of Fortiweb.

 

2. As you all may knows, Fortinet has made changes in licensing policies. Reports says V7.6 needs a valid license even for lab setup. This makes the case a little complicated, because we could use a 2-months Eval license before. If your recommend is to raise a ticket and asking for Evaluation license, I sadly must disagree and say: we need more than one node in the setup, at least 2 of each appliance for different designs at the same time (Exp, Core and Edge Firewall or different WAF for 2 separate segment of network).

 

Please share your idea and experiences.

 

EhsRjb
EhsRjb
3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Anthony-Fortinet Community Team.
Jean-Philippe_P
Community Manager
Community Manager

Hello EhsRjb,

 

I found this document. Can you tell us if it helps, please?

 

FortiGate & FortiWeb 7.6.x Deployment Challenges on EVE-NG Community

 

 

1. Compatibility & Boot Issue

Both FortiGate 7.6.3 and 7.6.4 display instability within EVE-NG Community—especially when nested under VMware Workstation (25H2/17.5) or Hyper-V. The common symptoms include:

  • Stuck at the message “Formatting shared partition” (7.6.4)
  • Hanging during IPS subsystem initialization or system logging steps (7.6.3)

 

These issues are caused by FortiOS 7.6’s increased dependency on KVM-level hardware flags and UEFI-based images, which the nested Workstation/Hyper‑V KVM environment used by EVE‑NG Community doesn’t fully emulate.

 

Workarounds:

  • Use EVE-NG Professional or a direct bare-metal KVM deployment to access the full QEMU capabilities (e.g., qemu 7.x with virtio-scsi).
  • In Community builds, try forcing legacy BIOS boot with --machine pc-i440fx-4.2 or --machine q35,accel=kvm in the .eve-ng/images/QEMU/fortios-7.6x/ definition, and convert disks with:
qemu-img convert -f qcow2 -O qcow2 fortios.qcow2 fortios-fixed.qcow2  
  • Use QEMU 7.2+ backend with ‘virtio-net-pci’ NIC type instead of e1000.
  • FortiWeb 7.6 requires virtio-scsi with legacy BIOS mode; switching to e1000 NICs prevents full initialization.
  • Known stable builds for lab emulation: FortiGate 7.4.3 and FortiWeb 7.4.2 still boot reliably within the EVE-NG Community stack.

 

If nested virtualization is necessary, Proxmox with nested KVM proves more consistent than VMware+EVE combinations for these images.

 

2. Licensing Model Changes in FortiOS 7.6

FortiOS 7.6 enforces license validation even in lab environments. Evaluation licenses remain available but are now per-node and expire after 15–30 days. This restriction affects FortiGate‑VM and FortiWeb‑VM equally.

 

Notable constraints:

  • Manual offline licenses are supported only on hardware units up to 7.2–7.4. 7.6 requires active validation via FortiManager or FortiCloud for VMs.
  • Offline or air‑gapped lab deployment is possible only when FortiManager is configured as an internal FortiGuard proxy. You can re‑use one validated evaluation license for multiple nodes if they check in via the same FortiManager instance.
  • FortiManager can cache and distribute the same signature and entitlement records to other FortiGates, simulating multi‑node licensing for lab purposes without requesting multiple evals.

 

 

3. Recommended Lab Setup Strategy

To avoid individual license requests and image hangs:

  • Host an internal FortiManager‑VM with valid evaluation (central authentication + FortiGuard proxy). Attach multiple FortiGates and FortiWeb VMs to it.
  • Run EVE‑NG Professional or migrate lab topology to Proxmox, which supports nested‑KVM flags required by FortiOS 7.6.
  • Keep test topology within FortiOS 7.4.x for now if dynamic feature labs (Active/Passive clustering, VDOMs, or WAF segmentation) are needed.
  • For future versions (e.g., 7.8+), expect continued dependency on UEFI virtualization and FortiCare back-end licensing.

 

Follow‑Up Options

If you intend to sustain a multi‑node environment without license limits, explore subscription tiers of FortiGate‑VMxxV (offline licenses available upon request through Fortinet Sales for training environments). Also, GNS3 or Proxmox‑based KVM configurations remain more stable than nested EVE‑NG Community for FortiOS 7.6+ images.

 

Key takeaway: FortiOS 7.6 virtualization builds now require full KVM/UEFI support and active license validation—so EVE‑NG Community nested under VMware is not a sustainable platform for future exam or lab preparation. Centralized FortiManager licensing or migration to Proxmox is the most resilient approach.

Regards,
Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors