Migrating FortiAnalyzer-VM licenses
You can apply a VM subscription license (VM-S) on top of an existing FortiAnalyzer-VM license, allowing you to migrate your FortiAnalyzer-VM (perpetual) to the VM-S (subscription) model. FortiAnalyzer will use the new license's serial number and notify all connected FortiGate models of the change.
Alternatively, you can migrate an existing subscription license to a perpetual license using the same process.
To migrate a license:
-
Download your new subscription license file from FortiCare, which includes the new serial number.
-
In the FortiAnalyzer-VM CLI, run the following command:
execute migrate serial-number-list <new serial number>
After running the command, OFTP will automatically restart.
-
After a short wait, run the following command in the FortiAnalyzer CLI to ensure that each FortiGate is connected to the FortiAnalyzer.
diagnose test application oftpd 3
-
Install the new license file through the FortiAnalyzer GUI.
FortiAnalyzer will automatically reboot once the license file has been added.
-
After the FortiAnalyzer reboots, use the following CLI commands on FortiAnalyzer to verify that FortiGate devices are able to connect and send logs, and check that the new serial number and license information has been migrated on FortiAnalyzer.
diagnose test application oftp 3
diagnose debug vminfo
get system status
Example: migrating a FortiAnalyzer-VM license to VM-S
-
Download the new subscription license file from FortiCare, which includes the new serial number.
In this example, the old serial number is FAZ-VMTM20012786 and the new serial number is FAZVMSTM21002251.
-
On the FortiAnalyzer-VM currently using a perpetual license, run the following command to migrate to the new serial number:
FAZVM64 # execute migrate serial-number-list FAZVMSTM21002251
After execute migrate serial number list, oftpd will restart!
Do you want to continue? (y/n)y
-
After a short wait, run the following command in the FortiAnalyzer CLI to ensure that each FortiGate is connected to the FortiAnalyzer.
FAZVM64 # diagnose test application oftpd 3
# SN HOSTNAME IP UPTIME IDLETIME #PKTS
--------------------------------------------------------------------------------
1 FGVMSLTM21000399 FortiGate-VM-213 10.4.90.213 2s 2s 2
2 FGVMSLTM21000416 FortiGate-VM-214 10.4.90.250 3s 2s 6
3 FGVMSLTM21000398 FortiGate-VM-212 10.4.90.212 8s 8s 3
4 FGVMSLTM21000399 FortiGate-VM-213 10.4.90.213 9s 9s 5
5 FGVMSLTM21000417 FortiGate-VM-215 10.4.90.250 9s 4s 7
6 FEVM040000218711 mail01 10.4.90.250 23s 23s 1
7 FGVMSLTM21000399 FortiGate-VM-213 10.4.90.213 2s 1s 4
8 FGVMSLTM21000416 FortiGate-VM-214 10.4.90.250 3s 3s 3
9 FGVMSLTM21000398 FortiGate-VM-212 10.4.90.212 8s 3s 7
10 FGVMSLTM21000399 FortiGate-VM-213 10.4.90.213 9s 9s 3
11 FGVMSLTM21000417 FortiGate-VM-215 10.4.90.250 9s 9s 3
12 FGVMSLTM21000416 FortiGate-VM-214 10.4.90.250 9s 9s 3
-
Install the new VM-S license file through the FortiAnalyzer GUI.
FortiAnalyzerwill automatically reboot once the license file has been added.
-
After the FortiAnalyzer reboots, use the following CLI commands on FortiAnalyzer to verify that FortiGate devices are able to connect and send logs, and check that the new serial number and VM license information has been migrated to VM-S on FortiAnalyzer.
FAZVM64 # diagnose test app oftp 3
FAZVM64 # diagnose debug vminfo
FAZVM64 # get system status