Fortinet black logo

Administration Guide

Importing FDS package and license file via FortiManager in an offline or air-gapped network

Copy Link
Copy Doc ID 36a93e95-602f-11eb-b9ad-00505692583a:7183
Download PDF

Importing FDS package and license file via FortiManager in an offline or air-gapped network

This topic shows how to download and import a FortiDeceptor license in an offline or air-gapped network using FortiManager.

When FortiManager is operating in a closed network, you can create a support ticket to request account entitlement files from Fortinet Customer Service & Support for devices, and then upload the files to FortiGuard. This allows devices in the closed network to check licenses.

To request the FortiDeceptor entitlement license file for FortiManager:
  1. Log into Customer Service and Support.
  2. Go to Assistance > Create a Ticket.
  3. Expand Customer Service and click Submit Ticket.
  4. Enter the required information.
    • For Subject, enter Entitlement file.
    • For Category, select CS Contract/License.
  5. Complete and submit the ticket.
  6. When you receive the entitlement file via email, download it to your computer.

Without a connection to a FortiGuard server, update packages and licenses must be manually downloaded from support, and then uploaded to FortiManager.

To upload the FortiDeceptor entitlement license file to FortiManager:
  1. In FortiManager, go to FortiGuard > Settings.
  2. Set Enable Communication with FortiGuard Server to OFF so that you can configure FortiManager as a local FDS server.
  3. In the Upload Options for FortiGate/FortiMail section, click Upload besides Service License.

    Enable Communication with FortiGuard Server

    Toggle OFF to disable communication with FortiGuard servers.

    Enable AntiVirus and IPS Service

    Toggle ON to enable antivirus and intrusion protection service.

    When on, select the versions of FortiGate, FortiClient, FortiAnalyzer, and FortiMail to download updates.

    Enable Web Filter Service

    Toggle ON to enable web filter services. When uploaded to FortiManager, the web filter database displays.

    AntiVirus/IPS Packages

    Click Upload to upload antivirus and IPS packages you downloaded from the Customer Service & Support portal.

    Web Filter Database

    Click Upload to upload the web filter database you downloaded from the Customer Service & Support portal. As the database can be large, uploading with CLI is recommended.

    Service License

    Click Upload to import the FortiGate license.

    You can get a license file from support by requesting your account entitlement for the device.

To configure FortiDeceptor to use FortiManager for FortiGuard services:
  1. Go to System > FortiGuard.
  2. In the FortiGuard Server Settings section, select Use override FDN server to download module updates and enter the FortiManager IP address.
  3. In the FortiGuard Web Filter Settings section, select Use override server for web filtering query (address or address:port) and enter the FortiManager IP address.
  4. In the FortiGuard Server Settings section, click Connect FDN Now to test the FDN connection.

  5. If the test passes, click Apply.

Importing FDS package and license file via FortiManager in an offline or air-gapped network

This topic shows how to download and import a FortiDeceptor license in an offline or air-gapped network using FortiManager.

When FortiManager is operating in a closed network, you can create a support ticket to request account entitlement files from Fortinet Customer Service & Support for devices, and then upload the files to FortiGuard. This allows devices in the closed network to check licenses.

To request the FortiDeceptor entitlement license file for FortiManager:
  1. Log into Customer Service and Support.
  2. Go to Assistance > Create a Ticket.
  3. Expand Customer Service and click Submit Ticket.
  4. Enter the required information.
    • For Subject, enter Entitlement file.
    • For Category, select CS Contract/License.
  5. Complete and submit the ticket.
  6. When you receive the entitlement file via email, download it to your computer.

Without a connection to a FortiGuard server, update packages and licenses must be manually downloaded from support, and then uploaded to FortiManager.

To upload the FortiDeceptor entitlement license file to FortiManager:
  1. In FortiManager, go to FortiGuard > Settings.
  2. Set Enable Communication with FortiGuard Server to OFF so that you can configure FortiManager as a local FDS server.
  3. In the Upload Options for FortiGate/FortiMail section, click Upload besides Service License.

    Enable Communication with FortiGuard Server

    Toggle OFF to disable communication with FortiGuard servers.

    Enable AntiVirus and IPS Service

    Toggle ON to enable antivirus and intrusion protection service.

    When on, select the versions of FortiGate, FortiClient, FortiAnalyzer, and FortiMail to download updates.

    Enable Web Filter Service

    Toggle ON to enable web filter services. When uploaded to FortiManager, the web filter database displays.

    AntiVirus/IPS Packages

    Click Upload to upload antivirus and IPS packages you downloaded from the Customer Service & Support portal.

    Web Filter Database

    Click Upload to upload the web filter database you downloaded from the Customer Service & Support portal. As the database can be large, uploading with CLI is recommended.

    Service License

    Click Upload to import the FortiGate license.

    You can get a license file from support by requesting your account entitlement for the device.

To configure FortiDeceptor to use FortiManager for FortiGuard services:
  1. Go to System > FortiGuard.
  2. In the FortiGuard Server Settings section, select Use override FDN server to download module updates and enter the FortiManager IP address.
  3. In the FortiGuard Web Filter Settings section, select Use override server for web filtering query (address or address:port) and enter the FortiManager IP address.
  4. In the FortiGuard Server Settings section, click Connect FDN Now to test the FDN connection.

  5. If the test passes, click Apply.