Fortinet white logo
Fortinet white logo

Administration Guide

Licensing in air-gap environments

Licensing in air-gap environments

In the Operational Technology industry, industrial equipment is critical and must not be connected to the internet. However, the equipment is still required to be protected by a firewall in this air-gap environment. Without a gateway to FortiGuard in air-gap environments, FortiGuard packages, such as AntiVirus and IPS, must be manually uploaded to the FortiGate. FortiGate licenses can be downloaded from FortiCloud and uploaded manually to the FortiGate.

Note

Manual licensing for air-gap environments is supported on FortiGate hardware appliances and FortiGate virtual machine (VM) appliaces running FortiOS 7.2.0 or later. When running on a Virtual appliance, the VM licensing still needs to connect to a licensing FortiManager or FortiGuard server. See VM license for details

To manually upload FortiGate licenses in the GUI:
  1. Register the FortiGuard license on FortiCloud. See Registration for more information.

  2. Download the product entitlement file in FortiCloud:

    1. Go to Products > Product List.

    2. Select the serial number of the FortiGate. The product page opens.

    3. In the License & Key section, click Get The License File. The file downloads to your device in the format FG201E*********ProductEntitlement.lic.

  3. In FortiOS, go to System > FortiGuard. Currently, the status for all services is Pending.

  4. Click Upload License File. The file explorer opens.

  5. Navigate to the product entitlement file and click Open.

    The license file uploads to the FortiGate. This operation does not require reboot. Once the upload is complete, the FortiGate shows that it is registered and licensed.

  6. Click Apply.

To manually upgrade the AntiVirus Database in the GUI:
  1. Download the static upgrade file from FortiCloud:

    1. Go to support.fortinet.com.

    2. Go to Download > Download FortiGuard Service Updates > FortiGate.

    3. Select the FortiOS version from the OS Version dropdown.

    4. Select the file from the appropriate FortiGate product model section. The file downloads to your device.

  2. In FortiOS, go to System > FortiGuard and expand the AntiVirus section to view the current licenses.

  3. Click Upgrade Database. The Anti-Virus Database Upgrade pane opens.

  4. Click Upload. The file explorer opens.

  5. Navigate to the static upgrade file and click Open.

  6. Click OK.

  7. Click Apply.

    The AntiVirus Database is upgraded.

To manually upload FortiGate licenses in the CLI:
# execute restore manual-license {ftp | tftp} <license file name> <server> [args]

Licensing in air-gap environments

Licensing in air-gap environments

In the Operational Technology industry, industrial equipment is critical and must not be connected to the internet. However, the equipment is still required to be protected by a firewall in this air-gap environment. Without a gateway to FortiGuard in air-gap environments, FortiGuard packages, such as AntiVirus and IPS, must be manually uploaded to the FortiGate. FortiGate licenses can be downloaded from FortiCloud and uploaded manually to the FortiGate.

Note

Manual licensing for air-gap environments is supported on FortiGate hardware appliances and FortiGate virtual machine (VM) appliaces running FortiOS 7.2.0 or later. When running on a Virtual appliance, the VM licensing still needs to connect to a licensing FortiManager or FortiGuard server. See VM license for details

To manually upload FortiGate licenses in the GUI:
  1. Register the FortiGuard license on FortiCloud. See Registration for more information.

  2. Download the product entitlement file in FortiCloud:

    1. Go to Products > Product List.

    2. Select the serial number of the FortiGate. The product page opens.

    3. In the License & Key section, click Get The License File. The file downloads to your device in the format FG201E*********ProductEntitlement.lic.

  3. In FortiOS, go to System > FortiGuard. Currently, the status for all services is Pending.

  4. Click Upload License File. The file explorer opens.

  5. Navigate to the product entitlement file and click Open.

    The license file uploads to the FortiGate. This operation does not require reboot. Once the upload is complete, the FortiGate shows that it is registered and licensed.

  6. Click Apply.

To manually upgrade the AntiVirus Database in the GUI:
  1. Download the static upgrade file from FortiCloud:

    1. Go to support.fortinet.com.

    2. Go to Download > Download FortiGuard Service Updates > FortiGate.

    3. Select the FortiOS version from the OS Version dropdown.

    4. Select the file from the appropriate FortiGate product model section. The file downloads to your device.

  2. In FortiOS, go to System > FortiGuard and expand the AntiVirus section to view the current licenses.

  3. Click Upgrade Database. The Anti-Virus Database Upgrade pane opens.

  4. Click Upload. The file explorer opens.

  5. Navigate to the static upgrade file and click Open.

  6. Click OK.

  7. Click Apply.

    The AntiVirus Database is upgraded.

To manually upload FortiGate licenses in the CLI:
# execute restore manual-license {ftp | tftp} <license file name> <server> [args]