Licensing in air-gap environments
In the Operational Technology industry, industrial equipment is critical and must not be connected to the Internet. However, the equipment is still required to be protected by a firewall in this air-gap environment. Without a gateway to FortiGuard in air-gap environments, FortiGuard packages, such as AntiVirus and IPS, must be manually uploaded to the FortiProxy. FortiProxy licenses can be downloaded from FortiCloud and uploaded manually to the FortiProxy.
To manually upload FortiProxy licenses in the GUI:
-
Register the FortiGuard license on FortiCloud. See FortiCloud documentation for more information.
-
Download the product entitlement file in FortiCloud:
-
Go to Products > Product List.
-
Select the serial number of the FortiProxy. The product page opens.
-
In the License & Key section, click Get The License File. The file downloads to your device in the format
FPX*************.lic
.
-
-
In FortiProxy, go to System > FortiGuard.
-
Click Upload License File. The file explorer opens.
-
Navigate to the product entitlement file and click Open.
The license file uploads to the FortiProxy. Once the upload is complete, the FortiProxy shows that it is registered and licensed.
-
Click Apply.
To manually upload FortiProxy licenses in the CLI:
# execute restore manual-license {ftp | tftp} <license file name> <server> [args]