Yuri Slobodyanyuk Blog on Information Security 2024年07月23日
Fortigate free VM Evaluation License is now permanent, not limited to 15 days, here is how to get it.
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Fortinet在FortiOS 7.2.1版本中移除了内置的15天免费评估许可证,改为永久评估许可证,但仍免费。获取方式变更,需创建免费Forticare/FortiCloud账户,并在Fortigate GUI内激活。新许可证存在限制,如安全规则、路由数量、接口数量等。

🔧 FortiOS 7.2.1版本的Fortigate VM镜像不再内置15天免费评估许可证,改为永久评估许可证,用户需创建Forticare/FortiCloud账户激活。

📛 新许可证带来限制:安全规则从5减少到3,路由数量限制为3,接口数量最多3个,包括禁用或下线的接口以及Loopback接口。

🔐 每个FortiCloud账户只能拥有一个评估许可证,若需多个,需创建多个账户。其他限制如CPU、内存等仍适用。

🔗 Fortigate VM需互联网访问以激活许可证,或通过Fortimanager操作。管理Web GUI现在支持https访问。

🚧 若激活评估许可证时遇到问题,可执行命令如ping、get sys stat等诊断,确保网络可达性和DNS解析正确。

Starting with FortiOS 7.2.1, Fortinet removed built-in 15 days free evaluationlicense from the Fortigate VM images. It was replaced with the permanentevaluation license, still free. The steps to get it have changed - you nowhave to create a free Forticare/FortiCloud account, and use it inside theFortigate GUI to activate this evaluation license. The license will be generatedand added to your Forticloud account automatically.

Unfortunately, there are new limitations as well:

    Security Rules: the limit is 3, instead of 5.

    Number of routes: the limit is also 3, while was unlimited before. This means severe limiting of dynamic protocols labs like OSPF/BGP. Currently (FortiOS 7.2.1) , though, there is no actual enforcement of this limit - I configured BGP and few static routes, 6 all in all, and it worked without any issue.

    Number of interfaces: maximum 3, was unlimited. This counts also interfaces that are in state disabled/down. And on top of it, it also counts Loopback interfaces as well.

    One license per one FortiCloud account: this means that to have multiple evaluation licenses for multiple Fortigates, we need to create multiple FortiCloud accounts, nuisance but doable. The accounts are still free of charge.

    The rest of limitations: additional limitations (CPU/Memory/etc.) that were present in 15 days license, are still enforced as well. See the reference at the bottom for details.

    Internet access: Fortigate VM has to have Internet access to activate the license. The alternative is having Fortimanager to do so.

    Let’s Encrypt Certificates - even though, we have now normal encryption for admin https access, the ACME daemon for provisioning SSL/TLS certificates willnot run.

Now, to the visual guide of how to issue this free evaluation license for yourvirtual Fortigate.

BTW: The only addition (and not subtraction) in this new evaluation licensing is that we can nowaccess management web GUI of the Fortigate via regular https not only http asbefore.

First, download VM image for your virtualization platform, as usual:

Then install it as before. I did it in the VMWare Workstation here. On the 1stboot we can see that the license status is invalid:

Next step is to login to the Fortigate GUI. We will be presented with this page,where we can enter the Forticare/FortiCloud account. The account does not haveto be a paying account, the free account is enough.

Upon clicking OK, the Fortigate will contact Fortiguard servers, and willissue itself a license automatically. Here is the license status after thesuccessful activation:

Debug if something goes wrong

You can get various error messages trying to activate the evaluation license,like Error downloading license: Invalid serial number, or Failed to downloadVM license. There can be few reasons for that:

    This Fortigate VM does not have access to the Internet.

    The Fortigate VM cannot resolve correctly via DNS Fortiguard-related domains.

    You are trying to register the Fortigate VM with the Forticare/Forticloud account that already has another evaluation registered to it.

    Finally, not frequently, but happens that FortiGuard servers are having areachability issues, and you need to wait and try later.

To diagnose these problems, you may run the following commands:

exe ping service.fortiguard.net, exe ping update.fortiguard.net to verifyDNS resolving and Internet accessibility.

get sys stat, diagnose debug vm-print-license to see the current licensestatus on the Fortigate. The valid license output will look like:

FGT-7-2-4 # diagnose debug vm-print-licenseSerialNumber: FGVMEV_ATFDMNL66CreateDate: Sun Nov  6 12:27:13 2022UUID: 564d5a668795856cbd9d9b2939a7eff8Key: yesCert: yesKey2: yesCert2: yesModel: EVAL (1)CPU: 1MEM: 2048VDOM license:  permanent: 2  subscription: 0

diagnose hardware sysinfo vm full to see the license status as the FortiGuardservers see it:

FGT-7-2-4 # diagnose hardware sysinfo vm fullUUID:     564d5a668795856cbd9d9b2939a7eff8valid:    1status:   1code:     0warn:     0copy:     0received: 5330050190warning:  4294940124recv:     202303060746dup:

execute vm-license, exe update now to re-initiate process of requesting the license. Onsuccess will show:

FGT-7-2-4 # execute vm-licenseTrial license exists.

Resources:

Follow me on https://www.linkedin.com/in/yurislobodyanyuk/ not to miss what Ipublish on Linkedin, Github, blog, and more.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

FortiOS Fortigate 评估许可证 FortiCloud 网络安全
相关文章