Fortinet white logo
Fortinet white logo

New Features

Dedicated activation FQDNs for VM licensing 7.4.10

Dedicated activation FQDNs for VM licensing 7.4.10

The default behavior has changed: when anycast is enabled, VM license activation now uses dedicated activation FQDNs instead of general update FQDNs, resulting in faster and more reliable activation.

FortiGate use the following new FQDNs while anycast is enabled:

  • vmactivation1.fortinet.net

  • vmactivation2.fortinet.net

  • vmactivation3.fortinet.net

FortiGate has no change and still use the old FQDN while anycast is disabled:

  • update/uspdate/eupdate.fortiguard.net

FortiGate standalone is able to validate VM license with the new, separate FDS FQDN while anycast is enabled:

FGT-ESXi-REGR # diagnose debug application cloudinitd -1
Debug messages will be on for 30 minutes.

FGT-ESXi-REGR # diagnose hardware sysinfo vm setup
UUID:     4213dbbc94f2520b0d75eeafe1b319c7

FGT-ESXi-REGR # vmlic status:success, valid:1
vmlic load config

vmlic setup vfid:0
vmlic resolve:vmactivation1.fortinet.net
vmlic server:192.168.100.85
vmlic resolve:vmactivation2.fortinet.net
vmlic resolve:vmactivation3.fortinet.net
vmlic add 192.168.100.85

vmlic setup 192.168.100.85
vmlic connect harelay:0
[222] ssl_add_ftgd_hostname_check: Add hostname checking 'vmactivation1.fortinet.net'
Protocol=3.0|Command=VMSetup|Firmware=FGVM64-FW-7.04-2865|SerialNumber=FGVMSLTM26090025|Connection=Internet|Address=172.16.200.74:0|Language=en-US|TimeZone=-8|UpdateMethod=1|Uid=4213dbbc94f2520b0d75eeafe1b319c7|VMPlatform=VMWARE
pkg size:280
Protocol=3.0|Response=200|Firmware=FPT033-FW-6.10-0152|SerialNumber=FDS-200-vm|Server=FDSG|Persistent=false|PEER_IP=172.18.64.64|Geolocation=DUBAI-APAC
vmlic setup result:200

FGT-ESXi-REGR # get system status
Version: FortiGate-VM64 v7.4.10,build2865,260110 (interim)
...
Serial-Number: FGVMSLTM26090025
License Status: Valid
License Expiration Date: 2027-01-10
VM Resources: 2 CPU, 3946 MB RAM

FortiGate standalone is able to validate VM license with the legacy FDS FQDN while anycast is disabled:

FGT-ESXi-REGR # diagnose debug application cloudinitd -1
Debug messages will be on for 30 minutes.

FGT-ESXi-REGR # vmlic status:success, valid:1
vmlic load config

vmlic setup vfid:0
vmlic resolve:update.fortiguard.net
vmlic server:192.168.100.205
vmlic add 192.168.100.205

vmlic setup 192.168.100.205
vmlic connect harelay:0

[219] ssl_add_ftgd_hostname_check: Add hostname checking 'update.fortiguard.net'...
Protocol=3.0|Command=VMSetup|Firmware=FGVM64-FW-7.04-2865|SerialNumber=FGVMSLTM26090025|Connection=Internet|Address=172.16.200.74:0|Language=en-US|TimeZone=-8|UpdateMethod=1|Uid=4213dbbc94f2520b0d75eeafe1b319c7|VMPlatform=VMWARE
pkg size:272
Protocol=3.0|Response=200|Firmware=FPT033-FW-6.10-0320|SerialNumber=FDS-VM-INTERNAL02|Server=FDSG|Persistent=false|PEER_IP=172.18.64.64
vmlic setup result:200

Dedicated activation FQDNs for VM licensing 7.4.10

Dedicated activation FQDNs for VM licensing 7.4.10

The default behavior has changed: when anycast is enabled, VM license activation now uses dedicated activation FQDNs instead of general update FQDNs, resulting in faster and more reliable activation.

FortiGate use the following new FQDNs while anycast is enabled:

  • vmactivation1.fortinet.net

  • vmactivation2.fortinet.net

  • vmactivation3.fortinet.net

FortiGate has no change and still use the old FQDN while anycast is disabled:

  • update/uspdate/eupdate.fortiguard.net

FortiGate standalone is able to validate VM license with the new, separate FDS FQDN while anycast is enabled:

FGT-ESXi-REGR # diagnose debug application cloudinitd -1
Debug messages will be on for 30 minutes.

FGT-ESXi-REGR # diagnose hardware sysinfo vm setup
UUID:     4213dbbc94f2520b0d75eeafe1b319c7

FGT-ESXi-REGR # vmlic status:success, valid:1
vmlic load config

vmlic setup vfid:0
vmlic resolve:vmactivation1.fortinet.net
vmlic server:192.168.100.85
vmlic resolve:vmactivation2.fortinet.net
vmlic resolve:vmactivation3.fortinet.net
vmlic add 192.168.100.85

vmlic setup 192.168.100.85
vmlic connect harelay:0
[222] ssl_add_ftgd_hostname_check: Add hostname checking 'vmactivation1.fortinet.net'
Protocol=3.0|Command=VMSetup|Firmware=FGVM64-FW-7.04-2865|SerialNumber=FGVMSLTM26090025|Connection=Internet|Address=172.16.200.74:0|Language=en-US|TimeZone=-8|UpdateMethod=1|Uid=4213dbbc94f2520b0d75eeafe1b319c7|VMPlatform=VMWARE
pkg size:280
Protocol=3.0|Response=200|Firmware=FPT033-FW-6.10-0152|SerialNumber=FDS-200-vm|Server=FDSG|Persistent=false|PEER_IP=172.18.64.64|Geolocation=DUBAI-APAC
vmlic setup result:200

FGT-ESXi-REGR # get system status
Version: FortiGate-VM64 v7.4.10,build2865,260110 (interim)
...
Serial-Number: FGVMSLTM26090025
License Status: Valid
License Expiration Date: 2027-01-10
VM Resources: 2 CPU, 3946 MB RAM

FortiGate standalone is able to validate VM license with the legacy FDS FQDN while anycast is disabled:

FGT-ESXi-REGR # diagnose debug application cloudinitd -1
Debug messages will be on for 30 minutes.

FGT-ESXi-REGR # vmlic status:success, valid:1
vmlic load config

vmlic setup vfid:0
vmlic resolve:update.fortiguard.net
vmlic server:192.168.100.205
vmlic add 192.168.100.205

vmlic setup 192.168.100.205
vmlic connect harelay:0

[219] ssl_add_ftgd_hostname_check: Add hostname checking 'update.fortiguard.net'...
Protocol=3.0|Command=VMSetup|Firmware=FGVM64-FW-7.04-2865|SerialNumber=FGVMSLTM26090025|Connection=Internet|Address=172.16.200.74:0|Language=en-US|TimeZone=-8|UpdateMethod=1|Uid=4213dbbc94f2520b0d75eeafe1b319c7|VMPlatform=VMWARE
pkg size:272
Protocol=3.0|Response=200|Firmware=FPT033-FW-6.10-0320|SerialNumber=FDS-VM-INTERNAL02|Server=FDSG|Persistent=false|PEER_IP=172.18.64.64
vmlic setup result:200