Dedicated activation FQDNs for VM licensing 7.4.10
The default behavior has changed: when anycast is enabled, VM license activation now uses dedicated activation FQDNs instead of general update FQDNs, resulting in faster and more reliable activation.
FortiGate use the following new FQDNs while anycast is enabled:
-
vmactivation1.fortinet.net -
vmactivation2.fortinet.net -
vmactivation3.fortinet.net
FortiGate has no change and still use the old FQDN while anycast is disabled:
-
update/uspdate/eupdate.fortiguard.net
FortiGate standalone is able to validate VM license with the new, separate FDS FQDN while anycast is enabled:
FGT-ESXi-REGR # diagnose debug application cloudinitd -1 Debug messages will be on for 30 minutes. FGT-ESXi-REGR # diagnose hardware sysinfo vm setup UUID: 4213dbbc94f2520b0d75eeafe1b319c7 FGT-ESXi-REGR # vmlic status:success, valid:1 vmlic load config vmlic setup vfid:0 vmlic resolve:vmactivation1.fortinet.net vmlic server:192.168.100.85 vmlic resolve:vmactivation2.fortinet.net vmlic resolve:vmactivation3.fortinet.net vmlic add 192.168.100.85 vmlic setup 192.168.100.85 vmlic connect harelay:0 [222] ssl_add_ftgd_hostname_check: Add hostname checking 'vmactivation1.fortinet.net' Protocol=3.0|Command=VMSetup|Firmware=FGVM64-FW-7.04-2865|SerialNumber=FGVMSLTM26090025|Connection=Internet|Address=172.16.200.74:0|Language=en-US|TimeZone=-8|UpdateMethod=1|Uid=4213dbbc94f2520b0d75eeafe1b319c7|VMPlatform=VMWARE pkg size:280 Protocol=3.0|Response=200|Firmware=FPT033-FW-6.10-0152|SerialNumber=FDS-200-vm|Server=FDSG|Persistent=false|PEER_IP=172.18.64.64|Geolocation=DUBAI-APAC vmlic setup result:200 FGT-ESXi-REGR # get system status Version: FortiGate-VM64 v7.4.10,build2865,260110 (interim) ... Serial-Number: FGVMSLTM26090025 License Status: Valid License Expiration Date: 2027-01-10 VM Resources: 2 CPU, 3946 MB RAM
FortiGate standalone is able to validate VM license with the legacy FDS FQDN while anycast is disabled:
FGT-ESXi-REGR # diagnose debug application cloudinitd -1 Debug messages will be on for 30 minutes. FGT-ESXi-REGR # vmlic status:success, valid:1 vmlic load config vmlic setup vfid:0 vmlic resolve:update.fortiguard.net vmlic server:192.168.100.205 vmlic add 192.168.100.205 vmlic setup 192.168.100.205 vmlic connect harelay:0 [219] ssl_add_ftgd_hostname_check: Add hostname checking 'update.fortiguard.net'... Protocol=3.0|Command=VMSetup|Firmware=FGVM64-FW-7.04-2865|SerialNumber=FGVMSLTM26090025|Connection=Internet|Address=172.16.200.74:0|Language=en-US|TimeZone=-8|UpdateMethod=1|Uid=4213dbbc94f2520b0d75eeafe1b319c7|VMPlatform=VMWARE pkg size:272 Protocol=3.0|Response=200|Firmware=FPT033-FW-6.10-0320|SerialNumber=FDS-VM-INTERNAL02|Server=FDSG|Persistent=false|PEER_IP=172.18.64.64 vmlic setup result:200