Fortinet black logo

Administration Guide

Licensing

Licensing

FortiPAM platforms work in evaluation mode until licensed.

In the evaluation mode:

  1. A maximum of 2 users are allowed; a default Super Administrator and an additional user.
  2. You can log in to the firewall VIP using https.
  3. The evaluation license expires after 15 days.
  4. All the features are available. You can create secret and launch secrets for a target server.
  5. FortiPAM does not have a valid serial number.
  6. No FortiCare support is available.

FortiPAM configured with less than 2 CPUs and 2048 MB of RAM works in the evaluation mode until licensed. Otherwise, a valid license is required.

DLP is available for secret launching only when you have a valid Advanced Malware Protection (AVDB & DLP) license.

Registering and downloading your license

After placing an order for FortiPAM-VM, a license registration code is sent to the email address used in the order form. Use the license registration code provided to register the FortiPAM-VM with FortiCloud.

Upon registration, download the license file. You will need this file to activate your FortiPAM-VM. You can configure basic network settings from the CLI to complete the deployment. Once the license file is uploaded, the CLI and GUI are fully functional.

  1. Go to FortiCloud and create a new account or log in with an existing account.

    The Asset Management portal opens.

  2. On the Asset Management portal, click Register Now to register FortiPAM.
  3. Provide the registration code:
    1. Enter a registration code.
    2. Choose your end user type as either a government or non-government user.
    3. Click Next.
  4. The Fortinet Product Registration Agreement page displays. Select the check box to indicate that you have read, understood, and accepted the service contract. Click Next.
  5. The Verification page displays. Select the checkbox to indicate that you accept the terms. Click Confirm.

    Registration is now complete and your registration summary is displayed.

  6. On the Registration Complete page, download the license file (.lic) to your computer.

    You will upload this license to activate the FortiPAM-VM as shown in Uploading the license file to FortiPAM-VM.

Note: After registering a license, Fortinet servers can take up to 30 minutes to fully recognize the new license. When you upload the license file to activate the FortiPAM-VM, if you get an error that the license is invalid, wait 30 minutes and try again.

When FortiPAM is initially deployed, it is in evaluation mode. Once you have downloaded the license (.lic) file from FortiCloud, you must load the .lic file to FortiPAM so that FortiPAM has a valid serial number.

Uploading the license file to FortiPAM-VM

There are two methods to upload the license file to FortiPAM-VM.

To upload the license via the FortiPAM-VM GUI:

You must be in maintenance mode to be able to upload a license. See Maintenance mode in Admin.

  1. Log in to FortiPAM-VM from a browser.

    Access FortiPAM by using the IP address configured on FortiPAM port1.

    The Upload License File pane appears immediately after you log in.

    If FortiPAM is in evaluation mode, go to Dashboard > Status, click the Virtual Machine widget, and click FortiPAM VM License.

    Use the https prefix with the FortiPAM IP address to access the FortiPAM-VM GUI.

  2. In the Upload License File pane, select Upload and browse to the license file on your management computer.
  3. Click OK.
  4. After the boot up, the license status changes to valid.

    Use the CLI command get system status to verify the license status.

To upload the license through the public IP address using SCP:

Use the following command:

scp <license_file> admin@<public_ip_address>:vmlicense

For example:

$ scp FPAVULTM23000007.lic admin@52.52.143.64:vmlicense

admin@52.52.143.64's password:

FPAVULTM23000xxx.lic 100% 9128 344.0KB/s 00:00

100-install VM license completed

Licensing

FortiPAM platforms work in evaluation mode until licensed.

In the evaluation mode:

  1. A maximum of 2 users are allowed; a default Super Administrator and an additional user.
  2. You can log in to the firewall VIP using https.
  3. The evaluation license expires after 15 days.
  4. All the features are available. You can create secret and launch secrets for a target server.
  5. FortiPAM does not have a valid serial number.
  6. No FortiCare support is available.

FortiPAM configured with less than 2 CPUs and 2048 MB of RAM works in the evaluation mode until licensed. Otherwise, a valid license is required.

DLP is available for secret launching only when you have a valid Advanced Malware Protection (AVDB & DLP) license.

Registering and downloading your license

After placing an order for FortiPAM-VM, a license registration code is sent to the email address used in the order form. Use the license registration code provided to register the FortiPAM-VM with FortiCloud.

Upon registration, download the license file. You will need this file to activate your FortiPAM-VM. You can configure basic network settings from the CLI to complete the deployment. Once the license file is uploaded, the CLI and GUI are fully functional.

  1. Go to FortiCloud and create a new account or log in with an existing account.

    The Asset Management portal opens.

  2. On the Asset Management portal, click Register Now to register FortiPAM.
  3. Provide the registration code:
    1. Enter a registration code.
    2. Choose your end user type as either a government or non-government user.
    3. Click Next.
  4. The Fortinet Product Registration Agreement page displays. Select the check box to indicate that you have read, understood, and accepted the service contract. Click Next.
  5. The Verification page displays. Select the checkbox to indicate that you accept the terms. Click Confirm.

    Registration is now complete and your registration summary is displayed.

  6. On the Registration Complete page, download the license file (.lic) to your computer.

    You will upload this license to activate the FortiPAM-VM as shown in Uploading the license file to FortiPAM-VM.

Note: After registering a license, Fortinet servers can take up to 30 minutes to fully recognize the new license. When you upload the license file to activate the FortiPAM-VM, if you get an error that the license is invalid, wait 30 minutes and try again.

When FortiPAM is initially deployed, it is in evaluation mode. Once you have downloaded the license (.lic) file from FortiCloud, you must load the .lic file to FortiPAM so that FortiPAM has a valid serial number.

Uploading the license file to FortiPAM-VM

There are two methods to upload the license file to FortiPAM-VM.

To upload the license via the FortiPAM-VM GUI:

You must be in maintenance mode to be able to upload a license. See Maintenance mode in Admin.

  1. Log in to FortiPAM-VM from a browser.

    Access FortiPAM by using the IP address configured on FortiPAM port1.

    The Upload License File pane appears immediately after you log in.

    If FortiPAM is in evaluation mode, go to Dashboard > Status, click the Virtual Machine widget, and click FortiPAM VM License.

    Use the https prefix with the FortiPAM IP address to access the FortiPAM-VM GUI.

  2. In the Upload License File pane, select Upload and browse to the license file on your management computer.
  3. Click OK.
  4. After the boot up, the license status changes to valid.

    Use the CLI command get system status to verify the license status.

To upload the license through the public IP address using SCP:

Use the following command:

scp <license_file> admin@<public_ip_address>:vmlicense

For example:

$ scp FPAVULTM23000007.lic admin@52.52.143.64:vmlicense

admin@52.52.143.64's password:

FPAVULTM23000xxx.lic 100% 9128 344.0KB/s 00:00

100-install VM license completed