Fortinet black logo

Installing the Windows VM package

Installing the Windows VM package

Downloading and installing the Microsoft Windows VM package is optional for FortiSandbox VM. For example, you do not need to install the Windows VM package when you choose to:

  • Deploy the unit as Primary or Secondary node of a cluster without doing any dynamic scans on it, or
  • Use Windows Cloud VM to do dynamic scans instead of using local VMs.

If you choose to install local Windows VM, there are two types to choose from: Default and Optional.

Install the default Windows VM package

The default Windows VMs includes two versions:

  • Windows 7, 32 bit with SP1 and Microsoft Office installed
  • Windows 10, 64bit

To view the VMs after they are installed, go to Scan Policy and Object > VM Settings > Default VMs.

You can install the VMs directly with the CLI, or download it to local FTP or SCP server first and then install it with the CLI command. For either method, the system must be able to access https://fsavm.fortinet.net.

To download and install the default Windows VM package directly with the CLI:

fw-upgrade -v -sfsavm.fortinet.net -thttps -f/images/v4.00/VM00_base.pkg

To download the default Windows VM package to a local server and install it:
  1. Go to https://fsavm.fortinet.net/images/v4.00/VM00_base.pkg to download the Windows VM package.
  2. Save the package on a host that supports file copy with the SCP or FTP protocol. FortiSandbox must be able to access the SCP or FTP server.
  3. In a CLI console window, use the following command to download and install the package:

    fw-upgrade -v -t<ftp|scp> -s<SCP/FTP server IP address> -u<user name> -f<file path>

    For example, fw-upgrade -v -tscp -sx.x.x.x -utest -f/home/test/xxxx

Install Optional Windows VM package

You can install an optional Windows VM to best mimic your environment. For example, if the majority of installations in your environment are Windows 10 with Office 2016, you can install WIN10O16V4 VM.

Available optional VMs are displayed in Scan Policy and Object > VM Settings > Optional VMs. You can download and install one from the list. The system must be able to access https://fsavm.fortinet.net. For more information, see the Scan Policy and Object > VM Settings chapter in the FortiSandbox Administration Guide.

Windows Sandbox VMs must be activated on the Microsoft activation server. This is done automatically when a system reboots after Windows activation keys are uploaded to the unit. For the activation to work, ensure port3 can access the Internet and the DNS server can resolve the Microsoft activation servers.

Installing the Windows VM package

Downloading and installing the Microsoft Windows VM package is optional for FortiSandbox VM. For example, you do not need to install the Windows VM package when you choose to:

  • Deploy the unit as Primary or Secondary node of a cluster without doing any dynamic scans on it, or
  • Use Windows Cloud VM to do dynamic scans instead of using local VMs.

If you choose to install local Windows VM, there are two types to choose from: Default and Optional.

Install the default Windows VM package

The default Windows VMs includes two versions:

  • Windows 7, 32 bit with SP1 and Microsoft Office installed
  • Windows 10, 64bit

To view the VMs after they are installed, go to Scan Policy and Object > VM Settings > Default VMs.

You can install the VMs directly with the CLI, or download it to local FTP or SCP server first and then install it with the CLI command. For either method, the system must be able to access https://fsavm.fortinet.net.

To download and install the default Windows VM package directly with the CLI:

fw-upgrade -v -sfsavm.fortinet.net -thttps -f/images/v4.00/VM00_base.pkg

To download the default Windows VM package to a local server and install it:
  1. Go to https://fsavm.fortinet.net/images/v4.00/VM00_base.pkg to download the Windows VM package.
  2. Save the package on a host that supports file copy with the SCP or FTP protocol. FortiSandbox must be able to access the SCP or FTP server.
  3. In a CLI console window, use the following command to download and install the package:

    fw-upgrade -v -t<ftp|scp> -s<SCP/FTP server IP address> -u<user name> -f<file path>

    For example, fw-upgrade -v -tscp -sx.x.x.x -utest -f/home/test/xxxx

Install Optional Windows VM package

You can install an optional Windows VM to best mimic your environment. For example, if the majority of installations in your environment are Windows 10 with Office 2016, you can install WIN10O16V4 VM.

Available optional VMs are displayed in Scan Policy and Object > VM Settings > Optional VMs. You can download and install one from the list. The system must be able to access https://fsavm.fortinet.net. For more information, see the Scan Policy and Object > VM Settings chapter in the FortiSandbox Administration Guide.

Windows Sandbox VMs must be activated on the Microsoft activation server. This is done automatically when a system reboots after Windows activation keys are uploaded to the unit. For the activation to work, ensure port3 can access the Internet and the DNS server can resolve the Microsoft activation servers.