FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
Courtney_Schwartz
Article Id 196223

Purpose

If either:
  • you want to upgrade FortiWeb-VM to a license with a higher vCPU limit
  • your original FortiWeb-VM license was an extended evaluation license, and you have now purchased a permanent, paid license
you must upload a new license file.
Currently, this can only be done while the FortiWeb-VM license is invalid. In order to upload a new license file, you must first invalidate the current one. There are multiple ways that you can do this.


Diagram


Expectations, Requirements
N/A
Configuration

To upload a new license for more vCPUs
  1. Log in to FortiWeb-VM as admin via the web UI.
  2. Go to System > Status > Status.
  3. In the System Information widget, click Shut Down.
    The virtual appliance will flush its data to its virtual disk, and prepare to be powered off. If you skip this step and immediately power off FortiWeb-VM, you may lose buffered data.
  4. On your management computer, start VMware vSphere Client.
  5. In IP address / Name, type the IP address or FQDN of the VMware vSphere server.
  6. In User name, type the name of your account on that server.
  7. In Password, type the password for your account on that server.
  8. Click Login.
  9. In the left pane, click the name of the virtual appliance, such as FortiWeb-VM-64-101.
  10. Click the Getting Started tab.
  11. Click Power off the virtual machine.
  12. Increase the vCPU allocation. For details, see the FortiWeb-VM Install Guide.
  13. Power on the virtual appliance again.
    FortiWeb-VM will evaluate its current license, and discover that you have allocated an unsupported number of vCPUs, causing the current license to become invalid. This will temporarily disable most of the GUI and CLI, except for the capability to upload a new license.
  14. Log in to the web UI again.
  15. Upload the new license. For details, see FortiWeb-VM Install Guide .
 
To upload a paid license if you have an extended evaluation
1. Either:
  • Shut down FortiWeb-VM, power it off, then increase the number of vCPUs to invalidate the trial license. For details, see FortiWeb-VM Install Guide .
  • Delete the instance. Re-deploy using a fresh FortiWeb-VM image with no license.
  • Wait for the current evaluation period to finish, invalidating the license.
2. Upload the new license. For details, see FortiWeb-VM Install Guide .


Verification

Your browser uploads the license file. Time required varies by the size of the file and the speed of the network connection. FortiWeb will then connect to Fortinet to validate its license. A message appears:
License has been uploaded. Please wait for authentication with registration servers.
To verify the FortiWeb-VM license upload
  1. Click Refresh on the upload message box.
    If you uploaded a valid license, a second message box should appear, informing you that your license authenticated successfully:
    License has been successfully authenticated with registration servers.
    Time required varies by connectivity to the license authentication servers. If the connection does not succeed the first time, you can either wait up to 30 minutes for the next license query, or enter the CLI command:
    execute update-now 
    Note: This command also contacts FortiGuard for FortiWeb Security Service contract validation and update availability.
  2. Click OK.
    The web UI logs you out. The login dialog reappears.
  3. Log in again.
  4. Go to System > Status > Status.
  5. Examine the License Information widget. The VM License row should say Valid.
  6. Also view the System Information widget. The Serial Number row should have a number that indicates the license’s vCPU limit, such as FVVM020000003619 (where “VM02” indicates a limit of 2 vCPUs).
    If FortiWeb was also able to contact FortiGuard, its FortiWeb Update Service row should also indicate that the FortiGuard service contract is valid. (This second license validation may occur a minute or two after the first, and so may not appear immediately.)


Troubleshooting
If the first license authentication attempt failed due to an interruption to the Internet connection, you can either reboot, wait 30 minutes for the next attempt, or enter the CLI command:

 
execute update-now



Contributors