LICENSEWARE

FortiGate-VM licensing

This article is about licensing the FortiGate-VM virtual firewall on hypervisors and public clouds. For FortiGuard bundles and FortiCare on hardware FortiGates see FortiGuard and FortiCare licensing; for points-based VM entitlements see FortiFlex and FortiPoints.

On This Page

FortiGate-VM licensing governs the virtual edition of the FortiGate next-generation firewall, which runs FortiOS on private-cloud hypervisors and on public clouds. FortiGate-VM is sold in vCPU bands from FG-VM01 (one vCPU) to FG-VMUL (unlimited vCPUs), each available as a normal-series, v-series or s-series licence.[1] Bought as bring-your-own-licence (BYOL), the normal and v-series are perpetual and the s-series is an annual subscription; alternatively, cloud marketplaces offer an on-demand model billed hourly.[2] Like all Fortinet products, FortiGate-VM is licensed under the Fortinet EULA, which subjects use to the licence metrics set out in Fortinet Documentation.[3] The metric the documentation uses is simple: “Licenses are based on the number of CPUs only.”[1]

Editions

Series

The FortiGate-VM administration guides list the models conventionally available to order as BYOL models: FG-VM01/01v/01s, FG-VM02/02v/02s, FG-VM04/04v/04s, FG-VM08/08v/08s, FG-VM16/16v/16s, FG-VM32/32v/32s and FG-VMUL/ULv/ULs, with a vCPU minimum of one for every model and a maximum equal to the band.[1] The suffix denotes the commercial series:

Series Licence form Support 
Normal (for example FG-VM08) Perpetual VM base Support services contracted separately on an annual basis 
v-series (for example FG-VM08v) Perpetual Single annually contracted SKU containing the VM base and a FortiCare service bundle 
s-series (for example FG-VM08s) Annual subscription SKU contains the VM base and service bundle entitlements 

The current order-types page states that BYOL “offers perpetual (normal series and v-series) and annual subscription (s-series) licensing”, and that s-series SKUs contain the VM base and service bundle entitlements for easier ordering.[2] The support column for the normal and v-series comes from the comparison table in the FortiOS 6.4 private-cloud guide, which also dates the S-series to the fourth quarter of 2019; the 8.0 guides no longer carry that table.[[vm_xen64]] Earlier platform-specific models, such as a FortiGate-VM for AWS with its own orderable menu, have been replaced by the common model that applies to all supported platforms.[1]

S-series SKUs

The FortiGate-VM data sheet (16 December 2025) lists the S-series subscription SKUs in the pattern FCn-10-FGVVS-<Support Bundle>-02-DD, where the prefix FC1 to FC7 selects the vCPU band and the support-bundle code selects the FortiGuard and FortiCare content: FortiGate-VM01-S (FC1, 1 vCPU), FortiGate-VM02-S (FC2), FortiGate-VM04-S (FC3), FortiGate-VM08-S (FC4), FortiGate-VM16-S (FC5), FortiGate-VM32-S (FC6) and FortiGate-VMUL-S (FC7, unlimited vCPUs).[4] FortiOS 6.4.0 and later support the S-series, and FortiManager 6.4.0 and later can manage it.[4]

The data sheet’s specification table gives the capacity of each band. Virtual domains default to two on every S-series band, with maximums of 10 (VM-01S), 25 (VM-02S), 50 (VM-04S) and 500 (VM-08S and above), and all bands include an unlimited user licence.[4]

Security services

FortiGate-VM uses the same FortiGuard bundles as hardware: Enterprise Protection, Unified Threat Protection (UTP) and Advanced Threat Protection (ATP), or services a la carte, each including FortiCare Premium.[4][5] A FortiGate-VM subscribed through a cloud marketplace comes with the UTP bundle (rule).[4]

Metrics

  • FortiGate-VM vCPU: the licensed vCPU band of each VM instance.[1]
  • Virtual domain (VDOM): VDOM addition licences for v-series and s-series VMs, sold for the S-series as seats of five VDOMs.[4]
  • FortiFlex Point: when a FortiGate-VM is deployed through FortiFlex, a daily point rate set by its vCPU count and service package replaces the fixed licence.[6]

Counting / floors

The licence caps the vCPUs used

FortiGate-VM licensing does not stop the VM from running on an instance with more vCPUs than licensed. The documentation states that the number of vCPUs in the licence “does not restrict the FortiGate-VM from working, regardless of how many vCPUs are included in the virtual instance”, but that “only the licensed number of vCPUs process traffic and management” and the rest are unused (rule).[1] The example given is an FGT-VM08 licence on a 16 or 32 vCPU instance: FortiOS uses eight vCPUs for traffic and management and ignores the others.[1]

Commentary: the licence file is therefore the enforcement point. An effective licence position for FortiGate-VM compares the licence (band and series) registered for each VM serial number with the VMs deployed, not the vCPUs allocated by the hypervisor. Oversized instances cost compute but do not create a licence shortfall; undersized licences cost throughput.

RAM

The documentation notes that FortiGate-VM BYOL licences generally have RAM size restrictions, but that these do not apply to AWS deployments, where any RAM size is allowed with certain CPU models and licences are based on the number of CPUs only.[1] The data sheet states that the S-series has no RAM restrictions at any vCPU level.[4]

VDOMs

The v-series and s-series do not support virtual domains by default. VDOMs are added by separately purchased VDOM addition licences, which can be stacked after deployment up to the maximum the model supports (rule).[1] For the S-series the VDOM Subscription License (FC1-10-FGVVS-498-02-DD) adds VDOMs to FortiGate-VMs running FortiOS 6.4.9 or 7.0.2 and later; it is seat-based, each seat equals five VDOMs, and the maximum is 100 seats (500 VDOMs).[4] On-demand marketplace instances do not support VDOMs at all.[2]

Registration and term start

A BYOL licence must be activated the first time the instance is accessed from the GUI or CLI before features can be used.[2] VM subscriptions are non-hardware-attached Service Contracts under the Grace Period Policy: if they are not registered, they start automatically 60 days after shipment or contract-number generation, in all regions (rule).[7] Like other Fortinet Service Contracts, they are fixed-term and do not renew automatically.[8]

Floors

There is no quantity minimum beyond one licence per VM. The smallest band is one vCPU. Through FortiFlex, a FortiGate-VM configuration can be set from 1 to 96 vCPUs in increments of one, with VDOM limits of 10 for VM01, 25 for VM02 to VM03, 50 for VM04 to VM07 and 500 for VM08 to VM96.[9]

Virtualization & partitioning

Because the licence counts vCPUs assigned to the firewall instance, hypervisor hosts, sockets and clusters do not enter the calculation, and the documentation publishes no host-based alternative. The data sheet lists private-cloud hypervisors including VMware ESXi, VMware NSX-T, Microsoft Hyper-V, Citrix and open-source Xen, KVM and Nutanix AHV, and public-cloud marketplaces including AWS, Microsoft Azure, Google Cloud, Oracle OCI, Alibaba Cloud and IBM Cloud; the same vCPU licence applies across them.[4][1] VDOMs partition a single FortiGate-VM into separate virtual firewalls and are licensed separately from the vCPU band, as described above.[1] When FortiGate-VMs are managed by FortiManager, each VDOM of a VDOM-enabled FortiGate consumes one FortiManager device licence.[10] For the general concepts see Virtualization and partitioning.

Cloud / BYOL

BYOL and on-demand

On public clouds there are usually two order types. BYOL licences are bought from resellers or distributors, priced in the list that Fortinet updates quarterly, and follow the same ordering practice on every private and public cloud. On-demand is an hourly subscription listed in the cloud marketplace, available immediately after the instance is created, with term-based prices shown on the marketplace product page.[2] In both cases the cloud provider charges separately for compute, storage and other resources.[2]

On-demand instances include support, but the customer must contact Fortinet Support with its customer information to obtain the support entitlement.[2] For BYOL, the customer typically orders a combination of products and services including the support entitlement.[2]

No conversion

“On-demand and BYOL licensing and payment models are not interchangeable”: a BYOL licence cannot be injected into an on-demand instance, and a BYOL instance cannot be converted to on-demand (rule).[2] The licence type is fixed for the VM’s lifetime and is predetermined by the marketplace image; migrating requires deploying a new instance and restoring the configuration, and a new BYOL licence must be bought from a reseller if the target is BYOL.[11] The two types also differ in features: an on-demand instance is packaged with Unified Threat Management protection and does not support VDOMs, while a BYOL instance supports protection levels and features according to its contract.[11]

Programs

Out of scope

This article does not cover FortiGate hardware appliances, FortiGate Cloud, FortiSASE, FortiGate-VM performance figures, or the separate VM editions of FortiManager, FortiAnalyzer, FortiWeb and other Fortinet products, which are licensed by their own metrics.

References

  1. FortiGate Public Cloud 8.0.0 AWS Administration Guide: ModelsPage not date-stamped. Catalog: FortiGate Public Cloud 8.0.0 AWS Administration Guide: ModelsRetrieved 2026-09-30.
  2. FortiGate Public Cloud 8.0.0 AWS Administration Guide: Order typesPage not date-stamped. Catalog: FortiGate Public Cloud 8.0.0 AWS Administration Guide: Order typesRetrieved 2026-09-30.
  3. Fortinet Product License Agreement / EULA and Warranty TermsDocument code September 2026 EULA. Catalog: Fortinet Product License Agreement / EULA and Warranty TermsEffective 2026-09-01. Retrieved 2026-09-30.
  4. FortiGate-Virtual Appliances Data SheetDocument code FG-VM-DAT-R62-20251216. Catalog: FortiGate-Virtual Appliances Data SheetEffective 2025-12-16. Retrieved 2026-09-30.
  5. Ordering Guide: FortiGate Subscriptions and FortiGuard BundlesDocument code FGD-OG-R24-20260504. Catalog: Ordering Guide: FortiGate Subscriptions and FortiGuard BundlesEffective 2026-05-04. Retrieved 2026-09-30.
  6. FortiFlex 26.3.1 Administration Guide: PointsCatalog: FortiFlex 26.3.1 Administration Guide: PointsEffective 2026-09-04. Retrieved 2026-09-30.
  7. Fortinet Service Contract Activation and Grace Period PolicyPolicy page, not date-stamped. Catalog: Fortinet Service Contract Activation and Grace Period PolicyRetrieved 2026-09-30.
  8. Fortinet Service Terms & Conditions (FortiCare, FortiGuard and other Fortinet Service Offerings)Document code 875110-3.10. Catalog: Fortinet Service Terms & Conditions (FortiCare, FortiGuard and other Fortinet Service Offerings)Effective 2026-09-01. Retrieved 2026-09-30.
  9. FortiFlex 26.3.1 Administration Guide: Service offeringsCatalog: FortiFlex 26.3.1 Administration Guide: Service offeringsEffective 2026-09-25. Retrieved 2026-09-30.
  10. Ordering Guide: FortiManagerDocument code FMG-OG-R29-20260626. Catalog: Ordering Guide: FortiManagerEffective 2026-06-26. Retrieved 2026-09-30.
  11. FortiGate Public Cloud 8.0.0 AWS Administration Guide: Migrating a FortiGate-VM instance between license typesPage not date-stamped. Catalog: FortiGate Public Cloud 8.0.0 AWS Administration Guide: Migrating a FortiGate-VM instance between license typesRetrieved 2026-09-30.
  12. FortiFlex 26.3.1 Administration Guide: IntroductionCatalog: FortiFlex 26.3.1 Administration Guide: IntroductionEffective 2026-09-04. Retrieved 2026-09-30.

See also

Catalog Rows Cited

4SKUs5Rules3Metrics4Programs

Esc