Solved

Fortigate firewall migration

Posted on 2014-10-21
4
212 Views
Last Modified: 2014-12-11
I have a legacy Fortigate model 400A want to be replaced by a 300C model. The existing 400A model is running a very old firmware v3.0, but the 300C is v5.0. Can you guys please give me some suggestion how to do the migrate? I'm not really familiar with forti products...

Many Thanks
0
Comment
Question by:gcl_hk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 63

Expert Comment

by:btan
ID: 40396996
It is best to engage fortinet to guide the specific steps since this should be part of the maintenance and do have them advise the details - they have a portal for user like yourself (http://www.fortinet.com/migrating_to_a_fortigate_firewall.html)

In EE forum there is sharing that you may want to check out - the author also gotten it from the principal support
http://www.experts-exchange.com/Hardware/Networking_Hardware/Firewalls/Q_26929154.html

of course in their kb, ther have some in general like this - Technical Tip : How to load/convert a FortiGate configuration file from one unit to another (file conversion for a different model).
http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=10063
0
 
LVL 18

Accepted Solution

by:
Garry Glendown earned 500 total points
ID: 40397330
Judging from the age of the old box you have, I'd say starting clean should be an option to give some thoughts ... over the years, a lot of stuff piles up that isn't used anymore, or may even be a security threat ... by going over the old config, migrating piece by piece, you can ensure everything you move over is actually what it's supposed to be ... it may be worth the extra time invested to do it this way ...
0
 
LVL 1

Expert Comment

by:Jinujoz
ID: 40426069
1.Upgrade the Firmware of FGT 400A to v4 MR3 patch 18 ( follow theUpgrade Path)
2.Download the config after upgrade
3.Flash the firmware  of FGT 300C with v4 MR3 patch 18(downgrade from v5 to v4)
4.Review the interfaces in FGT 400C config &replace the same with mapped interfaces of FGT 300C on it
5.Post editing the config of 400A  ,copy paste the configuration into the CLI of FGT 300C(start copy past the content from"config system accprofile & neglect the content on top of it in the conf file).
6.Then go for upgrade to v5 on FGT 300C
0
 
LVL 6

Author Closing Comment

by:gcl_hk
ID: 40495440
Finally, start from scratch...
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question