Solved

Fortigate firewall migration

Posted on 2014-10-21
4
194 Views
Last Modified: 2014-12-11
I have a legacy Fortigate model 400A want to be replaced by a 300C model. The existing 400A model is running a very old firmware v3.0, but the 300C is v5.0. Can you guys please give me some suggestion how to do the migrate? I'm not really familiar with forti products...

Many Thanks
0
Comment
Question by:gcl_hk
4 Comments
 
LVL 62

Expert Comment

by:btan
ID: 40396996
It is best to engage fortinet to guide the specific steps since this should be part of the maintenance and do have them advise the details - they have a portal for user like yourself (http://www.fortinet.com/migrating_to_a_fortigate_firewall.html)

In EE forum there is sharing that you may want to check out - the author also gotten it from the principal support
http://www.experts-exchange.com/Hardware/Networking_Hardware/Firewalls/Q_26929154.html

of course in their kb, ther have some in general like this - Technical Tip : How to load/convert a FortiGate configuration file from one unit to another (file conversion for a different model).
http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=10063
0
 
LVL 17

Accepted Solution

by:
Garry-G earned 500 total points
ID: 40397330
Judging from the age of the old box you have, I'd say starting clean should be an option to give some thoughts ... over the years, a lot of stuff piles up that isn't used anymore, or may even be a security threat ... by going over the old config, migrating piece by piece, you can ensure everything you move over is actually what it's supposed to be ... it may be worth the extra time invested to do it this way ...
0
 
LVL 1

Expert Comment

by:Jinujoz
ID: 40426069
1.Upgrade the Firmware of FGT 400A to v4 MR3 patch 18 ( follow theUpgrade Path)
2.Download the config after upgrade
3.Flash the firmware  of FGT 300C with v4 MR3 patch 18(downgrade from v5 to v4)
4.Review the interfaces in FGT 400C config &replace the same with mapped interfaces of FGT 300C on it
5.Post editing the config of 400A  ,copy paste the configuration into the CLI of FGT 300C(start copy past the content from"config system accprofile & neglect the content on top of it in the conf file).
6.Then go for upgrade to v5 on FGT 300C
0
 
LVL 6

Author Closing Comment

by:gcl_hk
ID: 40495440
Finally, start from scratch...
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question