Solved

Fortigate firewall migration

Posted on 2014-10-21
4
204 Views
Last Modified: 2014-12-11
I have a legacy Fortigate model 400A want to be replaced by a 300C model. The existing 400A model is running a very old firmware v3.0, but the 300C is v5.0. Can you guys please give me some suggestion how to do the migrate? I'm not really familiar with forti products...

Many Thanks
0
Comment
Question by:gcl_hk
4 Comments
 
LVL 63

Expert Comment

by:btan
ID: 40396996
It is best to engage fortinet to guide the specific steps since this should be part of the maintenance and do have them advise the details - they have a portal for user like yourself (http://www.fortinet.com/migrating_to_a_fortigate_firewall.html)

In EE forum there is sharing that you may want to check out - the author also gotten it from the principal support
http://www.experts-exchange.com/Hardware/Networking_Hardware/Firewalls/Q_26929154.html

of course in their kb, ther have some in general like this - Technical Tip : How to load/convert a FortiGate configuration file from one unit to another (file conversion for a different model).
http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=10063
0
 
LVL 17

Accepted Solution

by:
Garry-G earned 500 total points
ID: 40397330
Judging from the age of the old box you have, I'd say starting clean should be an option to give some thoughts ... over the years, a lot of stuff piles up that isn't used anymore, or may even be a security threat ... by going over the old config, migrating piece by piece, you can ensure everything you move over is actually what it's supposed to be ... it may be worth the extra time invested to do it this way ...
0
 
LVL 1

Expert Comment

by:Jinujoz
ID: 40426069
1.Upgrade the Firmware of FGT 400A to v4 MR3 patch 18 ( follow theUpgrade Path)
2.Download the config after upgrade
3.Flash the firmware  of FGT 300C with v4 MR3 patch 18(downgrade from v5 to v4)
4.Review the interfaces in FGT 400C config &replace the same with mapped interfaces of FGT 300C on it
5.Post editing the config of 400A  ,copy paste the configuration into the CLI of FGT 300C(start copy past the content from"config system accprofile & neglect the content on top of it in the conf file).
6.Then go for upgrade to v5 on FGT 300C
0
 
LVL 6

Author Closing Comment

by:gcl_hk
ID: 40495440
Finally, start from scratch...
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question