Solved

Fortigate firewall migration

Posted on 2014-10-21
4
183 Views
Last Modified: 2014-12-11
I have a legacy Fortigate model 400A want to be replaced by a 300C model. The existing 400A model is running a very old firmware v3.0, but the 300C is v5.0. Can you guys please give me some suggestion how to do the migrate? I'm not really familiar with forti products...

Many Thanks
0
Comment
Question by:gcl_hk
4 Comments
 
LVL 61

Expert Comment

by:btan
ID: 40396996
It is best to engage fortinet to guide the specific steps since this should be part of the maintenance and do have them advise the details - they have a portal for user like yourself (http://www.fortinet.com/migrating_to_a_fortigate_firewall.html)

In EE forum there is sharing that you may want to check out - the author also gotten it from the principal support
http://www.experts-exchange.com/Hardware/Networking_Hardware/Firewalls/Q_26929154.html

of course in their kb, ther have some in general like this - Technical Tip : How to load/convert a FortiGate configuration file from one unit to another (file conversion for a different model).
http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=10063
0
 
LVL 17

Accepted Solution

by:
Garry-G earned 500 total points
ID: 40397330
Judging from the age of the old box you have, I'd say starting clean should be an option to give some thoughts ... over the years, a lot of stuff piles up that isn't used anymore, or may even be a security threat ... by going over the old config, migrating piece by piece, you can ensure everything you move over is actually what it's supposed to be ... it may be worth the extra time invested to do it this way ...
0
 
LVL 1

Expert Comment

by:Jinujoz
ID: 40426069
1.Upgrade the Firmware of FGT 400A to v4 MR3 patch 18 ( follow theUpgrade Path)
2.Download the config after upgrade
3.Flash the firmware  of FGT 300C with v4 MR3 patch 18(downgrade from v5 to v4)
4.Review the interfaces in FGT 400C config &replace the same with mapped interfaces of FGT 300C on it
5.Post editing the config of 400A  ,copy paste the configuration into the CLI of FGT 300C(start copy past the content from"config system accprofile & neglect the content on top of it in the conf file).
6.Then go for upgrade to v5 on FGT 300C
0
 
LVL 6

Author Closing Comment

by:gcl_hk
ID: 40495440
Finally, start from scratch...
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now