Migrate Fortigate VM to Fortigate 500E

CLR Benjamin
CLR Benjamin used Ask the Experts™
on
Hi,

here my project : Migrate Fortigate VM64 v5.6.8 build1672 (GA) to a Fortigate 500e v6.0


The Fortigate VM64 is installed inside a Vcenter ( 4 ESX) with different Vswitches.
Physically the ESXs are on a FC SWITCH with different VLAN.

Here the configuration :

fg1So I think I should do that before migrate :

-Upgrade FG VM64  to v6.0
-Copy the FG VM64 config and adapt it for the FG 500E
-Plug a cable between the FC SWITCH (with the good port and vlan) to the correct interface on the 500E.
-Mount the same interface on the 500E (with the good vlan  and should be the same from the FG VM64)
-Turn off the old interface on the FG VM64
-Test
-Repeat for each interface

BUT, I think I missing something on the vcenter, any ideas?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Qlemo"Batchelor", Developer and EE Topic Advisor
Top Expert 2015

Commented:
If you move that config over to the 500e one by one as described, which means that the FC needs to have 4 additional ports configured with the individual VLANs, you should be fine. But you should take care that you first disconnect the VM port before plugging in or activating the physical port to the 500e.
Technical Lead - Network Security
Commented:
So before you ever do ANY upgrade you should do a backup first. So do a backup first and then go forward with the upgrade. If you have problems you will thank me later! Also, you shouldnt do ANY of this unless you have a documented and APPROVED change window.

Just getting the (hopefully) obvious things covered first.

Your process seems pretty acceptable.

Author

Commented:
@qlemo what do you mean by "which means that the FC needs to have 4 additional ports configured with the individual VLANs", I don't understand why 4 additional ports, I thought it was 1 port for each VLAN for the new FG.
Qlemo"Batchelor", Developer and EE Topic Advisor
Top Expert 2015

Commented:
Correct, 4x 1 port = 4 (new) ports, one for each VLAN. You now have 4 ports coming from the ESX hosts, and need 4 ports to forward traffic to the corresponding ports on 500e.

Author

Commented:
Thanks for your help!

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial