Skip to main content
arleniscg
Staff
Staff
June 23, 2026

Technical Tip: Steps to convert backup file from FortiDDoS 400B to 200F

  • June 23, 2026
  • 0 replies
  • 14 views

Description

This article describes the steps to follow when converting a backup file between different FortiDDoS hardware models.

Scope

FortiDDoS F and FortiDDOS B models.

Solution

There is no supported tool to automatically convert a FortiDDoS 400B configuration backup to a FortiDDoS 200F backup. Since these are different hardware generations (B-series and F-series), a direct restore is generally not supported.

  • Option 1 (recommended): Reconfigure the new FortiDDoS appliance from scratch and manually recreate the configuration.

  • Option 2 (best effort): Open a TAC case (Support) and provide the following:


Phase 1: Converting a backup file.

  1. Both FortiDDoS Backups.

  2. The TAC team can review the files and attempt a configuration conversion on a best-effort basis using a CLI script, as migrations between different FortiDDoS models and serial numbers are not guaranteed to be fully supported and may require manual adjustments.

  3. Attach the current cabling topology on the existing FortiDDoS to the case while it is still in production, including the interconnections of each SPP with the ISP Internet links and the LAN segments. This information will facilitate the migration and help ensure the new FortiDDoS is deployed with the same traffic flow and connectivity design.

  4. Document the following parameters before migration (physical cabling and interface assignments) on both FortiDDoS systems:

  • Management port (subnet/mask).

  • Default Gateway.

  • DNS server(s).

  • NTP server(s).

  • SPP settings (ISP and LAN connectivity mapping)

  • Services protected behind each SPP.

  1. The feature configuration on the FortiDDoS-F platform differs significantly from the FortiDDoS-B series. Therefore, new feature profiles will need to be created and tuned for each SPP rather than reusing the existing B-series configuration.


Phase 2: FortiDDoS tuning.

  1. Learning phase: allow at least one week. Small Networks: 7 days; Big Networks/ISP Providers: 15 days.

  2. Configuration and tuning:

  • Review and tune the feature profiles for each SPP.

  • Configure and adjust thresholds in Detection Mode.

  1. False positive review:

  • Review logs and monitor for false-positive drops for several days.

  • Adjust feature profiles and thresholds as needed.

  • Enable Prevention Mode and monitor traffic behavior.