Skip to main content
desaia
Staff
Staff
November 26, 2025

Technical Tip: FortiGate-VM Migration Procedure

  • November 26, 2025
  • 0 replies
  • 2844 views
Description This article describes the recommended procedure for migrating a FortiGate-VM instance to a new hypervisor, region, or cloud environment. The process focuses on preserving the existing FortiGate license and ensuring configuration continuity while avoiding serial-number or licensing conflicts.
Scope FortiGate-VM.
Solution

Before beginning the migration, ensure:

  • Access to the FortiCare Support Portal.
  • Administrative access to both the source and target environments.
  • The ability to deploy a new FortiGate-VM instance in the destination platform.
  • A maintenance window if the source VM is production-critical.

 

  1. Before deploying the new VM, confirm that the target platform meets all requirements published by Fortinet. Requirements vary depending on:
  • FortiOS software version.
  • VM size and user/traffic load.
  • Hypervisor type (VMware, Hyper-V, KVM, etc.).
  • Cloud provider (AWS, Azure, GCP, OCI, etc.).

Refer to the official product documentation for details:
FortiGate Private Cloud 
FortiGate Public Cloud

Confirm supported instance types, CPU/memory requirements, NIC configuration, and storage specifications before proceeding.

  1. Provision a fresh FortiGate-VM instance in the destination region or cloud environment. At this stage, the VM will have a temporary serial number and no license applied.

  2. Log in to the FortiCare Support Portal and download the license file associated with the existing FortiGate VM instance.

  3. Power off the old FortiGate-VM. Wait at least 90 minutes (6 - 24 hours is recommended in some cases) for FortiGuard servers to clear the old instance registration. This prevents 'Duplicate license detected' errors. Monitor the Asset portal: the old serial number should eventually show as inactive/removed.

     

  4. Upload the previously downloaded license file to the newly deployed VM. The VM will automatically reboot.

  5. Verify the license status (should show as VALID) and confirm that the configuration has been restored or synchronised as expected.

  6. Update any relevant settings if network changes were made (such as IP addressing, HA configuration, or routing). If required, consider using FortiConverter services to ensure accurate configuration migration.


Related article:
Technical Tip: VM License transfer from one SN to another SN 
Technical Tip: Migrating FortiGate-VM to production licenses (Full), which are running Evaluation/trial licenses in HA and Standalone 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.