Skip to main content
Somashekara_Hanumant
Staff & Editor
Staff & Editor
February 25, 2026

Technical Tip: Migrating DDNS from an old FortiGate to a new FortiGate unit

  • February 25, 2026
  • 0 replies
  • 905 views
Description This article describes how to migrate a DDNS name from an old FortiGate to a new FortiGate unit.
Scope FortiGate.
Solution

To migrate to a new FortiGate from an old FortiGate unit where DDNS is registered with the old FortiGate unit, follow the steps below.

  • Before making any changes, make sure to have a backup of the current FortiGate configuration. This can be done via the FortiGate GUI or CLI.
  • Review the current DDNS settings on FortiGate. Do this by navigating to the DDNS settings in the GUI or by using the following CLI command:

 

show system ddns

 

  • Since the same DDNS cannot be used on multiple FortiGates, the user needs to register a support ticket with Fortinet. The Technical Assistance Center (TAC) team can assist in transferring the DDNS from the old device to the new one. See Welcome to Fortinet Support.
  • Ensure the new FortiGate is properly configured and ready to take over the role of the old device. This includes setting up interfaces, policies, and any other necessary configurations. Follow the Migration process.

 

Important:
Before initiating the DDNS migration, ensure that the old FortiGate is no longer connected to the internet. This can be done by shutting down the device or physically disconnecting it from the network. This step prevents the old device from continuing to update the DDNS record and avoids potential conflicts during the migration process. 

 

  • Once the new device is ready with the configuration, take a scheduled maintenance window to replace the old device with a new device, and contact the Fortinet Support toll-free number to delete the existing DDNS from the old firewall. Once this process is completed, check the DDNS settings on the new device.

 

config system ddns
    edit 1
        set ddns-server FortiGuardDDNS
        set ddns-domain "ddns-domain"
        set use-public-ip enable
        set monitor-interface "wan1"
    next
end

 

Refer to Technical Tip: How to configure Dynamic DNS FortiGate.

 

If the DDNS is not working after configuration, capture the output of the debug commands below, open a TAC ticket, and update the debug output for TAC investigation. See this article: Customer Service Tip: How to create a ticket for Fortinet TAC.

 

diagnose debug disable
diagnose debug reset
diagnose debug application ddnscd -1

diagnose debug enable 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.