Skip to main content
Sunil_Panchal
Staff
Staff
February 10, 2025

Technical Tip: FortiMail and FortiSandBox-VM migration

  • February 10, 2025
  • 3 replies
  • 2277 views

Description

This article describes the best practices for FortiMail and FortiSandBox VM-to-VM migration.

Scope

FortiMail VM, FortiSandbox VM.

Solution

Under some circumstances, FortiMail or FortiSandbox VMs may need to be migrated to a different hypervisor, like VMware to Nutanix or KVM to Xen.

 

FortiMail and FortiSandbox VMs cannot be migrated from one hypervisor to a different one as a whole due to a number of factors.

 

However, the following may be done to migrate as much data and configuration as possible:

  • Spin up the new VM in the target hypervisor with the same specs as the older VM.

  • For FortiMail VM, details may be found here: FortiMail VM Installation Guide: FortiMail VM Overview.

  • For FortiSandBox VM details may be found here: FortiSandBox Private Cloud: Preparing for Deployment

  • Take the configuration backup from the old VM for FortiMail: System maintenance or FortiSandBox: System Recovery.

  • Shut down the old VM.

  • For FortiMail, first Install the license file to the new VM and then upload the configuration. Otherwise, due to license issues, the new FortiMail with the new configuration will not allow HTTPS access.

  • For FortiSandbox, Inter-Hypervisor Configuration Migration is not supported. But native conversion tools can be used to Convert the FSA disk, like the official import-tool from Proxmox. Set the harddisks to virtIOBlock and activate the VM.

 

License Validation can take some time to complete from a new VM. The old VM should be powered off at this point, as the new VM may otherwise encounter an invalid or duplicate license error during validation.

  • The new FortiMail VM will have the same configuration as the old VM, but data like log files or generated reports cannot be migrated. For logs, an external logging server like FortiAnalyzer can ensure that logs are retained even after migration.

  • The correct firmware image needs to be selected based on the specific hypervisor. The image name ends in an extension that indicates the virtualization type/hypervisor the image can run on. Images are available at the support page: Fortinet Support: Firmware Download.

    3 replies

    dalibor
    New Member
    April 28, 2026

    What if I don’t have licence file, for the past two years old VM is licenced through Fortiguard. 
    Can I register new Trial license (Expire in 14 days 23 hours 36 mins) whith Forticloud for the testing purpose and then when everything os working just to shutdown the old VM. And than how the licence is transferd to the new VM?

    dalibor
    New Member
    April 28, 2026

    Aha, I see now where I can download the licence file :)
    But the question about register new trial VM on Forticloud still is valid, can I do it or to wait when I insert the lic file?

    No_Username
    New Member
    June 2, 2026

    This solution says these steps can be used “to migrate as much data and configuration as possible”. Does that mean that System Quarantine, User Quarantine, and IBE user data cannot be migrated with the Mail Data backup and restore options found under System>Maintenance>Mail Data since these steps don’t mention these types of data at all? Is there a way to force the FortiMail to send at least some of the recent and/or historic log data to the FortiAnalyzer? By default it appears to only send logs that are generated after the remote log settings are created.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!