Skip to main content
FredMB
New Member
March 28, 2019
Question

Export configuration from FG100D to FG60D

  • March 28, 2019
  • 7 replies
  • 7845 views

Hello,

 

We have a FG100D as our main router and got a FG60D from a closed remote office.

I would like to use the FG60D as a backup router.

 

Is it possible to do so as a cluster between the FG100D and FG60D ?

 

Or is it possible to backup the configuration of the FG100D and restore it to the FG60D ? 

I tried to do that but it seems it's not working from scratch :

[ul]
  • Importing the config directly returns an error.
  • So I edited the config file and changed the config-version from FG100D to FGT60D. The configuration was imported but it seems I didn't get any more access to the FG60D and I had to do a hard reset.[/ul]

    Both units are in 5.2.13 firmware.

     

    Thank you for your help,

     

    Regards,

     

    Fred

     

    • 7 replies

      ede_pfau
      SuperUser
      SuperUser
      March 28, 2019

      You can import the foreign config into the 60D but you will have to adjust it beforehand. Chances are that the number of ports and maybe their names are different.

      As a means of last resort one could do that. Every time you change the config on the 100D you would have to adjust the 60D config as well. Your call.

      If you want to create a redundant pair of firewalls with different hardware you could go the VRRP way. But, no config sync either, and failover time is slow in comparison.

       

      IMHO getting a used 100D and new contract(s) would be much more efficient.

      Dave_Hall
      New Member
      March 28, 2019

      Hi Fred.

       

      You would need to replace the header line (first line) on the 200D config with the header line from a copy of the 60D config before importing (loading) the "modified" config on to the 60D.  Assuming you are not using anything fancy, the only "real" difference in porting a modded config would be the 200D's 14-port switch vs the 60D's 7-port switch.  But as Ede indicated the internal interface ports may be named differently.  Not having access to a 60D, I would assume the internal interface on it are in switch mode by default, whereas the ports 1-through-8 on the 100D are a switch + individual ports (9 though 14) - just guessing on this.  (If these fgts are firmware upgradable to 5.4 or higher, the internal ports should be all converted to a hardware switch with individual port members and thus named similarly - someone correct me on this, though.)

       

      I would follow Ede' suggestion.   However, if you do plan to import a modded 200D config over to the 60D, perform a diagnose debug config-error-log read from the CLI after that first boot to see what has messed up and edit the modded config accordingly.

      Toshi_Esumi
      SuperUser
      SuperUser
      March 28, 2019

      Side notes to Ede's suggestion. Unlike Cisco who has registration ripping-off policy, Fortinet doesn't let the new owner of a FGT reregister it unless the registered owner is reachable and agreed to release the registration. I had a first-hand experience when I bought an used 50E and the registered owner refused to release it when FTNT reached him. So some risk is associated with an used one.

      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!