Skip to main content
Visitor II
August 4, 2026
Question

FortiGate 500D to 1000F Migration – Incoming Traffic Not Reaching Internal Server

  • August 4, 2026
  • 5 replies
  • 37 views

Hello everyone,

I am currently working on a production firewall migration from a FortiGate 500D (FortiOS 5.6.x) to a FortiGate 1000F (FortiOS 7.6.x).

After migrating the configuration, we are facing an issue where public traffic reaches the FortiGate 1000F but does not reach the internal server. If we reconnect the old FortiGate 500D with the same network topology, everything works normally.

Environment

  • Source firewall: FortiGate 500D (FortiOS 5.6.4)
  • Target firewall: FortiGate 1000F (FortiOS 7.6.6)
  • Same public IP addresses
  • Same ISPs
  • Same internal servers
  • BGP is used for routing
  • VIPs are used for inbound services

What has already been verified

We have carefully compared the configurations of both firewalls and checked the following:

  • VIP configuration
  • Firewall policies
  • Address objects and address groups
  • Static routes
  • BGP routing
  • Interface mapping
  • Central NAT and Policy NAT
  • Security policies
  • Traffic logs
  • diagnose debug flow
  • Routing table

We also disabled Central NAT and tested Policy NAT, but the behavior remained the same.

Current Observation

From the initial analysis, we have not identified any configuration errors on the FortiGate 1000F. The migration appears to be technically correct.

However, inbound traffic is still not forwarded to the internal server, while the exact same service works immediately when the FortiGate 500D is reinstalled.

My Questions

  1. Has anyone experienced a similar issue when migrating from FortiOS 5.6 to FortiOS 7.6?
  2. Are there any significant changes in VIP, NAT, policy processing, or routing behavior between these versions that could explain this issue?
  3. Is there any migration-related feature or hidden setting that should be checked on the FortiGate 1000F?
  4. Are there any advanced debug commands you would recommend beyond diagnose debug flow?

Any suggestions or recommendations would be greatly appreciated.

Thank you in advance for your support.

5 replies

abelio
SuperUser
SuperUser
August 4, 2026

Hello,
if you can manage the ISPs routers, try flushing arp tables 
If not, try rebooting ISPs routers

best regards

nsomoneAuthor
Visitor II
August 4, 2026

Thank you for your suggestion.

We are using the same public IP addresses as on the previous FortiGate 500D, so an ARP cache issue is definitely something to consider.

We will verify the ARP tables on the ISP routers (or ask the providers to clear them) and check whether the new FortiGate 1000F MAC address is being learned correctly.

Thank you for your recommendation.

sjoshi
Staff
Staff
August 4, 2026

Hi Since you are seeing traffic is reaching the FGT 1000F, you can take sniffer.

diag sniff packet any ‘host x.x.x.x’ 4 0 l » where x.x.x.x is the src public ip

 

Yes you can take debug flow too.

https://docs.fortinet.com/document/fortigate/8.0.0/administration-guide/54688/debugging-the-packet-flow

Thanks, Salon
nsomoneAuthor
Visitor II
August 5, 2026

Thank you for your suggestion.

We have already collected some debug flow logs, but I will also capture packet traces using the sniffer as you recommended.

This should help us verify whether the packets are correctly forwarded to the internal server and whether the return traffic is received.

I will share the results once the tests are completed.

Thank you for your support.

sjoshi
Staff
Staff
August 5, 2026

yes please take filter using only the source IP as this will capture ingress and egress traffic since the traffic is towards VIP

Thanks, Salon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.