FortiGate 500D to 1000F Migration – Incoming Traffic Not Reaching Internal Server
Hello everyone,
I am currently working on a production firewall migration from a FortiGate 500D (FortiOS 5.6.x) to a FortiGate 1000F (FortiOS 7.6.x).
After migrating the configuration, we are facing an issue where public traffic reaches the FortiGate 1000F but does not reach the internal server. If we reconnect the old FortiGate 500D with the same network topology, everything works normally.
Environment
- Source firewall: FortiGate 500D (FortiOS 5.6.4)
- Target firewall: FortiGate 1000F (FortiOS 7.6.6)
- Same public IP addresses
- Same ISPs
- Same internal servers
- BGP is used for routing
- VIPs are used for inbound services
What has already been verified
We have carefully compared the configurations of both firewalls and checked the following:
- VIP configuration
- Firewall policies
- Address objects and address groups
- Static routes
- BGP routing
- Interface mapping
- Central NAT and Policy NAT
- Security policies
- Traffic logs
diagnose debug flow- Routing table
We also disabled Central NAT and tested Policy NAT, but the behavior remained the same.
Current Observation
From the initial analysis, we have not identified any configuration errors on the FortiGate 1000F. The migration appears to be technically correct.
However, inbound traffic is still not forwarded to the internal server, while the exact same service works immediately when the FortiGate 500D is reinstalled.
My Questions
- Has anyone experienced a similar issue when migrating from FortiOS 5.6 to FortiOS 7.6?
- Are there any significant changes in VIP, NAT, policy processing, or routing behavior between these versions that could explain this issue?
- Is there any migration-related feature or hidden setting that should be checked on the FortiGate 1000F?
- Are there any advanced debug commands you would recommend beyond
diagnose debug flow?
Any suggestions or recommendations would be greatly appreciated.
Thank you in advance for your support.
