Question
Integrating Fortigate into existing network
Hello, We have a Fortigate 300 C which is not in the default path to the internet. It is connected to the network gateway router and the gateway router policy routes all the traffic going out to the internet to this FG300C. We want to move this firewall behind the gateway router and implement FG HA. We also plan on moving all the IPsec tunnels and NAT from the gateway router to this firewall. I would like some input on what would be the best way to move the firewall behind the gateway with minimal downtime. One way I am thinking of doing it is by connecting the second FG300C(which is right now on the bench as a backup) behind the router and configuring it to allow all traffic through(open policy) to the gateway router. Once I have done this I can move the configurations (ipsec vpns, nat etc) from the gateway router to this firewall behind the router and once I have moved all the configuration that i want to move, I can restrict the policy as required and apply web filtering and remove the other firewall and connect it to this firewall to make HA pair. Do you think this is better then configuring the firewall offline? Thank you.
