Skip to main content
mdndiaye
Visitor III
March 13, 2023
Question

TUNNEL VPN SITE TO SITE AND REMOTE ACESS

  • March 13, 2023
  • 2 replies
  • 1794 views

Good morning,
I would like to know if possible, if there is a way to recover the configuration file of the S2S and RA VPN tunnels from a fortigate to copy it to another fortigate box.
Only VPN configuration.
Thank you in advance for your answers

2 replies

jintrah_FTNT
Staff
Staff
March 14, 2023

Hi,

Please see Technical Tip: How to load/convert a FortiGate con... - Fortinet Community if it  may help, ideally copying the config to another FortiGate on same version should be possible.

 

Best regards,

Jin

sw2090
SuperUser
SuperUser
March 14, 2023

you could get yourselve an unencrypted backup of that FGT. Then open that in some Text Editor and find the vpn config.

For IPSEC it starts with "config vpn ipsec". You need to get Phase1 and Phase 2 config of the tunnel. 

You can then run that as script on the other FGT or paste into cli.

Just make sure you run the same FortiOS version on both because that could create issues with content that is only stored encrypted in the config like ipsec psks since the encryption changed between fortios versions.

 

Also you would need to copy all objects the ipsec depends on. That might be adresses/addressgroups if you use mode config or user/usergroups for xauth.

 

Also keep in mind that you might need to copy static routing and policies since IPSec will not come up if there is no policy for it.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!