Skip to main content
Maerre
Explorer III
July 8, 2026
Question

Unexpected Loss of SD-WAN and VPN Configurations on FortiGate 401F during Migration from 501E Managed by FortiManager (v7.4.11)

  • July 8, 2026
  • 0 replies
  • 15 views

Hello guys,

 

I would like to understand whether anyone has experienced a similar issue and, if possible, identify the root cause.

I recently performed a migration from a pair of FortiGate 501E devices to a pair of FortiGate 401F devices. Both the FortiGates and FortiManager were running version 7.4.11.
The firewalls being migrated were the central hub of our entire infrastructure.
They were managed by FortiManager and used SD-WAN Templates extensively.
In addition, they were acting as the VPN hub through VPN Manager, with approximately 100 remote FortiGate devices connected to them.
To prepare for the migration, I brought the new 401F devices online and initially configured only the primary unit.
At that stage, the two new firewalls were not yet configured in an HA cluster.
I imported the complete configuration from the old 501E and assigned the new device to the existing SD-WAN template in FortiManager.
The only step I intentionally postponed until the migration day was adding the new firewall as a device within VPN Manager.
Apart from that, the entire configuration appeared to have been imported correctly.
The SD-WAN configuration, VPN settings, and all related objects were present and working as expected.
Later, after configuring HA, both units appeared fully synchronized and there were no obvious issues.
However, approximately two days before the scheduled migration, I noticed that FortiManager was reporting errors for the new firewall.
When I investigated, I discovered that most of the SD-WAN and VPN-related configuration had completely disappeared from the device configuration.
I reviewed the FortiManager event logs and audit logs but could not find any event, installation task, or configuration change that would explain why such a large portion of the configuration was removed.
As a result, to keep the migration on schedule, I had to manually recreate and restore the entire SD-WAN and VPN-related configuration on the new 401F devices.
This included rebuilding a significant amount of configuration that had previously been present and correctly synchronized.

My questions are:

 1)Has anyone experienced a similar issue?

 2)Could FortiManager have automatically removed the configuration because the device was assigned to templates but not yet fully integrated into VPN Manager?

3)Are there any logs or debug commands that could help determine exactly what triggered the configuration removal?

 

I am trying to understand what happened to avoid a similar situation in future hardware migrations.

Any insights or suggestions would be greatly appreciated.

 

Thank you.