FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
AnthonyH
Staff
Staff
Article Id 342498
Description

This article describes how to change the region where the FortiGate is deployed in FortiGate Cloud.

Scope

FortiGate, FortiGate Cloud.

Solution

For reference, FortiGates can be deployed to one of several regions to specify which FortiGate Cloud servers are utilized for logging/management. These regions currently include:

  • Global.
  • US.
  • EU.
  • Japan.

 

If a given FortiGate is confirmed to be deployed to FortiGate Cloud but is seemingly not visible in the web portal, it is possible that it was deployed to a different region than expected. There are two methods for changing the assigned region:

 

Option 1: Changing the FortiGate's assigned region from FortiGate Cloud:

To move a FortiGate from one region to another in FortiGate Cloud, follow the steps in the FAQ of the FortiGate Cloud Admin Guide to undeploy and redeploy the FortiGate to a new region (see 'How can I move a FortiGate from region A to region B?').

 

Note: 

Data migration between regions is not supported, so any logs generated while the FortiGate is in the original region will not be carried over to the new region.

 

Option 2: Changing the FortiGate's assigned region on the FortiGate itself:

It is possible to change the FortiGate's assigned region from the FortiGate itself. To do this, use the following procedure:

 

  1. Navigate to Dashboard -> Status -> FortiGate Cloud in the FortiGate GUI, then select the 'Activated' Status and select Logout to log out of FortiGate Cloud.

 

fortigate_cloud_logout.png

 

  1. Upon logging out, the FortiGate Cloud status will say 'Not Activated'. To sign back in, select 'Not Activated'.

 

not_activated.PNG

 

  1. At the login prompt, specify the Password associated with the FortiGate Cloud Email. When choosing the Domain, select the new region for the FortiGate to be deployed to, then select OK to complete the activation process.

 

server_region.PNG

 

If the Domain dropdown selection is showing either only US or Europe, run the commands below to update the FortiGuard server location:

 

config system fortiguard
     set update-server-location automatic
end

 

Validation:

Once the above process is completed using either option, navigate to FortiGate Cloud and validate that the FortiGate now shows in the correct region (the region can be changed using the dropdown menu in the upper-right corner).

  • FortiGate Cloud can also be accessed via the Fortinet Support Site under the Services -> Cloud Management -> FortiGate Cloud section.

 

region_dropdown.png

 

Note:

  • If the 'Logout' option from the FortiGate GUI encounters an error, then the following CLI command may be used instead:

 

execute fortiguard-log login <email> <password> <FortiCloud_domain>

 

When choosing the domain, select the new region for the FortiGate to be deployed in, e.g., US, Europe, or GLOBAL.

 

  • If the changing region on the FortiGate cloud is not available and is grayed out, as shown below. 

 

No region selection.png

 

This is because the FortiGate is not registered with the account used to log in to the FortiGate Cloud. Only the master user will be able to switch the regions. If the sub-user wants to switch regions, it must log in with the IAM account, not their regular email account. More information about the IAM account is found in the following document: Adding IAM users 

 

Related article:

Technical Tip: FortiGate Cloud switch region

Adding IAM users