Created on 05-10-2009 09:41 AM Edited on 09-03-2024 10:59 PM By Anthony_E
Description
This article describes how to import the configuration file from one FortiGate to a different FortiGate or firmware.
Scope
FortiGate.
Solution
Fortinet Support for the import of a configuration file between different hardware models or firmware versions.
It is only officially supported to import configuration files between the same hardware model and firmware version.
This is because there can be configuration syntax differences between firmware versions as well as hardware models. For example, prior to FortiOS 6.4, SD-WAN is configured under 'config system virtual-wan-link', while in 6.4 and newer it's under 'config system sdwan'.
In addition, the interface mappings and other features may not be the same across different hardware models. Attempting to import such a configuration can have unexpected consequences and may not function as desired.
Fortinet Technical Support does not provide support for modified configuration files that were initially from another FortiGate (for example, changing the interface names in the config file to match the newer FortiGate model), however parts of the configuration can be restored manually by copying the required configuration parts from the old backup configuration file to new configuration file (for example, address objects or some other settings).
Recommended Solution:It is recommended that the FortiConverter service is used for this task.
The FortiConverter service is sold as a one-time service to convert a third-party or older FortiOS configuration to the latest FortiOS for the new FortiGate.
The FortiConverter service offers the possibility to convert the configuration correctly and is the only supported way the configuration can be migrated automatically. For more information regarding FortiConverter please see the following documents:
Manual Conversion:
Another possible option would be to manually configure the new FortiGate appliance from factory default settings, by referencing to the settings on the other unit.
However, keep in mind that converting the configuration in such a way can be error prone, as with any other process done manually.
The configuration file from the FortiGate can be viewed from any text editor such as Notepad, vi or Notepad++.
Note:
Refrain from using rich text editors (Microsoft Word, Wordpad, ...) as their formatting features may re-encode ASCII characters into different encodings and create unreadable configuration parts with hard to spot errors (example hyphen ‘-’ vs. ‘‐’).
It must be noted that modifying .conf files in this manner will not ensure that all profiles will be saved.
This is particularly true if this procedure is used for .conf files being used on different versions of FortiOS.
Related Document:
Migrating a FortiGate configuration manually using configuration files
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.