FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ashaikh
Staff
Staff
Article Id 214916

Description

 

This article explains how to import a configuration backup of a FortiGate-50E to 52E.

 

Scope

 

FortiGate 50E and 52E.

 

Solution

 

FortiGate-50E and FortiGate 52E are quite similar in terms of the number of interfaces and functionality.

In a situation when replacing a FortiGate-50E with 52E, the configuration backup of 50E requires a simple tweak after which this modified configuration file is ready to be restored on FortiGate-52E.

 

Pre-requisites : 

 

1) Working configuration backup taken from FortiGate 50E. 

 

On FortiGate GUI Admin -> Configuration -> Backup.

 

2) Admin credentials for FortiGate 50E.

 

3) Serial console access for FortiGate 52E.

 

Here are the steps to be followed :

 

1) Setup 52E configuration for management access preferably GUI.

 

2) Upgrade 52E to the same software build on which 50E config backup was taken on.

 

3) Login to CLI of 52E and run the command 'show' as shown in the example below.

 

FGT-52E # show
#config-version=FGT52E-6.2.10-FW-build1263-211103:opmode=1:vdom=0:user=administrator
#conf_file_ver=431098752501780
#buildno=1263
#global_vdom=1
config system global

 

4) Copy the first line as shown below:


#config-version=FGT52E-6.2.10-FW-build1263-211103:opmode=1:vdom=0:user=administrator

5) Open the configuration file collected from FortiGate-50E in a notepad and replace the first line with the line taken from 52E in step4.

 

6) Save the modified file and restore it to the 52E.

 

On FortiGate GUI, go to Admin -> Configuration -> Restore.

 

7) The device will reboot and come up with the restored configuration.

 

8 ) Verify if there are any config import errors under ' diag debug config-error-log read'.

 

Note: The other access methods are used to restore the modified configuration provided step 3,4,5 are followed properly.

Contributors