FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
asengar
Staff
Staff
Article Id 257907
Description This article describes how to deploy from non-SD-WAN to SD-WAN setup by adding the ISP links (interfaces) to SD-WAN members without deleting the references.
Scope FortiOS 7.0.x and Higher.
Solution

- To deploy SD-WAN on the current running setup without having a large downtime window.

- Initially, if a migration needs to be done from non-SD-WAN to SDWAN then while adding the ISP links in SDWAN, it was asking to delete all the references of the link(port) in order to add in SD-WAN member.

- Due to the deletion of the reference it required a large downtime window also along with additional configuration.

- From version 7.0.x without deleting the reference, it is possible to add the interface in SD-WAN existing zone or can create a new zone.

 

Steps:
1) Go to Dashboard -> Network -> Interfaces.
2) Select the interface from the list which needs to be added to the SD-WAN member.
3) After selecting interface, select the option Integrate Interface on the top as shown in the below picture.

 

2a23153b-9668-46bc-85c7-aac81a8a7552.jpg

 

4) Selecting the integrated interface gives 3 options, select the last option to add in SD-WAN, select 'Next' and select the zone from the dropdown list.

 

cc07d4fd-0df4-4d10-a140-55f52c60f349.jpg

 

4e305e55-6e73-4396-8e7f-5d4ac634f06e.jpg


5) Post selection of the zone click Next, It will show all the reference and ask to delete the reference or replace the same with a new instance.

 

1ef6c8bf-7f99-4513-8ebb-590e51559d26.jpg

6) Once the settings are applied it will reflect in the SD-WAN, so it avoids any additional configuration in the policies.


It is possible to change the interface type, define VLAN ids with the help of Integrate Interface Option.


Note:

Once the changes are done i.e. from the Physical interface to another, later on, this does not support turning an aggregate, software switch, redundant, zone, or SD-WAN zone interface back into a physical interface.


Interface migration wizard | FortiGate / FortiOS 7.0.0 (fortinet.com).