Requirements before proceeding:
- Have admin access to the FortiGate, as well as both the source and destination migration FortiCloud and FortiGate Cloud accounts.
- Be a master account user.
- Log migration is only supported within the same FortiGate Cloud region.
Migrating FortiGate to a different FortiGate Cloud account:
From the FortiGate Cloud portal:
- FortiGate Cloud 'Assets'/'Network Overview'.
- Select the gear icon on the line of the FortiGate to migrate.
-
Select 'Migrate Existing Data'.
-
Enter the email of the destination 'FortiGate Cloud' main account and 'submit'. The data will be migrated.
-
Go to FortiGate and reactivate FortiGate Cloud using the main account email for the destination FortiGate Cloud account in the CLI command:
execute fortiguard-log login <destination account email> <password>
-
The device joins the destination FortiGate Cloud account in the same region (US | Europe | Global) as it had in the source FortiGate Cloud Account. All of the logs will now be available in the destination FortiGate Cloud account.
Notes:
- After logging in to the destination account, logs are no longer visible in the source account.
- For FortiGate clusters, each cluster member has to be moved individually.
- FortiCloud keys cannot be used to move a FortiGate from one account to another if the FortiGate already exists in one FortiCloud account.
- Migrating logs between different FortiGate Cloud regions are not supported.
After FortiGate Cloud migration, the device is still registered to the previous Asset Management Portal:
The process above only affects FortiGate Cloud logging and central management. The license and any support contracts are still associated with the Asset Management Portal in the existing FortiCloud account. If an administrator logs out of FortiGate Cloud and later attempts to log in to FortiGate Cloud from GUI, the account shown will be the current FortiCloud account id. To reconnect to the destination FortiGate Cloud account, use 'execute fortiguard-log login' as in step 5.
If the FortiGate is moved to FortiGate Cloud but not to FortiCloud, there will be a 'FortiCloud Migration' notification visible next to the device in the new FortiGate Cloud portal. This is expected and informs the FortiGate Cloud administrator that the device license is still registered to a different account.
No action needs to be taken unless asset management should also be transferred including licenses and support contracts. To transfer these, see 'Administration Guide: Transfer a device to another FortiCloud account'.
|