FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
saleha
Staff
Staff
Article Id 324308
Description

This article describes how to perform the a common task of migrating managed devices such as FortiSwitch and FortiAP when migrating from one FortiGate device to another.

Scope FortiSwitch, FortiAP, FortiGate.
Solution
  • Before migration, it is recommended to ensure that both the old FortiGate and the new or replacement FortiGate are running matching FortiOS release versions to avoid conflicts between commands, settings, and features. 
  • The old FortiSwitch can be de-authorized, and disconnected from the old firewall. Then, after connecting the switch to the new firewall and completing the process to get the FortiSwitch online and managed by the new FortiGate, the 'switch-controller' configuration can be copied from the old firewall to the new firewall.

    This config would be located under 'config switch-controller managed-switch'. There will be an entry for each switch the FortiGate is managing, all of the configs for that switch and each port on that switch will be present. 


switch.PNG

Alternatively, the switch-controller configuration can be copied to the new FortiGate first, even though the FortiSwitch(es) are not yet managed or connected to the new FortiGate. Follow up with the physical connection at the planned time for migration. 

  • A different approach to manual migration is to utilize FortiConverter services, which is a license-based service that includes assistance from the FortiConverter team. See this document.