We've got a small setup with two locations, a FAC, FAZ, and FGT at the main location, and a FGT at the branch location (IPsec connection), set up for 6.0.x security fabric.
I'm replacing the FAZ 200D with a FAZ 200F (so we can be set to move to 6.2.x later) and haven't been able to find consistent documentation on how to move over to it. Would really appreciate any comments or suggestions. Here's what I've worked out so far, which is:
[ul]
After getting the new FAZ set up, the next question is what is the best method for switching the FortiGates to it?
I could set the new FAZ to have the same IP as the old one, but I'm betting the FortiGate would see that as a security error. Or I can point the root FortiGate at the new FAZ IP, which should filter down to the branch FortiGate, though I assume I probably need to also accept it on the FAZ side again? If use the new FAZ IP, I will need to change my security policies for IPsec to allow the logs through to the new IP, etc.
Only after all this is up and stable for a while would I then upgrade the FAZ to 6.2.x.
So, what am I missing and are there easier ways to do this?
Also, will this method bring over my custom reports, custom datasets, custom event handlers, etc.?
Thanks in advance for any help with this.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Finished this and want to pass on what worked when transferring to different new FAZ hardware.
[ul]
Hope this is helpful.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.