Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lukáš_Majoros
New Contributor

FCON and NATs

Hi, I have been using FCON lately for Cisco ASA migration over to the FGT(FMG) but seems like almost all policy which used NAT have ben wrongly created by FCON, same applies to VPNs.

 

FCON randomly creates NATs and policy, looks like he is going for 50/50 functional approach, where somewhere is good SNAT/DNAT, somewhere isn't. Also grouping the policy seems like big problem for him as well.

 

Is this some kind of bug which needs to be reported? Or is this known issue? Because I don't see point of using FCON when I have to do 90% of migration manually anyway.

 01001000 01001001 

🏄 01001000 01001001 🏄
1 REPLY 1
AEK
SuperUser
SuperUser

FCON never does the job 100%, I used it for several PAN migrations, it can migrates interfaces, routes, firewall policies (80%), addresses, central NAT, can make errors for DNAT, and it doesn't migrate many things, like OSPF, all security profiles, ... and many others.

So it helps but you have to do 40% of the job by hand or with scripts if you have many policies and objects.

AEK
AEK
Labels
Top Kudoed Authors