Hi I am new to FortiGate firewalls.
We are planning to upgrade the existing FW which is FG300C 5.2.2 to FG300E latest fortios. I would like to know if there is any recommendation that i have to consider or some procedure which i can follow for the upgrade.
Thank you
Solved! Go to Solution.
keep two things in Mind:
[ul]
If you do not need to preserve your config you don't need to do this of course. In this case upgrade it to the latest FortOS and then config from scratch :)
hth
Sebastian
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
As it turns out the 300E is a brand-new model which is supported by FOS v5.6 only. This is often the case when you keep the hardware for, say, more than 5 years, and buy the latest HW.
But, as so often, there's a light side to this:
if you reconfigure from scratch you will wade out a lot of 'historical' objects, like addresses, services, policies. There even could be more efficient ways to achieve a protection because FOS has evolved over time.
'from scratch' isn't meant literally, you can reuse chunks of the config (like address definitions) by cut&paste between old and new config file. Inserting into the running config will give you instant feedback of syntactical errors; OTOH the amount of 'live pasted' code is limited (finally, you'll run into a timeout).
To faciliate live pasting:
open a second console window (SSH), enter 'diag deb ena', 'diag deb cli 7'. Now, the command line interface will be quite chatty so you can spot the reason for an error more easily.
FG-300C is not supported in FOS v5.6! there is no firmware which supports both models.
why don't you use the forticonverter ? :
Can migrate configurations between FortiGate devices to minimize the risk associated with network upgrades. Facilitates migration to new hardware models from legacy FortiGate devices. This feature is enabled with the trial license
oh yeah great idea loic. Just had forgotten that this exists xD
Will be worth a try maybe. However on my tries I always lost something on conversion (e.g. setup of my interfaces)...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hi,
Unfortunately, you can not update from a 300c to a 500e. usually you can save the config, change the header and read in a new fortigate. in the textfile you can also change the interfaces with search and replace. between 5.2 and 5.6, however, the hash value has changed for the encrypted passwords. Unfortunately, it is now impossible to simply transfer the config. that does not work with the forticonverter, which is more intended to convert configurations from other manufacturers. if you do not want to rewrite the complete config, you can do the detour via a 300d. Take a 300d 5.2 on it, copy 300c config on the 300d and make the update steps to 5.6.3 Maybe your reseller can help you out with a piece of her own
we have done this way from 300c to 500e.
Regards,
andy
Fortigate 500E HA Fortimail 200 Fortimanager
FortiEMS
FortiSandbox 1000D
FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------
ok than do it as I wrote before copy paste part by part and manually fix the errors.
And reset your passwords because of the hashes (wich also changed from 5.2 to 5.4 as I noticed).
Or as andy wrote get a 300d and do what he wrote.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
ok than do it as I wrote before copy paste part by part and manually fix the errors.
And reset your passwords because of the hashes (wich also changed from 5.2 to 5.4 as I noticed).
Or as andy wrote get a 300d and do what he wrote.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Thanks Guys.. Really appreciate your response it will be very helpful for me.
I am planning to go with upgrading via 300D which i will loan from my vendor. (hopefully). Else forticonverter as suggested. The last option would be to do it manually which is more accurate but stressful.
I will post here on how it went.
Thanks again
I'd go with using the 300D as as bridge between the two models. I've done this successfully with converting 60Bs to 60Ds (using a 60C as the bridge between both).
Well that's bad luck then :(
In this case you have no choice than start from scratch and copy your config partwise. Rating Overrides or Policies or Interface setup should work but you may have to fix it manually.
I did that too with old configs...part by part with fixing worked fine. And - as edepfau wrote - you get rid of a load of old and obsolete things (that were obsoleted by fortinet or you) :)
cheers
Sebastian
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.