Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NeoRant
Contributor

Fortimail VM01(onprem) to Fortimail Cloud Transition

Hello, we currently run FortiMail VM01 on‑prem and have purchased 110 FortiMail Cloud licenses.
What’s the recommended way to transition—can existing settings, policies, and configurations be migrated to the cloud?
Or does everything need to be rebuilt manually from scratch in FortiMail Cloud?
Looking for best practices, steps, or guidance from anyone who has done this migration.

3 REPLIES 3
AEK
SuperUser
SuperUser

I'd not do a backup/restore (probably not compatible), but I'd use CLI to copy most config sections.

AEK
AEK
NeoRant

Morning AEK, i know you have to basically recreate the AS profiles etc, mimic what was in onprem, but regarding the tenant to be used as i will still stick with the on prem exchange server(i guess i have to use the mapped public ip for it in firewall or just use the fqdn .e.g. mail.company.com.au) and regarding this whole thing about putting dns, mx/txt, dkim, spf records etc. Is there a guide in Fortinet how to streamline this transition process/setup?

AEK
SuperUser
SuperUser

I don't think this is documented in Fortinet docs, because this is not really FML specific, it is more DNS specific.

But in that case you can proceed globally as follows:

  1. Prepare your new FML with configuration similar to the existing one
  2. Setup rDNS/PTR for the new FML public IP (check with your ISP)
  3. Add the new A record and MX record to the public DNS, with lower priority (i.e. higher number, e.g. the old is 10 and the new is 20)
  4. Add the new FML public IP to the existing SPF record (in case your SPF doesn't already contain the "mx" option)
  5. Generate a new DKIM in your new FML and add the record in the public DNS
  6. Add an the new FML IP as a receive connector to your Exchange config, so it accepts mails from the new FML (safe during working hours)
  7. On your firewall, allow SMTP(S) inbound and outbound traffic between your MS Exchange and the new FML IP

Then during off hours do the following:

  1. Change the send connector on your Exchange to point to the new FML IP
  2. Change the new MX priority to a low value like 5
  3. Perform some inbound tests to see if the mails are received as expected
  4. Perform some outbound tests by sending mails from the mail server, you can also use mail-tester.com to check your score (should be 10/10)
  5. If the score is lower than 10 then correct the errors and test again until you get 10/10
  6. Roll-back the changes if needed (the send connector and MX value)

If the tests are fine then you can keep the changes.

I think I've mentioned all important steps.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors