My setup is that of your traditional legacy WAN hub (data center) and spoke (branch sites). Currently, my only Internet access is at my data center. Even though they are on private WAN connections, the branch locations' connection to the WAN is via FortiGate (for traffic inspection purposes away from the data center).
I am in the process of adding Internet connectivity to each of these branch sites (will also add secondary Internet connectivity at the data center as well in the near future). I have a fair grasp of what needs to be done and following the hub/spoke guidelines in the SD-WAN Branch Deployment Guide documentation; however, what I am missing is process/procedures or caveats in migrating an existing used interface over to a new zone. So what I mean is, if I have my existing interface in a WAN zone and policies are applied to that zone, will I be able to easily move that interface to the new SD-WAN zone? I know I cannot do anything with the interface while it references something, so I know I have to deal with these things, but I am just trying to make sure I am thinking of everything and have "all my i's dotted and t's crossed" as it were. I know once I move my interface, I will have to change all of my policies to reflect to the new SD-WAN zone.
Hoping someone that has done this can chime in and give some additional thoughts or guidance in case I am missing something.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You can use the Interface Migration Wizard to assist you here: https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/885870/interface-migration-w...
I would definitely suggest testing this during a maintenance window to ensure everything works as expected. But this should take most of the headaches and pain away when moving from legacy to SD-WAN configuration on your existing FortiGates.
Hello
First, it doesn't matter if you fail the first and second try but the most important is to have a quick, clear and valid rollback procedure.
Try prepare your interface migration (the whole procedure or some) by CLI commands in a text file. Then just run it on CLI script when you want to migrate.
Here is a overall scenario:
Hope it helps
You can use the Interface Migration Wizard to assist you here: https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/885870/interface-migration-w...
I would definitely suggest testing this during a maintenance window to ensure everything works as expected. But this should take most of the headaches and pain away when moving from legacy to SD-WAN configuration on your existing FortiGates.
OMG, how did I miss this? I confirmed this is also applicable with fortiOS 7.0.9, which is the code rev I am on. I will have to play around with this, but it looks extremely promising. Thanks.
I attempted this today and that worked fairly well. It failed once with something due to the interface being tied to OSPF, then it let me attempt again and the option was to remove it from OSPF, which I did, though when I compared the configs, the OSPF config was the same as before. I had to manually change my policies over to new SD-WAN zone from old zone (did not know if the process would do that automatically too) but all looked and tested good.
About to try this too in the next few weeks. Did you encounter any problems.
Originally was going to do it 'manually, copy all the policies etc then move the interfaces' but then found this post.
So upgraded to ver7 and going to follow the auto path.
regards,
Chris.
Created on 11-04-2024 05:57 AM Edited on 11-04-2024 05:58 AM
That's been over a year ago and I have slept since then, but it all went well. Like mentioned, the only thing for some reason that hung it up was it did not like being tied to OSPF. Based on what I mentioned before, it must have given me the option to remove it from OSPF, then it processed, but when I looked at it again, that's where I'm a little fuzzy on if I had to actually do anything under OSPF or if it all looked well and I just then had the chore of moving my policies over to use the new zone. All in all, it was fairly painless other than the policy changes... and that was honestly, easy enough.
I totally forgot this. I'm definitely still old school.
Thanks Graham.
Need to do this too, however on an older code 6.4.15 which doesnt have the auto update type option.
Is it worth going to the next code revision to get this done ?
I am thinking yes, it is the sensible thing to get to the latest version and also may save a lot of hassle getting upgraded to SD WAN.
Any opinions welcome.
Chris.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.