Hello everyone,
I have a question to which I was not able to find an answer yet.
We have a SDWAN/ADVPN setup with one hub (vdom on a 400E) and about 80 spokes.
For the hub we want to buy a new 200G, mainly because of the 10GB interfaces.
I have found a couple of articles here about migrating a Fortigate to a new model and this article (346859) points out, that i have to add the new 200G to Fortimanager with the help of Forticonverter.
Our SDWAN/ADVPN setup is a couple of years old (we started with 6.4) and I wonder if there is way to migrate the hub without breaking all the scripts.
Under VPN Manager -> IPSec VPN communities we have ADVPN-1, ADVPN-2 and ADVPN-3. Every ADVPN has the same Fortigate with the "Hub"-role - and this is bound to the serial of the device.
I would like to replace this object with the new 200G....
Is there a document around, that shows how to do this?
Or do I need to create all the SDWAN/ADVPN stuff from scratch?
Best regards
Volker
Solved! Go to Solution.
Hello again Volker,
I found this solution. Can you tell us if it helps you, please?
To migrate your SD-WAN/ADVPN setup to a new FortiGate 200G without breaking existing scripts, you can follow these general steps:
Preparation:
FortiConverter Service: Use the FortiConverter Service to assist in migrating configurations from the FortiGate 400E to the new 200G. This service helps in converting and adapting configurations to the new model, minimizing errors and redundancy.
FortiManager Integration: Add the new FortiGate 200G to FortiManager. This will allow you to manage the new device centrally and apply existing policies and configurations.
Configuration Transfer: Transfer the existing SD-WAN and ADVPN configurations to the new FortiGate 200G using FortiManager. Ensure that the configurations are adapted to the new hardware specifications and interfaces.
Update VPN Manager: In FortiManager, update the IPsec VPN communities to replace the old hub device with the new FortiGate 200G. This involves changing the device serial number and ensuring that the new device is recognized as the hub.
Testing: Before fully deploying, test the new setup in a controlled environment to ensure that all configurations work as expected and that scripts are not broken.
Deployment: Once testing is successful, deploy the new FortiGate 200G as the hub in your live environment.
Unfortunately, there is no specific document provided in the context that details this exact process. However, these steps should guide you in migrating your setup. If you require further assistance, consider reaching out to Fortinet support or consulting the FortiManager and FortiConverter documentation for more detailed guidance.
Hello volkerdose,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Hello again Volker,
I found this solution. Can you tell us if it helps you, please?
To migrate your SD-WAN/ADVPN setup to a new FortiGate 200G without breaking existing scripts, you can follow these general steps:
Preparation:
FortiConverter Service: Use the FortiConverter Service to assist in migrating configurations from the FortiGate 400E to the new 200G. This service helps in converting and adapting configurations to the new model, minimizing errors and redundancy.
FortiManager Integration: Add the new FortiGate 200G to FortiManager. This will allow you to manage the new device centrally and apply existing policies and configurations.
Configuration Transfer: Transfer the existing SD-WAN and ADVPN configurations to the new FortiGate 200G using FortiManager. Ensure that the configurations are adapted to the new hardware specifications and interfaces.
Update VPN Manager: In FortiManager, update the IPsec VPN communities to replace the old hub device with the new FortiGate 200G. This involves changing the device serial number and ensuring that the new device is recognized as the hub.
Testing: Before fully deploying, test the new setup in a controlled environment to ensure that all configurations work as expected and that scripts are not broken.
Deployment: Once testing is successful, deploy the new FortiGate 200G as the hub in your live environment.
Unfortunately, there is no specific document provided in the context that details this exact process. However, these steps should guide you in migrating your setup. If you require further assistance, consider reaching out to Fortinet support or consulting the FortiManager and FortiConverter documentation for more detailed guidance.
Dear Jean-Phillipe,
thank you very much. I understand that the bullet points 4 and 5 carry a slight risk ...
We also have the challenge, that the ADVPN hub is a vdom - I wonder how this will affect the migration process.
But anyway, thanks again, we will postpone the migration as we can extend the support for our 400e.
Best regards,
Volker
Hello Volker,
Glad that it helped :) Do not hesitate if you have further questions!
| User | Count |
|---|---|
| 2806 | |
| 1426 | |
| 812 | |
| 762 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.