Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
volkerdose
New Contributor II

Migrate ADVPN hub to new hardware

Hello everyone,

 

I have a question to which I was not able to find an answer yet.

We have a SDWAN/ADVPN setup with one hub (vdom on a 400E) and about 80 spokes. 

For the hub we want to buy a new 200G, mainly because of the 10GB interfaces.

 

I have found a couple of articles here about migrating a Fortigate to a new model and this article (346859) points out, that i have to add the new 200G to Fortimanager with the help of Forticonverter.

 

Our SDWAN/ADVPN setup is a couple of years old (we started with 6.4) and I wonder if there is way to migrate the hub without breaking all the scripts. 

 

Under VPN Manager -> IPSec VPN communities we have ADVPN-1, ADVPN-2 and ADVPN-3. Every ADVPN has  the same Fortigate with the "Hub"-role - and this is bound to the serial of the device. 

 

I would like to replace this object with the new 200G....

 

Is there a document around, that shows how to do this?

 

Or do I need to create all the SDWAN/ADVPN stuff from scratch?

 

Best regards

Volker

1 Solution
Jean-Philippe_P
Moderator
Moderator

Hello again Volker,

 

I found this solution. Can you tell us if it helps you, please?

 

To migrate your SD-WAN/ADVPN setup to a new FortiGate 200G without breaking existing scripts, you can follow these general steps:

  1. Preparation:

    • Ensure that your FortiManager and FortiConverter are up to date.
    • Backup the current configuration of your existing FortiGate 400E.

  2. FortiConverter Service: Use the FortiConverter Service to assist in migrating configurations from the FortiGate 400E to the new 200G. This service helps in converting and adapting configurations to the new model, minimizing errors and redundancy.

  3. FortiManager Integration: Add the new FortiGate 200G to FortiManager. This will allow you to manage the new device centrally and apply existing policies and configurations.

  4. Configuration Transfer: Transfer the existing SD-WAN and ADVPN configurations to the new FortiGate 200G using FortiManager. Ensure that the configurations are adapted to the new hardware specifications and interfaces.

  5. Update VPN Manager: In FortiManager, update the IPsec VPN communities to replace the old hub device with the new FortiGate 200G. This involves changing the device serial number and ensuring that the new device is recognized as the hub.

  6. Testing: Before fully deploying, test the new setup in a controlled environment to ensure that all configurations work as expected and that scripts are not broken.

  7. Deployment: Once testing is successful, deploy the new FortiGate 200G as the hub in your live environment.

 

Unfortunately, there is no specific document provided in the context that details this exact process. However, these steps should guide you in migrating your setup. If you require further assistance, consider reaching out to Fortinet support or consulting the FortiManager and FortiConverter documentation for more detailed guidance.

Regards,
Jean-Philippe - Fortinet Community Team

View solution in original post

5 REPLIES 5
Jean-Philippe_P
Moderator
Moderator

Hello volkerdose, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again Volker,

 

I found this solution. Can you tell us if it helps you, please?

 

To migrate your SD-WAN/ADVPN setup to a new FortiGate 200G without breaking existing scripts, you can follow these general steps:

  1. Preparation:

    • Ensure that your FortiManager and FortiConverter are up to date.
    • Backup the current configuration of your existing FortiGate 400E.

  2. FortiConverter Service: Use the FortiConverter Service to assist in migrating configurations from the FortiGate 400E to the new 200G. This service helps in converting and adapting configurations to the new model, minimizing errors and redundancy.

  3. FortiManager Integration: Add the new FortiGate 200G to FortiManager. This will allow you to manage the new device centrally and apply existing policies and configurations.

  4. Configuration Transfer: Transfer the existing SD-WAN and ADVPN configurations to the new FortiGate 200G using FortiManager. Ensure that the configurations are adapted to the new hardware specifications and interfaces.

  5. Update VPN Manager: In FortiManager, update the IPsec VPN communities to replace the old hub device with the new FortiGate 200G. This involves changing the device serial number and ensuring that the new device is recognized as the hub.

  6. Testing: Before fully deploying, test the new setup in a controlled environment to ensure that all configurations work as expected and that scripts are not broken.

  7. Deployment: Once testing is successful, deploy the new FortiGate 200G as the hub in your live environment.

 

Unfortunately, there is no specific document provided in the context that details this exact process. However, these steps should guide you in migrating your setup. If you require further assistance, consider reaching out to Fortinet support or consulting the FortiManager and FortiConverter documentation for more detailed guidance.

Regards,
Jean-Philippe - Fortinet Community Team
volkerdose

Dear Jean-Phillipe,

 

thank you very much. I understand that the bullet points 4 and 5 carry a slight risk ...

We also have the challenge, that the ADVPN hub is a vdom - I wonder how this will affect the migration process.

 

But anyway, thanks again, we will postpone the migration as we can extend the support for our 400e.

Best regards,

Volker

Jean-Philippe_P

Hello Volker,

 

Glad that it helped :) Do not hesitate if you have further questions!

Regards,
Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors