Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
robertcrichton
New Contributor

Migrate config from FG100D-6.2.10 to FG101F-6.4.6 without Forticonverter

Hi everyone we have a deadline days whereby our old and trusty 100Ds run out of license runway. We have 2 new 101F plugged in at factory default ready to take over. 

 

Lifting and shifting the config fails out of the box - so we find out we need FortiConverter. 3 days later we are still waiting on a sales person rocking up to sell us. 

 

Found this article about taking the text file from "old" and "new" and editing the first line only ((?)) and putting that over my "old" figs first line. 

 

? Is that it or am i not getting lost - has anyone done a config lift and edit then shift that could possibly help please? The new unit I can hard reset and get back to factory if it comes to it and build the new unit line by line ...slow...but prefer see what Converter can do (as the offical supported route - mind you am also like ETA how long do they take? ) but as the Sales folks oddly havent responded am now getting a bit drastic and looking for some field craft advice on the editing of old config to stick on my new boxes approach Thanks!

4 REPLIES 4
AlexC-FTNT
Staff
Staff

In addition to the first line, you should remove all the "uuid" fields. These are automatically calculated. Also, make sure you regenerate the certificates after loading the config. Not lastly - you must move the config from 100D 6.2.10 to  101F 6.2.10 (the same version), then upgrade the 101F. If this is not possible (due to 101F being too new for 6.2 firmware), use a trial VM for this process.

 

And maybe most importantly: "Lifting and shifting the config fails out of the box" - try again after replacing the first line (and UUIDs if using a logging device), and see what errors you receive "get system startup-error-log" - most should be cosmetic only. However, FortiConverter is the safest way to go. 


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
AlexC-FTNT

There is FortiOS 6.2.10 for 101F - so start by installing FortiOS 6.2.10 on the 101F 


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Yurisk
SuperUser
SuperUser

Forticonverter is the surest way to go, as Alex said, but after all Fortigate configuration file is a text file you can copy&paste from to the new FGT101F part by part via CLI, after deleting all UUIDs from the text file. It will take time and patience, but is totally doable. 

 

Have you contacted your local Fortinet account manager or FTNT directly? because regarding FortiConverter, as I understand, there is an option of buying it directly from FOrtinet, not local AM , may worth your attention, who knows  - https://docs.fortinet.com/document/forticonverter-service/20.1.0/online-help/933819/general-faqs 

 

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
robertcrichton

Thanks both !! Am hoping to hear back today from a sales person re converter - the VPN that my 100D hosts took my a while of brain pain to setup so am hoping converter will also shift it to save me doing this manual rebuild or dirty config edit process. thanks again all

Labels
Top Kudoed Authors