Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Maerre
Contributor II

Migrating on premise Fortianalyzer to Azure

Hello,

i need to move my on premise Fortianalyzer to Azure.

How can i move my license actually associated to the on premise faz to the new one on azure?

Is it feasible?

I would like to do the following:

 

  1. create the new faz on azure
  2. import the old faz configurazion
  3. transfer the on prem license to the new azure Faz
  4. change the ip on all the fortigates to the new Faz
  5. be able for a short period to access the on prem faz to see the old log (i.e. for two weeks), i these case i need a trial license or because it's receiving no logs i'll be able to access the machine with no license?

haven't found documentation about transferring the licence, so i think i just need to go on my forticloud and change the serial number of the old on prem faz with the new one, is it correct?

And at which stage of the deployment should i select the BYOL ?

 

Thank you

Regards

1 Solution
Jean-Philippe_P
Moderator
Moderator

Hello Maerre,

 

I found this solution, can you tell me if it helped, please?

 

To move your on-premises FortiAnalyzer to Azure and handle the license transfer, follow these steps:

 

  1. Create the New FortiAnalyzer on Azure: Deploy a new FortiAnalyzer instance in Azure. Ensure it is in a location accessible by your FortiGate-VM.

  2. Import the Old FortiAnalyzer Configuration: Backup the configuration from your on-premises FortiAnalyzer and restore it to the new Azure FortiAnalyzer.

  3. Transfer the License: You will need to contact Fortinet Support to assist with transferring the license from your on-premises FortiAnalyzer to the new Azure instance. This typically involves updating the serial number in your FortiCloud account.

  4. Change the IP on All FortiGates: Update the FortiGate devices to point to the new FortiAnalyzer IP address in Azure.

  5. Access the On-Premises FortiAnalyzer: You can access the on-premises FortiAnalyzer for a short period to view old logs. If it is not receiving logs, you may still access it without a license. However, for extended access, you might need a trial license.

  6. Select BYOL (Bring Your Own License) During Deployment: During the deployment of the new FortiAnalyzer in Azure, select the BYOL option to use your existing license. Ensure you have all necessary backups and have coordinated with Fortinet Support for the license transfer to avoid any service interruptions.
Jean-Philippe - Fortinet Community Team

View solution in original post

5 REPLIES 5
Jean-Philippe_P
Moderator
Moderator

Hello Maerre, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello Maerre,

 

I found this solution, can you tell me if it helped, please?

 

To move your on-premises FortiAnalyzer to Azure and handle the license transfer, follow these steps:

 

  1. Create the New FortiAnalyzer on Azure: Deploy a new FortiAnalyzer instance in Azure. Ensure it is in a location accessible by your FortiGate-VM.

  2. Import the Old FortiAnalyzer Configuration: Backup the configuration from your on-premises FortiAnalyzer and restore it to the new Azure FortiAnalyzer.

  3. Transfer the License: You will need to contact Fortinet Support to assist with transferring the license from your on-premises FortiAnalyzer to the new Azure instance. This typically involves updating the serial number in your FortiCloud account.

  4. Change the IP on All FortiGates: Update the FortiGate devices to point to the new FortiAnalyzer IP address in Azure.

  5. Access the On-Premises FortiAnalyzer: You can access the on-premises FortiAnalyzer for a short period to view old logs. If it is not receiving logs, you may still access it without a license. However, for extended access, you might need a trial license.

  6. Select BYOL (Bring Your Own License) During Deployment: During the deployment of the new FortiAnalyzer in Azure, select the BYOL option to use your existing license. Ensure you have all necessary backups and have coordinated with Fortinet Support for the license transfer to avoid any service interruptions.
Jean-Philippe - Fortinet Community Team
Maerre

Hello @Jean-Philippe_P ,

 

thank you so much for your post, next week i'm gonna deploy the new azure FAZ instance so i'll follow your tips.

I've still got some further questions:

is there any documentation about which azure vm to be chosen for the deploy? How many vCpu, Ram or log ingestion rate should i keep in mind to select the correct Vm instance?

The official datasheet documentation only refers to physical appliance or private Vm but not on Azure instances.

On Azure side there are a lot of instances but they differ only about the Ram or vCpu used, so i'd like to understand what would be more suitable for me, for example based on what requirements should i choose the "Standard_D4_v3" instance with 4 vCpu and 16 gb of Ram instead of the "Standard_D8_v3" instance with 8 vCpu and 32 gb of ram?

Selecting the correct Azure Instance is crucial both for the cost and to have a VM that performs correctly.

So the actual question and doubt is: based on my actual on premise FAZ deployment, which requirements should i keep in mind to select and deploy the correct Azure instance?

 

Thank you

Regards

Bashi
New Contributor

@Maerre 
Good day!

Appriciate if you could share how did you go with this. Any specific ways you followed? Any challanges you faced. What steps should be included to migrate it smoothly
Thanks

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors