Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
capricorn80
New Contributor II

Moving configr from old FW to New FW

Hi!

 

We have bought new Fortigate FW and new one has different interfaces with SFP. 

 

What is the best way to move old config to new Firewall?

 

Regards,

 

Capricorn

3 REPLIES 3
sw2090
Honored Contributor

We had this here quite often ;)

 

However:

 

if not the new FGT has the same interface names the best way might be to create an (unencrypted) backup since this is just a text file. Edit this with an editor of your choice and correct the interface names.

You should also check the firmware version on old and on new FGT and look up the upgrade path because this could also affect your config. If the old FGT is on an older Firmware I recommond a downgrade on the new one to the same version. Then apply the config backup and then upgrade again according to the documented upgrade path.

 

Also you could instead of restoring your backup also use the cli and copy paste part by part. In this case you would have to remove some lines in your congih, like snmp-ids or set policy numbers to zero to make the FGT generate new policiy ids upon setting up this policy.

 

I used the second way to migrate  configs from FGT 80C/110C to 100E (and from Firmware v5.2 to 5.4 with that). Cost a load of time but worked fine.

 

HTH

Sebastian

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
capricorn80
New Contributor II

Thanks Sebastian

 

Yes copy/paste is easy way to do it. I will see if I can find some Ansible script to create the objects.

I have IPSec and SSL tunnel as well.

Backup the local username/password is also I am looking for and also ther SSL certifcate.

Let see how it goes.

 

By the way how did you configure your 100E as we will use the same model. Do you have some guide/doc with its configuration example?

 

sw2090
Honored Contributor

Well....

 

I took the old FGT. Upgraded it accoarding to upgrade path (glad there is 5.4 for 80C and 110C) and then created an unencrypted backup. 

From this I then took the parts I needed. That was Interface setup (physical and vlan), IPSec tunnels, SNMP, static Routes, global settings. I edited those to have them fit the 100E (different interface names an that stuff) and then copy pasted them into the 100E on CLI.

I didn't need to copy policies or objects since after this basic setup I added the 100E to our new Fortimanager and it then got Policies and Objects from there.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors