Hi!
We have bought new Fortigate FW and new one has different interfaces with SFP.
What is the best way to move old config to new Firewall?
Regards,
Capricorn
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
We had this here quite often ;)
However:
if not the new FGT has the same interface names the best way might be to create an (unencrypted) backup since this is just a text file. Edit this with an editor of your choice and correct the interface names.
You should also check the firmware version on old and on new FGT and look up the upgrade path because this could also affect your config. If the old FGT is on an older Firmware I recommond a downgrade on the new one to the same version. Then apply the config backup and then upgrade again according to the documented upgrade path.
Also you could instead of restoring your backup also use the cli and copy paste part by part. In this case you would have to remove some lines in your congih, like snmp-ids or set policy numbers to zero to make the FGT generate new policiy ids upon setting up this policy.
I used the second way to migrate configs from FGT 80C/110C to 100E (and from Firmware v5.2 to 5.4 with that). Cost a load of time but worked fine.
HTH
Sebastian
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Thanks Sebastian
Yes copy/paste is easy way to do it. I will see if I can find some Ansible script to create the objects.
I have IPSec and SSL tunnel as well.
Backup the local username/password is also I am looking for and also ther SSL certifcate.
Let see how it goes.
By the way how did you configure your 100E as we will use the same model. Do you have some guide/doc with its configuration example?
Well....
I took the old FGT. Upgraded it accoarding to upgrade path (glad there is 5.4 for 80C and 110C) and then created an unencrypted backup.
From this I then took the parts I needed. That was Interface setup (physical and vlan), IPSec tunnels, SNMP, static Routes, global settings. I edited those to have them fit the 100E (different interface names an that stuff) and then copy pasted them into the 100E on CLI.
I didn't need to copy policies or objects since after this basic setup I added the 100E to our new Fortimanager and it then got Policies and Objects from there.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.