Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FirewallNoob
New Contributor III

New ISP for WAN Config Question

Hi Everyone - first post here. I'm new to fortinet but hopefully I have a simple question for the experts. We are about to activate a new WAN service from a new ISP. Currently, our 100D is configured only for WAN1, but I would like to keep that config as there are a lot of rules and site-site VPN config that I wouldn't know how to duplicate if we brought in the new WAN link and connected it to WAN2. So my question is: can I simply edit the .cfg backup file from the existing config and search for all references to my existing IP and replace it with the new IPs? Then, once it's up and running on the new IP I can go back and take my time and manually build WAN2 as a redundant link. The current WAN1 link is just a slow 20Mb/20Mb and the new is 100Mb/100Mb. Since the switchover is so critical this method seems like it would be really fast and basically come online instantly, the site-site tunnel would reestablish itself after i changed the IPs on the destination fortigate also. Anyone with experience do something like this?

Thanks!

1 Solution
MikePruett

you can edit the config and find and replace. 

 

 

You can copy the policies relating to WAN1 and find and replace them with wan2 for the new circuit. Then just putty into the Gate and past the policy set in (be sure to change "edit 13" "edit 20" etc with "edit 0" so it will pick the next available policy ID instead of overwriting the existing ones though.

View solution in original post

Mike Pruett Fortinet GURU | Fortinet Training Videos
3 REPLIES 3
FirewallNoob
New Contributor III

Wow after 75 views...nobody's done anything like this before? Is Fortinet support watching these forums or should I contact them directly?

MikePruett

you can edit the config and find and replace. 

 

 

You can copy the policies relating to WAN1 and find and replace them with wan2 for the new circuit. Then just putty into the Gate and past the policy set in (be sure to change "edit 13" "edit 20" etc with "edit 0" so it will pick the next available policy ID instead of overwriting the existing ones though.

Mike Pruett Fortinet GURU | Fortinet Training Videos
FirewallNoob

Fantastic! Thank you for confirming that Mike and great idea about copying the policies in the CLi also. That will probably save me many days of trying to figure it all out!

Labels
Top Kudoed Authors