I have several FortiGates and due to having added most of them over the last couple of years, my Fabric root is still my main Internet edge firewall. I want to move this to a new core firewall I setup a few weeks ago but am not seeing any mention about this in the admin guide (running fortiOS 7.0.12).
Is it just a simple changing my core to serve as the Fabric root and my edge to that of "Join Existing Fabric" and repoint my other FortiGates to the new Upstream FortiGate IP (core)? I just want to make sure I won't cause any issues with all of the fabric sync'd address objects I have in play now by making such a change by not going through the correct workflow.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Dear Cajuntank,
Thank you for posting to the Fortinet Community Forum.
Problem Description:-
Let us know if this helps.
Thanks
I understand the deployment, I was just making sure that if I do make that fabric root change and such, all of the address objects that were being sync'd from the old root, would not break due to now trying to come from a new root (if that makes sense). So for example, when I go to my existing root, the address objects give me a Fabric Sync column and show me which objects are enabled for sync. If I change roots, how will that affect those objects at my other firewalls? Will they sync those from the new root or will I lose sync for those objects until I recreate them from the new root?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.