Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ClayN
New Contributor

Upgrading From One FortiGate to Another

Hello. I' m new to this forum, so I hope this question is in the right place. I have a FortiGate60 up and running (firmware 3.00). I would like to replace it with a new FortiGate 60C. Is this as easy as copying the configuration from the older FortiGate to the new one? Would there be some problems because they run different versions of firmware? Any suggestions are appreciated.
3 REPLIES 3
Dave_Hall
Honored Contributor

Ideally, when migrating from one fgt model to another, both devices should be on the same firmware. Then it would be a matter of copying the header line from the target model' s config file and pasting it into the source fgt' s config file. If the ports do not match up on either fgts, you will need to substitute or duplicate (i.e. virtually create) the old ports on the replacement fgt. (There are several threads on these forums about this.) Fortinet has provides a firmware upgrade path to help you with getting your fgt device to a firmware you want. Unfortunately, 3.0 MR7 Patch 10 is the last firmware update for the 60. And the earliest firmware for the 60C seems to be approx. 4.0 MR2 patch 2 (or there abouts). (Too lazy to look up the actual version numbers, but I think rwpatterson has a list.) You may be better off putting both fgt devices side-by-side (browser-wise) and " manually" replicating the config settings from the 60 to the 60C. (Personally, I would load up both the 60 config and a clean 60C config into Winmerge (or other text comparent tool) and selectively " migrate" settings over.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
billp
Contributor

You can' t do this cleanly, unfortunately. There is a half-baked work-around, though. You can take the old config and edit it in notepad++ or similar editor. Then upload the relevant parts of the config to the new box section by section. This works reasonably well. You need to be aware of the firmware syntax changes between your old box and your box, though, so you don' t upload an incompatible setting. For the most part, the box will reject configs that are invalid, so it' s relatively safe to upload chunks that you are reasonably sure have not changed between versions. It' s still some work to do the upgrade, but it' s better than re-entering hundreds of lines of custom changes. Hope that helps.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
rwpatterson
Valued Contributor III

If you trust me, send off a copy of the backup. I' ll lay it into a 60B I have hanging around, upgrade to the version the 60D supports, and send it back.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors