Cisco ASA migration to Fortigate 100F
I am working on coming up with a design to migrate from an older ASA to a 100F. The current config is 2 ISPs coming in to an Edge Router where it is advertising a full class C public network block through BGP. The ASA is handling a lot of NAT policies for all the public services living in a DMZ zone.
I will have 2 100F devices. I was thinking of putting the 1st device (FG1) in parallel with the ASA and giving it an unused public IP on the WAN side and creating the same zones (dmz, lan, voip) with an unused IP in those zones. I would like to move one service at a time from the ASA to the Fortigate. I am also trying not to modify the ASA in any way. Is there a way I could put the second 100F (FG2) in between the ASA and the inside zones and do some type of routing to allow for me to cut a single service over at a time?