Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gardarr
New Contributor

Migrate from Fortigate 50E to 60E via Fortimanager.

Hi,

 

I have a Fortigate 50E in fortimanager that I need to replace with 60E. What are the steps that I need to make to ensure the same config is on the 60E when I migrate and I have the smallest downtime ? 

 

Thanks, 

7 REPLIES 7
sw2090
Honored Contributor

Unfortunately this is not the easy way. If it is same model you replace with you can simple replace the serial in FMG Cli.

In this case you would have to apply the device config to the 60E. If FGT50E ad 60E have identical port names and numbers you could try to make a backup (Or download the last revision from FMG) from the 50E and also the 60E. Then replace the first 3 or 4 Lines (the ones with beginning with a "#") in the FGT50E backup with those from the 60E Backup. Then try to restore it on the 60E. With same Port names and numbers this cheat usually works.

Then add the 60E to FMG.

If you use provisioning template and/or a default policy package in that adom you should roll it out the the FGT60 afterwards.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
gardarr
New Contributor

THanks for your reply.

 

Would I have to have the same version of software running on both boxes ? One is 5.4 and one is 5.6

sw2090
Honored Contributor

sorry I forgot to mention that: yes

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
gardarr
New Contributor

But I can't upgrade the 50E to 5.4, only 5.3 and 5.6. 

 

Should I then upgrade the 50E to 5.6.6 and 60E to 5.6.6 as well ?

sw2090
Honored Contributor

if there is a vaild upgrade path for the 50e from your current firmware verson to 5.6.6 I'd upgrade both to 5.6.6.

You need to keep the upgrade path in oderder not to loose or damager (parts of) your config.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
gardarr
New Contributor

Yes I think that is the best way.

 

One other thing. When I switch out the boxes, should I switch the mgmt ip address also or use the same ? Can i add the new firewall to the manager with the same ip address that the old one was using ?

 

Thanks :) 

sw2090
Honored Contributor

Afaik Ip and name in FMG is unique. THis means you cannot have two FGT with same hostname or ip at the same time in FMG no matter if it is in same adom or different.

So either you'd have to remove the old one first or you give the new one a different management ip.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors