How to carry out a FortiGate migration in a multi-site network
1. Inventory your existing FortiGate infrastructure
Every successful migration starts with a clear picture of the current state. Gather information on every FortiGate unit in your network, including model number, current firmware version and configuration detail for each site.
Build a structured inventory that includes network interfaces, VDOM configurations and active VPN tunnels. This documentation becomes your reference point throughout the migration.
Identify any FortiToken or MFA configurations that need special handling. Tokens are tied to a device's serial number and cannot move directly to new hardware.
2. Plan the migration order for each site
In a multi-site environment, migration order determines how much disruption you cause. Categorize your sites by business criticality and by the network dependencies between locations.
Start with less critical sites to build experience and refine the process before tackling your most central nodes. This approach reduces the risk of a large-scale outage.
Build a schedule that accounts for local time zones and business cycles. A site with high daytime activity should get migrated during evenings or weekends.
3. Back up every FortiGate configuration
Backups are your safety line through the entire migration. Create full configuration backups from every FortiGate unit through the GUI or CLI before making any changes.
If you use encrypted backups, document the passwords carefully. You'll need them to restore configurations on the new devices. Store backup files somewhere secure, outside the network being migrated.
For environments with VDOM enabled, confirm your new hardware carries the correct licensing. Most FortiGate models support a maximum of 10 VDOMs by default.
4. Verify firmware compatibility between devices
Firmware versions play a central role in a smooth migration. Upgrade the new FortiGate unit to the same firmware version as the existing device before transferring the configuration.
Check Fortinet's compatibility matrix to confirm the upgrade paths you're planning are supported. Some version jumps require intermediate upgrades.
Document the config-version string from each device's configuration file. You'll need to adjust it when migrating between different models.
5. Convert and adapt configuration files
Migrating between different FortiGate models requires adapting the configuration files. FortiConverter is the recommended tool for automated conversion, though manual editing is an option for experienced administrators.
Open both configuration files in a plain text editor such as Notepad++. Replace the config-version section on the first line of the old configuration with the corresponding section from the new device.
Review interface names and layout differences between models. An FG-80 uses different port names than an FG-100, and these need correct mapping to avoid configuration errors.
6. Validate and test the migrated configuration
Restore the modified configuration file on the new FortiGate unit and reboot. After the reboot, run #diag debug config-error-log read to check for any import errors.
Compare the error log against the two configuration files and correct any discrepancies. Repeat the process until the device starts with no errors.
NetSymphony helps you maintain traceability through the entire validation process. With structured workflows and automatic documentation, your team can verify every step with full audit tracking.
7. Document and monitor after migration
Once the new FortiGate unit is active, swap the cables from the old device. FortiSwitch units connected to the FortiGate keep their previous configuration automatically.
Set a monitoring period after migration to catch anything that didn't surface during testing. Review log files and traffic patterns to confirm normal operation.
Update your network documentation with the new hardware's details, configuration changes and timestamps for completed migrations.
What tools exist for FortiGate configuration migration?
Fortinet offers several paths for configuration migration. FortiConverter Service is the official solution, automating conversion between different FortiGate models and even from competing platforms.
FortiManager can migrate configurations between devices in managed environments. The tool offers centralized control and the ability to push configurations to multiple devices at once.
For organizations with heterogeneous network environments spanning multiple vendors, a platform like NetSymphony provides vendor-agnostic orchestration and automation that connects existing systems together.
How do you handle HA clusters during a FortiGate migration?
Migrating High Availability clusters needs its own planning. When migrating from a standalone device to a new cluster, keep both cluster devices separate at first, with no network or HA cables connected to the secondary unit.
Restore the configuration file on the primary device first. Then edit the secondary device's configuration file, changing the hostname and adjusting HA priority and override settings.
When migrating from an existing HA cluster to a new cluster, restore the configuration file from each old FortiGate to its corresponding new unit before connecting the HA cables. Wait until the cluster is synchronized before connecting network cables.
How NetSymphony supports network migration in multi-site environments
NetSymphony is a vendor-agnostic platform for network lifecycle management and automation. The platform connects existing infrastructure from multiple vendors, including Fortinet, into one unified operational view.
For multi-site migrations, NetSymphony offers structured workflows that guide your team through every step. Automatic documentation makes sure every change is logged and can be traced back to an approved change request.
The ChangeGuard module builds ITSM approval logic directly into operational workflows. Every sensitive action gets validated against policy and executes automatically once conditions are met.
With NetSymphony, you can manage hundreds of sites without growing your IT headcount. The platform automates up to 70 percent of daily network tasks and frees your engineers for strategic projects.