cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9927
Views
0
Helpful
8
Replies

Moving from Cisco ASA to Fortigate

matti_nok
Level 1
Level 1

Hey,

 

I'm started as trainee job couple weeks ago and my first task is to migrate Cisco ASA to a Fortigate firewall. I have CCNA experience so I'm not completely lost. 

 

My problem is how to move all the VPN credentials from Cisco to FortiGate one? I've rarely touched firewalls and the ones is touched were usually running pfSense.

 

Another question/problem is, that is there any easy way to extract Cisco ASA configuration (ASMD is not working) apart just from logging everything with PuTTY?

 

Tanks in advance!

 

 

 

 

8 Replies 8

1) If you need the PSKs when referring to the VPN-credentials, then the following command will show them:

asa# more system:running-config | b tunnel-group

User-passwords are hashed and not extractable in plain-text.

2) You can use the "backup" command in CLI and generate a ZIP-file with all configuration that you can transfer to your PC.

Thanks for your answer.

 

Never used backup command need to look into it, any pointers?

Thanks...

AlexPi
Level 1
Level 1

Hello Matti,

 

Have a look at the FortiNet Automated Configuration Migration Tool.

 

I think this would help you a lot. Since it support migration of all relevant components of the firewall including VPNs.

 

Hope that helps.

 

------------------------------------------------------------------
If this was helpful, please vote as helpful by clicking on the star icon below.
-------------------------------------

The licence for that is 3000$ a year, we only need for 2 days

Wow!!! Thieves!!! I would expect since you buy their product you would be able to get a tool to help you migrate across...

 

Since you bought their product and you are moving from another vendor to them, I would contact their sales team and explain the situation. I have read in some forums that they give out fully functional demo releases of the product.

 

Unfortunately I cannot help you on the technical bit since I have never used a Fortigate firewall. :-( 

------------------------------------------------------------------
If this was helpful, please vote as helpful by clicking on the star icon below.
-------------------------------------

Yup, that's what my boss said, it's stupid that you need buy whole 1 year of license... Who migrates their devices for a whole year?!?

 

I'll ask him, that can I send them an email in the name of company, hopefully he agrees.