FortiGate Legacy Firewall Upgrade

Lifecycle planning · migration · secure cutover

FortiGate Legacy Firewall Upgrade in Dubai, UAE

An ageing firewall can remain operational long after it has stopped fitting the organisation around it. Internet speeds increase, VPN requirements change, inspection becomes heavier, branch connectivity expands, and product support milestones approach. A FortiGate legacy firewall upgrade is therefore best handled as a controlled infrastructure migration: understand the existing security policy, choose the new platform from measured requirements, convert what can be converted, manually rebuild what must be rebuilt, validate the result and plan a cutover with a rollback path.

Start with the current firewall

Share the existing model, support status, internet speed, users, interfaces, VPNs, HA design and security subscriptions.

FourTeck can use that information to prepare sizing, migration and quotation guidance without assuming that a like-for-like model number is the right replacement.

Source first
Document the live policy before redesign.
Size by workload
Inspection and growth affect the target model.
Convert selectively
Automation does not remove validation.
Plan rollback
Cutover needs recovery checkpoints.

Direct answer: what does a legacy firewall upgrade involve?

A FortiGate legacy firewall upgrade replaces or modernises an older firewall while carrying forward the security intent that the business still needs. It can involve an older FortiGate moving to a newer FortiGate, or a supported third-party firewall being migrated to FortiGate. The work typically includes discovery, lifecycle review, target sizing, interface and route mapping, policy conversion or rebuilding, VPN recreation, subscription planning, configuration testing, cutover and post-change validation. Businesses should consider an upgrade when the existing platform is approaching support limits, cannot handle present traffic or inspection requirements, no longer fits the network design, or creates operational risk. Before proceeding, confirm the exact source model, target requirements, dependencies, maintenance window and rollback expectations.

What the upgrade service does

The service turns a broad replacement requirement into a controlled technical project. The existing firewall is treated as a source of business rules rather than as a configuration file that should be copied blindly. Policies are reviewed for purpose, active objects are identified, network interfaces are mapped to the target architecture, routes and dynamic routing requirements are recorded, and VPN relationships are documented. This creates a design baseline before any conversion is attempted.

For suitable migrations, Fortinet provides FortiConverter options that can translate configurations from older FortiGate platforms and supported third-party firewalls to a target FortiGate configuration. Conversion can reduce repetitive manual work, but the converted output still needs review against the new platform, current FortiOS behaviour, available interfaces, security services and the organisation’s present requirements. Some certificates, tokens, external systems or features can need manual treatment, so the migration plan must separate automatable work from engineering tasks.

Who should consider it

This service suits organisations running an older FortiGate that is close to a lifecycle milestone, has insufficient capacity, or has become difficult to maintain. It also fits companies moving from selected Check Point, Cisco, Forcepoint, Juniper, Palo Alto Networks, SonicWall, Sophos or WatchGuard environments where a supported FortiConverter workflow may help translate the firewall configuration. Support varies by source platform and feature, so compatibility should be checked before the migration method is finalised.

A business should not choose a target firewall only because the current appliance and the new appliance appear to occupy similar places in a model range. Required performance depends on actual traffic, enabled security inspection, SSL/TLS inspection expectations, VPN load, concurrent users, WAN bandwidth, interface speed, routing complexity, logging, high availability and expected growth. The upgrade is most useful when those requirements are measured and translated into a bill of materials rather than guessed.

Business problems a controlled upgrade helps address

Lifecycle exposure

When a platform reaches the end of vendor support, security updates, fixes and technical assistance may no longer be available. Upgrade planning should begin before the final support date, not after an incident forces an emergency replacement.

Capacity pressure

Internet bandwidth and encrypted application traffic can grow faster than the original firewall design. The replacement should be sized for the services that will actually run, not only for raw firewall throughput.

Configuration debt

Years of changes can leave duplicate objects, temporary rules, old VPNs and naming inconsistencies. Migration is an opportunity to identify what is still required before carrying it to the new environment.

Cutover uncertainty

A replacement can disrupt routing, public services, branch tunnels, remote access or cloud connectivity if dependencies are missed. A documented test and rollback plan lowers operational uncertainty.

Core service outcomes

Lifecycle and requirement baseline

A practical upgrade starts with the support status and the current production role of the firewall. The assessment records internet circuits, VLANs, routed networks, public services, VPN peers, authentication dependencies, logging destinations, management method and operational constraints.

Target platform sizing

FourTeck can help buyers compare suitable FortiGate options using traffic volume, inspection profile, ports, high availability, user count, VPN demand and expansion plans. The result is a more defendable procurement decision.

Migration and validation plan

The configuration is converted, rebuilt or combined using the method appropriate to the source. Engineers then review the output, test dependencies, prepare change controls and define a cutover sequence with verification checkpoints.

Service-fit matrix

Business situationRelevant assistanceScope dependency
Older FortiGate approaching support milestoneLifecycle review, target sizing, FortiGate-to-FortiGate migration planningSource version, target model, interface mapping, feature usage
Third-party firewall moving to FortiGatePolicy inventory, supported conversion review, manual reconstruction planVendor, model, configuration format, feature equivalence
Bandwidth or inspection requirement has grownPerformance sizing and subscription reviewTraffic profile, encrypted traffic, enabled security services
HA pair needs replacementHA design, cabling, interface and failover planningTopology, session expectations, switch design, maintenance window
Multiple branches need standardisationTemplate, routing, VPN and management planningBranch diversity, central management, addressing and rollout sequence

Service information and planning table

TopicFortiGate Legacy Firewall Upgrade
Main purposeReplace or modernise an older firewall with a suitably sized FortiGate deployment while preserving required network and security policy.
Suitable forSMB, enterprise, branches, campuses, warehouses, retail, healthcare, education, hospitality and multi-site environments, subject to requirements.
Assessment supportExisting firewall inventory, lifecycle status, traffic, interfaces, VPNs, routing, public services and security profiles.
Migration methodFortiConverter where supported, manual conversion, configuration rebuild or a mixed approach; source and target dependent.
LicensingFortiCare, FortiGuard and migration service requirements are subscription or service dependent. Confirm the selected bundle and term.
High availabilityConfiguration and topology dependent. Confirm HA mode, switches, interface count and cutover method.
TestingIncludes agreed validation checks such as routing, DNS, internet access, application reachability, VPNs and public services; exact test plan is project dependent.
Customer inputs requiredSource configuration, network diagram where available, ISP details, public IPs, VPN peer details, critical applications, user and bandwidth data, maintenance constraints.
UAE availabilityContact FourTeck to confirm target model, license, migration service and project availability.
Important noteNo universal like-for-like replacement is assumed. Final hardware, licenses and migration scope depend on verified requirements.

Configuration, licensing and compatibility dependencies

Configuration conversion is not the same as a complete production migration. FortiConverter can translate many firewall policies and objects, but the target appliance may have different physical interfaces, interface naming, switch-controller roles, VPN options, routing design, VDOM requirements, management integrations or FortiOS behaviours. Fortinet documentation also notes that some items cannot be converted automatically and must be handled manually. Certificates and FortiToken-related elements are examples that may require separate preparation. Migration involving managed external products such as FortiAP, FortiSwitch, FortiManager, FortiClient EMS or other systems may also require separate upgrade or integration planning rather than being assumed to move with the firewall configuration.

Licensing must also be treated separately from configuration. Security inspection capability can depend on FortiGuard subscriptions, support depends on the selected FortiCare term, and a third-party-to-FortiGate conversion can require a FortiConverter service purchase. Fortinet currently documents a free opt-in FortiGate-to-FortiGate conversion licence in specific FortiConverter Service circumstances, while third-party conversion remains a purchased service; eligibility and current terms should be confirmed for the exact project. FourTeck can include hardware, support, subscriptions, migration service and engineering scope as distinct items so procurement can see what is required and what remains optional.

A practical upgrade journey

01

Discover

Capture the source model, FortiOS or vendor version, policies, interfaces, routes, VPNs, NAT, public services, authentication, logging and critical application paths.

02

Design

Choose the target platform based on inspected traffic, users, interfaces, HA, subscriptions, growth and operational requirements. Define any network changes rather than hiding them in migration work.

03

Convert and rebuild

Use supported conversion where appropriate, then manually prepare features or dependencies that are not converted. Clean up obsolete objects only when their purpose is understood.

04

Validate

Review policies, routing, NAT, VPNs, certificates, admin access, logging and security profiles against the intended design. Test in a lab or staging approach where feasible.

05

Cut over

Execute the change in an agreed maintenance window, validate core services, maintain rollback checkpoints and record deviations from the planned configuration.

Sizing the new FortiGate for inspected traffic, not brochure numbers

One of the most common mistakes in firewall replacement is choosing a target appliance by comparing only basic firewall throughput. Real production traffic may pass through intrusion prevention, application control, antivirus, DNS or web security, SSL inspection, IPsec VPN, remote access, traffic shaping, SD-WAN logic and detailed logging. Each organisation combines these functions differently. A branch with modest bandwidth but heavy SSL inspection can have a different performance requirement from a warehouse with faster internet but lighter security inspection. Likewise, a head office terminating many VPNs or publishing applications may need more resources and interfaces than a similarly sized office using mostly cloud applications.

FourTeck can help build a sizing profile around current peak bandwidth, forecast growth, concurrent users, encrypted traffic proportion, security services, VPN tunnels, remote access demand, WAN count, copper and fibre interfaces, switch connectivity and redundancy. The target should leave sensible operational headroom without turning the migration into an unnecessarily expensive hardware exercise. If the business expects a major ISP upgrade, new branches, increased cloud usage or deeper inspection during the next lifecycle, those changes should be represented in the sizing discussion.

The same process helps identify when a hardware FortiGate is not the only element that needs attention. Existing transceivers, rack power, WAN handoffs, upstream switches, downstream segmentation, central management, log storage, authentication servers and monitoring systems may influence the final bill of materials. Treating the firewall as part of the wider network avoids discovering during cutover that the new appliance has the required performance but not the correct connectivity or integration design.

Preserving policy intent while reducing configuration debt

A legacy configuration often reflects years of operational history. Some rules are business critical, some were created for temporary projects, some reference servers that no longer exist, and some are duplicated because different administrators solved similar requirements at different times. Copying everything without review can carry unnecessary exposure and complexity to the new firewall. Removing too much during a compressed migration, however, can break applications that still rely on obscure rules. The safer approach is controlled classification.

FourTeck can help separate active and understood policies from items that need owner confirmation. Object naming can be normalised where the change is safe, expired temporary access can be challenged, and shadowed or obviously redundant rules can be flagged for review. NAT policy needs particular care because public services, outbound translation and overlapping address spaces can be tied to ISP addressing or server assumptions that are not visible in a simple rule export. VPN policies also need dependency checking because remote peers may be managed by another company and may have strict change windows.

The goal is not to turn the firewall upgrade into an endless policy-cleanup project. Instead, the migration should prevent known obsolete configuration from being copied blindly, preserve required access, document exceptions, and establish a cleaner operational baseline for the new platform. Post-migration hardening and deeper policy recertification can then be scheduled as a separate activity when business owners have time to review application needs properly.

Testing, rollback and change control protect the business outcome

Firewall replacement affects more than internet access. It can change routes, public NAT, DNS behaviour, application reachability, branch tunnels, remote access, identity integrations, logging, monitoring and management access at the same time. A migration plan therefore needs a test matrix that maps technical checks to business functions. Instead of saying only “internet works,” the team may need to verify ERP access, cloud applications, payment or booking systems, branch connectivity, vendor tunnels, remote administration, inbound services and critical SaaS platforms.

Rollback should be designed before cutover. The source firewall configuration must be backed up securely, the physical reconnection method should be understood, and any ISP or switch changes that could prevent rollback should be documented. For HA environments, the implementation method should consider how the new pair is staged and how failover is validated. For branch migrations, the sequence should avoid losing the management path needed to complete the change. Change records should list who approves the cutover, who validates business applications and who can authorise rollback if the agreed success criteria are not met.

After cutover, validation should continue beyond the first successful ping. Log forwarding, security profiles, time synchronisation, backups, administrative access, monitoring, VPN stability and performance should be checked. The final configuration should be saved once the production state is confirmed, and documentation should record any changes made during the maintenance window. This turns the migration from a one-time appliance swap into a maintainable operational handover.

Where a FortiGate legacy upgrade is commonly used

Head office internet edge

Replace an ageing gateway while preserving public services, VPNs, secure web access and business application policies, with sizing for current ISP bandwidth and future inspection needs.

Branch standardisation

Move older mixed firewall estates toward a consistent FortiGate approach, with repeatable templates for routing, VPN, SD-WAN and security policy where branch requirements allow.

Warehouse and industrial sites

Maintain connectivity between office systems, scanners, cameras, operational networks and head office services while improving segmentation and lifecycle support.

Retail and hospitality

Plan migration around business hours, payment or booking services, guest networks, back-office applications and multi-site VPN dependencies that cannot tolerate an undocumented cutover.

Healthcare and education

Review user groups, guest access, application categories, VPNs, logging, segmentation and subscription requirements before replacing a firewall supporting sensitive operational services.

Data-centre or server edge

Map higher-capacity interfaces, routed networks, NAT, HA, published services and monitoring dependencies carefully when moving from a legacy platform to a newer FortiGate architecture.

Integration and operational considerations

A firewall rarely works alone. Before replacement, identify the systems that depend on its addresses, logs, certificates, authentication or routing decisions. These can include managed switches, wireless controllers, FortiAP or FortiSwitch environments, FortiManager, FortiAnalyzer, SIEM platforms, RADIUS or LDAP servers, identity providers, monitoring tools, IP telephony, CCTV networks, public DNS records, cloud VPNs and third-party site-to-site peers. Each dependency should have an owner and a validation method.

Software compatibility is also important. The target FortiOS release should be selected with supportability and integration in mind rather than simply using the newest available build. An organisation with central management, specific VPN clients or established operational procedures may need to confirm version compatibility. Firmware planning can therefore be part of the migration design rather than an afterthought. If the source appliance is very old, there may be syntax or feature changes that make direct policy translation less useful than a redesigned configuration.

Operational ownership after migration should be clear. Decide who will receive security alerts, who renews subscriptions, who manages backups, who reviews policy changes and who coordinates future firmware maintenance. A newer firewall reduces lifecycle risk only when the organisation also has a maintainable support and renewal process.

Questions to resolve before ordering

What exactly is being replaced?

Provide source vendor, model, serialised appliance count, current firmware, HA status and whether the device is still under support.

What must the new firewall handle?

Share internet bandwidth, users, inspected traffic, VPNs, public services, branches and expected growth rather than relying only on the old model class.

Which interfaces are required?

Confirm copper, fibre, transceiver, WAN, LAN, DMZ, HA, management and switch connectivity requirements, including link speeds.

Which subscriptions are needed?

Define the required FortiGuard security services, FortiCare support term and any migration service rather than assuming they are included.

What can be changed during migration?

Agree whether the project is a like-for-like policy move or includes VLAN redesign, address changes, routing changes, VPN redesign or cleanup.

What is the acceptable outage?

Set the maintenance window, validation sequence, escalation contacts and rollback threshold before cutover.

Procurement checklist for a FortiGate upgrade

□ Exact source firewall model and firmware

□ Quantity and HA requirement

□ Current support or lifecycle status

□ Internet bandwidth and expected growth

□ User and device count

□ Required security inspection services

□ VPN tunnels and remote users

□ Copper, fibre and transceiver needs

□ Public services and NAT dependencies

□ FortiCare and FortiGuard term

□ FortiConverter or migration engineering scope

□ Installation and cutover requirement

□ Rollback and testing expectations

□ Target delivery and change window

How FourTeck can support the upgrade

FourTeck can support the project from requirement clarification through quotation and implementation planning. For procurement teams, the first goal is to define the correct bill of materials: target FortiGate hardware or virtual platform, required support term, security subscriptions, migration service where relevant, transceivers or accessories, and any installation or configuration scope. For IT teams, the focus is on documenting the source environment, identifying dependencies, deciding the migration method and preparing validation steps.

Where FortiConverter is appropriate, FourTeck can help the buyer understand whether the source and target are suitable for conversion and what still needs manual engineering. Where conversion is not suitable, a structured rebuild can be planned from the policy and network requirements. For organisations already using FortiGate, the discussion may include model-to-model migration, central management, HA, SD-WAN, VPN, logging and subscription changes. For third-party migrations, feature mapping and policy equivalence require more attention because terminology and architecture differ between vendors.

Buyers can also use FourTeck’s firewall product catalogue, technology services and Fortinet firewall guidance to review related options. A formal project quotation should be based on the actual source firewall and target requirements, because appliance capacity, licensing, accessories, engineering time and delivery timing vary by environment.

UAE availability and support guidance

Contact FourTeck to confirm current UAE availability for the recommended FortiGate model, support bundle, security subscriptions, migration service and accessories. Availability can vary by appliance, licence term, quantity, region and vendor lead time. Delivery and project coordination can be discussed after the exact requirement is confirmed. If installation, configuration, migration, policy review or cutover assistance is needed, that scope should be included in the quotation so procurement and IT teams are working from the same assumptions.

For businesses that have not yet selected a target model, FourTeck can begin with a sizing discussion rather than a product code. Share the source appliance, internet bandwidth, users, VPN requirements, current interfaces, desired security services and expected growth. This information helps narrow the suitable FortiGate range and identify whether a simple hardware refresh is enough or whether the network design should change at the same time.

Dubai, Abu Dhabi, Sharjah and Ajman coverage

Businesses in Dubai, Abu Dhabi, Sharjah and Ajman can contact FourTeck for FortiGate legacy upgrade planning, model selection, quotation coordination and deployment-scope discussion. The same technical method applies across locations: document the source, size the target, confirm subscriptions and interfaces, decide which configuration can be converted, plan manual work, validate the new firewall and agree the cutover process. Site conditions can still differ significantly. A Dubai head office may prioritise HA and public services, an Abu Dhabi branch may depend on long-lived site-to-site VPNs, a Sharjah warehouse may require segmentation for CCTV and operational devices, while an Ajman office may need a compact replacement with remote support. The quotation should therefore reflect the exact site role and maintenance requirement rather than a generic city-based package.

GCC Availability

FourTeck can assist organisations planning FortiGate firewall upgrades for GCC operations where requirements need to be reviewed from the UAE and coordinated with regional project teams. The discussion can cover target-model sizing, FortiCare and FortiGuard terms, FortiConverter suitability, accessories, configuration scope, installation planning, renewal guidance and change-window requirements. Businesses operating in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman should provide the destination country, source firewall details, quantity, required license term, deployment location and expected project timeline before commercial assumptions are made. Product availability, licence eligibility, delivery schedules, engineering visits and vendor lead times can vary by country, model and quantity. For Kuwait-focused requirements, buyers may also use the FourTeck Kuwait regional channel. FourTeck does not assume local stock, fixed delivery timing or country-specific certification without confirmation; the objective is to prepare a requirement that can be quoted and coordinated accurately.

Africa Availability

For organisations planning firewall modernisation in Africa, FourTeck can help evaluate FortiGate appliance classes, support terms, security subscriptions, migration requirements, accessories and deployment dependencies before regional procurement is arranged. This is particularly useful for businesses with mixed legacy firewalls across branches, because the migration method may differ by site even when the target platform is standardised. Buyers should share the destination country, source vendor and model, quantity, preferred deployment schedule, ISP bandwidth, VPN dependencies, installation expectation and local technical resources. Availability and fulfilment can depend on destination, hardware model, licence region, power and regulatory requirements, shipping arrangements, vendor lead time and project scope. FourTeck provides dedicated regional inquiry paths through FourTeck Africa, FourTeck Kenya and FourTeck Uganda. Local inventory, immediate shipment, customs outcomes, onsite coverage and delivery dates should be confirmed for the specific requirement rather than assumed.

Related options to consider with the migration

FortiGate replacement models

Choose the exact target based on measured workload, interfaces, security services and growth rather than a fixed cross-reference.

Browse firewall products

FortiGuard subscriptions

Review which security services should be active on the new appliance and for what term. Bundle selection affects both capability and commercial planning.

Review Fortinet options

FortiCare support

Confirm the required support coverage, entitlement period and lifecycle alignment for the replacement platform.

Ask for support guidance

Configuration and cutover support

Include engineering scope when the project needs migration preparation, testing, onsite coordination, remote assistance or post-change validation.

See FourTeck services

Why businesses contact FourTeck for firewall upgrade planning

The difficult part of a legacy firewall upgrade is usually not identifying that the old device should be replaced. It is converting a live production environment into a clear purchasing and migration plan. FourTeck can help buyers clarify the source environment, compare suitable target models, identify required subscriptions, map interfaces and accessories, review migration tooling, define engineering scope and prepare a quotation that separates hardware, licensing and services. This gives procurement teams better commercial clarity and gives technical teams a more useful starting point for deployment.

FourTeck can also assist when the customer is unsure whether an older FortiGate should be replaced now, renewed temporarily, or reviewed against a wider network redesign. Lifecycle information, current bandwidth, inspection load and operational constraints can be discussed together. The objective is not to promise a universal answer before the environment is known, but to reduce the risk of buying a firewall that is undersized, missing required licences, incompatible with the intended interfaces or difficult to migrate within the available maintenance window. Businesses can contact FourTeck with the current firewall details to begin the review.

What buyers are trying to solve before replacing an older firewall

Most firewall-upgrade searches begin with a model question: “What replaces my old FortiGate?” That is useful as a starting point, but a replacement model should be chosen from the workload that exists now. A firewall purchased five or seven years ago may have been sized for slower internet, fewer cloud applications, lighter encrypted traffic and fewer remote users. A newer model with a similar position in the product family can still be the wrong choice if the organisation has added SSL inspection, SD-WAN, more VPN tunnels, multiple WAN links, public applications or higher-speed switching. The most useful information to give a supplier is therefore the old model plus the current traffic and feature profile.

Should I upgrade because the firewall is EOL?

If the platform is approaching or has passed its end-of-support milestone, upgrade planning becomes a priority because future fixes, security updates and vendor support may be limited or unavailable. Confirm the exact model on Fortinet’s product lifecycle resource rather than relying on a general family assumption. If the device still has support remaining, that time can be used to plan the migration calmly instead of waiting for a forced replacement.

Can the existing FortiGate configuration be copied?

Moving configuration between models is more complex than copying a backup file. Interfaces, hardware roles, FortiOS syntax and supported features can differ. FortiConverter can help translate configurations to the target model, but the result should still be reviewed. Certificates, FortiToken items and some external-device related functions may need separate manual handling. A converted file is therefore an input to engineering validation, not a substitute for it.

Can a third-party firewall migrate to FortiGate?

Fortinet supports FortiConverter migration from a range of third-party vendors, including Check Point, Cisco, Forcepoint, Juniper, Palo Alto Networks, SonicWall, Sophos and WatchGuard. Exact conversion coverage depends on the source platform, version and feature usage. A configuration with complex NAT, identity policies, dynamic routing or vendor-specific objects may need more manual review than a simpler rule set.

Another recurring buyer question is whether the new appliance should be purchased with a security bundle. The answer depends on what the firewall is expected to do. FortiGate can provide core firewall and VPN functionality, while many threat-protection functions depend on FortiGuard services and support entitlement is tied to FortiCare. A buyer requesting only “the firewall” may receive a commercial quote that does not match operational expectations. The request should identify whether intrusion prevention, web or DNS security, antivirus, application control, sandbox-related services, premium support or other subscriptions are required. The selected term also matters because hardware and subscription lifecycle planning are easier when the organisation knows how long it expects to keep the appliance in service.

Downtime is another practical concern. Firewall replacement often requires a physical or logical handover of WAN and LAN links, routing adjacency, public IP use and VPN termination. The outage can be short when the design is simple and the target is staged correctly, but it should not be promised in advance without understanding the topology. A migration involving high availability, multiple ISPs, BGP or OSPF, many site-to-site VPNs, published applications or remote branches needs a more detailed change plan. The safest quotation describes engineering scope and cutover coordination without guaranteeing a fixed outage before discovery.

Businesses also ask whether old policies should be cleaned during migration. Some cleanup is valuable, especially clearly expired temporary rules and duplicate objects, but wholesale redesign during a time-sensitive hardware refresh increases change risk. A balanced project identifies questionable configuration, removes items that are safe to retire, preserves required access and records a post-migration policy review backlog. This gives the new FortiGate a cleaner starting point while keeping the cutover focused on continuity.

For a useful quotation, send the current firewall model, HA status, current firmware, internet bandwidth, number of users, security features in use, VPN tunnel count, remote access requirement, interface types, number of WAN links, published services, central management or logging products and target maintenance window. If the firewall is part of a branch estate, include the number of sites and whether configurations are standardised. FourTeck can use that information to discuss suitable FortiGate classes, licensing, FortiConverter or manual migration options, accessories and deployment support. The result is a quote built around the environment rather than around a single replacement-model guess.

Buyer questions that shape the final migration plan

How do I know whether to replace the firewall or only renew support?

Check the exact product lifecycle, remaining support eligibility, current performance and whether the appliance still supports the required FortiOS path and security functions. A renewal can make sense when the hardware remains supported and fits the workload, but it does not solve an approaching end-of-support date or a genuine capacity limitation. Share the serialised model and current contract status with FourTeck so renewal and replacement can be compared on the same requirement.

What data is needed to size the target FortiGate?

Use peak and expected internet bandwidth, concurrent users, enabled inspection, SSL/TLS inspection expectations, IPsec and remote-access VPN load, WAN links, port speeds, HA requirements and growth. If the business is moving from 1 GbE to multi-gigabit or fibre interfaces, that requirement should be explicit. Model selection is stronger when these numbers are available than when it is based only on the source appliance name.

Will FortiConverter migrate everything automatically?

No migration tool should be assumed to reproduce every production dependency without review. FortiConverter can translate supported configurations, but manual handling may still be necessary for certificates, FortiToken-related data, unsupported objects, overlapping networks, target-specific interfaces or external managed systems. The project should define what is converted, what is recreated manually and what is intentionally redesigned.

Should the target run the same rules as the old firewall?

The business intent should be preserved, but rules should not be copied blindly. Migration is a suitable point to flag temporary access, unused address objects, redundant NAT and old VPNs. Changes that are clearly understood can be cleaned; uncertain items should be preserved or tested until the application owner confirms they are no longer needed. Larger policy recertification can follow after the hardware migration.

What should be tested after cutover?

Validate more than basic internet access. Test routing, DNS, critical SaaS and internal applications, branch VPNs, remote access, inbound services, public NAT, authentication, logging, monitoring, security profiles and management access. For HA, test failover according to the agreed change plan. Record exceptions and save a confirmed post-migration configuration backup.

How should I ask FourTeck for a quote?

Provide the source model, target site role, quantity, support status, bandwidth, users, VPNs, interfaces, subscriptions and desired migration scope. State whether you need hardware only, licensing, FortiConverter, configuration preparation, onsite cutover or remote support. Also provide the destination and preferred timeline. FourTeck can then structure the quotation around the actual bill of materials and project scope.

Frequently asked questions

What is a FortiGate legacy firewall upgrade?

It is a planned replacement or modernisation of an older firewall with a newer FortiGate platform, including requirement review, target sizing, configuration migration or rebuilding, testing, cutover and post-change validation as required.

Can FourTeck help replace an older FortiGate with a newer model?

Yes. FourTeck can assist with sizing, bill-of-material guidance, licensing, migration planning and quotation coordination. The exact target model should be selected from current workload and growth rather than assumed from the old model name.

Can third-party firewall rules be migrated to FortiGate?

Fortinet FortiConverter supports configuration conversion from multiple third-party firewall vendors. Compatibility, feature coverage and manual work depend on the exact source platform, version and configuration, so the source should be reviewed before scope is confirmed.

Is FortiConverter included with every FortiGate?

No universal inclusion should be assumed. FortiConverter licensing or service eligibility depends on the migration type and current Fortinet policy. Third-party conversion can require a purchased service, while specific FortiGate-to-FortiGate scenarios may have different eligibility. Confirm the exact requirement.

Do certificates and FortiToken settings migrate automatically?

Not necessarily. Fortinet documentation identifies manual prerequisites for some certificate and FortiToken-related migration tasks. These items should be inventoried and handled separately in the project plan.

How is the replacement FortiGate sized?

Sizing should consider actual bandwidth, inspected traffic, users, VPN load, encrypted traffic, interfaces, HA, logging, subscriptions and future growth. Raw firewall throughput alone is not enough for a reliable selection.

Can the firewall be upgraded with no downtime?

Downtime depends on topology, HA, ISP connections, routing, VPNs, public services and staging options. FourTeck can help plan a maintenance window and rollback method, but a zero-downtime outcome should not be promised without a verified design.

Should old firewall policies be cleaned during migration?

Clearly obsolete items can be reviewed, but large-scale policy redesign can increase cutover risk. A controlled migration usually preserves required business access, flags uncertain rules and schedules deeper recertification separately when needed.

Is FortiGate legacy firewall upgrade support available in the UAE?

FourTeck can assist with UAE requirement review, quotation, model and licence guidance, migration planning and project coordination. Hardware, licensing and service availability depend on the exact model, quantity, term and project scope.

What should I send for an accurate quotation?

Send the source model, firmware, quantity, HA status, bandwidth, users, interfaces, VPNs, public services, required security subscriptions, target location, migration scope and preferred change window. A configuration summary or backup can be reviewed through an agreed secure process.

Plan the replacement before the old firewall becomes the constraint

Share the current firewall model, bandwidth, users, VPN requirements, interfaces, support status and expected migration window. FourTeck can help translate that information into a target FortiGate shortlist, licensing direction, migration approach and formal quotation.

Request Product ConsultationCheck UAE Availability

Scroll to Top
Powered by Joinchat