FortiGate F-Series to G-Series Migration: What Actually Breaks (and How to Plan It)
Last updated: 31 August 2026
Fortinet's F-series FortiGate models are steadily reaching end-of-sale, and most businesses running one eventually face the same question: how disruptive is moving to a G-series unit actually going to be? The honest answer is that the hardware swap is the easy part — the configuration migration is where projects go sideways if it isn't planned properly.
Why businesses are moving off the F-series
End-of-sale doesn't mean a unit stops working, but it does mean shrinking support windows, no new firmware features, and eventually end-of-support entirely. Most migrations we see are driven by one of three things: a support contract renewal that's no longer available on the old hardware, a performance ceiling being hit (SD-WAN and inspection-heavy setups are usually the trigger), or simply replacing failing hardware with something that isn't already near end-of-life.
What FortiConverter handles — and where it falls short
Fortinet's FortiConverter tool will move the bulk of a standard configuration across automatically, but it isn't a guaranteed one-click migration. In practice, VPN tunnels and user authentication profiles are the two areas most likely to need manual rebuilding rather than a clean automatic conversion — compatibility gaps between firmware generations mean some settings simply don't map across cleanly. Treat FortiConverter as a strong starting point, not the finish line.
A practical migration approach
The lowest-risk path is staged, not a single big-bang cutover. Migrate the primary or headquarters unit first, validate it thoroughly against real traffic, then repeat the process for branch or secondary sites once the configuration pattern is proven. This is the same approach we've used across every FortiGate migration we've delivered — including multi-site projects where the retired unit from the HQ upgrade gets redeployed to a branch as its own replacement, cutting hardware cost on top of the upgrade.
What to check before you start
- A full configuration backup of the existing unit, kept somewhere other than the firewall itself
- Current firmware and licensing status on both the old and new units
- Every VPN tunnel and remote-access profile documented before migration, not reconstructed from memory afterward
- A defined maintenance window and rollback plan, even if you don't expect to need it
Done this way, a single-site migration is realistically an overnight change, not a multi-day outage. Every FortiGate migration we've delivered so far has landed inside one maintenance window.
