#FortiGate Replacement Case Study: Network Upgrade and Challenge Analysis at a Hong Kong Primary School
  

Sangfor Jojo Lv5Posted Dec-11-2025 12:33


I. Project Background: Educational Network Upgrade and Performance Challenges
The client for this case study is a primary school in Hong Kong that aimed to replace its aging FortiGate firewall with a Sangfor Next-Generation Firewall (NGFW). This upgrade was necessary to meet the increasing demand for online teaching (such as STEAM courses) in the post-pandemic era, and to resolve performance bottlenecks and network lag experienced with the old FortiGate during peak usage (e.g., multiple classes accessing the internet simultaneously). The core requirement from the client was a smooth transition with zero changes to the existing network architecture, and cutover completion within two hours.

------------------------------------------------------------------------------------------------------------------------------------------------------------

II. Core Challenges and Technical Solutions  
During the migration, we faced three main challenges, which were successfully overcome through the following methods:

Challenge 1: FortiGate "Software Switch Interface" Incompatibility  
The critical configuration on the original FortiGate utilized the "Software Switch" mode, which is not directly supported by Sangfor NGFW. This mode bundles multiple physical interfaces into a single logical interface, on which a Layer 3 IP address and multiple VLAN interfaces (e.g., VLAN 100, VLAN 1024) are configured.

1) Solution:
  • Architecture Re-mapping: Since the Sangfor NGFW does not support Software Switch type interfaces, the relevant physical interfaces were configured as Layer 2 interfaces and added to the same switching domain.
  • Feature Equivalence: We created separate VLAN interfaces (e.g., vlan1, vlan100, vlan1024) and assigned the Layer 3 IP addresses from the original software switch and VLAN sub-interfaces to these new VLAN interfaces.



2) Result:
We successfully simulated the Layer 2 isolation and Layer 3 gateway functionalities of the original FortiGate software switch using Trunk/Native VLAN mode on the Sangfor NGFW, thus avoiding any modification to the client's existing network (i.e., no changes to the network topology or switch configurations were needed).
  

Challenge 2: Policy Migration Accuracy and Business Disruption Risk  
Due to a lack of long-term maintenance, the original FortiGate configuration was complex and contained outdated policies. Manually migrating numerous network objects, ACLs, and NAT policies carried a high risk of error, which could cause business disruption.

Solution:
  • Leveraging Automation Tools: We utilized the configuration conversion tool provided by Sangfor to rapidly and accurately import the core policy objects (including network objects, ACLs, and NAT) from the original FortiGate configuration file into the NGFW.
  • Dual Verification: After the automated conversion, a meticulous manual verification and optimization of the imported configuration was performed to ensure that the NGFW policy sequence aligned with the business logic, preventing the blocking of critical services.





Challenge 3: On-site Incompatibility of 10G/1G Optical Modules during Cutover  
During the on-site cutover, it was discovered that the new Sangfor NGFW used 10G optical interfaces and modules, but the connecting downstream switch port, although rated for 10G, was only configured with a 1G optical module, preventing the establishment of a physical link.

Solution:
  • The issue was identified immediately, and we determined that a 10G optical module needed to be procured to replace the 1G module in the downstream switch.
  • A second cutover was quickly arranged, ensuring successful link connectivity.




------------------------------------------------------------------------------------------------------------------------------------------------------------

III. Final Value and Project Achievements  
This migration project not only successfully replaced the hardware but also significantly enhanced the client's network security, management efficiency, and performance.

1. Greatly Improved Efficiency and Accuracy: The use of the automation tool boosted configuration migration efficiency by over 50%, shortening the originally estimated half-day workload to approximately two hours, thereby significantly accelerating the cutover process while ensuring policy configuration accuracy.

2. Seamless Core Feature Takeover: The compatibility challenge posed by the software switch interface was successfully resolved, achieving an unobtrusive replacement of the client's existing complex network structure.

3. Enhanced User Experience: The Sangfor NGFW offers a more intuitive user interface, significantly simplifying policy management. Furthermore, the enhanced log visibility, real-time threat awareness, and smoother network performance provide a safer and more stable online learning environment for students and staff.

------------------------------------------------------------------------------------------------------------------------------------------------------------

IV. Detailed Documentation Reference  
For the complete implementation steps and configuration details of this FortiGate migration to Sangfor NGFW, please refer to the attached documentation.



This article is written by Newbie976834, a technical engineer with extensive experience and a better understanding of Sangfor network security (NGAF) and Endpoint Secure products. You can follow him to learn more about him.




If you like this article, don’t forget to give it a thumbs up or leave a comment!
Your support helps the author to know his sharing is useful and recognized.

XXX Primary School_Fortigate Replacement.pdf

3.66 MB, Downloads: 19

Like this topic? Like it or reward the author.

Creating a topic earns you 5 coins. A featured or excellent topic earns you more coins. What is Coin?

Enter your mobile phone number and company name for better service. Go

Sangfor Jojo Lv5Posted Dec-11-2025 12:43
  
Congratulations on getting 45000 coins  !!

If you would like to share articles like FortiGate to Sangfor NGFW Migration Experience, please click the links below to register for these events.

1. Join Beta testing: https://community.sangfor.com/forum.php?mod=viewthread&tid=11497

2. Share migration experience after the testing: https://community.sangfor.com/forum.php?mod=viewthread&tid=11565
Humayun Ahmed Lv3Posted Dec-12-2025 14:57
  
Thanks to share!
YZJ Lv3Posted Dec-15-2025 17:37
  
Thanks to share! Very Helpful!