Firewall migration · entire Czech Republic

Switching to FortiPro without interruption to operations.

Do you have a Cisco ASA, Sophos, WatchGuard or SonicWall at the end of support? We will migrate rules, VPN tunnels and user policies to FortiGate. Migration takes place over the weekend; by Monday morning everything works as before, only faster. Audit of the existing configuration within 5 working days free of charge.

0 min outage with HA 5 days for an audit Rollback by switching the cable NIS2 Ready
Network distribution boards and firewall in the server room during migration
Migration without risk
Original firmware as a backup
Where we are migrating from

We know the habits all major brands.

Migration is not export and import. Every platform handles NAT, VPN and objects differently, these are the points where transitions usually fail and where it pays to know what to look for.
Cisco network equipment in the distribution board
01 / Cisco

Cisco ASA and Firepower

ACL policy migration with object references, conversion of crypto maps to IPsec tunnels, replacement of AnyConnect with FortiClient. We monitor order of rules - In ASA, this is evaluated differently than in FortiOS.

Security policy management
02 / Sophos

Sophos XG and UTM

Conversion of web filtering and application policies, mapping of groups from Active Directory, retention of SSL inspection. including exceptions for banking and state portals.

Older firewall after end of support
03 / Other

WatchGuard, SonicWall, Kerio

The most common reason is the end of support or an expired licence. We will transfer the rules as well. site-to-site tunnels to remote sites, which cannot simply be restarted.

How the migration takes place

Four steps, no surprises.

You determine the switching date. The original firewall remains connected as a backup.until you confirm that everything is running correctly, return is a matter of switching the cable.
Audit of the existing firewall configuration
01 · Audit

Audit of the current configuration

Send us the configuration export or grant us read-only access. Within 5 working days You will receive an overview of rules that are dead, duplicate or risky, and a proposal for how they will appear on FortiGate. Free of charge, no obligation.

Configuration preparation and testing
02 · Preparation

Dry run deployment

We will prepare the FortiGate at our premises, configure all policies and test it. The device will then be delivered to you. already knows your network - on-site connection only.

Switching operation to the new firewall
03 · Switching

At a time of your choice

Typically Friday evening or Saturday morning. The actual switch-over takes tens of minutes, at With HA, downtime is zero.The original firewall remains connected as a backup safeguard.

Supervision of operation after migration
04 · Supervision

Two weeks of heightened attention

After switching over, we monitor the logs and fine-tune the rules that invariably emerge during migration. The system then moves into routine management. SLA within 1 hour during working hours.

Why address this now

Firewall after end of support the gate is open.

Postponing replacement makes sense as long as the equipment receives patches. After EoL, it becomes the network's weakest point, and for companies under NIS2, an additional issue during audits.
01 / Risk

Without security patches

Devices no longer receive updates after support ends. Published firewall vulnerabilities are scanned automatically. The attacker isn't targeting you personally; they're after your software version..

02 / Compliance

NIS2 requires demonstrable management.

If you fall under NIS2, you must demonstrate access control, logging and current support. Unsupported equipment is non-compliant during an inspection. hard to justify.

03 / Budget

Without a major investment

A 36-month rental includes hardware, FortiGuard licences and management in a single monthly payment. from 2 790 KčNothing from the investment budget.

Frequently Asked Questions

What people ask prior to migration.

The two most common concerns are operational downtime and what if it doesn't work out. We address both so that the decision is not irreversible.
How long will the network be unavailable?+

The actual switchover takes tens of minutes and is scheduled outside operating hours, so users notice nothing during working hours. For companies with continuous operation, we handle the transition via an HA pair, where downtime is zero.

What if the migration fails?+

The original firewall remains physically connected and configured. Reverting is a matter of switching the cable, not restoring from backup: the decision is therefore not irreversible.

Do we need to buy new hardware?+

No. The equipment is included in the monthly rental, covering warranty and replacement at the end of the cycle. If you already own a FortiGate, we will take over management only.

How much does migration cost?+

The deployment cost is determined by the audit, for a simple network it is a one-off setup from 4 900 Kč, while for multiple branches with SD-WAN it depends on the scope. The audit is free so you know what you are getting into before making a decision.

Can you also handle branches and home offices?+

Yes. SD-WAN between branches and VPN for remote work are standard components of the design, for distributed companies, this is precisely why a FortiGate usually makes sense.

Let's start with an audit

Send us your configuration. we will return the migration plan.

Tell us what you are migrating from and how many users and branches you have. We will contact you within 24 hours with questions for the audit, and within 5 working days you will receive a proposed architecture and price, free of charge and without obligation.

Břehová 40/1, Praha 1

Request for migration quotation

Free audit · response within 24 hours