Cisco ASA and Firepower
ACL policy migration with object references, conversion of crypto maps to IPsec tunnels, replacement of AnyConnect with FortiClient. We monitor order of rules - In ASA, this is evaluated differently than in FortiOS.
Do you have a Cisco ASA, Sophos, WatchGuard or SonicWall at the end of support? We will migrate rules, VPN tunnels and user policies to FortiGate. Migration takes place over the weekend; by Monday morning everything works as before, only faster. Audit of the existing configuration within 5 working days free of charge.
ACL policy migration with object references, conversion of crypto maps to IPsec tunnels, replacement of AnyConnect with FortiClient. We monitor order of rules - In ASA, this is evaluated differently than in FortiOS.
Conversion of web filtering and application policies, mapping of groups from Active Directory, retention of SSL inspection. including exceptions for banking and state portals.
The most common reason is the end of support or an expired licence. We will transfer the rules as well. site-to-site tunnels to remote sites, which cannot simply be restarted.
Send us the configuration export or grant us read-only access. Within 5 working days You will receive an overview of rules that are dead, duplicate or risky, and a proposal for how they will appear on FortiGate. Free of charge, no obligation.
We will prepare the FortiGate at our premises, configure all policies and test it. The device will then be delivered to you. already knows your network - on-site connection only.
Typically Friday evening or Saturday morning. The actual switch-over takes tens of minutes, at With HA, downtime is zero.The original firewall remains connected as a backup safeguard.
After switching over, we monitor the logs and fine-tune the rules that invariably emerge during migration. The system then moves into routine management. SLA within 1 hour during working hours.
Devices no longer receive updates after support ends. Published firewall vulnerabilities are scanned automatically. The attacker isn't targeting you personally; they're after your software version..
If you fall under NIS2, you must demonstrate access control, logging and current support. Unsupported equipment is non-compliant during an inspection. hard to justify.
A 36-month rental includes hardware, FortiGuard licences and management in a single monthly payment. from 2 790 KčNothing from the investment budget.
The actual switchover takes tens of minutes and is scheduled outside operating hours, so users notice nothing during working hours. For companies with continuous operation, we handle the transition via an HA pair, where downtime is zero.
The original firewall remains physically connected and configured. Reverting is a matter of switching the cable, not restoring from backup: the decision is therefore not irreversible.
No. The equipment is included in the monthly rental, covering warranty and replacement at the end of the cycle. If you already own a FortiGate, we will take over management only.
The deployment cost is determined by the audit, for a simple network it is a one-off setup from 4 900 Kč, while for multiple branches with SD-WAN it depends on the scope. The audit is free so you know what you are getting into before making a decision.
Yes. SD-WAN between branches and VPN for remote work are standard components of the design, for distributed companies, this is precisely why a FortiGate usually makes sense.
Tell us what you are migrating from and how many users and branches you have. We will contact you within 24 hours with questions for the audit, and within 5 working days you will receive a proposed architecture and price, free of charge and without obligation.