Fortinet / Renewal & Support / FG-100ETK Migration
Migrate from FortiGate FG-100ETK — EOL Upgrade to FortiGate 90G, 100F or 120G
End of Life Notice: The FortiGate FG-100ETK has reached End of Life status. Fortinet has ceased engineering support, firmware updates and FortiGuard threat intelligence for this platform. Running EOL hardware creates a security gap and compliance exposure under RBI, PCI DSS and ISO 27001. Migration is required — not optional.
eNeoteric manages end-to-end migration from FortiGate FG-100ETK to FortiGate 90G, 100F or 120G — full configuration export and conversion, parallel staging, zero-downtime cutover and new FortiCare and FortiGuard enrollment. As an authorised Fortinet partner, we have done this before.
Authorised Fortinet partner · All India coverage · GST invoicing · Config migration included
Understanding EOL
What End of Life means for your FG-100ETK
Fortinet's product lifecycle has distinct phases — and EOL is the final one. Here's what has stopped for the FG-100ETK:
End of Engineering Support
No new firmware builds, no security patches, no CVE hotfixes. Known vulnerabilities discovered after the EOL date will never be patched on your FG-100ETK.
End of FortiGuard Updates
IPS signatures, AV definitions, web-filter categories and application control databases will no longer update on EOL hardware. Your threat intelligence becomes stale and exploitable.
End of TAC & RMA
Fortinet's Technical Assistance Center will not provide support for EOL hardware. If your FG-100ETK fails, there is no hardware replacement via RMA.
FortiManager Compatibility
Future FortiManager versions may drop support for old firmware versions used by EOL devices, creating centralised management gaps in your estate.
Business Risk
4 risks of keeping your FG-100ETK running
Unpatched Vulnerabilities
FortiGate firmware CVEs are actively exploited in the wild. EOL hardware with no patch path is a prime ransomware and lateral movement entry point — especially for perimeter firewalls facing the internet.
Compliance Failure
RBI IT Framework, PCI DSS v4.0, ISO 27001:2022 and CERT-In guidelines require supported, patched network infrastructure. Running EOL hardware is an audit finding and can trigger regulatory penalties or loss of certifications.
No Hardware Recovery
FortiGate power supply, ASIC and port failures happen. EOL hardware has no RMA path — if your FG-100ETK fails at 2am, you are sourcing a grey-market replacement with no support, no warranty and no SLA.
Performance Ceiling
The FG-100ETK's older ASIC architecture creates a throughput bottleneck for SSL inspection and IPS at modern network speeds. Migration delivers 2–4× throughput gains on the same use case.
Recommended Upgrade Path
From FG-100ETK to FortiGate 90G, 100F or 120G
eNeoteric recommends the FortiGate 100F as the primary rack-mount migration target. The FortiGate 90G is a compact desktop option for smaller branch sites. The FortiGate 120G is ideal if you need higher throughput or SFP+ uplinks going forward.
FG-100ETK
EOL · E-series · NP6 ASIC · No new patches · No FortiGuard updates
FortiGate 90G
Active · G-series · NP7lite · 18 Gbps FW · 12x GE + 2x SFP · SD-WAN built-in
FortiGate 100F
Active · F-series · NP7 ASIC · Full FortiGuard · 20 Gbps FW · SD-WAN built-in
FortiGate 120G
Active · G-series · NP7lite · 25 Gbps FW · 10x GE + 2x SFP+ · AI-powered FortiGuard
Need higher capacity? The FortiGate 200F is available for environments requiring above 20 Gbps IPS throughput. Ask eNeoteric for a sizing assessment →
Side-by-Side Comparison
FG-100ETK vs FortiGate 90G vs 100F vs 120G
Indicative specifications. Check official Fortinet datasheets for exact figures. Final sizing by eNeoteric based on your traffic profile:
| Specification | FG-100ETK (EOL) | FortiGate 90G | FortiGate 100F | FortiGate 120G |
|---|---|---|---|---|
| Lifecycle Status | ⛔ End of Life | ✅ Active | ✅ Active | ✅ Active |
| ASIC | NP6 | NP7lite | NP7 | NP7lite |
| Form Factor | 1U Rack | Desktop | 1U Rack | 1U Rack |
| Firewall Throughput | ~10 Gbps | ~18 Gbps | 20 Gbps | 25 Gbps |
| IPS Throughput | ~1.5 Gbps | ~3.5 Gbps | 5 Gbps | 6 Gbps |
| SSL Inspection Throughput | ~770 Mbps | ~3 Gbps | 4 Gbps | 4.5 Gbps |
| Concurrent Sessions | 1.3 M | ~2 M | 3 M | 4 M |
| Secure SD-WAN | Limited | ✅ Built-in | ✅ Built-in | ✅ Built-in |
| Ports | 2x GE WAN + 14x GE | 12x GE RJ45 + 2x SFP | 2x GE WAN + 14x GE + 2x SFP | 10x GE + 2x SFP+ |
| FortiGuard Updates | ⛔ No longer updated | ✅ ATP / UTP / Enterprise | ✅ ATP / UTP / Enterprise | ✅ ATP / UTP / Enterprise |
| FortiCare / RMA | ⛔ Not available | ✅ Available | ✅ Available | ✅ Available |
Specs are indicative. Source: Fortinet official datasheets. eNeoteric performs a traffic and policy analysis before recommending the target model.
How We Do It
eNeoteric's 5-step FG-100ETK migration process
Structured, change-managed and designed for zero disruption to your network:
Environment Assessment & Documentation
eNeoteric audits your FG-100ETK — full config export, policy count, NAT rules, VPN tunnels (IPsec/SSL), SD-WAN links, VDOM structure, routing table, FortiManager integration and interface mapping. Outputs a migration scope document and technical risk register.
Migration Plan & Change Management
A detailed migration runbook covering: target model selection, config conversion approach, pre-migration tests, rollback plan, cutover window and post-migration monitoring period. Submitted through your change management process (or ours).
Config Conversion & Staging
The FG-100ETK configuration is exported, cleaned and converted for the target firmware version. Key areas handled: policy objects, address groups, NAT, application profiles, SSL inspection profiles, IPsec VPN, BGP/OSPF routes and FortiGuard profiles. The converted config is validated in a staging environment before it touches production.
Parallel Deployment & Cutover
The new FortiGate is deployed in parallel, fully configured and tested against your environment. Cutover is executed during an agreed maintenance window — typically under 30 minutes of planned downtime. eNeoteric engineers are on-call during cutover and the 48 hours following go-live.
FortiCare, FortiGuard & Handover
New FortiCare and FortiGuard (UTP or ATP) subscriptions are enrolled on the Fortinet Support Portal against the new device's serial number. Full as-built documentation is delivered and the device is handed over to eNeoteric's annual support engagement or your internal team.
What eNeoteric Handles End-to-End
Everything included in the migration engagement
You don't need to prepare anything. eNeoteric handles the entire migration lifecycle:
Config Export & Backup
Full FG-100ETK config export, backup and version-controlled archive before any changes are made.
Policy & Object Migration
All firewall policies, address objects, service objects, application profiles and schedules — converted for the target model and firmware.
NAT & Routing
IP Pool, VIP, static routes, policy-based routes, BGP/OSPF config — all migrated and validated against your addressing scheme.
VPN Migration
IPsec site-to-site tunnels and SSL VPN config migrated and re-tested with remote sites before cutover.
SD-WAN Configuration
SD-WAN rules, performance SLA monitors, link health checks and application steering profiles rebuilt on the new platform.
FortiManager Integration
If your estate uses FortiManager, the new device is registered, onboarded and policy synced from FortiManager without disrupting other managed devices.
Post-Cutover Monitoring
eNeoteric engineers monitor the new FortiGate for 48 hours post-cutover — traffic flows, VPN tunnels, SD-WAN SLAs, log health and FortiGuard update status.
As-Built Documentation
Complete as-built network and security documentation delivered at handover — topology diagrams, policy summary, VPN inventory and FortiCare/FortiGuard certificate copies.
After migration — keep your new FortiGate protected
Migration is the start, not the finish. eNeoteric's annual support engagement ensures your new FortiGate stays patched, monitored and compliant:
FAQ
FG-100ETK migration — frequently asked questions
What does FortiGate FG-100ETK End of Life mean?
EOL means Fortinet has ceased engineering support for the FG-100ETK — no new firmware, no security patches, no FortiGuard threat intelligence updates and no TAC or RMA support. Running EOL hardware on a network perimeter is an active security risk and a compliance finding under RBI, PCI DSS and ISO 27001.
What should I upgrade the FG-100ETK to?
eNeoteric recommends the FortiGate 100F as the primary migration target — same rack form factor, NP7 ASIC, 20 Gbps firewall throughput, full SD-WAN and active FortiGuard support. The FortiGate 120G is recommended when higher throughput or SFP+ uplinks are needed. We size the replacement based on your actual traffic profile.
Can eNeoteric migrate the entire FG-100ETK config?
Yes. eNeoteric handles the full configuration migration — policies, NAT, VPN tunnels, routing, SD-WAN, address objects, profiles and FortiManager integration. We convert, validate and test the config in staging before touching production, then execute a planned cutover in your maintenance window.
Is there any downtime during migration?
eNeoteric targets zero production downtime by staging the new FortiGate in parallel and running a brief, planned cutover (typically under 30 minutes) in an agreed maintenance window. Exact downtime depends on your topology and HA configuration. A rollback plan is always prepared and tested.
How long does the migration take?
A typical FG-100ETK migration takes 2–4 weeks from kickoff to production cutover — covering assessment, config conversion, staging validation, change management approval and cutover. Complex environments with multiple VDOMs, many VPN tunnels or FortiManager integration may require additional time. eNeoteric provides a project plan at the assessment stage.
What happens to FortiCare and FortiGuard after migration?
FortiCare and FortiGuard licenses are serial-number specific and cannot be transferred from the EOL unit. eNeoteric enrolls the new FortiGate 100F or 120G on the Fortinet Support Portal and provides a consolidated renewal quote for new FortiCare + FortiGuard (UTP/ATP/Enterprise) subscriptions — with GST invoicing.
We have multiple FG-100ETK units across sites — can you handle all of them?
Yes. eNeoteric has managed multi-site FortiGate migration programmes across India. We produce a unified migration plan covering all sites, stagger cutovers to avoid simultaneous risk, and provide a single point of coordination across all locations. Contact us for a multi-site assessment.
Get in touch
Book Your FG-100ETK Migration Assessment
Drop your details and our Fortinet migration team will reach out within one business day. Or call us directly on +91 91080 15170.