Skip to content

Migrate from FortiGate FG-100ETK — EOL Upgrade to FortiGate 90G, 100F or 120G

End of Life Notice: The FortiGate FG-100ETK has reached End of Life status. Fortinet has ceased engineering support, firmware updates and FortiGuard threat intelligence for this platform. Running EOL hardware creates a security gap and compliance exposure under RBI, PCI DSS and ISO 27001. Migration is required — not optional.

eNeoteric manages end-to-end migration from FortiGate FG-100ETK to FortiGate 90G, 100F or 120G — full configuration export and conversion, parallel staging, zero-downtime cutover and new FortiCare and FortiGuard enrollment. As an authorised Fortinet partner, we have done this before.

Authorised Fortinet partner · All India coverage · GST invoicing · Config migration included

What End of Life means for your FG-100ETK

Fortinet's product lifecycle has distinct phases — and EOL is the final one. Here's what has stopped for the FG-100ETK:

🔴

End of Engineering Support

No new firmware builds, no security patches, no CVE hotfixes. Known vulnerabilities discovered after the EOL date will never be patched on your FG-100ETK.

🔴

End of FortiGuard Updates

IPS signatures, AV definitions, web-filter categories and application control databases will no longer update on EOL hardware. Your threat intelligence becomes stale and exploitable.

🔴

End of TAC & RMA

Fortinet's Technical Assistance Center will not provide support for EOL hardware. If your FG-100ETK fails, there is no hardware replacement via RMA.

🟡

FortiManager Compatibility

Future FortiManager versions may drop support for old firmware versions used by EOL devices, creating centralised management gaps in your estate.

4 risks of keeping your FG-100ETK running

🛡️

Unpatched Vulnerabilities

FortiGate firmware CVEs are actively exploited in the wild. EOL hardware with no patch path is a prime ransomware and lateral movement entry point — especially for perimeter firewalls facing the internet.

📋

Compliance Failure

RBI IT Framework, PCI DSS v4.0, ISO 27001:2022 and CERT-In guidelines require supported, patched network infrastructure. Running EOL hardware is an audit finding and can trigger regulatory penalties or loss of certifications.

💥

No Hardware Recovery

FortiGate power supply, ASIC and port failures happen. EOL hardware has no RMA path — if your FG-100ETK fails at 2am, you are sourcing a grey-market replacement with no support, no warranty and no SLA.

📉

Performance Ceiling

The FG-100ETK's older ASIC architecture creates a throughput bottleneck for SSL inspection and IPS at modern network speeds. Migration delivers 2–4× throughput gains on the same use case.

From FG-100ETK to FortiGate 90G, 100F or 120G

eNeoteric recommends the FortiGate 100F as the primary rack-mount migration target. The FortiGate 90G is a compact desktop option for smaller branch sites. The FortiGate 120G is ideal if you need higher throughput or SFP+ uplinks going forward.

End of Life

FG-100ETK

EOL · E-series · NP6 ASIC · No new patches · No FortiGuard updates

Desktop Option

FortiGate 90G

Active · G-series · NP7lite · 18 Gbps FW · 12x GE + 2x SFP · SD-WAN built-in

or
or
Higher Throughput

FortiGate 120G

Active · G-series · NP7lite · 25 Gbps FW · 10x GE + 2x SFP+ · AI-powered FortiGuard

Need higher capacity? The FortiGate 200F is available for environments requiring above 20 Gbps IPS throughput. Ask eNeoteric for a sizing assessment →

FG-100ETK vs FortiGate 90G vs 100F vs 120G

Indicative specifications. Check official Fortinet datasheets for exact figures. Final sizing by eNeoteric based on your traffic profile:

Specification FG-100ETK (EOL) FortiGate 90G FortiGate 100F FortiGate 120G
Lifecycle Status ⛔ End of Life ✅ Active ✅ Active ✅ Active
ASIC NP6 NP7lite NP7 NP7lite
Form Factor 1U Rack Desktop 1U Rack 1U Rack
Firewall Throughput ~10 Gbps ~18 Gbps 20 Gbps 25 Gbps
IPS Throughput ~1.5 Gbps ~3.5 Gbps 5 Gbps 6 Gbps
SSL Inspection Throughput ~770 Mbps ~3 Gbps 4 Gbps 4.5 Gbps
Concurrent Sessions 1.3 M ~2 M 3 M 4 M
Secure SD-WAN Limited ✅ Built-in ✅ Built-in ✅ Built-in
Ports 2x GE WAN + 14x GE 12x GE RJ45 + 2x SFP 2x GE WAN + 14x GE + 2x SFP 10x GE + 2x SFP+
FortiGuard Updates ⛔ No longer updated ✅ ATP / UTP / Enterprise ✅ ATP / UTP / Enterprise ✅ ATP / UTP / Enterprise
FortiCare / RMA ⛔ Not available ✅ Available ✅ Available ✅ Available

Specs are indicative. Source: Fortinet official datasheets. eNeoteric performs a traffic and policy analysis before recommending the target model.

eNeoteric's 5-step FG-100ETK migration process

Structured, change-managed and designed for zero disruption to your network:

1

Environment Assessment & Documentation

eNeoteric audits your FG-100ETK — full config export, policy count, NAT rules, VPN tunnels (IPsec/SSL), SD-WAN links, VDOM structure, routing table, FortiManager integration and interface mapping. Outputs a migration scope document and technical risk register.

2

Migration Plan & Change Management

A detailed migration runbook covering: target model selection, config conversion approach, pre-migration tests, rollback plan, cutover window and post-migration monitoring period. Submitted through your change management process (or ours).

3

Config Conversion & Staging

The FG-100ETK configuration is exported, cleaned and converted for the target firmware version. Key areas handled: policy objects, address groups, NAT, application profiles, SSL inspection profiles, IPsec VPN, BGP/OSPF routes and FortiGuard profiles. The converted config is validated in a staging environment before it touches production.

4

Parallel Deployment & Cutover

The new FortiGate is deployed in parallel, fully configured and tested against your environment. Cutover is executed during an agreed maintenance window — typically under 30 minutes of planned downtime. eNeoteric engineers are on-call during cutover and the 48 hours following go-live.

5

FortiCare, FortiGuard & Handover

New FortiCare and FortiGuard (UTP or ATP) subscriptions are enrolled on the Fortinet Support Portal against the new device's serial number. Full as-built documentation is delivered and the device is handed over to eNeoteric's annual support engagement or your internal team.

Everything included in the migration engagement

You don't need to prepare anything. eNeoteric handles the entire migration lifecycle:

Config Export & Backup

Full FG-100ETK config export, backup and version-controlled archive before any changes are made.

Policy & Object Migration

All firewall policies, address objects, service objects, application profiles and schedules — converted for the target model and firmware.

NAT & Routing

IP Pool, VIP, static routes, policy-based routes, BGP/OSPF config — all migrated and validated against your addressing scheme.

VPN Migration

IPsec site-to-site tunnels and SSL VPN config migrated and re-tested with remote sites before cutover.

SD-WAN Configuration

SD-WAN rules, performance SLA monitors, link health checks and application steering profiles rebuilt on the new platform.

FortiManager Integration

If your estate uses FortiManager, the new device is registered, onboarded and policy synced from FortiManager without disrupting other managed devices.

Post-Cutover Monitoring

eNeoteric engineers monitor the new FortiGate for 48 hours post-cutover — traffic flows, VPN tunnels, SD-WAN SLAs, log health and FortiGuard update status.

As-Built Documentation

Complete as-built network and security documentation delivered at handover — topology diagrams, policy summary, VPN inventory and FortiCare/FortiGuard certificate copies.

After migration — keep your new FortiGate protected

Migration is the start, not the finish. eNeoteric's annual support engagement ensures your new FortiGate stays patched, monitored and compliant:

Fortinet Renewal Services → FortiCare + FortiGuard renewal, ITILv4 support, quarterly health checks and upgrade management. Fortinet Partner India Full Fortinet Security Fabric — FortiGate, FortiManager, FortiAnalyzer, SD-WAN and more. FortiGate Price India FortiGate 100F / 120G pricing guide, UTP bundles and buy-back offers. Managed Security Services 24×7 NOC monitoring, policy lifecycle management and incident response.

FG-100ETK migration — frequently asked questions

What does FortiGate FG-100ETK End of Life mean?

EOL means Fortinet has ceased engineering support for the FG-100ETK — no new firmware, no security patches, no FortiGuard threat intelligence updates and no TAC or RMA support. Running EOL hardware on a network perimeter is an active security risk and a compliance finding under RBI, PCI DSS and ISO 27001.

What should I upgrade the FG-100ETK to?

eNeoteric recommends the FortiGate 100F as the primary migration target — same rack form factor, NP7 ASIC, 20 Gbps firewall throughput, full SD-WAN and active FortiGuard support. The FortiGate 120G is recommended when higher throughput or SFP+ uplinks are needed. We size the replacement based on your actual traffic profile.

Can eNeoteric migrate the entire FG-100ETK config?

Yes. eNeoteric handles the full configuration migration — policies, NAT, VPN tunnels, routing, SD-WAN, address objects, profiles and FortiManager integration. We convert, validate and test the config in staging before touching production, then execute a planned cutover in your maintenance window.

Is there any downtime during migration?

eNeoteric targets zero production downtime by staging the new FortiGate in parallel and running a brief, planned cutover (typically under 30 minutes) in an agreed maintenance window. Exact downtime depends on your topology and HA configuration. A rollback plan is always prepared and tested.

How long does the migration take?

A typical FG-100ETK migration takes 2–4 weeks from kickoff to production cutover — covering assessment, config conversion, staging validation, change management approval and cutover. Complex environments with multiple VDOMs, many VPN tunnels or FortiManager integration may require additional time. eNeoteric provides a project plan at the assessment stage.

What happens to FortiCare and FortiGuard after migration?

FortiCare and FortiGuard licenses are serial-number specific and cannot be transferred from the EOL unit. eNeoteric enrolls the new FortiGate 100F or 120G on the Fortinet Support Portal and provides a consolidated renewal quote for new FortiCare + FortiGuard (UTP/ATP/Enterprise) subscriptions — with GST invoicing.

We have multiple FG-100ETK units across sites — can you handle all of them?

Yes. eNeoteric has managed multi-site FortiGate migration programmes across India. We produce a unified migration plan covering all sites, stagger cutovers to avoid simultaneous risk, and provide a single point of coordination across all locations. Contact us for a multi-site assessment.

Book Your FG-100ETK Migration Assessment

Drop your details and our Fortinet migration team will reach out within one business day. Or call us directly on +91 91080 15170.

💬 Chat on WhatsApp instead
Call Now WhatsApp Quote