Firewall + CloudKey > Unifi Cloud Gateway

2nd February 2026

This is the general path i took to migrate a Fortinet Firewall + Cloudkey (CK) to Unifi Cloud Gateway Max (CGM) which has a combined Firewall + CloudKey


CGW Update Network App version to same as CK
-Settings, Control Plane, Updates

Backup old CK in 2 locations
-Settings, System, Backups, Download
-Settings, Control Plane, Backups, Backup Now… Download

Restore config on new CGM so it can manage existing Unifi devices
-Settings, Control Plane, Backups, Restore
-when done the CloudKey can be removed
-configure CGM internal network, it will likely default to 192.168.x.x
-set CGW LAN + DHCP same as Old Firewall

If Internet/WAN is NOT DHCP
-Configure an additional WAN port on CGW, Settings, Internet, Add_WAN
-plug WAN2 into existing network, verify it shows in Unifi WebPortal
-set CGW WAN1 as StaticIP/PPPoE get info from Old Firewall
-Old Firewall; record info for other ports; IP addr, DHCP, VLANs, VPN etc

Swap UCG to primary Firewall, remove Old Firewall/Fortigate
-setup any DMZ ports, VLANs, VPNs etc

Tip
-Old Fortigate DHCP WAN can be plugged into any network to look at old settings
https://customersso1.fortinet.com