Skip to main content
bstefanovski
Staff
Staff
July 17, 2026

Technical Tip: Configuration backup from FortiGate HA primary generates a 0 KB file while the secondary backup works

  • July 17, 2026
  • 0 replies
  • 71 views

Description

This article describes a scenario where FortiGate configuration backup from the HA primary unit generates an empty 0 KB file, while the secondary unit can generate a valid backup.

Scope

FortiGate.

Solution

The issue can happen on the HA primary member, where configuration backups were generated as 0 KB files. The same behavior can be seen from GUI backup, CLI backup, both .conf and .yml formats, and with different administrator accounts. Backup from the HA secondary member was generated correctly.

Verification:

  1. Check if the issue is GUI-only or also CLI-related. Try a backup from the GUI: Select the Admin username in the top-right corner -> Configuration -> Backup -> Local PC.


Then test CLI backup to an external TFTP server:

execute backup config tftp test_config.conf
execute backup full-config tftp test_full.conf
execute backup yaml-config tftp test_yaml.yml


Check the generated file size after each test.

  1. Check if the issue affects only one HA member.


Test backup from the current primary unit and from the secondary unit.

  • Primary backup file size.

  • Secondary backup file size.


If one unit creates a 0 KB file and the other unit creates a valid backup, continue with the HA synchronization test.

  1. Check HA status. Run the following command:


get system ha status diagnose sys ha status


Check for HA Health Status, and the primary and secondary serial numbers.

Configuration Status in-sync or out-of-sync state monitored interfaces status. If the HA cluster is out of sync, this should be fixed as the main problem first.

See the following knowledge base articles to synchronize the HA cluster:


Tip: Most out-of-sync tables have dedicated articles explaining how they should be fixed. Search for the specific table in the Knowledge Base.

Factory reset and config reload should only be considered if:

  • HA is already in sync.

  • A valid backup exists.

  • The issue stays with the same physical unit.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!