Technical Tip: Configure automation backup over IPsec tunnel
Description
This article describes configuring automation stitches to make backups using TFTP over an IPSec tunnel.
Scope
FortiGate.
Solution
Create an Automation Stitch as per the picture below. Go to Security Fabric -> Automation from the GUI and select 'Create New'.
In this example, the trigger is scheduled to execute the command 'execute backup config tftp Minjo.cfg 10.187.5.102' every day at 01:09.
The IP address is a host over the IPsec where the backups are being done.

In this example:
From the FortiGate, where the backup is stored.




How to configure an IPSec tunnel: Site-to-site VPN.


Make sure phase 2 is up before initiating traffic. To check phase 2 status, navigate Dashboard -> Network -> IPSec.

In case phase 2 is not up, refer to this document for more troubleshooting steps: Troubleshooting Tip: Troubleshooting IPsec Site-to... - Fortinet Community

Another way is to use preferred-source parameter under the static route to specify the source IP that will be used for local or self-originating traffic of FortiGate. More details can be found on Technical Tip: Custom source IP for locally originated TFTP/FTP/SFTP traffic.
Automation stitches
