backup and restore - why is it so difficult and how can we do it the right way ?
Hi,
First, please let me say, i have gone over the forum and read many posts about this issue, and i just can't find a recommended solution for CLI backups for my system.
We have some Fortigate firewalls, all are configured with VDOMs and running in a 2 device cluster (some as active/active and the other as active/passive)
Backing up the device should not be so hard. i am trying to log-in to the machine using CLI and running a backup to TFTP operation (Later, i would like also to run an automataed script , but thats the next step)
I created a user for the backup. It has a dedicated admin profile (i dont think it is a good idea to give the backup admin user a super admin permission) When i log in with that user, i cannot run the "config global" command , which makes me wonder : 1) what is the difference between running "execute backup full-configuration" from VDOM menu , and running "execute backup config " from global menu? From where should i execute the backup operation? 2) What is the difference between execute backup config / full-config / all-settings ?
One more thing that i am puzzled about, in a cluster enviurment , should i run the backup from each cluster member ? or can i run it once while connecting to the VIP address?
Final question, what kind of backup should i run in order to be able to fully restore the machine? Should the backup be encrypted in order to fully save the passwords and VPN configuration ? Or can it be without encryption?
It is very strange that fortinet are not providing easy to use backup & restore operation (not talking about scheduling, which is a all other subject)
Thanks.
