Skip to main content
jamaykans
New Member
February 13, 2023
Question

CFG-Save Revert & FortiManager

  • February 13, 2023
  • 2 replies
  • 4806 views

I have a situation where I'm about to import several deployed Fortigates into Fortimanager (cloud) so we can centrally manage them. Most of these Fortigates have specific device settings including "cfg-save revert" enabled. They were configured that way because they are in remote locations and "revert" acted as a fail-safe in case someone goofed-up a setting.

Is it good practice to continue using "cfg-save revert" when the Fortigates are centrally managed through Fortimanager? If so, what's the best way to actually commit changes to devices after a push has been made through Fortimanger? Right now our admins are used to Fortigate GUI indicating a change has been made, and clicking on "Save" (7.0.9). Is there any kind of reminder or indicator in FortiManager to commit saved changes?

Thanks!

2 replies

gfleming
Staff
Staff
February 13, 2023

FortiManager has its own failsafes built-in. If a remote FortiGate is configured by FortiManager (config push) and subsequently loses its connection back to FortiManager, the FortiGate will revert back.

 

https://docs.fortinet.com/document/fortimanager/6.4.0/fortigate-fortimanager-communications-protocol-guide/141304/fgfm-recovery-logic

Debbie_FTNT
Staff & Editor
Staff & Editor
February 14, 2023

In addition to Graham's comment:

- the cfg-save setting shouldn't really matter; it applies to changes made to FortiGate via CLI, and ideally with a FortiManager all changes should be made from the manager and NOT locally on the FortiGate, as that would cause it to go out of sync with FortiManager

-> if you anticipate some changes will still be made on FortiGate directly, then by all means leave the setting in place

- Configuration changes on FortiManager are NOT automatically pushed to FortiGate; they need to be manually saved, and then the package can be pushed (installed) to FortiGate

- FortiManager has its own failsaves as Graham mentioned - if the connection between FortiGate and FortiManager goes down during a policy push, and doesn't restore in a given timeframe, the FortiGate aborts any changes made by FortiManager
- if the connection remains up between FortiManager and FortiGate and there are no errors, changes are automatically committed by FortiGate (the cfg-save setting has no impact on this)
-> if there are errors, all configuration except the bits causing the error are committed, and FortiManager can display a dialogue with the errors encountered during a policy push

- FortiManager retains a revision history automatically; each successful policy push creates a new revision of that FortiGate's configuration
-> https://docs.fortinet.com/document/fortimanager/6.0.7/administration-guide/26761/managing-configuration-revision-history

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.