Skip to main content
Jon_Hill
New Member
July 13, 2009
Question

Newbie Question - Copy config from one firewall to another in the CLI

  • July 13, 2009
  • 7 replies
  • 9698 views
I' ve got two Fortigate firewalls with different policies and need to make sure that both policies match. Is it possible to copy addresses and address groups from the CLI between the two firewalls? Is there anything I need to make sure I do first before I commence the work? Thanks Jon

    7 replies

    g3rman
    New Member
    July 13, 2009
    Hi Jon, welcome to the forums. Copying objects on the CLI is the fastest way to do this unless you happen to have a FortiManager around :) The order you should go in: -Host addresses (show firewall address) -Address groups (show firewall addrgrp) -Custom services -Custom service groups -Policies
    Jon_Hill
    Jon_HillAuthor
    New Member
    July 22, 2009
    Thanks for the info, if a host address or group exists already in the config of the firewall I' m transferring to will it overwrite the existing host\group or ignore it? Thanks Jon
    rwpatterson
    New Member
    July 22, 2009
    It will add to it, overlay existing, and adding unique entities.
    Contributor III
    August 3, 2009
    Jon, if the 2 fortigates are the same model, you can export, then import the whole configs file from on into another. If this isn' t the case, I would personally save both firewall configs as text files, then edit/compare them manually on your PC. You can copy/paste configs commands back and forth between the 2 configs files as needed.
    TopJimmy
    New Member
    August 19, 2009
    I' ve had to do this recently and I didn' t have much (any) luck. I' ve got a pair of FGT800' s in a cluster that aren' t syncing properly since the upgrade to 4.0.3. One of the procedures that Fortinet support asked me to do was to take the slave offline, disconnect ethernet cables and from the console port, do a " factory default" and then, after changing the HA priority and the " name" of the unit, copy the config from the primary to the slave and then reconnect the slave to the cluster. My config from the primary is over 5MB in size. The paste process hosed the 2 different terminal programs (hyper term and PowerTerm) I use. I' m not sure if it overloaded the comm port on my PC or what but I' ve got a couple questions for those that have done this in the past successfully: 1.) What program did you use? 2.) Did you connect to the console port directly or was it a CLI/Telnet/SSH connection? 3.) How big is your config file? Any help would be much appreciated.
    rwpatterson
    New Member
    August 19, 2009
    Did you try restoring into the backup instead of cut/paste? I get about 200 lines, and the Windoze clipboard takes a dump....
    TopJimmy
    New Member
    August 19, 2009
    yeah....I' m a moron. I just did that and it works great. I think the Fortinet support dude saw my post or something and he called me and told me of the restore function. Using the console cable through a serial port to load huge files doesn' t work very well. Thanks!
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!