FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
cgustave
Staff
Staff
Article Id 194875
Purpose
This article explains how to use the online "FortiGuard Analysis and Managed Service" (FAMS) to backup and restore a FortiGate configuration.

The FAMS service is a free service  allowing storage of up to 1 GB of data for low end units which are covered by a FortiCare 8x5 or 24x7 contract.

For more details on FAMS, refer to the attached "What's New document" and to the FortiOS 4.0 MR3 patch7 release notes.

Scope

FortiGate 4.3


Diagram


Expectations, Requirements
Requirement

FortiGuard Analysis and Management Service should be activated.  Activation is explained in the attached "What's New document", section 'Logging and reporting enhancement'->'FortiGuard Analysis and Management Service (FAMS)'

 Expectations

- Backup FortiGate configuration file to FAMS
- Restore a FAMS backup revision to the FortiGate

Configuration
To allow the FAMS Service to backup/restore configuration, the FortiGate should be configured with central-management backup service for FortiGuard.
FWF60B-CGUS # config system central-management
FWF60B-CGUS (central-manage~e) # set type fortiguard
FWF60B-CGUS (central-manage~e) # set mode backup
FWF60B-CGUS (central-manage~e) #end
It is now possible to use manual backup/restore CLI command to save and restore.

Manual backup of the configuration to FAMS

FWF60B-CGUS # execute backup config management-station "Backup my config"

Running............Config upload request to management station done.
Setting timestamp
FWF60B-CGUS #

On the FAMS portal under 'Management'->'Config History' the upload of the configuration file should be displayed referenced by a revision number.

cgustave_33803_a_FD33803.jpg

The URL of the FAMS portal is https://fams.fortinet.com

Manual restore of the FAMS configuration backup to FortiGate

The first step is to determine the revision number that is to be restored, this can be seen from the FAMS portal or obtained from FortiGate CLI as shown below:

FWF60B-CGUS # execute restore config management-station normal 0

Running..Done.
------------------------------------------------
Total configuration revisions available: 1
------------------------------------------------
Revision Timestamp Comments
------------------------------------------------
2812 2012/09/11 10:48:34 Backup my config
------------------------------------------------

Note that providing '0' for the revision will list the revisions available on FAMS.

Once the revision number is known, use the exec restore command with the required revision as shown below:

FWF60B-CGUS # execute restore config management-station normal 2812
This operation will overwrite the current settings!
Do you want to continue? (y/n)y

Please wait...

Running...Done.
config download request to management station OK
File check OK.
Done.

FWF60B-CGUS #

The FortiGate will download configuration from FAMS and reboot with this revision of the configuration.

Contributors