FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.

This article describes how to configure automation stitch to make backups using TFTP over IPSec tunnel.

Related document.

1) Create Automation Stitch as per the picture below.

From GUI, go to Security Fabric -> Automation and select 'Create New'.

In this example the trigger is scheduled to execute the command '# execute backup config tftp Minjo.cfg' every day at 01:09.
The IP address is a host over the IPsec where the backups are being done.

2) Configure IP addresses in the IPsec tunnels:

From GUI go to  Network -> Interfaces.
Under the port where the VPN tunnel is configured, select '+' and select the VPN tunnel.
From CLI check '# get router info routing-table all' to choose a free IP address range to use for the tunnel interface.

In this example:
From the fortiGate from where the backup is settled.

Do the same steps for the remote FortiGate:

3) How to configure an IPSec tunnel.
From GUI, go to VPN -> IPsec Tunnels and select the tunnel.
In the phase2 selectors tunnel IP address is used as local and the TFTP server as remote address.
If it is changed over an IPSec tunnel that is already in use, do not forget to apply new policies and static routes for this implementation.
The phase2 selectors must match on both FortiGates, therefore adjust the IPsec tunnel as below:

As a result of the previous steps, it is possible to do a configuration backup using TFTP over IPsec tunnel: