FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
bksol92
Staff
Staff
Article Id 267096
Description This article describes one of the more common issues when transferring a FortiManager config backup to a remote SFTP server, and offers a workaround.
Scope FortiManager.
Solution

In this scenario, the user has created an SFTP server to initiate SFTP transfer from FortiManager as per this TECadmin article

The SFTP user created this way should only have access to the chrooted home directory (/var/sftp) and the directory 'files' (/var/sftp/files) via SFTP.

 

If the SFTP user only has permission for a specific folder (e.g /home/sftpuser/fmgbackup), then user have to specify the complete directory path when setup the path.

 

For example:

 

exe backup all-settings sftp 10.47.4.149 /home/sftpuser/fmgbackup sftpuser password

 

An error will occur when specifying only the 'files' directory in the 'exe backup...' command as the destination for the FortiManager backup transfer:

 

sftp-fail.PNG

 

Running 'dia de app curl -1' while the transfer is initiated will show that authentication was successful but the upload operation failed.

 

To resolve this, specify the filename of the backup to be uploaded into the SFTP server:

 

exe backup all-settings sftp <SFTP server IP> /<directory>/<filename> <SFTP user> <password>

 

sftp-success.PNG

 

The upload will be successful, as can be seen in the debug output.