Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damianhlozano
Contributor

Automatic backup not to FTP

Hello team!!!

 

I am just starting with automatic backups, I am looking for a way to send automatically backups to any of the following:

* Cloud storage

* Shared folder on the internal network (SMB)
* Email

* Any other suggested desination but FTP, SFTP nor TFTP

 

The only way I found is to any kind of FTP Server, but I dont want to create a FTP Server just for a Fortigate backup.

I could modify the stitch for FTP to send an email but I dont know how to attach the backup file to it.

 

Any idea?

Thanks in advance.

Regards,

Damián

1 Solution
kcheng
Staff
Staff

Hi @damianhlozano 

 

Unfortunately, the method of backup available in FortiGate is limited to FTP, SFTP, USB, flash. You may want to consider downloading the configuration file using SCP is you do not want to setup a FTP server for the respective:

Technical Tip: How to download a FortiGate configu... - Fortinet Community

Cheers,
Kayzie Cheng

If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

4 REPLIES 4
kcheng
Staff
Staff

Hi @damianhlozano 

 

Unfortunately, the method of backup available in FortiGate is limited to FTP, SFTP, USB, flash. You may want to consider downloading the configuration file using SCP is you do not want to setup a FTP server for the respective:

Technical Tip: How to download a FortiGate configu... - Fortinet Community

Cheers,
Kayzie Cheng

If you have found a solution, please like and accept it to make it easily accessible for others.
Yurisk
Valued Contributor

Like @kcheng already said there is no built-in support in Fortigate for such back up destinations. But for the benefit of other readers of this post, I will go and add that none of the back up destinations seem safe enough, or according to the best practices of today. 

 

  • Cloud storage? It is a matter of time until someone by mistake makes this S3 bucket public-read, and ongoing scans discover it.
  • Shared folder/SMB? The first place any malware/ransomware will look for once inside the network.
  • Email? Makes it so much easier for someone by mistake/maliciously to forward the configs, or leave it in the forgotten external harddisk/storage backup of the mail server. Also, one of the favored by malware/ransomware agents to get hands on/dump mail server backups/storage.

Yes, Fortigate encrypts all passwords/PSKs in the config when exported, but still, having the complete firewall config file available makes malicious actors' life so much easier.

The usual practice in the corporate/Ent environment is either to have a dedicated product that backs up config securely, or set up custom hardened server (SFTP/SCP) with encrypted filesystem and with very restricted access controls to it. 

   

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
damianhlozano
Contributor

Thanks Yuri and Kcheng!

I prefer to have an unsecure backup outside the fortigate than do not have any backup or an old backup.

I will try with scp, although I think I will need to install a program because we have few PCs with linux

 

Anyway, is good to know the options.

Regards!

Damián

xsilver_FTNT

@damianhlozano 

"because we have few PCs with linux"
no need to have Linux/Unix machine.

How about WinSCP if you are looking for manual SCP copy ?
Windows 10+ do have Windows Linux Subsystem support and so you can run CLI based linux inside and integrated within your Windows workstation.
Another option would be to use PuTTY and plink and make simple script to connect to FortiGate and do a backup this way. Or how about some Python? Or FortiOS API calls?
There is plenty of ways how to do it.
But if in local network, and for simplicity sake (setup&forget) I'd opt for FTP or SFTP option. Then you can move those backups whenever you'd like.
And yes, there are (S)FTP servers even for Windows (for simple example Serva64 is one of them I use occasionally for lab testing purposes).

 

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Labels
Top Kudoed Authors