Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FatalHalt
Contributor II

Automatic Backups not happening (backup mode)

Hi all, I' m running a 1000c 5.0.5 and experiencing some issues. All of my ADOMs are in backup mode (different story, changing soon), but only 1 of them is actually doing automatic backups when an Admin makes a change on the managed device. The thing is, the the Manager knows as soon as it' s out of sync with a device. If I even just add a comment to the firewall, the manager goes to ' out-of-sync' but doesn' t pull the new configuration. All of the devices have an appropriately configured ' config system central-management' section that looks something like this:
Fatal_Halt (central-management) # get
 mode                : backup 
 type                : fortimanager 
 schedule-config-restore: enable 
 schedule-script-restore: enable 
 allow-push-configuration: enable 
 allow-pushd-firmware: enable 
 allow-remote-firmware-upgrade: enable 
 allow-monitor       : enable 
 serial-number       : " xxxxxxxxxxxxxxxxxxxxx" 
 fmg                 : xxx.xxx.xxx.xxx 
 fmg-source-ip       : xxx.xxx.xxx.xxx
 vdom                : root 
 enc-algorithm       : default 
All the devices have FGFM enabled on the interface being used. Anyone have any thoughts?
2 REPLIES 2
FatalHalt
Contributor II

Well, Fortinet got back to me, but I' m not sure I understand everything. In my original post, I showed the configuration of the central-management piece for a 1000c, this is the device that IS working, and getting automatic backups:
Fatal_Halt (central-management) # get 
  mode                : backup  
  type                : fortimanager  
  schedule-config-restore: enable  
  schedule-script-restore: enable  
  allow-push-configuration: enable  
  allow-pushd-firmware: enable  
  allow-remote-firmware-upgrade: enable  
  allow-monitor       : enable  
  serial-number       : " xxxxxxxxxxxxxxxxxxxxx"  
  fmg                 : xxx.xxx.xxx.xxx  
  fmg-source-ip       : xxx.xxx.xxx.xxx 
  vdom                : root  
  enc-algorithm       : default 
On other devices, this section looks a bit different, like such:
Fatal_Halt2 (central-management) # get
 mode                : backup 
 type                : fortimanager 
 schedule-config-restore: enable 
 schedule-script-restore: enable 
 allow-push-configuration: enable 
 allow-pushd-firmware: enable 
 allow-remote-firmware-upgrade: enable 
 allow-monitor       : enable 
 fortimanager-fds-override: disable
 serial-number       : " xxxxxxxxxxxxxxxxxxx" 
 fmg                 : xxx.xxx.xxx.xxx 
 fmg-source-ip       : xxx.xxx.xxx.xxx
 vdom                : root 
 enc-algorithm       : default 
My Fortinet tech had me ' set fortimanager-fds-override enable' on this second box, and it is now working. However, do I now have to make configuration settings to ensure that the manager is distributing fortiguard settings correctly?
oheigl
Contributor II

Can you upgrade one FortiGate to the latest 5.0.9 release? I' m not sure everything is working correctly with 5.0.5, so you could rule out firmware bugs.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors