Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FatalHalt
Contributor II

Automatic Backups not happening (backup mode)

Hi all, I' m running a 1000c 5.0.5 and experiencing some issues. All of my ADOMs are in backup mode (different story, changing soon), but only 1 of them is actually doing automatic backups when an Admin makes a change on the managed device. The thing is, the the Manager knows as soon as it' s out of sync with a device. If I even just add a comment to the firewall, the manager goes to ' out-of-sync' but doesn' t pull the new configuration. All of the devices have an appropriately configured ' config system central-management' section that looks something like this:
Fatal_Halt (central-management) # get
 mode                : backup 
 type                : fortimanager 
 schedule-config-restore: enable 
 schedule-script-restore: enable 
 allow-push-configuration: enable 
 allow-pushd-firmware: enable 
 allow-remote-firmware-upgrade: enable 
 allow-monitor       : enable 
 serial-number       : " xxxxxxxxxxxxxxxxxxxxx" 
 fmg                 : xxx.xxx.xxx.xxx 
 fmg-source-ip       : xxx.xxx.xxx.xxx
 vdom                : root 
 enc-algorithm       : default 
All the devices have FGFM enabled on the interface being used. Anyone have any thoughts?
2 REPLIES 2
FatalHalt
Contributor II

Well, Fortinet got back to me, but I' m not sure I understand everything. In my original post, I showed the configuration of the central-management piece for a 1000c, this is the device that IS working, and getting automatic backups:
Fatal_Halt (central-management) # get 
  mode                : backup  
  type                : fortimanager  
  schedule-config-restore: enable  
  schedule-script-restore: enable  
  allow-push-configuration: enable  
  allow-pushd-firmware: enable  
  allow-remote-firmware-upgrade: enable  
  allow-monitor       : enable  
  serial-number       : " xxxxxxxxxxxxxxxxxxxxx"  
  fmg                 : xxx.xxx.xxx.xxx  
  fmg-source-ip       : xxx.xxx.xxx.xxx 
  vdom                : root  
  enc-algorithm       : default 
On other devices, this section looks a bit different, like such:
Fatal_Halt2 (central-management) # get
 mode                : backup 
 type                : fortimanager 
 schedule-config-restore: enable 
 schedule-script-restore: enable 
 allow-push-configuration: enable 
 allow-pushd-firmware: enable 
 allow-remote-firmware-upgrade: enable 
 allow-monitor       : enable 
 fortimanager-fds-override: disable
 serial-number       : " xxxxxxxxxxxxxxxxxxx" 
 fmg                 : xxx.xxx.xxx.xxx 
 fmg-source-ip       : xxx.xxx.xxx.xxx
 vdom                : root 
 enc-algorithm       : default 
My Fortinet tech had me ' set fortimanager-fds-override enable' on this second box, and it is now working. However, do I now have to make configuration settings to ensure that the manager is distributing fortiguard settings correctly?
oheigl
Contributor II

Can you upgrade one FortiGate to the latest 5.0.9 release? I' m not sure everything is working correctly with 5.0.5, so you could rule out firmware bugs.
Labels
Top Kudoed Authors