Hello team!!!
I am just starting with automatic backups, I am looking for a way to send automatically backups to any of the following:
* Cloud storage
* Shared folder on the internal network (SMB)
* Email
* Any other suggested desination but FTP, SFTP nor TFTP
The only way I found is to any kind of FTP Server, but I dont want to create a FTP Server just for a Fortigate backup.
I could modify the stitch for FTP to send an email but I dont know how to attach the backup file to it.
Any idea?
Thanks in advance.
Regards,
Damián
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Unfortunately, the method of backup available in FortiGate is limited to FTP, SFTP, USB, flash. You may want to consider downloading the configuration file using SCP is you do not want to setup a FTP server for the respective:
Technical Tip: How to download a FortiGate configu... - Fortinet Community
Unfortunately, the method of backup available in FortiGate is limited to FTP, SFTP, USB, flash. You may want to consider downloading the configuration file using SCP is you do not want to setup a FTP server for the respective:
Technical Tip: How to download a FortiGate configu... - Fortinet Community
Like @kcheng already said there is no built-in support in Fortigate for such back up destinations. But for the benefit of other readers of this post, I will go and add that none of the back up destinations seem safe enough, or according to the best practices of today.
Yes, Fortigate encrypts all passwords/PSKs in the config when exported, but still, having the complete firewall config file available makes malicious actors' life so much easier.
The usual practice in the corporate/Ent environment is either to have a dedicated product that backs up config securely, or set up custom hardened server (SFTP/SCP) with encrypted filesystem and with very restricted access controls to it.
Thanks Yuri and Kcheng!
I prefer to have an unsecure backup outside the fortigate than do not have any backup or an old backup.
I will try with scp, although I think I will need to install a program because we have few PCs with linux
Anyway, is good to know the options.
Regards!
Damián
"because we have few PCs with linux"
no need to have Linux/Unix machine.
How about WinSCP if you are looking for manual SCP copy ?
Windows 10+ do have Windows Linux Subsystem support and so you can run CLI based linux inside and integrated within your Windows workstation.
Another option would be to use PuTTY and plink and make simple script to connect to FortiGate and do a backup this way. Or how about some Python? Or FortiOS API calls?
There is plenty of ways how to do it.
But if in local network, and for simplicity sake (setup&forget) I'd opt for FTP or SFTP option. Then you can move those backups whenever you'd like.
And yes, there are (S)FTP servers even for Windows (for simple example Serva64 is one of them I use occasionally for lab testing purposes).
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.