Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
albaker1
Contributor

Backups stopped working after implementing FAZ for FMG-managed firewalls

All our FortiGates (running 7.2.8) are managed by a virtual FMG (running 7.2.5), and backups have run consistently since they were setup. We recently implemented FAZ, and as soon as we setup a root for the security fabric, every backup has been failing except for the one that is the root. The backup for the root FortiGate is now creating 5 files every night (file sizes are different) and we get 5 alerts; also, all files are in the same folder. Files are encrypted, so I don't know if they are all from the same firewall, but I may disable encryption for a night to see what I can find inside the files. Incidentally, we have 13 FortiGates and should have 13 backup files. Can someone point me in a direction to look at to figure why the backups are no longer running? Thank you.

1 Solution
albaker1

I think we got the problem resolved. The Security Fabric Automation doesn't run on non-root FGTs, and we were able to add the backups for all FortiGates to the root on the Security Fabric under the Automation Stitch. Thanks for your time and effort, adambomb1219.

View solution in original post

6 REPLIES 6
adambomb1219
SuperUser
SuperUser

Backups to what? Local flash?  Remote server?  What do the logs say?  What is the use-case to have the firewalls perform backups directly when the configuration db is in FortiManager?

albaker1

It's backing up for an SFTP server. I understand there is configuration within the FMG, but we all network devices are backed up to the SFTP server. 

adambomb1219

Did/Is the FMG resetting the SFTP keys?  What if you manually trigger a backup attempt?

albaker1

I think we got the problem resolved. The Security Fabric Automation doesn't run on non-root FGTs, and we were able to add the backups for all FortiGates to the root on the Security Fabric under the Automation Stitch. Thanks for your time and effort, adambomb1219.

mpapisetty

Hi @albaker1 , 

Yes, the automation stiches only run on the root Fortigate. The relevant documentation can be found in the cookbook - 

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/139441/automation-stitches

 

"Automation stitches can only be created on the root FortiGate in a Security Fabric."

HTH
Manoj Papisetty
Priyanka_Arumugam29
New Contributor

I am currently working with a demo FortiManager device deployed in a VMware environment, and I’m encountering some challenges with specific functionalities.

Restoring FortiGate Backups via FortiManager: I need to know whether it is possible to restore a FortiGate firewall using a backup configuration file through FortiManager, in the same way we typically do directly on the FortiGate device. If this feature is supported, I would appreciate detailed steps or reference documentation that can guide me through the restoration process within FortiManager.

Firmware Upgrade Capabilities: I’m also looking to confirm if FortiManager supports firmware upgrades for FortiGate devices, both individually and in bulk. If this functionality is available, I would be grateful for guidance on how to perform the upgrades, including any prerequisites and best practices to follow.

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors