Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
albaker1
Contributor

Backups stopped working after implementing FAZ for FMG-managed firewalls

All our FortiGates (running 7.2.8) are managed by a virtual FMG (running 7.2.5), and backups have run consistently since they were setup. We recently implemented FAZ, and as soon as we setup a root for the security fabric, every backup has been failing except for the one that is the root. The backup for the root FortiGate is now creating 5 files every night (file sizes are different) and we get 5 alerts; also, all files are in the same folder. Files are encrypted, so I don't know if they are all from the same firewall, but I may disable encryption for a night to see what I can find inside the files. Incidentally, we have 13 FortiGates and should have 13 backup files. Can someone point me in a direction to look at to figure why the backups are no longer running? Thank you.

1 Solution
albaker1

I think we got the problem resolved. The Security Fabric Automation doesn't run on non-root FGTs, and we were able to add the backups for all FortiGates to the root on the Security Fabric under the Automation Stitch. Thanks for your time and effort, adambomb1219.

View solution in original post

5 REPLIES 5
adambomb1219
SuperUser
SuperUser

Backups to what? Local flash?  Remote server?  What do the logs say?  What is the use-case to have the firewalls perform backups directly when the configuration db is in FortiManager?

albaker1

It's backing up for an SFTP server. I understand there is configuration within the FMG, but we all network devices are backed up to the SFTP server. 

adambomb1219

Did/Is the FMG resetting the SFTP keys?  What if you manually trigger a backup attempt?

albaker1

I think we got the problem resolved. The Security Fabric Automation doesn't run on non-root FGTs, and we were able to add the backups for all FortiGates to the root on the Security Fabric under the Automation Stitch. Thanks for your time and effort, adambomb1219.

mpapisetty

Hi @albaker1 , 

Yes, the automation stiches only run on the root Fortigate. The relevant documentation can be found in the cookbook - 

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/139441/automation-stitches

 

"Automation stitches can only be created on the root FortiGate in a Security Fabric."

-Manoj Papisetty
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors