Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vladyslaw
New Contributor

How to export revision list via CLI ?

Hi all, 

 

I have two FortiGates 600C that working in cluster (Active-Passive)

FG1 Master

FG2 Slave 

 

Now we had some configuration failure during a maintenance and FG2 became a master.

Now we want to export revision list files that stored on FG1 and I don't have an access to it via Web GUI, only via CLI,

 

When I go to Web GUI it takes me to FG2 because he is a master now and I can see revision config list that stored on this appliance via admin -> Configuration -> Revisions. and there I can manage them and export via Save,

 

But I don't have Web GUI access to FG1, only via CLI, I can see the list with command "execute revision list config" and cant find a way to export and compare these files,

 

Please assist

4 REPLIES 4
Seppel
Contributor II

hi

I do not know if an export of a specific revision is possible. but what you could do, assign a free interface to an ip from a free range and then use a computer directly via gui to access your node 1. then you can download the revision on the gui. for the future, it might be useful to configure a management vlan, so you can connect direct on the gui of each member.

 

regards

Fortigate 500E HA Fortimail 200 Fortimanager

FortiEMS

FortiSandbox 1000D

FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------

Fortigate 500E HA Fortimail 200 Fortimanager FortiEMS FortiSandbox 1000D FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------
vladyslaw

Seppel, thanks for response,

 

We don't have physical access to appliance and must perform this action remotely, 

 

:(

emnoc
Esteemed Contributor III

IMHO your wasting your time. I the FGt 2x where in a HA and you cfg unit1 the changes are sent to unit2 , nothing to compare.

 

if you had a hardware failure and unit2 become active , than it has the most current change and will sync the cfg when unit1 is re-introduce into a HA cluster.

 

Again no need to sync anything, the master is just that ...."the master" regardless if it was unit1 and then unit2 or reverse.

 

And if you suspect cfg sync run  "diag sys ha cluster-csum" the checksum should match on both units

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
orani
Contributor II

You can also reboot the FGT2 to make FGT1 master again and access the web gui.

Orestis Nikolaidis

Network Engineer/IT Administrator

Orestis Nikolaidis Network Engineer/IT Administrator
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors