Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
THOUEL
New Contributor

Reset Fortigate config from Fortimanager

Hello,
I am looking for a way to do a factory reset of a Fortigate from a Fortimanager.
I haven't found anything in the documentation about this.
Am I missing something or is it really not done?
Thanks in advance for your feedback.
Regards,

11 REPLIES 11
dingjerry_FTNT

@THOUEL ,

 

To factory reset a FortiGate (FGT) device managed by a FortiManager (FMG), you can use the command "execute factory-reset" within the FortiGate CLI, which will reset all configurations on the device to factory defaults; always ensure you have a backup before performing a factory reset as it will erase all settings. 

 

However, please note, after Factory Reset, you will lose the connection to the FGT on the FMG.  So you still need console access or local access to the FGT for further configuration. 

 

That means, it does not make any sense or it is not practical to factory reset an FGT from FMG.

Regards,

Jerry
THOUEL
New Contributor

Thank you for your time.

 

The idea is to prevent live configuration on the Fortigate, so all configuration is done from the Fortimanager.

But when we sell a facility, and the Fortigates (HA cluster) are transferred, how can we do that the team can run a factory reset from the Fortimanager... Currently, one of the IT managers, who has the local administrator password, connects for a few minutes and performs the factory reset action on the reset all conf call.

dingjerry_FTNT

Hi @THOUEL ,

 

I am not sure what you mean.

 

Do you mean that you sell a FGT to someone, and want to erase all configuration on this FGT before you give the FGT device to that customer?

Regards,

Jerry
THOUEL

Hi,

Sometimes my company buys and/or sells facilities. When selling, we leave the firewalls to the buyers. So we need to factory reset them.

Regards,

dingjerry_FTNT

Hi @THOUEL ,

 

So does that mean you(FMG) no longer take care of the FGT after the factory reset?

Regards,

Jerry
THOUEL

Hello,

 

Yes, this is it: the FMG no longer take care of the reseted FGT.

 

Regards,

dingjerry_FTNT

Hi @THOUEL ,

 

Then in the Device Manager page, right click on the FGT, choose "Remote Access", login to the FGT, run "exe factoryreset".  Lastly, delete this FGT in FMG.  

That's it.

Regards,

Jerry
THOUEL
New Contributor

And the team only have read access to the Fortigate.

johnlloyd_13
Contributor II

hi,

you can delete/remove the FGT device in FMG: device manager > device & groups > right-click device > delete.

then you issue the factory reset command in privilege mode "execute factory-reset".

the new/receiving team can console access using the default login and configure from scratch.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors