Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mykolasb
New Contributor

policy install date

Hi Guys, I' ve been googling for a while but no luck. I have a need to find out the date on which last firewall policy configuration changes were done. Currently I' m doing this by comparing firewall' s full-configuration daily backups. Also, in GUI system>maintenance I can find the date last backup was done. Is there a nice CLI or GUI way to know when was the configuration saved? Fortigate saves changes automatically, so last save should mean last changes? Thanks!
6 REPLIES 6
ede_pfau
SuperUser
SuperUser

Yes, exactly. But I don' t think you could get the list of recent saved configs via SNMP or such. Seen a post on the net where a guy uses plink (putty link) to grab the config from his mgmt host. You could do that periodically, compare to last config, discard if equal and save and log if not.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
mykolasb

Thanks, I' m doing the same right now - comparing backups. I mean - is there a way to check on device itself? Checkpoint FW' s have this Revision Control function under SmartDashboard, maybe something similar exists for Fortigates?
ede_pfau
SuperUser
SuperUser

I' m running 4.3.x. On the Dashboard, System Information widget, System Configuration, click ' [Revisions]' . Check 2 configs then you have a ' Diff' button. So you can get a clue what was changed last. Date and rev. number are given in the list. BTW, as the diff is line-wise, it' s not easy to grasp in which context the change was made. I do the diffs manually in a program that shows the whole config (like windiff) which is much easier.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

You want the FortiManager. That' s what it' s designed todo and setup revision and change control management Also altenatively, you could set a date/time on the fwpolicy comment field.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rwpatterson
Valued Contributor III

Under ' Log & Report' , there is an option to send a scheduled email indicating if there is a configuration change. At least it' s here in 4.2.x land...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
rwpatterson
Valued Contributor III

Sample message:
Message meets Alert condition
 date=2013-06-13 time=09:21:28 devname=(my_fortigate)-1 device_id=FGT1KA26065xxxxx log_id=0104032127 type=event subtype=admin pri=notice
 vd=root user=" rpatters"  ui=GUI(192.168.60.160) seq=328 sintf=" Wireless VLANs"  dintf=" port1"  saddr=" VLAN.148.guest"  daddr=" Server" 
 act=accept nat=no iptype=ipv4 schd=" always"  svr=" Allow.services"  msg=" User rpatters changed IPv4 firewall policy 328 from GUI(192.168.60.160)" 
 

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors