Steps to implement an automated config backup solution for your FortiGate with Wasabi Cloud for 6.99$/month
- Create an account on wasabi cloud https://wasabi.com/fr.
- Create a bucket and activate the versioning.
- Activate the FTP/FTPS protocol in Wasabi
- Configure your FortiGate CLI config backup over FTP command
- Configure Your automation Trigger
- Configure Your automation Action
- Configure Your automation Stitch
FortiGate CLI config backup over FTP command
You can connect over FTP/FTPS to your Wasabi S3 Bucket with your account credentials. In paid plan you can create sub-user with FTP/FTPS access.
To connect to your Wasabi S3 Bucket over FTP you need :
- The region where the bucket is created here is eu-west-2
- The name of the Bucket, here is backup_fortigate
- Your username/email & password of your Wasabi account here is fortigate@gitbook.deddy.me
You can connect to your Bucket with a FTP’s client https://winscp.net or https://filezilla-project.org with this configuration :
- Host : s3.<wasabi_bucket_region>.wasabisys.com ⇒ s3.eu-west-2.wasabisys.com
- Username : The Wasabi account email => fortigate@gitbook.deddy.me
- Password : The Wasabi account password => superStrongPassword
Build the FortiGate CLI Command
execute backup full-config ftp <bucket_name>/fortigate_01_config [s3.<](http://s3.eu-west-2.wasabisys.com:21/)wasabi_bucket_region>.wasabisys.[com:21](http://s3.eu-west-2.wasabisys.com:21/) <ftp_username/email> <ftp_password>
The complete FortiGate CLI Command
execute backup full-config ftp backup_fortigate/fortigate_01_config [s3.](http://s3.eu-west-2.wasabisys.com:21/)eu-west-2.wasabisys.[com:21](http://s3.eu-west-2.wasabisys.com:21/) fortigate@gitbook.deddy.me superStrongPassword
Wasabi Cloud Active the FTP/FTPS protocol in the settings
data:image/s3,"s3://crabby-images/5ada6/5ada624db15502f4fd544398ad02358d6a387223" alt="Use Wasabi cloud to backup your FortiGate Firewall configuration for 6.99$/month 2 Wasabi Cloud Active the FTP/FTPS protocol in the settings"
Create a Trigger in Security Fabric > Automation > Trigger
Each day the script will be executed.
data:image/s3,"s3://crabby-images/ee69a/ee69a238db9385b090e1ae655547503a118b5679" alt="Use Wasabi cloud to backup your FortiGate Firewall configuration for 6.99$/month 3 fortigate automation trigger"
Create an action in Security Fabric > Automation > Action
data:image/s3,"s3://crabby-images/15ff6/15ff661d8f556297a807191aee33247f4e30ebd4" alt="Use Wasabi cloud to backup your FortiGate Firewall configuration for 6.99$/month 4 fortigate automation action"
Create a Stitch on Security Fabric > Automation > Stitch
data:image/s3,"s3://crabby-images/22f9a/22f9af19a0ebfc1cf9b3e0f1e70bf191e42d4ee0" alt="Use Wasabi cloud to backup your FortiGate Firewall configuration for 6.99$/month 5 fortigate automation stitch - Use Wasabi cloud to backup your FortiGate Firewall configuration for 6.99$/month"
How to monitor that Fortigate backups are up to date ?
You can implement a solution that monitors the last modification date of files either via the AWS S3 SDK JS library. See