Page 1 of 1

support for fortigate?

Posted: Fri Jan 01, 2021 9:06 pm
by tomislav91
Do you have support for FortiGate devices? I tried but didnt suceed to connect, ssh works fine via putty.

Re: support for fortigate?

Posted: Fri Jan 01, 2021 10:04 pm
by Tomas
Yes, FortiGates (and many other FortiOS devices) are fully supported.

What's the reason for discovery on your FortiGate?
Dashboard > Latest failed jobs > select job > Show log

Re: support for fortigate?

Posted: Sat Jan 02, 2021 4:01 pm
by tomislav91
Tomas wrote:
Fri Jan 01, 2021 10:04 pm
Yes, FortiGates (and many other FortiOS devices) are fully supported.

What's the reason for discovery on your FortiGate?
Dashboard > Latest failed jobs > select job > Show log

Code: Select all

Error: Could not connect to device

Discovery log:
Service check:
  SSH: Service available

Service connection:
  SSH: CONNECTION_ERROR

Re: support for fortigate?

Posted: Tue Jan 05, 2021 2:50 pm
by Tomas
Best would be to enable both Debug options (Debug Logging and Device Output Logging) under "Zones > your_zone > Debug mode", and after the discovery fails, download both log files.

Please create a ticket on our Portal, and attach both logs, and we will investigate :)

Re: support for fortigate?

Posted: Tue Jan 12, 2021 9:31 pm
by neodawg007
Not trying to hijack this thread, but I was wondering if there is a way to change the command to do show full-config vs show running.
The reason being is that the running doesn't print any installed SSL certificates, so thus in a failure you wouldn't have the SSL certs reimported with the config restore.

I realize this makes the config way way longer as it prints every configurable command available. I am testing on Fortigate 3000D firewalls.

Thanks

Re: support for fortigate?

Posted: Tue Jan 12, 2021 10:59 pm
by Tomas
neodawg007 wrote:
Tue Jan 12, 2021 9:31 pm
Not trying to hijack this thread, but I was wondering if there is a way to change the command to do show full-config vs show running.
The reason being is that the running doesn't print any installed SSL certificates, so thus in a failure you wouldn't have the SSL certs reimported with the config restore.
Sorry, currently no way to influence what Unimus retrieves from devices during backups. We do plan to add a mechanism to be able to specify how / what Unimus does during backup, but I can't promise any ETA at the moment.

Re: support for fortigate?

Posted: Wed Jan 13, 2021 7:47 pm
by neodawg007
Tomas wrote:
Tue Jan 12, 2021 10:59 pm
neodawg007 wrote:
Tue Jan 12, 2021 9:31 pm
Not trying to hijack this thread, but I was wondering if there is a way to change the command to do show full-config vs show running.
The reason being is that the running doesn't print any installed SSL certificates, so thus in a failure you wouldn't have the SSL certs reimported with the config restore.
Sorry, currently no way to influence what Unimus retrieves from devices during backups. We do plan to add a mechanism to be able to specify how / what Unimus does during backup, but I can't promise any ETA at the moment.
Thanks for the response, I am really liking the product so far, so much better than the alternates I have tried. Please put/keep this on the future feature list :)

Re: support for fortigate?

Posted: Thu Aug 05, 2021 5:55 pm
by alfie
Tomas wrote:
Tue Jan 12, 2021 10:59 pm
neodawg007 wrote:
Tue Jan 12, 2021 9:31 pm
Not trying to hijack this thread, but I was wondering if there is a way to change the command to do show full-config vs show running.
The reason being is that the running doesn't print any installed SSL certificates, so thus in a failure you wouldn't have the SSL certs reimported with the config restore.
Sorry, currently no way to influence what Unimus retrieves from devices during backups. We do plan to add a mechanism to be able to specify how / what Unimus does during backup, but I can't promise any ETA at the moment.
I had a scan through the roadmap but could not see anything relating to this. Is it still happening?

Thank you

Alfie

Re: support for fortigate?

Posted: Thu Aug 05, 2021 7:21 pm
by Vik@Unimus
As Tomas outlined in his last response, this feature is planned, however, there is no ETA yet.