Discussion:
[rancid] Rancid and Fortinet Vdoms
toad toad
2013-10-09 12:40:01 UTC
Permalink
Hi everyone,

I've been using rancid's fnlogin script to backup Fortinet for months and
everything works fine.

I've a problem with a Fortinet that uses VDOMs. As I understand (I'm not a
Fortinet expert, I'm just in charge of the backups), I only get the
configuration of the VDOM that the backup user is part of.

For example, let's assume of the following configuration : user1 is part of
the VDOM1, user2 is part of the VDOM2 and they have a super_admin profile.
If I use the user1 to backup, I get the global configuration and the VDOM1,
but not the VDOM2 configuration. If I use the user2 to backup, I get the
global configuration and the VDOM2 but not the VDOM1 configuration.

Is there any script I can use to get all the VDOMs configurations? Or
update an existing one?

Thanks for help.
Alexander Bochmann
2013-10-31 07:56:43 UTC
Permalink
Question is a couple of weeks old, but as there was no answer on the list -
Post by toad toad
I've a problem with a Fortinet that uses VDOMs. As I understand (I'm not a
Fortinet expert, I'm just in charge of the backups), I only get the
configuration of the VDOM that the backup user is part of.
I don't currently use rancid to backup Fortigate configurations, but your
firewall people should be able to create a global read-only admin user that
has access to all VDOM configurations (the predefined accprofile "super_admin"
is read/write for all VDOMs, for example). As recent versions of fnrancid run
"show full-configuration", you should then get complete config data, global
and for all vdoms.

Alex.

Loading...