To configure the date and time:
1. Go to System Settings > General > Dashboard.
2. In the System Information widget, in the System Time field, select Change. The Change System Time Settings dialog box appears, see Time Settings dialog box.
Time Settings dialog box
Configure the following settings to either manually configure the system time, or to automatically synchronize the FortiManager unit’s clock with an NTP server:
System Time The date and time according to the FortiManager unit’s clock at the time that this tab was loaded, or when you last selected the Refresh button.
Time Zone Select the time zone in which the FortiManager unit is located and whether or not the system automatically adjusts for daylight savings time.
Set Time Select this option to manually set the date and time of the FortiManager unit’s clock, then select the Hour, Minute, Second, Year, Month, and Day fields before you select OK.
Synchronize with NTP
Server Select this option to automatically synchronize the date and time of the FortiManager unit’s clock with an NTP server, then configure the Syn Interval and Server fields before you select OK.
Sync Interval Type how often in minutes the FortiManager unit should synchronize its time with the NTP server. For example, entering 1440 causes the FortiManager unit to synchronize its time once a day.
Server Type the IP address or domain name of an NTP server. To find an NTP server that you can use, go to http://www.ntp.org. Select the add icon to add an NTP server. Select the delete icon to delete an NTP server.
3. Select OK to apply your changes.
Updating the system firmware
To take advantage of the latest features and fixes, FortiManager provides two ways to upgrade its firmware: manually or through the FDN.
For information about upgrading your FortiManager device, see the FortiManagerRelease Notes or contact Fortinet Customer Service & Support.
Back up the configuration and database before changing the firmware of your FortiManager unit. Changing the firmware to an older or incompatible version may reset the configuration and database to the default values for that firmware version, resulting in data loss. For information on backing up the configuration, see Backing up the system.
Before you can download firmware updates for your FortiManager unit, you must first register your FortiManager unit with Customer Service & Support. For details, go to https://support.fortinet.com/ or contact Customer Service & Support.
To manually update the FortiManager firmware:
1. Download the firmware (the .out file) from the Customer Service & Support website, https://support.fortinet.com/.
2. Go to System Settings > Dashboard.
3. In the System Information widget, in the Firmware Version field, select [Update].
The Firmware Upgrade window opens.
4. Select Browse to locate the firmware package (.out file) that you downloaded from the Customer Service & Support website, and select Open.
5. Select OK to upload the file.
Your browser uploads the firmware file. The time required varies by the size of the file and the speed of your network connection. When the file transfer is complete, a prompt appears:
“Manual upload release complete. It will take a few minutes to unpack the uploaded release. Please wait.”
6. Wait until the unpacking process completes, then refresh the page. The firmware package file name will appear in the Releases Available ForUpgrade section after you refresh the page.
7. Select the firmware package, then select the icon in the Upgrade Firmware column and select OK in the dialog box that appears. The FortiManager unit installs the firmware and restarts.
If you changed the firmware to an earlier version whose configuration is not compatible, you may need to do firsttime setup again. For instructions, see the FortiManagerQuickStart Guide for your unit.
8. Update the vulnerability management engine and definitions. For details, see FortiGuard Management.
Installing firmware replaces the current network vulnerability management engine with the version included with the firmware release that you are installing. After you install the new firmware, make sure that your vulnerability definitions are up-to-date. For more information, seeFortiGuard Management.
The FortiManager firmware can also be updated through the FDN. For more information, seeFirmware images of the FortiGuard Management chapter.
Backing up the system
Fortinet recommends that you back up your FortiManager configuration to your management PC or central management server on a regular basis to ensure that, should the system fail, you can quickly get the system back to its original state with minimal affect to the network. You should also perform a back up after making any changes to the FortiManager configuration or settings that affect the managed devices.
You can perform backups manually or at scheduled intervals. You can also create a backups – called checkpoints – that define a point where the FortiManager and network management is stable and functioning. Should any future configurations cause issues, you have a point where the system is stable.
Fortinet recommends backing up all configuration settings from your FortiManager unit before upgrading the FortiManager firmware.
To back up the FortiManager configuration:
1. Go to System Settings > Dashboard.
2. In the System Information widget, under System Configuration, select [Backup]. The Backup dialog box opens.
3. Configure the following settings:
Encryption Select to encrypt the backup file with a password. The password is required to restore the configuration. The check box is selected by default.
Password (Optional) Select a password. This password is used to encrypt the backup file, and is required to restore the file. (This option is available only when the encryption check box is selected.)
Confirm Password Type the password again. The passwords must match.
4. If you want to encrypt the backup file, select the Encryption check box, then type and confirm the password you want to use.
5. Select OK and save the backup file on your management computer.
Restoring the configuration
You can use the following procedure to restore your FortiManager configuration from a backup file on your management computer. If your FortiManager unit is in HA mode, switch to Standalone mode.
The restore operation will temporarily disable the communication channel between FortiManager and all managed devices. This is a safety measure, in case any devices are being managed by another FortiManager. To re-enable the communication, please go to System Settings >Advanced >Advanced Settings and disable Offline Mode.
To restore the FortiManager configuration:
1. Go to System Settings > Dashboard.
2. In the System Information widget, under System Configuration, select [Restore]. The Restore dialog box appears; see Restore dialog box.
Restore dialog box
3. Configure the following settings and select OK.
From Local Select Browse to find the configuration backup file you want to restore.
Password Type the encryption password, if applicable. The password can be a maximum of 15 characters.
Overwrite current IP, routing and HA settings Select the check box to overwrite the current IP, routing and HA settings.
Restore in Offline Mode Informational check box. Hover over the help icon for more information.
Creating a system checkpoint
You can create a system checkpoint backup to capture a specific configuration. This backup provides a history where the FortiManager and FortiGate units are completely in sync. Should there be a major failure, you can completely revert the FortiManager to when it was in working order. These are, in essence, snapshots of your FortiManager managed network system.
You should make a system checkpoint backup before installing new firmware to devices or making a major configuration change to the network. If the update or modification causes problems, you can quickly revert to an earlier known “good” version of the configuration to restore operation.
A system checkpoint backup includes the system configuration of the FortiManager unit.
Please note the following:
l The system checkpoint does not include the FortiGate settings.
l For policy package specific settings, after reverting to a checkpoint, you need to re-install policy packages to update FortiGate policy and related configuration. For non-policy package settings, after reving to a checkpoint, you must trigger FortiGate to auto-update and overwrite the checkpoint reverted configuration. Alternatively, you can disable the auto update function in System Settings and re-install the checkpoint reverted configuration to FortiGate.
To create a system checkpoint:
1. Go to System Settings > Dashboard.
2. In the System Information widget, under System Configuration, select [System Checkpoint]. The System Checkpoint table opens.
System checkpoint table
3. Select Create New. The Create New System Checkpoint dialog box opens.
Create new system checkpoint
4. In the Comments box, type a description, up to 63 characters, for the reason or state of the backup.
5. Select OK. The system checkpoint task will be run and the checkpoint will be created.
To revert to a system checkpoint:
1. Go to System Settings > Dashboard.
2. In the System Information widget, under System Configuration, select [System Checkpoint]. The System Checkpoint table opens.
System checkpoint table
3. Select the system checkpoint in the table and select the revert icon.
4. A confirmation dialog box will open. Select OK to continue.
To delete a system checkpoint:
1. Go to System Settings > Dashboard.
2. In the System Information widget, under System Configuration, select [System Checkpoint]. The System Checkpoint table opens.
3. Select the system checkpoint in the table and select the Delete in the toolbar.
4. A confirmation dialog box will open. Select OK to continue.
Enable or disable FortiAnalyzer features
The FortiAnalyzer feature set can enabled or disabled via the CLI using the following command:
config system global set faz-status {enable | disable}
end
You can also enable or disable these features in the FortiManager Web-based Manager. The FortiAnalyzer feature set includes the following modules: FortiView, Event Management, and Reports. Other menu items are FortiAnalyzer