execute : restore
 
restore
Use this command to
restore the configuration from a file
change the FortiGate firmware
change the FortiGate backup firmware
restore an IPS custom signature file
When virtual domain configuration is enabled (in system global, vdom-admin is enabled), the content of the backup file depends on the administrator account that created it.
A backup of the system configuration from the super admin account contains the global settings and the settings for all of the VDOMs. Only the super admin account can restore the configuration from this file.
A backup file from a regular administrator account contains the global settings and the settings for the VDOM to which the administrator belongs. Only a regular administrator account can restore the configuration from this file.
Syntax
execute restore av ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
execute restore av tftp <filename_str> <server_ipv4[:port_int]>
execute restore config dhcp <port>
execute restore config flash <revision>
execute restore config ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>] [<backup_password_str>]
execute restore config management-station {normal | template | script} <rev_int>
execute restore config tftp <filename_str> <server_ipv4> [<backup_password_str>]
execute restore config usb <filename_str> [<backup_password_str>]
execute restore config usb-mode [<backup_password_str>]
execute restore forticlient tftp <filename_str> <server_ipv4>
execute restore image flash <revision>
execute restore image ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
execute restore image management-station <version_int>
execute restore image tftp <filename_str> <server_ipv4>
execute restore image usb <filename_str>
execute restore ips ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
execute restore ips tftp <filename_str> <server_ipv4>
execute restore ipsuserdefsig ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
execute restore ipsuserdefsig tftp <filename_str> <server_ipv4>
execute restore secondary-image ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
execute restore secondary-image tftp <filename_str> <server_ipv4>
execute restore secondary-image usb <filename_str>
execute restore src-vis <src-vis-pkgfile>
execute restore vcm {ftp | tftp} <filename_str> <server_ipv4>
execute restore vmlicense {ftp | tftp} <filename_str> <server_ipv4>
 
Variable
Description
av ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
Download the antivirus database file from an FTP server to the FortiGate unit.
av tftp <filename_str> <server_ipv4[:port_int]>
Download the antivirus database file from a TFTP server to the FortiGate unit.
config dhcp <port>
Restore the system configuration from a DHCP server. The new configuration replaces the existing configuration, including administrator accounts and passwords.
config flash <revision>
Restore the specified revision of the system configuration from the flash disk.
config ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>] [<backup_password_str>]
Restore the system configuration from an FTP server. The new configuration replaces the existing configuration, including administrator accounts and passwords.
If the backup file was created with a password, you must specify the password.
config management-station {normal | template | script} <rev_int>
Restore the system configuration from the central management server. The new configuration replaces the existing configuration, including administrator accounts and passwords.
rev_int is the revision number of the saved configuration to restore. Enter 0 for the most recent revision.
config tftp <filename_str> <server_ipv4> [<backup_password_str>]
Restore the system configuration from a file on a TFTP server. The new configuration replaces the existing configuration, including administrator accounts and passwords.
If the backup file was created with a password, you must specify the password.
config usb <filename_str> [<backup_password_str>]
Restore the system configuration from a file on a USB disk. The new configuration replaces the existing configuration, including administrator accounts and passwords.
If the backup file was created with a password, you must specify the password.
config usb-mode [<backup_password_str>]
Restore the system configuration from a USB disk. The new configuration replaces the existing configuration, including administrator accounts and passwords. When the USB drive is removed, the FortiGate unit needs to reboot and revert to the unit’s existing configuration.
If the backup file was created with a password, you must specify the password.
forticlient tftp <filename_str> <server_ipv4>
Download the FortiClient image from a TFTP server to the FortiGate unit. The filename must have the format: FortiClientSetup_versionmajor.versionminor.build.exe.
For example, FortiClientSetup.4.0.377.exe.
image flash <revision>
Restore specified firmware image from flash disk.
image ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
Download a firmware image from an FTP server to the FortiGate unit. The FortiGate unit reboots, loading the new firmware.
This command is not available in multiple VDOM mode.
image management-station <version_int>
Download a firmware image from the central management station. This is available if you have configured a FortiManager unit as a central management server. This is also available if your account with FortiGuard Analysis and Management Service allows you to upload firmware images.
image tftp <filename_str> <server_ipv4>
Download a firmware image from a TFTP server to the FortiGate unit. The FortiGate unit reboots, loading the new firmware.
This command is not available in multiple VDOM mode.
image usb <filename_str>
Download a firmware image from a USB disk to the FortiGate unit. The FortiGate unit reboots, loading the new firmware.
ips ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
Download the IPS database file from an FTP server to the FortiGate unit.
ips tftp <filename_str> <server_ipv4>
Download the IPS database file from a TFTP server to the FortiGate unit.
ipsuserdefsig ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
Restore IPS custom signature file from an FTP server. The file will overwrite the existing IPS custom signature file.
ipsuserdefsig tftp <filename_str> <server_ipv4>
Restore an IPS custom signature file from a TFTP server. The file will overwrite the existing IPS custom signature file.
secondary-image ftp <filename_str> <server_ipv4[:port_int] | server_fqdn[:port_int]> [<username_str> <password_str>]
Download a firmware image from an FTP server as the backup firmware of the FortiGate unit. Available on models that support backup firmware images.
secondary-image tftp <filename_str> <server_ipv4>
Download a firmware image from a TFTP server as the backup firmware of the FortiGate unit. Available on models that support backup firmware images.
secondary-image usb <filename_str>
Download a firmware image from a USB disk as the backup firmware of the FortiGate unit. The unit restarts when the upload is complete. Available on models that support backup firmware images.
src-vis <src-vis-pkgfile>
Download source visibility signature package.
vcm {ftp | tftp} <filename_str> <server_ipv4>
Restore VCM engine/plugin from an ftp or tftp server.
vmlicense {ftp | tftp} <filename_str> <server_ipv4>
Restore VM license (VM version of product only).
Example
This example shows how to upload a configuration file from a TFTP server to the FortiGate unit and restart the FortiGate unit with this configuration. The name of the configuration file on the TFTP server is backupconfig. The IP address of the TFTP server is 192.168.1.23.
execute restore config tftp backupconfig 192.168.1.23